Data Controller:

SINTEX Vietnam Trading and Services Company Limited

Address: 58 Street 56, Binh Trung Ward, Ho Chi Minh City, Vietnam

Phone: +84 96 281 0724

Email: info@sintex.com

Working hours: Monday – Friday, 08:00 – 17:00

We respect and are committed to protecting your privacy in accordance with Vietnamese law, including the Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP on personal data protection, together with other related legal provisions. This policy explains how we collect, use, share, store, and protect personal data when you access the website or use our services.

By using the website/services, you confirm that you have read, understood, and agree to this Policy. If you do not agree, please cease accessing or using the services.

1. Scope of Application

The policy applies to:

  • Candidates, job seekers, and individuals submitting their resumes/CVs through our website.
  • Employers, companies, and organizations requesting recruitment, executive search, multilingual recruitment, or HR consulting services.
  • Clients using our business consulting, market research, investment advisory, market entry, company incorporation, legal advisory, licensing, intellectual property registration, training, or other professional services.
  • Participants registering for seminars, workshops, networking events, leadership training programs, or investment promotion activities organized or coordinated by SINTEX.
  • Individuals contacting us through our website, email, telephone, or other communication channels.
  • Visitors accessing or browsing our website.

2. Personal Data We Collect

Depending on the service you use and your consent, we may collect:

2.1. Identification & Contact Information

Full name, gender, date of birth, nationality, photo, phone number, email, contact/residential address.

Company information: company name, job title, business email, phone number, company address, industry, company description, and other business information voluntarily provided.

2.2. Employment & Education Information

Resume/CV, education and work history, certificates, skills, recommendation letters, references, language proficiency, years of experience, desired salary, employment preferences, application history, and other information voluntarily submitted in connection with recruitment services.

2.3. Business & Service Request Information

Information relating to your enquiry or service request, including recruitment requirements, organizational consulting requirements, market research requests, investment consulting enquiries, legal advisory requests, licensing enquiries, intellectual property registration requests, training enquiries, uploaded Job Descriptions (JD), company profiles, and supporting documents.

2.4. Technical Data When Accessing the Website

IP address, browser type, device, cookies, tracking pixels/codes, access logs, visited pages, feature interactions.

2.5. Sensitive Data (only when necessary and with a lawful basis/clear consent)

Processing of sensitive data is carried out only when there is explicit written consent or an equivalent form from the data subject, except where permitted by law pursuant to Article 15 of the Personal Data Protection Law No. 91/2025/QH15.

Sensitive data includes but is not limited to:

  • Health information
  • Religious beliefs, political opinions
  • Racial or ethnic origin
  • Personal and private life information
  • Criminal record information (if any)
  • Other categories of sensitive personal data as defined by applicable law.

Examples of sensitive data we may collect: health information required for specific recruitment or consulting services (if applicable), criminal record information where required by law or requested by the client for a specific position, and other sensitive personal data voluntarily provided by the data subject.

2.6. Third-Party Data You Provide

When you provide information about references/colleagues, you represent that you have obtained their valid consent.

2.7. Email Subscription Management Data

To manage unsubscribe/re-subscribe requests, we may process information such as: email address, email subscription status, request timestamp, confirmation timestamp, request source (website/email), and related technical logs for abuse prevention and complaint handling.

3. Purpose of Data Processing

We process data to:

  • Core service provision: Executive Search & Headhunting, Multilingual Recruitment, Organization & Operations Consulting, Performance Management System Development, Compensation & Benefits Consulting, Labor Relations & Employment Law Compliance Consulting, Management Training & Leadership Development, Market Research & Investment Strategy Consulting, Vietnam Market Entry Strategy Consulting, Business Partner & Supply Chain Matching, Business Delegation & Investment Promotion Program Organization, Business Seminars, Forums & Networking Events, Company Incorporation, Corporate Legal Advisory, Cosmetic, Food Product & Conditional Business Product Registration, Trademark, Copyright & Intellectual Property Registration, Industry-Specific Licensing Services, and other related professional services.
  • Recruitment connection: Share candidate profiles and recruitment requirements with suitable employers and candidates, process CV submissions, review Job Descriptions (JDs), and facilitate recruitment activities.
  • Business consultation: Process consultation requests, provide advisory services, arrange meetings, prepare proposals, and support clients throughout the engagement.
  • Suggestion – experience optimization: Analyze enquiries and website usage to improve our services, website performance, and customer experience.
  • Transaction & support: Respond to enquiries, provide customer support, process consultation requests, and handle complaints or disputes.
  • Verification & compliance: Verify information where necessary (with consent where applicable), comply with legal obligations, and prevent fraud or misuse of our services.
  • Selective marketing: Send information regarding recruitment services, consulting services, leadership training, market insights, seminars, events, newsletters, and promotional offers when you have not opted out.
  • Email preference management: Receive and process unsubscribe/re-subscribe requests, send confirmation emails, and update your email subscription status.

We only process data beyond the above purposes when we have a lawful basis or your additional consent.

4. Cookies and Tracking Technologies

We use cookies, pixel tags and similar technologies to:

  • Remember your browsing preferences, improve your user experience, and retain information entered into website forms (where applicable).
  • Analyze traffic, measure the effectiveness of content/recruitment.
  • Personalize content/job/candidate suggestions.

