| Document name | TrustAI Terms of Service |
|---|---|
| Version | 1.0 |
| Effective date | May 2026 |
| Scope | All TrustAI users |
| Issuer | Trust Soft, Legal & Policy Department |
| Classification | Public document |
| Related documents | Personal Data Protection & Privacy Policy, Third-Party Provider List Appendix |
This document is effective from the date of issuance.
Preamble
Welcome to TrustAI, an artificial intelligence platform developed by Trust Soft, serving the digital transformation needs of enterprises and government agencies in Vietnam.
These Terms of Service (the “Terms”) define the rights, obligations, and legal responsibilities between Trust Soft and users when accessing, registering for, or using TrustAI. By logging in and using any feature of TrustAI, you confirm that you have read, understood, and agree to comply with all provisions of this document.
These Terms are designed to ensure a safe, effective, and legally compliant environment, while protecting the legitimate interests of both parties. The processing of personal data is detailed in the Personal Data Protection & Privacy Policy, issued together with these Terms and forming an inseparable part of TrustAI's legal documentation.
If you do not agree with any provision, please stop using the service and contact your Organization Administrator or Trust Soft's support contact in Article 35 for clarification.
Chapter 1: Definitions and Scope
Article 1. Definitions
In these Terms, the following terms have the meanings set out below:
- “TrustAI” or “System” means the AI software platform developed and operated by Trust Soft, including all modules, features, and related services provided through web browsers and integration channels.
- “Trust Soft” means the entity that develops, owns, and operates TrustAI, responsible for the technical and legal aspects of the service.
- “Organization” means a legal entity that has signed a contract to deploy and use TrustAI, including: enterprises established under the Enterprise Law, government agencies (administrative, legislative, judicial at central and local level), public service units, political, socio-political, and socio-professional organizations, and other legal entities under Vietnamese law.
- “User” means an individual (officer, civil servant, public employee, worker) of the Organization, granted a valid account by the Organization Administrator to access TrustAI directly through the web interface at Trust Soft's official address.
- “End User” means an individual, including citizens, customers, partners, or stakeholders of the Organization, who interacts with TrustAI indirectly through integration channels deployed by the Organization (Zalo Official Account, Web Component embedded into the Organization's website, Facebook Fanpage), without holding a direct account on TrustAI. End Users are data subjects protected by the Organization as Data Controller under Decree 13/2023/ND-CP.
- “Administrator” means the user with the highest privileges within the Organization, able to create, manage, authorize and delete other user accounts.
- “User Content” means all data, documents, text, images, questions, prompts, and any information that a user uploads or enters into the System.
- “AI Assistant” means the artificial intelligence agents configured in the System to perform natural language processing, answer questions, and support business processes.
- “Knowledge Base” means the internal document storage space of the Organization in the System, used as a knowledge source for AI Assistants.
- “Workflow” means a sequence of automated processing steps designed and operated in the Workflow module of the System.
- “Account” means the credential information (email and password) issued to each user to access the System.
- “Third-Party Provider” means service providers used by Trust Soft to operate the System, including LLM providers, cloud infrastructure providers, and related services. The current list is published in the Appendix attached to these Terms (see /providers).
- “Data Security Incident” means any security breach resulting in unauthorized access, disclosure, alteration, loss, or destruction of personal data or Organization data on TrustAI.
Article 2. Scope
These Terms apply to:
- All Users of TrustAI under accounts authorized by the Organization.
- System Administrators designated by the Organization to manage and operate TrustAI.
- Users with the Developer role authorized to create and configure AI Assistants (bots), set up workflows, and manage internal knowledge bases.
- All devices, browsers, and connection environments used to access TrustAI.
- End users interacting with the System through Zalo OA, the Web Component and Facebook Fanpage, as governed by Chapter 8.
Note: These Terms apply in addition to the Service Contract or Deployment Agreement signed between the Organization and Trust Soft. In case of conflict, the Service Contract prevails.
Article 3. Effectiveness and updates
These Terms take effect at the moment of the user's first login. Trust Soft may update, amend, or supplement these Terms at any time. Update notices are sent to the Organization Administrator at least 15 days before they take effect, except for emergency updates to protect system safety.
Continued use of the System after an update is published constitutes acceptance of the changes.
