Privacy Policy
1. Introduction
1.1. Purpose
- Bestarion Software Joint Stock Company (“We”, “the Company”, “Bestarion”) is committed to protecting your privacy and personal data. This Policy describes how we collect, use, process and transfer your data, as well as your rights relating to personal data
- This Policy is developed to comply with the Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP effective from January 01, 2026, together with other applicableIn case of any difference legal regulations in Vietnam
- In the event of any inconsistency or conflict between the above legal documents, the application shall follow the current legal regulations in effect at each point in time
- For matters not provided for in this document, the processing of personal data shall be carried out in accordance with the relevant laws of Vietnam
1.2. Definitions
In this Policy, the following terms shall have the meanings assigned to them under Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP unless otherwise defined herein:
- Personal data (PD) is digital data or information in another form that identifies or helps identify a specific individual, including basic personal data and sensitive personal data. Personal data, once de-identified, is no longer personal data
- Basic personal data is personal data reflecting common personal and background elements, frequently used in transactions and social relationships, falling under the list issued by the Government
- Sensitive personal data is personal data associated with an individual’s privacy, which, if violated, will directly affect the lawful rights and interests of agencies, organizations and individuals, falling under the list issued by the Government
- Personal data protection is the use of forces, means and measures by agencies, organizations and individuals to prevent and combat activities that infringe upon personal data
- Personal data subject is the person reflected by the personal data
- Personal data processing is an activity that affects personal data, comprising one or more of the following activities: collecting, analyzing, aggregating, encrypting, decrypting, editing, deleting, destroying, de-identifying, providing, disclosing, transferring personal data and other activities affecting personal data
- Personal data controller is the agency, organization or individual that decides the purpose and means of processing personal data
- Personal data processor is the agency, organization or individual that processes personal data at the request of the personal data controller, or the personal data controller and processor, through a contract
- Personal data controller and processor is the agency, organization or individual that decides the purpose and means of, and directly carries out, the processing of personal data
- Third party is an organization or individual, other than the personal data subject, the personal data controller, the personal data controller and processor, or the personal data processor, that takes part in the processing of personal data in accordance with the law
- Employees include all individuals who have or have had an employment or working relationship with the Company, including but not limited to permanent employees, probationary employees, interns and former employees
2. Personal Data Protection Principles
- Comply with the provisions of the Constitution, this Law and other relevant legal provisions
- Personal data may only be collected and processed within a specific, clear scope and purpose, ensuring compliance with legal regulations
- Personal data shall be kept accurate and updated where necessary.
- Personal data shall be stored for a period appropriate to the purpose of processing, unless otherwise provided by applicable law
- Implement synchronized and effective institutional, technical and human measures and solutions appropriate to protect personal data
- Proactively prevent, detect, deter, combat, and promptly and strictly handle all acts violating the law on personal data protection
- Personal data protection is linked to the protection of national and ethnic interests, serving socio-economic development, and ensuring national defense, security and external affairs; ensure harmony between the protection of personal data and the protection of the lawful rights and interests of agencies, organizations and individuals
3. Personal Data Collected
3.1. Website Visitors
- Identification data: Full name
- Contact data: Email, phone number
- Communication data: Content sent via contact form, email, live chat
- Technical data: IP address, browser type, cookies and data on usage behavior on the website in order to optimize user experience. Please refer to the Bestarion Cookie Policy for further details
- Third-party websites: BESTARION’s website may include links to third-party websites, plug-ins and applications. Clicking on these links may allow third parties to collect or share your data. BESTARION does not control these websites and is not responsible for the privacy terms of third parties. When leaving BESTARION’s website (https://bestarion.com), BESTARION encourages you to read the privacy notices when visiting other websites
3.2. Candidates
- BESTARION will collect the following information to the extent necessary for providing recruitment services, from the following sources:
- Information you directly provide; or
- Information related to the Candidate collected through:
(i) recruitment postings by BESTARION on recruitment platforms and social networks
(ii) online recruitment platforms and publicly shared online profiles of the Candidate found by BESTARION during the recruitment process; or
(iii) any other communication channel the Candidate uses to interact with BESTARION
- The information collected includes:
- Personal information — basic identification and contact fields: full name, date of birth, gender, nationality, address, phone number, email, photo, and education history
- Professional profile — all professional information: CV, experience, skills, expected salary, portfolio, publicly available professional profile information (if any), work history
- Reference — contact information provided by the candidate: full name, position, email, phone number, and their comments / assessment
- Assessment & interview — all recruitment data: test results, interview schedule, notes, assessment scores, interview rounds, and interviewers
3.3. Employees, Collaborators
3.3.1. Basic Data
| Data | Detailed content |
|---|---|
| Personal identification information |
|
| Contact information |
|
| Professional information |
|
| Recruitment information |
|
| Time & performance data |
|
| General image data |
|
| Digital account information |
|
| Data of relatives / dependents |
|
Table 1: Basic data
3.3.2. Sensitive Data
| Data | Detailed content |
|---|---|
| Personal identification information |
|
| Financial information |
|
| Health information |
|
| Biometric data |
|
| Information on violation handling |
|
Table 2: Sensitive data
3.4. Prospective Customers, Customers
BESTARION primarily processes the personal data of representatives, authorized persons, contact points or personnel of customers and prospective customers to the extent necessary to establish, maintain and carry out business relationships.
Depending on the purpose of data processing, BESTARION may collect and process the following types of personal data:
- Identification and contact information of customers or customer representatives, including: full name, position / title, organization, email, work phone number and other contact information
- Information related to the organization where the individual works, including: business name, tax code, address, website, field of operation and related business information. Information provided during the process of sending requests, requesting quotations, registering for services, exchanging information or contacting BESTARION
- Information related to the negotiation, execution, performance and management of contracts, agreements or transactions between customers and BESTARION
- Payment, invoice, receivable / payable and other information necessary to carry out financial transactions related to BESTARION’s products or services
- Information related to the use of products and services, support requests, feedback, complaints or customer satisfaction surveys
- Other personal data provided by customers or prospective customers during the process of establishing and maintaining a relationship with BESTARION
3.5. Suppliers, Partners & Contractors
Depending on the purpose of data processing, BESTARION may collect and process the following types of personal data:
- Identification and contact information of the representative, contact point or personnel designated by the supplier or partner, including: full name, position / title, organization, email, work phone number and other contact information
- Information related to the organization where the individual works, including: business name, tax code, address, website, field of operation and related business information. Information provided during the process of exchange, capability assessment, due diligence, supplier selection or establishment of a cooperative relationship with BESTARION
- Information related to the negotiation, execution, performance, management or termination of contracts, agreements or business transactions with BESTARION
- Payment, invoice, payment account, receivable / payable and other information necessary to carry out financial transactions between the parties
- Information related to the provision of goods, services, technical support, project implementation or other obligations under a contract or agreement
- Information for performance assessment, compliance, audit, risk management and information security assurance activities as required by BESTARION or by applicable law
- Other personal data provided by suppliers or partners during the process of establishing and maintaining a cooperative relationship with BESTARION
3.6. Shareholders
Bestarion collects and processes personal data of individual shareholders, as well as the legal representatives or authorized representatives of institutional shareholders, including:
- Identification information: Full name, date of birth, nationality, Citizen Identity Card / Passport number, and signature
- Contact information: Permanent address, phone number, and email
- Bank account information for dividend payments
- Shareholding information: Quantity, percentage, and class of shares, as well as share transfer transaction history
- Information regarding attendance, proxy authorization, and voting at the General Meeting of Shareholders (proxies, ballots, and attendance confirmations)
4. Purposes of Processing Personal Data
BESTARION only uses personal data for the purposes set out below on a valid legal basis under Law No. 91/2025/QH15:
4.1. Website Visitors
BESTARION may collect and process the personal data of Website users for the following purposes:
- Providing, operating, maintaining and improving BESTARION’s Website
- Managing and responding to requests, questions, feedback or information submitted through contact forms or other functions on the Website
- Analyzing Website usage to assess operational effectiveness, improve user experience and enhance the quality of content, products and services provided on the Website
- Ensuring the safety, security and integrity of the Website, including detecting, preventing and handling unauthorized access, fraud, cyberattacks or other activities that may affect the Website and BESTARION’s information systems
- Managing registrations to receive newsletters, documents, events, seminars or other information provided by BESTARION through the Website
- Carrying out marketing, communication or promotional activities for BESTARION’s products and services in accordance with applicable law
- Complying with legal obligations, requests from competent state authorities, or legal regulations applicable to BESTARION
4.2. Candidates
BESTARION may collect and process candidates’ personal data for the following purposes:
| Activity | Purpose of personal data processing |
|---|---|
| Sourcing candidates and receiving applications | Sourcing candidates through recruitment platforms, professional social networks, internal referral programs and other lawful sources; receiving and managing application files |
| Screening and interviewing | Assessing the candidate’s competency, experience, professional qualifications and suitability for the vacant position |
| Verifying candidate information | Verifying information provided by the candidate, conducting reference checks or other appropriate verification activities in accordance with law |
| Sharing profiles with customers | Sharing candidate profiles with customers or partners who have recruitment needs or use IT Staffing services, where there is an appropriate legal basis and / or the candidate’s consent as required by law |
| Sending offer letters and onboarding new personnel | Preparing offer letters, executing contracts, completing onboarding procedures and establishing personnel records |
| Managing the pool of potential candidates | Storing candidate profiles for consideration for future recruitment opportunities in accordance with law and, when necessary, on the basis of the candidate’s consent |
Table 3: Activities and purposes of collecting and processing candidates’ personal data
4.3. Employees, Collaborators
BESTARION may collect and process the personal data of employees and collaborators for the following purposes:
4.3.1. Human Resources Management
| Activity | Purpose of personal data processing |
|---|---|
| Managing personnel records | Managing personal information, employment records, organizational structure, job titles and internal contact information |
| Managing work performance | Setting goals, performance appraisals, competency assessments, considering promotions, transfers or income adjustments |
| Managing project resources | Allocating personnel, managing skills, experience, competency and ability to meet project or customer requirements |
| Managing collaborators | Managing collaboration contracts, scope of work, performance and related obligations |
| Business travel and working with customers | Managing business trips, on-site work at customers, ticket booking, accommodation, visas and related procedures |
Table 4: Activities and purposes of collecting and processing personal data of employees and collaborators
4.3.2. Payroll, Benefits and HR Administration
| Activity | Purpose of personal data processing |
|---|---|
| Managing records and contracts | Storing and managing labor contracts, contract appendices, personnel decisions and related records |
| Managing time and attendance | Recording working time, overtime, leave, remote work and other labor arrangements |
| Managing salary and income | Calculating salary, bonus, allowances, deductions, income payment and period-end settlement |
| Mandatory insurance | Carrying out procedures related to social insurance, health insurance, unemployment insurance and other labor regimes as required by law |
| Personal income tax | Registering tax codes, dependents, deductions and personal income tax finalization |
| Welfare and healthcare | Managing health insurance, periodic health check-ups, welfare programs and employee support |
| Discipline and labor relations | Handling violations, resolving complaints, labor disputes and other matters related to labor relations |
| Termination of cooperation or resignation | Carrying out handover procedures, benefit settlement, asset recovery and closing personnel records |
| Complying with legal obligations | Performing obligations required by law and by competent state authorities |
Table 5: Payroll, benefits and HR administration
4.3.3. Training and Capability Development
| Activity | Purpose of personal data processing |
|---|---|
| Training needs survey | Identifying employees’ learning and capability development needs |
| Training management | Organizing, registering and managing internal or external training programs |
| Online training system | Creating learning accounts, tracking progress, results and training history |
| Certificate management | Tracking professional certificates, training fee reimbursement and learning support programs |
| Training effectiveness evaluation | Collecting feedback and evaluating the effectiveness of application after training |
Table 6: Training and human resource development
4.3.4. IT and Information Security Management
| Activity | Purpose of personal data processing |
|---|---|
| User account management | Creating, managing, modifying or revoking accounts for access to IT systems, applications and services |
| IT equipment management | Issuing, tracking, maintaining and recovering equipment used for work |
| Monitoring and protecting systems and the workplace | Recording access logs, monitoring system activities, detecting and handling information security incidents |
| Investigating and handling violations | Investigating violations of internal policies, regulations or incidents related to information security |
Table 7: IT and information security management
4.3.5. Legal Compliance
BESTARION processes the personal data of employees and collaborators to fulfill obligations required by law and by competent state authorities, including but not limited to:
- Performing obligations relating to labor, wages, social insurance, health insurance, unemployment insurance, personal income tax and other financial obligations
- Performing obligations relating to occupational safety and hygiene, fire prevention and fighting, cybersecurity, personal data protection and other relevant legal regulations
- Storing records and documents for the retention period prescribed by law
- Providing information, documents, or coordinating with competent state authorities upon lawful request
- Establishing, exercising or defending BESTARION’s lawful rights and interests in the course of resolving complaints, disputes, litigation or other legal proceedings
4.3.6. Other Internal Purposes
BESTARION may process the personal data of employees and collaborators for other administrative, operational and business development purposes, in accordance with law, including but not limited to:
- Administering internal operations, human resource planning and business operation management
- Conducting internal inspections and assessments, risk management, internal audits and ensuring compliance with the Company’s policies and procedures
- Developing and improving work processes, information systems, management policies and programs to enhance operational effectiveness
- Conducting statistics, analysis, management reporting and business development strategy planning based on data with restricted access or appropriate protective measures applied
- Carrying out internal communications, event organization, employee engagement programs and other internal administrative activities in service of BESTARION’s lawful operations
4.3.6.1. Employee Engagement
| Activity | Purpose of personal data processing |
|---|---|
| Employee surveys | Assessing satisfaction, engagement and corporate culture |
| Organizing internal events | Organizing conferences, team-building, sports and cultural activities and other internal programs |
| Gifts and employee support | Managing gift programs, allowances, condolence / celebration support and other welfare programs |
| Rewards and recognition | Recording achievements, giving awards and internal communications about outstanding individuals or teams |
| Employee relations | Receiving and handling feedback, complaints or support requests from employees |
Table 8: Employee engagement
4.3.6.2. Employer Branding
| Activity | Purpose of personal data processing |
|---|---|
| Internal and external communications | Posting information, images or content related to the Company’s activities and personnel |
| Sharing employee stories | Producing articles, videos or content introducing work experience and corporate culture |
| Recruitment events | Organizing or participating in job fairs, career seminars and other recruitment promotion activities |
| Brand ambassadors | Managing candidate referral programs, brand ambassador and employee promotional activities |
Table 9: Employer branding communications
The use of images, videos, articles or other personal data of employees for communication, promotion or marketing purposes will be carried out on the basis of the data subject’s consent or another appropriate legal basis as provided by law.
