Personal Data Protection Policy | Green SM

Privacy policy
Personal Data Protection Policy
PERSONAL DATA PROTECTION POLICY GSM GREEN AND SMART MOBILITY JOINT STOCK COMPANY This Personal Data Protection Policy (hereinafter referred to as the "Policy") describes the processing of personal data arising in the course of the operations and business activities of GSM GREEN AND SMART MOBILITY JOINT STOCK COMPANY (the "Company"), having its registered address at Symphony Office Building, Chu Huy Man Street, Vinhomes Riverside Urban Area, Phuc Loi Ward, Hanoi City, Vietnam, and its official website at https://www.greensm.com. The Company processes personal data in its capacity as Personal Data Controller or Personal Data Controller and Processor in accordance with the applicable laws. This Privacy Policy is issued to ensure that the processing of personal data is carried out in a transparent, controlled, and legally compliant manner. It also aims to enable Data Subject to clearly understand their rights and the mechanisms in place to safeguard their privacy in the context of their relationship with the Company. This Privacy Policy also constitutes the Company's Consumer Information Protection Policy, evidencing the Company's commitment to: • respecting the privacy and personal information of Data Subject; • safeguarding personal information against unauthorized access, use, disclosure, alteration, or destruction; and • maintaining a safe, transparent, and trustworthy environment for individuals engaging in transactions with, residing in, or accessing the Company's products and services. The Company reserves the right to revise or amend this Privacy Policy from time to time as necessary to ensure compliance with applicable laws and to reflect changes in its business operations or personal data processing practices. Any revised version of this Privacy Policy will be made available through the Company's official communication channels and shall become effective as specified therein.
1. DEFINITIONS
1.1. "Customer" means all individual customers; representatives/contact persons of organizational customers that have entered into and performed agreements with the Company; individuals who are exploring and considering the use of the Company's products and services; walk-in visitors; individuals participating in events introducing the Company's products and services; individuals participating in community activities; and users of the Company's websites, applications, and digital platforms. This definition also includes Consumers as prescribed under the laws on consumer protection. 1.2. "Personnel" means individuals who currently have or have previously had an employment relationship with the Company, including but not limited to members of the Board of Management, managers, employees, job applicants, interns, and collaborators. 1.3. "Contact Person" means an individual who is currently or has previously been designated, authorized, or assigned in practice by the Company's Partner to represent such Partner in contacting, communicating, conducting transactions, or coordinating work with the Company. 1.4. "Shareholder" means an individual holding at least one share in the Company. 1.5. "Insider" means an individual holding a significant position within the Company's governance or management structure, as determined in accordance with the applicable laws from time to time. 1.6. "Related Person" means an individual having a direct or indirect relationship with the Company, as determined in accordance with the applicable laws from time to time. 1.7. "Consumer" means an individual who purchases or uses products, goods, or services for the consumption or daily living purposes of himself/herself, his/her family, or for the internal use of an agency or organization, and not for commercial purposes. 1.8. "Partner" means organizations or individuals working with the Company to cooperate, provide products or services, or support the Company's operations. Individual Partners include, without limitation, individual contractors, consultants, and personnel supplied to the Company by third parties. 1.9. "Personal Data" means data in electronic form or any other form of information that identifies or helps identify a specific individual, including Basic Personal Data and Sensitive Personal Data. Personal Data that has been de-identified shall no longer be regarded as Personal Data. 1.10. "Basic Personal Data" means personal data reflecting an individual's basic identity and background information that is commonly and regularly used in transactions and social relationships, and falls within the categories promulgated by the Government. 1.11. "Sensitive Personal Data" means personal data associated with an individual's privacy, the infringement of which may directly affect the lawful rights and interests of agencies, organizations, or individuals, and which falls within the categories promulgated by the Government. 1.12. "Data Subject" means an individual to whom the Personal Data relates. 1.13. "Processing of Personal Data" or "Processing" means any operation performed on Personal Data, including one or more of the following activities: collection, analysis, aggregation, encryption, decryption, modification, deletion, destruction, de-identification, provision, disclosure, transfer of Personal Data, and any other activity involving Personal Data. 1.14. "Personal Data Controller" means the party that determines the purposes and means of the Processing of Personal Data. 1.15. "Personal Data Processor" means the party that processes Personal Data on behalf of the Company pursuant to an agreement with the Company. 1.16. "Applicable Laws" means the laws and regulations of Vietnam (including laws, decrees, circulars, and relevant implementing regulations) governing or relating to the protection of Personal Data and other obligations relating to Personal Data. 1.17. "Personal Data Protection Policy" or the "Policy" means the entire contents of this Policy, consisting of fourteen (14) Sections.
2. COMMITMENT TO PERSONAL DATA PROTECTION
The Company is committed to NOT buying or selling Personal Data and shall comply with the following principles when Processing Personal Data: - Strictly complying with all agreements and documents entered into with the Data Subject. - Processing Personal Data only for specific, explicit, and lawful purposes as set out in this Policy and in compliance with the Applicable Laws. - Adopting, implementing, and regularly updating appropriate measures to protect Personal Data in accordance with the Applicable Laws to safeguard Personal Data against incidents, unauthorized access, and/or destruction, loss, or damage. - Retaining Personal Data appropriately and only to the extent necessary in accordance with the Applicable Laws.
