banner-news

Privacy Policy

PERSONAL DATA PROTECTION POLICY

Legal basis:

  1. Law on Personal Data Protection No. 91/2025/QH15 dated June 26, 2025, effective from January 1, 2026.
  2. Decree No. 356/2025/ND-CP detailing a number of articles of and measures for implementation of the Law on Personal Data Protection.
  3. Other relevant legal regulations.

————————————

This PERSONAL DATA PROTECTION POLICY (“Policy”) sets out the rights and obligations of individuals and organizations participating in or relating to personal data processing activities in accordance with law, arising in the course of the operation and business activities of Sunshine Group Joint Stock Company (hereinafter referred to as the “Company”), with Enterprise Registration Number: 0106771556, having its address at 12th Floor, Sunshine Center Building, 16 Pham Hung, Tu Liem Ward, Hanoi City, and official website at: https://sunshinegroup.vn.

ARTICLE 1. GENERAL PROVISIONS

1.1 Definitions

The terms used in this document, unless otherwise defined, shall be defined and construed in accordance with Article 2 of the Law on Personal Data Protection No. 91/2025/QH15 (“Data Protection Law”), specifically as follows:

  1. Personal data means digital data or information in other forms that identifies or helps identify a specific individual, including basic personal data and sensitive personal data. Personal data shall no longer be personal data after anonymization.
  2. Basic personal data means personal data reflecting common identity and background elements, frequently used in transactions and social relations, as listed by the Government.
  3. Sensitive personal data means personal data associated with an individual’s privacy which, when infringed, directly affects the lawful rights and interests of agencies, organizations, and individuals, as listed by the Government.
  4. Personal data protection means the use by agencies, organizations, and individuals of forces, means, and measures to prevent and combat acts infringing personal data.
  5. Personal data subject means the person reflected by the personal data.
  6. Personal data processing means activities impacting personal data, including one or more of the following activities: collection, analysis, aggregation, encryption, decryption, editing, deletion, destruction, anonymization, provision, disclosure, transfer of personal data, and other activities impacting personal data.
  7. Personal data controller means an agency, organization, or individual that decides the purposes and means of processing personal data.
  8. Personal data processor means an agency, organization, or individual that processes personal data at the request of the personal data controller or the personal data controller-cum-processor under a contract.
  9. Personal data controller-cum-processor means an agency, organization, or individual that decides the purposes and means of, and directly processes, personal data.
  10. Third party means an organization or individual other than the personal data subject, personal data controller, personal data controller-cum-processor, or personal data processor, that participates in personal data processing in accordance with law.
  11. Personal data anonymization means the process of altering or removing information to create new data that cannot identify or help identify a specific individual.
  12. Personal data processing impact assessment means the analysis and assessment of risks that may arise during personal data processing in order to apply measures to mitigate risks and protect personal data.

In the event that the contents of the foregoing terms are amended or supplemented by legal regulations, the definitions used in this Policy shall also be immediately, automatically construed, defined, and applied in accordance with the definitions provided under the applicable laws, regardless of whether any update or amendment to this Policy or notice from the Company has been made.

1.3 Statements and disclaimers of the Company

For the purposes of this Policy, the Company hereby declares that:

