Article 1. Introduction to the Policy
KALAPA Joint Stock Company (the "Company" or "We") provides a digital onboarding and identity verification platform for financial institutions in Vietnam.
In compliance with applicable law, this Privacy Policy (the "Policy") is developed to provide Customers with transparent information about the Company's processing procedures and the measures applied to protect Personal Data ("PD").
This Policy applies to all Customers who access the website at: https://kalapa.vn (the "Website").
By performing a Consent Action as set out in Article 3 of this Policy, the Customer is deemed to confirm that the Company has fully notified the Customer of its Personal Data processing practices before the Customer provided such data, and that the Customer consents to the Company processing the Personal Data of the data subject. The provision of Personal Data to the Company is entirely voluntary and free from deception, threat, or coercion by the Company or any third party.
The Company respects the Customer's privacy and undertakes to process PD only after obtaining the Customer's voluntary and clear consent, in accordance with this Policy.
Article 2. Definitions
Personal Data: Digital data or information in other forms that identifies or helps identify a specific individual, including basic personal data and sensitive personal data. For clarity, personal data that has been de-identified is no longer considered personal data.
Basic Personal Data: Personal data reflecting common identity and background details that are regularly used in transactions and social relationships, including:
- a) Full name (family name, middle name and given name at birth) and other names (if any);
- b) Date, month and year of birth; date, month and year of death or disappearance;
- c) Gender;
- d) Place of birth, place of birth registration, permanent residence, temporary residence, current address, hometown, and contact address;
- e) Nationality;
- f) Personal images;
- g) Phone number, ID card number, personal identification number, passport number, driving licence number, vehicle registration plate number, personal tax code, social insurance number, health insurance card number;
- h) Marital status;
- i) Information on family relationships (parents, children);
- j) Information on an individual's digital accounts; personal data reflecting online activities and activity history in cyberspace;
- k) Other information associated with, or used to identify, a specific individual as provided by law, other than the data listed in clause 3 of this Article.
Sensitive Personal Data: Personal data linked to an individual's privacy which, if infringed, would directly affect that individual's lawful rights and interests, including:
- a) Login usernames and passwords for an individual's electronic identification account; images of ID cards, citizen identity cards, or identity cards;
- b) Political and religious views;
- c) Health status and personal details recorded in medical records, excluding blood type information;
- d) Information relating to racial or ethnic origin;
- e) Biometric data and information on inherited or acquired genetic characteristics of the individual;
- f) Information on physical attributes and unique biological characteristics of the individual;
- g) Data on crimes and criminal acts collected and stored by law enforcement agencies;
- h) Customer information held by credit institutions, foreign bank branches, payment intermediary service providers, and other licensed organisations, including: customer identification information as prescribed by law, account information, deposit information, information on assets deposited, transaction information, and information on organisations or individuals acting as guarantors at credit institutions, bank branches, or payment intermediary service providers;
- i) An individual's location data as determined through positioning services;
- j) Data tracking an individual's behaviour and activity in the use of telecommunications, social network, online media, and other services in cyberspace.
Personal Data Protection: The activities of preventing, detecting, deterring, and handling violations relating to personal data in accordance with law.
Data Subject: The individual reflected by the personal data. A Data Subject is also a Customer as defined in clause 6 of this Article.
Customer: An individual who voluntarily provides personal information through the consultation/product-demo registration form on the Company's Website in order to request consultation or a demonstration of the Company's products or services. Where the Customer acts as a representative or employee of an organisation or enterprise, the personal information collected still belongs to that individual, who remains the holder of the rights set out in this Policy.
Personal Data Processing: One or more activities affecting personal data, such as: collecting, recording, analysing, confirming, storing, editing, disclosing, combining, accessing, retrieving, recalling, encrypting, decrypting, copying, sharing, transmitting, providing, transferring, deleting, or destroying personal data, or other related actions.
Consent of the Data Subject: A clear, voluntary, and affirmative expression by the data subject of their agreement to allow the processing of their personal data.
