| Document name | Personal Data Protection & Privacy Policy |
|---|---|
| Version | 1.1 |
| Effective date | September 2026 |
| Scope | Account users and End Users interacting via Zalo OA, Web Component and Facebook Fanpage (Messenger and comments) |
| Issuer | Trust Soft, Legal & Policy Department |
| Legal basis | Decree 13/2023/ND-CP on personal data protection and related regulations |
| Related documents | TrustAI Terms of Service v1.0, Appendix, Third-Party Provider List |
This document is effective together with the TrustAI Terms of Service and forms an inseparable part of TrustAI's legal documentation.
Preamble
At Trust Soft, we respect and are committed to protecting the privacy and personal data of all users and partners interacting with the TrustAI system. This policy describes how we collect, use, share, store and protect personal data, and sets out your rights over your data.
This policy is built on Decree No. 13/2023/ND-CP dated 17 April 2023 of the Vietnamese Government on personal data protection and related Vietnamese legislation. It applies to all channels through which you interact with TrustAI: the authenticated web application, Zalo Official Account, the Web Component embedded in Organization websites, and Facebook Fanpage (Messenger and comments).
By using TrustAI or interacting with any TrustAI integration channel, you confirm that you have read and understood this policy. Please read it carefully before using the service.
Article 1. Definitions
In this policy, terms have the meanings given in Decree 13/2023/ND-CP and are supplemented as follows:
- Personal data: information in the form of symbols, text, numbers, images, sound or similar forms in the electronic environment associated with a specific person or that helps identify a specific person, including basic and sensitive personal data.
- Sensitive personal data: personal data tied to an individual's privacy, the violation of which would directly affect the lawful rights and interests of that individual, per Clause 4 Article 2 of Decree 13/2023/ND-CP.
- Data subject: the individual whom personal data describes.
- Data Controller: the organization or individual that determines the purpose and means of processing personal data.
- Data Processor: the organization or individual that processes personal data on behalf of a Controller under a contract or agreement.
- Processing of personal data: one or more operations performed on personal data (collecting, recording, analyzing, confirming, storing, modifying, disclosing, combining, accessing, retrieving, recovering, encrypting, decrypting, copying, sharing, transmitting, providing, transferring, deleting, destroying or other related actions).
- End User: an individual who interacts with TrustAI through integration channels such as Zalo OA, the Web Component or a Facebook Fanpage, without holding a direct account on the system.
Article 2. Allocation of Controller and Processor roles
Processing of personal data through TrustAI is allocated as follows:
| Data category | Controller | Processor |
|---|---|---|
| User account data (email, full name, role), individuals granted access by the Organization | The user's Organization | Trust Soft |
| Trust Soft internal operating data (access logs, billing, technical support) | Trust Soft | Trust Soft |
| Content supplied by the Organization/user (documents, prompts, chat history) | The user's Organization | Trust Soft (and authorized LLM providers) |
| End User data via Zalo OA, Web Component, Facebook Fanpage | The Organization operating the integration channel | Trust Soft (and authorized LLM providers) |
| Data on Trust Soft's official website (marketing traffic) | Trust Soft | Trust Soft |
Note: If you are an End User interacting through Zalo OA, the Web Component or a Facebook Fanpage, requests concerning your personal data should be sent directly to the Organization operating that integration channel. Trust Soft supports the Organization in handling such requests through standard technical procedures.
Article 3. Personal data we collect
3.1. Basic personal data
- Account identifiers: full name, email address, role in the Organization, avatar (if any), interface language, time zone.
- Contact and organizational data: Organization name, job title, department/unit (configured by the Organization).
- Interaction data: chat content with the AI assistant, documents uploaded to the knowledge base, prompts and bot configurations, workflow execution history.
- Technical data: IP address, browser and device type, operating system, screen resolution, cookies and session tokens, session start time and duration.
- Usage data: AI token consumption, AI models used, feature usage frequency, response times.
3.2. Sensitive personal data
The system does not require Organizations or users to provide sensitive personal data to operate. However, owing to the nature of certain workflows (especially for government agencies), users may introduce the following data into the system as reference documents or chat content:
- Data relating to ethnic origin, political views, religious beliefs
- Data on health and sexual life
- Detailed geographic location data of individuals
- Financial records and criminal records
- Other sensitive data under Clause 4 Article 2 of Decree 13/2023/ND-CP.
