CUSTOMER INFORMATION SECURITY POLICY

I. Purpose and Scope of Information Collection:

  1. Unitourist may utilize all or part of the information collected to conduct business operations effectively, within the limits required by business activities:
    • To inform and provide services;
    • To develop services;
    • To respond to information requests;
    • To fulfill a contract signed between Unitourist and the customer;
    • To provide after-sales service for products, as well as to send information about new events and services.
  2. In relation to its core business activities, Unitourist will only collect and use information for specific purposes in compliance with legal regulations. When requesting customers to provide information, the company will clearly state the intended purpose to obtain the customer’s consent.
  3. Unitourist will not disclose information to third parties without the customer’s consent, except in the following special circumstances:
    • In cases where disclosure is required by law or competent authorities;
    • In situations where information is necessary to protect the life, health, or property of the customer and obtaining consent is difficult;
    • In cases of business restructuring, corporate reorganization, joint ventures, or other reasons.

II. Scope of Information Use:

  1. Personal Information: This includes all information related to an individual, such as full name, date of birth, identification card number, passport details, and other identifying descriptors, including symbols, codes, or images that identify the individual. This also encompasses information that, while not personally identifiable on its own, can easily be associated with other information to identify an individual. Additionally, it covers all data that represents a fact, acknowledges, and evaluates the characteristics of the individual, including physical appearance, assets, profession, or personal circumstances.
  2. Payment Information: This consists of all details related to bank accounts; cash transaction amounts, bank account transactions, or transactions conducted in other forms; and content related to transfers.
  3. Methods of Information Provision:
    • Information is provided directly to Unitourist by completing forms on the website www.unitourist.vn.
    • Information is provided directly to Unitourist through methods other than those mentioned above.

III. Information Retention Period:

  1. Like most other websites, when customers access the company’s site, the server generates files containing information about the visitor’s IP address, access time, and pages visited. Unitourist periodically reviews this information and uses it to generate statistics about website access. These files are also deleted quarterly.
  2. For the customer information obtained by Unitourist during transactions, the retention period lasts until a request for deletion is made by the customer.

IV. Individuals or Organizations That May Access Personal Information:

Unitourist Travel Company Limited will not disclose information to third parties without the customer’s consent, except in the following special circumstances:

  • When disclosure is mandated by law or competent authorities;
  • When information is necessary to protect the life, health, or property of the customer, and obtaining consent is difficult;
  • In cases of business transformation, corporate reorganization, joint ventures, or other reasons.

V. Address of the Organization Collecting and Managing Personal Information:

Unitourist Travel Company Limited

Address: 8A/11D1 Thai Van Lung, Ben Nghe Ward, District 1, Ho Chi Minh City

Phone: 1900 2112

Email: info@unitourist.com

Working Hours: Monday to Friday – From 8:30 AM to 6:00 PM (excluding holidays).

VI. Means and Tools for Users to Access and Modify Their Personal Data:

  1. Customers may request to adjust, supplement, or delete their information. If such a request is made, the company will require you to provide identification documents. When Unitourist determines that adjustment, supplementation, or deletion of the information is necessary, it will modify, supplement, or delete your information that the company holds, within reasonable limits and timeframes.
  2. Customers may request to cease the use of or cancel their personal information. If such a request is made, Unitourist will stop using or cancel the personal information that the company retains, within reasonable limits and timeframes.

VII. Commitment to Protecting Customer Personal Information:

Unitourist is committed to safeguarding information to prevent unauthorized disclosure or alteration and will promptly implement all necessary measures in case of emergencies.

  1. Security: Transactional payment information is processed on the payment gateway [please insert payment gateway provider information] (e.g., Cybersource – Sacombank epay), which is certified to meet PCI DSS (Payment Card Industry Data Security Standard) requirements set by international card organizations. When card information is entered on the [please insert payment gateway provider information] payment page, the transaction is encrypted during transmission to prevent theft and copying of card details.
  2. Use of Cookies: Cookies may be used to ensure security and provide relevant information to users. A cookie is a piece of data sent from the website’s hosting server to the user’s browser and may be stored on the customer’s hard drive or other storage devices. Cookies do not contain any information that can help Unitourist identify individual users.

Customers can choose to accept or block cookies from being set in their browser. However, if customers do not accept cookies, they may be unable to use the services offered on the Company’s website.

  1. Information Storage Regarding Browsing Sessions: If customers visit the website operated by the Company, information about their session will be stored on the website’s hosting server. This information will not be used for any purpose other than to collect statistical data regarding customer visits.
  2. Additional Measures:
    • Establish a payment system that ensures online connectivity 24 hours a day, 7 days a week. Downtime for maintenance will not exceed 12 hours per maintenance session, and customers will be notified in advance.
    • Implement applications capable of detecting, alerting, and preventing unauthorized access and attacks on the online payment system.
    • Maintain access control measures for the system and regulated access to the physical locations of the online payment system equipment.
    • Store transaction data in compliance with the requirements outlined in the Accounting Law.

VIII. Mechanism for Receiving and Addressing Complaints Regarding Customer Personal Information:

  1. Unitourist will take necessary measures to manage and protect the integrity of personal information to prevent leakage, loss, or distortion.
  2. Customers may request confirmation regarding whether Unitourist holds or processes personal data related to them and seek clarification on the use of such information retained by the Company. If such a request is made, Unitourist will require identification documents. When the Company determines that disclosure is necessary, it will provide the information held by the Company within reasonable limits and timeframes.
  3. If customers wish to complain about how Unitourist handles personal information, please direct your complaint to the address provided or via email to the Company.