PRIVACY POLICY OF VINMEC INTERNATIONAL GENERAL JOINT STOCK COMPANY

PRIVACY POLICY OF VINMEC INTERNATIONAL GENERAL JOINT STOCK COMPANY

I. General Principles

  1. This Privacy Policy describes how Vinmec International General Joint Stock Company (“Vinmec”) collects, receives, compiles, stores, uses, processes, discloses, shares and keeps confidential the Customer Information of relevant organizations and individuals (“Customer” or “you”), including cusstomers, agents, suppliers, contractors and partners who: (i) use services provided directly at medical facilities of Vinmec or other services provided by Vinmec and Vingroup; (ii) access and use customer interaction channels owned by Vinmec, including but not limited to www.vinmec.com website, My Vinmec application, other websites and groups on social network (such as Facebook, etc.) (“Vinmec Channel”) (“together, “Services”).
  2. “Customer Information” means any information, data that can be used to identify the Customer or upon which the Customer is identified, such as name, nationality, telephone number, payment card and bank details, personal preferences, email address, location, photo, ID card/citizen identity card, date of birth, marital status, insurance information, transactional information, access history, customer journey, health/medical records, biometric data.
  3. Privacy Policy. Vinmec will post the amended, supplemented and/or updated Privacy Policy on www.vinmec.com website. The Customer’s continued use, access to any Vinmec Channel, continued use of the Services constitutes the Customer’s consent to the content of that amended, supplemented, and/or updated Privacy Policy.
  4. Privacy Policy is made bilingual in Vietnamese and English, in the event of any discrepancy between Vietnamese version and English version, the Vietnamese version shall prevail.
  5. Privacy Policy includes the following contents:

5.1. Customer Information We Collect

5.2. How We Secure Customer Information
5.3. How We Use Customer Information
5.4. How We Share Customer Information
5.5. Access and Choice
5.6.Contacts, Notices, and Revisions
5.7. Additional Information for the EU

II. Customer Information We Collect

We collect your personal information in the course of providing Services to you
Here are the types of information we gather:
1.Information You Give Us:
a) We collect any information you provide in relation to Services during the course of (i) use of Services or participate in science research projects and/or clinical trial projects carried out by Vinmec; (ii) account registration, logging in, interaction with Vinmec Channel; (iii) participation in seminars, customer events, contests, games, surveys or other events organized by Vinmec; (iv) use of biometric functions for individual identification and transaction authentication, etc.
b) The Customer is responsible for ensuring that the information provided by the Customer is complete, accurate and up-to-date to ensure the interests of the Customer in accordance with the use of the corresponding service. Vinmec will not be held responsible in case the Customer provides inaccurate or incomplete information pursuant to the relevant terms of Services.
c) For Customers under the age of 18, please ensure to obtain full consent and approval of your parent or legal representative to provide the Customer Information to Vinmec, who shall be bound by this Privacy Policy and are responsible for the behavior of the Customers. Vinmec reserves the right to refuse the Customers’ access to the Vinmec Channel or provide related Services if there is evidence that the Customers whose age is under 18 has not obtained the above consent and approval from his/her parent or legal representative.
d) In the event that the Customer provides the information of a third party, the Customer represents and warrants that the Customer has fully obtained such third party’s consent and approval for the Customer to provide information to Vinmec and for Vinmec to use such information, which will be subject to the terms and conditions in this Privacy Policy. Vinmec shall not be liable to such third party in the event of Customer failing to provide information with such third party’s consent and approval. In such case, the Customer shall solely be liable for any consequences arisen from his/her violation including but not limited to settling, at his/her own cost, any claim or action made by such third party against the Customer and/or Vinmec and indemnifying Vinmec for any amount made by Vinmec, if any, to such third party in relation to such claim or action.
2. Automatic Information: We automatically collect certain types of information when you interact with Services. Vinmec reserves the right to collect information, data related to the activities performed by the Customer within the Services, including but not limited to information, data about service and good providers for the Customer, information of transactions performed by the Customer (type of goods, service, location, time of transaction), payment method (excluding important data of payment cards which includes detailed card number, CVV number and other verification numbers with the same legal validity), device information (such as IP address, operating system, browser type, hardware specifications, UDIDs, MEIDs, location, address of referring website (if any), pages visited by the Customer from Vinmec Channel and mobile applications, number of visits, responses, file’s name, versions and advertising identities and other relevant information (if any)).
3. Collection and use of cookies a) We use cookies, pixels, and other similar technologies (collectively, “cookies”) to recognize your browser or device, learn more about your interests, provide you with essential features and services, and for other additional purposes, including: b) Recognizing you when you sign in use Services. This allows us to provide you with recommendations, display personalized content, and provide other customized features and services. c) Keeping track of your specified preferences. This allows us to honor your likes and dislikes, such as your language and configuration preferences. d) Conducting research and analysis to improve Services. e) Preventing fraudulent activity. f) Improving security. g) Delivering content, including ads, relevant to your interests on our sites and third-party sites. h) Measure and analyze the performance of Services. i) Cookies allow you to take advantage of some of our essential features. For instance, if you block or otherwise reject our cookies, you might not be able to use certain offerings that require you to sign in, or you might have to manually adjust some preferences or language settings every time you visit our sites. j) Approved third parties may also set cookies when you interact with Services. Third parties usuaully include search engines, providers of measurement and analytics services, social media networks, and advertising companies. Third parties use cookies in the process of delivering content, including ads relevant to your interests, to measure the effectiveness of their ads, and to perform services on our behalf. k) You can manage browser cookies through your browser settings. The ‘Help’ feature on most browsers will tell you how to prevent your browser from accepting new cookies, how to have the browser notify you when you receive a new cookie, how to disable cookies, and when cookies will expire. If you disable all cookies on your browser, neither we nor third parties will transfer cookies to your browser. If you do this, however, you may have to manually adjust some preferences every time you visit a site and some features and services may not work.
4. Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources.