Warning: The Organization/user must ensure they have a valid legal basis (consent of the data subject or another lawful basis under Article 17 of Decree 13/2023/ND-CP) before introducing sensitive personal data into TrustAI.
3.3. End User data via integration channels
When you interact with an Organization through Zalo OA, the Web Component or a Facebook Fanpage (Messenger, comments) using TrustAI, the following data may be collected:
- Channel identifiers: Zalo user ID (provided by Zalo), Zalo display name, Zalo avatar
- For the Web Component: an anonymous session identifier generated automatically (not tied to a real identity unless the Organization requires login)
- The content of messages you send to the AI assistant
- For a Facebook Fanpage: your Page-scoped user ID (PSID, issued by Meta), your public Facebook display name, the content of messages sent to the Page via Messenger (including attached images), and comments on the Page's posts together with the commenter's ID
- Technical data of the accessing device.
3.4. Data processing on the Facebook Fanpage channel (Messenger and comments)
The Organization connects its own Facebook Page using Facebook Login for Business on app.trustsoft.vn and chooses which Pages are connected; Trust Soft is not added to the Organization's Business Manager. Page access tokens are stored encrypted, data is isolated per Organization, and storage is prioritized on infrastructure located in Vietnam.
End User data on the Facebook channel is processed for the following purposes:
- The AI assistant replies to Messenger messages and comments on the Page's posts on the Organization's behalf.
- Storing conversations so staff of the Organization that owns the Page can review and follow up; the customer's public display name is used only to label conversations, not for advertising and not combined with data from other sources.
- Automatically replying to public comments and following up privately via Messenger.
- Drafting, approving and publishing or scheduling posts to the Page: staff compose the content (optionally using AI to write text and generate illustrative images), and one person from the Organization must approve before a post is published immediately or handed to Facebook to publish at the scheduled time; cancelling a schedule removes the post from the Page. Nothing is published without approval.
Note: End Users' Messenger messages and comments are transmitted automatically to the AI model provider to generate responses (unlike the Word Add-in, where transmission happens only when the user actively acts). Trust Soft does not sell data and does not use this data for advertising.
Article 4. Purposes and legal bases for processing
| Purpose | Primary data category | Legal basis (Decree 13/2023) |
|---|---|---|
| Providing TrustAI: authentication, authorization, responding to user requests | Account data, interaction data | Contract performance (Article 17.b) |
| System security: fraud detection, attack prevention, incident investigation | Technical data, access logs | Protection of legitimate interests (Article 17.đ), legal compliance (Article 17.c) |
| Service quality improvement: usage analytics, error analysis, UX optimization | Usage data (anonymized where possible) | Legitimate interests, consent |
| Contact and technical support: responding to support requests | Account data, content of requests | Contract performance |
| Service billing and accounting | Usage data, payment data | Contract performance, legal compliance |
| Compliance with legal requirements: providing data upon lawful government requests | As required by the specific request | Legal compliance |
| Marketing and communications (account users only, opt-in) | Email, contact data | Consent, may be withdrawn at any time |
Article 5. Sharing data with third parties
5.1. Data processing partners
To deliver the service, Trust Soft uses the following partners (detailed in the Third-Party Provider List Appendix):
- Cloud infrastructure providers: storage and processing on infrastructure secured to international standards. Trust Soft prioritizes infrastructure located in Vietnam.
- Large Language Model providers: process prompt content and generate AI responses. These include FPT AI Factory (Vietnam), Microsoft Azure OpenAI Service (United States / Europe), OpenAI (United States), Anthropic Claude (United States), Google Gemini (United States), DeepSeek (China), Moonshot AI Kimi (China), Zhipu AI GLM (China), and other providers listed in the Third-Party Provider List Appendix. Document content and User prompts are transmitted over HTTPS to the providers above to generate AI responses: for features the User actively invokes (for example the Chat or Edit action in the TrustAI Word Add-in) content is transmitted only when the User acts, whereas on conversational channels (Zalo OA, Web Component, Facebook Messenger) End Users' messages are transmitted automatically so the AI assistant can generate replies on the Organization's behalf. In all cases, content is not used to train any foundation model and is retained only according to each provider's retention policy.