3. SCOPE OF APPLICATION
This Policy applies to all Data Subjects of the Company, including: - Customers. - The Company's Personnel. - Contact Persons. - The Company's Shareholders, Insiders, and Related Persons.
4. TYPES OF PERSONAL DATA COLLECTED AND PURPOSES OF PROCESSING
4.1. For Customers 4.1.1. Types of Personal Data collected 4.1.1.1. Basic Personal Data • Contact and identification information: Full name; date, month, and year of birth; gender; nationality; phone number; email address; permanent residence address; contact address. • Legal and identification information: Information contained in personal identification documents and identification information such as Identity Card/Citizen Identification Card/Passport/Personal Identification Number; other identification information as prescribed by law (if any). • Residency information: Information on residency status, form, duration, and purpose of residence for the purposes of complying with legal regulations, managing records, and determining the scope of provision of products and services. • Transportation means and access control information: Information on transportation means (e.g., vehicle license plate number); access cards; access control data of buildings, areas, or events. • Information on needs and interests in products and services; information on registration for consultation; registration to participate in events, programs, and activities organized by the Company. • Information on products, services, and history of use of products and services: Information on registration for and use of products and services; data related to the process and history of use of products and services. • Digital account data and usage history: Account data on websites/applications such as login information; data on the history of using websites, applications, or service channels (e.g., views, actions, interactive content). • Technical and system operation data: IP address, cookies, device ID, device information, browser information, system logs, and other technical data serving the operation, security, and improvement of the system. • Feedback and evaluation data: Feedback, complaints, recommendations, and evaluations from Customers. • Customer segmentation information: Information on Customers’ preferences and needs regarding products and services. 4.1.1.2. Sensitive Personal Data • Biometric data: Facial recognition data and other biometric data (in cases where Customers register for or consent to the use thereof). • Financial, credit, and transaction information: Information related to contracts, transactions, financing, guarantees, or loans (including financial and credit information); bank account information and information serving payment purposes (including financial transaction information). • Identifiable audio and video recording data: Data from audio and video recording systems at buildings, urban areas, public areas, or events, to the extent that such data may be used to identify or monitor individuals. • Data on activities and behaviors on the Company’s online services: Data on website/application access journeys, cookie data regarding application usage behaviors, user interaction data, and data on user profiles or user segmentation. • Images of identity cards/citizen identification cards/identification cards/passports. 4.1.2. Legal Basis for Processing Personal Data and Purposes of Personal Data Processing The Company processes Customers’ Personal Data for the following purposes based on the consent of the Data Subject or other legal bases, including the performance of agreements, compliance with legal obligations, and other legal bases as described below. 4.1.2.1. Based on the consent of the Data Subject, Personal Data shall be processed for: (a) Marketing and advertising Conducting consultation, introduction, and communication of the Company’s products and services through events, programs, community activities, or other forms such as websites, applications, and digital platforms; Personalizing and conducting advertising and marketing activities on websites, applications, digital platforms, and other channels based on Customers’ preferences. (b) Research, development, and improvement of products and services Conducting activities relating to research, development, and improvement of products/services; Personalizing Customer experiences through improvements to technology, website interfaces, social networks, and applications to ensure convenience for Customers. (c) Transferring Personal Data to third parties for such third parties to use for their own purposes (e.g., research and development; advertising and marketing of products and services) in accordance with applicable laws. 4.1.2.2. Carrying out other purposes permitted by law for processing Personal Data without the consent of the Data Subject, including: (a) Assessing the ability to provide products and services to specific Customers, including: - Identifying and verifying information relating to the Data Subject. - Assessing, appraising, and approving the provision of products and services based on registration documents, applications, requests, contracts of the Data Subject and/or related persons of the Data Subject. - Considering the provision or continued provision of any products or services of the Company to the Data Subject. (b) Performing contracts, agreements, and other documents between the Company and the Data Subject, and supporting Customers, including: - Performing obligations under contracts, agreements and providing products and services to the Data Subject. - Updating and processing information of the Data Subject. - Providing customer care services and resolving complaints and claims of the Data Subject. - Using and transferring Personal Data and related information to partners for the purposes of identifying and resolving product and service issues; repairing products. - Contacting and notifying the Data Subject. - Implementing promotional programs, gift exchange programs, awarding programs, and delivering gifts. - Conducting other customer care and support activities, such