1. PURPOSES
In compliance with Decree No. 13/2023/ND-CP of the Government on Personal Data Protection, effective from 01 July 2023, Nam Long Investment Corporation would like to inform Customers the Personal Data Protection Policy (“Policy”). The purpose of this Policy is to outline how the Company protects the Customer’s Personal Data in accordance with the Company’s internal regulations, the provisions of Vietnamese laws on the protection of personal data, and all applicable laws relating to privacy and personal data protection of Vietnam.
2. DEFINITION OF TERMS
2.1. “Data Subject” refers to an individual identified by Personal Data.
2.2. “The Company” or “The Group” or “Nam Long” or “We” refer to the Nam Long Investment Corporation and subsidiaries belonging to the Nam Long Group.
2.3. “Personal Data” refers to electronic information in the form of symbols, letters, numbers, images, sounds, or in a similar form in the electronic environment which is associated with an individual or used to identify an individual. The Personal Data includes Basic Personal Data and Sensitive Personal Data.
2.4. “Basic Personal Data ” includes:
a. Last name, middle name and first name as stated in the birth certificate, other names (if any);
b. Day, month and year of birth; day, month, year of death or missing;
c. Gender;
d. Place of birth, place of birth registration; place of permanent residence; place of temporary residence; current place of residence; hometown; contact address;
e. Nationality;
f. Personal image;
g. Phone number; ID Card number, personal identification number, passport number, driver’s license number, license plate number, taxpayer identification number, social insurance number and health insurance card number;
h. Marital status;
i. Information about the individual’s family relationship (parents, children);
j. Digital account information; personal data that reflects activities and activity history in cyberspace;
k. Other information associated with a specific individual or helping identify a specific individual other than Sensitive Personal Data.
2.5. “Sensitive Personal Data” refers to personal data in association with an individual’s privacy which, when being infringed, shall cause a direct effect on the legitimate rights and interests of such individual, including:
a. Political and religious views;
b. Health status and privacy stated in medical records, excluding information on blood type;
c. Information about racial or ethnic origin;
d. Information related to an individual’s inherited or acquired genetic characteristics;
e. Information about an individual’s physical attributes and biological characteristics;
f. Information about an individual’s sex life or sexual orientation;
g. Data on crimes and criminal acts collected and stored by law enforcement agencies;
h. Information on clients of credit institutions, foreign bank branches, intermediary payment service providers and other licensed institutions, including: information on client identification as prescribed by law, information on accounts, information on deposits, information on deposited assets, information on transactions, information on organizations and individuals that are securing parties at credit institutions, bank branches, and intermediary payment service providers;
i. Personal position identified via positioning services;
j. Other personal data defined as specific by law that requires necessary security measures.
2.6. “Personal Data Processing” or “Data Processing” refers to one or multiple activities that impact on personal data, including collection, recording, analysis, certification, storage, rectification, publicizing, combination, access, retrieval, withdrawal, encryption, decryption, copying, sharing, transmission, provision, transfer, deletion, destruction of Personal Data or other relevant activities.
2.7. “Customer” means an individual who approaches, learns, registers, transacts, uses products and services of the Company, or is involved in the operation and provision of products and services of the Company.
2.8. “Third party” refers to an organization or individual other than the data subject, and the Company authorizes them to process personal data.
2.9. “Personal data controller” means an organization or individual that decides on the purposes and means of personal data processing.
2.10. “Personal data processor” means an organization or individual that carries out data processing on behalf of a data controller under a contract or an agreement with the data controller.
2.11. “Personal data controlling and processing party” means an organization or individual that simultaneously decides on personal data processing purposes and means and directly carries out personal data processing.
2.12. “Data Protection Officer” or “DPO” means one or more individuals designated by the Company to ensure that the Company complies with Privacy Laws. .
3. TYPES OF PERSONAL DATA COLLECTED
3.1. To provide products and services to Customers, and/or handle Customer’s requests, the Company and/or a data processor authorized by the Company may need to and/or be required to collect Personal Data, including: (i) Basic Personal Data and (ii) Sensitive Personal Data, (iii) Data relating to websites or applications and (iv) Marketing Data relating to Customers and individuals related to Customers.
3.2. Personal Data that may be collected and processed include the following information as below and are subject to change from time to time depending on the Data Subject’s relationship with the Company:
3.2.1. Basic Personal Data:
3.2.2. Sensitive Personal Data:
3.2.3. Data related to websites or applications:
a. Technical data (including device type, operating system, browser type, browser settings, IP address, language settings, date and time of connection to the Website, application usage statistics, application settings, date and time of connection to the Application, location data, and other technical communication information);
b. Account name; password; secure login details;
c. Usage data, etc.
