This Personal Data Protection Policy describes the manner in which Vietnam-America VAIS International Joint Stock Company and St. Paul International Primary, Middle, and High School (Giải thích: St. Paul International Primary, Middle, and High School: là tên tiếng Anh được ghi trong Giấy phép hoạt động trường. Còn St. Paul American School Hanoi là tên gọi thực tế) (hereinafter referred to as the “Company”) collects, uses and processes personal data arising in the course of the Company’s operations and business activities. The Company is located at Lot TH3-NT4, Km 10 + 600, Splendora New Urban Area, Thang Long Avenue, Son Dong Commune, Hanoi City, and its official website is https://stpaulhanoi.com.
1.1 Personal Data means information in the form of symbols, letters, numbers, images, sounds or similar forms in electronic media that is associated with a specific individual or enables the identification of a specific individual. Personal Data includes Basic Personal Data and Sensitive Personal Data.
1.2 Data Subject means the individual to whom the Personal Data relates, including all individual customers using the Company’s products and services, the Company’s employees, shareholders and/or any other individuals who have a legal relationship with the Company.
1.3 Processing of Personal Data means one or more operations performed on Personal Data, such as: collection, recording, analysis, verification, storage, modification, disclosure, combination, access, retrieval, withdrawal, encryption, decryption, copying, sharing, transmission, provision, transfer, deletion, destruction of Personal Data or any other related actions.
1.4 Where Personal Data of persons related to the Data Subject (including but not limited to information of dependents, persons related under the law, spouse, children and/or parents and/or guardians, friends, beneficiaries, authorised persons, partners, emergency contacts or any other individuals related to the Data Subject) is provided to the Company, the Data Subject and the related persons of the Data Subject warrant, guarantee and undertake that the information provided is complete and that the Data Subject has lawfully consented to or approved the processing of such data for the purposes set out in this Policy. The Data Subject and the related persons of the Data Subject agree that the Company has no obligation to verify the legality or validity of such consent or approval, and that the responsibility for retaining evidence of such consent or approval rests with the Data Subject and the related persons of the Data Subject. The Company shall be exempt from liability and shall be entitled to claim compensation for any damages and costs incurred if the Data Subject and/or the related persons of the Data Subject fail to comply with the provisions herein.
1.5 By registering for, using the Company’s products and services, entering into contracts and/or permitting the Company to Process Personal Data, the Data Subject accepts in full and without any conditions all the policies set out herein and any amendments (if any) from time to time.
1.6 This Policy may be updated, amended, supplemented or replaced by the Company from time to time and shall be posted on the Company’s official website. You should regularly visit and check our website to stay informed of the latest changes.
1.7 The Company undertakes to comply with the following principles when Processing Personal Data:
In order for the Company to Process Personal Data for the purposes set out in Section 3 of this Policy, the Company may process the following types of Personal Data:
2.1 Basic Personal Data includes:
2.2 Sensitive Personal Data includes the following main categories:
Personal Data may be processed for one or more of the following purposes:
3.1 Assessing the ability to provide products and services and/or entering into contracts with the Data Subject, including but not limited to:
3.2 Improving the quality of the Company’s products and services, including but not limited to:
3.3 Serving the Company’s business and operational activities, including but not limited to the performance of reporting, financial, accounting and tax obligations, audit activities, compliance activities and other activities serving the Company’s lawful business operations in cases the Company deems necessary.
3.4 Restructuring, transfer of projects/businesses: In the course of business, the Company may sell or purchase businesses or restructure the business or transfer projects or other services in accordance with the laws. Accordingly, Personal Data and the right to use information in general constitute one of the assets to be transferred. In all cases, the transfer and processing of data shall be carried out by the parties in accordance with the laws and this Policy.
3.5 Other purposes:
4.1 Methods of collection: Personal Data is collected as follows:
4.2 Methods of storage Personal Data is stored in Vietnam in the Company’s database system or at any location where we or our branches, subsidiaries, affiliates, partners or service providers maintain facilities. The retention period of personal data is determined based on the purposes of use as stated in this Policy and in accordance with the laws.