III. How We Secure Customer Information

  1. At Vinmec, security is our highest priority. We design our systems with your security and privacy in mind. All Customer Information is stored and kept confidential by Vinmec’s system or service provider for Vinmec in accordance with the law and this Vinmec Privacy Policy.
  2. When collecting data, Vinmec will exert its best endeavours to the permitted extent to store and secure Customer Information at a server system and these information is secured by firewalls, access control measure and data encryption. We employ appropriate technical and security measures to prevent as much as possible to the permitted extent unauthorized access and use of Customer Information. Vinmec also regularly cooperates with security experts to be updated with the latest information on network security to ensure the safety of Customer Information.
  3. The information of your payment card issued by the relevant financial institution is protected by us in accordance with international standards on the principle that no important data of the payment card (card numbers, full names, CVV number or other verification numbers with the same legal) is recorded in our system. Your payment transaction is made by the relevant bank system.
  4. The Customer may not use any tools, programs or methods to illegally interfere with the system or alter the data structure of any Services, nor carry out any other activities to spread, promote activities with purpose of intervening, sabotaging or infiltrating Vinmec system’s data, as well as activities violating Vietnamese laws. In case we detect a violation, we reserve the right to transfer information about the violation to the competent authorities in accordance with the laws.
  5. You are responsible for protecting your account information and shall not provide any information related to your account, password or authentication methods (eg., OTP) accessed on websites, applications, software, and other tools (if any).
  6. We store Customer Information to ensure that you are able to use the Services continuously, and store it for as long as necessary to fulfill the Purpose, or as otherwise required by law (including for tax and accounting purposes), or to perform other work as notified to you in advance. The period we store specific Customer Information varies depending on the Purpose or as required by laws. When the Customer Information is no longer needed for the provision of the Services or Purpose or Vinmec no longer has a business or legal purpose to retain Customer Information, we will take steps to prevent the access to or use of Customer Information for any purpose other than to comply with this Privacy Policy, or for the security, confidentiality, fraud detection and prevention purposes; or removing identifiable information of Customer Information in accordance with applicable laws.
  7. Customer Information may be stored in, accessed from or transmitted to many countries, including Vietnam. When we transfer your Customer Information to other countries, we will ensure that such information is transferred in accordance with this Privacy Policy and is permitted under the relevant laws and regulations.