3.2.4. Marketing data:
a. Advertising interests;
b. Cookie data;
c. Clickstream data;
d. Browsing history;
e. Responses to direct marketing; and opt-out choices from direct marketing, etc.
4. METHODS OF COLLECTING PERSONAL DATA
The Company and/or data processors authorized by the Company may collect the Data Subject’s Personal Data from the following sources:
4.1. Information provided by the Customer to us: We collect any information that the Customer provides related to our products and/or services through transactions between the Customer and the Company:
a. when the Customer provides information in profiles, transaction documents, or creates an account to use products/services,
b. when participating in surveys and promotional programs for customers;
c. information provided by the Customer through telephone, email, or correspondence between the Customer and the Company.
4.2. Automatic Information: We automatically collect certain types of information when Customers interact with our products and/or services:
a. The Company may collect Personal Data that the Customer declares or makes public when using the Company’s websites, applications, or social media platforms.
b. The Company may automatically collect Personal Data through the use of cookies and other similar technologies whenever the Customer’s web browser views our websites or materials provided by or on behalf of the Company on another website.
4.3. Information from other sources: We may collect information of Customers from other sources, including service providers, partners, and publicly available sources as below. Whenever we collect such personal data, the Company will assume that the relevant third parties have obtained the Customer’s consent for: (i) providing personal data from the third party to the Company; and (ii) processing the data for the Company’s purposes in this Policy. If the Customer does not agree, please do not provide personal data to third parties.
a. Information collected from any publicly available sources or from regulatory agencies;
b. Through footage stored from security cameras at the Company’s offices/customer service centers, or videos of events organized by the Company or units authorized by the Company;
c. From third-party sources where the Customer has agreed that the third party may share/provide the Customer’s Personal Data, or sources where collection is required or permitted by law.
5. DATA PROCESSING
5.1. Data Processing Purposes
The Company collects, processes, and discloses the Customer’s Personal Data within the scope necessary for the Company’s business operations. Specifically, the Customer agrees that their Personal Data may be processed for one or more of the following purposes (collectively referred to as the “Purposes”):
a. Fulfill our contractual obligations and provide services to customers:
i. Serve the company’s production and business activities and provide financial support to customers, including communicating and sending notifications to Customers to answer their questions or handle complaints, and sending information to banks to execute requests for issuing guarantees on future housing; support management and operation tasks after handing over houses and premises;
ii. Manage and maintain the Customer’s digital account(s);
iii. Contact for consultation, service, care, and enhance customer experience; address customer inquiries; provide the latest project information; develop and offer suitable products and services.
b. Communication with Customers:
We use the Customer’s personal information to communicate through various channels (e.g., phone, email, chat, etc.) and to respond to the Customer’s requests:
i. Verify the identity of individuals contacting us via phone, electronic means, or other methods;
ii. Contact the Customer or communicate with the Customer via phone/voice calls, text messages and/or fax messages, emails, and/or postal mail.
The Customer acknowledges and agrees that such communications from us may be carried out by sending letters, documents, or notices to the Customer, which may involve disclosing certain personal data about the Customer to facilitate these communications as well as on the outer cover of the envelope/package.
c. Execution of operational activities:
i. Serve accounting and financial requirements: Customer data is collected, stored, and used for internal business purposes (e.g., record-keeping and compliance with legal and financial obligations). This data will be retained in accordance with current legal regulations;
ii. Comply with the policies, procedures, and operational, audit, administrative, security, and risk management processes of Nam Long, including but not limited to monitoring via security cameras, daily activity logs, personal authentication, storage, and backup of email communications;
iii. Facilitate business asset transactions (which may extend to any buying, merging, or selling of assets) related to any member company of Nam Long;
iv. Data archiving; storing, hosting, backing up (whether for disaster recovery (DR) or other purposes) the Customer’s Personal Data;
v. Internal and external publications;
vi. Protect and enforce the Company’s contractual rights and obligations and legal rights and obligations.
d. Compliance with legal obligations:
In certain circumstances, we have a legal obligation to collect, use, store, or provide your personal information, including but not limited to the following cases:
i. Conducting activities related to anti-money laundering as prescribed by law;
ii. Complying with or adhering to the requirements of any applicable laws, governmental requests, or directives, including fulfilling disclosure requests as required by any laws binding on the Company and/or for the purposes of any guidelines issued by regulatory bodies or other competent authorities that Nam Long or its subsidiaries must comply with; or responding to requests for information from state agencies, ministries, departments as required by law, or other similar agencies. To avoid confusion, this means that we may/will disclose your personal data to the aforementioned parties upon the request or directive of these agencies.
