Sunstar Singapore Pte. Ltd. Personal Data Protection Policy

Effective Date of Policy:1st June 2026

This Personal Data Protection Policy (“Policy”), including its jurisdiction-specific supplemental terms, sets out the basis upon which Sunstar Singapore Pte. Ltd. (“We”, “us”, or “our”) may collect, use, disclose, and/or otherwise process personal data in accordance with applicable laws such as the Singapore Personal Data Protection Act 2012 (“Singapore PDPA”) and all the associated regulations and guidelines as may from time to time be issued.

This Policy applies to personal data in our possession or under our control, including personal data in the possession of organisations which we have engaged to collect, use, disclose or process personal data for our purposes.

Please read the following carefully to understand our policies and practices regarding the handling of your personal data.

In the event of any inconsistency between the provisions of the jurisdiction-specific supplemental terms (“Jurisdiction-Specific Supplemental Terms”) and the main body of this Policy, the former shall prevail to the extent of the inconsistency.

To avoid doubt, where your personal data is collected, used, disclosed or otherwise processed by third-parties (such as our distributors, business partners and affiliates) acting in their own capacity and determining the purposes and means of processing, such third-parties shall be your data controller and shall be responsible for compliance with applicable local data protection laws. Sunstar Singapore shall not be responsible for the data processing activities of any such party acting as an independent data controller. In such cases, we encourage you to review their privacy notices to learn more on how they will handle any personal data they collect from you.

Application of this policy

  1. As used in this Policy, “personal data” means data, whether true or not, about an individual who can be identified: (a) from that data; or (b) from that data and other information to which we (and all our affiliated entities and relevant unaffiliated third-parties) have or are likely to have access. Depending on your relationship with us and the nature of your interaction with us, the personal data we collect may include, without limitation, your (or such person’s): name; address; telephone number(s); email address(es); date of birth; gender; nationality; marital status; passport number, date and place of issue; NRIC number or other national identification numbers; driver’s licence number and expiration date; photographs and other audio-visual material; employment information; payment information (such as bank account or credit card details); marketing preferences; preferred communication methods. We may also collect and process other personal data that you choose to provide to us or our affiliated entities, third-party service providers and agents, or where such collection is permissible or required under applicable laws.

  2. However, “business contact information” (which means an individual’s name, position name or title, business telephone number, business address, business electronic mail address or business fax number and any other similar information about the individual, not provided by the individual solely for his/her personal purposes, as the case may be) is not regarded as personal data for the purposes of this Policy, to the extent that such information is not governed by the applicable data protection law.

Use of cookies

  1. When you interact with us on our websites, we automatically receive and record information on our server logs from your browser. We may employ cookies in order for our server to recognise a return visitor as a unique user including, without limitation, monitoring information relating to how a visitor arrives at the website, what kind of browser a visitor is on, what operating system a visitor is using, a visitor's IP address, and a visitor's click stream information and time stamp (for example, which pages they have viewed, the time the pages were accessed and the time spent per web page).
  2. Cookies are small text files stored in your computing or other electronic devices which allow us to remember you or other data about you. The cookies placed by our server are readable only by us, and cookies cannot access, read or modify any other data on an electronic device. Most web-browsers offer the option to refuse any cookie, and if you refuse our cookie(s) then we do not gather any information on that visitor, though some functionality may be impaired.
  3. Should you wish to disable the cookies associated with these technologies, you may do so by either managing consent preferences in our pop-up to ‘opt-out’ of optional cookies or change the settings on your browser. However, this may affect your ability to enter certain parts of our website or use certain features.
  4. Our website may contain links to other websites operated by third-party companies with different privacy practices. We encourage you to learn about the privacy policies of such third-party websites. We have no control over personal data that you submit to or receive from these third parties

Purposes for collection, use and disclosure of personal data

  1. To the extent permitted by applicable law, we will only collect, use, or disclose your personal data where we have your consent, where it is necessary for our legitimate interests, or where otherwise permitted or required by applicable law. We may also collect, use or disclose your personal data that you knowingly and voluntarily provide in the course of or in connection with certain activities or transactions with us and/or our affiliated entities, third-party service providers and agents.

