Hi! We noticed that your browser has extensions installed that may cause our website to not display or function properly for you.

For best user experience, we highly suggest to turn off ad blockers or privacy trackers (such as Privacy Badger or Firefox Enhanced Tracking).

Thank you.

ANDUIN TRANSACTIONS VIETNAM
PERSONAL DATA PRIVACY POLICY

Effective date: January 1, 2026

 

 

Anduin Transactions Vietnam Co., Ltd. (the “Company”, “we”, or “us”) collects and processes “Personal Data” (defined below) about job candidates, employees and their dependents during recruitment, employment and benefits administration in Vietnam. This employee and candidate personal data privacy policy (the “Policy”) explains what Personal Data we collect, why, how long we keep it, who we share it with, and the rights available to you under Law No. 91/2025/QH15 on Personal Data Protection (“PDPL”) and its implementing Decree No. 356/2025/ND-CP (“Decree 356”).

This Policy applies to all candidates who apply for a role with the Company, all current and former employees, and, where relevant, employees' dependents whose data is processed for insurance or benefits purposes. It applies regardless of whether the Personal Data is held on paper, in the Company's systems or in a third-party system used by the Company.

 

Effective Date

This Policy takes effect from January 1, 2026 and may be occasionally updated in accordance with company policy and regulatory changes. Any updates to this Policy will be communicated to the employee as soon as possible.

 

Definitions

  • “Basic Personal Data” includes name, date of birth, gender, addresses, nationality, photo, phone number, national ID/passport/driver's license numbers, marital status, family relationship details, and digital account information.

  • “Personal Data” means any information that identifies or can help identify a specific individual.

  • “Personal Data Controlling Party” is the Company, which decides the purposes and means of processing your Personal Data.

  • “Personal Data Processing Party” is any vendor (e.g., payroll provider, HRIS platform, benefits administrator, background-check firm) engaged by the Company that processes data on the Company's behalf under a written agreement.

  • “Processing” refers to activities which include one or more of the following activities: collection, analysis, summary, encryption, decryption, modification, deletion, destruction, de-identification, provision, disclosure, transfer of personal data and other activities which impact Personal Data.

  • “Sensitive Personal Data” includes health status, biometric and genetic data, information on private or family life, ethnic origin, political or religious views, and financial/credit/account information. In practice this includes health declarations, medical exam results, biometric attendance or access-control data, copies of ID cards, and background-check results.

 

What Personal Data We Collect

Depending on the stage of Anduin employment “lifecycle”, the following may be collected by the company:

Candidates: CV/resume details, contact information, education and work history, interview notes and references, but only as needed for the role you applied for.

Employees:

  • The above candidate data.

  • Payroll and tax information, bank account details, national ID/passport data, emergency contacts, family/dependent information for benefits, performance records, disciplinary records, background-check or assessment results, and training records.

  • Health and biometric data: medical exam results and health declarations where required by law or for insurance purposes, and biometric data (e.g. fingerprint or facial recognition) where used for office access or time and attendance.

Candidates and Employees: System and monitoring data

  • For employees: Data generated by company-issued devices, email/collaboration systems, badge access logs, and CCTV footage in common work areas, to the extent such monitoring is in place (see Section 7).

  • For candidates: Possible CCTV footage in common work areas when in office for interviews, if applicable.

 

Legal Basis and Consent

We process your Personal Data based on your consent, to perform your employment contract or to comply with our legal obligations (e.g., labor, tax, social insurance law), or as otherwise permitted by applicable law without consent (e.g., to protect life or health in an emergency, or at the request of a competent state authority).

Where we rely on consent, we will tell you what data is collected, for what purpose, and who controls it, before you consent. Consent is specific to each purpose, and you may withdraw it at any time by using the process outlined in Section 8, except where the applicable law does not permit withdrawal (for example, data we are legally required to retain). The Company do not use default “opt-in” boxes, and your silence is never treated as consent. Where we ask for Sensitive Personal Data, we will tell you at that time that it is being treated as Sensitive Personal Data.

 

Recruitment

During recruitment, we only ask for information relevant to the specific role applied for and use it only for recruitment purposes, or other purposes you agree to. If you are not selected, we will delete or destroy your application data promptly following the close of the recruitment process, unless you have separately agreed for us to keep your profile on file for future opportunities.