as providing services and utilities to serve Customers. - Providing and operating online services through websites, applications, and digital platforms. - Organizing and managing events, programs, and community activities. (c) For the purpose of performing the Company’s legal obligations - Complying with legal regulations on taxation, accounting, anti-money laundering, cybersecurity, and other relevant legal regulations and international treaties to which Vietnam is a member. - Complying with requests and decisions of competent state authorities. (d) For the purpose of protecting the lawful and legitimate rights and interests of the Data Subject and/or the Company - Ensuring security, safety, and order at urban areas, buildings, events, and locations of the Company; protecting the lawful and legitimate rights and interests of the Data Subject, the Company, and other relevant parties. - Preventing, investigating, detecting, preventing, and handling crimes and acts infringing upon the life, health, property, lawful rights, and legitimate interests of the Company and Customers. (e) For the purpose of handling emergency situations. The processing of Personal Data under this Section includes the transfer of Personal Data to Personal Data Processors and third parties (e.g., subcontractors) to carry out the purposes stated above. During the course of its business operations, the Company may carry out forms of corporate restructuring, including but not limited to restructuring, division, separation, merger, or consolidation. In such cases, Personal Data and the rights to use related information may be transferred and/or continue to be processed for the purpose of carrying out the aforementioned activities, provided that such processing does not give rise to any new data processing purposes beyond those specified in Section 4.1.2.2 herein. 4.2. For Personnel including Candidates 4.2.1. Types of Personal Data Collected 4.2.1.1. Personal Data of Candidates applying for positions at the Company: (a) Basic Personal Data: - Contact and identification information, including full name, email address, identification document number, address, phone number, date of birth, gender, marital status, and family relationships. - Educational qualifications and work experience, professional qualifications, skills, employment history, and other information stated in the candidate information form. - Other Personal Data voluntarily provided by candidates during the recruitment process. (b) Sensitive Personal Data: - Images of identification cards, citizen identification cards, identity cards, and passports. - Health information, such as height, weight, medical history, and health classification results. - Ethnic origin and religion. - Salary and income information at the most recent workplace. 4.2.1.2. Personal Data of Employees, Interns, and Collaborators of the Company (a) Basic Personal Data: - Contact and identification information, including full name, employee ID/internal identification code, date of birth, gender, nationality, residential address/contact address, work email address, phone number, personal images (ID photos, profile photos), emergency contact information, and beneficiary information (if applicable). - Legal and identification information: Citizen identification card/identity card/passport number; tax identification number; social insurance number, health insurance number; residency status; work permits, visas; information relating to foreign employees (if any). - Occupational information and employment relationship: Job title; work position; commencement date and termination date of employment relationship; offer letters; labor contracts/probationary contracts; employment history. - Recruitment records and qualifications: Curriculum vitae; job application records; educational background, professional qualifications; degrees, certificates; personal background verification information. - Human resource management information: Performance evaluations; rewards; disciplinary records; working hours; overtime; annual leave, sick leave, maternity leave, and other types of leave. - Financial, income, and benefits information: Insurance information; benefits and other entitlements arising from employment relationships or contractual relationships. - Family and dependent information (if applicable): Full names, dates of birth, and contact information of spouse, children, and dependents; information serving tax, insurance, and benefits obligations. - Training and development information: Internal training records; training certificates and results; information relating to skills development and career pathways. - Information serving internal operations and management: Work-related travel and movement information; personal vehicle information (e.g., vehicle license plate number); access control data, employee card information (to the extent necessary); information technology system usage data, work email, work schedules; system access logs; image, video, and audio recording data at the workplace for security, safety, training, or internal management purposes. (b) Sensitive Personal Data: - Salary, wages, bonuses, allowances; personal income tax information. - Images of identification cards, citizen identification cards, identity cards, and passports. - Bank account information used for payment of salary, wages, bonuses, allowances, and benefits. - Biometric data: Facial recognition data and other biometric data (in cases where the Data Subject registers for or consents to the use of such data). - Financial, credit, and transaction information: Information relating to contracts, transactions, financing, guarantees, or loans (including financial and credit information); bank account information and payment-related information (including financial transaction information). - Criminal record information (if required by law or the nature of the job). - Health information, medical conditions, and health classification. - Audio and video recording data capable of identification: Data collected from audio and video recordings at the workplace within the scope that may be used for identification purposes, serving human resource management, work management, and compliance with relevant legal regulations. 