  1. The Company – in its capacity as a Personal Data Controller or Personal Data Controller-cum-Processor, shall take all actions within its capability to comply with the provisions of the Data Protection Law and other relevant regulations. Accordingly, the Company shall bear no liability in the event personal data is infringed after the Company has taken all actions, measures, and procedures in accordance with law and within the Company’s capability.
  2. Where personal data of individuals related to the personal data subject (including information of dependents, related persons as prescribed by law, spouse, children and/or parents and/or guardians, friends, beneficiaries, authorized persons, partners, emergency contacts, or other related individuals of the personal data subject) is provided by the personal data subject to the Company together with such subject’s own personal data, then:
    • The person providing such personal data to the Company in accordance with law shall be deemed the Personal Data Controller, and such person shall be responsible for complying with relevant legal regulations and for having completed the obtaining of consent/approval for provision of such personal data to the Company in the form/manner prescribed by law for the purposes set out in this Policy; and
    • Accordingly, the Company shall have no obligation to verify and/or be liable for the legality or validity of such consent/approval and shall have no obligation to retain evidentiary proof thereof. The Company shall be fully exempt from all legal liabilities arising therefrom (if any) and shall have the right to claim compensation for related losses and costs where the personal data subject and/or related persons of the personal data subject fail to comply with the legal requirements.
  3. Where standards, technical regulations, or provisions of Vietnamese law are mandatorily applicable to the processing or anonymization of personal data but have not yet been promulgated and come into effect, the Company shall have the right to refer to existing Vietnamese standards/regulations or similar foreign standards/regulations in order to select and promulgate a temporary standard/regulation applicable to the Company’s personal data processing on the basis of its maximum capability and maximum compliance with law. In such case, Our Customers (as defined below) shall not use the absence of such legal provisions, standards, or regulations as a ground to object to the Company’s personal data processing, and the Company shall be fully exempt from all related legal liabilities in such case.
  4. This Policy may be updated, amended, or supplemented by the Company from time to time to ensure compliance with law and shall be published on the Company’s official website. Our Customers, Our Partners, and Our Employees (hereinafter collectively referred to as “Our Customers”) are recommended to access and review the website regularly for the latest updates. Where such amendments or supplements to the Policy are solely for compliance with and reflection of applicable laws, the fact that Our Customers are not notified of or are unaware of such update, amendment, or supplement shall not be a ground for exemption from compliance with this Policy.

ARTICLE 2. PERSONAL DATA TO BE PROCESSED

The personal data processed by the Company includes Basic Personal Data and Sensitive Personal Data as prescribed in Article 3 and Article 4 of Decree No. 356/2025/ND-CP detailing a number of articles of and measures for implementation of the Law on Personal Data Protection (“Decree 365”), specifically as follows:

Article 3. List of basic personal data

Basic personal data includes:

  1. Full birth name, middle name(s), given name, and other name(s) (if any);
  2. Date, month, and year of birth; date, month, and year of death or disappearance;
  3. Gender;
  4. Place of birth, place of birth registration, place of permanent residence registration, place of temporary residence registration, current place of residence, hometown, contact address;
  5. Nationality;
  6. Image of the individual;
  7. Telephone number, personal identification number, passport number, driver’s license number, vehicle license plate number;
  8. Marital status;
  9. Information on family relationships (parents, children, wife, husband);
  10. Information on the individual’s digital accounts;
  11. Other information associated with or helping identify a specific person that does not fall under Article 4 of this Decree.”

Article 4. List of sensitive personal data

  1. Sensitive personal data includes:
    1. Data disclosing racial origin or ethnic origin;
    2. Political, religious, or belief-related views;
    3. Information relating to private life, personal secrets, family secrets;
    4. Health status;
    5. Biometric data, genetic characteristics;
    6. Data disclosing an individual’s sex life or sexual orientation;
    7. Data on crimes and legal violations collected and stored by law enforcement agencies;
    8. An individual’s location determined through positioning services;
    9. Username and password for access to an individual’s electronic identification account; images of identity cards, citizen identity cards, identity documents;
    10. Usernames and passwords for access to bank accounts; bank card information; data on bank account transaction history; financial and credit information and information on customers’ financial, securities, and insurance activities and transaction history at credit institutions, foreign bank branches, payment intermediary service providers, securities institutions, insurance institutions, and other licensed organizations;
    11. Data monitoring behavior and usage activities of telecommunications services, social networks, online communication services, and other services in cyberspace;
    12. Other personal data required by law to be kept confidential or subject to strict security measures.”

In the event that the scope of the aforesaid personal data is amended or supplemented by legal regulations, the scope applicable under this Policy shall also be immediately, automatically construed, defined, and applied in accordance with the scope provided under applicable laws without having to wait for any update or amendment to this Policy or notice from the Company, whether such update or notice exists or not.

