Privacy Policy

CHAPTER I: GENERAL PROVISIONSARTICLE 1. PURPOSE OF THE DOCUMENT

This Privacy Policy is issued for the following purposes:

  • Establish a data and information governance framework that is consistent and strictly adheres to Vietnamese law.
  • Establishing commitments and mandatory control regulations to protect the integrity, security, and availability of all Customer data; comprehensively preventing risks of unauthorized access, leakage, loss, or misuse of personal information; ensuring Customer privacy and the legal compliance of Alliance members.
  • Clearly define the authority and limits on information access among Alliance Members; create a secure and confidential coordination mechanism while optimizing operational speed and service quality for Customers.
  • Protect the integrity of the Alliance's legally owned technological solutions, coordination algorithms, internal trade policies, and standard operating procedures from any illegal exploitation or transfer.

ARTICLE 2. SCOPE AND SUBJECTS OF APPLICATION

This Policy outlines all principles, technical measures, risk control regulations, and legal commitments related to the collection, storage, processing, transmission, and protection of data within the Vietnam Medical Tourism Alliance ecosystem.

This Policy defines the rights, obligations, and legal liabilities of the following parties:

  • Members of the Alliance
  • The customers using the service are participants in the Alliance's medical tourism supply chain.

ARTICLE 3. DEFINITION OF TERMS

  1. Alliance: The Vietnam Medical Tourism Alliance was officially established on April 7, 2026.
  2. Members: These are the organizations that have signed the Declaration establishing the Alliance and those that have signed the Agreement to join the Alliance.
  3. Customers: Individuals who access the Alliance's platforms and/or use services within the Alliance's ecosystem.
  4. Personal Data: refers to digital data or information in other forms that identifies or helps to identify a specific individual, including basic personal data and sensitive personal data. Personal data after deidentification is no longer considered personal data.
  5. Personal Data Processing: refers to activities that affect personal data, including one or more of the following: collection, analysis, aggregation, encryption, decryption, modification, deletion, destruction, deidentification, provision, disclosure, transfer of personal data, and other activities that affect personal data.
  6. Policy: This refers to the entire content of the Information Security Policy drafted and issued by the Alliance, applicable to the Alliance, its Members, and other individuals/organizations with legal relationships with the Alliance.

 

CHAPTER II: INFORMATION PRIVACY POLICYFOR ALLIANCE MEMBERSARTICLE 4. CLASSIFICATION OF CONFIDENTIAL INFORMATION

All Members participating in the Alliance's ecosystem have a legally binding obligation to maintain the confidentiality, integrity, and strict control over access to the following two groups of information:

  1. This information group is owned by the Alliance.

Members undertake to maintain absolute confidentiality, not to copy, transfer, or disclose to any third party without the written consent of the Alliance any confidential and proprietary information concerning the operations or business of the information provider that is confidential to the information provider and not part of the common knowledge of the information recipient; including but not limited to:

  1. Confidential technology and platform solutions: Source code, system architecture, database structure, and shared technical documentation belonging to the Alliance; application programming interfaces, inter-hospital data connection protocols, and end-to-end encryption methods implemented in the network; intelligent algorithms and control logic used to automatically coordinate and allocate customer flows based on the capacity and location of healthcare facilities.
  2. Information on strategy, operations, and branding: Business plan, marketing strategy, international market research data, reports analyzing the behavior and trends of medical tourism customers; a system of related documents; personnel information, lists, contact information, and work history of partners, suppliers, collaborators, and exclusive agents under the Alliance's patronage system.
  3. Internal financial mechanisms and trade policies: Special preferential cross-pricing structure applied exclusively between Members within the ecosystem; product package pricing formula and surcharge calculation mechanism; trade discount rates, sales bonus regulations, and internal commission sharing and allocation mechanisms.

Confidential information does not include the following:

  1. Information is currently being made public or will be made public on the Alliance's platforms;
  2. Information that a party legally obtains from a third party is not subject to disclosure restrictions and does not violate confidentiality obligations.
  1. Customer's personal data information group

Members are responsible for establishing maximum technical controls to protect Customers' personal data in accordance with the provisions of Chapter III of this Policy; any unauthorized exploitation, appropriation, sale, or use of Personal Data is strictly prohibited.