4.3 Methods of transfer/sharing of data The Company will not sell Personal Data to any party. The Company applies necessary security measures to ensure that the transfer/sharing of Personal Data is secure. Personal Data is shared by the Company with (i) the Company’s parent company, subsidiaries and affiliates; (ii) individuals/organisations participating in the Processing of Personal Data as stipulated in this Policy; or (iii) competent state authorities or other cases in accordance with the laws. If the recipient of Personal Data is located outside the territory of Vietnam, when providing or transferring Personal Data abroad (including but not limited to the use of cyberspace, devices, electronic means or other forms to transfer Personal Data outside the territory of Vietnam), the Company will require the recipient to ensure the safety and security of the Personal Data provided or transferred. The Company undertakes to fully comply with the regulations and requirements of Vietnamese law to protect the safety of Personal Data.
4.4 Methods of analysis Personal Data is analysed based on the Company’s internal procedures, data security principles and assurance of information security for the information technology system.
4.5 Methods of encryption Where necessary, collected Personal Data is encrypted in accordance with appropriate encryption standards during storage, transfer and processing to ensure that the data is always protected.
4.6 Methods of deletion of data In accordance with the laws or upon a valid request from the Data Subject, the Company will delete the Personal Data being stored, except in the following cases:
4.7 Security Throughout the entire process of Processing Personal Data, security is the Company’s highest priority. The Company has appropriate technical measures to prevent unauthorised access to or use of Personal Data. We also regularly cooperate with security experts to update the latest cybersecurity techniques to ensure the safety of Personal Data. Payment card data of customers issued by financial institutions is protected by the Company on the principle that important card data (card number, cardholder name, CVV) is not recorded on our system. Your payment transactions are processed on the relevant bank’s system.
5.1 The Company will Process Personal Data of children in accordance with the principles of protecting children’s rights and best interests and in compliance with the laws.
5.2 The Company will only Process Personal Data of children and provide products and services to children if the parents or guardians consent to the child’s use of the Company’s products and services, consent to the Company’s Processing of the child’s Personal Data, consent to this Policy and comply with the relevant legal requirements. In the case of children aged 7 years or older using the Company’s products and services, in addition to the requirements stated herein, the Company will only Process the child’s Personal Data with the consent of that child. Parents or guardians are responsible for obtaining the child’s consent before providing the child’s Personal Data to the Company.
6.1 The Company employs various information security technologies such as firewalls, access control measures, encryption, etc., to protect and prevent Personal Data from being accessed, used or shared without authorisation. However, the Company cannot guarantee absolute security of Personal Data in certain cases such as: a. Hardware or software errors during data processing that result in loss of the Data Subject’s data; b. Security vulnerabilities beyond the Company’s control, or the system being attacked by hackers causing data leakage or exposure.
6.2 The Company advises Data Subjects to keep confidential information related to account login passwords and OTP codes and not to share such content with any other person.
6.3 Data Subjects must be aware that at any time when a Data Subject discloses or makes public their own Personal Data, that data may be collected and used by others for purposes beyond the control of the Data Subject and the Company.
6.4 The Company advises Data Subjects to safeguard their personal devices (mobile phones, tablets, personal computers, etc.) while using them. Data Subjects should log out of their accounts when not in use.
6.5 In the event that the data storage server is attacked resulting in loss, leakage or exposure of Personal Data, the Company will be responsible for promptly notifying the competent authorities for investigation and handling and will notify the Data Subject in accordance with the laws.
6.6 Cyberspace is not a completely safe environment and the Company cannot guarantee that Personal Data shared over cyberspace will always be secure. When transmitting Personal Data over cyberspace, Data Subjects should only use secure systems to access websites, applications or devices. Data Subjects are responsible for keeping their authentication information for each website, application or device safe and confidential.
7.1 Personal Data is processed from the time the Company lawfully receives the Personal Data and has a lawful basis to process the data in accordance with the laws.