ARTICLE 3. PURPOSES OF PERSONAL DATA PROCESSING

Within the scope of the Company’s operations, based on the consent of Our Customers in accordance with law, personal data may be processed for one or more of the following purposes:

3.1 For entering into and performing contracts and transactions between the Company and Our Customers

  1. Completing personal information required in contract forms in accordance with law or agreement of the parties;
  2. Identifying and verifying information of the personal data subject; assessing, appraising, and approving the provision of products and services under registration documents, application forms, and contracts of the personal data subject and/or related persons of the personal data subject;
  3. Considering the provision or continued provision of any products or services of the Company to the personal data subject;
  4. Performing obligations under contracts and agreements and providing products and services to the personal data subject;
  5. Updating and processing information of the personal data subject;
  6. Providing care for, settling complaints and disputes of the personal data subject;
  7. Using and transferring personal data and relevant information to partners to identify and remedy incidents of products and services; repairing products on the basis of ensuring personal data protection in accordance with law;
  8. Contacting, communicating, and notifying the personal data subject;
  9. Implementing promotional programs, gift redemption, prize awarding, gift delivery, and other similar programs;
  10. Carrying out other customer care and support activities.

3.2 For research and improvement of the quality of the Company’s products and services

  1. Providing information requested by customers or that the Company considers useful to customers;
  2. Improving technology, interfaces of websites, social networks, and applications to ensure convenience for customers;
  3. Managing customer accounts and customer loyalty programs implemented by the Company/other companies within the Sunshine Group ecosystem;
  4. Compiling statistics and analyzing data for research, development, improvement, and enhancement of products and services; improving customer experience;
  5. Developing and providing new products and services personalized to customers’ needs and actual conditions;
  6. Introducing and providing promotional programs and incentives for products and services of the Company and of collaborations between the Company and its partners;
  7. Recommending products and services that customers may be interested in through recognition of customer preferences.

3.4 Serving the Company’s business and operational activities

Performing reporting, financial, accounting, and tax obligations, audit and compliance-related activities, and other activities serving the Company’s lawful business activities in cases deemed necessary by the Company.

3.5 Restructuring, transfer of projects/businesses

In the course of business, the Company may sell or acquire businesses, restructure businesses, or transfer projects or other services in accordance with law. Accordingly, personal data and rights to use information in general are among the assets transferred. In all cases, such data transfer and processing shall be carried out by the parties in accordance with law and this Policy.

3.6 Marketing and promotion

Developing marketing and promotional campaigns for products and services, including campaigns based on customer preferences;

3.7 Compliance with other legal regulations

  1. Preventing, combating, deterring, investigating, and detecting crimes; protecting social order and safety; and protecting the lawful rights and interests of the personal data subject, the Company, and other relevant parties.
  2. Complying with legal regulations and international treaties to which Vietnam is a member.

3.8 Other purposes if consented to by the personal data subject from time to time.

ARTICLE 4. METHODS OF PERSONAL DATA PROCESSING

4.1 Methods of collecting personal data

For the purposes of personal data processing set out in this Policy, personal data may be collected by one or more of the following methods:

  1. From the Company’s websites and applications 

    Personal data is collected when the personal data subject fills in forms made available on the Company’s websites and applications.

  2. From the provision of products and services and performance of obligations under contracts and agreements of the Company

    Personal data is collected when the personal data subject purchases, registers for, uses any products or services, or enters into contracts with the Company.

  3. From exchanges and communications with the personal data subject

    Personal data is collected through interactions between the Company and the personal data subject (in person, by mail, telephone, online, call center system, electronic communications, or any other means), including surveys.

  4. From social media

    Personal data is collected through the Company’s social media channels and/or social media channels used by the Company or in cooperation with partners.

  5. From audio and video recording devices: 

    Personal data is collected through audio and video recording devices installed at stores, business locations, or places where part or all of the Company’s business activities are carried out and where the personal data subject encounters, appears, or interacts with the Company.

  6. From interactions or automated data collection technologies

    Personal data may be collected by the Company through Cookies, pixel tags, and other similar technologies; or any technology capable of tracking personal activities on devices or websites;

  7. Data information from other sources

    The Company may collect personal data through public and official information sources or through receiving necessary data shared by parent companies, subsidiaries, affiliates, or partners in the course of cooperation with the Company in accordance with law.