4.2.2. Legal Basis for Processing Personal Data and Purposes of Personal Data Processing 4.2.2.1. Based on the consent of the Data Subject: - For Candidates: For recruitment purposes for job positions at the Company (including receiving applications, assessing suitability, making recruitment decisions, and carrying out related activities); - For Candidates, Employees, Interns, and Collaborators: Notifying and contacting them regarding other future job opportunities. - Other cases where consent is provided by the Data Subject. 4.2.2.2. Carrying out other purposes permitted by law for processing Personal Data without the consent of the Data Subject, including: (a) For the purpose of performing labor contracts and other agreements between the Data Subject and the Company (Employees/Interns/Collaborators) - Establishing, maintaining, managing, and terminating employment relationships, contractual relationships, or cooperation relationships. - Adjusting job assignments and working conditions. - Paying salaries, wages, implementing benefits, insurance schemes, and other entitlements. - Managing and evaluating work performance, and providing training and personnel development. - Organizing and managing the working environment, supporting work activities, and internal operations. (b) For the purpose of performing the Company’s legal obligations - Preparing, maintaining, and storing mandatory personnel records in accordance with legal regulations. - Fully complying with legal regulations on labor, occupational safety and hygiene, salaries, working hours, taxation, social insurance, gender equality, management of foreign employees, reporting obligations, and other relevant regulations. - Complying with requests and decisions of competent authorities. (c) For the purpose of protecting the lawful and legitimate rights and interests of the Data Subject and/or the Company - Ensuring security, safety, and order at the workplace; protecting the lawful and legitimate rights and interests of Personnel, the Company, and other relevant parties. - Preventing, investigating, detecting, preventing, and handling crimes; minimizing legal risks; resolving disputes and complaints related to Personnel and the Company. - Ensuring health and safety, handling incidents, and protecting the lawful and legitimate rights and interests of Personnel at the workplace. (d) For the purpose of handling emergency situations. The processing of Personal Data under this Section includes the transfer of Personal Data to Personal Data Processors and third parties (e.g., subcontractors) to carry out the purposes stated above. During the course of its business operations, the Company may carry out forms of corporate restructuring, including but not limited to restructuring, division, separation, merger, or consolidation. In such cases, Personal Data and the rights to use related information may be transferred and/or continue to be processed for the purpose of carrying out the aforementioned activities, provided that such processing does not give rise to any new data processing purposes beyond those specified in Section 4.2.2.2 herein. 4.3. For Contact Persons of Partners and Individual Partners 4.3.1. Types of Personal Data Collected: - Contact information: Full name; date of birth; identification document number (Citizen Identification Card/Identity Card) or personal identification number; job title; email address; workplace address; contact phone number. - Professional qualifications, work experience, and practicing licenses (if applicable) in certain cases where verification of the Partner’s suitability is required. - Entry and exit information at the Company’s locations. - Sensitive Personal Data (if any) collected from audio and video recording activities through security cameras at the Company’s locations; images of identification cards, citizen identification cards, and identity cards. - Other Personal Data provided by the Partner during the process of communication, cooperation, and performance of contractual agreements. 4.3.2. Legal Basis for Processing Personal Data and Purposes of Personal Data Processing Carrying out purposes permitted by law for processing Personal Data without the consent of the Data Subject, including: 4.3.2.1. For the purpose of performing agreements between the Company and the Partner: - Verifying the Partner’s suitability for the scope of cooperation. - Contacting, communicating, negotiating, and coordinating work between the Company and the Partner. - Establishing, maintaining, and managing the cooperation relationship. - Performing and managing relevant contracts and transactions. 4.3.2.2. For the purpose of performing the Company’s legal obligations: - Preparing, maintaining, and storing mandatory records in accordance with legal regulations. - Complying with requests and decisions of competent authorities. - Complying with legal regulations on tax management, accounting, and other relevant legal regulations. 4.3.2.3. For the purpose of protecting the lawful and legitimate rights and interests of the Data Subject and/or the Company: - Ensuring security, safety, and order at the Company; protecting the lawful and legitimate rights and interests of the Partner, the Company, and other relevant parties. - Preventing, investigating, detecting, preventing, and handling crimes; minimizing legal risks related to the Partner and the Company. - Recording, controlling entry and exit, and monitoring through security camera systems. - Protecting people, assets, as well as the lawful and legitimate rights and interests of the Partner, Contact Person, and the Company during the cooperation process. 4.3.2.4. For the purpose of handling emergency situations. The processing of Personal Data under this Section includes the transfer of Personal Data to Personal Data Processors and third parties (e.g., subcontractors) to carry out the purposes stated above. During the course of its business operations, the Company may carry out forms of corporate restructuring, including but not limited to restructuring, division, separation, merger, or consolidation. In such cases, Personal Data and the rights to use related information may be transferred and/or continue to be processed for the purpose of carrying out the aforementioned activities, provided that such processing does not give rise to any new data processing purposes beyond those specified in Section 4.3.2 herein. 