e. Direct marketing:
We may/will use Customer’s personal information to market and promote our products. If you agree to allow the Company to process your Personal Data for the purpose of implementing marketing programs and product introductions, you agree that Nam Long and/or Nam Long’s partners have the rights to market, advertise, and introduce products as follow:
i. Content: Marketing and introducing advertising products of Nam Long and its partners.
ii. Methods: Through advertising messages, notifications on Nam Long’s website, or other methods as prescribed by law.
iii. Form: The Company may/will send you marketing and promotional information and materials related to products and/or services of Nam Long or its partners via email, postal mail, or other communication methods, whether such products or services are currently available or will be developed in the future.
In addition to the above provisions, the Company is responsible for complying with legal regulations on advertising and marketing.
5.2. Methods of processing personal data
Depending on the time and the Purposes, Nam Long and/or data processors authorized by Nam Long may carry out one or more activities affecting Personal Data, such as: collecting, recording, analyzing, verifying, storing, editing, disclosing, combining, accessing, retrieving, recovering, encrypting, decrypting, copying, sharing, transmitting, providing, transferring, deleting, destroying Personal Data, or other related actions.
Personal Data Processing activities may be performed by Nam Long in an automated or non-automated manner, using electronic means, manual methods, or any other methods that Nam Long and/or data processors authorized by Nam Long deem appropriate.
The Company will only store the Customer’s personal data in cases related to the purposes stated in this Policy. The Company may also need to store the customer’s personal data for a period of time, such as when required by applicable laws.
6. CROSS-BORDER TRANSFER OF PERSONAL DATA
The Company may transfer a part or all of the Customer’s Personal Data or data related to the Customer to a location outside the territory of the Socialist Republic of Vietnam or use a location outside the territory of the Socialist Republic of Vietnam for Data Processing. Accordingly, the Company may transfer Personal Data abroad in the following case:
• Customer information may be transferred to third-party service providers who handle information on behalf of the Company, including IT service providers, identity management, hosting and website administration, data analytics, data backup, security, and storage services.
Regarding the transfer of data abroad, the Company will enter into agreements and/or require the individuals or organizations receiving the data to ensure that the personal data is processed carefully in accordance with the requirements outlined in this Policy and relevant legal regulations.
7. PARTIES INVOLVED IN THE PROCESSING OF PERSONAL DATA
7.1. Customer information is a crucial part of the Company’s operations. To carry out the purposes and personal data processing activities under the Personal Data Protection Policy, Nam Long only shares Customer’s personal data with the following parties:
a. For the Company’s operations:
i. Employees and staff of the Company
ii. Subsidiaries/affiliates of Nam Long
b. Transactions involving third parties or third-party service providers:
i. Professional advisors (e.g., auditors, lawyers, etc.) of the Company or Nam Long’s subsidiaries/affiliated companies;
ii. Third-party service providers (such as building management units, providers of telecommunications, information technology, storage, data retention and processing, order processing, transportation, postal and delivery services, website functionality, email and text message monitoring and distribution services, advertising, affiliates and related analytics services, customer support, and call center services, distribution services for the Company or any subsidiary/affiliated company of Nam Long) where sharing/disclosing data to them is necessary for the Company to fulfill its obligations to Customers;
iii. Credit institutions, intermediary payment service providers.
c. Business/Project/Asset Transfer, Restructuring:
i. Any business partner, investor, transferee, or assignee (actual or potential) to facilitate business asset transactions (which may include any purchase, merger, or sale of assets) related to the Company or any subsidiary/affiliated company of Nam Long;
ii. Any party that receives or may receive the transfer of the rights and obligations of the Company or any affiliated company of Nam Long.
In these transactions, personal information, databases, and the right to use information in general are considered business assets being transferred, and the transferee must continue to comply with the provisions of this Policy (or as agreed by the customer).
d. Legal Compliance and Other Obligations:
i. Individuals, competent authorities, regulatory bodies, or third parties to whom Nam Long is permitted or required to disclose information in accordance with legal regulations;
ii. Other parties approved by the Customer or for whom Nam Long has a legal basis to share the Customer’s personal data.
