Personal Data Protection Policy (hereinafter referred to as the “Policy”) describes how personal data arising in the course of the operations and business of VINMEC INTERNATIONAL GENERAL HOSPITAL JOINT STOCK COMPANY (the “Company”), with its address at 458 Minh Khai, Vinh Tuy Ward, Hanoi City, Vietnam, and official website Vinmec.com, is processed. The Company processes personal data in the capacity of a Personal Data Controller or a Personal Data Controller and Processor in accordance with relevant laws.
Personal data being processed is your data (referred to as the “Data Subject”) when you interact or engage in a relationship with the Company in various capacities, such as a customer, consumer, employee, candidate, partner contact person, shareholder, or any individual whose personal data is collected and processed by the Company. For further details regarding the processing of your personal data, please review the specific content of this Policy corresponding to your role in connection with the Company.
This Policy is issued to ensure that the processing of personal data is carried out transparently, in a controlled manner, and in compliance with legal regulations, and to help the Data Subject understand their rights and the mechanisms for protecting their privacy in their relationship with the Company.
This Policy also serves as the Company's Consumer Information Protection Rules, reflecting the Company's commitment to:
• Respecting the privacy and personal information of the Data Subject;
• Protecting personal information from unauthorized access, use, or disclosure;
• Building a safe, transparent, and trustworthy environment for transactions, daily life, and the experience of products and services.
The Company may update or amend this Policy from time to time to align with legal regulations and its actual operations. The updated version will be published through the Company's official channels.
ARTICLE 1. DEFINITIONS
1.1 “Customer”: includes all individual customers, and representatives/contact persons of institutional customers who have entered into and are performing an agreement with the Company; individuals who are learning about and considering using the Company's products or services; walk-in visitors or participants in events introducing the Company's products or services; participants in community activities; and users of the Company's website, application, and other digital platforms. This definition also includes consumers as defined under the law on protection of consumer rights.
1.2. “Personnel”: means an individual who currently has, or has previously had, an employment relationship with the Company, including but not limited to members of the Board of Management, managers, and employees; candidates, interns, and collaborators.
1.3. “Contact Person”: means an individual who is currently, or has previously been, designated, authorized, or assigned tasks in practice by the Company's Partner to represent the Partner in contacting, exchanging information, transacting, or coordinating work with the Company.
1.4. “Shareholder”: means an individual who owns at least one share of the Company.
1.5. “Insider”: means a person holding an important position in the Company's governance or management apparatus, as determined under the law from time to time.
1.6. “Related Person”: means an individual who has a direct or indirect relationship with the Company, as determined under the law from time to time.
1.7. “Consumer”: means an individual who purchases or uses products, goods, or services for consumption or living purposes of themselves or their family, or for use by an agency or organization for internal purposes and not for commercial purposes.
1.8. “Partner”: means organizations or individuals working with the Company to cooperate, provide products or services, or support the Company's operations. Individual partners include, but are not limited to, individual contractors, consultants, and personnel supplied to the Company by a third party.
1.9. “Personal Data”: means digital data or information in another form that identifies or helps identify a specific individual, comprising Basic Personal Data and Sensitive Personal Data. Once de-identified, Personal Data is no longer considered Personal Data.
1.10. “Basic Personal Data”: means personal data reflecting common personal identity and background elements that are frequently used in transactions and social relationships, falling within the list issued by the Government.
1.11. “Sensitive Personal Data”: means personal data associated with an individual's privacy which, if infringed, will directly affect the lawful rights and interests of an agency, organization, or individual, falling within the list issued by the Government.
1.12. “Data Subject”: means the individual reflected by the Personal Data.
1.13. “Personal Data Processing” or “Processing”: means any activity affecting Personal Data, including one or more of the following activities: collection, analysis, aggregation, encryption, decryption, editing, deletion, destruction, de-identification, provision, disclosure, and transfer of Personal Data, and other activities affecting Personal Data.
1.14. “Personal Data Controller”: means the party that decides the purposes and means of Processing Personal Data.
1.15. “Personal Data Processor”: means the party that carries out the Processing of Personal Data on behalf of the Company on the basis of an agreement with the Company.
1.16. “Applicable Law” means Vietnamese legal instruments (including relevant laws, decrees, circulars, and guiding documents) that govern or relate to the protection of Personal Data and other obligations relating to Personal Data.
1.17. “Personal Data Protection Policy” or “Policy” means the entire content of this policy, comprising 14 sections.
ARTICLE 2. COMMITMENT TO PERSONAL DATA PROTECTION
The Company commits that it does NOT buy or sell Personal Data, and complies with the following principles when Processing Personal Data:
Fully complying with the agreements and instruments entered into with the Data Subject.
Processing Personal Data for specific, clear, and lawful purposes as stated in this Policy and in accordance with Applicable Law.
