Personal Data Processing Agreement (DPA)

Issued together with the 1Office Software subscription agreement

1Office publishes this Personal Data Processing Agreement (the “DPA”) to govern the confidentiality and processing of personal data arising in the course of providing the Service. The DPA is an integral part of the Master Agreement under Article 1.5 of the Agreement and becomes automatically binding on the Customer as soon as the Customer signs the Agreement or starts using the Service, with no separate document required for each Customer.

In this DPA, “1Office” or “the data processor” means 1Office Joint Stock Company; “Customer” or “the data controller” means the Customer identified in the Agreement.

On the basis of compliance with the Personal Data Protection Law 2025, this DPA (hereinafter the “DPA” or the “Commitment”) sets out the confidentiality and personal data processing provisions on the specific terms and conditions below:

Article 1. Definitions and interpretation

1.1. Personal data

  • Digital data or information in another form that identifies or helps identify a specific person, comprising basic personal data and sensitive personal data. Data that has been de-identified is no longer personal data.
  • The personal data referred to in this agreement may be data of the Customer's own customers, of representatives or employees of either Party, and/or of any individual connected with the Agreement and this DPA whose data the parties may exchange or transfer to each other while signing, performing and implementing this Agreement.

1.2. Basic personal data

Basic personal data is data reflecting common identity and background details regularly used in transactions and social relations, within the list issued by the Government, comprising:

  • Surname, middle name and given name at birth, and any other name (if any);
  • Date of birth; date of death or disappearance;
  • Sex;
  • Place of birth, place of birth registration, permanent residence, temporary residence, current residence, place of origin and contact address;
  • Nationality;
  • Images of the individual;
  • Phone number, personal identification number, passport number, driving licence number and vehicle registration number;
  • Marital status;
  • Family relationship information (parents, children, spouse);
  • Information about the individual's digital accounts;
  • Other information attached to or helping to identify a specific person, as understood under Decree 356 and other applicable laws.

1.3. Sensitive personal data

Personal data tied to an individual's privacy which, if infringed, directly affects the individual's lawful rights and interests, within the list issued by the Government, comprising:

  • Data revealing racial or ethnic origin;
  • Political, religious or belief views;
  • Information about private life, personal secrets and family secrets;
  • Health status;
  • Biometric data and genetic characteristics;
  • Data revealing an individual's sex life or sexual orientation;
  • Data on crimes and criminal conduct collected and stored by law enforcement agencies;
  • The individual's location as determined through location services;
  • Username and password for an individual's electronic identification account, and images of identity cards, citizen identity cards and ID cards;
  • Bank account usernames and passwords; bank card information and bank account transaction history; financial and credit information and information on customers' financial, securities and insurance activity and transaction history at credit institutions, foreign bank branches, payment intermediary service providers, securities and insurance organisations and other licensed organisations;
  • Data tracking behaviour and use of telecommunications services, social networks, online communication services and other services in cyberspace;
  • Other personal data that the law requires to be kept secret or to be subject to strict security measures.

1.4. Processing of personal data / processing

Any operation affecting personal data, comprising one or more of the following: collecting, analysing, aggregating, encrypting, decrypting, editing, deleting, destroying, de-identifying, providing, publishing and transferring personal data, and other operations affecting personal data.

1.5. Data subject

The person to whom the personal data relates.

1.6. Data controller

The agency, organisation or individual that determines the purposes and means of processing personal data.

1.7. Personal data processor

The agency, organisation or individual that processes personal data at the request of the personal data controller under the Agreement/DPA or an arrangement with the data controller.

1.8. Third party

An organisation or individual other than the data subject, the personal data controller or the personal data processor that takes part in processing personal data as provided by law.

1.9. Data breach incident

An event that exposes, loses, gives unauthorised access to, unlawfully alters or destroys personal data; or other conduct breaching personal data protection rules.

1.10. Technical data (system logs)

Data arising from use of the service for the purposes of operation, information security, measurement and service improvement.