7.2. When sharing the Customer’s personal data with third parties, the Company ensures that these third parties will protect the Customer’s personal data from unauthorized access, collection, use, disclosure, processing, or similar risks, and will only retain the Customer’s personal data for the period necessary to achieve the purposes mentioned above.
7.3. Customers may see advertisements or other content on any websites, applications, or devices that may link to the websites or services of Nam Long’s partners, advertisers, sponsors, or other third parties.
7.4. The Company does not control the content or links that appear on third-party websites or services, and the Company is not responsible for the practices employed by third-party websites or services linked to or from any website, application, or device.
7.5. Those websites and services may be subject to the third parties’ own privacy policies and terms of use.
8. START AND END TIME OF PERSONAL DATA PROCESSING
8.1. Start time of data processing:
We will start processing personal data from the time of receiving personal data.
8.2. End time of data processing:
Until the completion of the Purposes for which the data was collected or until necessary to comply with statutory obligations and to resolve any dispute or until the information provided is requested to be deleted by the Data Subject.
9. RIGHTS AND OBLIGATIONS OF THE DATA SUBJECT
9.1. Rights of the Data Subject
Under the Personal Data Protection regulations, Customers have the following rights:
a. Right to be informed
The Customer has the right to be informed of the processing of the Customer’s Personal Data, unless otherwise provided by law.
b. Right to give consent
The Customer has the right to consent or not to consent to the processing of the Customer’s personal data, except as provided in Article 9 of this Policy.
c. Right to access
• The Customer has the right to access his/her personal data in order to view, modify, or request the modification of his/her personal data, unless otherwise provided by law.
• The Company will modify the Customer’s personal data after obtaining the Customer’s consent as soon as possible, or in accordance with specialized legal regulations. In cases where the data cannot be modified, the Company will notify the Customer within 72 hours upon receiving the Customer’s request of modifying personal data.
d. Right to withdraw consent
• The data subject has the right to withdraw his/her consent, unless otherwise provided by law.
e. Right to delete personal data
i. The Customer has the right to delete or request the deletion of his/her personal data, unless otherwise provided by law.
ii. The Company will delete or destruct the Customer’s personal data within 72 hours when receiving and verifying that the Customer’s request is valid, for the personal data that the Customer requests to restrict, except where otherwise provided by law. In cases where the request cannot be fulfilled, the Company will notify the Customer as soon as possible, along with the reason, upon receiving the Customer’s request.
f. Right to restrict the data processing
i. The Customer has the right to request the restriction of the processing of his/her personal data, unless otherwise provided by law;
ii. The Company will restrict the processing of data within 72 hours upon receiving and verifying that the Customer’s request is valid, for all Personal Data that the Customer requests to restrict, except where otherwise provided by law. In cases where the request cannot be fulfilled, the Company will notify the Customer as soon as possible, along with the reason, upon receiving the Customer’s request.
g. Right to obtain personal data
i. The Customer has the right to request us to provide him/her with his/her Personal Data, unless otherwise provided by law.
ii. The Customer’s request will be processed within 72 hours upon receiving and verifying that the Customer’s request is valid, except where otherwise provided by law. In cases where the request cannot be fulfilled, the Company will notify the Customer as soon as possible, along with the reason, upon receiving the Customer’s request.
h. Right to object to data processing
i. The Customer has the right to object to our processing of his/her Personal Data for the purpose of preventing or restricting the disclosure or use of personal data for advertising or marketing purposes, unless otherwise provided by law.
ii. The Customer’s request will be processed within 72 hours upon receiving and verifying that the Customer’s request is valid, except where otherwise provided by law. In cases where the request cannot be fulfilled, the Company will notify the Customer as soon as possible, along with the reason, upon receiving the Customer’s request
i. Right to file complaints, denunciations and lawsuits
The Customer has the right to file complaints, denunciations and lawsuits as prescribed by law.
j. Right to request compensation for damages
The Customer has the right to request compensation for damages as prescribed by law when there are violations of regulations on protection of his/her Personal Data, unless otherwise agreed by parties or otherwise prescribed by law.
k. Right to self-protection
The Customer has the right to self-protection according to regulations of the Civil Code, other relevant laws, Decree 13/2023/ND-CP, and other provisions of laws, or to request competent agencies and organizations to implement civil right protection methods.
To exercise these rights, the Customer should contact us at the details provided below. The Customer needs to provide proof of his/her identity and state the rights to be exercised for our support.