Personal Data Controller: An organisation or individual that determines the purposes and means of processing personal data.
Personal Data Processor: An organisation or individual that processes data on behalf of a Personal Data Controller, under a contract or agreement with that Personal Data Controller.
Personal Data Controller and Processor: An organisation or individual that both determines the purposes and means of, and directly carries out, the processing of personal data.
Third Party: An organisation or individual, other than the Data Subject, the Personal Data Controller, the Personal Data Processor, or the Personal Data Controller and Processor, that is permitted to process personal data.
Personal Data Protection Regulations: The Law on Personal Data Protection No. 91/2025/QH15, dated 26 June 2025, together with any amending, supplementing, or replacing legal instruments issued from time to time.
Article 3. Consent Action
Before providing personal data to use the features on the Website, the Customer must carefully read and agree to the entire content of this Policy (including any amended, supplemented, or updated versions from time to time).
The Customer's consent is recorded electronically upon performing one or more of the following acts (the "Consent Action"):
- a) Ticking the box "I agree…";
- b) Clicking the "Agree", "Continue", or other equivalent buttons on the interactive screen;
- c) Entering a one-time password (OTP) to confirm consent; and/or proactively providing PD to the Company via the Website.
By performing the Consent Action, the Customer is deemed to have read, fully understood, and agreed to all of the provisions on personal data processing set out in this Policy.
If the Customer does not agree with any provision of this Policy, the Customer should refrain from performing the Consent Action, and should stop accessing and discontinue using the actions and services provided by the Company.
Article 4. Categories of PD Collected, Processing Methods, and Purposes of Processing
The Company collects the Customer's PD as set out below; the categories of PD collected, the collection methods, and the purposes of processing are listed in the following table:
| Category of PD | Type of PD | PD Collection Method | Purpose of PD Processing |
|---|---|---|---|
| Basic PD | Full name (family name, middle name and given name at birth) | PD provided directly by the Customer when registering for a product demo on the Website | Contacting the Customer to confirm a demo schedule suited to their industry and specific use case |
| Phone number | |||
| Other information associated with, or used to identify, a specific individual as provided by law, other than the data listed in clause 3 of this Article. | |||
| Sensitive PD (if any) |
The Company undertakes to keep the Customer's PD confidential and to use it only for the purposes set out in this Policy. Where the Company processes PD for another purpose, the Company will notify the Customer before such processing in order to obtain the Customer's "Consent".
The Customer is responsible for ensuring that all PD provided to the Company is complete, accurate, truthful, and lawfully owned or used by the Customer.
The Customer undertakes to fully indemnify the Company against any dispute, damage, or loss arising from the use of inaccurate or unlawful information provided by the Customer.
Article 5. Sharing of the Customer's PD
To the extent permitted by law, the Company undertakes not to provide, share, or transfer the Customer's PD to any third party, except where necessary to achieve the processing purposes set out in Articles 4 and 5 of this Policy. Accordingly, the Customer agrees that its PD may be shared or transferred to the following recipients in their respective legal capacities:
| No. | Data Recipient (Partner/Third Party) | Legal Capacity regarding PD | Type of PD Shared | Purpose of Sharing |
|---|---|---|---|---|
| 1 | Automated messaging/calling service providers | PD Processor (processes only as instructed and under its service contract with the Company) | User PD (full name, phone number) | Sending one-time passwords (OTP); sending notifications or reminder calls for appointments (if any) |
| 2 | Cloud computing solution/platform providers (Cloud Services Provider) | PD Processor (provides technical storage infrastructure only) | All PD collected | Securely storing data on digital infrastructure and ensuring system availability |
| 3 | The Company's official employees, collaborators, branches, and affiliated units | Internal to the PD Controller (the Company), or acting jointly as PD Controller and Processor | All or part of the PD, on a least-privilege basis | Operating the system and performing obligations and entitlements under the agreement between the Customer and the Company |
| 4 | Law enforcement agencies, competent State management authorities, or parties involved in litigation | Independent data recipient and processor (processing under statutory authority) | All or part of the PD, upon official written request | Complying with legal obligations, litigation decisions, or mandatory requirements of Vietnamese law |
The Company undertakes to keep the Customer's PD confidential in accordance with applicable law and this Policy. PD is shared with Third Parties only to the minimum extent necessary to achieve the agreed processing purposes.