  2. We currently, and/or may in the future, collect, use and disclose your personal data as authorised or required by law, and/or for any or all of the following purposes (collectively, the “Purposes”):

    • performing obligations in the course of or in connection with our provision of products and/or services requested by you;
    • verifying your identity;
    • responding to, handling and processing your requests, queries, applications, complaints, and feedback;
    • managing your relationship with us;
    • evaluating and improving the quality and content of our products and services;
    • processing purchase, payment or credit transactions;
    • administrative purposes in relation to continuing professional education workshops and accreditation;
    • managing and organising events;
    • sending you marketing information about our goods and services including notifying you of our marketing events, initiatives and any promotions. Where required by applicable laws, we will obtain your prior express “opt-in” consent;
    • media coverage and publicity;
    • assessing and evaluating your suitability, eligibility or qualifications for employment or continued employment with us or with any of our affiliated entities, or for other engagements or appointments;
    • safeguarding and defending our rights and property or that of any of our affiliated entities against any security threat (including, but without limitation to, threats to our physical infrastructure and environment, computer systems, and network);
    • complying with any applicable laws, regulations, codes of practice, guidelines, or rules, or to assist in law enforcement and investigations conducted by any governmental and/or regulatory authorities;
    • any other purposes for which you provided the information;
    • transmission to any of our affiliated entities or any unaffiliated third parties including our third-party service providers and agents, and relevant governmental and/or regulatory authorities, whether in Singapore or abroad, for the aforementioned purposes; and
    • any other incidental business purposes related to or in connection with the above.
  3. The purposes listed above may continue to apply even in situations where your relationship with us (for example, pursuant to a contract) has been terminated or altered in any way, for a reasonable period thereafter (including where applicable, a period to enable us to enforce our rights under any contract with you).

  4. In compliance with applicable law, we also currently, and/or may in the future, collect, use and disclose your personal data without your consent for legitimate interest, in particular, for the following purposes:

    • detecting and preventing illegal, unlawful or unethical activities such as fraud and money laundering; and
    • safeguarding and defending our rights and property or that of any of our affiliated entities against any security threat (including, but without limitation to, threats to our physical infrastructure and environment, computer systems, and network).

Data security

  1. We will take reasonable precautions to protect your personal data from accidental loss, unauthorised access, collection, use, disclosure, duplication, modification, disposal, destruction, and the loss of any storage medium or device on which personal data is stored. You should be aware, however, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures.
  2. In the event of a data breach, we will take the relevant investigative and remedial steps, and notify the relevant regulators and/or affected individuals where required in accordance with applicable laws. In the case of Singapore, should a data breach occur that results in, or is likely to result in, significant harm to individuals whose personal data is affected, or is of a significant scale, we will notify the Singapore Personal Data Protection Commission and/or affected individuals as soon as practicable, in accordance with our obligations under the Singapore PDPA. We will also take steps to assess the impact of the breach and to mitigate any potential harm.

Accuracy of personal data

  1. We generally presume that personal data provided by you (or your authorised representative) is complete and accurate and rely on you to ensure the accuracy of such data. In order to ensure that your personal data is current, complete and accurate, please update us if there are changes to your personal data by contacting our Data Protection Officer (“DPO”) at the contact details provided below.

Retention of personal data

  1. Personal data will be held only for as long as it is necessary to fulfil the purpose for which it was collected, or as required or permitted by applicable laws. We will cease to retain personal data or remove the means by which the personal data can be associated with particular individuals, as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected, and is no longer necessary for legal or business purposes.

International transfers of personal data

  1. In situations where we transfer your personal data to countries outside of your jurisdiction (e.g., to our affiliated entities, or to third-party service providers who may be located overseas), we will take steps to ensure that your personal data continues to receive a standard of protection that is at least comparable to that provided under the data protection law of your jurisdiction, unless we are able to rely on other grounds for transfer under applicable laws. This may include ensuring that the recipient is bound by legally enforceable obligations to provide a comparable standard of protection.
  1. Withdrawal of Consent:

    • You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by submitting your request to our DPO;
    • Upon receipt of your written request to withdraw your consent, we will process your request within a reasonable time and thereafter cease (and cause our data intermediaries and agents to cease) to collect, use and/or disclose your personal data in the manner stated in your request, unless otherwise permitted or required under applicable laws;
    • Please note that withdrawing consent does not affect our right to continue to collect, use and disclose personal data where such collection, use and disclosure without consent is permitted or required under applicable laws. The withdrawal of consent may result in certain consequences. For example, it may mean that we will not be able to continue providing certain services to you. We will inform you of such consequences.
  2. Access to and Correction of Personal Data:

    • If you wish to request access to a copy of the personal data which we hold about you, or information about the ways in which we have used or disclosed your personal data within a year before the date of your request, please submit your request in writing to our DPO.
    • Please note that a reasonable fee may be charged for an access request where permitted by applicable law. If so, we will inform you of the fee before processing your request.
    • We will respond to your access request as soon as reasonably possible. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under applicable law).
    • If you wish to request to correct an error or omission in the personal data which we hold about you, please submit your request in writing to our DPO. We will correct your personal data as soon as practicable after the request has been received, unless we have reasonable grounds not to do so.
    • Where required under applicable law, we will also send the corrected personal data to every other organisation to which the personal data was disclosed to in accordance with applicable requirements.
  3. Other Data Subject Rights:
    Subject to applicable laws, you also have the following rights:

    • Right to be informed: To be informed of whether personal data pertaining to you shall be, are being or have been processed;
    • Right to data portability: To request that we transmit your personal data that is in our possession or under our control, to another organisation in a commonly used machine-readable format;
    • Right to erasure: To request the deletion, erasure, anonymisation of personal data;
    • Right to object or restrict the processing of your personal data: To object or restrict to the processing of your personal data for a specified purpose or in a specified manner.
  4. If you wish to exercise any of these rights, please contact our DPO. The DPO will respond to your request in accordance with the timelines and requirements under the applicable laws.

  5. Specific rights, requirements, or limitations that apply in particular jurisdictions are set out in the Jurisdiction-Specific Supplemental Terms for those jurisdictions.

Data protection officer

  1. If you have any questions or feedback regarding this Policy, please write to:

The Data Protection Officer

Sunstar Singapore Pte Ltd

3 Fusionopolis Link #02-07

Nexus @ One-North

Singapore 138543

Complaints handling process

  1. All complaints regarding our handling of personal data or alleged breaches of our obligations under applicable law may be referred to the DPO, we will endeavour to acknowledge receipt of the complaint within five (5) working days, subject to the Jurisdiction-Specific Supplemental Terms. Further contact will be dependent upon the nature of the complaint..

  2. The DPO will investigate the complaint and endeavour to provide a substantive response to all valid complaints within thirty (30) days from the date the complaint was acknowledged, or as soon as reasonably practicable, whichever is earlier. This shall be subject to the Jurisdiction-Specific Supplemental Terms.

Changes to policy

  1. We reserve the right to modify or update this Policy, including its Jurisdiction-Specific Supplemental Terms, at any time to ensure it is consistent with our future developments, industry trends and/or any changes in legal or regulatory requirements. The effective date, as stated above, indicates the last time this Policy was materially revised. If we make material changes to this Policy, we will post any changes on this page. Please review this page periodically for updated information on our policies and practices regarding the handling of your personal data. Your continued use of our services after any changes to this Policy constitutes your acceptance of the revised Policy.

Jurisdiction-specific supplemental terms

INDONESIA

General

  1. The applicable law for personal data in Indonesia is Law No. 27 of 2022 on Personal Data Protection (“PDP Law”) and prevailing implementing regulations.
  2. This Policy and this Jurisdiction-Specific Supplemental Terms for Indonesia apply only where we directly determine the purposes and means of processing personal data in Indonesia as provided under paragraphs 7 and 8.
  3. As used in this Policy, “personal data” under the PDP Law means data of an individual that is or can be identified specifically or in combination with other information, either directly or indirectly through an electronic or non-electronic system.
  4. In addition to paragraph 7, in certain circumstances, we may process your personal data without consent where permitted by law, including: (i) to perform contractual obligations; (ii) to comply with legal or regulatory requirements; (iii) to protect the vital interests of the data subject; or (iv) to carry out duties in the public interest or in the exercise of official authority.

Data Breach

  1. In the event of a data breach, we will notify you within 3 x 24 hours (3 calendar days) as of our knowledge of such an event and the authority about what happened, when and how it occurred, and what impact it may have. We will also share the steps we are taking to fix the issue and prevent it from happening again. Should a data breach occur that disrupts public services and/or has a serious impact on the interest of the public, we will notify the public, within the required timeline in accordance with our obligations under the PDP Law.

Accuracy Of Personal Data

  1. We are committed to ensuring that the personal data we process is accurate, complete, and consistent, in accordance with applicable laws and regulations. To achieve this, we will verify the personal data you provide. Please help us maintain the accuracy of your information by updating us promptly if any of your personal data changes by contacting our DPO at the contact details provided under paragraph 21.