7.2 Personal Data will be processed until the purposes of processing the data have been fulfilled.
7.3 The Company may be required to retain Personal Data even after the contract between the parties has terminated in order to perform obligations under the laws and/or requirements of competent state authorities.
8.1 Depending on the circumstances, the Company may act as the data controller or as both the data controller and data processor.
8.2 To the extent permitted by law, the Data Subject understands that the Company may share Personal Data for the purposes set out in this Policy with the following organisations and individuals: a. The Company’s parent company, subsidiaries and affiliates; b. Organisations and individuals providing services to and/or cooperating with the Company, including but not limited to: agents, auditors, lawyers, business cooperation partners, providers of information technology solutions, software, applications, operational services, management services, troubleshooting services and infrastructure development services; c. Any individual or organisation acting as the representative or authorised person of the Data Subject, acting on behalf of the Data Subject.
8.3 The sharing of data will be carried out in accordance with the procedures, methods and current laws. Recipients of Personal Data are obliged to keep Personal Data confidential in accordance with this Policy, the Company’s internal regulations and standards on Personal Data protection and the current laws.
8.4 The Company may be required to share Personal Data with competent state authorities in accordance with the laws.
9.1 The right to be informed about the Processing of their own Personal Data, except where otherwise provided by law.
9.2 The right to consent or not to consent to the Processing of their own Personal Data, except where otherwise provided by law.
9.3 The right to access, view, edit or request the editing of their own Personal Data, except where otherwise provided by law.
9.4 The right to withdraw consent.
9.5 The right to request deletion of data.
9.6 The right to restrict the Processing of their own Personal Data in accordance with the laws.
9.7 The right to request the provision of their own Personal Data to themselves, except where otherwise provided by law.
9.8 The right to object to the processing of data.
9.9 The right to lodge complaints, denunciations or lawsuits.
9.10 The right to claim compensation for damages.
9.11 The right to self-protection.
9.12 The Data Subject may exercise these rights by submitting a request to the Company. The request form must be sent to the Company and must contain the basic details of the requester, the specific content of the request (for example, the type of data to be provided or deleted, the name of the document or file (if any)), the reason and purpose of the request, and any other relevant information depending on the nature of the request (for example, whether the requested document must be provided in electronic file or hard copy form, the delivery address, etc.). All costs (if any) incurred in fulfilling the requests set out herein, including but not limited to printing, copying, postage and express delivery fees for sending the data, shall be borne by the requester and must be paid no later than upon receipt of the data or within the time limit set by the Company.
9.13 The Company will process the Data Subject’s requests in accordance with the laws and taking into account the legitimate interests of the Data Subject. However, if the Data Subject withdraws their consent, requests deletion of data and/or exercises other related rights with respect to any or all Personal Data in a manner that affects the Company’s ability to provide or maintain its products or services to the Data Subject or to maintain the contractual relationship, depending on the nature of the Data Subject’s request, the Company may consider and decide not to continue providing the Company’s products or services to the Data Subject or to terminate the contractual relationship between the Company and the Data Subject. Any actions taken by the Data Subject in accordance with this provision shall be deemed a unilateral termination by the Data Subject of any relationship between the Data Subject and the Company and may fully result in a breach of obligations or commitments under the contract between the Data Subject and the Company, in which case the Company reserves all its lawful rights and remedies. Accordingly, the Company shall not be liable to the Data Subject for any losses arising therefrom and the Company’s lawful rights shall be fully reserved. By reasonable efforts, the Company will implement lawful and valid requests from the Data Subject within a time frame consistent with the laws. However, for security purposes, the Company may require the Data Subject to verify their identity before processing the Data Subject’s request.
9.14 The Company has the right to refuse to fulfil the Data Subject’s requests in certain cases, including but not limited to: (i) the Data Subject fails to follow the procedures and instructions provided by the Company and the request lacks information or is invalid; (ii) the Data Subject fails to provide or provides incomplete documents to verify their identity; or (iii) the Company assesses that there are signs of fraud or violation of Personal Data protection regulations; or (iv) the laws do not permit the fulfilment of the Data Subject’s request.