Chapter 2: Accounts and Access
Article 4. Account provisioning
TrustAI accounts are provisioned under the following principles:
- The Organization Administrator is the sole point of contact authorized to create, issue, and delete user accounts within the Organization.
- Each account is identified by a unique email address and tied to a specific role: Administrator, Developer, or User.
- The number of accounts that may be created depends on the service plan the Organization has subscribed to.
- Each account may only be used by the individual to whom it was issued, it may not be transferred, lent, or shared.
Article 5. Role-based access control
TrustAI implements a three-tier permission model:
| Role | Primary permissions | Limitations |
|---|---|---|
| Administrator | Full system management, create/delete users, view reports, configure Zalo, Web Component and Facebook Fanpage integrations | Bears legal responsibility for all activity within the Organization |
| Developer | Create and configure AI Assistants (bots), design and operate automated Workflows, create and manage internal Knowledge Bases | No user management or system integration permissions |
| User | Use AI Assistants (bots) already published within the Organization, cannot create bots, knowledge bases or workflows | No access to Document Management, Workflows, or System Administration modules |
Article 6. Account security
Users are responsible for securing their credentials in accordance with the following rules:
- Do not share your login (email) or password with anyone, including Trust Soft staff.
- Set a strong password (minimum 8 characters, combining upper- and lower-case letters, digits and special characters) and rotate it according to your Organization's policy.
- Log out of the System at the end of a session, especially on shared devices.
- Notify your Administrator immediately upon detecting account compromise or signs of unauthorized access.
Warning: Trust Soft is not liable for damages arising from credentials being disclosed due to the user's own security failures.
Article 7. Account suspension and revocation
Trust Soft and the Organization Administrator may suspend or revoke an account in the following cases:
- The user violates these Terms.
- The account has been inactive for an extended period per the Organization's policy.
- The Organization terminates its service contract with Trust Soft (handled under Chapter 9).
- Detection of fraudulent activity or unauthorized use of the System.
- Request from a competent authority as required by law.
Chapter 3: User Rights and Obligations
Article 8. User rights
Users have the following rights when using TrustAI:
- The right to access and use the features available for their role, including: AI Assistants, Document Management, Workflows, and enabled integrations.
- The right to select the AI language model (LLM) appropriate for each business task, from the list of models the Organization has subscribed to.
- The right to create and manage personal knowledge bases, share documents in Private, Restricted, or Public modes within the Organization.
- The right to set up and use AI Assistants in configurations suited to their work.
- The right to use voice input (speech-to-text).
- The right to export and share chat history in accordance with the Organization's confidentiality rules.
- The right to request technical support through the channel designated by the Organization.
- The right to be notified of material changes affecting their usage rights, including changes of third-party providers per Article 14.
Article 9. User obligations
Users must comply with the following obligations:
9.1. Permitted use
- Use TrustAI only for lawful business purposes serving the Organization's work.
- Do not use the System for personal purposes unrelated to work, for commercial purposes outside the contract, or for any unlawful purpose.
- Comply with the Organization's internal procedures on information technology and data management.
9.2. Content submitted to the System
- Only upload and process documents or data that the user is authorized to use.
- Ensure that uploaded content does not infringe the copyright or intellectual property of any third party.
- Do not submit false, misleading, or fraudulent information.
- Process personal data of citizens in compliance with Decree 13/2023/ND-CP and related laws.
9.3. Use of AI output
- Verify and review AI-generated output before using it for important decisions or formal documents.
- Do not invoke AI output to disclaim or shift personal legal or professional responsibility when making decisions without expert review.
- Clearly disclose the use of AI when required by the Organization or by law.
Chapter 4: Prohibited Content and Violations
Article 10. Prohibited conduct
Users must not engage in any of the following while using TrustAI:
10.1. System security violations
- Intentionally attacking, intruding into, or disabling the System by any means (hacking, DDoS, SQL injection, etc.).
- Intentionally probing or exploiting security vulnerabilities without Trust Soft's prior written authorization.
- Installing or transmitting malware (viruses, malware, ransomware) through the System.
- Using unauthorized bots, automated scripts, or scraping tools.
10.2. Illegal or unethical content
- Submitting or generating content that infringes national security or propaganda against the Socialist Republic of Vietnam.
- Creating content that incites hostility or discrimination based on ethnicity, religion, gender, or any protected characteristic.
