Legal
Retained Personal Data
- Effective date
- Last reviewed
“Retained personal data” means personal data that HCT SYSTEMS JSC has the authority to disclose, correct, add to, delete, suspend the use of, or suspend the provision of to third parties. This page sets out the matters we are required to make publicly available, and the procedure for making a request.
1. Matters to be publicly announced
| Item | Detail |
|---|---|
| Business operator | HCT SYSTEMS JSC |
| Address | 237A/08 Dũng Sĩ Thanh Khê, Phường Thanh Khê, Thành phố Đà Nẵng, Viet Nam |
| Representative | Representative Director |
| Purposes of use of all retained personal data | As set out in Personal Information Handling, section 2 |
| Contact for complaints and requests | Privacy Officer — privacy@hct-systems.com |
| Authorised personal information protection organisation | None at present |
2. Categories of retained personal data
| Category | Data items | Purpose | Retention period |
|---|---|---|---|
| Enquiry records | Name, email address, company name, enquiry category, message content, date of submission | Responding to and keeping a record of enquiries | 24 months from last contact |
| Client contact records | Name, email address, telephone number, role, company name | Performing the services agreement and supporting the client | Duration of the engagement, plus the period stated in the contract |
| Supplier contact records | Name, email address, company name, payment details | Managing the supply relationship | Duration of the relationship, plus the statutory accounting period |
| Recruitment records | Information contained in an application | Assessing the application | 12 months from the decision, unless you ask us to keep it longer |
| Website access logs | IP address, user agent, requested URL, timestamp, country | Site delivery, security, abuse prevention | Per Cloudflare’s retention schedule — typically days |
Data we process on behalf of a client is not our retained personal data. If you believe a client holds information about you that we process, please direct your request to that client; we will support them in responding.
3. Security control measures for retained personal data
Organisational. A named Privacy Officer is accountable for personal information. Handling rules are documented, access is logged, and incidents are reported through a defined route.
Personnel. Everyone with access is bound by confidentiality obligations that survive the end of their engagement, and receives periodic training on handling personal information.
Physical. Work happens on managed devices with full-disk encryption, screen locking, and remote wipe. Paper records containing personal information are not created.
Technical. Access is granted on a least-privilege basis and reviewed periodically. Multi-factor authentication is required on all systems that hold personal information. Data is encrypted in transit (TLS 1.2 or above) and at rest. Systems are monitored and logged.
External environment. Where personal data is held outside Viet Nam, we confirm the legal framework of the destination and put contractual safeguards in place before transferring. Details are available on request.
4. How to make a request
You may ask us to:
- notify you of the purpose of use of your retained personal data;
- disclose your retained personal data, including records of provision to third parties;
- correct, add to or delete data that is inaccurate;
- suspend use or delete data handled in breach of the law or beyond the stated purpose;
- suspend provision of your data to third parties.
Procedure
- Send a request to privacy@hct-systems.com with the subject line “Personal data request”. Tell us which of the above you are asking for, and give us enough detail to find your records — usually the email address you contacted us from.
- Confirm your identity. We will reply asking you to verify your identity. We ask because disclosing personal data to the wrong person is a more serious failure than a short delay. If an agent is acting for you, we will ask for evidence of their authority.
- We respond. We aim to respond within 14 days and will respond within 30 days. If we need longer we will tell you why before that deadline passes.
Method of response
We respond by email to the verified address, unless you ask for another method and it is reasonable for us to use it.
Fees
We do not charge for a request. If a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee reflecting our administrative costs, or decline it — and we will explain why in writing either way.
If we decline
We may be unable to act on a request in full — for example where doing so would harm someone’s rights, interfere with the conduct of our business to a significant degree, or breach another law. Where we decline, we will tell you the reason and how to challenge the decision.
5. Contact
HCT SYSTEMS JSC — Privacy Officer privacy@hct-systems.com 237A/08 Dũng Sĩ Thanh Khê, Phường Thanh Khê, Thành phố Đà Nẵng, Viet Nam