10.1 To protect their own Personal Data and to require other related organisations and individuals to protect their Personal Data. To promptly notify the Company upon discovering any errors, mistakes, leaks of Personal Data or suspicion that Personal Data is being infringed.
10.2 To respect and protect the personal data of others.
10.3 To provide complete and accurate Personal Data when consenting to the Processing of Personal Data. If any information is inaccurate, the Data Subject shall bear all costs themselves in the event that such information affects or restricts the Data Subject’s rights and benefits.
10.4 To comply with the laws on personal data protection and to participate in preventing and combating violations of the regulations on personal data protection.
10.5 Other responsibilities as prescribed by law.
11.1 The Data Subject confirms that, by accepting this Policy, the Data Subject has consented to the Processing of their Personal Data by the Company and by the organisations and individuals participating in the Processing of Personal Data as stated in this Policy, and has been fully informed of the types of data to be processed, the purposes of processing, the organisations and individuals that will Process the Personal Data, and their rights and obligations relating to Personal Data. The Data Subject has been notified by the Company, has been aware of and has agreed to all the contents that must be notified before the Personal Data is processed by the Company and by the organisations and individuals participating in the Processing of Personal Data. The Data Subject agrees that the Company and the organisations and individuals participating in the Processing of Personal Data are not required to provide further notification before Processing the Personal Data.
11.2 If you have any questions regarding the Company’s personal data protection, please contact us and we will endeavour to respond to your questions as soon as possible. You may also contact us at the following address:
Vietnam – America VAIS International Joint Stock Company and St. Paul International Primary, Middle, and High School (the accurate school name as stated in the school operation license):
Address: Lot TH3-NT4, Km 10 + 600, Splendora New Urban Area, Thang Long Avenue, Son Dong Commune, Hanoi City
Telephone: +84 24 3399 6464
Email: info@stpaulhanoi.com
This Policy is effective from 1 July 2023 and constitutes the updated Privacy Policy in accordance with the laws on personal data protection. The rights and obligations of the Data Subject are guaranteed in accordance with the applicable laws at each relevant time.
Chính sách bảo vệ dữ liệu cá nhân này mô tả cách thức Công ty Cổ phần Quốc tế VAIS Việt – Mỹ và Trường Tiểu học, Trung học cơ sở và Trung học phổ thông quốc tế St. Paul (the accurate St. Paul name stated in the school operating license) (sau đây gọi là “Công Ty”) thu thập, sử dụng và xử lý dữ liệu cá nhân phát sinh trong quá trình hoạt động, kinh doanh của Công Ty có địa chỉ tại: Lô TH3-NT4, Khu đô thị mới Splendora, Km 10+600, Đại lộ Thăng Long, xã Sơn Đồng, thành phố Hà Nội và trang thông tin điện tử chính thức là https://stpaulhanoi.com.
Để Công Ty có thể Xử Lý Dữ Liệu Cá Nhân cho các mục đích nêu tại Mục 3 của Chính sách này, Công Ty có thể xử lý loại Dữ Liệu Cá Nhân sau:
2.1 Dữ Liệu Cá Nhân cơ bản bao gồm:
2.2 Dữ Liệu Cá Nhân nhạy cảm bao gồm các dữ liệu chính sau:
Dữ Liệu Cá Nhân có thể được xử lý cho một hoặc nhiều mục đích như sau:
Dữ Liệu Cá Nhân được lưu trữ tại Việt Nam tại hệ thống cơ sở dữ liệu của Công Ty hoặc tại bất cứ đâu mà chúng tôi hoặc các chi nhánh, công ty con, công ty liên kết, đối tác hoặc nhà cung cấp dịch vụ của chúng tôi có cơ sở. Thời gian lưu trữ dữ liệu cá nhân được xác định căn cứ vào mục đích sử dụng như nêu tại Chính sách này và phù hợp với quy định pháp luật.
