| Document name | TrustAI Third-Party Provider List Appendix |
|---|---|
| Version | 1.0 |
| Effective date | May 2026 |
| Scope | Applies together with Terms of Service v1.0 and Privacy Policy v1.1 |
| Updates | Trust Soft updates on changes and notifies under Article 14 of the Terms of Service |
| Contact | legal@trustsoft.com.vn | dpo@trustsoft.com.vn |
This Appendix forms an inseparable part of the TrustAI Terms of Service and Personal Data Protection & Privacy Policy.
Part 1. Introduction
This Appendix publishes the list of third-party providers used by Trust Soft to operate the TrustAI platform, including:
- Cloud infrastructure providers and related services
- Large Language Model (LLM) providers
- Monitoring, security, and analytics service providers
- Other technical partners that come into contact with data during service operations.
Note: This Appendix is published to fulfill the commitment to data processing transparency, meet the requirements of Decree 13/2023/ND-CP, and assist Organizations in assessing legal risk when using the service.
1.1. How to read this Appendix
Each provider is described with key information:
- Name: trade name and legal entity (if different).
- Service type: the provider's role in the TrustAI ecosystem.
- Processing location: country/region where servers process data, key to assessing cross-border transfer risk.
- Data categories shared: scope of data Trust Soft transfers to the provider.
- Legal basis: Data Processing Agreement (DPA), Standard Contractual Clauses (SCC), or equivalent commitments.
- Policy link: link to the provider's privacy policy.
1.2. Appendix updates
- Trust Soft updates this Appendix on provider changes
- Update notices are sent to Organization Administrators at least 30 days before changes take effect (per Article 14.2 of the Terms of Service)
- The current version is always published at Trust Soft's official address.
Part 2. Large Language Model (LLM) providers
LLMs process prompt content and generate AI responses. They are the most direct content-processing components and require the highest transparency.
Note: Organizations may choose which AI models to use in their plan and may exclude specific providers as needed (especially when requiring Vietnam-based providers), per Article 14.3 of the Terms of Service.
2.1. FPT AI Factory (Vietnam)
| Legal entity | FPT Smart Cloud Company Limited (FPT AI Factory) |
|---|---|
| Service type | Open-source LLMs hosted by FPT on infrastructure located in Vietnam |
| Models used | GPT OSS 120B, Qwen3.6-27B, GLM-5.1 |
| Processing location | Data centers in Vietnam (operated by FPT AI Factory) |
| Data shared | Prompt content and conversation context necessary to generate responses, no user identity data is sent |
| Security commitment | Data does not leave Vietnam, customer content is not used to train models |
| Legal basis | DPA between Trust Soft and FPT Smart Cloud, compliant with Decree 13/2023/ND-CP |
| Cross-border transfer | No |
| Recommended for | Organizations with strong data sovereignty requirements, especially government agencies |
| Policy link | https://fptcloud.com/privacy-policy/ |
2.2. Microsoft Azure (United States)
| Legal entity | Microsoft Corporation (delivered via Microsoft Azure) |
|---|---|
| Service type | Large language models hosted on Azure |
| Models used | GPT-5.3 chat, GPT-5.4, GPT-5.4 mini, Kimi-K2.6 |
| Processing location | United States |
| Data shared | Prompt content, conversation context, attached documents (if any), technical session identifiers (not including user identity data) |
| Provider commitment | Microsoft commits not to use customer data to train foundation models |
| Legal basis | Data Processing Addendum under Microsoft's standard terms |
| Cross-border transfer | Yes (processing in the United States), TIA performed and safeguards applied |
| Policy link | https://www.microsoft.com/privacy |
2.3. DeepSeek API (China)
| Legal entity | DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) |
|---|---|
| Service type | DeepSeek language models via API |
| Models used | Deepseek v3.2, Deepseek v4 Flash, Deepseek v4 Pro |
| Processing location | China |
| Data shared | Prompt content and conversation context necessary to generate responses, no user identity data is sent |
| Legal basis | DeepSeek API terms |
| Cross-border transfer | Yes, TIA performed |
| Recommendation | Organizations evaluate per business requirements, opt-out available under Article 14.3 of the Terms of Service |
| Policy link | https://www.deepseek.com/privacy |
2.4. LLM provider comparison
| Provider | Models | Processing location | Public-sector suitability | No-training commitment on customer data |
|---|---|---|---|---|
| FPT AI Factory | GPT OSS 120B, Qwen3.6-27B, GLM-5.1 | Vietnam | High, recommended | Yes (hosted domestically, under DPA) |
| Microsoft Azure | GPT-5.3 chat, GPT-5.4, GPT-5.4 mini, Kimi-K2.6 | United States | Medium-high | Yes (Microsoft commitment) |
| DeepSeek API | Deepseek v3.2, v4 Flash, v4 Pro | China | Low, requires review | Per provider terms |
Part 3. Cloud infrastructure providers
TrustAI prioritizes cloud infrastructure hosted in Vietnam to ensure data sovereignty and compliance with the Cybersecurity Law.