International Transfers of Personal Data

  1. In situations where we transfer your personal data to countries outside of your jurisdiction (e.g., to our affiliated entities, or to third-party service providers who may be located overseas), we will take steps to ensure that the country of the recipient provides a level of data protection equivalent to or higher than that required under the PDP Law. If this standard cannot be guaranteed, we will implement adequate and legally binding safeguards to protect your personal data. In cases where neither of these measures can be ensured, we will obtain your consent before transferring your data.

Rights of Data Subject

  1. Paragraph 17 will be revised in its entirety to read as follows. You have the right to access the personal data we process about you, including a record of how it has been processed, for as long as we retain your data. You also have the right to request corrections or updates to ensure accuracy and completeness of your personal data and to request that the processing of your personal data be temporarily delayed or restricted, in whole or in part. We will respond within 3 x 24 hours (3 calendar days) of the time we receive your request without cost unless for certain circumstances and we deem that it is necessary, a reasonable fee may be charged for an access request.

  2. In addition to your rights under paragraphs 16 and 18, you may request copies of your data, and, in the event of a violation of data confidentiality, you may file a civil lawsuit and seek compensation. You also have the right to object if a decision about you is made only through automated processing, including profiling, especially if it creates legal effects or has a significant impact on you.

Changes to Policy

  1. We reserve the right to modify or update this Policy, including its Jurisdiction-Specific Supplemental Terms, at any time to ensure it is consistent with our future developments, industry trends and/or any changes in legal or regulatory requirements. The effective date, as stated above, indicates the last time this Policy was materially revised. If we make material changes to this Policy, we will post any changes on this page. To the extent your additional consent is required under the applicable law, we will first obtain your express consent. If you do not provide your consent (which is your right), we may not be able to continue providing certain services to you.

MALAYSIA

  1. This Policy applies to personal data processed by us acting as a data controller in Malaysia.

  2. Any reference in the main body of this Policy to the collection, use, or disclosure of personal data (and any similar expression) shall be deemed to include, and shall be construed as referring to, the processing of personal data as defined under Malaysia’s Personal Data Protection Act 2010, which means collecting, recording, holding or storing personal data or carrying out any operation or set of operations on the personal data, including:

    • the organisation, adaptation or alteration of personal data;
    • the retrieval, consultation or use of personal data;
    • the disclosure of personal data by transmission, transfer, dissemination or otherwise making available; or
    • the alignment, combination, correction, erasure or destruction of personal data.
  3. We may collect your personal data from various sources, including personal data you knowingly and voluntarily provide to us in the course of, or in connection with, your activities or transactions with us. In addition, we may collect your personal data from our affiliated entities, third-party service providers and agents, distributors, insurers, auditors and other advisors, online platform operators, as well as from publicly available sources where permitted by law.

  4. We may disclose or transfer your personal data to our affiliated entities, third-party service providers and agents who provide services including professional and legal advisory services, including insurers and auditors, and other advisors. We may also share your personal data with business partners, distributors, online platform operators, organisers, external trainers, accreditation bodies, and employment screening providers where relevant, as well as with financial institutions and payment networks in connection with transactions. In addition, we may disclose your personal data to governmental, regulatory, supervisory, or law enforcement authorities, whether in Malaysia or overseas, where required by applicable laws or for purposes of investigations, compliance, or safeguarding our rights and property.

  5. In general, it is mandatory for you to provide us with your personal data, as such personal data is necessary for us to carry out the purposes described above. Failure to provide the required personal data may result in us being unable to enter into or continue a contractual relationship, perform our contractual obligations or otherwise perform our obligations in relation to our products or services requested by you including the inability to provide the relevant products or services, process your applications, respond to your queries or feedback, facilitate your participation in our programmes, events or workshops, assess your suitability for employment or other engagements, or comply with our legal and regulatory obligations. In certain cases, the failure to supply personal data may also result in delays, the rejection of applications, or our inability to continue our relationship with you.

  6. For purposes of paragraph 17 of this Policy, the period of thirty (30) days referred to therein shall be reduced to twenty-one (21) days.

  7. For purposes of paragraph 21 of this Policy, the phone number of the DPO is +65 6761 8555.

  8. The main body of this Policy and the Jurisdiction-Specific Supplemental Terms for Malaysia are available in both the English language and Bahasa Malaysia. In the event of any conflict or inconsistency between the English texts and the Bahasa Malaysia texts, the English texts shall prevail to the extent of such conflict or inconsistency.