Article 2. Roles and scope of processing

  1. Within the scope of providing and operating the service under the Agreement, the Customer is the data controller and 1Office is the data processor for personal data the Customer enters into or stores on the system.
  2. The data processor undertakes not to retain, use or exploit the Personal Data transferred to it by the data controller for purposes beyond those set out in the Agreement and this DPA and/or applicable law. In all cases the data processor undertakes to apply the measures and put in place the conditions necessary to ensure the security and safety of the Personal Data processed.
  3. The categories of personal data the Parties may process are: basic personal data and sensitive personal data
  4. The Customer owns all data it enters into the system throughout the subscription period and is responsible for the lawfulness of the data source, the purposes of processing, the content of notices to data subjects and the corresponding legal bases.
  5. Where the Customer asks 1Office to process categories of sensitive personal data, the Customer warrants that it has the appropriate legal basis and processing conditions required by law and provides 1Office with instructions recorded in writing (or in an equivalent form). Where 1Office seeks clarification, the Customer will supplement or confirm detailed instructions in writing before 1Office continues processing.
  6. 1Office is responsible for processing personal data only within the scope of its own access, management and control under the Agreement and this DPA. 1Office is under no obligation to check or verify the lawfulness, accuracy, completeness or currency of data provided by the Customer and is not liable for any breach or damage arising from the Customer collecting or providing unlawful or inaccurate data, or using, sharing or processing such data for the Customer's own purposes.
  7. After 1Office has handed over the data, or terminated access to it at the Customer's request, 1Office is not responsible for any subsequent storage, use, sharing or processing of that data by the Customer or by a third party appointed by the Customer, except for the part of the responsibility that rests with 1Office under the law and the terms of the Agreement and this DPA.
  8. Where the data controller faces a complaint, denunciation, lawsuit and/or compensation claim from a data subject, the data controller bears responsibility and resolves the matter at its own cost, and holds the data processor harmless and released from any resulting obligation (if any), unless the data subject's complaint, denunciation, lawsuit and/or compensation claim arises from the data processor's fault.

Article 3. Security and governance measures

  1. Infrastructure and storage: Data is stored in a Data Centre and controlled in accordance with the international information security standard ISO 27001:2022.
  2. Technical measures: 1Office applies encryption in transit; multi-layer access control; vulnerability scanning and remediation on a reasonable cycle; information security monitoring and anomaly detection; and change control and configuration management.
  3. Organisation and personnel: 1Office personnel involved in accessing or processing Customer data must sign a confidentiality and information security undertaking; are granted appropriate permissions; receive periodic training on data protection and information security; and are subject to compliance monitoring when accessing Customer data.
  4. Testing and assessment: 1Office periodically assesses information security in proportion to the scale of the service. Where 1Office requests an inspection or reconciliation, the two Parties cooperate according to an agreed plan, scope and appropriate confidentiality conditions (without disrupting the service).

Article 4. Third parties

  1. 1Office may engage third-party processors, being other organisations or individuals, to carry out part of the data processing in order to provide the service, subject to the Customer's prior written approval (including approval expressed through the Customer following the notification procedure and not objecting under Article 4.2 below). 1Office is responsible for selecting the third party, binding it by a contract or a confidentiality and data protection agreement offering protection no lower than the corresponding obligations in this DPA, and monitoring the third party's compliance within the work assigned by 1Office.
  2. 1Office will notify the Customer of the list of principal third parties directly involved with the Customer's personal data, and of material changes to that list, by email or an agreed communication channel. The third-party list includes but is not limited to: cloud infrastructure/storage providers, digital signature and SMS service providers, and providers of artificial intelligence (AI) models or platforms used to process the Customer's AI Input and AI Output under Article 10 of the ToS, where such processing involves transferring Personal Data to that provider. The Customer may comment or object in writing within 07 (seven) working days of receiving the notice; if the Customer does not comment within that period, it is understood not to object to the use (or continued use) of that third party.
  3. Where the Customer raises a reasonably grounded objection to a third party, the two Parties will discuss in good faith to find a suitable solution that maintains the service.

Article 5. Data subject rights and compliance support

  1. On receiving a request to exercise a data subject's rights, the Customer will notify 1Office and act only on lawful written instructions signed and stamped by the Customer's duly authorised legal representative, unless the law provides otherwise.
  2. 1Office supports the Customer in meeting lawful data subject requests within the periods set out in Decree 356/2025/ND-CP, namely: 02 (two) working days for requests to withdraw consent, restrict or object to the processing of personal data; 10 (ten) days for requests to access, correct or provide personal data; 20 (twenty) days for requests to delete personal data, or another period under relevant law as amended from time to time. So that the Customer has enough time to act within those periods, 1Office undertakes to respond and provide technical support for the Customer's request within 24 (twenty-four) hours of receiving the Customer's notice under Article 5.1, for requests within the standard service scope. Where 1Office's support goes beyond the standard service scope or involves a significant workload, the two Parties will agree in advance in writing on the scope of work, the timeline and the corresponding costs (if any).
  3. The Customer leads and is responsible for carrying out personal data processing impact assessments and cross-border transfer assessments (if any) as required by law, and cooperates by providing 1Office with the information, documents and instructions needed within the scope relevant to the service.