4.2 Methods of storing personal data

Personal data shall be stored in Vietnam in the Company’s database systems or anywhere the Company or its branches, subsidiaries, affiliates, partners, or service providers maintain facilities.

The retention period of personal data shall be determined based on the purposes of use as set out in this Policy and in accordance with law.

4.3 Methods of transferring/sharing personal data

The Company will not sell personal data to any party. The Company uses necessary security measures to ensure safe transfer/sharing of personal data. Personal data may be shared by the Company with (i) the Company’s parent company, subsidiaries, and affiliates; (ii) individuals/organizations participating in the personal data processing set out in this Policy; or (iii) competent state authorities or in other cases in accordance with law.

4.4 Methods of analysis

Personal data is analyzed based on the Company’s internal procedures, data confidentiality principles, and information security assurance for information technology systems.

4.5  Methods of encryption

Where necessary, collected personal data shall be encrypted in accordance with appropriate encryption standards during storage, transfer, and data processing to ensure that such data is always protected.

4.6 Methods of data deletion

In accordance with law or upon a valid request from the personal data subject, the Company shall delete stored personal data except in the following cases:

  1. Where law does not permit deletion of data or mandates data retention;
  2. Where personal data is processed by competent state authorities for the purpose of serving activities of state authorities in accordance with law;
  3. Where personal data has been disclosed in accordance with law;
  4. Where personal data is processed for legal claims, scientific research, or statistical purposes in accordance with law;
  5. In cases of emergency relating to national defense, national security, social order and safety, major disasters, dangerous epidemics; where there is a threat to security or national defense short of declaration of a state of emergency; prevention and combat of riots, terrorism, crimes, and legal violations;
  6. Responding to emergency situations threatening the life, health, or safety of the personal data subject or other individuals.

ARTICLE 5. PROCESSING OF CHILDREN’S PERSONAL DATA

5.1. The Company shall process children’s personal data in accordance with the principle of protecting children’s rights and in the best interests of children, and in compliance with laws on personal data protection.

5.2. The Company shall only process children’s personal data to the extent necessary for:

    1. Protecting the lawful and legitimate rights and interests of children;
    2. Complying with requests of competent state authorities;
    3. Providing, maintaining, or improving products and services appropriate for children (if any);
    4. Other purposes set out in Article 3 of this Policy.

For clarity, the processing of children’s personal data in all circumstances is not for the purpose of publishing or disclosing information relating to children’s private life or personal secrets.

5.3. The Company shall only process children’s personal data and provide products and services to children if the father, mother, or lawful guardian agrees to allow the child to use the Company’s products and services, consents to the Company’s processing of the child’s personal data, agrees to this Policy, and complies with relevant legal requirements.

5.4. The Company shall cease processing children’s personal data in the following cases:

  1. The person who provided valid consent withdraws consent to the processing of personal data, unless otherwise provided by law;
  2. At the request of competent state authorities where there are grounds proving that the processing of personal data is likely to infringe the lawful rights and interests of children, unless otherwise provided by law.

5.5 The Company shall apply appropriate technical, administrative, and organizational measures to protect children’s personal data against unauthorized access, collection, use, disclosure, modification, or destruction.

ARTICLE 6. PROCESSING OF PERSONAL DATA IN RECRUITMENT, MANAGEMENT, AND USE OF EMPLOYEES

  • The Company undertakes to protect and only process personal data of applicants and employees in accordance with the Data Protection Law, labor laws, employment laws, and other relevant legal regulations. The Company shall only collect and process personal data to the extent necessary and appropriate for recruitment, management, and use of employees, on the basis that applicants and/or employees have been fully informed and have validly consented, unless otherwise provided by law.
  • The collected personal data shall only be used for the above purposes or other purposes consented to by the data subject, and shall be retained for the period prescribed by law or under lawful agreement. The Company shall delete and destroy personal data of applicants in the event of non-recruitment, and delete and destroy personal data of employees upon termination of the employment relationship, unless otherwise provided by law or otherwise agreed by the parties in accordance with law.
  • Where the Company applies technological or technical measures for employee management purposes, such measures shall be implemented in accordance with law, ensuring the lawful rights and interests of the data subject, on the basis that the employee has been informed and is fully aware thereof; the Company shall not process or use personal data collected through measures contrary to law.