ARTICLE 5. PRINCIPLE OF MINIMUM ACCESS RIGHTS

  1. For Healthcare Facilities: These organizations are primarily responsible for medical expertise, acting as the controller and processor of Client's medical data, and have full access to Client's Personal Data records for medical examination and treatment purposes. They are required to protect the confidentiality of medical information as stipulated in Article 69 of the Law on Medical Examination and Treatment 2023.
  2. For Members that are organizations providing other supplementary services such as travel, accommodation, transportation, etc.: These organizations are absolutely not allowed to access the detailed medical records and treatment plans of Customers. They are only allowed to access basic Personal Data and specific notes for each group of medical services extracted by Healthcare Facilities (for example: transportation vehicles need to have beds, hotel rooms do not have stairs, specific nutritional regimens for patients after surgery).

ARTICLE 6. TECHNICAL STANDARDS

To minimize the risk of data leakage, Members are responsible for building and maintaining internal technology infrastructure that meets the following standards:

  1. All information and records provided by the Customer, and information exchanged between the Member's private system and the Alliance's common technology portal, must be automatically encrypted at the point of sending and only "unlocked" at the point of receiving (referred to as end-to-end encryption).
  2. Under no circumstances should anyone else be allowed to use the username and password to access the system. Each doctor, coordinator, or instructor assigned to process data must be assigned a separate account linked to their personnel code and full name.
  3. The Member's infrastructure and technology system must be configured to automatically record all personnel actions on the system into an uneditable electronic logbook.

ARTICLE 7. ADMINISTRATIVE SANCTIONS

  1. It is strictly prohibited to buy, sell, rent, or transfer Customers' Personal Data to third parties, or to use shared data to entice customers to conduct independent commercial transactions outside the Alliance's coordinated system.
  2. Depending on the severity, any violations will be subject to strict penalties including: financial fines, temporary disconnection from the technology system, permanent expulsion from membership, and criminal/civil prosecution under Vietnamese law if serious consequences result.

CHAPTER III: INFORMATION PRIVACY POLICYFOR CUSTOMERSARTICLE 8. SCOPE OF PROCESSING OF CUSTOMER'S PERSONAL DATA

In order for the Alliance to process Personal Data for the purposes stated in Article 9 of this Policy, the Alliance may process the following types of Personal Data:

  1. Basic Personal Data:
  • Surname, middle name and given name, other names (if any);
  • Date of birth; date of death or disappearance;
  • Sex;
  • Place of birth, place of birth registration, permanent residence, temporary residence, current residence, hometown, contact address;
  • Nationality;
  • Images of individuals; information obtained from security systems, including video recordings of Customers on surveillance cameras at the Alliance's business/transaction locations;
  • Phone number , personal identification number, passport number, driver's license number, vehicle license plate number;
  • Marital status;
  • Information about family relationships (parents, children, spouses);
  • Information about an individual's digital account;
  • Other information associated with or that helps identify a specific person does not fall within the scope of sensitive Personal Data as defined in paragraph 2 of Article 8 below.
  1. Sensitive Personal Data :
  • Political views, religious views, beliefs;
  • Health status and personal information are recorded in medical records;
  • Information about private life, personal secrets, and family secrets;
  • Information relating to racial origin and ethnic origin;
  • Information about inherited or acquired genetic traits of an individual;
  • Information about the physical attributes and unique biological characteristics of an individual;
  • Data on crimes and criminal acts are collected and stored by law enforcement agencies;
  • Information including username and password for accessing the individual's electronic identity account; images of identity cards, citizen identification cards, and national identity cards;
  • Username and password for bank account access; bank card information, transaction history data of bank account; financial and credit information, and information on the activities and transaction history of customers' financial, securities, and insurance transactions at credit institutions, branches of foreign banks, payment intermediary service providers, securities and insurance companies, and other authorized organizations;
  • Data tracking behavior and activity related to the use of telecommunications services, social networks, online communication services, and other services in cyberspace;
  • Customer location data is determined through location services;
  • Other personal data that is legally defined as specific and requires necessary security measures.