- Using the System to create pornographic or violent content, or content harmful to children.
- Producing false information intended to cause harm, including deepfake video, image, or audio, and disinformation aimed at fraud, defamation, or social destabilization.
- Using the System for fraud, deception, or criminal activity.
10.3. IP and data violations
- Copying, distributing, or commercially using content generated by TrustAI outside the scope permitted by contract.
- Disclosing the Organization's confidential or trade-secret information to third parties without authorization.
- Extracting or using data from another Organization's instance without authorized access.
Warning: All violations are logged in the System and may be used as evidence when handling violations under applicable law.
Article 11. Consequences of violations
Depending on severity, the user may face one or more of the following enforcement actions:
- Level 1 (Warning): a written warning or in-product notice for a first, minor offense.
- Level 2 (Account suspension): suspension of access for 1 to 30 days for intentional or repeat offenses.
- Level 3 (Permanent revocation): account deletion and termination of service for serious offenses.
- Level 4 (Legal action): Trust Soft transfers the case to competent authorities, reports suspected criminal conduct under the Criminal Procedure Code, files civil claims for damages, and cooperates in administrative enforcement as required by law.
Chapter 5: Data, Security and Privacy
Article 12. Data collection and use
When using TrustAI, the System collects and processes the following data:
| Data category | Content | Purpose |
|---|---|---|
| Account data | Email, full name, role, account creation time | Identity authentication, access control |
| Activity log | Login history, actions performed, access IP | Security monitoring, technical support |
| User content | Questions, uploaded documents, chat history | Providing AI services, improving accuracy |
| Usage data | Token consumption, AI models used, response times | Performance monitoring, billing |
| Technical data | Browser type, operating system, screen resolution | User experience optimization |
Details on personal data processing are set out in the Personal Data Protection & Privacy Policy (see /privacy), issued alongside these Terms.
Article 13. Data storage and protection
Trust Soft commits to protecting Organization and user data under the following standards:
- Data is encrypted in transit (TLS 1.2 or later) and at rest (AES-256).
- The System is deployed on high-availability infrastructure with regular backups and disaster-recovery capability.
- Each Organization's data is stored in isolation and is not shared with other Organizations (data isolation).
- Trust Soft staff access Organization data only with explicit authorization and solely for technical support.
- Data retention periods are set out in the Service Contract. After expiry, data is securely deleted per the standard procedure (see Chapter 9).
Note: TrustAI is deployed on cloud infrastructure in Vietnam, ensuring compliance with in-country data residency requirements under Decree 13/2023/ND-CP and related laws.
Article 14. Sharing data with third parties
Trust Soft commits not to sell, rent, or disclose user data to third parties, except in the following cases:
- With express written consent of the Organization or user.
- Upon a lawful request by a competent authority under applicable law.
- Cloud and technical infrastructure providers that have signed NDAs and DPAs with Trust Soft.
- AI model providers (LLM providers) to the extent necessary to deliver the service, under the rules in the following clauses.
14.1. Third-party provider list
The current list of third-party providers used by Trust Soft to operate the service, including cloud infrastructure, LLM providers, and related services, is published in the Third-Party Provider List Appendix (see /providers), which forms an inseparable part of these Terms. The Appendix is updated regularly and published at Trust Soft's official address.
14.2. Notice of provider changes
When Trust Soft plans to add, replace, or remove a third-party provider, Trust Soft commits to:
- Advance notice: send written notice (email and/or in-product) to the Organization Administrator at least 30 days before the change takes effect.
- Notice content: name of the new provider, services provided, processing/storage location (domestic/foreign), data categories shared, and a link to the provider's privacy policy.
- Emergency cases: if a change must be made urgently due to a current provider's issue (service outage, security breach…), Trust Soft may switch without the 30-day notice, but must notify within 48 hours and explain the reasons.
14.3. Organization rights
- The Organization may request detailed information about a specific provider, including security certifications, storage location, and compliance commitments under Decree 13/2023/ND-CP.
- The Organization may request exclusion of a provider from its data processing (opt-out), especially for providers hosted outside Vietnam, for legitimate reasons. Trust Soft confirms feasibility within 15 working days, where not feasible for technical reasons, the parties negotiate an alternative.
- If a provider change causes a material change in personal data processing, the Organization may terminate the affected services without breach-of-contract penalty under Chapter 9.