THE PHILIPPINES

Application

  1. This Jurisdiction-Specific Supplemental Terms is adopted in compliance with Republic Act No. 10173 or the Data Privacy Act of 2012 (“DPA”), its Implementing Rules and Regulations (“IRR”), and other relevant policies, including issuances of the National Privacy Commission (“NPC”). All personal data that may be collected from you are processed in adherence to the general principles of transparency, legitimate purpose, and proportionality.
  2. This Jurisdiction-Specific Supplemental Terms applies in addition to the Policy when Sunstar Singapore Pte. Ltd. processes personal data in the capacity of a personal information controller, and:
    • The data subject is found or established in the Philippines;
    • The act, practice, or processing relates to personal data about a Philippine citizen or Philippine resident;
    • The processing of personal data is being done in the Philippines; or
    • The act, practice, or processing of personal data is done or engaged in by Sunstar Singapore Pte. Ltd., with due consideration to international law and comity.
  3. “Business contact information” as defined in the Policy is regarded as personal data even if not provided by the individual solely for his/her personal purposes.

Definition of Terms

  1. “Privileged information” refers to any and all forms of data which under the Rules of Court of the Philippines and other pertinent laws constitute privileged communication;
  2. “Sensitive personal information” refers to personal data or information:
    • About an individual’s race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;
    • About an individual’s health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such person, the disposal of such proceedings, or the sentence of any court in such proceedings;
    • Issued by government agencies peculiar to an individual which includes, but is not limited to, social security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns; and
    • Specifically established by an executive order or an act of the Congress of the Philippines to be kept classified.

Processing Sensitive Personal Information or Privileged Information

  1. We may only process sensitive personal information or privileged information if:
    • you have given your consent, specific to the purpose stated prior to processing;
    • the processing of the same is provided for by existing laws and regulations;
    • the processing is necessary to protect your life and health or that of another person, and you are not legally or physically able to express your consent prior to the processing;
    • the processing is necessary for the purpose of medical treatment; or
    • the processing concerns sensitive personal information necessary for the protection of lawful rights and interests of natural or legal persons in court proceedings, or the establishment, exercise, or defense of legal claims, or when provided to government or public authority pursuant to a constitutional or statutory mandate.

Retention of Personal Data

  1. Personal data that may be collected will be held in accordance with our Retention Policy and only for as long as it is necessary to fulfil the purpose for which it was collected, or as required or permitted by applicable laws. We will inform you of any changes in our Retention Policy as they arise.

Breaches and Security Incidents

  1. We will notify the NPC, through the Data Breach Notification Management System (“DBNMS”), and affected data subjects within seventy-two (72) hours upon knowledge or reasonable belief that a data breach requiring notification has occurred. Notification of personal data breach is required when:
    • sensitive personal information or any other information that may, under the circumstances, be used to enable identity fraud are reasonably believed to have been acquired by an unauthorized person; and
    • we or the NPC believe that such unauthorized acquisition is likely to give rise to a real risk of serious harm to any affected data subject.
  2. We will document all security incidents and personal data breaches through written reports, including those not covered by the notification requirements and submit the Annual Security Incident Report via the DBNMS.

Data Subject Rights

  1. In addition to the data subject rights enumerated in the Policy, you have the rights to:
    • be indemnified for any damages sustained due to such inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of personal data;
    • lodge a complaint before the National Privacy Commission if you are affected by: a violation of the DPA, its IRR and other issuances of the NPC; a violation of your rights as a data subject; or injury suffered as a result of the processing of your personal data.
  2. If you have any questions or feedback regarding the Policy and this jurisdiction-specific terms for the Philippines, you may call or write to:

