1. Introduction

This privacy policy is an important document. Bestarion recommends that users read it carefully.

If a user has any questions regarding this Privacy Policy, including any requests to exercise the user’s legal rights, the user can contact Bestarion using the following information:

  • Full name of legal entity: BESTARION SOFTWARE JOINT STOCK COMPANY.
  • Email address: *protected email*
  • Address: 3rd Floor, QTSC Building 1, Street 14, Quang Trung Software City, Tan Chanh Hiep Ward, District 12, HCM City, Vietnam.

User duty to inform Bestarion of changes: It is important that the personal data Bestarion holds about users is accurate and current. The user should keep Bestarion informed if the user’s personal data changes during the relationship between the user and Bestarion.

Third-party links: This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about users. Bestarion does not control these third-party websites and is not responsible for their privacy statements. When a user leaves the website, Bestarion encourages the user to read the privacy notice of every website visited.

In this policy, the terms are used:

  • “Bestarion” in the Privacy Policy is BESTARION SOFTWARE JOINT STOCK COMPANY.
  • “Personal Information” or “Personal Data” is any information relating to an identified or identifiable natural person.
  • “Identifiable natural person” is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors.
  • “User” and “the user” (and other similar terms) refer to Bestarion clients, individuals associated with Bestarion clients, contacts, suppliers, job applicants, staff and visitors to the Bestarion website

2. General Information

Bestarion values the privacy of users who provide personal information to the company. This Privacy Policy aims to give the user information on how Bestarion collects and processes their personal data including any data that they may provide through the Bestarion website.

People under 18 years old will not be considered as Bestarion users. The access to Bestarion website from them would be considered misuse of Bestarion service and Bestarion is not responsible for any consequence of such access.

This policy applies to both personal information supplied to Bestarion either by an individual or by legal third parties. Bestarion may use personal data supplied for any of the purposes as set out in this policy, or as otherwise disclosed at the point of collection.

In particular, Bestarion will make sure that all personal data shall be processed in compliance with the following principles:

  • Lawfulness, fairness, and transparency: To process lawfully, fairly, and in a way that is transparent to the data subject.
  • Purposes limitation: To collect or create for specified, explicit and lawful purposes and not be further processed in a manner that is not complied with the purposes under this policy.
  • Data minimization: To collect personal data in the manner of adequate, relevant, and limited to what is necessary for Bestarion’s purposes.
  • Accuracy: To reasonably maintain the personal data is accurate and updated.
  • Storage limitation: To retain the personal data no longer than the necessity of Bestarion’s purposes, except in the circumstances established by law.
  • Integrity and confidentiality: To keep personal data safe from any unauthorized access, processing, accidental or deliberate loss or destruction.

3. User Rights In Relation To Personal Information And How To Exercise Them

  • Under certain circumstances users have the following rights:
    • Request access to the personal data (commonly known as a “data subject access request”). This enables users to receive a copy of the personal data Bestarion holds about him/her and to check that Bestarion is lawfully processing it.
    • Request correction of the personal data that Bestarion holds. This enables users to correct any incomplete or inaccurate data Bestarion holds about him/her.
    • Request erasure of the personal data. This enables users to lawfully request Bestarion to delete or remove his / her personal data where there is no good reason for Bestarion continuing to process it.
      The user also has the right to ask Bestarionto delete or remove the personal data where the user has the right to object to processing (see below), where Bestarion may have misused his / her information or where Bestarion is required to erase the personal data to comply with local law.
      However, that Bestarion may not always be able to comply with the request of erasure for specific legal and business reasons which will be notified to the user, if applicable, at the time of the request.
    • Object to processing of the personal data where Bestarion is relying on a legitimate interest (or those of a third party) and there is something about the particular situation which makes the user want to object to processing on this ground as the user feels it impacts on his / her fundamental rights and freedoms.
      The user also has the right to object where Bestarion is processing the personal data for direct marketing purposes. In some cases, Bestarion has compelling legitimate grounds to process the information that override the agreement with the user.
    • Request restriction of processing of the personal data. This enables users to ask Bestarion to suspend the processing of his / her personal data in the following scenarios:
      • If users want Bestarion to establish the data’s accuracy
      • Where data usage is misused but users do not want to erase it
      • Where user needs to hold the data even if Bestarion no longer requires it as the user needs to establish, exercise or defend legal claims
      • User has objected to Bestarion usage his / her data but Bestarion needs to verify whether Bestarion has overriding legitimate grounds to use it
    • Request the transfer of personal data to users or to a third party. Bestarion will provide to the user, or the third party, the user’s personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which users initially provided consent for Bestarion to use or where Bestarion used the information to perform a contract with the user.
    • Withdraw consent at any time where Bestarion is relying on consent to process user’s personal data. However, this will not affect the lawfulness of any processing carried out before the user withdraws his / her consent. In this case, Bestarion may not be able to provide certain products or services to users. Bestarion will advise users at the time user withdraws his / her consent.
    • If users wish to exercise any of the rights set out above, please contact Bestarion via email at*protected email*
  • No fee usually required: User will not have to pay a fee to access the personal data (or to exercise any of the other rights). However, Bestarion may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, Bestarion may refuse to comply with the request in these circumstances.
  • What Bestarion may need from user: Bestarion may need to request specific information from users to identify and ensure user’s right to access the personal data (or to exercise any of user rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to access it. Bestarion may also contact you to ask you for further information in relation to your request to speed up our response.
  • Time limit to respond: Bestarion tries to respond to all legitimate requests within one month. Occasionally it may take longer than a month to process the requests. In this case, Bestarion will notify users about the processing time.