4.4. For Shareholders and Internal Persons (including Related Persons) 4.4.1. Types of Personal Data Collected - Contact information: Full name; date of birth; nationality; identification document number (Citizen Identification Card/Identity Card/Passport) or personal identification number; email address; contact address; contact phone number. - Information on owned shares/stocks: Number of shares/stocks owned; ownership percentage; time of becoming/ceasing to be a shareholder; ownership change history. - Information on share/stock transactions: Transaction registration date; transaction history; transaction value; transaction reports of Internal Persons and Related Persons. - Information on relevant rights and obligations of Shareholders: Voting rights; voting information; purchase rights, issuance rights; rights to receive dividends and profits. - Information on positions within the Company: Position/title; management role; scope of authority and responsibilities; appointment and dismissal dates. - Legal relationship information: “Related Person” relationships as prescribed by law; information of Internal Persons/Related Persons (including historical information). - Tax information: Tax obligations arising from dividends, transfer of shares/stocks. - Ownership verification information: Legal documents and documents evidencing ownership of contributed capital/shares. - Information on attendance at General Meeting of Shareholders and authorization: List of individuals attending meetings; personal information of authorized persons participating in meetings and voting. - Data serving governance and control purposes, including data used for detecting conflicts of interest and information relating to signs of violations of information disclosure obligations or corporate governance obligations. - Data serving dispute resolution and protection of rights and interests: Legal records; evidentiary documents; information exchanged in relation to complaints, disputes, and legal proceedings; data serving the reconciliation of obligations and protection of rights and interests after transactions. - Sensitive Personal Data (if any): Bank account information for receiving dividends, profits, or conducting transactions relating to contributed capital/shares; images of identification cards, citizen identification cards, and identity cards. - Other necessary personal information as required by law from time to time (if any) to serve the Company’s governance in accordance with regulations on enterprises and securities. 4.4.2. Legal Basis for Processing Personal Data and Purposes of Personal Data Processing Carrying out purposes permitted by law for processing Personal Data without the consent of the Data Subject, including: 4.4.2.1. For the purpose of performing mandatory legal obligations regarding corporate governance, securities (if applicable), and relevant regulations - Preparing and maintaining shareholder/member registration books and managing the history of share/contributed capital ownership. - Disclosing information and preparing periodic/ad hoc reports in accordance with applicable laws (including laws on enterprises, securities, and specialized regulations, if any). - Managing transactions, changes in ownership, contributed capital, and transactions of Internal Persons and Related Persons. - Performing tax and financial obligations related to capital owners. - Serving inspections, examinations, audits, and requests from competent state authorities. - Storing records in accordance with legal regulations. 4.4.2.2. For the purpose of performing agreements, rights, and obligations of the Data Subject in accordance with applicable laws - Exercising rights and performing obligations established under the Company’s Charter, resolutions/decisions of the General Meeting of Shareholders, the Board of Directors, authorization agreements, and other lawful legal relationships. - Managing lists of meeting attendees, authorized persons, voting information, and decision-making procedures at meetings. - Recording and exercising shareholders’ rights, including: receiving dividends/profits, transferring shares/stocks, purchase rights, issuance rights, and other arising rights/benefits. - Communicating and contacting shareholders and Internal Persons (including Related Persons) to ensure the rights of shareholders, Internal Persons, and to serve corporate governance activities. 4.4.2.3. For the purpose of protecting the lawful and legitimate rights and interests of the Data Subject and/or the Company - Preventing, detecting, and managing conflicts of interest in the governance and operation of the Company. - Preventing insider trading, misuse of internal information, and other related violations of law. - Monitoring and minimizing risks of violations of governance obligations, information disclosure obligations (if applicable), and other legal obligations. - Responding to requests, recommendations, complaints, and resolving disputes and arising rights and interests, including after the termination of the status of shareholder, Internal Person, or Related Person. - Protecting the reputation, transparency, and compliance of the Company’s operations. 4.4.2.4. Performing other responsibilities of the Company (if any) in accordance with applicable laws from time to time. The processing of Personal Data under this Section includes the transfer of Personal Data to Personal Data Processors and Third Parties (e.g., subcontractors) to carry out the purposes stated above. During the course of its business operations, the Company may carry out forms of corporate restructuring, including but not limited to restructuring, division, separation, merger, or consolidation. In such cases, Personal Data and the rights to use related information may be transferred and/or continue to be processed for the purpose of carrying out the aforementioned activities, provided that such processing does not give rise to any new data processing purposes beyond those specified in Section 4.4.2 herein.
5. SHARING AND TRANSFER OF PERSONAL DATA
5.1. General Principles When sharing and transferring Personal Data to third parties, the Company commits to: - Only sharing Personal Data within the necessary scope in accordance with the Personal Data Processing purposes specified for each category of Data Subject; and - Requiring data recipients to apply appropriate data protection measures. 5.2. Data Recipients Depending on each category of Data Subject, the purposes and activities of Personal Data Processing, the Company may share, provide, or transfer Personal Data to the following data recipients:
Data Recipient Purpose of Sharing