The Data Protection Officer

Sunstar Singapore Pte Ltd

3 Fusionopolis Link #02-07

Nexus @ One-North

Singapore 138543

TEL: +65 6761 8555

THAILAND

  1. If you are residing in Thailand, the following additional terms will apply to you. In the event of any inconsistencies or conflicts between the Policy and this Thailand supplemental terms, these Thailand supplemental terms will take precedence. The following Thailand-specific supplemental terms apply only where Sunstar Singapore Pte. Ltd. directly determines the purposes and means of processing of your personal data.
  2. Where you do not provide personal data which are required for our legal compliance, we may not be able to comply with our legal obligations, and this may be deemed as us and/or you failing to comply with, or having carried out an act violating, the applicable laws, in which case we may refuse to provide you with the products or services to prevent the violation of said applicable laws. Furthermore, if you do not provide your personal data which are required for or in accordance with the terms of the contracts we have with you, or to proceed with your request prior to entering into said contracts, we may be unable to perform our obligations under the contract we have or are attempting to enter into with you (such as our inability to provide you with our products or services, or to grant you access to our application).
  3. Personal data will be held only for as long as it is necessary to fulfil the purpose for which it was collected, or as required or permitted by applicable laws. We will cease to retain personal data or remove the means by which the personal data can be associated with particular individuals, as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected, and is no longer necessary for legal or business purposes. In general, we will retain your personal data throughout the period which you are our active registered users and for ten (10) years after the cessation of our contractual relationship, or our last contact/communication, unless otherwise required or permitted by applicable law.
  4. Subject to the conditions under the Personal Data Protection Act B.E. 2562 (2019) of Thailand, you also have the additional rights as follows:
    • Right that we disclose how we obtain your personal data without your consent.
    • Right to request that you receive your personal data in a format which is generally usable or readable by automatic tools or equipment, and which can be used or disclosed via automatic means or we transfer your personal data in such format to another data controller or to directly obtain your personal data in such format that we transfer to other data controllers.
    • Right to lodge a complaint in relation to our processing of your personal data with the Office of the Personal Data Protection Committee of Thailand.
  5. If you have any questions relating to our processing of your personal data, you may contact our Data Protection Officer per contact details in paragraph 21 or contact us at:

The Data Protection Officer

Sunstar Singapore Pte Ltd

3 Fusionopolis Link #02-07

Nexus @ One-North

Singapore 138543

VIETNAM

  1. Data Controller. For Vietnam, Sunstar Singapore Pte. Ltd. (“Sunstar Singapore”) acts as the Controller of your personal data for the purposes described in this Policy, to the extent that Sunstar Singapore determines the purposes and means of processing.

  2. Personal data collected by us. Personal data collected by us for the purposes outlined in this Policy, which may include your business contact information, may consist of both your basic personal data and your sensitive personal data.

  3. Legal basis for data collection and processing. We will only collect, use, or disclose your personal data where we have your consent, or where otherwise permitted or required by applicable law.

  4. Disclosure and transfer of your personal data. We may disclose or transfer your personal data to our affiliated entities, and to third-party service providers and agents who support our operations by providing services such as professional, legal, insurance, audit, and advisory services. We may also share your personal data with our business partners, distributors, online platform operators, organisers, external trainers, accreditation bodies, and employment screening providers where relevant to the operation, administration, improvement, and facilitation of our business activities, events, programmes, and services. In addition, we may disclose your personal data to financial institutions and payment networks for the purposes of processing payments and managing related transactions. We may further disclose your personal data to governmental, regulatory, supervisory, or law enforcement authorities, whether in Vietnam or overseas, where required under applicable laws or for purposes such as complying with regulatory obligations, responding to investigations, or safeguarding our rights, interests, and property.

  5. Your rights and obligations. In addition to your rights stated under paragraphs 16 through 18 of this Policy, unless otherwise provided by Vietnamese law from time to time, you also have the following rights: (a) right to consent; (b) right to request data provision; (c) right to complain, denounce and initiate lawsuits; (d) right to claim compensation of damages; and (e) right to self-defence.
    As a data subject, you also have the following obligations:

    • to protect your own personal data;
    • to respect and protect others’ personal data;
    • to fully and accurately provide your personal data as required by law, by contract, or when you consent to the processing; and
    • to comply with regulations under the law on protection of personal data and prevent violations of regulations on protection of personal data.
  6. Response to Your Request. Notwithstanding paragraphs 16 through 20 of this Policy, for Vietnam, we will respond to your request to exercise your data subject rights within 2 business days. We will then process and complete your request within the statutory time limits prescribed under Vietnamese personal data protection laws, including any permitted extensions where applicable.

  7. Complaints handling process. All complaints regarding our handling of personal data or alleged breaches of our obligations under applicable law may be referred to the DPO, we will endeavour to acknowledge receipt of and/or respond to the complaint within seventy-two (72) hours, unless the law specified otherwise. Further contact will be dependent upon the nature of the complaint.

  8. Changes to this Policy. We reserve the right to modify or update this Policy, including its Jurisdiction-Specific Supplemental Terms, at any time to ensure it is consistent with our future developments, industry trends and/or any changes in legal or regulatory requirements. If we make material changes to this Policy, we will notify you and post any changes on this page. Please review this page periodically for updated information on our policies and practices regarding the handling of your personal data. When required by Vietnamese laws, we will obtain your new consent for changes to this Policy.