- Monitoring and security services: incident detection and response systems, application performance monitoring (APM).
- Payment and accounting services: invoice and financial transaction processing (applies to Organizations on paid service contracts).
5.2. Safeguards
- All third-party providers sign a Non-Disclosure Agreement (NDA) and a Data Processing Agreement (DPA) with Trust Soft, committing to comply with Decree 13/2023/ND-CP.
- Trust Soft only shares data to the minimum extent necessary for the agreed purpose.
- Trust Soft performs periodic risk assessments of its providers.
5.3. Government authorities
Trust Soft may share personal data with competent government authorities in the following cases:
- Pursuant to a lawful written request from a competent authority (a decision, order or request from investigative agencies, the procuracy, courts, or inspection authorities)
- Where necessary to protect national security or public order
- Where there are signs of legal violation requiring coordination.
5.4. Cross-border data transfers
Warning: Some third-party LLM providers may host processing servers outside Vietnam. Cross-border data transfers are conducted under Articles 25 and 26 of Decree 13/2023/ND-CP.
Where a cross-border transfer occurs, Trust Soft commits to:
- Transfer Impact Assessment: prepare and retain a TIA file under Article 25 of Decree 13/2023/ND-CP.
- Notify the Ministry of Public Security: submit the assessment dossier as required.
- Apply safeguards: require foreign providers to commit to protection standards equivalent to Vietnamese requirements (via standard contractual clauses).
- Notify the Organization: where the Organization requires use of providers hosted in Vietnam only, Trust Soft supports such a configuration (see Article 14.3 of the Terms of Service).
Article 6. Data retention
Personal data is retained for as long as necessary to achieve the processing purpose or as required by law. Specifically:
| Data category | Retention period | After expiry |
|---|---|---|
| Account data | Duration of the contract + 30-day grace period | Deleted per Article 29 of the Terms of Service |
| Chat content and knowledge-base documents | As configured by the Organization (default: for the contract duration) | Deleted on request or upon termination |
| Access and security logs | At least 12 months (Cybersecurity Law requirement) | Deleted or anonymized |
| End User data via Zalo/Web/Facebook | As configured by the Organization (recommended max 90 days where there is no business need) | Automatically deleted |
| Accounting and invoice data | 10 years (Accounting Law) | Retained as required by law |
| Security incident records | At least 3 years | Deleted when no longer necessary |
Article 7. Security measures
Trust Soft applies technical and organizational measures to protect personal data:
7.1. Technical measures
- Encryption in transit (TLS 1.2 or later) and at rest (AES-256)
- Per-Organization data isolation to prevent cross-tenant access
- Multi-factor authentication (MFA) for administrator accounts
- Regular backups with verified restore capability
- Intrusion detection and prevention systems (IDS/IPS)
- Vulnerability management and regular patching.
7.2. Organizational measures
- Access control based on the least-privilege principle
- Regular security awareness training for Trust Soft staff
- Confidentiality commitments from all personnel and partners with system access
- Incident response procedures and regular drills
- Periodic independent security assessments.
Article 8. Data subject rights
Under Article 9 of Decree 13/2023/ND-CP, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Right to be informed | To be informed about the processing of your personal data (this policy is one means of fulfilling that right) |
| Right to consent | To consent or refuse consent to processing, unless another legal basis applies |
| Right of access | To view, correct or request correction of your personal data |
| Right to withdraw consent | To withdraw consent previously given, unless otherwise required by law |
| Right to erasure | To request deletion of your personal data, unless otherwise required by law |
| Right to restriction | To request restriction of processing in certain cases |
| Right to data portability | To request a copy of your personal data in a structured format |
| Right to object | To object to processing in order to prevent or restrict disclosure |
| Right to complain, denounce, sue | As provided by law |
| Right to compensation | Where damage arises from violation of data protection rules |
| Right to self-protection | Under Article 9 and related provisions |
8.1. How to exercise your rights
To exercise the rights above, you may:
- Account users: use the self-service functions in the system interface (edit profile, delete chats, delete documents…) or contact your Organization Administrator.