ARTICLE 9. PURPOSE OF PROCESSING PERSONAL DATA

Personal data may be processed for one or more of the following purposes:

  1. Assessing the ability to provide products, services, or/and enter into contracts with the Customer, including but not limited to the following purposes:
  • Identify and verify customer information;
  • Evaluate, assess, and approve the provision of products and services in accordance with the registration documents, applications, and contracts of the Customer and/or related parties of that Customer;
  • Consider providing or continuing to provide any Alliance products or services to Customers;
  1. Fulfilling obligations under contracts, agreements, terms, conditions, and other documents between the Alliance and the Client, and supporting the Client including but not limited to the following purposes:
  • Fulfill contractual obligations and agreements, and provide products and services to Customers;
  • Updating and processing customer information;
  • Providing customer care and resolving customer complaints and grievances;
  • Using and transferring Personal Data and related information to partners to identify and resolve product and service issues; and to repair products;
  • Contact and inform the Customer;
  • Implement promotional programs, gift exchanges, reward programs, and gift delivery;
  • Perform other customer care and support activities.
  1. Improving the quality of the Alliance's products and services includes, but is not limited to:
  • Provide information that the Client has requested or that the Alliance deems useful to the Client;
  • Improving technology, website interfaces, social media, and applications to ensure convenience for customers;
  • Manage customer accounts and loyalty programs implemented by the Alliance and its Members;
  • Data collection and analysis for research, development, and improvement of products and services; enhancing customer experience;
  • Develop and deliver new, personalized products and services tailored to the specific needs and circumstances of our customers.
  • Suggest products and services that customers might be interested in by identifying their preferences.
  1. Serving the business operations of the Alliance includes, but is not limited to, fulfilling reporting, financial, accounting, and tax obligations, auditing and compliance activities, and other activities serving the Alliance's legitimate business in cases where the Alliance deems it necessary.
  2. Marketing: Develop marketing and promotional campaigns for products and services, including creating campaigns based on customer preferences;
  3. Crime prevention, control, deterrence, investigation, and detection.
  4. To protect social order and security, and to safeguard the legitimate rights and interests of Clients, Alliances, and other stakeholders.
  5. Compliance with the law and international treaties to which Vietnam is a party includes, but is not limited to:
  • To provide information to competent state agencies as prescribed by law;
  • To fulfill the obligations stipulated by law and international treaties that the Union and its Members must comply with (if any).
  1. Other purposes, if agreed upon by the Client.

ARTICLE 10. METHODS OF HANDLING PERSONAL DATA

  1. Methods of collecting Personal Data
  1. From the Alliance's websites and applications and/or Alliance Members: Personal Data is collected when Customers fill out forms provided on the Alliance's websites and applications and/or Alliance Members.
  2. From providing products and services, fulfilling contractual obligations and agreements with the Alliance and/or organizations authorized by the Alliance: Personal Data is collected when Customers purchase, register for, use any products or services, or sign contracts, agreements, or consent forms with the Alliance and/or organizations authorized by the Alliance.
  3. From exchanges and communications with Customers: Personal Data is collected through interactions between Alliance/Members and Customers (in person, via mail, telephone, online, call center system, electronic communication, ChatBot, or any other means), including surveys.
  4. Social media refers to the League's social media networks and/or social media networks developed by the League in collaboration with partners.
  5. From audio and video recording devices: located at the Member's premises, or where part or all of the Alliance's service activities are performed, where the Customer encounters, appears, or interacts with the Alliance/Member.
  6. From interactions or automated data collection technologies : The League may collect automatically recorded information from connections:
  • Cookies and other similar technologies;
  • Any technology capable of tracking personal activity on electronic devices or websites;
  • Other data information is provided by a device.
  1. Other means: The Alliance may collect Personal Data through public, official sources of information or through receiving necessary data sharing from Members and partners in the course of cooperation with the Alliance in accordance with the law.
  1. Data transfer/sharing principles
  1. The Alliance will not sell Personal Data to any party. The Alliance uses necessary security measures to ensure the secure transfer/sharing of Personal Data. Personal Data is shared by the Alliance with (i) Members and affiliated organizations of the Alliance; (ii) individuals/organizations involved in the Personal Data Processing process as stipulated in the Policy; or (iii) competent government agencies or other cases in accordance with the law.
  2. If the recipient of Personal Data is located outside Vietnam, when providing/transferring Personal Data abroad (including but not limited to the use of cyberspace, electronic devices, or other forms to transfer Personal Data outside Vietnam), the Alliance will require the recipient to ensure the safety and security of the Personal Data provided/transferred. The Alliance commits to fully comply with all regulations and requirements of Vietnamese law to protect the safety of Personal Data.
  1. Exceptions to the processing of personal data may not require the subject's consent.
  1. The law stipulates that data deletion is not permitted, nor does it require mandatory data retention.
  2. Personal data is processed by competent state agencies for the purpose of serving the activities of state agencies in accordance with the law;
  3. Personal data has been made public in accordance with legal regulations;
  4. Personal data is processed to serve legal requirements, scientific research, and statistical purposes in accordance with legal regulations;
  5. In cases of national defense and security emergencies, social order and safety emergencies, major disasters, dangerous epidemics; when there is a threat to national security and defense but not to the extent of declaring a state of emergency; in the prevention and control of riots, terrorism, crime, and violations of the law;
  6. Responding to emergencies that threaten the life, health, or safety of Customers or other individuals.