4.4. Prospective Customers, Customers
BESTARION may collect and process the personal data of customers and prospective customers for the following purposes:
- Receiving, processing and responding to requests regarding products, services, quotations, cooperation proposals or other business requests
- Assessing customer needs, identifying business opportunities and carrying out sales, marketing and business development activities
- Establishing, managing and maintaining relationships with customers and prospective customers through customer relationship management (CRM) systems and customer care activities
- Negotiating, executing, performing, managing and renewing contracts, agreements or business commitments with customers
- Providing products, services, technical support, maintenance, consulting or other services as requested by customers or as agreed between the parties
- Carrying out project management, service quality management, customer support and handling customer requests, complaints or feedback
- Sending information about products, services, events, seminars, marketing programs or other content related to BESTARION’s business activities in accordance with applicable law
- Conducting customer satisfaction surveys, market research, statistical analysis and other activities aimed at improving the quality of products, services and customer experience
- Performing accounting, payment, invoicing, receivable / payable reconciliation and other financial obligations related to transactions with customers
- Protecting BESTARION’s lawful rights and interests, establishing, exercising or defending legal claims; preventing, detecting and handling fraud, breach of contract or other unlawful acts
- Complying with legal obligations, requests from competent state authorities, or legal regulations applicable to BESTARION
4.5. Suppliers, Partners And Contractors
BESTARION may collect and process the personal data of suppliers, business partners, contractors, and the representatives, employees or contact points of these organizations for the following purposes:
- Establishing, maintaining and managing business cooperation relationships with suppliers, partners, contractors and related parties
- Assessing, selecting, evaluating the capabilities of suppliers, partners and contractors and conducting due diligence
- Exchanging information, negotiating, executing, performing, managing, amending, renewing or terminating contracts, agreements or business transactions with suppliers and partners
- Managing the supply of goods, services, project implementation, technical support or other obligations under contracts or agreements between the parties
- Managing procurement, bidding, supplier selection, performance management and quality assessment of goods and services provided by suppliers or partners
- Carrying out accounting, payment, invoicing, receivable / payable reconciliation, auditing and other related financial obligations
- Managing access rights to and use of BESTARION’s facilities, information systems or resources when necessary for business cooperation activities
- Ensuring information safety and security, preventing, detecting and handling fraud, breach of contract, policy violations or other unlawful acts
- Establishing, exercising or defending BESTARION’s lawful rights and interests; resolving disputes, complaints or other legal matters arising
- Complying with legal obligations, requests from competent state authorities, or legal regulations applicable to BESTARION
4.6. Shareholders
Bestarioon may collect and process shareholders’ personal data for the following purposes:
- Compiling, updating, and managing the Register of Shareholders in accordance with Article 122 of the Law on Enterprises 2020
- Convening and organizing the General Meeting of Shareholders and verifying attendance eligibility in accordance with Article 139 of the Law on Enterprises 2020
- Paying dividends and fulfilling obligations regarding personal income tax declaration and withholding in accordance with current tax laws
- Fulfilling accounting and record-keeping obligations in accordance with the Law on Accounting
- Providing information to competent state authorities and depository institutions / securities depository centers (if applicable) upon lawful request
5. Sources & Methods of Personal Data Collection
BESTARION collects personal data through lawful, fair and transparent means to serve the purposes notified to the data subject. Depending on the relationship between BESTARION and the data subject, personal data may be collected from the following sources:
5.1. Direct Collection From The Data Subject
- BESTARION may collect personal data directly from the data subject when:
- The data subject submits an application, participates in an interview or other recruitment activities
- The employee provides information during the execution and performance of the labor contract
- Customers, partners or their representatives provide information during exchanges, execution and performance of contracts
- Users send requests, feedback or contact BESTARION via email, phone, website or other communication channels
- The data subject registers to participate in events, seminars, training programs or other activities organized by BESTARION
- Shareholders provide information when registering share ownership, transferring shares, or attending or authorizing a representative to attend the General Meeting of Shareholders
5.2. Collection From Public Sources Or Third Parties
BESTARION may collect personal data from other lawful sources, including:
- Recruitment sites, professional social networks or online platforms where the data subject has publicly disclosed information
- Recruitment partners, recruitment service providers or candidate referrers
- Customers, partners or related organizations, to the extent permitted by applicable law
- Other publicly available sources of information permitted to be accessed under the applicable law
5.3. Collection Through The Website And Information Technology Systems
When the data subject accesses the website, portal, or uses systems managed by BESTARION, BESTARION may automatically collect certain information, including:
- IP address
- Device type, operating system and browser
- Access time, access history and system log data
- Cookie data and similar tracking technologies
- Other technical information necessary for the purpose of operation, security and service improvement
5.4. Personal Data Provided By Customers
- In the course of providing software development, information technology or outsourcing services, BESTARION may receive personal data from Customers to carry out processing activities under the service contract and the Customer’s lawful instructions
- In these cases, BESTARION may act as the Personal Data Processor or as the Personal Data Controller and Processor, depending on the nature of the services provided and the agreement between the parties
5.5. Principles Of Personal Data Collection
BESTARION commits to collecting personal data only:
- In accordance with the notified processing purpose
- To the extent necessary for business operations and service provision
- On an appropriate legal basis as provided by applicable law
- Through transparent, lawful methods that ensure the rights of the data subject
6. Legal Basis For Data Processing
6.1. Legal Basis for Processing
BESTARION only processes personal data when there is a legal basis under Vietnamese law
Depending on the specific processing activity, processing may be based on the consent of the data subject or on cases where the law permits processing without consent
BESTARION may process personal data on one or more of the following grounds:
a) Consent of the data subject
BESTARION processes personal data on the basis of the data subject’s consent where required by law or where the processing does not fall under the cases permitted without consent. The collection, management and withdrawal of consent are carried out in accordance with Section 6.2 and 6.3 of this Policy.
b) Performance of a contract or measures requested by the data subject
BESTARION may process personal data when the processing is necessary to enter into, perform, amend or terminate a contract with the data subject, or to fulfill requests of the data subject prior to entering into a contract.
Examples include but are not limited to:
- Executing and performing labor contracts
- Executing and performing service contracts with customers
- Performing contracts with suppliers, partners or collaborators
- Carrying out transactions, payments and other obligations arising from contracts
c) Performance of obligations required by law
BESTARION may process personal data when the processing is necessary to perform obligations required by law or by lawful requests of competent state authorities.
Including but not limited to:
- Performing obligations relating to labor, social insurance, health insurance, and tax
- Storing records as required by applicable law
- Providing information at the request of competent state authorities
- Performing obligations relating to accounting, auditing, anti-money laundering, cybersecurity, personal data protection or other legal obligations
d) Other cases as prescribed by law
BESTARION may process personal data in other cases permitted or required by applicable law without the consent of the data subject, including but not limited to cases aimed at protecting the life or health of the data subject or others in an emergency situation; serving the operations of state authorities as prescribed by applicable law; or other cases prescribed by the law on personal data protection.
In all cases, BESTARION commits to processing personal data only to the extent necessary, for the defined purpose, applying appropriate security measures and ensuring the lawful rights and interests of the data subject in accordance with applicable law.
6.2. Collection Of Consent
BESTARION only collects the consent of the data subject in cases required by applicable law or where consent is the legal basis for processing personal data.
Consent is collected in a form appropriate to each data processing activity, ensuring that the consent is expressed voluntarily, clearly, specifically and in a manner that can be demonstrated.
Depending on the specific case, BESTARION may apply one or more of the following forms of collecting consent:
| Form of expressing consent | Example / Description |
|---|---|
| In writing | Signature on a paper document; electronic signature or other lawful forms of signing an electronic document expressing consent |
| Verbally | Clearly expressing consent verbally (e.g., by phone, in person, online meeting). Should be recorded or otherwise evidenced to serve as proof of consent |
| By affirmative action | The data subject proactively performs an action expressing consent, such as ticking (opting in) a box that is not pre-checked, clicking the “Agree” button, confirming on an application, or performing a similar action |
| By electronic means | Confirmation via email, OTP, digital signature, electronic signature or other electronic authentication methods as provided by applicable law |
| Other forms | Any other form that can demonstrate the voluntary, clear, specific and unambiguous intent of the data subject to consent to the processing of personal data |
Table 10: Forms of expressing consent
BESTARION retains evidence of the data subject’s consent for as long as necessary to demonstrate compliance with legal obligations.
6.3. Withdrawal Of Consent
The data subject has the right to withdraw consent to the processing of their personal data at any time by sending a request to BESTARION through the request channels published by the Company.
The withdrawal of consent does not affect the lawfulness of personal data processing activities carried out before the withdrawal takes effect.
Withdrawal of consent may result in BESTARION being unable to continue providing certain products or services or carrying out certain activities that depend on the data subject’s consent. In such cases, BESTARION will notify the data subject of the relevant effects (if any).
The receipt and handling of requests to withdraw consent are carried out in accordance with the provisions in Section 13 “Rights of the data subject & procedure for exercising rights” of this Policy.
7. Sharing & Disclosure Of Personal Data
BESTARION may share personal data with third parties to the extent necessary to carry out the processing purposes set out in this Policy and in accordance with applicable law.
7.1. Service Providers
BESTARION may share personal data with service providers that support BESTARION’s business operations, including but not limited to:
- Providers of information technology infrastructure, cloud computing services, data storage, email, source code management, customer relationship management, collaboration and productivity
- Providers of recruitment platforms, candidate sourcing and recruitment management
- Providers of data analytics, marketing, survey and electronic communication services
- Providers of payment, accounting, audit, insurance, healthcare or event organization services
- Legal consultancies, professional advisors, auditors or other support service providers
BESTARION requires service providers to process personal data only in accordance with BESTARION’s instructions, to apply appropriate security measures and to comply with personal data protection obligations under applicable law.
7.2. Customers And Business Partners
In the course of providing software development, information technology or related services, BESTARION may share the competency profiles, professional information and necessary personal data of personnel expected to participate in a project with the customer, in order to serve the assessment, selection, resource allocation and personnel management during contract performance. This sharing is always limited to what is necessary and complies with the law on personal data protection:
- Assessing the professional qualifications, skills, experience and suitability of personnel for the position or project
- Carrying out assessment, interviewing, competency verification activities or personnel selection procedures at the reasonable request of the customer
- Assigning, coordinating, managing and deploying personnel to serve the performance of the contract or project
- Managing progress, service quality, information security, compliance and project governance requirements under the contract or agreement with the customer
- Performing other obligations arising from the contract or at the lawful request of the customer in connection with the provision of services
BESTARION only shares personal data on a lawful basis and in accordance with applicable laws. Where the law requires the consent of the data subject, BESTARION will share the data only after having obtained the data subject’s valid consent as required.
BESTARION requires data recipients to process personal data only to the extent necessary for the defined purpose and to apply appropriate personal data protection measures in accordance with the law.
7.3. Parent Company, Subsidiaries And Affiliated Companies
BESTARION may share personal data with the parent company, subsidiaries or affiliated companies within the same group in order to serve administrative, operational, business support, human resource management, information system management purposes or other lawful purposes consistent with this Policy and applicable law.
7.4. Professional Advisors And Organizations Providing Professional Services (Professional Advisors)
BESTARION may share personal data with professional service providers to support administrative, operational, legal compliance activities or to protect the Company’s lawful rights and interests, including but not limited to:
- Law offices, law firms or legal consultants
- Independent auditing firms, accountants, tax consultants or financial advisors
- Certification, assessment or compliance inspection organizations
- Other consulting organizations serving BESTARION’s lawful operations
Personal data is shared only to the extent necessary for the above organizations to provide services or perform their assigned tasks. BESTARION requires these organizations to implement appropriate personal data protection measures, ensure the confidentiality of personal data, and process data only for the defined purpose or as required by applicable law.
7.5. Competent State Authorities
BESTARION may disclose or provide personal data when such provision is required by applicable law, requested by competent state authorities or competent authorities or judicial authorities to protect the lawful rights and interests of BESTARION, customers, partners or other related parties.
7.6. Business Transactions
In the case of a merger, consolidation, restructuring, business transfer, project transfer or similar transaction, personal data may be transferred to the transferee in accordance with applicable law and on the basis of appropriate personal data protection measures.
8. Transfer Of Data Overseas
In the course of its operations, BESTARION may transfer personal data outside the territory of Vietnam or allow personal data to be stored, processed or accessed from abroad in the following cases:
- Using cloud computing, data storage, email, online meeting, customer relationship management (CRM) services or other information technology platforms provided by foreign service providers
- Using data analytics, marketing, survey, electronic communication services or operational support tools whose servers or processing infrastructure are located outside Vietnam
- Sharing personal data with customers, partners, affiliated companies or service providers abroad to the extent necessary to provide services, perform contracts, or serve the notified processing purposes
- Sharing professional profiles, competency information or related data of candidates, employees or collaborators with foreign customers to the extent necessary to carry out assessment, selection or resource deployment activities for a project, in accordance with applicable law
- Booking hotel rooms, registering to attend exhibitions / conferences abroad directly with a foreign service provider
In cases required by applicable law, BESTARION will prepare a Cross-Border Personal Data Transfer Impact Assessment Dossier and enter into a legally binding agreement with the foreign data recipient before carrying out the data transfer.