Article 6. Incidents and data breach notification

  1. Where 1Office discovers, or has reasonable grounds to believe, that a personal data breach incident has occurred, 1Office must notify the Customer no later than 72 (seventy-two) hours from the time 1Office confirms the incident, consistent with the period in Article 12.3 of the ToS, and cooperate with the Customer in assessing and remedying the incident and performing the related legal obligations.
  2. The written notice includes, so far as possible: a description of the incident, the categories of data affected, the estimated scale, the risk to data subjects' interests, the measures applied or proposed, and contact point details. Where the investigation is not complete within the 72-hour period, 1Office will send a preliminary notice within that period and provide further updates as information becomes available.
  3. Where the Customer or a third party discovers a breach of personal data protection rules capable of harming national defence, national security, social order and safety, or infringing data subjects' lawful rights and interests, the Customer must notify the competent state authority within 72 (seventy-two) hours of discovering the breach, as required by law.

Article 7. Retention, data export and deletion/anonymisation

  1. While the Agreement is in force, the Customer may request a data export in a format supported by the system, on a basis that ensures security and reasonable cost.
  2. When the Agreement terminates (including automatic termination on expiry of the renewal-pending period for a License Period as provided in the Agreement), 1Office keeps the Customer's data on the system for at most 06 (six) months from the termination date, consistent with the period in Article 22 of the ToS, to support handover. During that period the Customer may request a data export. After it, 1Office deletes or anonymises the data in accordance with its internal data retention and protection procedures, unless the law or a competent state authority requires 1Office to retain it longer.
  3. After completing the deletion or anonymisation under clause 7.2, 1Office will confirm to the Customer in writing or in an equivalent electronic form, stating when the deletion/anonymisation was completed and the scope of data processed.

Article 8. Disclosure at the request of state authorities

  1. Where 1Office receives a written request from a competent state authority relating to the Customer's data or information, 1Office will, to the extent the law permits, notify the Customer in writing as soon as possible and provide information on the content and scope of the request. 1Office discloses information and data only to the minimum extent necessary to comply with that request and applicable law.
  2. The Parties cooperate in handling requests from competent state authorities, including but not limited to exchanging the necessary information and documents, in order to ensure compliance with the law and to protect the lawful rights and interests of the Customer and data subjects as far as possible. Where the law prohibits 1Office from notifying the Customer (for example: a confidential request or one serving an investigation), 1Office is released from the notification obligation in clause 8.1 until further notice from the state authority.

Article 9. Personal data protection contact points

  1. The data controller (the Customer) and the data processor (1Office) notify each other of their personal data protection contact point (department/address/contact email) by email or an agreed channel during implementation of the Service; it need not be recorded in this DPA.
  2. 1Office's contact point details are published on its official product information page or provided through the support channel at the Customer's request.

Article 10. Sanctions, liability and limits

  1. Each Party's confidentiality and personal data protection obligations, and the sanctions for breaching them, are governed by Article 17 of the ToS (Confidentiality), this DPA and applicable personal data protection law. Internal handling measures and compensation claims are dealt with on the basis set out in Article 10.2 below.
  2. Damages or penalties (if any) are determined on the basis of fault, the seriousness of the breach and the actual damage incurred.
  3. The Parties cooperate to remedy and mitigate damage and to perform compensation obligations (if any) as agreed, in a spirit of cooperation and in accordance with applicable law.

Article 11. Effect and application

  1. This DPA takes effect automatically together with the Agreement, as soon as the Customer signs the Agreement or starts using the Service (whichever comes first), with no separate document required. The DPA is an integral part of the Agreement and remains in force for the term of the Agreement, unless the Parties agree otherwise in writing.
  2. The two Parties undertake to perform their obligations fully and correctly under the terms of this DPA and under the Personal Data Protection Law No. 91/2025/QH15 and the Government's Decree 356/2025/ND-CP signed on 31/12/2025 (“Decree 356”), together with other amending and supplementing instruments, in respect of the Agreements signed by the two Parties, including but not limited to Agreements already signed, currently in force and to be signed in future.
  3. Matters not addressed in this DPA are governed by the Agreement.
  4. 1Office may amend or supplement this DPA with at least 15 days' prior notice to the Customer's registered email, following the same update procedure as the Terms of Service (ToS) set out in Article 1.2 of the ToS. The Customer's continued use of the Service after that notice period is deemed acceptance of the amended DPA.
  5. This DPA is published together with the Agreement and applies uniformly to Customers, with no separately signed document required for each Customer.
Zalo Hotline