ARTICLE 11. HANDLING OF CHILDREN'S PERSONAL DATA

  1. The Alliance will process children's personal data in accordance with the principles of protecting the rights and best interests of children and in compliance with the law.
  2. The Alliance only processes children's personal data and provides products and services to children if the parents or guardians consent to the child using the Alliance's products and services, agree to the Alliance processing the child's personal data, agree to the Policy, and comply with relevant legal requirements. In the case of children aged 7 and above using the Alliance's products and services, in addition to the requirements stated herein, the Alliance will only process the child's personal data with the child's consent. Parents or guardians are responsible for obtaining the child's consent before providing the child's personal data to the Alliance.

ARTICLE 12. POTENTIAL UNINTENDED CONSEQUENCES AND DAMAGES

  1. The Alliance employs various information security technologies to protect and prevent unauthorized access, use, or sharing of Personal Data. However, the Alliance cannot guarantee absolute security of Personal Data in certain cases, such as:
  1. Hardware or software errors during data processing can lead to the loss of customer data.
  2. The security vulnerability was beyond the League's control; the system was attacked by hackers, resulting in data leaks and breaches.
  1. The Alliance advises customers to keep their account login passwords and OTP codes secure and not share this information with anyone else.
  2. Customers should be aware that at any time they disclose and make their Personal Data public, that data may be collected and used by others for purposes beyond the control of the Customer and the Alliance.
  3. The Alliance advises customers to take care of their personal devices (phones, tablets, personal computers, etc.) while using the service. Customers should log out of their accounts when not in use.
  4. In the event that the data storage server is attacked resulting in the loss, leakage, or unauthorized access of Personal Data, the Alliance will be responsible for notifying the relevant authorities for timely investigation and handling, and informing Customers in accordance with the law.
  5. The online environment is not secure, and the Alliance cannot guarantee that Personal Data shared online will always be secure. When transmitting Personal Data online, Customers should only use secure systems to access websites, applications, or devices. Customers are responsible for keeping their login credentials for each website, application, or device secure and confidential.

ARTICLE 13. START AND END TIMES FOR PROCESSING PERSONAL DATA

  1. Personal Data is processed from the moment the Alliance lawfully receives the Personal Data and the Alliance has a proper legal basis to process the data in accordance with the law.
  2. Personal data will be processed until the purposes for which it was processed have been fulfilled.
  3. The Alliance may be required to retain Personal Data even after the contract between the parties has terminated in order to fulfill obligations under the law and/or requirements of competent government authorities.

ARTICLE 14. ORGANIZATIONS AND INDIVIDUALS PARTICIPATING IN THE PROCESSING OF CUSTOMERS' PERSONAL DATA

  1. Depending on the circumstances, the Alliance may be the party controlling Personal Data or the party controlling and processing Personal Data.
  2. To the extent permitted by law, the Customer understands that the Alliance may share Personal Data for the purposes outlined in this Policy with the following organizations and individuals:
  1. Members of the Alliance include full members and associate members;
  2. Organizations and individuals providing services and/or collaborating with the Alliance, including but not limited to: agents, auditors, lawyers, business partners, providers of information technology solutions, software, applications, operational services, management, troubleshooting, and infrastructure development;
  3. Any individual or organization acting as a representative or authorized agent of the Client, or acting on behalf of the Client;

Data sharing will be carried out in accordance with the proper procedures, methods, and applicable legal regulations. Parties receiving Personal Data are obligated to maintain the confidentiality of Personal Data in accordance with the Alliance's Policies, internal regulations, Personal Data Protection standards, and applicable legal regulations.