IV. How We Use Personal Information

We use your personal information to operate, provide, and improve Services for the purposes (“Purposes”) include:

1.Provide Services: We use your Customer Information
a) to provide Services and process transactions related to Services, including registrations, subscriptions, and payments;
b) to recommend Services that might be of interest to you, identify your preferences, and personalize your experience with Services;
c) to perform internal operations necessary to provide services, including troubleshooting software failures and operational issues, conducting data analysis, testing and diagnosis, monitoring and analyzing the usage trends and activities;
d)to protect the security or integrity of the Service and any facilities or equipment used to provide the Services;
e) to confirm transactions and process payments; (vi) to create, administer and update the Customer’s accounts, verify the Customer’s identity;
f) to create, administer and update the Customer’s accounts, verify the Customer’s identity;
g) To enable interactions between Customers and Vinmec or between Customers and associated partners (if any); and
2. Measure, Support, and Improve Services: We use your Customer Information to measure use of, analyze performance of, fix errors in, provide support for, improve, and develop Services.
3. Comply with Legal Obligations: We have a legal obligation to collect, use or store your Customer Information in certain circumstances, including when required, when consulted, recommended or required by legal advisors or any legal provisions, bylaws, documents or requests of the government or local or foreign authorities, at the request of competent authorities, including without limitation to the obligation to disclose information and reports in accordance with the law on sales promotion, record keeping, audit, investigation and settlement of complaints or disputes, and compliance with court order or legal requirements, documents or requests of the government or other regulations; enforcing other agreements; and protect our rights or property in the event of a complaint or dispute.
4. Communicate with You: We use your Customer Information to communicate with you in relation to Services via different channels (e.g., email, chat) and to respond to your requests.
5. Marketing: We use your Customer Information to market and promote Services. We might display interest-based ads for Services.
6. Fraud and Abuse Prevention and Credit and Property Risks: We use your Customer Information to prevent and detect fraud and abuse in order to protect the security of our customers, us, and others. We may also use scoring methods to assess and manage credit and property risks.

7. Purposes for Which We Seek Your Consent: We may also ask for your consent to use your Customer Information for a specific purpose that we communicate to you.

V. How We Share Customer Information

Information about our customers is an important part of our operation and we are not in the business of selling our customers’ Customer Information to others. We share Customer Information only as described below and as permitted by law. All of the third parties who receive Customer Information in accordance with this Privacy Policy are subject to this Privacy Policy, other similar policies and other relevant laws.

  1. Complying at the request of the competent state authority, or as required by laws;
  2. Transactions Involving Third Parties: We make available to you services, software, and content provided by third parties for use on or through Services. You can tell when a third party is involved in your transactions, and we share information related to those transactions with that third party.
  3. Third-Party Service Providers: We employ and/or cooperate with other companies and individuals to perform certain functions on our behalf. Examples include: sending communications, processing payments, assessing credit and compliance risks, analyzing data, providing marketing and sales assistance (including advertising and event management), conducting customer relationship management, and providing training. These third party service providers have access to Customer Information needed to perform their functions, but may not use it for other purposes. Further, they must adhere to this Privacy Policy and the applicable data protection law.
  4. Restructuring, Business Transfers: As we continue to develop our business, we might restructure, sell or buy businesses or services in accordance with the laws. In such transactions, Customer Information, database and right to use information generally are amongst the transferred business assets but the transferee remains subject to the Privacy Policy (or the individual consents otherwise). Also, in the event that Vinmec or substantially all of its assets are acquired, your information will be one of the transferred assets.
  5. Protection of Us and Others: We release account and other Customer Information when we believe release is appropriate to comply with the law, enforce or apply our terms and other agreements, or protect the rights, property, or security of us, our customers, or others. This includes exchanging information with other companies and organizations for fraud prevention and detection and credit risk reduction.
  6. At Your Option: Other than as set out above, you will receive notice when Customer Information about you might be shared with third parties, and your choice on sharing the information.
  7. Sharing Without Your Consent: As per prevailing laws, your Customer Information as part of your medical information, subject to permission by the head of the medical examination and treatment facility, might be shared among practitioners of a group directly providing treatment to patients for quality improvement of diagnosis, care and treatment of patients; or to certain persons including apprentices, researchers, practitioners in the medical facility who are allowed to borrow the medical records for reading on site or copying for research or technical and professional matters; or as required by Vietnamese competent authorities.