ARTICLE 7. PROCESSING OF PERSONAL DATA ON SOCIAL NETWORKING PLATFORMS AND ONLINE COMMUNICATION SERVICES

  • Where the Company provides or operates social networking platforms, online communication services, or interactive online features, the Company undertakes to protect and only process users’ personal data in accordance with the Data Protection Law and relevant legal regulations.
  • The Company shall clearly inform users of the types of personal data collected when users install, register for, and use the service; collection and processing of personal data shall only be carried out to the extent necessary and appropriate for the purpose of providing services to users and other purposes that have been notified and agreed upon with users, and shall not collect personal data unlawfully or beyond such scope. The Company does not require users to provide images or videos containing all or part of identity documents as an account authentication factor, unless otherwise provided by law.
  • The Company provides users with options related to privacy, including the right to refuse or manage the collection and sharing of data through cookies, the right to refuse tracking or only permit tracking of service usage activities with the user’s consent, as well as appropriate privacy setting tools.
  • The Company shall not engage in eavesdropping, call recording, reading text messages, or other forms of monitoring the content of users’ communications without the valid consent of the data subject, unless otherwise provided by law.

ARTICLE 8. PROCESSING OF PERSONAL DATA RELATING TO PERSONAL LOCATION DATA AND BIOMETRIC DATA

  • Where the Company collects and processes users’ personal location data or biometric data, the Company undertakes to protect and process such personal data in accordance with laws on personal data protection and relevant legal regulations.
  • Personal location data shall only be collected and used with the valid consent of the data subject, at the request of competent state authorities, or in other cases as prescribed by law. For platforms and mobile applications provided or operated by the Company, the Company shall clearly inform users of the use of personal location data, apply necessary measures to prevent collection of personal location data by unrelated parties, and provide users with options to permit, restrict, or refuse tracking of personal location in accordance with law. The Company does not apply tracking via radio frequency identification cards or other technologies, unless consented to by the data subject or required by competent authorities in accordance with law or otherwise provided by law.
  • With respect to biometric data, the Company shall only collect and process such data to the extent necessary and appropriate for the notified purposes, and shall apply appropriate physical, technical, and administrative security measures to protect biometric data, including access control, monitoring, and prevention of unauthorized access and use, and compliance with relevant legal, technical, and international standards and practices. Where the processing of biometric data causes damage to the data subject, the Company shall notify the data subject in accordance with law.

ARTICLE 9. PROCESSING OF PERSONAL DATA OBTAINED FROM AUDIO AND VIDEO RECORDING ACTIVITIES IN PUBLIC PLACES AND PUBLIC ACTIVITIES

  • Where the Company conducts audio and video recording activities in public places or public activities, the collection and processing of personal data arising from such activities shall be carried out in accordance with the Data Protection Law and relevant legal regulations.
  • The Company may conduct audio and video recording in public places or public activities without separate consent of the data subject in cases permitted by law, including for the purposes of ensuring security, order, and social safety, protecting the lawful rights and interests of the Company or relevant parties, or in respect of audio, images, and other identifying information obtained from public activities such as conferences, seminars, events, sports competitions, artistic performances, and other public activities, provided that such recording does not harm the honor, dignity, or reputation of the data subject, unless otherwise provided by law.
  • In the above recording cases, the Company shall provide notice in an appropriate form so that the data subject is aware that audio and/or video recording is taking place, unless otherwise provided by law.
  • Personal data obtained from audio and video recording activities shall only be processed and used in accordance with the identified purposes, shall not be used for unlawful purposes or purposes infringing the lawful rights and interests of the data subject, and shall only be retained for the period necessary to serve the purpose of collection. Upon expiry of the retention period, the personal data shall be deleted and destroyed in accordance with law.
  • The Company shall apply necessary measures to protect personal data obtained from audio and video recording activities in accordance with the Data Protection Law and relevant legal regulations.