Công Ty sẽ không bán Dữ Liệu Cá Nhân cho bất cứ bên nào. Công Ty sử dụng các biện pháp bảo mật cần thiết để đảm bảo việc chuyển giao/chia sẻ Dữ Liệu Cá Nhân được an toàn. Dữ Liệu Cá Nhân được Công Ty chia sẻ cho (i) công ty mẹ, công ty con, công ty liên kết của Công Ty; (ii) cá nhân/tổ chức tham gia vào quá trình Xử Lý Dữ Liệu Cá Nhân quy định tại Chính sách này; hoặc (iii) cơ quan nhà nước có thẩm quyền hoặc các trường hợp khác phù hợp với quy định của pháp luật.
Nếu bên nhận Dữ Liệu Cá Nhân có trụ sở ngoài lãnh thổ Việt Nam thì khi cung cấp/chuyển Dữ Liệu Cá Nhân ra nước ngoài (bao gồm nhưng không giới hạn ở hoạt động sử dụng không gian mạng, thiết bị, phương tiện điện tử hoặc các hình thức khác để chuyển Dữ Liệu Cá Nhân ra ngoài lãnh thổ Việt Nam), Công Ty sẽ yêu cầu bên tiếp nhận đảm bảo an toàn, bảo mật đối với Dữ Liệu Cá Nhân được cung cấp/chuyển giao. Công Ty cam kết tuân thủ đầy đủ quy định, yêu cầu tuân thủ của pháp luật Việt Nam để bảo vệ an toàn cho Dữ Liệu Cá Nhân.
4.4 Cách thức phân tích
Dữ Liệu Cá Nhân được phân tích dựa trên quy trình nội bộ của Công Ty, nguyên tắc bảo mật dữ liệu và bảo đảm an toàn thông tin đối với hệ thống công nghệ thông tin.
4.5 Cách thức mã hóa
Khi cần thiết, Dữ Liệu Cá Nhân thu thập được mã hóa theo các tiêu chuẩn mã hóa phù hợp trong quá trình lưu trữ hoặc chuyển giao và xử lý dữ liệu để đảm bảo các dữ liệu luôn được bảo vệ.
4.6 Cách thức xóa dữ liệu
Theo quy định của pháp luật hoặc theo yêu cầu hợp lệ từ Chủ Thể Dữ Liệu Cá Nhân, Công Ty sẽ xóa Dữ Liệu Cá Nhân đang được lưu trữ trừ trường hợp sau đây:
4.7 Bảo mật
Trong suốt quá trình Xử Lý Dữ Liệu Cá Nhân, bảo mật là ưu tiên cao nhất của Công Ty. Công Ty có các biện pháp thích hợp về kỹ thuật để ngăn chặn việc truy cập, sử dụng trái phép Dữ Liệu Cá Nhân. Chúng tôi cũng thường xuyên phối hợp với các chuyên gia bảo mật nhằm cập nhật những kỹ thuật mới nhất về an ninh mạng để đảm bảo sự an toàn cho Dữ Liệu Cá Nhân. Các dữ liệu về thẻ thanh toán của Quý vị do các tổ chức tài chính phát hành được Công Ty bảo vệ với nguyên tắc không ghi nhận các dữ liệu quan trọng của thẻ thanh toán (số thẻ, họ tên, số CVV) trên hệ thống của chúng tôi. Giao dịch thanh toán của Quý vị được thực hiện trên hệ thống của ngân hàng liên quan.
Công ty Cổ phần Quốc tế VAIS Việt – Mỹ và Trường Tiểu học, Trung học cơ sở và Trung học phổ thông quốc tế St. Paul
Chính sách này được áp dụng từ ngày 1/7/2023, là Chính sách bảo đảm quyền đối với Thông Tin Riêng Tư được cập nhật theo quy định của pháp luật về bảo vệ Dữ Liệu Cá Nhân. Quyền và nghĩa vụ của Chủ thể Dữ Liệu Cá Nhân được đảm bảo theo quy định pháp luật tương ứng trong từng thời điểm.