- End users: contact directly the Organization that operates the integration channel (Zalo OA, Web Component, Facebook Fanpage), they are your Data Controller.
- Facebook end users: you can remove the app or send a data deletion request through Facebook. When a connecting user deauthorizes the app at https://api.trustsoft.vn/facebook/deauthorize, their Pages stop operating but conversations are retained as the Organization's business records. Data deletion requests are handled via Meta's Data Deletion Callback at https://api.trustsoft.vn/facebook/data-deletion, with status available at https://api.trustsoft.vn/facebook/data-deletion/status?code=<code>; deletion removes the Page connection, the Page–Organization mapping and per-Page message counters.
- Anyone: send a request to Trust Soft at dpo@trustsoft.com.vn. Trust Soft will route the request to the appropriate party if needed.
8.2. Response timelines
- Acknowledgement of receipt: within 3 working days
- Completion: within 15 working days of receiving a valid request
- Complex cases: may be extended by up to 15 additional days, with a reasoned notice
- First request in a calendar year: free of charge. Repeat requests may incur a reasonable processing fee.
Article 9. Protection of children's personal data
Under Article 20 of Decree 13/2023/ND-CP, the personal data of children (persons under 16) is subject to special protection:
- TrustAI does not actively collect children's data. It is designed for office workers and staff in professional environments.
- For children aged 7 and above: consent from both the child and the parent or guardian is required.
- For children under 7: consent of a parent or guardian is required.
- Organization responsibility: if the Zalo OA, Web Component or Facebook Fanpage channel could serve users under 16 (e.g. school portals, pediatric healthcare services), the operating Organization must implement age verification and obtain guardian consent before processing.
- If children's data is found to have been collected without valid consent, Trust Soft will work with the Organization to delete it as soon as possible.
Article 10. Cookies and similar technologies
TrustAI uses cookies and similar technologies (local storage, session storage) for the following purposes:
| Cookie category | Purpose | Can be disabled? |
|---|---|---|
| Strictly necessary | Maintain login sessions, store core system state | No (disabling will break the service) |
| Security | Protect against CSRF attacks, fraud detection | No |
| Preferences | Store language and theme (light/dark) selection | Yes (via browser settings) |
| Analytics | Measure performance and errors (anonymized) | Yes (via browser settings) |
- TrustAI does not use third-party advertising cookies.
- The Web Component embedded in an Organization's website may use cookies depending on the Organization's configuration, the Organization's cookie policy takes precedence for end users.
Article 11. Data breach notification
Trust Soft commits to fulfilling its notification obligations under Article 23 of Decree 13/2023/ND-CP. In the event of a personal data security incident, Trust Soft will:
- Notify the affected Organization/users within 24 hours of detection
- Coordinate with the Organization (acting as Controller) to notify the Ministry of Public Security (Department of Cyber Security and Hi-tech Crime Prevention, A05) within 72 hours
- Apply remediation measures and limit the impact
- Retain incident records for at least 3 years.
The detailed incident notification procedure is set out in Article 16 of the TrustAI Terms of Service.
Article 12. Policy updates
Trust Soft may update this policy as needed. The update process is:
- Minor changes (grammar fixes, clarifications…): published on the website and effective immediately.
- Material changes (adding/removing processing purposes, adding new providers involving cross-border transfers…): notified to Organization Administrators at least 30 days before taking effect.
- Fundamental changes (changes to the business model or legal basis of processing…): may require fresh consent from the Organization/user.
The version number and update date are published at the top of this document.
Article 13. Contact
To submit requests, complaints or questions regarding this policy:
| Contact point | Details |
|---|---|
| Unit | Trust Soft, Legal & Policy Department |
| Data Protection Officer (DPO) | dpo@trustsoft.com.vn |
| Legal email | legal@trustsoft.com.vn |
| General support email | support@trustsoft.com.vn |
| Security incident contact (24/7) | security@trustsoft.com.vn |
| Working hours | Monday to Friday, 08:00-17:30 (GMT+7) |
| Website | https://trustsoft.ai/ |
You may also lodge a complaint with the state authority for personal data protection (Department of Cyber Security and Hi-tech Crime Prevention, A05, Ministry of Public Security) if you believe your rights have been violated.
─── End of document ───