4. What Personal Information Does Bestarion Collect ?

Bestarion aims to be transparent about why and how Bestarion processes personal information.

  • For all visitors to the Bestarion website, Bestarion may collect, use, store and transfer different kinds of personal data which BESTARION has aggregated as follows:
    • Identity Data includes first name, last name, user name or similar identifier, title, and gender.
    • Contact Data includes address, email address, and telephone numbers.
    • Technical Data includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
    • Profile Data includes user name, interests, preferences, and feedback.
    • Usage Data includes information about how users use the Bestarion website, products, and services.
    • Communications Data includes data user sent to Bestarion via Bestarion website, email, or chatbox.
  • In addition, if a user is a candidate being considered for a role or any opportunities
    • Bestarion may also collect other information including in the candidate’s CV/resume as well as other details about kills and experience, career history, salary range, right to work status, any information which has been published or made available on a social media profile or job board (whether by a user or a legal third party), or in any news media.
  • Bestarion may also collect need information to complete a contract for a candidate such as:
    • Bank account.
    • A copy of passport details including passport photograph.
    • Recruitment-specific details such as any professional certifications, education, and qualifications.
    • Referees and emergency contacts including full name, address, email address, and telephone number.
    • References from third parties such as previous employers and nominated referees.
    • The results of pre-employment screening or vetting checks which Bestarion is asked or required to undertake in relation to you.
    • Any email communications, including attachments, which candidate sends to Bestarion.
    • General health-care checkup information.
    • Any other information relevant required by law.
  • Where a user is a customer, Bestarion may collect more information from or about his / her, including:
    • Details of role, title, and responsibilities within his / her organization.
    • Any opinion or feedback shared regarding the Bestarion product/service.
    • Details of any queries raised regarding Bestarion products/services.
    • Any email communications, including attachments, which are sent to Bestarion.

5. How Is Personal Data Collected?

BESTARION uses different methods to collect data from and about users including through:

  • Direct interactions: User may give Bestarion the identity and contact data by filling in forms or providing other information via the Bestarion website or email This includes personal data provided when:
    • Request Bestarion products/services.
    • Respond to recruitment posted by Bestarion on job advertisement services.
    • Request marketing or providing services.
    • Give Bestarion some inquiries/feedback.
  • Automated technologies or interactions. As users interact with Bestarion website, it may automatically collect data about the user’s equipment, browsing actions and patterns… Such technical data might reveal certain types of personal data by using cookies, server logs, and other similar technologies. Please see Bestarion Cookies Policy for further details
  • Third parties or publicly available sources: Bestarion may receive personal data from various third parties and public sources that have legal permission to share the information. They are listed below but not limited to:
    • Analytic providers [such as Google based outside the EU]. For more information on Google’s use of personal information, please see Types of Cookies Used by Google.
    • Social network sites: LinkedIn, publicly available on job board (whether by a user or a legal third party).

Bestarion will only use the personal data for lawful purposes. Commonly, Bestarion will use the personal data in the following circumstances:

  • Where it is necessary to perform a business contract between Bestarion and a user.
  • Where it is necessary for Bestarion legitimate interests (or those of a third party), user’s interests and fundamental rights do not override those interests.
  • Where it is necessary to comply with any legal or regulatory obligations.