The Company applies mandatory legal and technical binding measures to ensure that data recipients bear strict confidentiality obligations and do not use the information for any purpose other than as agreed.
Article 6. Data Storage
The Customer's personal data is securely stored on dedicated hardware devices and on the cloud computing infrastructure of reputable storage-solution partners, with data centers located within Vietnam's domestic infrastructure, meeting all cybersecurity standards required by law.
Data retention period: The Company stores and processes the Customer's PD from the time of collection until the processing purposes have been fulfilled, or until it receives a lawful request from the Customer or a competent State authority to delete or destroy the data.
Storage limitations and exceptions: To ensure transparency and manage legal risk, the Customer acknowledges and agrees that, where the Customer proactively requests the deletion or destruction of data, the Company retains the right and obligation to keep part or all of the Customer's PD under the following conditions:
- a) To serve the Company's legitimate and essential business purposes (including financial reconciliation, and resolving complaints or disputes); and/or
- b) To comply with mandatory legal requirements on the retention of specialised records and documents (such as accounting, tax, audit, or anti-money-laundering records) which, under Vietnamese law, may not be deleted before the prescribed retention period.
Article 7. Information Security
To the extent reasonably possible, the Company always strives to keep PD secure by implementing a range of safeguards, including:
- Encryption of stored data: AES-256; data in transit: TLS 1.3;
- Role-based access control (RBAC) and multi-factor authentication for all employees;
- 24/7 intrusion monitoring and detection (SOC);
- Periodic security testing (penetration testing, VAPT);
- Production environments fully isolated from development/testing environments;
- Other statutory standards for the protection of PD.
- ISO/IEC 27001:2022 certification for Information Security Management Systems;
- Mandatory annual security training for all employees;
- Assurance of security within the operating environment;
- A Security Incident Response Plan;
- Other statutory standards for the protection of PD.
The Company applies technical, physical, managerial, and organisational measures consistent with commercial standards and legal requirements to protect the Customer's PD, in order to prevent risks of misuse, loss, alteration, disclosure, or unauthorised access.
The Customer acknowledges and agrees that the Company is exempt from all legal liability and compensation obligations for any leak, loss, or unauthorised access to PD arising from causes beyond the Company's reasonable control, including but not limited to:
- a) Force majeure events: natural disasters (storms, floods, earthquakes), fire, war, riots, … or large-scale cyber-attacks that exceed the defensive capability of the security technology in place at the time of the incident;
- b) National infrastructure incidents: submarine cable breaks, widespread Internet connectivity failures, telecommunications network disruptions, or national power-grid failures caused by third-party infrastructure providers;
- c) Faults on the Customer's part: the Customer's device becoming infected with malware or a virus.
Incident response procedure: If the Company detects that its storage system has been attacked, or that an incident has occurred which risks the loss or leakage of the Customer's PD, the Company undertakes to immediately implement the following measures:
- a) Activate the emergency response procedure to contain and isolate the affected data area;
- b) Within 72 (seventy-two) hours of detecting the incident, submit a written notification to the competent regulatory authority in accordance with applicable regulations;
- c) Promptly notify the Customer via email or the Website so that the Customer may proactively cooperate in implementing risk-mitigation measures.