  1. The Alliance may be required to share Personal Data with competent government agencies in accordance with the law.

ARTICLE 15. CUSTOMER RIGHTS

  1. The right to know about the processing of one's personal data, except where otherwise provided for by law.
  2. You have the right to consent or not consent to the processing of your personal data, except where otherwise provided by law.
  3. The right to access, view, edit, or request editing of one's Personal Data, except as otherwise provided by law.
  4. Right to withdraw consent.
  5. Data deletion permission.
  6. The right to restrict the processing of personal data in accordance with the law.
  7. The right to request access to one's own Personal Data, except as otherwise provided by law.
  8. The right to object to data processing.
  9. The right to file complaints, denunciations, and lawsuits.
  10. The right to claim compensation for damages.
  11. The right to self-defense.

Customers can exercise these rights by submitting a request to the Alliance. The request must be sent to the Alliance and include essential information such as the requester's details, the specific request (e.g., the type of data to be provided or deleted, the name of the document or file (if applicable)), the reason and purpose for the request, and relevant information depending on the nature of the request (e.g., whether the requested document is in file or paper format, the delivery address, etc.). Any costs (if any) arising from fulfilling the requests as stated herein, including but not limited to printing, photocopying, postage, and courier fees for sending the data, will be borne by the requester and must be paid no later than upon receipt of the data or within a deadline set by the Alliance.

The Alliance will process Customer requests in accordance with the law and considering the legitimate interests of the Customer. However, if the Customer withdraws their consent, requests data deletion and/or other related rights regarding any or all Personal Data that affect the Customer's ability to provide/maintain products and services to the Customer or maintain the contractual relationship, depending on the nature of the Customer's request, the Alliance may consider and decide whether to discontinue providing the Alliance's products and services to the Customer or terminate the contractual relationship between the Alliance and the Customer. Any actions taken by the Client under these terms will be deemed a unilateral termination by the Client of any relationship between the Client and the Alliance and may result in a breach of contractual obligations or commitments between the Client and the Alliance. The Alliance reserves the right to its legal remedies in such cases. Accordingly, the Alliance will not be liable to the Client for any resulting losses, and the Alliance's legal rights will be fully reserved. Through reasonable effort, the Alliance will fulfill legitimate and valid requests from the Client within a timeframe consistent with legal requirements. However, for security purposes, the Alliance may require the Client to verify their identity before processing the Client's request.

The Alliance reserves the right to refuse to fulfill Customer requests in certain circumstances, including but not limited to: (i) the Customer failing to follow the procedures instructed by the Alliance, where the request lacks information or is invalid; (ii) the Customer failing to provide or providing incomplete documents to verify identity; or (iii) the Alliance assessing signs of fraud or violations of Personal Data protection; or (iv) the law prohibits the fulfillment of the Customer's request.

ARTICLE 16. OBLIGATIONS OF PERSONAL DATA SUBJECTS

  1. Protect your Personal Data yourself; request other relevant organizations and individuals to protect your Personal Data. Promptly notify the Alliance when you discover any errors, mistakes, leaks of Personal Data, or suspect that your Personal Data is being compromised.
  2. Respect and protect the personal data of others.
  3. Provide complete and accurate Personal Data when agreeing to allow Personal Data Processing. If any information is inaccurate, the Customer will bear the cost themselves if such information affects or restricts their rights.
  4. Implement legal regulations on personal data protection and participate in preventing and combating violations of personal data protection regulations.
  5. Other responsibilities as prescribed by law.

CHAPTER IV: IMPLEMENTATION PROVISIONS

ARTICLE 17. AMENDMENTS AND SUPPLEMENTS

The Alliance may modify or update this Policy from time to time, in accordance with applicable laws and the Alliance's operations. The latest version, along with any notice of modification, update, or adjustment to this Policy, will be publicly updated and posted on the Alliance's platform and/or other applications/platforms deployed by the Alliance from time to time.

ARTICLE 18. RESPONSIBILITIES AND COMMITMENTS
All Members are obligated to comply with the provisions of this Policy.