BESTARION applies appropriate technical, organizational and contractual measures to ensure that personal data is protected throughout its transmission, storage and processing by data recipients.
9. Personal Data Retention Period
BESTARION retains data for as long as necessary for the stated purpose and in accordance with applicable law. Below are the retention periods for each group of data subjects:
| Type of data | Retention period |
|---|---|
| Personnel records, labor contracts and related records | At least 10 years from the date of termination of the employment / cooperation relationship, or a longer period if required by applicable law |
| Payroll, accounting data and financial documents | Retained for 10 years, or longer if required by applicable law |
| Social insurance, health insurance, unemployment insurance and personal income tax records | 10 years or as prescribed by the retention period required by applicable law |
| Records of candidates not recruited | 02 years from the end of the recruitment process, or as consented to by the candidate |
| Health check-up results and related welfare records | 05 years or as required by applicable sector-specific laws |
| System logs and information security data | In accordance with the Company’s log retention policy, up to 02 years or as required by applicable law or contract |
| Data from the CCTV surveillance system | Not exceeding 90 days, except where needed for incident investigation, dispute resolution, or at the request of a competent authority |
| Register of shareholders and shareholder-related records | Throughout the period of share ownership and for a minimum of 10 years following the termination of shareholder status, in accordance with the Law on Accounting |
| Personal data of customers, suppliers or partners who are individuals | For as long as the transactional relationship is maintained, plus an additional 10 years after completion of the relevant tax inspection or audit |
| Contracts, transaction records and documents relating to customers, suppliers or partners that are organizations / enterprises | Retained for as long as necessary to serve business administration, look up transaction history, protect BESTARION’s lawful rights and interests, resolve disputes, or meet legal requirements |
| Marketing and communications data | Until the data subject withdraws consent or 03 years after the last interaction |
Table 11: Data retention
10. Deletion And Destruction Of Personal Data
BESTARION deletes, destroys or anonymizes personal data in the following cases:
- The personal data is no longer necessary for the notified processing purpose
- The retention period prescribed by applicable law or BESTARION’s retention policy has expired
- The data subject requests deletion of personal data and BESTARION has no legal basis or lawful obligation to continue storing or processing the data
- The processing of personal data is no longer necessary or there is no longer a legal basis to continue it
- Other cases as prescribed by applicable law
Where personal data is processed in the course of providing services to a customer, the deletion or return of the data will be carried out in accordance with the agreement with the customer and relevant legal obligations.
BESTARION applies appropriate measures to ensure that personal data is deleted, destroyed or anonymized as required and cannot be used for unauthorized processing purposes once deletion has been completed.
11. Personal Data Protection Measures
BESTARION applies appropriate technical and organizational measures to protect personal data from unauthorized loss, access, use, disclosure, alteration or destruction throughout the process of collecting, storing, processing and transferring data.
11.1. Technical Measures
- Implementing appropriate security measures to protect personal data during transmission, storage and processing
- Implementing user authentication, access control and role-based authorization mechanisms, ensuring that only authorized persons with a legitimate work need may access personal data
- Applying information system protection measures such as firewalls, access control, and other security solutions to prevent unauthorized access and cyberattacks
- Recording, monitoring and analyzing system logs to detect, prevent and handle abnormal access or information security violations
- Performing periodic data backups and applying data recovery measures to ensure the availability, integrity and recoverability of the system
- Applying encryption or other appropriate technical protection measures to personal data during storage, transmission and processing, based on the nature of the data, the level of risk and the technical conditions of the system
- Conducting regular vulnerability assessments, applying security patches and technical risk management measures to minimize the risk of exploitation of system weaknesses
11.2. Organizational Measures
- Applying the principle of least-privilege access, ensuring that personal data is accessed only to the extent necessary to perform assigned work
- Only authorized employees, collaborators, contractors or third parties who are bound by confidentiality obligations are permitted to access and process personal data
- Conducting appropriate due diligence on data processors, suppliers or partners before sharing personal data or authorizing them to process it
- Issuing, maintaining and updating internal policies and procedures on personal data protection and information security
- Training and raising awareness among employees and related parties on personal data protection and information confidentiality obligations
- Conducting periodic assessments, monitoring and improvement of personal data protection measures to ensure effectiveness and legal compliance
11.3. Physical Protection Measures
BESTARION applies physical protection measures to prevent unauthorized access to areas, equipment or documents containing personal data, including:
- Controlling physical access, work areas and restricted areas
- Managing visitors and recording entry / exit information in accordance with the Company’s regulations
- Protecting servers, storage devices and assets containing personal data in controlled areas
- Storing paper records and documents containing personal data in a secure, access-controlled area
- Destroying documents, equipment or storage media containing personal data using appropriate procedures and methods to prevent unauthorized data recovery
11.4. Personal Data Incident Management
BESTARION maintains a process for managing and responding to incidents related to personal data. In the event that an incident affecting personal data is detected or suspected, BESTARION will implement the necessary handling measures to minimize risk. If the incident falls under a case requiring notification to related parties as prescribed by applicable law, BESTARION will notify the competent authority and / or the data subject
11.5. Sensitive Personal Data
For sensitive personal data as defined by applicable law, BESTARION applies enhanced protective measures commensurate with the level of risk, including strict access restrictions, close control over the processing, monitoring of access activities, encryption during storage or transmission (where appropriate), and application of specialized management procedures
11.6. Security Limitations
Although BESTARION applies appropriate protective measures to ensure the safety of personal data, no method of transmission over the Internet or method of electronic storage is completely secure
In the event of an incident beyond BESTARION’s reasonable control, the Company will implement necessary measures to limit damage, remediate the consequences and fulfill notification obligations as prescribed by applicable law
12. Children’s Privacy
BESTARION may collect and process the personal data of children to the extent necessary to implement welfare programs, employee well-being activities and other internal activities, including but not limited to:
- Managing dependents as required by applicable law
- Implementing insurance, healthcare or welfare programs for employees and their relatives
- Organizing activities for employees’ families such as International Children’s Day, Mid-Autumn Festival, travel, internal events or other recognition and support programs
- Performing other obligations or benefits related to dependents in accordance with applicable law or BESTARION’s policies
In cases required by applicable law, BESTARION will process children’s personal data on the basis of the consent of the parent or legal guardian, and will apply appropriate protective measures for children’s personal data
Parents or legal guardians may exercise, on behalf of the child, the rights related to personal data as prescribed by applicable law by contacting BESTARION via the email address: dataprivacy@bestarion.com
13. Rights Of The Data Subject & Procedure For Exercising Rights
13.1. Rights Of The Data Subject
Under the law on personal data protection, the data subject has the following rights with respect to their personal data:
- The right to be informed about the processing of their personal data
- The right to give or withdraw consent, and to request withdrawal of consent to the processing of personal data
- The right to access and request correction of personal data
- The right to request a copy, deletion, or restriction of processing of personal data; and to object to the processing of personal data
- The right to complain, denounce, initiate a lawsuit, and claim damages as prescribed by applicable law
- The right to request the competent authority or the agency, organization or individual involved in the processing of personal data to implement measures and solutions to protect their personal data as prescribed by applicable law
13.2. Method Of Submitting Requests
To exercise any of the above rights, the data subject may send a request to BESTARION through the following channels:
- Email: dataprivacy@bestarion.com
- Other request-receiving channels published by BESTARION from time to time (if any)
In the request, the data subject should provide all necessary information for BESTARION to have a basis for identifying and processing the request, including but not limited to:
- Full name
- Contact information
- Content of the request
- Related personal data or processing activity (if known)
- Other supporting documents or information (if any)
13.3. Receiving And Processing Requests:
After receiving the request, BESTARION will:
- Receive and record the data subject’s request
- Verify the identity of the requester when necessary to protect the lawful rights and interests of the data subject and to prevent unauthorized access, requests or disclosure of data
- Assess the content of the request, the legal basis, and the scope of the related personal data
- Coordinate with relevant departments or personal data processors to handle the request
- Notify the data subject of the processing result as prescribed by applicable law