Parent companies, subsidiaries, and affiliated companies of the Company

Sharing and transferring Personal Data within the necessary scope and in accordance with the purposes and activities of Personal Data Processing specified in this Policy.

Service providers and operational partners

Service providers may include:

- Public services, utilities, repair, upgrade, and maintenance services;

- Information technology services, digital platforms, and management systems (including: sales, brokerage, human resources, shareholders, and contracts);

- Payment and transaction processing services;

- Payroll, tax, insurance, benefits, and other human resources administrative services;

- Data storage, database management, and operation services;

- Recruitment, assessment, training, and personnel development services;

- Operational support services, brokerage management, and sales system services;

- Contract management services and information exchange with partners;

- Legal, financial, audit, corporate governance consulting services, and other professional services.

The Company may share and transfer Personal Data with service providers and partners to carry out Personal Data Processing activities on behalf of the Company. These parties may only Process Personal Data within the scope and for the purposes determined by the Company and must comply with confidentiality and information security requirements under agreements with the Company and applicable laws.

Media and advertising partners

To conduct communication and product promotion activities, the Company may coordinate and share Personal Data with media and advertising partners, provided that:

- The sharing is consistent with the notified processing purposes;

- It complies with applicable advertising regulations;

- Consent of the Data Subject is obtained in cases required by law.

The Company does not share Customers' contact information with third parties for independent marketing purposes without an appropriate lawful basis.

Relevant parties in cases of corporate restructuring or reorganization, including division, separation, merger, or consolidation of enterprises

In the event that the Company participates in or is involved in organizational restructuring activities such as division, separation, merger, or consolidation, Personal Data may be disclosed or transferred as part of such transaction, provided that the data recipient continues to comply with Personal Data protection requirements in accordance with applicable laws.

Relevant parties in cases of compliance with legal obligations and protection of the Company's and Data Subject's lawful rights and interests outside contractual obligations

The Company may provide Personal Data to competent state authorities, legal advisors, or relevant parties where necessary to:

- Comply with legal regulations or lawful requests;

- Establish, exercise, or protect the Company's lawful rights and interests;

- Prevent, detect, and handle fraud and violations;

- Protect the safety, health, rights, and lawful interests of the Data Subject or other individuals and organizations.

Entities engaged in research and development activities in blockchain technology, virtual worlds, artificial intelligence, and other automated systems

The Company may provide, share, and transfer Personal Data for the purposes of researching and developing technology products and services, including blockchain technology, virtual worlds, artificial intelligence, and other automated systems, provided that all relevant legal requirements are fully complied with.

Third parties at the request or with the consent of Customers

The Company may share Personal Data with third parties based on the consent or explicit instructions of the Data Subject.

