USER PRIVACY POLICY

1. General Terms

PayME Technology Joint Stock Company (hereinafter referred to as "PayME") has established and published this Privacy & Data Protection Policy (hereinafter referred to as "Policy") to uphold its commitments and responsibilities in protecting Users' personal information. This Policy ensures compliance with Decree 13/2023/NĐ-CP and other relevant legal regulations regarding data security and privacy protection when Users access and use PayME’s services.

This Policy informs Users about:

By directly or indirectly providing personal information to PayME, the User acknowledges and agrees that their data will be collected, processed, used, stored, and secured in accordance with this Privacy Policy.

If the User does not agree with this Policy, they should:

The terms used in this Policy are referenced from the User Agreement (PayME Terms and Conditions).

 

2. Definitions

In this Privacy Policy, unless otherwise required by the context, the following terms are defined as follows:

2.1. PayME

PayME Technology Joint Stock Company (PayME) is a legally established and operating enterprise in Vietnam, registered under Business Registration Certificate No. 0310476487, first issued on November 25, 2010.

2.2. PayME Services

PayME Services refer to products and services developed or co-developed by PayME for Users, including but not limited to:

2.3. PayME Account

A PayME Account is an electronic account built on PayME’s technology platform, designed to meet technical requirements and regulations for payment intermediary services.

2.4. User

A User refers to an individual or organization that:

2.5. Personal Data

Personal Data refers to information in the form of symbols, text, numbers, images, audio, or other electronic formats that is linked to a specific individual or helps identify a specific individual. Personal Data includes Basic Personal Data and Sensitive Personal Data.

2.6. Data Subject

A Data Subject is the individual whose Personal Data is being collected and processed.

2.7. Basic Personal Data includes:

a. Full name, middle name, birth name, and any other aliases (if applicable).
b. Date of birth, date of death, or date of disappearance.
c. Gender.
d. Place of birth, registered birthplace, permanent residence, temporary residence, current address, hometown, and contact address.
e. Nationality.
f. Personal photographs.
g. Phone number, National ID number, personal identification number, passport number, driver’s license number, vehicle registration number, tax identification number, social security number, and health insurance card number.
h. Marital status.
i. Family relationships (parents, children, etc.).
j. Bank account information, online activity records, and digital footprint data.
k. Any other information associated with a specific individual that does not fall under the category of Sensitive Personal Data.

2.8. Sensitive Personal Data

Sensitive Personal Data refers to personal information linked to an individual’s privacy, where unauthorized access or misuse could directly affect their legal rights and interests. This includes:

a. Political opinions and religious beliefs.
b. Health status and private medical records (excluding blood type information).
c. Information related to racial or ethnic origin.
d. Inherited or acquired genetic traits.
e. Physical attributes and unique biological characteristics.
f. Sexual life and sexual orientation.
g. Criminal records and law enforcement-collected crime data.
h. Financial data related to banking and payment services, including:

i. Location data obtained via geolocation services.
j. Other personal data classified as sensitive under applicable laws, requiring special security measures.

2.9. Processing of Personal Data

Processing Personal Data refers to any operation performed on personal data, including but not limited to:

2.10. Personal Data Controller

A Personal Data Controller is an organization or individual that determines the purpose and means of processing personal data.

2.11. Personal Data Processor

A Personal Data Processor refers to an organization or individual that processes personal data on behalf of the Personal Data Controller, based on a contract or agreement.

2.12. API (Application Programming Interface)

API, short for Application Programming Interface, is a set of methods and protocols that enable software applications, libraries, and systems to communicate and exchange data with one another. This is done through request-response interactions.

2.13. QR Code (Quick Response Code)

QR Code, short for Quick Response Code, is a type of machine-readable barcode that encodes information into an image format. It allows scanning devices (such as smartphones or dedicated QR scanners) to retrieve, access, connect, or execute commands quickly.

2.14. KYC/eKYC (Know Your Customer / Electronic Know Your Customer)

KYC (Know Your Customer) and eKYC (electronic Know Your Customer) refer to the customer identification, verification, and authentication process.

2.15. OTP (One-Time Password)

OTP, short for One-Time Password, is a randomly generated sequence of characters or numbers that is unique and non-repeatable.