Always applying, and regularly updating, Personal Data protection measures consistent with Applicable Law, in order to protect Personal Data from incidents, unauthorized access, and/or destruction, loss, or damage.
- Retaining Personal Data appropriately and only to the extent necessary as permitted under Applicable Law.
ARTICLE 3. SCOPE OF APPLICATION
This Policy applies to all Data Subjects of the Company, including:
• Customers.
• The Company's Personnel.
• Contact Persons.
• Shareholders, Insiders, and Related Persons of the Company.
ARTICLE 4. TYPES OF PERSONAL DATA COLLECTED AND PURPOSES OF PROCESSING
4.1. For Customers
4.2. For Personnel, including candidates
4.3. For partner contact persons and individual partners
4.4. For Shareholders, Insiders (including Related Persons)
ARTICLE 5. SHARING AND TRANSFER OF PERSONAL DATA
5.1. General principles
When sharing and transferring Personal Data to a third party, the Company commits to:
• Only sharing Personal Data to the extent necessary and consistent with the purposes of Processing Personal Data stated for each category of Data Subject; and
• Requiring the data recipient to apply appropriate data-protection measures.
5.2. Data Recipients
Depending on the category of Data Subject and the purpose and activity of Processing Personal Data, the Company shares, provides, or transfers Personal Data to the following data recipients:
Data Recipient | Purpose of Sharing |
| Parent company, subsidiaries, and affiliated companies of the Company | Sharing and transferring Personal Data to the extent necessary and consistent with the purposes and activities of Processing Personal Data stated in this Policy. |
| Service providers and operating partners These service providers may include: • Public utility services, and repair, upgrade, and maintenance services; • Information technology services, digital platforms, and management systems (including sales, brokerage, human resources, shareholder, and contract management systems); • Payment and transaction-processing services; • Payroll, tax, insurance, benefits, and other HR-administration services; • Data storage, database management, and operation services; • Recruitment, evaluation, training, and personnel-development services; • Operational support services, and brokerage/sales-system management; • Contract-management services and information exchange with partners; • Legal, financial, audit, corporate-governance consulting, and other professional services. | The Company may share and transfer Personal Data with service providers and partners to carry out Personal Data Processing activities on the Company's behalf. These parties may only Process Personal Data within the scope and for the purposes determined by the Company, and must also comply with the security and information-safety requirements set out in the agreement with the Company and under applicable law. |
| Media and advertising partners | To carry out communication and promotion of products, the Company may coordinate with and share Personal Data with media and advertising partners, provided that: • The sharing is consistent with the processing purposes that have been notified; • Legal regulations on advertising are complied with; • The Data Subject's consent is obtained in cases where the law so requires. The Company does not share Customer contact information with third parties for independent marketing purposes without an appropriate legal basis. |
| Related parties in cases of corporate restructuring, such as division, separation, merger, or consolidation | Where the Company undergoes or is involved in corporate reorganization such as division, separation, merger, or consolidation, Personal Data may be disclosed or transferred as part of that transaction, provided that the data recipient continues to comply with Personal Data protection requirements under the law. |
| Related parties in cases involving compliance with legal obligations and protection of the lawful rights and interests of the Company and the Data Subject, outside of any contract | The Company may provide Personal Data to competent state authorities, legal advisors, or related parties where necessary to: • Comply with legal regulations or lawful requests; • Establish, exercise, or defend the Company's lawful rights and interests; • Prevent, detect, and handle fraud or violations; • Protect the safety, health, rights, and lawful interests of the Data Subject or other individuals/organizations. |
| Entities engaged in research and development of blockchain technology, the metaverse, artificial intelligence, and other automated systems | The Company may provide, share, or transfer Personal Data for the purpose of researching and developing technology products and services, including blockchain technology, the metaverse, artificial intelligence, and other automated systems, provided all relevant legal requirements are fully satisfied. |
| Third parties at the request of, or with the consent of, the Customer | The Company may share Personal Data with a third party in accordance with the clear consent or instruction of the Data Subject. |
The transfer of Personal Data in accordance with this Policy and in compliance with applicable law, whether or not for a fee, does not constitute the buying or selling of Personal Data.
ARTICLE 6. PROCESSING OF PERSONAL DATA IN SCIENCE AND TECHNOLOGY ACTIVITIES
6.1. Transfer of Personal Data to support scientific and technological development
On an appropriate legal basis and in strict compliance with Applicable Law, the Company may transfer Personal Data to its parent company, subsidiaries, affiliated companies, and technology partners for purposes of scientific and technological development and innovation, including:
• Research and development of financial technology (Fintech) products and services;
• Big Data processing;
• Building and operating blockchain technology, metaverse systems, and cloud computing;
• Cybersecurity technology;
• Technologies applying self-learning algorithms, artificial intelligence (AI) systems, and other automated systems.
