
Policy
Data Privacy
A transparent and compliant commitment to protecting personal data to the highest standards.
Privacy Policy
Personal Data Protection Commitment
In accordance with Decree No. 13/2023/ND-CP of the Government on personal data protection, effective from July 1, 2023.
Feaon Technology Solutions Co., Ltd. is committed to protecting customer data under strict information security standards and full legal compliance.
Article 1. Purpose and Scope of Application
Purpose: This commitment ensures that all personal and related customer/partner data collected, processed, and stored by Feaon is protected with strict security and transparency.
Scope of application:
- Software outsourcing services.
- Software solutions/products provided by Feaon (e.g., GTS, AUTOTMS, VAMS).
- Consulting and technical support services.
- Information collected through Feaon websites, applications, or official communication channels.
Article 2. Personal Data Protection Content
The parties acknowledge and agree that: (i) Feaon acts as a personal data processor under applicable law; (ii) the customer/partner acts as data subject, controller, or controller-processor; and (iii) each party fully complies with legal obligations.
Purposes of data collection, storage, and processing:
- Execution of contracts and related operations.
- Delivery of notices and operational communications between parties.
- Prevention of fraud, abuse, or account compromise.
- Research and development of new services and suitable recommendations.
- Identity verification and security assurance.
- Record retention and compliance with legal and tax obligations.
- Other lawful purposes as required by regulations over time.
Feaon will not:
- Process, retain, use, or disclose personal data beyond what is necessary for contractual performance or legal requirements.
- Sell personal data to any third party.
- Disclose data outside the direct business relationship unless requested by the data subject or required by law.
Customer/partner instructions regarding data processing must align with the contract and applicable data protection laws. Customers/partners are responsible for the accuracy, legality, and origin of the data they provide.
Where the customer/partner is not the data subject:
- Clear consent has been obtained from the data subject for collection, sharing, and use under the contract.
- The data subject has been informed and has clearly consented to any cross-border processing (if applicable).
- If acting as controller or controller-processor, the customer/partner confirms legal authorization when appointing Feaon as another processor.
Protected data types include symbols, text, numbers, images, audio, or equivalent electronic data linked to or identifying a specific person, including basic and sensitive personal data (e.g., full name, address, phone number, date of birth, email, and other data as prescribed by law).
Data protection period: Feaon processes data during contract validity and as required by law.
Feaon applies all reasonable measures to secure data. In case of disruption, system errors, vendor incidents, or force majeure events, Feaon will make best efforts to notify affected parties promptly and is exempt from liability within legally permitted limits.
Upon detecting a data protection violation, Feaon will notify customers/partners as soon as possible. Controllers or controller-processors are responsible for notifying competent authorities within 72 hours of the incident under applicable regulations.
Article 3. Data Protection Principles
- Lawful, fair, and transparent: all processing activities have a clear legal basis.
- Purpose limitation: data is used only for stated and notified purposes.
- Data minimization: only necessary and relevant data is collected.
- Accuracy and updates: data is maintained correctly and updated when required.
- Storage limitation: data is retained only as long as necessary unless otherwise agreed by law.
- Integrity and confidentiality: technical and organizational measures are applied to prevent unauthorized access, loss, or damage.
Article 4. Rights and Obligations of Data Subjects
- Right to know how data is collected, processed, and used.
- Right to access and request correction of inaccurate information.
- Right to withdraw consent at any time (unless otherwise required by law).
- Right to request deletion of unnecessary or unlawfully processed data.
- Obligation to provide accurate information and protect personal data responsibly.
Feaon commits to respond to valid data subject requests within 72 hours of receipt.
Article 5. Data Protection Measures
- Comply with ISO 27001 standards for information security management.
- Apply encryption, firewall, and IDS/IPS technologies for system protection.
- Maintain strict internal procedures for access control, backup, and recovery.
- Conduct periodic staff training on security and compliance.
- Require partners/vendors to follow equivalent security standards.
Article 6. Return and Deletion of Personal Data
Depending on the contract, customers/partners may be granted access or request data deletion. In the absence of a deletion request, data will be removed according to contractual terms or Feaon internal retention policy in compliance with law.
Before contract termination, customers/partners should export required records or request deletion of unnecessary data, provided this does not disrupt remaining service obligations or violate legal requirements.
Data deletion does not apply when:
- The law does not permit deletion.
- Data is processed by competent state authorities for regulatory functions.
- Data has been lawfully made public.
- Data is required for legal obligations, research, or statistical purposes.
- Emergency situations related to national defense, security, public order, disasters, epidemics, or crime prevention under law.
- Emergency response to threats against life, health, or safety of the data subject or others.
Article 7. Customer and Partner Declaration
Customers/partners voluntarily agree to and understand the full contents of this commitment.
Where acting as controller or controller-processor, customers/partners confirm they have lawfully notified and obtained data subject consent prior to collection and processing, and accept liability for damages caused by violations of these commitments.
Article 8. Website Forms, Security, and Analytics
When customers submit a contact or consultation form on the website, Feaon may collect name, phone number, email, area of interest, and request details to respond, provide consultation, and manage business opportunities.
- Form data may be sent through a transactional email provider or a server-side lead intake/CRM system configured by Feaon.
- The website may use Cloudflare Turnstile to verify anti-spam protection and protect forms from automated abuse.
- The website may use analytics tools such as Google Analytics when configured to measure traffic, content performance, and user experience.
- Secret keys, server tokens, and sensitive configuration values are not exposed to the browser.
Article 9. General Terms
This commitment forms an integral part of the contract between Feaon and customers/partners. If Feaon provides personal data it has collected or controls to customers/partners, the receiving party commits to applying protection standards no lower than those stated in this document.
Google Analytics and cookie choices
The site uses Google Analytics 4 only after you actively allow analytics measurement. Under basic consent mode, the Google tag is not loaded and measurement data is not sent before you agree or when you reject.
The analytics choice is stored in your browser’s local storage so the site can remember it. You can reopen “Cookie preferences” in the footer to change or revoke your choice at any time.
Google Ads, remarketing, and advertising consent are not active. This description reflects technical behavior and is not a legal-compliance certification.