Article 8. The Customer's Rights and Control over PD
The Company respects and ensures the full exercise of the Customer's lawful rights over PD in accordance with applicable law, including:
- a) Right to be informed: to be transparently and clearly notified of the PD-processing activities carried out by the Company;
- b) Right to decide on consent: the right to consent, refuse, or withdraw previously given consent for the Company to process their PD, at any time;
- c) Right to access and rectify: the right to view, correct, or submit a request to the Company to correct or update their own PD;
- d) Right to control processing: the right to request that the Company provide, delete, restrict the processing of, or object to the continued processing of, their PD, in cases prescribed by law;
- e) Right to legal self-protection: to lodge complaints, denunciations, lawsuits, or claims for damages in accordance with law upon discovering any infringement of their data-protection rights;
- f) Right to request protection from competent authorities: to request that competent State authorities or relevant parties implement measures or solutions to protect their PD in accordance with law.
Customer's obligations: alongside the rights guaranteed to them, the Customer is responsible for fully performing the following obligations, together with the Company, to build a safe data environment:
- a) Proactive self-protection: responsible for protecting their own PD while using the service;
- b) Respect for others' data: to respect and protect the PD of other individuals;
- c) Commitment to accuracy of information: to provide complete, accurate, and truthful PD in accordance with law, contractual agreements, or upon consenting to the Company's processing of data. The Customer bears full responsibility for any consequences arising from providing false or fraudulent information;
- d) Compliance with law: to strictly comply with legal regulations on PD protection, and to actively help prevent, and promptly notify the Company or the competent authorities upon discovering, any activity that infringes the safety of personal data.
The Customer may proactively exercise, or submit a request to exercise, the rights set out in clause 1 of this Article by contacting the Company's data protection department at the following addresses:
- a) Email: info@kalapa.vn.
- b) Hotline: 0246 327 1144.
- c) Company address: 2nd Floor, A1-A3 Ecolife Building, No. 58 To Huu, Yen Hoa Ward, Hanoi City, Vietnam.
To ensure maximum compliance with the Personal Data Protection Regulations, the Company applies the following committed response and processing timelines for each specific category of request:
| No. | Customer's Right | Response Time | Processing Time (Company's internal system) | Joint Processing Time (requests to Third Parties/Processors) | Maximum Extension (in case of complex technical obstacles) |
|---|---|---|---|---|---|
| 1 | Withdrawing consent / restricting / objecting to data processing | Within 02 working days | Within 15 days | Within 20 days | An additional maximum of 15 days (with reasons notified) |
| 2 | Viewing, correcting, or requesting the provision of data | Within 02 working days | Within 10 days | Within 15 days | An additional maximum of 10 days (with reasons notified) |
| 3 | Deleting data | Within 02 working days | Within 20 days | Within 30 days | An additional maximum of 20 days (with reasons notified) |
| 4 | Requesting the implementation of data-protection measures | Within 02 working days | Within 15 days (subject to coordination arrangements) | An additional maximum of 15 days (with reasons notified) |
Article 9. Version and Effectiveness
This Privacy Policy is issued and takes effect from 01/07/2026
The Company reserves the right to amend, supplement, or update this Policy from time to time to ensure alignment with changes in law and with the Company's actual operations. Every updated version will be publicly announced, with its effective date clearly displayed on the Website, for the Customer's ease of reference.
Where amendments to this Policy change any rights or obligations of the Data Subject, change the scope of PD processing, or change the nature of the original data-processing activities (including but not limited to: adding a new processing purpose, changing the type of data collected, or transferring data to a new Third Party outside the previously agreed list), the Company shall directly notify the Customer through the interface displayed on the Website or through other lawful communication channels. Processing of data under such changes will only be carried out after the Customer has proactively clicked to confirm agreement with the new version of the Policy.
Article 10. Address and Contact Information
Personal Data Controller: KALAPA JOINT STOCK COMPANY
- Head office address: 2nd Floor, A1-A3 Ecolife Building, No. 58 To Huu, Yen Hoa Ward, Hanoi City, Vietnam.
Contact information: If the Customer wishes to exercise the data subject's rights under Article 8, or has any questions about this Policy, please contact the Company at:
- Email: info@kalapa.vn.
- Hotline: 0246 327 1144.