13.4. Cases Of Refusal Or Restriction Of Request Fulfillment
BESTARION may refuse or restrict the fulfillment of part or all of the data subject’s request in cases permitted by applicable law, including but not limited to:
- The identity of the requester cannot be verified
- The request does not fall within the scope of the data subject’s rights as prescribed by applicable law
- Continued processing of the personal data is necessary to perform a legal obligation, perform a contract, protect the lawful rights and interests of BESTARION or of a third party, or falls under other cases permitted by applicable law
- The request is repetitive in nature, unfounded, or seriously affects the lawful rights and interests of BESTARION or of other organizations or individuals
- Other cases as prescribed by applicable law
In case of refusal or restriction of the request, BESTARION will notify the data subject of the reason for the refusal or restriction, unless otherwise provided by applicable law.
14. Contact
Contact information: If you have any questions, requests or complaints related to this Privacy Policy or Bestarion’s processing of personal data, please contact the Personal Data Protection Department:
- Company: Bestarion Software Joint Stock Company
- Office address: 3rd Floor, QTSC Building 1, Lot 34, Street No. 14, Quang Trung Software City, Trung My Tay Ward, Ho Chi Minh City
- Phone: (+84) 28 37 154 152
- Email: dataprivacy@bestarion.com
Bestarion will receive, consider and respond to requests within the timeframe prescribed by applicable laws
15. Effectiveness And Amendment Of The Policy
- Bestarion may update or amend this Privacy Policy from time to time to reflect changes in business operations, personal data processing methods, or the requirements of applicable law
- The updated version will be published on Bestarion’s website or through other appropriate means. For material changes that significantly affect the rights and interests of the data subject, Bestarion will provide notice in an appropriate form before such changes take effect, unless otherwise provided by applicable law
- Bestarion recommends that data subjects regularly monitor this Policy to remain informed on the latest information regarding the processing and protection of personal data
- Effective date: July 01, 2026
- This Policy takes effect from the date stated above and supersedes all previously issued versions of the Privacy Policy
1. Giới thiệu
1.1. Mục Đích
- Công ty Cổ phần Phần mềm Bestarion (“Chúng tôi”, “Công ty”, “Bestarion”) cam kết bảo vệ quyền riêng tư và dữ liệu cá nhân của bạn. Chính sách này mô tả cách chúng tôi thu thập, sử dụng, xử lý và chuyển giao dữ liệu của bạn, cũng như các quyền của bạn liên quan đến dữ liệu cá nhân
- Chính sách này được xây dựng nhằm tuân thủ Luật Bảo vệ Dữ liệu Cá nhân số 91/2025/QH15 và Nghị định 356/2025/NĐ-CP có hiệu lực từ ngày 01/01/2026, cùng các quy định pháp luật hiện hành có liên quan tại Việt Nam
- Trong trường hợp có sự khác biệt hoặc xung đột giữa các văn bản pháp luật nêu trên, việc áp dụng sẽ tuân theo quy định pháp luật hiện hành có hiệu lực tại từng thời điểm
- Đối với các vấn đề chưa được quy định trong tài liệu này, việc xử lý dữ liệu cá nhân sẽ được thực hiện theo quy định của pháp luật Việt Nam có liên quan
1.2. Định nghĩa
Trong Chính sách này, các thuật ngữ được định nghĩa theo Luật 91/2025/QH15 và NĐ 356/2025/NĐ-CP:
- Dữ liệu cá nhân (DLCN) là dữ liệu số hoặc thông tin dưới dạng khác xác định hoặc giúp xác định một con người cụ thể, bao gồm: dữ liệu cá nhân cơ bản và dữ liệu cá nhân nhạy cảm. Dữ liệu cá nhân sau khi khử nhận dạng không còn là dữ liệu cá nhân
- Dữ liệu cá nhân cơ bản là dữ liệu cá nhân phản ánh các yếu tố nhân thân, lai lịch phổ biến, thường xuyên sử dụng trong các giao dịch, quan hệ xã hội, thuộc danh mục do Chính phủ ban hành
- Dữ liệu cá nhân nhạy cảm là dữ liệu cá nhân gắn liền với quyền riêng tư của cá nhân, khi bị xâm phạm sẽ gây ảnh hưởng trực tiếp đến quyền, lợi ích hợp pháp của cơ quan, tổ chức, cá nhân, thuộc danh mục do Chính phủ ban hành
- Bảo vệ dữ liệu cá nhân là việc cơ quan, tổ chức, cá nhân sử dụng lực lượng, phương tiện, biện pháp để phòng, chống hoạt động xâm phạm dữ liệu cá nhân
- Chủ thể dữ liệu cá nhân là người được dữ liệu cá nhân phản ánh
- Xử lý dữ liệu cá nhân là hoạt động tác động đến dữ liệu cá nhân, bao gồm một hoặc nhiều hoạt động như sau: thu thập, phân tích, tổng hợp, mã hóa, giải mã, chỉnh sửa, xóa, hủy, khử nhận dạng, cung cấp, công khai, chuyển giao dữ liệu cá nhân và hoạt động khác tác động đến dữ liệu cá nhân
- Bên kiểm soát dữ liệu cá nhân là cơ quan, tổ chức, cá nhân quyết định mục đích và phương tiện xử lý dữ liệu cá nhân
- Bên xử lý dữ liệu cá nhân là cơ quan, tổ chức, cá nhân thực hiện việc xử lý dữ liệu cá nhân theo yêu cầu của bên kiểm soát dữ liệu cá nhân hoặc bên kiểm soát và xử lý dữ liệu cá nhân thông qua hợp đồng
- Bên kiểm soát và xử lý dữ liệu cá nhân là cơ quan, tổ chức, cá nhân quyết định mục đích, phương tiện và trực tiếp xử lý dữ liệu cá nhân
- Bên thứ ba là tổ chức, cá nhân ngoài chủ thể dữ liệu cá nhân, bên kiểm soát dữ liệu cá nhân, bên kiểm soát và xử lý dữ liệu cá nhân, bên xử lý dữ liệu cá nhân tham gia vào việc xử lý dữ liệu cá nhân theo quy định của pháp luật
- Nhân Viên gồm toàn bộ cá nhân có hoặc đã có quan hệ lao động hoặc quan hệ làm việc với Công ty, bao gồm nhưng không giới hạn ở nhân viên chính thức, nhân viên thử việc, thực tập sinh và nhân viên đã nghỉ việc
2. Nguyên Tắc Bảo Vệ Dữ Liệu Cá Nhân
- Tuân thủ quy định của Hiến pháp, quy định của Luật này và quy định khác của pháp luật có liên quan
- Chỉ được thu thập, xử lý dữ liệu cá nhân đúng phạm vi, mục đích cụ thể, rõ ràng, bảo đảm tuân thủ quy định của pháp luật
- Bảo đảm tính chính xác của dữ liệu cá nhân và được chỉnh sửa, cập nhật, bổ sung khi cần thiết; được lưu trữ trong khoảng thời gian phù hợp với mục đích xử lý dữ liệu cá nhân, trừ trường hợp pháp luật có quy định khác
- Thực hiện đồng bộ có hiệu quả các biện pháp, giải pháp về thể chế, kỹ thuật, con người phù hợp để bảo vệ dữ liệu cá nhân
- Chủ động phòng ngừa, phát hiện, ngăn chặn, đấu tranh, xử lý kịp thời, nghiêm minh mọi hành vi vi phạm pháp luật về bảo vệ dữ liệu cá nhân
- Bảo vệ dữ liệu cá nhân gắn với bảo vệ lợi ích quốc gia, dân tộc, phục vụ phát triển kinh tế – xã hội, bảo đảm quốc phòng, an ninh và đối ngoại; bảo đảm hài hòa giữa bảo vệ dữ liệu cá nhân với bảo vệ quyền, lợi ích hợp pháp của cơ quan, tổ chức, cá nhân
3. Dữ Liệu Cá Nhân Thu Thập
3.1. Khách Truy Cập Website / Website Visitors
- Dữ liệu nhận dạng: Họ tên
- Dữ liệu liên hệ: Email, số điện thoại
- Dữ liệu liên lạc: Nội dung gửi qua form liên hệ, email, live chat
- Dữ liệu kỹ thuật: Địa chỉ IP, loại trình duyệt, cookie và dữ liệu về hành vi sử dụng trên website nhằm tối ưu hóa trải nghiệm người dùng. Vui lòng tham khảo Chính sách Cookie của Bestarion để biết thêm chi tiết
- Trang web của bên thứ ba: Trang web của Bestarion có thể bao gồm các liên kết đến các trang web, plug-in và ứng dụng của bên thứ ba. Việc nhấp vào các liên kết này có thể cho phép bên thứ ba thu thập hoặc chia sẻ dữ liệu của bạn. Bestarion không kiểm soát các trang web này và không chịu trách nhiệm về các điều khoản bảo mật của bên thứ ba. Khi rời khỏi trang web của Bestarion (https://bestarion.com/), Bestarion khuyến khích bạn nên đọc các thông báo bảo mật khi truy cập các trang web khác
3.2. Ứng Viên
- Bestarion sẽ thu thập các thông tin sau đây trong phạm vi cần thiết cho việc cung cấp dịch vụ tuyển dụng, từ các nguồn sau:
- Thông tin do bạn trực tiếp cung cấp; hoặc
- Thông tin liên quan đến Ứng viên được thu thập thông qua:
(i) các tin tuyển dụng do Bestarion đăng tải trên các nền tảng tuyển dụng và mạng xã hội
(ii) các nền tảng tuyển dụng trực tuyến và các hồ sơ trực tuyến công khai do Ứng viên chia sẻ mà Bestarion tìm thấy trong quá trình tuyển dụng; hoặc
(iii) bất kỳ kênh liên lạc nào khác mà Ứng viên sử dụng để tương tác với Bestarion
- Thông tin được thu thập bao gồm:
- Thông tin cá nhân — các trường định danh và liên hệ cơ bản: họ tên, ngày sinh, giới tính, quốc tịch, địa chỉ, SĐT, email, ảnh, và lịch sử học tập
- Hồ sơ nghề nghiệp — toàn bộ thông tin chuyên môn: CV, kinh nghiệm, kỹ năng, lương kỳ vọng, portfolio, thông tin hồ sơ nghề nghiệp công khai (nếu có), lịch sử làm việc
- Người tham chiếu: thông tin liên lạc mà ứng viên cung cấp: họ tên, chức vụ, email, SĐT, và nhận xét / đánh giá của họ
- Đánh giá & phỏng vấn — toàn bộ dữ liệu tuyển dụng: kết quả test, lịch phỏng vấn, ghi chú, điểm đánh giá, vòng phỏng vấn, và người phỏng vấn
3.3. Nhân Viên, Cộng Tác Viên
3.3.1. Dữ Liệu Cơ Bản
| Dữ liệu | Nội dung chi tiết |
|---|---|
| Thông tin định danh cá nhân |
|
| Thông tin liên hệ |
|
| Thông tin nghề nghiệp |
|
| Thông tin tuyển dụng |
|
| Dữ liệu thời gian & hiệu suất |
|
| Dữ liệu hình ảnh thông thường |
|
| Thông tin tài khoản số |
|
| Dữ liệu người thân / phụ thuộc |
|
Table 1: Dữ liệu cơ bản
3.3.2. Dữ Liệu Nhạy Cảm
| Dữ liệu | Nội dung chi tiết |
|---|---|
| Thông tin định danh cá nhân |
|
| Thông tin tài chính |
|
| Thông tin sức khỏe |
|
| Dữ liệu sinh trắc học |
|
| Thông tin về xử lý vi phạm |
|
Table 2: Dữ liệu nhạy cảm
3.4. Khách Hàng Tiềm Năng, Khách Hàng
Bestarion chủ yếu xử lý dữ liệu cá nhân của người đại diện, người được ủy quyền, đầu mối liên hệ hoặc nhân sự của khách hàng, khách hàng tiềm năng trong phạm vi cần thiết để thiết lập, duy trì và thực hiện quan hệ kinh doanh.
Tùy thuộc vào mục đích xử lý dữ liệu, Bestarion có thể thu thập và xử lý các loại dữ liệu cá nhân sau:
- Thông tin nhận dạng và thông tin liên hệ của khách hàng hoặc người đại diện khách hàng, bao gồm: họ tên, chức vụ / chức danh, đơn vị công tác, email, số điện thoại công việc và các thông tin liên hệ khác
- Thông tin liên quan đến tổ chức nơi cá nhân làm việc, bao gồm: tên doanh nghiệp, mã số thuế, địa chỉ, website, lĩnh vực hoạt động và thông tin kinh doanh liên quan.Thông tin được cung cấp trong quá trình gửi yêu cầu, đề nghị báo giá, đăng ký sử dụng dịch vụ, trao đổi thông tin hoặc liên hệ với Bestarion
- Thông tin liên quan đến việc đàm phán, ký kết, thực hiện và quản lý hợp đồng, thỏa thuận hoặc giao dịch giữa khách hàng và Bestarion
- Thông tin thanh toán, hóa đơn, công nợ và các thông tin cần thiết để thực hiện các giao dịch tài chính liên quan đến sản phẩm hoặc dịch vụ của Bestarion
- Thông tin liên quan đến việc sử dụng sản phẩm, dịch vụ, yêu cầu hỗ trợ, phản hồi, khiếu nại hoặc khảo sát mức độ hài lòng của khách hàng
- Các dữ liệu cá nhân khác được khách hàng hoặc khách hàng tiềm năng cung cấp trong quá trình thiết lập và duy trì quan hệ với Bestarion
3.5. Nhà Cung Cấp, Đối Tác & Nhà Thầu
Tùy thuộc vào mục đích xử lý dữ liệu, Bestarion có thể thu thập và xử lý các loại dữ liệu cá nhân sau:
- Thông tin nhận dạng và thông tin liên hệ của người đại diện, đầu mối liên hệ hoặc nhân sự được nhà cung cấp, đối tác chỉ định, bao gồm: họ tên, chức vụ / chức danh, đơn vị công tác, email, số điện thoại công việc và các thông tin liên hệ khác