ARTICLE 10. POSSIBLE UNINTENDED CONSEQUENCES AND DAMAGE

10.1 The Company undertakes to use various information security technologies such as firewalls, access control measures, encryption, etc. to make its best efforts to protect and prevent unauthorized access to, use of, or sharing of personal data. However, in certain situations beyond the Company’s control (such as unlawful hacking causing data leakage, technical failures of telecommunications network providers, or force majeure events), absolute security of personal data cannot be guaranteed and may lead to the following consequences:

  1. Data loss due to hardware or software errors during data processing;
  2. Data leakage or disclosure due to security vulnerabilities beyond the Company’s control, including hacking attacks causing data leakage or disclosure.
  3. Lost/disclosed data may be used for fraudulent or deceptive acts, or cause financial loss to the personal data subject. In addition, disclosure of sensitive information may adversely affect the personal data subject’s reputation, personal life, or work.

10.2 The Company recommends

  1. That personal data subjects keep confidential information relating to account login passwords and OTP codes and not share such content with any other person.
  2. That personal data subjects understand clearly that at any time when they disclose and make public their personal data, such data may be collected and used by others for purposes beyond the control of the personal data subject and the Company.
  3. The Company recommends that personal data subjects safeguard their personal devices (mobile phones, tablets, personal computers, etc.) during use. Personal data subjects should log out of their accounts when not in use.
  4. When transmitting personal data over cyberspace, personal data subjects should only use secure systems to access websites, applications, or devices. Personal data subjects are responsible for keeping their access authentication information for each website, application, or device safe and confidential.

10.3 Responsibilities of the Company in the event of unintended consequences and damage

To the extent permitted by law, the Company undertakes to perform the following responsibilities to mitigate risks and protect the rights and interests of personal data subjects:

  1. Proactive response and remediation: Immediately upon detecting an incident related to loss or leakage of personal data, the Company shall promptly implement necessary technical and organizational measures to prevent and remedy the consequences, minimize damage to the greatest extent possible, and notify the personal data subject in accordance with law.
  2. Cooperation with competent authorities: The Company shall closely cooperate with competent authorities to investigate and handle incidents and fulfill reporting obligations in accordance with law.
  3. Remedy of damage: Where actual damage arises due to the Company’s fault, the Company shall consider performing responsibilities toward the personal data subject in accordance with applicable law.
  4. Review and improvement: After each incident, the Company shall assess the causes, review systems, and update security measures to prevent similar incidents in the future. 

ARTICLE 11. COMMENCEMENT TIME AND TERMINATION TIME OF PERSONAL DATA PROCESSING

11.1 Personal data shall be processed from the time the Company lawfully receives the personal data and has appropriate legal grounds to process such data in accordance with law.

11.2 Personal data shall be processed until the purposes of processing have been fulfilled or as otherwise prescribed by law.

11.3 The Company shall retain personal data for the period prescribed by law and/or required by competent state authorities.

ARTICLE 12. ORGANIZATIONS AND INDIVIDUALS PARTICIPATING IN THE PERSONAL DATA PROCESSING PROCESS AND SCOPE OF USE OF PERSONAL DATA

12.1 Depending on the case, the Company may act as a Personal Data Controller or a Personal Data Controller-cum-Processor.

12.2 To the extent permitted by law, personal data may be transferred or shared for the purposes stated in this Policy with:

  1. Parties participating in the Company’s personal data processing;
  2. Competent state authorities and law enforcement authorities;
  3. Other subjects in accordance with law.

12.3 The personal data subject understands clearly that the following parties may participate in personal data processing:

  1. Branches, representative offices, business locations, or other organizational forms (if any) of the Company;
  2. The Company’s parent company, subsidiaries, and affiliates;
  3. Organizations and individuals providing services to and/or cooperating with the Company, including agents, auditors, lawyers, business cooperation partners, providers of information technology solutions, software, applications, operational services, management services, incident handling services, and infrastructure development services;
  4. Any individual or organization acting as representative or authorized person of the personal data subject, acting on behalf of the personal data subject;

12.4 The sharing of personal data shall be carried out in accordance with the order, methods, and applicable legal regulations. Recipients of personal data are obliged to keep such personal data confidential in accordance with this Policy, the Company’s internal regulations, standards on personal data protection, and applicable laws.