6.2.Compliance conditions for the transfer and processing of data in a technology environment
All activities involving the transfer and Processing of Personal Data in Big Data, artificial intelligence, blockchain, metaverse, and cloud-computing environments are carried out for their intended purpose, limited to the extent necessary, and in compliance with Applicable Law. The Company only carries out the Processing of Personal Data where the following requirements are satisfied:
• The Processing activity is consistent with the purpose notified to the Data Subject and has an appropriate legal basis. If the law requires the consent of the Data Subject for transfer or Processing to support artificial intelligence or automated systems, the Company will obtain the consent of the Data Subject.
• Continuous monitoring, and periodic inspection and evaluation of cybersecurity and data security.
• Classification by risk level for Processing carried out by artificial intelligence; notifying the Data Subject of automated Processing, explaining the algorithmic principles applied, and allowing the Data Subject to opt out.
• Binding the Data Recipient by a data transfer/processing agreement containing confidentiality obligations, with Processing limited to the scope and purposes determined by the Company.
• Not using or developing systems that use Personal Data in a manner that harms national defense, national security, social order and safety, or infringes upon the lawful rights and interests of others.
ARTICLE 7. DATA RETENTION PERIOD
7.1. The Company only retains the Data Subject's Personal Data for the period necessary to carry out the processing purposes stated in this Personal Data Protection Policy, or as required by relevant law.
7.2. As soon as the purpose of Processing Personal Data has been fulfilled, or there is no further need to use Personal Data for the notified purposes, the Company will promptly delete, destroy, or de-identify the Personal Data, except where the law permits or requires continued retention for a specific period. The Company may need to retain Personal Data even after the contract between the parties has terminated, in order to fulfill obligations under the law and/or requirements of competent state authorities.
7.3. In cases where the law requires the deletion or destruction of Personal Data, the Company will promptly delete or destroy it in accordance with the relevant regulations, and will apply necessary measures to ensure that the Personal Data can no longer be accessed, recovered, or used without authorization.
7.4. The Company is committed to always carrying out the retention, deletion, and destruction of Personal Data carefully, safely, and in accordance with legal regulations, in order to protect the lawful rights and interests of the Data Subject and of the Company.
ARTICLE 8. PERSONAL DATA PROTECTION MEASURES
8.1. To best protect Customer information, the Company has been and continues to apply the following specific measures:
8.1.1. Technical measures to prevent unauthorized access to or use of Personal Data. The Company regularly coordinates with security experts to update the latest cybersecurity techniques to ensure the safety of Personal Data. All new software systems or major updates must undergo a rigorous evaluation and penetration-testing (Pentest) process before being put into actual operation.
8.1.2. Organizational measures such as establishing an internal regulatory framework for Personal Data protection and a risk-management process for third parties; and assigning dedicated personnel and a compliance-monitoring unit. The Company implements periodic and ad-hoc monitoring and inspection of compliance with its security policies in order to promptly detect and address potential risks.
8.1.3. Operational measures such as maintaining periodic and daily data-control processes, and implementing data backup and recovery plans to ensure that data is stored and processed for its intended purpose and within the committed scope. The Company has established a cybersecurity incident-response process and regularly provides security-awareness training to its personnel.
8.1.4. Physical measures such as establishing physical barriers and strict access-control systems for IT infrastructure areas, servers, and data-storage devices, and ensuring the physical safety of equipment and devices in order to prevent any unauthorized access.
8.1.5. In addition, when it is necessary to share Personal Data with a third party for the purposes stated in this Policy, the Company requires the relevant parties to apply appropriate data-protection measures, in order to ensure that Personal Data continues to be processed safely.
However, given the nature of the technology environment and the Internet, no security measure can guarantee absolute safety. Therefore, although the Company always strives to apply appropriate measures, we cannot absolutely guarantee or warrant that your Personal Data will always be safe under all circumstances.
ARTICLE 9. PROTECTION OF THE RIGHTS OF VULNERABLE CONSUMERS
9.1. Where a Customer belongs to a group of vulnerable consumers under Applicable Law, the Processing of that Customer's Personal Data must be carried out carefully, appropriately, and with enhanced protection, in order to ensure the Customer's lawful rights and interests.
9.2. Where necessary to receive and process a Customer's request, the Company may collect relevant information and documents to determine vulnerable-consumer status, on the following basis:
9.2.1. Only collecting to the extent necessary;
9.2.2. Using the data solely for the purpose of receiving and processing the request;
9.2.3. Applying appropriate security measures to the Personal Data arising.
9.2.4. Where the Customer's rights are infringed and the Customer requests protection: the officer receiving the request is responsible for forwarding it to the competent authority for resolving the Customer's complaint in accordance with the Company's regulations in force at the time, ensuring that the Customer is supported, served, and responded to as promptly as possible;
9.2.5. The Company prioritizes the direct receipt and handling of requests from Customers who are vulnerable consumers ahead of requests from ordinary Customers.