- Thông tin liên quan đến tổ chức nơi cá nhân làm việc, bao gồm: tên doanh nghiệp, mã số thuế, địa chỉ, website, lĩnh vực hoạt động và thông tin kinh doanh liên quan. Thông tin được cung cấp trong quá trình trao đổi, đánh giá năng lực, thẩm định, lựa chọn nhà cung cấp hoặc thiết lập quan hệ hợp tác với Bestarion
- Thông tin liên quan đến việc đàm phán, ký kết, thực hiện, quản lý hoặc chấm dứt hợp đồng, thỏa thuận hoặc giao dịch kinh doanh với Bestarion
- Thông tin thanh toán, hóa đơn, tài khoản thanh toán, công nợ và các thông tin cần thiết để thực hiện các giao dịch tài chính giữa các bên
- Thông tin liên quan đến việc cung cấp hàng hóa, dịch vụ, hỗ trợ kỹ thuật, thực hiện dự án hoặc các nghĩa vụ khác theo hợp đồng hoặc thỏa thuận
- Thông tin phục vụ hoạt động đánh giá hiệu suất, tuân thủ, kiểm toán, quản lý rủi ro và bảo đảm an toàn thông tin theo yêu cầu của Bestarion hoặc theo quy định pháp luật
- Các dữ liệu cá nhân khác được nhà cung cấp hoặc đối tác cung cấp trong quá trình thiết lập và duy trì quan hệ hợp tác với Bestarion
3.6. CỔ ĐÔNG
Bestarion có thể thu thập và xử lý dữ liệu cá nhân của cổ đông cho các mục đích sau:
- Lập, cập nhật và quản lý Sổ đăng ký cổ đông theo Điều 122 Luật Doanh nghiệp 2020
- Triệu tập, tổ chức Đại hội đồng cổ đông và xác nhận tư cách tham dự theo Điều 139 Luật Doanh nghiệp 2020
- Chi trả cổ tức và thực hiện nghĩa vụ kê khai, khấu trừ thuế thu nhập cá nhân theo quy định pháp luật thuế hiện hành
- Thực hiện các nghĩa vụ kế toán, lưu trữ hồ sơ theo Luật Kế toán
- Cung cấp thông tin cho cơ quan nhà nước có thẩm quyền, tổ chức lưu ký / trung tâm lưu ký chứng khoán (nếu có) khi có yêu cầu hợp pháp
4. Mục Đích Xử Lý Dữ Liệu Cá Nhân
Bestarion chỉ sử dụng dữ liệu cá nhân cho các mục đích được nêu dưới đây với căn cứ pháp lý hợp lệ theo Luật 91/2025/QH15:
4.1. Khách Truy Cập Website
Bestarion có thể thu thập và xử lý dữ liệu cá nhân của người dùng Website cho các mục đích sau:
- Cung cấp, vận hành, duy trì và cải thiện Website của Bestarion
- Quản lý và phản hồi các yêu cầu, câu hỏi, phản hồi hoặc thông tin được gửi thông qua các biểu mẫu liên hệ hoặc các chức năng khác trên Website
- Phân tích việc sử dụng Website nhằm đánh giá hiệu quả hoạt động, cải thiện trải nghiệm người dùng và nâng cao chất lượng nội dung, sản phẩm và dịch vụ được cung cấp trên Website
- Đảm bảo an toàn, bảo mật và tính toàn vẹn của Website, bao gồm việc phát hiện, ngăn ngừa và xử lý các hành vi truy cập trái phép, gian lận, tấn công mạng hoặc các hoạt động có thể ảnh hưởng đến Website và hệ thống thông tin của Bestarion
- Quản lý việc đăng ký nhận bản tin, tài liệu, sự kiện, hội thảo hoặc các thông tin khác do Bestarion cung cấp thông qua Website
- Thực hiện các hoạt động tiếp thị, truyền thông hoặc quảng bá sản phẩm, dịch vụ của Bestarion theo quy định của pháp luật hiện hành
- Tuân thủ các nghĩa vụ pháp lý, yêu cầu của cơ quan nhà nước có thẩm quyền hoặc các quy định pháp luật áp dụng đối với Bestarion
4.2. Ứng Viên
Bestarion có thể thu thập và xử lý dữ liệu cá nhân của ứng viên cho các mục đích sau:
| Hoạt động | Mục đích xử lý dữ liệu cá nhân |
|---|---|
| Tìm nguồn ứng viên và tiếp nhận hồ sơ | Tìm kiếm ứng viên thông qua các nền tảng tuyển dụng, mạng xã hội nghề nghiệp, chương trình giới thiệu nội bộ và các nguồn hợp pháp khác; tiếp nhận và quản lý hồ sơ ứng tuyển |
| Sàng lọc và phỏng vấn | Đánh giá năng lực, kinh nghiệm, trình độ chuyên môn và mức độ phù hợp của ứng viên đối với vị trí tuyển dụng |
| Kiểm tra thông tin ứng viên | Xác minh thông tin do ứng viên cung cấp, thực hiện kiểm tra người tham chiếu hoặc các hoạt động thẩm tra phù hợp theo quy định pháp luật |
| Chia sẻ hồ sơ cho khách hàng | Chia sẻ hồ sơ ứng viên cho khách hàng hoặc đối tác có nhu cầu tuyển dụng hoặc sử dụng dịch vụ IT Staffing khi có căn cứ pháp lý phù hợp và / hoặc sự đồng ý của ứng viên theo quy định pháp luật |
| Gửi thư mời nhận việc và tiếp nhận nhân sự mới | Chuẩn bị thư mời nhận việc, ký kết hợp đồng, hoàn tất thủ tục tiếp nhận và thiết lập hồ sơ nhân sự |
| Quản lý nguồn ứng viên tiềm năng | Lưu trữ hồ sơ ứng viên để xem xét cho các cơ hội tuyển dụng trong tương lai theo quy định pháp luật và trên cơ sở sự đồng ý của ứng viên khi cần thiết |
Table 3: Hoạt động và mục đích thu thập và xử lý dữ liệu cá nhân của ứng viên
4.3. Nhân Viên, Cộng Tác Viên
Bestarion có thể thu thập và xử lý dữ liệu cá nhân của nhân viên và cộng tác viên cho các mục đích sau:
4.3.1. Quản Lý Nhân Sự
| Hoạt động | Mục đích xử lý dữ liệu cá nhân |
|---|---|
| Quản lý hồ sơ nhân sự | Quản lý thông tin cá nhân, hồ sơ lao động, cơ cấu tổ chức, chức danh và thông tin liên hệ nội bộ |
| Quản lý hiệu suất làm việc | Thiết lập mục tiêu, đánh giá hiệu suất, đánh giá năng lực, xem xét thăng chức, điều chuyển hoặc điều chỉnh thu nhập |
| Quản lý nguồn lực dự án | Phân bổ nhân sự, quản lý kỹ năng, kinh nghiệm, năng lực và khả năng đáp ứng yêu cầu dự án hoặc khách hàng |
| Quản lý cộng tác viên | Quản lý hợp đồng cộng tác, phạm vi công việc, hiệu suất và nghĩa vụ liên quan |
| Công tác và làm việc với khách hàng | Quản lý việc đi công tác, onsite khách hàng, đặt vé, lưu trú, visa và các thủ tục liên quan |
Table 4: Hoạt động và mục đích thu thập và xử lý dữ liệu cá nhân của nhân viên, cộng tác viên
4.3.2. Lương, Phúc Lợi Và Hành Chính Nhân Sự
| Hoạt động | Mục đích xử lý dữ liệu cá nhân |
|---|---|
| Quản lý hồ sơ và hợp đồng | Lưu trữ và quản lý hợp đồng lao động, phụ lục hợp đồng, quyết định nhân sự và các hồ sơ liên quan |
| Quản lý chấm công | Ghi nhận thời gian làm việc, làm thêm giờ, nghỉ phép, làm việc từ xa và các chế độ lao động khác |
| Quản lý lương và thu nhập | Tính lương, thưởng, phụ cấp, khấu trừ, thanh toán thu nhập và quyết toán cuối kỳ |
| Bảo hiểm bắt buộc | Thực hiện các thủ tục liên quan đến bảo hiểm xã hội, bảo hiểm y tế, bảo hiểm thất nghiệp và các chế độ lao động theo quy định |
| Thuế thu nhập cá nhân | Đăng ký mã số thuế, người phụ thuộc, khấu trừ và quyết toán thuế thu nhập cá nhân |
| Phúc lợi và chăm sóc sức khỏe | Quản lý bảo hiểm sức khỏe, khám sức khỏe định kỳ, chương trình phúc lợi và hỗ trợ nhân viên |
| Kỷ luật và quan hệ lao động | Xử lý vi phạm, giải quyết khiếu nại, tranh chấp lao động và các vấn đề liên quan đến quan hệ lao động |
| Chấm dứt hợp tác hoặc nghỉ việc | Thực hiện thủ tục bàn giao, quyết toán quyền lợi, thu hồi tài sản và đóng hồ sơ nhân sự |
| Tuân thủ nghĩa vụ pháp lý | Thực hiện các nghĩa vụ theo quy định pháp luật và yêu cầu của cơ quan nhà nước có thẩm quyền |
Table 5: Lương, phúc lợi và hành chính nhân sự
4.3.3. Đào Tạo Và Phát Triển Năng Lực
| Hoạt động | Mục đích xử lý dữ liệu cá nhân |
|---|---|
| Khảo sát nhu cầu đào tạo | Xác định nhu cầu học tập và phát triển năng lực của nhân viên |
| Quản lý đào tạo | Tổ chức, đăng ký và quản lý các chương trình đào tạo nội bộ hoặc bên ngoài |
| Hệ thống đào tạo trực tuyến | Tạo tài khoản học tập, theo dõi tiến độ, kết quả và lịch sử đào tạo |
| Quản lý chứng chỉ | Theo dõi chứng chỉ nghề nghiệp, hoàn phí đào tạo và các chương trình hỗ trợ học tập |
| Đánh giá hiệu quả đào tạo | Thu thập phản hồi và đánh giá hiệu quả áp dụng sau đào tạo |
Table 6: Đào tạo và phát triển nhân lực
4.3.4. Quản Lý CNTT Và An Toàn Thông Tin
| Hoạt động | Mục đích xử lý dữ liệu cá nhân |
|---|---|
| Quản lý tài khoản người dùng | Tạo, quản lý, thay đổi hoặc thu hồi tài khoản truy cập hệ thống, ứng dụng và dịch vụ CNTT |
| Quản lý thiết bị CNTT | Cấp phát, theo dõi, bảo trì và thu hồi thiết bị phục vụ công việc |
| Giám sát , bảo vệ hệ thống và nơi làm việc | Ghi nhận nhật ký truy cập, giám sát hoạt động hệ thống, phát hiện và xử lý sự cố an toàn thông tin |
| Điều tra và xử lý vi phạm | Điều tra các hành vi vi phạm chính sách, quy định nội bộ hoặc các sự cố liên quan đến bảo mật thông tin |
Table 7: Quản lý CNTT và an toàn thông tin
4.3.5. Tuân Thủ Pháp Luật
Bestarion xử lý dữ liệu cá nhân của nhân viên, cộng tác viên nhằm đáp ứng các nghĩa vụ theo quy định của pháp luật và yêu cầu của cơ quan nhà nước có thẩm quyền, bao gồm nhưng không giới hạn:
- Thực hiện nghĩa vụ về lao động, tiền lương, bảo hiểm xã hội, bảo hiểm y tế, bảo hiểm thất nghiệp, thuế thu nhập cá nhân và các nghĩa vụ tài chính khác
- Thực hiện các nghĩa vụ về an toàn, vệ sinh lao động, phòng cháy chữa cháy, an ninh mạng, bảo vệ dữ liệu cá nhân và các quy định pháp luật có liên quan
- Lưu trữ hồ sơ, tài liệu theo thời hạn do pháp luật quy định
- Cung cấp thông tin, tài liệu hoặc phối hợp với cơ quan nhà nước có thẩm quyền khi có yêu cầu hợp pháp
- Thiết lập, thực hiện hoặc bảo vệ quyền và lợi ích hợp pháp của Bestarion trong quá trình giải quyết khiếu nại, tranh chấp, tố tụng hoặc các thủ tục pháp lý khác
4.3.6. Các Mục Đích Nội Bộ Khác
Bestarion có thể xử lý dữ liệu cá nhân của nhân viên, cộng tác viên cho các mục đích quản trị, vận hành và phát triển doanh nghiệp khác, phù hợp với quy định của pháp luật, bao gồm nhưng không giới hạn:
- Quản trị hoạt động nội bộ, lập kế hoạch nguồn nhân lực và quản lý vận hành doanh nghiệp
- Thực hiện kiểm tra, đánh giá nội bộ, quản lý rủi ro, kiểm toán nội bộ và bảo đảm tuân thủ các chính sách, quy trình của Công ty
- Xây dựng, cải tiến quy trình làm việc, hệ thống thông tin, chính sách quản trị và các chương trình nâng cao hiệu quả hoạt động
- Thực hiện thống kê, phân tích, lập báo cáo quản trị và hoạch định chiến lược phát triển doanh nghiệp trên cơ sở dữ liệu đã được giới hạn truy cập hoặc áp dụng các biện pháp bảo vệ phù hợp
- Thực hiện các hoạt động truyền thông nội bộ, tổ chức sự kiện, chương trình gắn kết nhân viên và các hoạt động quản trị nội bộ khác phục vụ hoạt động hợp pháp của Bestarion
4.3.6.1. Employee Engagement – Gắn Kết Nhân Viên
| Hoạt động | Mục đích xử lý dữ liệu cá nhân |
|---|---|
| Khảo sát nhân viên | Đánh giá mức độ hài lòng, gắn kết và văn hóa doanh nghiệp |
| Tổ chức sự kiện nội bộ | Tổ chức hội nghị, teambuilding, hoạt động thể thao, văn hóa và các chương trình nội bộ khác |
| Quà tặng và hỗ trợ nhân viên | Quản lý các chương trình quà tặng, trợ cấp, hỗ trợ hiếu hỷ và các chương trình phúc lợi khác |
| Khen thưởng và vinh danh | Ghi nhận thành tích, trao thưởng và truyền thông nội bộ về các cá nhân hoặc tập thể tiêu biểu |
| Quan hệ nhân viên | Tiếp nhận, xử lý phản ánh, khiếu nại hoặc các yêu cầu hỗ trợ từ nhân viên |
Table 8: Gắn kết nhân viên
4.3.6.2. Employer Branding – Truyền Thông Thương Hiệu Tuyển Dụng
| Hoạt động | Mục đích xử lý dữ liệu cá nhân |
|---|---|
| Truyền thông nội bộ và bên ngoài | Đăng tải thông tin, hình ảnh hoặc nội dung liên quan đến hoạt động công ty và đội ngũ nhân sự |
| Chia sẻ câu chuyện nhân viên | Xây dựng bài viết, video hoặc nội dung giới thiệu kinh nghiệm làm việc và văn hóa doanh nghiệp |
| Sự kiện tuyển dụng | Tổ chức hoặc tham gia ngày hội việc làm, hội thảo nghề nghiệp và các hoạt động quảng bá tuyển dụng |
| Đại sứ thương hiệu | Quản lý các chương trình giới thiệu ứng viên, đại sứ thương hiệu và hoạt động quảng bá của nhân viên |
Table 9: Truyền thông thương hiệu tuyển dụng
Việc sử dụng hình ảnh, video, bài viết hoặc các dữ liệu cá nhân khác của nhân viên cho mục đích truyền thông, quảng bá hoặc tiếp thị sẽ được thực hiện trên cơ sở sự đồng ý của chủ thể dữ liệu hoặc căn cứ pháp lý phù hợp theo quy định của pháp luật.