 

3. Scope of Data Collection and Applicability

3.1. Applicability

This Privacy Policy applies to all Users, including:

3.2. Scope of Data Collection

PayME collects, processes, uses, stores, and protects User information provided through the following means:

a. Direct data collection from Users

b. Indirect data collection from legal sources

 

4. Purpose of Information Collection and Scope of Use

4.1. Providing Services and Features

PayME uses the collected information to deliver, personalize, maintain, and enhance its services. This includes:

a. Providing services such as:

b. Storing User information to prevent repeated manual data entry during current and future visits.

c. Automatically updating the PayME App, fixing software bugs, resolving operational issues, analyzing data, conducting tests, and performing research.

4.2. Security and Safety

PayME uses User data to ensure security, safety, and integrity across its services. This includes:

4.3. Customer Support

If a User contacts PayME’s customer support, PayME may collect and use information, including call recordings, after obtaining User consent. The collected information helps:

a. Direct User inquiries to the appropriate support personnel.
b. Investigate and resolve User concerns or complaints.
c. Monitor and enhance the quality of customer support services.

4.4. Research and Development

PayME may use collected data for research, analysis, and product development purposes, such as:

4.5. Communications from PayME

PayME may use collected information to communicate with Users about:

PayME will use the following communication channels:

a. Push notifications through the PayME App.
b. SMS messages or phone calls to the User’s registered phone number.
c. Emails to the User’s registered email address.
d. Announcements and communications posted on:

4.6. Legal Compliance and Regulatory Requirements

PayME may use collected information to:

a. Investigate or resolve complaints and disputes related to the use of PayME Services by Users.
b. Carry out other legal activities permitted under applicable laws.
c. Provide information to competent state authorities or comply with legal requirements.

 

5. Information Collected

5.1. Information Collected When Users Register for a PayME Account

a. For Individual Users (Vietnamese Citizens):

b. For Individual Users (Foreign Nationals):

c. For Organizations:

5.2. Additional Personal Information Collected by PayME

PayME may collect information when Users:

a. Interact with PayME via the hotline, app, website, or official social media accounts.
b. Communicate with other Users via PayME’s services, such as "Money Transfer", "Send Gift Money", or similar services.
c. Participate in surveys through the PayME App.
d. Enable device access permissions, allowing PayME to access contacts, photos, or location.

5.3. Information Generated During PayME Service Usage

a. Account Information Updates

b. Location Data

c. Transaction Information

d. Usage and Preferences

e. Device Information

f. Log Data

g. Messaging Data

h. Contact List Access

5.4. Information from Other Sources

a. PayME may collect User information when they create or access a PayME Account through:

b. Publicly available sources.

c. Marketing and market research service providers.

5.5. Other Information Required for Legal Compliance

PayME may request Users to provide additional information related to their use of PayME services for the following reasons:

a. Ensuring PayME's compliance with legal obligations.

b. Reporting to competent government authorities as required by law.

c. Assessing whether the User has complied, is complying, and can continue to comply with PayME's policies.

 

6. User Rights

6.1. Ownership of Personal Information

Users have full ownership of their personal information.

6.2. Control Over Personal Data

Users have the right to:

6.3. Request for Data Protection Measures

Users have the right to request PayME to implement security measures to protect their information.

6.4. Data Breach Response

Users can request PayME to take appropriate measures if they suspect their personal data has been leaked, lost, or misused, which may cause damage or financial loss.

 

7. Entity Responsible for Data Collection and Management

PAYME TECHNOLOGY JOINT STOCK COMPANY (PayME)

 

8. Data Retention Period

 

9. Data Security and Protection Measures at PayME

9.1. Secure Storage and Protection of User Information

9.2. PayME’s Commitment to User Data Protection

a. With User consent.

b. Upon User request, via:

c. Sharing with third parties, including:

d. As required by law or governmental authorities.