9.3. Processing of Personal Data of children and of persons who have lost, or have limited, civil act capacity:
9.3.1. The Company only processes Personal Data to the extent necessary to ensure the lawful rights, interests, and safety of the individuals referred to above, for example:
• Helping children or vulnerable individuals to access and use services and amenities;
• Ensuring security, safety, and a suitable and friendly environment for the provision of products and services;
• Fulfilling necessary obligations under legal regulations.
9.3.2. Where the law requires consent for the Processing of Personal Data, such consent will be given by the legal representative on behalf of the child or the person lacking full civil act capacity, unless otherwise provided by law. For children aged 7 years or older, if the processing of data is intended to publish or disclose information about their private life or personal secrets, the Company will only proceed with the consent of both the child and the legal representative.
9.3.3. Where the Company refuses to resolve a Customer's request, the Company will respond to the Customer in writing, clearly stating the legal grounds and the reasons why the Customer's request is not appropriate.
ARTICLE 10. RIGHTS AND OBLIGATIONS OF THE DATA SUBJECT
10.1. The Data Subject has the following rights in relation to their Personal Data:
10.1.1. To be informed of the Processing of Personal Data.
10.1.2. Providing or withholding consent, or requesting the withdrawal of consent for Personal Data Processing.
10.1.3. To view, edit, or request correction of Personal Data.
10.1.4. To request the provision, deletion, or restriction of Processing of Personal Data; and to send an objection to the Processing of Personal Data.
10.1.5. To lodge complaints or denunciations, initiate lawsuits, and claim damages in accordance with the law.
10.1.6. To request the implementation of measures and solutions to protect their Personal Data in accordance with the law.
10.2. The Data Subject may exercise their rights in relation to their Personal Data by sending a request to the Personal Data Protection Department using the contact information provided in the relevant section, either directly in writing, by email, or through other electronic means.
10.3. Any request to exercise the Data Subject's rights must clearly state at least the following:
10.3.1. Information of the Data Subject (full name, email, or phone number).
10.3.2. The specific right the Data Subject wishes to exercise and the type of Personal Data relevant to the request.
10.3.3. The reason and purpose of exercising the right (if any); and
10.3.4. Information and documents relating to the exercise of the Data Subject's right.
10.4. After receiving a request, we will verify the identity of the requester and the validity, completeness, and accuracy of the request in accordance with the law, and will assess whether the request can be fulfilled. We reserve the right to request additional information for verification purposes, or to refuse to process the request if:
10.4.1. The Data Subject does not provide sufficient information to verify their identity and the validity of the request; or
10.4.2. Legal regulations do not permit the Company to fulfill the Data Subject's request; or
10.4.3. There is a specific request from a competent state authority.
10.5. Please note that the rights set out above are not absolute and may be limited by certain legal regulations, exceptions, and other requirements and principles under the law. In specific cases, the Company may be entitled to refuse or restrict the exercise of these rights in accordance with applicable law.
ARTICLE 11. AMENDMENTS AND UPDATES
11.1. This Policy may be updated, amended, supplemented, or replaced by the Company from time to time, provided that such update, amendment, supplement, or replacement does not conflict with Applicable Law and/or is intended to better protect the Data Subject's information.
11.2. Any updated, amended, supplemented, or replaced content of this Policy (if any) will be publicly posted by the Company in accordance with Applicable Law in force at the relevant time. The Data Subject should regularly access and check the website in order to stay informed of the latest changes.
ARTICLE 12. INFORMATION OF THE DEPARTMENT IN CHARGE OF PERSONAL DATA PROTECTION
If you have any questions regarding the Company's Personal Data protection activities, please contact the Personal Data Protection Department using the information below.
Company: Vinmec International General Hospital Joint Stock Company
Head Office: No. 458 Minh Khai, Vinh Tuy Ward, Hanoi
Email: info@vinmec.com
ARTICLE 13. NOTICE
This Policy is deemed to be the notice provided prior to the Processing of Personal Data by the Company. Accordingly, the Company, and any organizations or individuals involved in the Processing of Personal Data, are not required to provide a further notice prior to Processing Personal Data.
ARTICLE 14. EFFECTIVENESS
This Personal Data Protection Policy takes effect from September 3, 2026, and replaces the Personal Data Protection Policy issued on December 18, 2025. It simultaneously serves as the Privacy Policy referenced in any publication of Vinmec, and as the Consumer Rights Protection Policy required by law.
To arrange an appointment, please call HOTLINE or make your reservation directly HERE. You may also download the MyVinmec app to schedule appointments faster and manage your reservations more conveniently.