4.4. Khách Hàng Tiềm Năng, Khách Hàng
Bestarion có thể thu thập và xử lý dữ liệu cá nhân của khách hàng và khách hàng tiềm năng cho các mục đích sau:
- Tiếp nhận, xử lý và phản hồi các yêu cầu về sản phẩm, dịch vụ, báo giá, đề xuất hợp tác hoặc các yêu cầu kinh doanh khác
- Đánh giá nhu cầu của khách hàng, xác định cơ hội kinh doanh và thực hiện các hoạt động bán hàng, tiếp thị và phát triển kinh doanh
- Thiết lập, quản lý và duy trì mối quan hệ với khách hàng và khách hàng tiềm năng thông qua các hệ thống quản lý quan hệ khách hàng (CRM) và các hoạt động chăm sóc khách hàng
- Đàm phán, ký kết, thực hiện, quản lý và gia hạn hợp đồng, thỏa thuận hoặc các cam kết kinh doanh với khách hàng
- Cung cấp sản phẩm, dịch vụ, hỗ trợ kỹ thuật, bảo trì, tư vấn hoặc các dịch vụ khác theo yêu cầu của khách hàng hoặc theo thỏa thuận giữa các bên
- Thực hiện các hoạt động quản lý dự án, quản lý chất lượng dịch vụ, hỗ trợ khách hàng và xử lý các yêu cầu, khiếu nại hoặc phản hồi của khách hàng
- Gửi thông tin về sản phẩm, dịch vụ, sự kiện, hội thảo, chương trình tiếp thị hoặc các nội dung khác có liên quan đến hoạt động kinh doanh của Bestarion theo quy định của pháp luật hiện hành
- Thực hiện khảo sát mức độ hài lòng của khách hàng, nghiên cứu thị trường, phân tích thống kê và các hoạt động nhằm nâng cao chất lượng sản phẩm, dịch vụ và trải nghiệm khách hàng
- Thực hiện các hoạt động kế toán, thanh toán, xuất hóa đơn, đối soát công nợ và các nghĩa vụ tài chính liên quan đến giao dịch với khách hàng
- Bảo vệ quyền và lợi ích hợp pháp của Bestarion, thiết lập, thực hiện hoặc bảo vệ các yêu cầu pháp lý; phòng ngừa, phát hiện và xử lý các hành vi gian lận, vi phạm hợp đồng hoặc các hành vi trái pháp luật khác
- Tuân thủ các nghĩa vụ pháp lý, yêu cầu của cơ quan nhà nước có thẩm quyền hoặc các quy định pháp luật áp dụng đối với Bestarion
4.5. Nhà Cung Cấp, Đối Tác Và Nhà Thầu
- Bestarion có thể thu thập và xử lý dữ liệu cá nhân của nhà cung cấp, đối tác kinh doanh, nhà thầu và người đại diện, nhân viên hoặc đầu mối liên hệ của các tổ chức này cho các mục đích sau:
- Thiết lập, duy trì và quản lý mối quan hệ hợp tác kinh doanh với nhà cung cấp, đối tác, nhà thầu và các bên liên quan
- Đánh giá, lựa chọn, thẩm định năng lực, thực hiện các hoạt động thẩm tra, đánh giá rủi ro và tuân thủ đối với nhà cung cấp, đối tác hoặc nhà thầu
- Trao đổi thông tin, đàm phán, ký kết, thực hiện, quản lý, sửa đổi, gia hạn hoặc chấm dứt hợp đồng, thỏa thuận hoặc các giao dịch kinh doanh với nhà cung cấp và đối tác
- Quản lý việc cung cấp hàng hóa, dịch vụ, thực hiện dự án, hỗ trợ kỹ thuật hoặc các nghĩa vụ khác theo hợp đồng hoặc thỏa thuận giữa các bên
- Quản lý hoạt động mua sắm, đấu thầu, lựa chọn nhà cung cấp, quản lý hiệu suất và đánh giá chất lượng hàng hóa, dịch vụ của nhà cung cấp hoặc đối tác
- Thực hiện các hoạt động kế toán, thanh toán, xuất hóa đơn, đối soát công nợ, kiểm toán và các nghĩa vụ tài chính liên quan
- Quản lý quyền truy cập và cơ sở vật chất, hệ thống thông tin hoặc tài nguyên của Bestarion khi cần thiết để phục vụ hoạt động hợp tác kinh doanh
- Đảm bảo an toàn, an ninh thông tin, phòng ngừa, phát hiện và xử lý các hành vi gian lận, vi phạm hợp đồng, vi phạm chính sách hoặc các hành vi trái pháp luật khác
- Thiết lập, thực hiện hoặc bảo vệ các quyền và lợi ích hợp pháp của Bestarion; giải quyết tranh chấp, khiếu nại hoặc các vấn đề pháp lý phát sinh
- Tuân thủ các nghĩa vụ pháp lý, yêu cầu của cơ quan nhà nước có thẩm quyền hoặc các quy định pháp luật áp dụng đối với Bestarion
4.6. CỔ ĐÔNG
Bestarion có thể thu thập và xử lý dữ liệu cá nhân của cổ đông cho các mục đích sau:
- Lập, cập nhật và quản lý Sổ đăng ký cổ đông theo Điều 122 Luật Doanh nghiệp 2020
- Triệu tập, tổ chức Đại hội đồng cổ đông và xác nhận tư cách tham dự theo Điều 139 Luật Doanh nghiệp 2020
- Chi trả cổ tức và thực hiện nghĩa vụ kê khai, khấu trừ thuế thu nhập cá nhân theo quy định pháp luật thuế hiện hành
- Thực hiện các nghĩa vụ kế toán, lưu trữ hồ sơ theo Luật Kế toán
- Cung cấp thông tin cho cơ quan nhà nước có thẩm quyền, tổ chức lưu ký / trung tâm lưu ký chứng khoán (nếu có) khi có yêu cầu hợp pháp
5. Nguồn & Phương Thức Thu Thập Dữ Liệu Cá Nhân
Bestarion thu thập dữ liệu cá nhân thông qua các phương thức hợp pháp và minh bạch nhằm phục vụ các mục đích đã được thông báo cho chủ thể dữ liệu. Tùy theo mối quan hệ giữa Bestarion và chủ thể dữ liệu, dữ liệu cá nhân có thể được thu thập từ các nguồn sau:
5.1. Thu Thập Trực Tiếp Từ Chủ Thể Dữ Liệu
Bestarion có thể thu thập dữ liệu cá nhân trực tiếp từ chủ thể dữ liệu khi:
- Chủ thể dữ liệu nộp hồ sơ ứng tuyển, tham gia phỏng vấn hoặc các hoạt động tuyển dụng
- Nhân viên cung cấp thông tin trong quá trình ký kết và thực hiện hợp đồng lao động
- Khách hàng, đối tác hoặc người đại diện của khách hàng, đối tác cung cấp thông tin trong quá trình trao đổi, ký kết và thực hiện hợp đồng
- Người dùng gửi yêu cầu, phản hồi hoặc liên hệ với Bestarion thông qua email, điện thoại, website hoặc các kênh liên lạc khác
- Chủ thể dữ liệu đăng ký tham gia các sự kiện, hội thảo, chương trình đào tạo hoặc các hoạt động do Bestarion tổ chức
- Cổ đông cung cấp thông tin khi đăng ký sở hữu cổ phần, thực hiện chuyển nhượng cổ phần hoặc tham dự, ủy quyền tại Đại hội đồng cổ đông
5.2. Thu Thập Từ Nguồn Công Khai Hoặc Bên Thứ Ba
Bestarion có thể thu thập dữ liệu cá nhân từ các nguồn hợp pháp khác, bao gồm:
- Các trang tuyển dụng, mạng xã hội nghề nghiệp hoặc các nền tảng trực tuyến mà chủ thể dữ liệu đã công khai thông tin
- Đối tác tuyển dụng, đơn vị cung cấp dịch vụ tuyển dụng hoặc bên giới thiệu ứng viên
- Khách hàng, đối tác hoặc tổ chức có liên quan trong phạm vi được pháp luật cho phép
- Các nguồn thông tin công khai khác được phép truy cập theo quy định pháp luật
5.3. Thu Thập Thông Qua Website Và Hệ Thống Công Nghệ Thông Tin
Khi chủ thể dữ liệu truy cập website, cổng thông tin hoặc sử dụng các hệ thống do Bestarion quản lý, Bestarion có thể tự động thu thập một số thông tin bao gồm:
- Địa chỉ IP
- Loại thiết bị, hệ điều hành và trình duyệt
- Thời gian truy cập, lịch sử truy cập và thông tin nhật ký hệ thống (log data)
- Dữ liệu cookie và các công nghệ theo dõi tương tự
- Các thông tin kỹ thuật khác cần thiết cho mục đích vận hành, bảo mật và cải thiện dịch vụ
5.4. Dữ Liệu Cá Nhân Do Khách Hàng Cung Cấp
- Trong quá trình cung cấp dịch vụ phát triển phần mềm, dịch vụ công nghệ thông tin hoặc các dịch vụ thuê ngoài (outsourcing), Bestarion có thể tiếp nhận dữ liệu cá nhân từ Khách hàng để thực hiện các hoạt động xử lý theo hợp đồng dịch vụ và các chỉ thị hợp pháp của Khách hàng
- Trong các trường hợp này, Bestarion có thể hoạt động với vai trò là Bên Xử Lý Dữ Liệu hoặc Bên Kiểm Soát và Xử Lý Dữ Liệu tùy thuộc vào bản chất dịch vụ được cung cấp và thỏa thuận giữa các bên
5.5. Nguyên Tắc Thu Thập Dữ Liệu Cá Nhân
Bestarion cam kết chỉ thu thập dữ liệu cá nhân:
- Phù hợp với mục đích xử lý đã được thông báo
- Trong phạm vi cần thiết cho hoạt động kinh doanh và cung cấp dịch vụ
- Trên cơ sở pháp lý phù hợp theo quy định của pháp luật
Bằng các phương thức minh bạch, hợp pháp và bảo đảm quyền của chủ thể dữ liệu
6. Cơ Sở Pháp Lý Xử Lý Dữ Liệu
6.1. Các căn cứ xử lý dữ liệu cá nhân
Bestarion chỉ xử lý dữ liệu cá nhân khi có căn cứ theo quy định của pháp luật Việt Nam.
Tùy từng hoạt động xử lý, việc xử lý có thể dựa trên sự đồng ý của chủ thể dữ liệu hoặc các trường hợp pháp luật cho phép xử lý không cần sự đồng ý.
Bestarion có thể xử lý dữ liệu cá nhân trên một hoặc nhiều căn cứ sau:
a) Sự đồng ý của chủ thể dữ liệu
Bestarion xử lý dữ liệu cá nhân trên cơ sở sự đồng ý của chủ thể dữ liệu khi pháp luật yêu cầu hoặc khi việc xử lý không thuộc các trường hợp được phép xử lý mà không cần sự đồng ý. Việc thu thập, quản lý và rút lại sự đồng ý được thực hiện theo quy định tại Mục 6.2 và 6.3 của Chính sách này.
b) Thực hiện hợp đồng hoặc các biện pháp theo yêu cầu của chủ thể dữ liệu
Bestarion có thể xử lý dữ liệu cá nhân khi việc xử lý là cần thiết để giao kết, thực hiện, sửa đổi hoặc chấm dứt hợp đồng với chủ thể dữ liệu hoặc để thực hiện các yêu cầu của chủ thể dữ liệu trước khi giao kết hợp đồng.
Ví dụ bao gồm nhưng không giới hạn:
- Ký kết và thực hiện hợp đồng lao động
- Ký kết và thực hiện hợp đồng cung cấp dịch vụ với khách hàng
- Thực hiện hợp đồng với nhà cung cấp, đối tác hoặc cộng tác viên
- Thực hiện các giao dịch, thanh toán và các nghĩa vụ phát sinh từ hợp đồng
c) Thực hiện nghĩa vụ theo quy định của pháp luật
Bestarion có thể xử lý dữ liệu cá nhân khi việc xử lý là cần thiết để thực hiện các nghĩa vụ theo quy định của pháp luật hoặc theo yêu cầu hợp pháp của cơ quan nhà nước có thẩm quyền.
Bao gồm nhưng không giới hạn:
- Thực hiện nghĩa vụ về lao động, bảo hiểm xã hội, bảo hiểm y tế, thuế
- Lưu trữ hồ sơ theo quy định của pháp luật
- Cung cấp thông tin theo yêu cầu của cơ quan nhà nước có thẩm quyền
- Thực hiện các nghĩa vụ về kế toán, kiểm toán, phòng chống rửa tiền, an ninh mạng, bảo vệ dữ liệu cá nhân hoặc các nghĩa vụ pháp lý khác
d) Các trường hợp khác theo quy định của pháp luật
Bestarion có thể xử lý dữ liệu cá nhân trong các trường hợp khác được pháp luật cho phép hoặc yêu cầu mà không cần sự đồng ý của chủ thể dữ liệu, bao gồm nhưng không giới hạn các trường hợp nhằm bảo vệ tính mạng, sức khỏe của chủ thể dữ liệu hoặc người khác trong tình huống khẩn cấp; phục vụ hoạt động của cơ quan nhà nước theo quy định của pháp luật; hoặc các trường hợp khác theo quy định của pháp luật về bảo vệ dữ liệu cá nhân.
Trong mọi trường hợp, Bestarion cam kết chỉ xử lý dữ liệu cá nhân trong phạm vi cần thiết, đúng mục đích đã xác định, áp dụng các biện pháp bảo mật phù hợp và bảo đảm quyền, lợi ích hợp pháp của chủ thể dữ liệu theo quy định của pháp luật.
6.2. Thu Thập Sự Đồng Ý
Bestarion chỉ thu thập sự đồng ý của chủ thể dữ liệu trong các trường hợp pháp luật yêu cầu hoặc khi sự đồng ý là căn cứ hợp pháp để xử lý dữ liệu cá nhân.
Việc thu thập sự đồng ý được thực hiện bằng hình thức phù hợp với từng hoạt động xử lý dữ liệu và bảo đảm sự đồng ý được thể hiện một cách tự nguyện, rõ ràng, cụ thể và có thể chứng minh được.
Tùy theo từng trường hợp, Bestarion có thể áp dụng một hoặc nhiều hình thức thu thập sự đồng ý sau:
| Hình thức thể hiện sự đồng ý | Ví dụ / Mô tả |
|---|---|
| Bằng văn bản | Ký tên trên văn bản giấy; ký điện tử hoặc các hình thức ký hợp pháp khác trên văn bản điện tử thể hiện sự đồng ý |
| Bằng lời nói | Thể hiện sự đồng ý rõ ràng bằng lời nói (ví dụ: qua điện thoại, trực tiếp, họp trực tuyến). Nên được ghi âm hoặc có biện pháp chứng minh để phục vụ việc chứng minh sự đồng ý |
| Bằng hành động cụ thể | Chủ thể dữ liệu chủ động thực hiện hành động thể hiện sự đồng ý, như tích chọn (opt-in) vào ô chưa được đánh dấu sẵn, nhấn nút “Đồng ý”, xác nhận trên ứng dụng hoặc thực hiện hành động tương tự |
| Bằng phương thức điện tử | Xác nhận qua email, OTP, chữ ký số, chữ ký điện tử hoặc các phương thức xác thực điện tử khác theo quy định của pháp luật |
| Các hình thức khác | Bất kỳ hình thức nào khác có thể chứng minh được ý chí tự nguyện, rõ ràng, cụ thể và không gây nhầm lẫn của chủ thể dữ liệu đối với việc đồng ý xử lý dữ liệu cá nhân |
Table 10: Hình thức thể hiện sự đồng ý
Bestarion lưu trữ bằng chứng về sự đồng ý của chủ thể dữ liệu trong thời gian cần thiết để chứng minh việc tuân thủ nghĩa vụ pháp lý.
6.3. Rút Lại Sự Đồng Ý
Chủ thể dữ liệu có quyền rút lại sự đồng ý đối với việc xử lý dữ liệu cá nhân của mình bất kỳ thời điểm nào bằng cách gửi yêu cầu đến Bestarion thông qua các kênh tiếp nhận yêu cầu được Công ty công bố.
Việc rút lại sự đồng ý không ảnh hưởng đến tính hợp pháp của hoạt động xử lý dữ liệu cá nhân đã được thực hiện trước thời điểm việc rút lại sự đồng ý có hiệu lực.
Việc rút lại sự đồng ý có thể dẫn đến việc Bestarion không thể tiếp tục cung cấp một số sản phẩm, dịch vụ hoặc thực hiện một số hoạt động phụ thuộc vào sự đồng ý của chủ thể dữ liệu. Trong trường hợp này, Bestarion sẽ thông báo cho chủ thể dữ liệu về các ảnh hưởng có liên quan (nếu có).
Việc tiếp nhận và xử lý yêu cầu rút lại sự đồng ý được thực hiện theo quy định tại Mục 13 “Quyền của chủ thể dữ liệu & quy trình thực hiện” của Chính sách này.