 

Employment Data and Retention

If you are hired, your Personal Data is used to administer and process your employment: payroll and benefits, performance management, training, workplace safety, and compliance with applicable labor and tax law. We keep employment data only for as long as required by law or agreed with you, and we delete or destroy it after your contract ends, unless a longer period is required by law (for example, statutory labor and tax record-keeping periods) or separately agreed with you.

 

Workplace Monitoring

Where the Company uses technology to monitor the office - for example, badge or biometric access control, CCTV in common areas, or device and activity monitoring on company equipment - such monitoring is carried out only to the extent permitted by applicable law and proportionate to a legitimate business purpose (e.g., security, safety or IT security). We will make you aware of any such monitoring, including through this Policy, the employee handbook, onboarding materials, or signage where applicable. We do not conduct covert monitoring of employees or candidates.

 

Your Rights and How to Exercise Them

Subject to limited exceptions provided by applicable law, you have the right to:

  • Be informed about how your Personal Data is Processed.

  • Give, refuse or withdraw consent to Processing at any time.

  • View, correct or request correction of your Personal Data.

  • Request that we provide, delete or restrict Processing of your Personal Data, or object to Processing, at any time.

  • Complain, report a violation, or seek legal remedies, including compensation, in accordance with the applicable law.

  • Request that we or a relevant authority take steps to protect your Personal Data.

To exercise any of these rights, please contact the Company's personal data protection personnel/unit at the address in Section 11. We will handle your request in accordance with the following timeline:

 

Your Right

Time to Acknowledge

Time to Complete

Be informed of Processing; give or withdraw consent; object to Processing

2 working days

15 days (20 if a vendor must act)

View, correct or obtain a copy of your data

2 working days

10 days (15 if a vendor must act)

Request deletion of your data

2 working days

20 days (30 if a vendor must act)

Request protective measures for your data

2 working days

15 days

Complain, raise a grievance or claim damages

Per grievance procedure

Per grievance procedure

 

Sharing, Processors and Cross-Border Transfers

We only share employee and candidate data with parties who need it to deliver services on our behalf (e.g., payroll processors, benefits administrators, cloud platform providers, background-check vendors) or as required by applicable law or a competent state authority. Every such Personal Data Processing Party is bound by a written data processing agreement that specifies the purpose, scope, retention and deletion requirements, and security obligations for the data.

Some Personal Data Processing Party may store or Process data outside Vietnam, including on cloud-hosted systems. Where this qualifies as a cross-border transfer under the PDPL, we carry out and file the required impact assessment with the relevant personal data protection authority, unless an exemption applies (for example, where employee data is simply stored on a cloud computing service, or where the transfer is for cross-border personnel management under our labor policies). We do not sell your Personal Data.

 

Data Security

We apply administrative, technical and physical safeguards appropriate to the sensitivity of the data involved, including access controls limiting data access to personnel who need it, in alignment with the principle of least privilege and need-to-know, encryption or de-identification where appropriate, and confidentiality obligations for staff and vendors who handle personal data. Sensitive Personal Data is subject to additional access restriction and confidentiality measures, including but not limited to:

  • Mandatory Multi-Factor Authentication (MFA): All HR databases, recruitment portals, and payroll systems holding sensitive records require MFA for access

  • Encryption Enforcement: Sensitive Personal Data is encrypted both at rest and in transit using industry-standard algorithms

  • Audit Logging & Traceability: Logging mechanisms track all access, modification, export, and deletion events involving candidate and employee data to ensure complete traceability

 

Data Protection Contact

The Company has designated personal data protection personnel/a unit responsible for this Policy and for handling data subject requests and incidents. Requests, questions or complaints about this Policy should be directed to that team through the channel communicated internally (e.g., HR or Legal/Compliance) or email at DPO@anduintransact.com.

 

Data Breach and Incident Notification

If we become aware a violation of this Policy or applicable law that could harm your rights or the Company's security, we will notify the relevant personal data protection authority within 72 hours, as required by applicable law. Where the incident involves your location or biometric data, we will also notify you within 72 hours, describing what happened, the risks involved, and the steps we are taking, and how to reach our data protection contact.

 

Policy Review and Updates

We review this Policy at least annually or whenever there is a material change in the applicable law or in how we process your Personal Data. We will notify employees of material updates through normal internal communication channels.

 

Acknowledgment

By continuing your application or employment with the Company after receiving this Policy, you acknowledge that you have read and understood how your Personal Data is Processed as described herein. Where your specific consent is required for a particular purpose, we will ask for it separately.