The transfer of Personal Data in accordance with this Policy and applicable laws, whether subject to fees or not, shall not be considered as the purchase or sale of Personal Data.
6. PROCESSING OF PERSONAL DATA IN SCIENCE AND TECHNOLOGY ACTIVITIES
6.1. Transfer of Personal Data for Science and Technology Development On the basis of appropriate legal grounds and strict compliance with Applicable Laws, the Company may transfer Personal Data to parent companies, subsidiaries, affiliated companies, and technology partners for the purposes of science, technology development, and innovation, including: - Researching and developing financial technology (Fintech) products and services; - Big Data processing; - Developing and operating blockchain technology, virtual world (Metaverse) systems, and cloud computing; - Cybersecurity technology; - Technologies applying machine learning algorithms, artificial intelligence (AI) systems, and other automated systems. 6.2. Compliance Conditions for Data Transfer and Processing in a Technology Environment All activities of transferring and Processing Personal Data in big data, artificial intelligence, blockchain, virtual world, and cloud computing environments shall be conducted for proper purposes, limited to the necessary scope, and in compliance with Applicable Laws. The Company shall only Process Personal Data when ensuring compliance with the following requirements: - The Processing activities are consistent with the purposes notified to the Data Subject and have appropriate legal grounds. If the law requires the consent of the Data Subject for the transfer or Processing of Personal Data for artificial intelligence or automated systems, the Company shall obtain the consent of the Data Subject. - Continuously monitoring, inspecting, and periodically assessing cybersecurity and data security. - Classifying risks associated with artificial intelligence-based Processing activities; notifying Data Subject of automated Processing activities, explaining algorithmic principles, and allowing Data Subject to choose not to participate. - Binding Data Recipients through data transfer/processing agreements with confidentiality obligations and requiring such recipients to Process Personal Data only within the scope and purposes determined by the Company. - Not using or developing systems that use Personal Data to cause harm to national defense, national security, social order and safety, or infringe upon the lawful rights and interests of others.
7. DATA RETENTION PERIOD
7.1. The Company shall only retain Personal Data of Data Subject for the period necessary to fulfill the processing purposes specified in this Personal Data Protection Policy or as required by applicable laws. 7.2. Once the purpose of Personal Data Processing has been completed or there is no longer a need to use Personal Data for the notified purposes, the Company shall promptly delete, destroy, or anonymize Personal Data, except where applicable laws permit or require continued retention for a specific period. The Company may be required to retain Personal Data even after the termination of contracts between the parties in order to fulfill obligations under applicable laws and/or requirements of competent state authorities. 7.3. In cases where the law requires the deletion or destruction of Personal Data, the Company shall carry out such deletion or destruction promptly in accordance with applicable regulations, and simultaneously apply necessary measures to ensure that the Personal Data can no longer be accessed, recovered, or unlawfully used. 7.4. The Company commits that the retention, deletion, and destruction of Personal Data shall always be carried out carefully, securely, and in compliance with applicable laws, in order to protect the lawful rights and interests of the Data Subject and the Company.
8. PERSONAL DATA PROTECTION MEASURES
8.1. To best protect Customers’ information, the Company has implemented and continues to apply the following specific measures: 8.1.1. Technical measures to prevent unauthorized access to and use of Personal Data. The Company regularly cooperates with security experts to update the latest cybersecurity technologies to ensure the safety of Personal Data. All new software systems or significant updates must undergo a strict assessment and penetration testing (Pentest) process before being put into actual operation. 8.1.2. Organizational measures, including establishing internal regulations and policies on Personal Data protection, third-party risk management processes; appointing dedicated personnel and compliance monitoring departments. The Company implements monitoring mechanisms, periodic and ad hoc inspections of compliance with security policies to promptly detect and handle potential risks. 8.1.3. Operational measures, including maintaining periodic and daily data control processes; implementing data backup and disaster recovery plans to ensure that data is stored and processed for the committed purposes and within the committed scope. Establishing cybersecurity incident response procedures and regularly providing security awareness training for personnel. 8.1.4. Physical measures, including establishing physical barriers and strict access control systems for information technology infrastructure areas, servers, and data storage devices. Ensuring physical safety of facilities and equipment to prevent any unauthorized access. 8.2. In addition, when it is necessary to share Personal Data with third parties for the purposes specified in this Policy, the Company requires relevant parties to apply appropriate data protection measures to ensure that Personal Data continues to be processed securely. However, due to the nature of the technology environment and the Internet, no security measure can guarantee absolute safety. Therefore, although the Company always strives to apply appropriate measures, we cannot absolutely guarantee or commit that your Personal Data will always be secure in all circumstances.
9. PROTECTION OF THE RIGHTS AND INTERESTS OF VULNERABLE CONSUMERS