7. Chia Sẻ & Tiết Lộ Dữ Liệu Cá Nhân
Bestarion có thể chia sẻ dữ liệu cá nhân với các bên thứ ba trong phạm vi cần thiết để thực hiện các mục đích xử lý được nêu trong Chính sách này và phù hợp với quy định pháp luật hiện hành.
7.1. Nhà Cung Cấp Dịch Vụ
Bestarion có thể chia sẻ dữ liệu cá nhân với các nhà cung cấp dịch vụ hỗ trợ hoạt động kinh doanh của Bestarion, bao gồm nhưng không giới hạn:
- Nhà cung cấp hạ tầng công nghệ thông tin, dịch vụ điện toán đám mây, lưu trữ dữ liệu, thư điện tử, quản lý mã nguồn, quản lý quan hệ khách hàng, cộng tác và năng suất làm việc
- Nhà cung cấp nền tảng tuyển dụng, tìm kiếm ứng viên và quản lý tuyển dụng
- Nhà cung cấp dịch vụ phân tích dữ liệu, tiếp thị, khảo sát và truyền thông điện tử
- Nhà cung cấp dịch vụ thanh toán, kế toán, kiểm toán, bảo hiểm, chăm sóc sức khỏe hoặc tổ chức sự kiện
- Đơn vị tư vấn pháp lý, tư vấn chuyên môn, kiểm toán hoặc các đơn vị cung cấp dịch vụ hỗ trợ khác
Bestarion yêu cầu các nhà cung cấp dịch vụ chỉ xử lý dữ liệu cá nhân theo hướng dẫn của Bestarion, áp dụng các biện pháp bảo mật phù hợp và tuân thủ các nghĩa vụ bảo vệ dữ liệu cá nhân theo quy định pháp luật hiện hành.
7.2. Khách Hàng Và Đối Tác Kinh Doanh
Trong quá trình cung cấp dịch vụ phát triển phần mềm, dịch vụ công nghệ thông tin hoặc các dịch vụ liên quan, Bestarion có thể chia sẻ hồ sơ năng lực, thông tin chuyên môn và các dữ liệu cá nhân cần thiết của nhân sự dự kiến tham gia dự án với khách hàng nhằm phục vụ việc đánh giá, lựa chọn, bố trí nguồn lực và quản lý nhân sự trong quá trình thực hiện hợp đồng. Việc chia sẻ này luôn được giới hạn ở mức cần thiết và tuân thủ quy định của pháp luật về bảo vệ dữ liệu cá nhân:
- Đánh giá trình độ chuyên môn, kỹ năng, kinh nghiệm và mức độ phù hợp của nhân sự đối với vị trí hoặc dự án
- Thực hiện các hoạt động đánh giá, phỏng vấn, xác minh năng lực hoặc các quy trình lựa chọn nhân sự theo yêu cầu hợp lý của khách hàng
- Phân công, điều phối, quản lý và triển khai nhân sự phục vụ việc thực hiện hợp đồng hoặc dự án
- Quản lý tiến độ, chất lượng dịch vụ, an toàn thông tin, tuân thủ và các yêu cầu quản trị dự án theo hợp đồng hoặc thỏa thuận với khách hàng
- Thực hiện các nghĩa vụ khác phát sinh từ hợp đồng hoặc theo yêu cầu hợp pháp của khách hàng liên quan đến việc cung cấp dịch vụ
Bestarion chỉ thực hiện việc chia sẻ dữ liệu cá nhân trên cơ sở phù hợp với quy định của pháp luật. Trường hợp pháp luật yêu cầu phải có sự đồng ý của chủ thể dữ liệu, Bestarion sẽ thực hiện việc chia sẻ dữ liệu sau khi đã thu thập sự đồng ý hợp lệ của chủ thể dữ liệu theo quy định.
Bestarion yêu cầu các bên nhận dữ liệu chỉ xử lý dữ liệu cá nhân trong phạm vi cần thiết cho mục đích đã xác định và áp dụng các biện pháp bảo vệ dữ liệu cá nhân phù hợp theo quy định pháp luật.
7.3. Công Ty Mẹ, công ty con và công Ty Liên Kết
Bestarion có thể chia sẻ dữ liệu cá nhân với công ty mẹ, công ty con hoặc các công ty liên kết trong cùng tập đoàn để phục vụ các mục đích quản trị, vận hành, hỗ trợ kinh doanh, quản lý nhân sự, quản lý hệ thống thông tin hoặc các mục đích hợp pháp khác phù hợp với Chính sách này và quy định pháp luật hiện hành.
7.4. Tư vấn chuyên môn và các tổ chức cung cấp dịch vụ chuyên nghiệp (Professional Advisors)
Bestarion có thể chia sẻ dữ liệu cá nhân với các đơn vị cung cấp dịch vụ chuyên môn nhằm hỗ trợ hoạt động quản trị, vận hành, tuân thủ pháp luật hoặc bảo vệ quyền và lợi ích hợp pháp của Công ty, bao gồm nhưng không giới hạn:
- Văn phòng luật sư, công ty luật hoặc chuyên gia tư vấn pháp lý
- Công ty kiểm toán độc lập, kế toán, tư vấn thuế hoặc tư vấn tài chính
- Tổ chức chứng nhận, đánh giá hoặc kiểm tra tuân thủ
- Các tổ chức tư vấn khác phục vụ hoạt động hợp pháp của Bestarion
Việc chia sẻ dữ liệu cá nhân chỉ được thực hiện trong phạm vi cần thiết để các tổ chức nêu trên cung cấp dịch vụ hoặc thực hiện nhiệm vụ được giao. Bestarion yêu cầu các tổ chức này thực hiện các biện pháp bảo vệ dữ liệu cá nhân phù hợp, bảo đảm tính bảo mật của dữ liệu cá nhân và chỉ xử lý dữ liệu theo mục đích đã được xác định hoặc theo quy định của pháp luật.
7.5. Cơ Quan Nhà Nước Có Thẩm Quyền
Bestarion có thể tiết lộ hoặc cung cấp dữ liệu cá nhân khi việc cung cấp đó được yêu cầu theo quy định của pháp luật, theo yêu cầu của cơ quan nhà nước có thẩm quyền, cơ quan tiến hành tố tụng hoặc để bảo vệ quyền, lợi ích hợp pháp của Bestarion, khách hàng, đối tác hoặc các bên liên quan khác.
7.6. Giao Dịch Doanh Nghiệp
Trong trường hợp sáp nhập, hợp nhất, tái cơ cấu, chuyển nhượng doanh nghiệp, chuyển nhượng dự án hoặc các giao dịch tương tự, dữ liệu cá nhân có thể được chuyển giao cho bên nhận chuyển giao theo quy định của pháp luật và trên cơ sở áp dụng các biện pháp bảo vệ dữ liệu cá nhân phù hợp.
8. Chuyển Dữ Liệu Ra Nước Ngoài
Trong quá trình hoạt động, Bestarion có thể chuyển dữ liệu cá nhân ra ngoài lãnh thổ Việt Nam hoặc cho phép dữ liệu cá nhân được lưu trữ, xử lý hoặc truy cập từ nước ngoài trong các trường hợp sau:
- Sử dụng các dịch vụ điện toán đám mây, lưu trữ dữ liệu, thư điện tử, họp trực tuyến, quản lý quan hệ khách hàng (CRM) hoặc các nền tảng công nghệ thông tin do các nhà cung cấp dịch vụ nước ngoài cung cấp
- Sử dụng các dịch vụ phân tích dữ liệu, tiếp thị, khảo sát, truyền thông điện tử hoặc các công cụ hỗ trợ vận hành có máy chủ hoặc hạ tầng xử lý dữ liệu đặt ngoài lãnh thổ Việt Nam
- Chia sẻ dữ liệu cá nhân với khách hàng, đối tác, công ty liên kết hoặc nhà cung cấp dịch vụ ở nước ngoài trong phạm vi cần thiết để cung cấp dịch vụ, thực hiện hợp đồng hoặc phục vụ các mục đích xử lý đã được thông báo
- Chia sẻ hồ sơ nghề nghiệp, thông tin năng lực hoặc các dữ liệu liên quan của ứng viên, nhân viên hoặc cộng tác viên với khách hàng nước ngoài trong phạm vi cần thiết để thực hiện các hoạt động đánh giá, lựa chọn hoặc triển khai nguồn lực phục vụ dự án, phù hợp với quy định pháp luật hiện hành
- Đặt phòng khách sạn, đăng ký tham dự triển lãm / hội nghị ở nước ngoài trực tiếp với đơn vị cung cấp dịch vụ nước ngoài
Trong các trường hợp pháp luật yêu cầu, Bestarion sẽ lập Hồ sơ đánh giá tác động chuyển dữ liệu cá nhân xuyên biên giới và ký kết thỏa thuận ràng buộc trách nhiệm pháp lý với bên nhận dữ liệu ở nước ngoài trước khi tiến hành chuyển dữ liệu.
Bestarion áp dụng các biện pháp kỹ thuật, tổ chức và hợp đồng phù hợp nhằm đảm bảo dữ liệu cá nhân được bảo vệ trong suốt quá trình truyền tải, lưu trữ và xử lý bởi các bên nhận dữ liệu.
9. Thời Hạn Lưu Trữ Dữ Liệu Cá Nhân
Bestarion lưu trữ dữ liệu trong thời gian cần thiết cho mục đích đã nêu và theo quy định pháp luật. Dưới đây là thời hạn lưu trữ theo từng nhóm đối tượng:
| Loại dữ liệu | Thời hạn lưu trữ |
|---|---|
| Hồ sơ nhân sự, hợp đồng lao động và hồ sơ liên quan | Ít nhất 10 năm kể từ ngày chấm dứt quan hệ lao động / hợp tác hoặc thời hạn dài hơn nếu pháp luật yêu cầu |
| Dữ liệu tiền lương, kế toán và chứng từ tài chính | 10 năm theo quy định của pháp luật |
| Hồ sơ bảo hiểm xã hội, bảo hiểm y tế, bảo hiểm thất nghiệp và thuế thu nhập cá nhân | 10 năm hoặc theo thời hạn lưu trữ do pháp luật quy định |
| Hồ sơ ứng viên không được tuyển dụng | 02 năm kể từ ngày kết thúc quá trình tuyển dụng hoặc theo sự đồng ý của ứng viên |
| Kết quả khám sức khỏe và hồ sơ phúc lợi liên quan | 05 năm hoặc theo quy định của pháp luật chuyên ngành |
| Nhật ký hệ thống (logs) và dữ liệu an toàn thông tin | Theo chính sách lưu trữ nhật ký của Công ty, tối đa 02 năm hoặc theo yêu cầu pháp luật, hợp đồng |
| Dữ liệu từ hệ thống camera giám sát (CCTV) | Không quá 90 ngày, trừ trường hợp cần phục vụ điều tra sự cố, giải quyết tranh chấp hoặc theo yêu cầu của cơ quan có thẩm quyền |
| Sổ đăng ký cổ đông và hồ sơ liên quan đến cổ đông | Trong suốt thời gian cổ đông sở hữu cổ phần và tối thiểu 10 năm kể từ khi chấm dứt tư cách cổ đông theo quy định của Luật Kế toán |
| Dữ liệu cá nhân của khách hàng, nhà cung cấp hoặc đối tác là cá nhân | Trong thời gian duy trì quan hệ giao dịch và thêm 10 năm sau khi cơ quan thuế hoàn tất kiểm tra, thanh tra quyết toán thuế |
| Hợp đồng, hồ sơ giao dịch và tài liệu liên quan đến khách hàng, nhà cung cấp hoặc đối tác là tổ chức / doanh nghiệp | Được lưu giữ trong thời gian cần thiết để phục vụ hoạt động quản trị doanh nghiệp, tra cứu lịch sử giao dịch, bảo vệ quyền và lợi ích hợp pháp của Bestarion, giải quyết tranh chấp hoặc đáp ứng các yêu cầu pháp lý |
| Dữ liệu tiếp thị và truyền thông | Cho đến khi chủ thể dữ liệu rút lại sự đồng ý hoặc sau 03 năm kể từ lần tương tác cuối cùng |
Table 11: Lưu trữ dữ liệu
10. Xóa Và Hủy Dữ Liệu Cá Nhân
Bestarion thực hiện xóa, hủy hoặc ẩn danh dữ liệu cá nhân trong các trường hợp sau:
- Dữ liệu cá nhân không còn cần thiết cho mục đích xử lý đã được thông báo
- Hết thời hạn lưu trữ theo quy định của pháp luật hoặc chính sách lưu trữ của Bestarion
- Chủ thể dữ liệu yêu cầu xóa dữ liệu cá nhân và Bestarion không có căn cứ pháp lý hoặc nghĩa vụ hợp pháp để tiếp tục lưu trữ, xử lý dữ liệu
- Việc xử lý dữ liệu cá nhân không còn cần thiết hoặc không còn cơ sở pháp lý để tiếp tục thực hiện
- Các trường hợp khác theo quy định của pháp luật
Trong trường hợp dữ liệu cá nhân được xử lý trong quá trình cung cấp dịch vụ cho khách hàng, việc xóa hoặc hoàn trả dữ liệu sẽ được thực hiện theo thỏa thuận với khách hàng và các nghĩa vụ pháp lý có liên quan.
Bestarion áp dụng các biện pháp phù hợp nhằm bảo đảm dữ liệu cá nhân được xóa, hủy hoặc ẩn danh theo quy định và không thể được sử dụng cho các mục đích xử lý không được phép sau khi việc xóa được hoàn tất.
11. Biện Pháp Bảo Vệ Dữ Liệu Cá Nhân
Bestarion áp dụng các biện pháp kỹ thuật và tổ chức phù hợp nhằm bảo vệ dữ liệu cá nhân khỏi mất mát, truy cập, sử dụng, tiết lộ, thay đổi hoặc phá hủy trái phép trong suốt quá trình thu thập, lưu trữ, xử lý và chuyển giao dữ liệu.