Article 15. User rights over data
Users and Organizations have the following rights over their data per Article 9 of Decree 13/2023/ND-CP:
- Right of access: request information on data being stored and processed.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of documents, chat history, or all personal data within technical limits.
- Right to portability: request data export in standard formats (CSV, JSON, or original format for documents) during and after contract termination (see Article 30).
- Right to object: refuse certain forms of processing not necessary to provide the service.
- Right to complain: file complaints with Trust Soft's DPO or with the competent authority.
15.1. Exercising rights
To exercise these rights, the user/Organization sends a written request (email) to the contact point in Article 35, with identity verification. Trust Soft commits to:
- Acknowledge receipt: within 3 working days.
- Complete processing: within 15 working days of receipt. Complex requests may be extended by up to 15 additional days with notice.
- Notify outcome: in writing, with evidence (e.g. for erasure: a Data Deletion Certificate).
- Fees: first request in a calendar year is free, repeat requests may incur a reasonable fee per the published schedule.
Article 16. Data breach notification
This article governs each party's responsibilities for notifying and handling data security incidents, consistent with Article 23 of Decree 13/2023/ND-CP on the 72-hour breach notification obligation.
16.1. Role allocation
Under Decree 13/2023/ND-CP:
- The Organization is the Data Controller for the personal data of employees, customers, and partners that the Organization submits to the System.
- Trust Soft is the Data Processor on behalf of the Organization, processing data within the agreed scope and purposes.
- Trust Soft is also the Controller of its internal operating data (accounts, access logs, billing data…).
16.2. Trust Soft's notification duties
Upon discovering or being notified of a data security incident, Trust Soft will:
- Within 24 hours: send preliminary notice to the affected Organization's Administrator by email and in-product. Initial content includes detection time, tentative scope of impact, and initial response measures.
- Within 72 hours: coordinate with the Organization (as Controller) to notify the Ministry of Public Security (A05) per Article 23 of Decree 13/2023/ND-CP.
- Where 72-hour notification is not feasible: the parties jointly explain the reasons to authorities and provide supplementary notification as soon as possible.
- Support data subject notification: Trust Soft provides technical support for the Organization to notify affected data subjects where the incident is likely to cause significant harm.
16.3. Notice content
The incident notice must include at minimum:
- Description of the nature of the incident and how it was detected
- Time of occurrence and time of detection
- Categories of data affected and estimated number of affected data subjects
- Potential or actual consequences
- Measures taken and to be taken to remediate, prevent, and limit harm
- Contact information of the incident response lead.
16.4. Records and retention
- Trust Soft maintains incident records as required, including root-cause analysis, remediation, notifications sent, and lessons learned.
- Records are retained for at least 3 years for inspection by competent authorities.
- The Organization may request records related to incidents affecting its data.
16.5. Liability and compensation
Compensation liability for breaches is allocated by root cause:
- Fault on Trust Soft's side (system or process errors of Trust Soft or providers designated by Trust Soft): Trust Soft is liable within the scope of Article 19.
- Fault on the Organization/User side (credential leakage, misconfigured sharing, breach of internal security procedures): the Organization/User bears responsibility.
- Mixed fault: liability is allocated by each party's contribution, negotiated in good faith.
Chapter 6: Service Quality and Liability
Article 17. Service quality commitment
Trust Soft commits to providing TrustAI at the following standards:
- Uptime: at least 99.5% monthly, excluding scheduled maintenance.
- Maintenance notice: at least 24 hours before scheduled maintenance affecting the entire service.
- Technical support: channels and response times as set out in the Service Contract.
- Feature updates: users will be notified of significant updates before deployment.
Article 18. Limitation of Trust Soft's liability
Trust Soft is not liable for:
- Absolute accuracy of AI model output, output is advisory and must be verified by the user.
- Indirect damages, data loss, or business interruption arising from unreviewed use of AI output.
- Technical incidents caused by force majeure: natural disasters, large-scale cyberattacks, national power outages, etc.
- Violations by users or third parties beyond Trust Soft's reasonable control.
- Service quality of third-party LLM providers due to policy changes or incidents outside Trust Soft's control, provided Trust Soft has complied with its notification duties under Article 14.
Warning: Users, as professionals, bear final responsibility for all business, legal, and professional decisions. TrustAI output is an assistive tool, not a substitute for human professional judgment.