9.3. Access to User Data by PayME and Related Entities

Users acknowledge and agree that PayME may allow certain individuals or organizations to access, process, and use their personal data, specifically:

a. PayME employees, such as:

Operations, technical, HR, customer support, and business development teams performing their job functions.

b. Legal professionals and consultants, such as:

Advisors, lawyers, inspectors, and auditors involved in handling legal or regulatory matters related to the User.

c. Parent company, subsidiaries, and group affiliates

 

10. User Security Recommendations

PayME strongly recommends that Users take proactive measures to protect their PayME Accounts, including:

PayME is not responsible for any data breaches caused by the User’s failure to follow these security recommendations.

11. Special Provisions on the Protection of Users' Personal Data Under Decree 13/2023/NĐ-CP (Issued on April 17, 2023)

11.1. Principles of Personal Data Protection at PayME

PayME adheres to the following principles when processing personal data:

a. Personal data is processed in compliance with legal regulations.

b. Data subjects (Users) have the right to be informed about the processing of their personal data, except where otherwise specified by law.

c. Personal data is processed only for the declared purposes as registered by PayME or third parties.

d. Data collection is appropriate, limited to necessity, and strictly for the intended purposes.

e. Personal data is regularly updated and supplemented in line with the intended processing purposes.

f. Personal data is protected with technical and organizational measures, ensuring security against:

g. Personal data is stored only for the necessary period required for processing, except where a longer retention period is mandated by law.

11.2. Rights and Obligations of Data Subjects (Users) at PayME

a. Rights of Data Subjects

b. Obligations of Data Subjects (Users)

11.3. Protection of Personal Data During Processing at PayME

a. User Consent for Data Processing

By reading and agreeing to this Privacy Policy, and checking the consent box when registering an account and using PayME services, the User has explicitly agreed to data processing under this Policy.

b. Withdrawal of Consent

c. Notification of Data Processing

d. Requesting Personal Data from PayME

By checking the consent box, the User agrees that PayME may share their personal data with third parties, including:

This data sharing is strictly for customer identity verification, account authentication, transaction verification, or other necessary operations related to PayME’s services, in compliance with Decree 13/2023/NĐ-CP.
Users may withdraw this consent at any time following the procedures in this Policy.

e. Modifying Personal Data

By checking the consent box, the User explicitly agrees that PayME has the right to modify, update, or correct personal data when necessary for:

Users may withdraw this consent at any time under the terms of this Policy.

f. Storage, Deletion, and Destruction of Personal Data

1. Users Can Request PayME to Delete Their Personal Data If:

2. PayME May Reject a Data Deletion Request If:

3. Timeline for Deleting Personal Data

4. PayME May Proactively Delete Personal Data If:

g. Other Regulations

1. PayME May Process Personal Data Without User Consent in Certain Situations, Including:

2. Data Processing for Marketing and Branding Purposes

By checking the consent box when registering and using PayME services, the User:

11.4. PayME’s Responsibilities in Personal Data Control and Processing

PayME is committed to ensuring legal compliance and data security in handling Users’ personal data. The company’s responsibilities include:

a. Implementation of Organizational and Technical Security Measures

b. Recording and Storing System Logs

c. Reporting Data Protection Violations

d. Ensuring Users’ Data Protection Rights

e. Accountability for Damages

f. Compliance with Legal Data Protection Measures

 

12. Other Provisions

12.1. Policy Review and Updates

12.2. Validity of Policy Provisions

12.3. Compliance with Government Regulations

12.4. Transfer and Assignment of Rights

12.5. Binding Effect

12.6. Contact Information for Inquiries and Complaints

For any questions, requests, or complaints regarding this Policy or the use of personal data, Users may contact PayME through the following channels:

a. 24/7 Customer Support Hotline: 1900.88.66.65
b. Email: hotro@payme.vn
c. Live Chat: Available via the PayME website.
d. In-Person Support:

12.7. Force Majeure Events

a. Definition of Force Majeure Events

A force majeure event is an event that occurs objectively and unpredictably, despite all reasonable preventive measures being taken. Such events include, but are not limited to:

If a force majeure event prevents either party from fulfilling its obligations:

b. Obligation to Minimize Damage

The affected party must take all reasonable measures to minimize any potential damages caused by the force majeure event.

c. Exemption from Liability

PayME is not liable for any failure to perform obligations under this Agreement due to force majeure events.

12.8. Dispute Resolution

12.9. Governing Law

Payme

Copyright © 2025 PayME Corporate

All rights reserved