VI. Access and Choice

  1. Unless otherwise provided by laws, you can view, update, and delete certain information about your account and your interactions with Services. If you cannot access or update your information yourself, you can always contact us for assistance.
  2. You have choices about the collection and use of your Customer Information. Many of Services include settings that provide you with options as to how your information is being used. You can choose not to provide certain information, but then you might not be able to take advantage of some of Services.

a) Account Information: If you want to add, update, or delete information related to your account, please follow Vinmec’s instructions from time to time. When you update or delete any information, we usually keep a copy of the prior version for our records for technical purpose.

b) Communications: If you do not want to receive promotional messages from us, please unsubscribe or adjust your communication preferences please follow Vinmec’s instructions from time to time. If you do not want to receive in-app notifications from us, please adjust your notification settings in the app or your device.
c) Advertising: If you don’t want to see interest-based ads, please follow Vinmec’s instructions from time to time.

d) Browser and Devices: The Help feature on most browsers and devices will tell you how to prevent your browser or device from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether.

VII. Contacts, Notices, and Revisions

Our business changes constantly, and our Privacy Policy may also change. You should check our website frequently to see recent changes. Unless stated otherwise, our current Privacy Policy applies to all Customer Information we have about you and your account. If you have any concern about privacy at Vinmec or want to contact one of our data controllers, please contact us and we will try to resolve it. You may also contact us at the address below: info@vinmec.com.

VIII. Additional Information for the EU

We provide additional information about the privacy, collection, and use of Customer Information of prospective and current customers of Services located in the European Economic Area.
1.Controller of Customer Information. Vinmec International General Joint Stock Company (at No. 458, Minh Khai street, Vinh Tuy ward, Hai Ba Trung district, Hanoi, Vietnam) is the controller of the Customer Information collected or processed under this Privacy Policy.
2. Processing. We process your Customer Information on one or more of the following legal bases:
a) as necessary to enter into a contract with you or a legal entity you represent, to perform our contractual obligations, to provide Services, to respond to requests from you, or to provide customer support;
b) where we have a legitimate interest, as described in Section 2 of this Privacy Policy;
c) as necessary to comply with relevant law and legal obligations;
d) respond to lawful requests and orders; or
e) with your consent.
3. Your Rights. Subject to applicable law, you have the right to:
a) ask whether we hold Customer Information about you and request copies of such Customer Information and information about how it is processed;
b) request that inaccurate Customer Information be corrected;
c) request removal of Customer Information that is no longer necessary for the purposes underlying the processing, processed based on withdrawn consent, or processed in non-compliance with applicable legal requirements;
d) request us to restrict the processing of Customer Information where the processing is inappropriate;
e) object to the processing of personal data;
f) request portability of Customer Information that you have provided to us (which does not include information derived from the collected information), where the processing of such Customer Information is based on consent or a contract with you and is carried out by automated means; and
g) lodge a complaint with the supervisory authority if you believe that we violate your privacy rights. You can exercise your rights of access, rectification, erasure, restriction, objection, and data portability by contacting us. If you wish to do any of these things and you are our customer, please contact us. If you are not our customer, please contact us at the address under Section V above. When you consent to our processing your Customer Information for a specified purpose, you may withdraw your consent at any time, and we will stop any further processing of your data for that purpose.
4. Transfers outside of the EU. When we transfer your Customer Information collected and stored within the EU to outside the EU we do so in accordance with the terms of this Privacy Policy and applicable data protection law. This may include the transfer of data pursuant to data transfer agreements that incorporate the Standard Contractual Clauses approved by the EU Commission.

APPENDIX 1 – CUSTOMER INFORMATION TO BE COLLECTED IN THE COURSE OF USE OF MYVINMEC APPLICATION

(attached to the Privacy Policy of Vinmec International General Hospital Joint Stock Company)

When Customer use MyVinmec application, we collect Customer Information including the following information and other information to be collected as per this Privacy Policy:

  1. Information you give us: when Customer creates and administers your account, we will ask you to provideinformation including: the name, age, email address, date of birth, permanent and contact address, phone number and other similar contact information; usernames, aliases, roles, and other authentication and security credential information; information relating identity, including government-issued identification information, nationality;..
  2. Informationabout the visits, vaccination history, examination and test results (including Covid-19 test results) which are supplied by Vinmec facilities. This information will be used by us to suggest services that Customer may be interested in, identify your preferences and personalize your experience with MyVinmec application (“Application”).
  1. Information we receive from Customer use of our Application, including:

Information about Application usage behavior: the content Customer viewed or searched for, page response times, and page interaction information (such as scrolling, clicks) to perform internal operations necessary to provide services, including troubleshooting software failures and operational issues, optimize the experience during use, conducting data analysis, testing and diagnosis;