Article 19. Disclaimer and liability cap
TrustAI is provided “as-is” and “as-available.” To the maximum extent permitted by law, Trust Soft makes no warranties, express or implied, of fitness for a particular purpose, non-infringement, or absence of technical defects.
Trust Soft's maximum liability shall not exceed the value of the service contract for the most recent 3 months, unless otherwise required by law or in the case of willful misconduct or gross negligence by Trust Soft.
Chapter 7: Intellectual Property and License
Article 20. Trust Soft's intellectual property
Trust Soft owns or is lawfully licensed all IP rights relating to TrustAI, including:
- Source code, software architecture, and user-interface design.
- The “TrustAI” brand, logo, product names, and related trademarks.
- Technical documentation, user guides, and training materials.
- Fine-tuned AI models specific to TrustAI.
Article 21. License
Trust Soft grants the Organization a license to use TrustAI under the following conditions:
- Non-exclusive: the Organization may not require Trust Soft to refrain from serving other third parties.
- Non-transferable: the license is tied to the Organization and may not be transferred to another Organization.
- Limited scope: usage is for the Organization's internal operations only, not for providing services to third parties absent a separate agreement.
- Time-bound: effectiveness is tied to the term of the signed Service Contract.
Article 22. Ownership of User Content
Users and Organizations retain ownership of all User Content submitted to the System. Trust Soft does not acquire ownership of any Organization documents, data, or content.
By using the System, the user grants Trust Soft a limited license to: process content to deliver the requested service, store content for the agreed period, and improve service quality in the form of aggregated, anonymized data.
Note: User Content will never be used to train AI models without the Organization's explicit written consent.
Chapter 8: Feature-Specific Terms
Article 23. AI Assistant and Language Models
- The list of available AI models (GPT OSS 120B, Qwen3.6-27B, GLM-5.1 hosted by FPT AI Factory, GPT-5.3 chat, GPT-5.4, GPT-5.4 mini, Kimi-K2.6 hosted by Microsoft Azure, Deepseek v3.2, v4 Flash, v4 Pro via DeepSeek API) is published in the Third-Party Provider List Appendix (see /providers) and may change with provider policies and subscribed service plans, under the notice mechanism in Article 14.
- AI-generated output may contain inaccuracies, factual errors, or biases. Users must verify before use.
- Image generation may only be used for lawful business purposes, do not generate images that infringe law or intellectual property.
- Speech-to-text (voice chat) requires microphone access on the device, voice data is processed under Articles 12 and 13.
Article 24. Knowledge Base and Document Management
- Users are responsible for the legality and accuracy of documents uploaded to the knowledge base.
- Uploaded documents go through embedding processing. AI response quality depends on source document quality.
- When sharing a knowledge base in Public mode, documents become accessible to all accounts in the Organization. The sharer is responsible for careful review before sharing.
- Trust Soft is not liable for consequences arising from sharing confidential documents beyond the permitted scope due to user misconfiguration.
Article 25. Automated Workflows
- Workflows execute according to user configuration. The Organization is responsible for the execution results of workflows it sets up.
- Workflows connecting to external services (email, calendar, etc.) operate using credentials provided by the user, Trust Soft does not store third-party service passwords.
- Workflow execution history is stored for monitoring and technical support, only the Administrator and the workflow owner can access it.
Article 26. Zalo OA, Web Components and Facebook Fanpage integration
26.1. Scope and shared responsibility
- Organizations using the Zalo Official Account (OA) integration must comply with Zalo/VNG's terms and are responsible for content sent to Zalo end users.
- Web Components embedded in an Organization's website must comply with web security policies and may not be used to collect user information without authorization.
- Organizations using the Facebook Fanpage integration (Messenger and comments) connect their own Page via Facebook Login for Business, must comply with Meta's Platform Terms, and are responsible for the responses, comments, and posts sent to Facebook end users.
- Trust Soft provides the technology and tools. The Organization is responsible for content, policy, and legal compliance in deploying these channels.
26.2. End-user notice obligations
Note: When deploying Zalo OA, the Web Component or a Facebook Fanpage to serve end users, the Organization is the Data Controller of end-user personal data and is responsible for notice obligations under Decree 13/2023/ND-CP.