3.1. Primary infrastructure
| Service type | Virtual machines (IaaS), object storage, internal networking, load balancing |
|---|---|
| Data center location | Vietnam (Hanoi, Ho Chi Minh City) |
| Data stored | All Organization data (accounts, documents, chat history, logs) |
| Commitment | Compliance with the Cybersecurity Law and in-country data residency |
| Legal basis | DPA signed between Trust Soft and the provider |
| Security standards | ISO 27001 or equivalent, Vietnamese information security certifications as applicable |
Note: the specific infrastructure provider name is disclosed to the Organization in the documentation attached to the Service Contract and may be subject to bilateral confidentiality.
3.2. Auxiliary services
| Service type | Purpose | Processing location |
|---|---|---|
| CDN (content delivery network) | Speed up loading of UI assets (CSS, JS, images) | Multi-region, no content data processed |
| Transactional email | Authentication and system notifications | Vietnam (preferred) or Southeast Asia |
| Vector database | Store and query document embeddings in the knowledge base | Vietnam (co-located with primary infrastructure) |
| ASR (speech-to-text) | Power the voice-to-text feature | Vietnam (preferred) or Singapore |
Part 4. Monitoring and security providers
These services help Trust Soft detect incidents, ensure performance, and protect the system. They DO NOT process user content, only technical logs and operational data.
| Service type | Purpose | Data processed |
|---|---|---|
| Application Performance Monitoring (APM) | Error detection, response time measurement, system optimization | Technical logs, error codes, performance metrics (no user content) |
| Centralized log management | Aggregate and analyze logs from services | Access logs, system activity logs |
| Web Application Firewall (WAF) | Block attacks targeting the web app (SQL injection, XSS…) | HTTP requests, IP addresses, attack signatures |
| Intrusion Detection System (IDS) | Detect and alert on anomalous network activity | Network traffic, access logs |
| SSL/TLS certificate management | Issue and renew HTTPS certificates | Domain names (no content processed) |
| Backup and Disaster Recovery | Regular backups and recovery on incidents | Encrypted backups of all system data |
Part 5. External channel integration partners
When Organizations enable integrations with external platforms, those platforms participate in data processing in their own roles.
5.1. Zalo Official Account (Zalo OA)
| Legal entity | VNG Corporation (Zalo) |
|---|---|
| Service type | OA messaging platform allowing Organizations to interact with end users |
| Legal role | Independent Controller (for end-user Zalo data) or Joint Processor |
| Processing location | Vietnam |
| Data involved | Zalo user ID, messages exchanged through the OA channel |
| Organization responsibility | Comply with Zalo OA terms, notify end users about AI processing (Articles 26 and 27 of the Terms of Service) |
| Policy link | https://zalo.me/policy |
5.2. Meta Platforms (Facebook, Messenger)
| Legal entity | Meta Platforms, Inc. |
|---|---|
| Service type | Social networking and messaging platform (Facebook, Messenger) allowing Organizations to connect their Page and interact with end users |
| Legal role | Independent Controller (for end-user Facebook data) or Joint Processor |
| Processing location | Global (Meta infrastructure); data stored by Trust Soft is hosted on infrastructure located in Vietnam |
| Data involved | PSID (Page-scoped user ID issued by Meta), public Facebook display name, Messenger message content (including attached images), comments on the Page's posts and the commenter's ID |
| How it is connected | Organizations connect their own Page via Facebook Login for Business on app.trustsoft.vn; Trust Soft is not added to the Organization's Business Manager. Page access tokens are stored encrypted and data is isolated per Organization |
| Organization responsibility | Comply with Meta's Platform Terms, notify end users about AI processing (Articles 26 and 27 of the Terms of Service) |
| Policy link | https://www.facebook.com/privacy/policy |
5.3. Web Component (embedded on the Organization's website)
- The Web Component is embedded in the Organization's website per the Organization's configuration.
- Trust Soft provides the technology. The Organization owns the website and is the Data Controller for end users visiting it.
- Trust Soft processes messages sent through the Web Component as Data Processor.
- The Organization is responsible for: displaying privacy notices, cookie consent (if applicable), and complying with the privacy policy of its website.
Part 6. Controls and Reviews
6.1. Provider selection criteria
Trust Soft applies the following criteria when selecting third-party providers:
- Hold international security certifications (ISO 27001, SOC 2, or equivalent)
- Commit to comply with Vietnamese law, particularly Decree 13/2023/ND-CP and the Cybersecurity Law
- Have a signed DPA or equivalent commitment in writing
- Commit not to use customer data to train AI models without consent
- Have a clear security incident notification mechanism
- Publish a complete privacy policy.
6.2. Periodic review
- Trust Soft performs risk reviews of third-party providers at least every 12 months.
- Ad-hoc reviews on material changes (provider policy, security incidents, legal changes).
- Review results are retained and made available to Organizations on valid request.
6.3. Organization rights
- Request detailed information about a specific provider (certifications, DPA, storage location).
- Request exclusion of a provider from its data processing under Article 14.3.
- Request periodic reports on the providers processing its data.
- Participate in audits of Trust Soft's processing activities, per Service Contract terms.
6.4. Contact
| Legal | legal@trustsoft.com.vn |
|---|---|
| Data Protection Officer (DPO) | dpo@trustsoft.com.vn |
| Security incident contact (24/7) | security@trustsoft.com.vn |
| General support | support@trustsoft.com.vn |
─── End of document ───