This Privacy Policy explains how CÔNG TY TNHH TRUYỀN THÔNG MẸ VÀ CON (“MVC”, “we”, “us”) collects, uses, discloses, retains and protects personal data.
1. Scope and our role
This Policy applies to personal data that MVC determines the purposes and means of processing for — including data about visitors to our website, business contacts, job applicants and our own personnel. In that context MVC acts as a controller of personal data.
MVC also processes personal data on behalf of its clients in the course of delivering marketing, communications and technology services. In that context MVC acts as a processor. Section 9 explains how that processing is governed. Where MVC acts as a processor, the client’s own privacy notice — not this one — describes the purposes of processing, and individuals should direct requests to that client.
2. Who we are and how to contact us
- Entity: CÔNG TY TNHH TRUYỀN THÔNG MẸ VÀ CON (MVC)
- Address: 48 Hoa Mai, Cau Kieu Ward, Ho Chi Minh City, Vietnam
- Privacy and information security contact: infosec@mvc.com.vn
- Telephone: (028) 3517 0278
Enquiries, complaints and requests to exercise the rights described in Section 10 should be sent to the address above.
3. Personal data we collect
3.1 Website visitors
- Information you submit through contact and enquiry forms: name, email address, telephone number, job title, company and the content of your message.
- Technical information collected automatically: IP address, browser and device type, pages viewed, referring page and time of visit. This is collected through Google Analytics and Google Tag Manager (see Section 7).
3.2 Business contacts
Name, job title, business email address, business telephone number, employer and communication preferences, together with records of our correspondence with you.
3.3 Job applicants
Information contained in your application, including personal history statement, identity documentation, educational qualifications and professional certificates, employment history and contact details. Where the role involves financial or system administration responsibilities we may additionally request a Judicial Record Certificate (Phiếu Lý lịch tư pháp).
3.4 MVC personnel
Employment records, payroll and benefits data, attendance records, and the facial recognition data described in Section 4.
4. Facial recognition used for attendance
This section applies only to MVC employees. MVC does not collect facial images or facial recognition data from clients, website visitors, or any member of the public.
MVC operates a facial recognition attendance system. When an employee records attendance, the system captures a facial image and compares it against a reference template previously enrolled for that employee, in order to confirm identity and record working time.
- Purpose. Verification of identity for attendance and working time records, and prevention of attendance fraud. Facial data is not used for any other purpose.
- Basis. The collection and use of facial recognition data for attendance is set out in the employment contract entered into between MVC and the employee, and is processed in accordance with applicable Vietnamese labour and personal data protection law.
- Disclosure. Facial recognition data is not sold, shared or disclosed to any third party, and is not used to train or improve any machine learning model.
- Security. Facial data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. It is stored with access restricted to authorised personnel under role-based access control with multi-factor authentication.
- Retention. The facial reference template is retained for the duration of employment and is deleted when employment ends. Resulting attendance records, which do not contain facial images, are retained for the period required by applicable labour, tax and social insurance law.
5. How we use personal data
| Purpose | Categories of data used |
|---|---|
| Responding to enquiries and providing our services | Contact details, correspondence, business contact data |
| Managing client and supplier relationships | Business contact data, correspondence |
| Recruitment and assessment of applicants | Job applicant data |
| Employment administration, payroll and attendance | Personnel records, attendance and facial recognition data |
| Website operation, measurement and improvement | Technical and usage data |
| Information security, fraud prevention and access control | Access and security logs, attendance data |
| Compliance with legal, tax and regulatory obligations | As required by the applicable obligation |
Where the law requires your consent for a particular processing activity, we obtain that consent before processing and you may withdraw it at any time by contacting us. Withdrawal does not affect processing carried out before withdrawal.
6. Marketing communications
Where we send you marketing or informational communications, each message includes a means of unsubscribing. You may also opt out at any time by writing to infosec@mvc.com.vn. Opting out of marketing does not stop communications necessary to perform a contract with you.
7. Service providers and disclosure
We do not sell personal data. We disclose personal data only as set out below.
| Recipient | Role | Data involved |
|---|---|---|
| Amazon Web Services | Cloud infrastructure hosting for MVC systems and client environments | Data held in hosted systems |
| CMC Cloud | Cloud infrastructure hosting | Data held in hosted systems |
| Microsoft (Microsoft 365, including Exchange Online and OneDrive for Business) | Email, file storage and collaboration | Correspondence and documents |
| Google (Google Analytics, Google Tag Manager) | Website measurement | Technical and usage data from our website |
We may also disclose personal data to professional advisers where necessary, and to competent authorities where disclosure is required by law or legal process.