9.1. In cases where Customers fall into the group of vulnerable consumers under Applicable Laws, the Processing of Customers’ Personal Data shall be carried out carefully, appropriately, and with enhanced protection to ensure the lawful rights and interests of Customers. 9.2. Where necessary to receive and process Customers’ requests, the Company may collect relevant information and documents to determine the status of vulnerable consumers, based on the following principles: 9.2.1. Only collecting information within the necessary scope; 9.2.2. Using data solely for the purpose of receiving and processing requests; 9.2.3. Applying appropriate security measures to the Personal Data generated. 9.2.4. In cases where Customers’ rights and interests are infringed and Customers request protection: The receiving officer shall be responsible for forwarding Customers’ requests to the appropriate competent authority/level responsible for handling Customer complaints in accordance with the Company’s regulations from time to time, ensuring that Customers receive support, services, and responses as soon as possible; 9.2.5. The Company prioritizes directly receiving and handling requests from vulnerable consumers over requests from ordinary Customers. 9.3. Processing of Personal Data of children and persons who have lost or have limited civil capacity: 9.3.1. The Company shall only Process Personal Data within the necessary scope to ensure the rights, lawful interests, and safety of the aforementioned subjects, for example: - Assisting children or vulnerable persons in accessing and using services and utilities; - Ensuring security, safety, and an appropriate, friendly environment for the provision of services and products; - Performing necessary obligations in accordance with legal regulations. 9.3.2. In cases where the law requires consent for the Processing of Personal Data, such consent shall be provided by the legal representative on behalf of children or persons who do not have full civil capacity, unless otherwise provided by law. Specifically, for children aged 07 years or older, where the processing of data is intended to disclose or reveal information relating to private life or personal confidentiality, the Company shall only carry out such processing with the consent of both the child and the legal representative. 9.4. In cases where the Company refuses to handle Customers’ requests, the Company shall respond to Customers in writing, clearly stating the legal basis and the reasons why the Customers’ requests are inappropriate.
10. RIGHTS AND OBLIGATIONS OF DATA SUBJECT
10.1. Data Subject have the following rights relating to their Personal Data, including: 10.1.1. Being informed of Personal Data Processing activities. 10.1.2. Giving consent or refusing to give consent, and requesting withdrawal of consent for Personal Data Processing. 10.1.3. Accessing, correcting, or requesting correction of Personal Data. 10.1.4. Requesting the provision, deletion, or restriction of Personal Data Processing; submitting requests to object to Personal Data Processing. 10.1.5. Filing complaints, denunciations, initiating lawsuits, and requesting compensation for damages in accordance with applicable laws. 10.1.6. Requesting the implementation of measures and solutions to protect their Personal Data in accordance with applicable laws. 10.2. Data Subject may exercise their rights relating to their Personal Data by submitting requests to the Personal Data Protection Department through the contact information provided in the relevant section, by submitting a written request directly, via email, or through other electronic means. 10.3. Any request to exercise Data Subject rights must at least specify the following contents: 10.3.1. Information of the Data Subject (full name, email address, or phone number). 10.3.2. The specific right that the Data Subject wishes to exercise and the type of Personal Data relating to the request. 10.3.3. The reasons and purposes for exercising the right (if any); and 10.3.4. Information and documents relating to the exercise of the Data Subject’s rights. 10.4. Upon receipt of a request, we shall verify the identity, validity, completeness, and accuracy of the request in accordance with applicable laws, and assess the ability to fulfill such request. We reserve the right to request additional information for verification purposes or refuse to process the request if: 10.4.1. The Data Subject fails to provide sufficient information to verify their identity and the validity of the request; or 10.4.2. Applicable laws do not permit the Company to fulfill the Data Subject’s request; or 10.4.3. There is a specific request from a competent state authority. 10.5. Please note that the aforementioned rights are not absolute and may be subject to limitations under certain legal provisions, exceptions, as well as other statutory requirements and principles. In specific circumstances, the Company may have the right to refuse or restrict the exercise of such rights in accordance with applicable laws.
11. AMENDMENTS AND UPDATES
11.1. This Policy may be updated, amended, supplemented, or replaced by the Company from time to time, provided that such updates, amendments, supplements, or replacements do not violate Applicable Laws and/or are intended to better protect the information of Data Subject. 11.2. Any updates, amendments, supplements, or replacements to this Policy (if any) shall be publicly posted by the Company in accordance with Applicable Laws from time to time. Data Subject should regularly access and check the website to stay updated on the latest changes.
12. INFORMATION OF THE PERSONAL DATA PROTECTION RESPONSIBLE DEPARTMENT
If you have any questions regarding the Company’s Personal Data protection activities, please contact the department responsible for Personal Data protection using the information below. GSM GREEN AND SMART MOBILITY JOINT STOCK COMPANY Head office: Symphony Office Building, Chu Huy Man Street, Vinhomes Riverside Urban Area, Phuc Loi Ward, Hanoi City, Vietnam Email: DPOoffice@greensm.com
13. NOTICE
This Policy shall be deemed as a notice prior to the processing of Personal Data by the Company. Accordingly, the Company and relevant organizations and individuals participating in the Personal Data Processing process shall not be required to provide additional notices prior to Processing Personal Data.
14. EFFECTIVENESS
This Personal Data Protection Policy shall take effect from 31 July 2026 and replace the Personal Data Protection Policy and Consumer Information Protection Rules issued before the effective date of this Policy.

GSM GREEN AND SMART MOBILITY JOINT STOCK COMPANY
Hotline: 1555
Symphony Office Building, Chu Huy Man Street, Vinhomes Riverside Urban Area, Phuc Loi Ward, Hanoi City, Vietnam
SOCIAL MEDIA
FacebookLinkedInZaloVcreator
Business ID: 0110269067 first issued by Hanoi Department of Finance on March 1, 2023.
Transport license No. 9620/GPKDVT issued for the fourth time by Hanoi Department of Construction on September 23, 2025.
Postal service confirmation No. 6150/XN-BTTTT issued by the Ministry of Information and Communications on December 13, 2023.
Bo Cong Thuong
© 2026 GSM. All rights reserved | Terms & Legal | Privacy Policy | Cookies setting
google play
apple store
Experience the App Now
Download app qrcode
Download app qrcode