Specifically, the Organization must:
- Display a processing notice: in Zalo OA's welcome message, the Web Component UI, or when starting a Facebook Messenger conversation, clearly display content equivalent to: “When using this service, your messages will be processed by an AI system and may be shared with third-party AI model providers to generate responses. Please read our Privacy Policy at [link].”
- Collect valid consent: for sensitive personal data or specific legal requirements, the Organization must have a clear mechanism to collect end-user consent before processing.
- Provide a contact point: so end users can exercise their rights of access, correction, and deletion.
- Comply with children's data rules: if the channel may serve users under 16, the Organization must implement age verification and obtain guardian consent under Article 20 of Decree 13/2023/ND-CP.
26.3. Trust Soft's support
Trust Soft provides tools and documentation to help the Organization fulfill these obligations, including:
- Standard notice templates built into the Zalo OA, Web Component and Facebook Fanpage configuration UI.
- A “Welcome message” field with a reminder when AI and privacy information is missing.
- Direct references to TrustAI's Privacy Policy when the Organization lacks its own policy.
Article 27. AI Transparency
Transparency in user-AI interaction is a core TrustAI principle, especially when government agencies deploy the service for citizens.
27.1. Transparency principle
Trust Soft and the Organization commit to ensuring end users are clearly informed that they are interacting with an AI system, not a human. This principle applies across all TrustAI channels, including the main UI, Zalo OA, the Web Component, and Facebook Fanpage.
27.2. Display requirements
- Clear self-introduction: the AI assistant's first message to an end user must include a clear introduction, e.g. “Hello, I'm the AI assistant of [Organization]. I can help with [scope].”
- Persistent label: the Web Component UI must display an “AI”, “Virtual assistant”, or equivalent label in a noticeable position (header or next to the assistant's name) throughout the session.
- Human handoff: when the assistant exceeds its capabilities or upon end-user request, it must hand off to a real support agent or provide a direct contact channel with the Organization.
27.3. AI assistant configuration
AI assistants in TrustAI must be configured to follow these principles:
- Do not claim to be human when asked directly
- Acknowledge when there is insufficient information to answer, rather than hallucinate
- For legal, medical, financial, or safety matters, advise users to verify with experts or competent authorities
- Do not impersonate a specific individual without that person's consent.
27.4. Allocation of responsibility
- Trust Soft provides technical tools, configuration guidance, and standard content templates to support transparency requirements.
- The Organization is responsible for configuring, testing, and maintaining the effectiveness of AI transparency notices in production. The Organization is also responsible for the specific behavior and speech of its deployed AI assistants.
Chapter 9: Service Termination
This chapter governs the right to terminate, the data export/deletion process on termination, and provisions surviving termination.
Article 28. Rights and grounds for termination
28.1. Termination by the Organization
- End-of-term termination: the Organization may terminate the service at the end of the contract term. Written notice must be given to Trust Soft at least 30 days before expiry.
- Mid-term termination for cause: the Organization may terminate mid-term without breach penalty where (i) Trust Soft materially breaches and fails to cure within 30 days of written notice, (ii) a third-party provider change materially changes personal data processing and the Organization does not accept it, (iii) other cases under the Service Contract.
- Mid-term termination without cause: must follow the Service Contract terms and may incur financial obligations (early termination fee).
28.2. Termination by Trust Soft
- With prior notice: Trust Soft may terminate where the Organization materially breaches these Terms or the Service Contract and fails to cure within 15 days of written notice.
- Immediate termination: where the Organization threatens system security, engages in serious unlawful activity recorded on the System, or is more than 60 days past due on fees.
28.3. Mutual agreement and force majeure
- The parties may terminate by mutual written agreement at any time, with arrangements for outstanding obligations.
- If a force majeure event (Article 33) continues for more than 90 days, either party may terminate by written notice without liability for damages for such termination.
Article 29. Data export and processing on termination
29.1. Data Export period
- Window: during the 30 days before and 30 days after termination (60 days total), the Organization may request export of all its data.
- Export formats: structured data (chat history, activity logs, bot and workflow configurations), JSON or CSV at the Organization's choice, knowledge-base documents, original upload format (PDF, DOCX, XLSX, TXT…), metadata (folder tree, sharing permissions, tags), JSON, usage reports, PDF or XLSX.
- Delivery: data is provided via a secure download channel (2FA required), with links valid for 14 days.