Service providers are engaged under terms requiring them to process personal data only for the purposes we specify, to apply appropriate security measures, and not to use the data for their own purposes.
8. International transfers
Some of the service providers listed in Section 7 operate infrastructure outside Vietnam, which may result in personal data being stored or processed outside Vietnam. Where this occurs we apply the safeguards required by applicable Vietnamese personal data protection law, and we require contractual commitments from the provider covering security and confidentiality of the data.
9. Data we process on behalf of our clients
When MVC delivers services to a client, we may process personal data that the client has collected. In that role:
- We process that personal data only in accordance with the client’s documented instructions, and for no other purpose.
- We do not use client personal data for our own purposes, and we do not sell it.
- We do not engage a sub-processor to process client personal data without the client’s prior authorisation.
- Personnel with access to client personal data are bound by confidentiality obligations that continue after their engagement with MVC ends.
- Each client’s data is held in a dedicated environment separated from that of other clients.
- We assist the client in responding to requests from individuals exercising their rights, and we notify the client without undue delay on becoming aware of a personal data breach affecting their data.
- On termination of the engagement, we return or delete the client’s personal data in accordance with the client’s instructions and the terms of the agreement.
10. Your rights
Subject to applicable law, you may have the right to:
- be informed about how your personal data is processed;
- access the personal data we hold about you;
- have inaccurate or incomplete personal data corrected;
- request deletion of your personal data;
- request restriction of, or object to, certain processing;
- withdraw consent where processing is based on consent;
- receive a copy of certain personal data in a portable format;
- lodge a complaint with the competent authority.
To exercise any of these rights, contact infosec@mvc.com.vn. We may need to verify your identity before acting on a request. We respond within the period required by applicable law. Where MVC processes your data on behalf of a client, we will refer your request to that client and assist them in responding.
11. Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, or for as long as required by law.
| Category | Retention |
|---|---|
| Website enquiry and contact form data | Up to 180 days, unless an ongoing business relationship requires longer |
| Business contact records | For the duration of the relationship and a reasonable period thereafter |
| Unsuccessful job applications | Up to 12 months, unless the applicant asks us to delete them sooner |
| Employment records | For the duration of employment and thereafter as required by labour, tax and social insurance law |
| Facial recognition reference template | Deleted when employment ends |
| Security and access logs | Minimum of 3 years |
| Personal data processed for a client | As instructed by the client and as set out in the client agreement |
When personal data is no longer required, it is securely deleted or destroyed.
12. How we protect personal data
MVC maintains a documented information security policy framework, reviewed at least annually, which applies to all personnel, contractors and third parties handling MVC or client data. Measures include:
- encryption of data at rest using AES-256, and of data in transit using TLS 1.2 or 1.3;
- additional application-level encryption of sensitive database fields containing personal data;
- role-based access control on the principle of least privilege, with multi-factor authentication and quarterly access reviews;
- logically isolated environments for each client, with no shared resources between clients;
- endpoint protection, data loss prevention controls and centralised logging and monitoring;
- risk-based patch management and periodic vulnerability assessment and penetration testing;
- documented incident management, business continuity and disaster recovery processes, exercised periodically;
- confidentiality obligations for all personnel that continue after their engagement ends.
No system can be guaranteed to be completely secure. If we become aware of a personal data breach affecting you, we will notify you and the competent authority where required by law.
13. Cookies and similar technologies
Our website uses cookies and similar technologies for the measurement purposes described in Section 7. You can control or delete cookies through your browser settings; disabling cookies may affect the functionality of parts of the site.
14. Children
Our website and services are not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Review and changes to this Policy
This Privacy Policy is reviewed at planned intervals of no more than twelve months. The review is carried out by MVC’s Information Security function, which is the designated owner of this Policy, and is also triggered by any material change to our processing activities, our service providers, or applicable law. The date of the most recent review and the date of the next scheduled review are recorded at the top of this Policy, and each version is retained.
Where a review results in a change, the revised Policy is published on this page and takes effect on the effective date stated. Where a change materially affects how we use your personal data, we will provide additional notice.