The possible ways, which Bestarion plans to use personal data, have set out below:

  • Providing Services: In this regard, Bestarion may collect, process, and disclose personal data for the purpose of:
    • Assessing of the suitable candidate for particular positions or employment roles as defined by customer.
    • Evaluating and assessing of the suitability for providing resourcing, outsourcing, or consultancy.
    • Matching a candidate details with vacancies of Bestarion and/or customer.
    • Disclosing a candidate’s personal data to customers for positions or employment roles as defined by customer.
  • Maintaining records of any and all candidate, consultant, customer, business partner, supplier, staff, and staff of third-party supplier.
  • Administering and carrying out relationship management procedures of customer and prospective customer.
  • For internal management, accounting, and employment purposes of Bestarion.
  • Conducting marketing, profiling, and business development activities as well as market research and statistical analysis and customer survey regarding Bestarion services.
  • Complying with any legal or regulatory requirements and to make the necessary disclosure under the requirements of any law, regulation, direction, court order, or code which are applicable to Bestarion.

Note that Bestarion may process the personal data for more than one legal basis depending on the specific purposes. User has the right to withdraw his / her consent by contacting Bestarion via*protected email*

7. Disclosures Of Personal Data

Bestarion may have to share personal data with the legal parties below for the purposes set out in the section 6 above:

  • Third-party service providers: When Bestarion shares the personal data with any third-party service providers to facilitate and support Bestarion in the provision of the services. This includes, but not limited to:
    • IT service providers.
    • Payment processors.
    • Third-party partners for the purposes of hosting events.
  • Outsourcing services: When Bestarion is using the personal data in the context of recruitment and outsourcing services, then Bestarion may share the personal data with customers, or where Bestarion believes that the candidate may be appropriate for a particular role or vacancy with that customer is hiring with the candidate/employee’s permission.
  • Umbrella/group companies: The personal data may be provided to Bestarion subsidiaries or affiliated companies for the purpose of processing personal data on behalf of Bestarion to provide products/services. These parties are required to process such data based on Bestarion instructions and in accordance with this Privacy Policy. They do not have any independent right to share such data.
  • Compliance with laws and legal proceedings: When Bestarion responds to court orders, or legal process, or to establish or exercise Bestarion legal rights or defend against legal claims. When Bestarion believes that it is necessary to share data in order to investigate, prevent or take actions against illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of Bestarion terms of use, or as otherwise required by law.

8. International Transfers

Bestarion will be entitled to disclose personal data to any third parties, and/or transferred either internally or outside of Vietnam, for the purposes as listed in the section 6 above of this policy when the consent thereof has been obtained in advance.

Bestarion would like to make sure that personal data is stored and transferred in a way that is secure. Thus, Bestarion will only transfer data to third parties where they comply with the data protection legislation and the means of transfer safeguards.

9. Data Security

Bestarion has put in place appropriate security measures to prevent personal data from being accidentally lost, used, or accessed in an unauthorized way, altered or disclosed. In addition, Bestarion limits access to personal data to those employees, contractors, and other third parties who have a business that requires the corresponding personal data. They will only process the personal data based on an agreement with Bestarion in which, among other constraints, they are subject to a duty of confidentiality.

Bestarion also has put in place procedures to deal with any suspected personal data breach and will notify users and any applicable regulator of a breach where Bestarion is legally required to do so.

10. Data Retention

Bestarion does not keep data longer than necessary.

  • For most users where Bestarion has limited contact, Bestarion will retain the personal data for a maximum of two years from the date of last contact.
  • Where Bestarion has a business contract with users, for instance Bestarion has worked with the user as a customer, the personal data will be kept for 10 years.
  • Where Bestarion has interviewed/placed user as a candidate, the personal data will be kept for 5 years.
  • In all cases listed above, Bestarion may retain data longer. In this case, Bestarion will notify users about the change of data retention.

Bestarion will delete personal data after that time except where Bestarionneeds to keep any personal data to comply with legal obligations, resolve disputes, or enforce agreements.

11. Changes To Our Privacy Policy

This Privacy Policy was last updated on 15/05/2020.

Please check back regularly to keep informed of updates to this Privacy Policy. Where Bestarion makes significant changes to this Privacy Policy and has users’ email addresses, Bestarion will send user notification of the changes.

Thanks for reading carefully our Privacy Policy.