- SLA: Trust Soft completes export within 15 working days of receiving the request.
- Fees: first export request on termination is free, additional requests beyond this window may incur a fee per the published schedule.
29.2. Grace Period
- For 30 days after termination, data is held in read-only state for the Organization to confirm and reconcile export.
- User accounts are suspended and cannot use AI features, Zalo OA, Web Component and Facebook Fanpage integrations are stopped.
- The Organization may extend the grace period by up to 30 days by written request before the initial period ends, with possible storage fees by agreement.
29.3. Data Deletion
- Primary deletion: at the end of the grace period, Trust Soft securely deletes all Organization data on the primary system within 15 days, using methods that prevent recovery.
- Backup deletion: backups are deleted on the backup rotation cycle, no later than 90 days after termination.
- Third-party deletion: Trust Soft requires third-party providers to delete related data under signed DPAs.
- Data Deletion Certificate: Trust Soft provides a Data Deletion Certificate on Organization request, with details of data categories, timing, and deletion method.
29.4. Exceptions
Some data may be retained beyond the above periods in the following cases:
- Lawful requests from competent authorities (decisions, orders, or written requests from investigative bodies, the procuracy, courts, or inspection authorities under law)
- Servicing ongoing legal disputes between the parties
- Retention obligations under law (accounting, tax, insurance, electronic record retention…)
- Data already anonymized and no longer capable of identifying data subjects, not subject to deletion obligations.
In exceptional cases, Trust Soft notifies the Organization of the scope, reason, and retention period.
Article 30. Provisions surviving termination
Termination of these Terms does not affect the effectiveness of the following provisions, which continue to apply after termination:
- Article 13 (Data storage and protection), for data retained under exceptions
- Article 16 (Breach notification), for incidents related to data in the grace period
- Articles 18 and 19 (Limitation of liability and disclaimers)
- Articles 20, 21, 22 (Intellectual property and License)
- Article 31 (Governing law) and Article 32 (Dispute resolution)
- Outstanding financial obligations of the parties
- Confidentiality and non-disclosure obligations (including after termination).
Chapter 10: Dispute Resolution and Final Provisions
Article 31. Governing law
These Terms are governed by and construed under the laws of the Socialist Republic of Vietnam, in particular:
- Law on Information Technology No. 67/2006/QH11 and its implementing regulations.
- Law on Cybersecurity No. 24/2018/QH14.
- Law on Electronic Transactions No. 20/2023/QH15 (effective from 1 July 2024).
- Decree No. 13/2023/ND-CP on personal data protection.
- Civil Code No. 91/2015/QH13, Intellectual Property Law No. 50/2005/QH11 (as amended) and other relevant laws in force.
Article 32. Dispute resolution
When a dispute arises, the parties prioritize resolution in this order:
- Step 1 (Negotiation): within 30 days of the dispute, the parties hold direct negotiations to find a solution.
- Step 2 (Mediation): if negotiation fails, the parties may propose mediation through an independent intermediary within the next 30 days.
- Step 3 (Arbitration or court): if mediation fails, the dispute is resolved at the Vietnam International Arbitration Centre (VIAC) or the competent People's Court under the Civil Procedure Code, with preference for the court at Trust Soft's head office, by the parties' choice or per the Service Contract.
Article 33. Force majeure
Trust Soft is not liable for non-performance or delayed performance caused by force majeure, including but not limited to: natural disasters, pandemics, war, government actions, large-scale cyberattacks, and national infrastructure outages. Trust Soft will notify promptly and remediate as quickly as possible. If the event continues for more than 90 days, the parties may terminate under Article 28.3.
Article 34. Severability
If any provision of this document is declared invalid or unenforceable by a competent authority, the remaining provisions stay in full force. The invalid provision will be replaced by the valid provision closest in intent to the original.
Article 35. Contact
For questions, complaints, or requests regarding these Terms, please contact:
| Unit | Trust Soft, Legal & Customer Support |
|---|---|
| Support email | support@trustsoft.com.vn |
| Legal email | legal@trustsoft.com.vn |
| Data Protection Officer (DPO) | dpo@trustsoft.com.vn |
| Security incident contact (24/7) | security@trustsoft.com.vn |
| Working hours | Monday to Friday, 08:00-17:30 (GMT+7) |
| Website | https://trustsoft.ai/ |
─── End of document ───