Except where the Company is permitted to process Personal Data without the Data Subject’s consent in accordance with Decree 13/2023/ND-CP, in the event that the Customer withdraws his/her consent, requests data deletion and/or exercises other relevant rights with respect to any or all of the Customer’s personal data: The acts performed by the Customer in accordance with these regulations may affect Nam Long’s ability to continue to provide its products and services to the Customer, and we reserves all legal rights and remedies of Nam Long in such cases. Accordingly, Nam Long will not be held liable to Customer for any loss incurred and our legal rights will be expressly reserved with respect to limitation, restriction, suspension, cancelation, prevention of the processing of Customer’s data.
9.2. Obligations of the Data Subject
Under the Personal Data Protection regulations, Customers have the following obligations:
a. Protect their own personal data and request organizations or individuals involved to protect their personal data;
b. Respect and protect the personal data of others;
c. Provide complete and accurate personal data when consenting to the processing of their personal data;
d. Participate in promoting and disseminating personal data protection skills; and
e. Comply with the legal regulations on personal data protection and participate in preventing and combating violations of personal data protection regulations.
10. PROCESSING OF PERSONAL DATA WITHOUT THE DATA SUBJECT’S CONSENT
Personal Data may be processed without the consent of the Customer – as the Data Subject – as stipulated by law in the following cases:
a. In an emergency, where it is necessary to immediately process relevant Personal Data to protect the life and health of the Customer or others.
b. The disclosure of Personal Data as required by law.
c. The processing of Personal Data by competent state authorities in cases of emergency related to national defense, national security, public order, social safety, major disasters, or dangerous epidemics; when there is a threat to national security and defense but it has not reached the level of declaring a state of emergency; in the prevention of riots, terrorism, crime prevention, and handling of law violations as prescribed by law.
d. d. To fulfill contractual obligations of the Customer with relevant agencies, organizations, or individuals as stipulated by law.
e. To serve the activities of state agencies as prescribed by specialized laws.
11. PERSONAL DATA PROTECTION
11.1. The Company is committed to processing Customers’ personal data in a safe and secure manner and ensuring Customers’ rights regarding the processing of personal data in accordance with applicable laws.
11.2. The Company will regularly review and update management and technical measures when processing Customers’ personal data.
11.3. Within the scope and capacity of the Company, accessing to Customers’ Personal Data is restricted to those who are in charge. Individuals with access rights to the data are required to maintain confidentiality of that information.
12. UNDESIRABLE CONSEQUENCES AND DAMAGES THAT MAY OCCUR
12.1. While The Company will make every effort to protect Customers’ Personal Data, the transmission and storage of information may still be affected by unauthorized activities of third parties or other objective factors. Specifically, the following unintended consequences and damages may occur, but are not limited to:
a. Hardware or software errors during data processing by the service provider that result in data loss;
b. Security vulnerabilities beyond the Company’s control, where the system is attacked by third parties leading to data leakage;
c. Data breaches by the service provider due to negligence or fraud, accessing websites/ downloading applications containing malware, etc.
12.2. In case of an undesirable event, if an incident or breach of personal data is detected, the Company will notify the relevant parties of the incident/breach within the period prescribed by law. At the same time, the Company will make every effort to remedy the situation, prevent further consequences, and minimize damages to the best of its ability and in accordance with applicable law.
13. CONTACT US
If Customers wish to exercise their rights, have any questions, complaints, or comments about this Personal Data Protection Policy and/or the Company’s processing of their personal data, please contact our Customer Service Center:
Phone number: (028) 54 16 17 18, or 0906 634 886
Email: [email protected]
Address: Nam Long Investment Corporation
06 Nguyễn Khắc Viện, Tân Phú Ward, District 7, Ho Chi Minh City, Vietnam.
14. AMENDMENTS AND SUPPLEMENTS TO THE POLICY
Nam Long reserves the right to amend this Personal Data Protection Policy from time to time if necessary. Any notice of amendments, updates, or adjustments will be posted on Nam Long’s website: https://namlongvn.com/ and/or communicated to the Data Subject through other means that the Company deems appropriate. The Company recommends Customers regularly review this Personal Data Protection Policy to stay informed of any changes and to be aware of how the Company is protecting their personal data.
15. OTHER MATTER
Other matters that are not addressed in this Policy shall be governed by Decree 13/2023/ND-CP, relevant legal regulations, and the internal policies and regulations of the Group
The Customer’s continued use of products, services, or applications is understood to mean that the Customer has read and acknowledged this Personal Data Protection Policy along with any related amendments and supplements.
Effective date: 22/11/2024
Last update: 22/11/2024