ARTICLE 13. RIGHTS OF PERSONAL DATA SUBJECTS

Unless otherwise provided by law, personal data subjects have the following rights:

13.1 The right to be informed of the processing of their personal data, unless otherwise provided by law.

13.2 The right to consent or refuse consent, and to request withdrawal of consent to the processing of their personal data, unless otherwise provided by law.

13.3 The right to view, edit, or request correction of their personal data, unless otherwise provided by law; and to submit requests objecting to the processing of personal data;

13.4 The right to request provision, deletion, or restriction of personal data processing; and to submit requests objecting to the processing of personal data;

13.5 The right to complain, denounce, initiate lawsuits, and request compensation for damages in accordance with law;

13.6 The right to request competent authorities or agencies, organizations, or individuals involved in personal data processing to implement measures and solutions to protect their personal data in accordance with law.

Personal data subjects may exercise these rights in forms consistent with law. Where coordination from the Company is required, personal data subjects may exercise their rights by submitting a request form to the Company. The request form must be sent to the Company and contain basic contents such as the requester’s information, detailed request content [for example, the type of data to be provided or deleted, name of document, file (if any)], reasons and purposes for making the request, and other relevant information depending on the nature of the request (for example, whether the requested documents should be provided in file or paper form, address for receipt of documents, etc.). Any costs (if any) arising from the implementation of the requests stated herein, including printing, copying, postage, and courier charges for sending data, shall be borne by the requester and must be paid no later than upon receipt of the data or within a time limit specified by the Company.

The Company shall process requests of personal data subjects in accordance with law and taking into account the legitimate interests of personal data subjects. However, where a personal data subject withdraws consent, requests deletion of data, and/or exercises other related rights in relation to any or all personal data affecting (1) the ability of the Company to provide/maintain relevant products and services to such personal data subject or (2) the performance of a contract between the Company and the personal data subject, depending on the extent of the impact, the Company may consider and decide not to continue providing relevant products and services to the personal data subject or to terminate the contractual relationship between the Company and the personal data subject. Acts performed by the personal data subject under this provision shall be deemed unilateral termination by the personal data subject of any relationship with the Company and may entirely result in breach of obligations or commitments under contracts between the personal data subject and the Company, and the Company reserves its lawful rights and remedies in such cases. Accordingly, the Company shall not be liable to the personal data subject for any arising losses, and the Company’s lawful rights shall be fully reserved. Using reasonable efforts, the Company shall comply with lawful and valid requests from personal data subjects within a time period consistent with law. However, for security purposes, the Company may require personal data subjects to verify their identity before processing their requests.

Where it is not possible to fulfill a request regarding a personal data subject’s personal data for legitimate reasons, the Company shall notify the personal data subject accordingly.

The Company has the right to refuse to fulfill requests of personal data subjects in certain cases, including where: (i) the personal data subject fails to follow the order and procedures instructed by the Company, including where the request lacks information or is invalid; (ii) the personal data subject fails to provide or provides incomplete documents and materials for identity verification; or (iii) where the Company assesses that there are signs of fraud or violations relating to personal data protection; or (iv) where law does not permit fulfillment of the request of the personal data subject.

ARTICLE 14. OBLIGATIONS OF PERSONAL DATA SUBJECTS

14.1 To protect their own personal data; request relevant organizations and individuals to protect their personal data. To promptly notify the Company upon detecting errors, mistakes, or leakage of personal data, or upon suspicion that personal data is being infringed.

14.2 To respect and protect the personal data of others.

14.3 To provide complete and accurate personal data in accordance with law, under contracts/agreements with the Company, or when consenting to personal data processing. If any information is inaccurate, the personal data subject shall bear the costs thereof in case such information affects or limits the rights and interests of the personal data subject.

14.4 To comply with legal regulations on personal data protection and participate in preventing and combating acts infringing personal data and violating regulations on personal data protection.

14.5 Other responsibilities as prescribed by law.

If you have any questions regarding the Company’s personal data protection, please contact us and we will endeavor to respond to your questions as soon as possible. You may also contact us via email at info@sunshinegroup.vn