11.1. Biện Pháp Kỹ Thuật
- Áp dụng các biện pháp bảo mật phù hợp để bảo vệ dữ liệu cá nhân trong quá trình truyền tải, lưu trữ và xử lý
- Thực hiện cơ chế xác thực người dùng, kiểm soát truy cập và phân quyền theo vai trò, đảm bảo chỉ những người có thẩm quyền và nhu cầu công việc hợp pháp mới được truy cập dữ liệu cá nhân
- Áp dụng các biện pháp bảo vệ hệ thống thông tin như tường lửa, kiểm soát truy cập, và các giải pháp bảo mật khác nhằm ngăn chặn truy cập trái phép và các hành vi tấn công mạng
- Ghi nhận, giám sát và phân tích nhật ký hệ thống nhằm phát hiện, phòng ngừa và xử lý các hành vi truy cập bất thường hoặc vi phạm an toàn thông tin
- Thực hiện sao lưu dữ liệu định kỳ và áp dụng các biện pháp khôi phục dữ liệu nhằm đảm bảo tính sẵn sàng, toàn vẹn và khả năng phục hồi của hệ thống
- Áp dụng các biện pháp mã hóa hoặc các biện pháp bảo vệ kỹ thuật phù hợp đối với dữ liệu cá nhân trong quá trình lưu trữ, truyền tải và xử lý, căn cứ vào tính chất của dữ liệu, mức độ rủi ro và điều kiện kỹ thuật của hệ thống
- Thực hiện đánh giá lỗ hổng, cập nhật bản vá bảo mật và các biện pháp quản lý rủi ro kỹ thuật nhằm giảm thiểu nguy cơ khai thác các điểm yếu của hệ thống
11.2. Biện Pháp Tổ Chức
- Áp dụng nguyên tắc phân quyền truy cập tối thiểu, đảm bảo dữ liệu cá nhân chỉ được truy cập trong phạm vi cần thiết để thực hiện công việc được giao
- Chỉ những nhân viên, cộng tác viên, nhà thầu hoặc bên thứ ba được ủy quyền và có nghĩa vụ bảo mật mới được phép truy cập và xử lý dữ liệu cá nhân
- Thực hiện đánh giá phù hợp đối với các bên xử lý dữ liệu, nhà cung cấp hoặc đối tác trước khi chia sẻ hoặc cho phép xử lý dữ liệu cá nhân
- Ban hành, duy trì và cập nhật các chính sách, quy trình nội bộ về bảo vệ dữ liệu cá nhân và an toàn thông tin
- Đào tạo và nâng cao nhận thức cho nhân viên và các bên liên quan về bảo vệ dữ liệu cá nhân và nghĩa vụ bảo mật thông tin
- Thực hiện đánh giá, giám sát và cải tiến định kỳ các biện pháp bảo vệ dữ liệu cá nhân nhằm đảm bảo hiệu quả và tuân thủ pháp luật
11.3. Biện pháp bảo vệ vật lý
Bestarion áp dụng các biện pháp bảo vệ vật lý nhằm ngăn ngừa việc truy cập trái phép vào khu vực, thiết bị hoặc tài liệu có chứa dữ liệu cá nhân, bao gồm:
- Kiểm soát việc ra vào văn phòng, khu vực làm việc và các khu vực hạn chế
- Quản lý khách đến làm việc và ghi nhận thông tin ra vào theo quy định của Công ty
- Bảo vệ máy chủ, thiết bị lưu trữ và các tài sản chứa dữ liệu cá nhân tại các khu vực được kiểm soát
- Lưu trữ hồ sơ, tài liệu giấy có chứa dữ liệu cá nhân tại khu vực an toàn, có kiểm soát truy cập
- Tiêu hủy tài liệu, thiết bị hoặc phương tiện lưu trữ dữ liệu cá nhân theo quy trình và phương pháp phù hợp nhằm ngăn ngừa việc khôi phục dữ liệu trái phép
11.4. Quản Lý Sự Cố Dữ Liệu Cá Nhân
Bestarion duy trì quy trình quản lý và ứng phó sự cố liên quan đến dữ liệu cá nhân. Trong trường hợp phát hiện hoặc nghi ngờ xảy ra sự cố ảnh hưởng đến dữ liệu cá nhân, Bestarion sẽ thực hiện các biện pháp xử lý cần thiết nhằm giảm thiểu rủi ro. Nếu sự cố thuộc trường hợp phải thông báo cho các bên liên quan theo quy định của pháp luật Bestarion sẽ tiến hành thông báo cho cơ quan có thẩm quyền và / hoặc chủ thể dữ liệu.
11.5. Dữ Liệu Cá Nhân Nhạy Cảm
Đối với dữ liệu cá nhân nhạy cảm theo quy định của pháp luật, Bestarion áp dụng các biện pháp bảo vệ tăng cường tương xứng với mức độ rủi ro, bao gồm giới hạn truy cập nghiêm ngặt, kiểm soát chặt chẽ quá trình xử lý, theo dõi hoạt động truy cập, mã hóa khi lưu trữ hoặc truyền tải (nếu phù hợp) và áp dụng các quy trình quản lý chuyên biệt.
11.6. Giới Hạn Bảo Mật
Mặc dù Bestarion áp dụng các biện pháp bảo vệ phù hợp nhằm bảo đảm an toàn dữ liệu cá nhân, không có hệ thống thông tin hoặc phương thức truyền tải dữ liệu nào có thể bảo đảm an toàn tuyệt đối.
Trong trường hợp phát sinh sự cố ngoài khả năng kiểm soát hợp lý của Bestarion, Công ty sẽ thực hiện các biện pháp cần thiết nhằm hạn chế thiệt hại, khắc phục hậu quả và thực hiện các nghĩa vụ thông báo theo quy định của pháp luật.
12. Quyền Riêng Tư Của Trẻ Em
Bestarion có thể thu thập và xử lý dữ liệu cá nhân của trẻ em trong phạm vi cần thiết để thực hiện các chương trình phúc lợi, chăm sóc đời sống nhân viên và các hoạt động nội bộ khác, bao gồm nhưng không giới hạn ở:
- Quản lý người phụ thuộc theo quy định của pháp luật
- Thực hiện các chương trình bảo hiểm, chăm sóc sức khỏe hoặc phúc lợi dành cho nhân viên và người thân của nhân viên
- Tổ chức các hoạt động dành cho gia đình nhân viên như ngày Quốc tế Thiếu nhi, Tết Trung thu, du lịch, sự kiện nội bộ hoặc các chương trình khen thưởng, hỗ trợ khác
- Thực hiện các nghĩa vụ hoặc quyền lợi khác liên quan đến người phụ thuộc theo quy định của pháp luật hoặc chính sách của Bestarion
Trong các trường hợp pháp luật yêu cầu, Bestarion sẽ thực hiện việc xử lý dữ liệu cá nhân của trẻ em trên cơ sở sự đồng ý của cha mẹ hoặc người giám hộ hợp pháp và áp dụng các biện pháp bảo vệ phù hợp đối với dữ liệu cá nhân của trẻ em.
Cha mẹ hoặc người giám hộ hợp pháp có thể thay mặt trẻ em thực hiện các quyền liên quan đến dữ liệu cá nhân theo quy định của pháp luật bằng cách liên hệ với Bestarion qua địa chỉ email: dataprivacy@bestarion.com.
13. Quyền Của Chủ Thể Dữ Liệu & Quy Trình Thực Hiện Quyền
13.1. Quyền Của Chủ Thể Dữ Liệu
Theo quy định của pháp luật về bảo vệ dữ liệu cá nhân, chủ thể dữ liệu có các quyền sau đây đối với dữ liệu cá nhân của mình:
- Được biết về hoạt động xử lý dữ liệu cá nhân
- Đồng ý hoặc không đồng ý, yêu cầu rút lại sự đồng ý cho phép xử lý dữ liệu cá nhân
- Xem, chỉnh sửa hoặc yêu cầu chỉnh sửa dữ liệu cá nhân
- Yêu cầu cung cấp, xóa, hạn chế xử lý dữ liệu cá nhân; gửi yêu cầu phản đối xử lý dữ liệu cá nhân
- Khiếu nại, tố cáo, khởi kiện, yêu cầu bồi thường thiệt hại theo quy định của pháp luật
- Yêu cầu cơ quan có thẩm quyền hoặc cơ quan, tổ chức, cá nhân liên quan đến xử lý dữ liệu cá nhân thực hiện các biện pháp, giải pháp bảo vệ dữ liệu cá nhân của mình theo quy định của pháp luật
13.2. Cách Thức Gửi Yêu Cầu
Để thực hiện bất kỳ quyền nào nêu trên, chủ thể dữ liệu có thể gửi yêu cầu đến Bestarion thông qua các kênh sau:
- Email: dataprivacy@bestarion.com
- Các kênh tiếp nhận yêu cầu khác do Bestarion công bố theo từng thời kỳ (nếu có)
Trong yêu cầu, chủ thể dữ liệu nên cung cấp đầy đủ các thông tin cần thiết để Bestarion có cơ sở xác định yêu cầu và xử lý, bao gồm nhưng không giới hạn:
- Họ và tên
- Thông tin liên hệ
- Nội dung yêu cầu
- Dữ liệu cá nhân hoặc hoạt động xử lý liên quan (nếu biết)
- Các tài liệu hoặc thông tin hỗ trợ khác (nếu có)
13.3. Tiếp Nhận Và Xử Lý Yêu Cầu:
Sau khi tiếp nhận yêu cầu, Bestarion sẽ:
- Tiếp nhận và ghi nhận yêu cầu của chủ thể dữ liệu
- Thực hiện xác minh danh tính của người yêu cầu khi cần thiết nhằm bảo đảm quyền và lợi ích hợp pháp của chủ thể dữ liệu, đồng thời ngăn ngừa các hành vi truy cập, yêu cầu hoặc tiết lộ dữ liệu trái phép
- Đánh giá nội dung yêu cầu, căn cứ pháp lý và phạm vi dữ liệu cá nhân liên quan
- Phối hợp với các đơn vị, bộ phận hoặc bên xử lý dữ liệu cá nhân có liên quan để xử lý yêu cầu
- Thông báo kết quả xử lý cho chủ thể dữ liệu theo quy định của pháp luật
13.4. Trường hợp từ chối hoặc hạn chế thực hiện yêu cầu
Bestarion có thể từ chối hoặc hạn chế việc thực hiện một phần hoặc toàn bộ yêu cầu của chủ thể dữ liệu trong các trường hợp được pháp luật cho phép, bao gồm nhưng không giới hạn:
- Không thể xác minh danh tính của người yêu cầu
- Yêu cầu không thuộc phạm vi quyền của chủ thể dữ liệu theo quy định của pháp luật
- Việc tiếp tục xử lý dữ liệu cá nhân là cần thiết để thực hiện nghĩa vụ pháp lý, thực hiện hợp đồng, bảo vệ quyền và lợi ích hợp pháp của Bestarion hoặc của bên thứ ba, hoặc thuộc các trường hợp khác được pháp luật cho phép
- Yêu cầu có tính chất lặp lại, không có căn cứ hoặc gây ảnh hưởng nghiêm trọng đến quyền, lợi ích hợp pháp của Bestarion hoặc của tổ chức, cá nhân khác
- Các trường hợp khác theo quy định của pháp luật
Trong trường hợp từ chối hoặc hạn chế thực hiện yêu cầu, Bestarion sẽ thông báo cho chủ thể dữ liệu về lý do từ chối hoặc hạn chế, trừ trường hợp pháp luật có quy định khác.
14. Liên Hệ
Thông tin liên hệ: Nếu bạn có bất kỳ câu hỏi, yêu cầu hoặc khiếu nại nào liên quan đến Chính sách bảo vệ dữ liệu cá nhân này hoặc việc xử lý dữ liệu cá nhân của Bestarion, vui lòng liên hệ Bộ phận Bảo vệ DLCN:
- Công ty: CÔNG TY CỔ PHẦN PHẦN MỀM BESTARION
- Địa chỉ văn phòng: Tầng 3, Tòa nhà QTSC Building 1, Lô 34, Đường số 14, Công viên Phần Mềm Quang Trung, P.Trung Mỹ Tây, TP. Hồ Chí Minh
- Điện thoại: (+84) 28 37 154 152
- Email: dataprivacy@bestarion.com
Bestarion sẽ tiếp nhận, xem xét và phản hồi các yêu cầu trong thời hạn phù hợp theo quy định của pháp luật hiện hành.
15. Hiệu Lực Và Sửa Đổi Chính Sách
- Bestarion có thể cập nhật hoặc sửa đổi Chính sách Bảo vệ Dữ liệu Cá nhân này theo từng thời điểm nhằm phản ánh các thay đổi trong hoạt động kinh doanh, phương thức xử lý dữ liệu cá nhân hoặc yêu cầu của pháp luật hiện hành
- Phiên bản cập nhật sẽ được công bố trên website của Bestarion hoặc thông qua các phương thức phù hợp khác. Đối với các thay đổi trọng yếu có ảnh hưởng đáng kể đến quyền và lợi ích của chủ thể dữ liệu, Bestarion sẽ thực hiện thông báo theo hình thức phù hợp trước khi các thay đổi đó có hiệu lực, trừ trường hợp pháp luật có quy định khác
- Bestarion khuyến nghị chủ thể dữ liệu thường xuyên theo dõi Chính sách này để cập nhật các thông tin mới nhất về việc xử lý và bảo vệ dữ liệu cá nhân
- Ngày hiệu lực: Ngày 01 tháng 07 năm 2026
- Chính sách này có hiệu lực kể từ ngày nêu trên và thay thế các phiên bản Chính sách Bảo vệ Dữ liệu Cá nhân đã được ban hành trước đó