Cookie Classification:

4.1. Essential Cookies:

Cannot be disabled because they are required for the basic operation, functionality, and security of the website

4.2. Analytical Cookies:

Help us understand how you use the website to improve the user experience.

4.3. Marketing Cookies:

Used to personalize advertising and marketing content in line with your preferences.

Managing Cookies:

  • Disable cookies in your browser settings
  • Use the cookie management tool on our website (if available)
  • Decline non-essential cookies when you first visit the website via the cookie banner

Note: Disabling certain cookies may affect your experience and some features may not function fully.

5. Legal Basis for Data Processing

  • Your consent (e.g., submitting a CV, requesting recruitment or consulting services, receiving marketing communications).
  • Performance of a contract or requested service between you and us.
  • Legal obligations (e.g., complying with applicable laws and lawful requests from competent authorities).
  • Legitimate interests (e.g., website security, fraud prevention, service improvement) — always balanced with your rights.

6. Who We Share Data With

We do not sell personal data. Data may be shared in the following circumstances:

  • Clients and recruitment partners: When you apply for a position, submit your CV, request recruitment services, or consent to being introduced to suitable employers.
  • Service providers acting on our behalf: Website hosting, cloud storage, information technology services, data analytics, marketing, customer support, and other operational service providers (access limited to what is necessary, with appropriate security safeguards).
  • Government agencies/authorities: When a lawful request is received.
  • Corporate transactions: Mergers, acquisitions, restructurings, or business transfers (personal data will continue to be protected at least at an equivalent level).
  • Training and event partners: When you register for a training program, seminar, workshop, networking event, or other activity organized or co-organized by SINTEX.

7. Transfer of Data Abroad

In certain circumstances (e.g., using cloud infrastructure, third-party service providers, or international business partners), data may be transferred and stored outside Vietnam. The transfer of personal data abroad is carried out in compliance with Articles 25 and 26 of the Personal Data Protection Law No. 91/2025/QH15.

Conditions for International Data Transfer:

7.1. Consent of the Data Subject:

Data may be transferred only with your explicit consent or when one of the legal conditions is met.

7.2. Data Protection Level of the Receiving Country:

The receiving country must provide a level of personal data protection that is comparable to or higher than that of Vietnam, as required by law.

7.3. Notification to the Data Subject:

We will inform you when your data is transferred abroad and the protective measures applied.

7.4. Additional Protective Measures:

If data is transferred to a country without an equivalent level of protection, we will implement appropriate safeguards in accordance with the law (e.g., entering into a confidentiality agreement, using standard contractual clauses).

Our Obligations

Pursuant to Articles 24 through 28 of the Personal Data Protection Law No. 91/2025/QH15, as a data controller, we have the following obligations:

1. Implement Measures to Protect Data Subject Rights

We commit to respecting and safeguarding your lawful rights throughout the personal data processing.

2. Establish Mechanisms for Receiving and Handling Data Subject Requests

We have established clear procedures to receive, process, and respond to requests concerning your personal data.

3. Maintain Records of Personal Data Processing Activities

We maintain comprehensive records of personal data processing activities as required by law.

4. Conduct Data Protection Impact Assessments When Necessary

Before undertaking high-risk data processing activities, we conduct impact assessments to identify and mitigate risks.

5. Implement Controls and Supervision of Data Processing Activities

We apply stringent control and monitoring measures to ensure compliance with personal data protection laws.

6. Apply Appropriate Personal Data Protection Measures

We employ suitable technical and organizational measures to protect personal data (encryption, access controls, monitoring, backup, periodic risk assessments, etc.).

8. Retention Period

We retain personal data for as long as necessary to fulfil the purposes described or as required by law. The retention periods for each data category are as follows:

Retention periods by data type:

8.1. Contact and enquiry data:

Retained for up to 5 years after the latest communication or completion of the requested service, unless a different legal requirement applies.

8.2. Application data:

Retained for up to 5 years after the conclusion of the recruitment process, unless a different legal requirement applies.

8.3. Marketing data:

Retained until you opt out of receiving marketing communications.

8.4. Email subscription management data:

Retained the email subscription status and confirmation request history for as long as necessary to operate the service, prevent abuse, handle complaints, and comply with legal obligations.

If there is no legal requirement or dispute/complaint resolution need for a longer retention, this data is retained for a maximum of 5 years from the most recent subscription status update.

When the retention period expires or the purpose/legal basis no longer exists, the data will be permanently deleted or anonymised in accordance with our internal procedures.

9. Your Rights

According to Article 9 of the Personal Data Protection Law 91/2025/QH15, you have the following rights (subject to applicable conditions):

  • Right to be informed about personal data processing activities.
  • Right of access, to obtain a copy of personal data.
  • Right to rectification, to update, supplement inaccurate/incomplete data.
  • Right to withdraw consent (without affecting the lawfulness of processing prior to withdrawal).
  • Right to erasure, restriction of processing, and objection to processing in certain circumstances as provided by law.
  • Right to lodge a complaint or report to the competent authority.
  • Right to data portability: Receive data in a commonly used structured format.
  • Right to object to personal data processing in specific cases.
  • Right to claim compensation for damages resulting from personal data protection violations.

How to exercise your rights:

Contact info@sintex.com with the subject line: “Personal Data Request” and include identity verification information.

For managing marketing email preferences, you may follow the unsubscribe/subscribe link provided in the email (if available).

We will update your email subscription status immediately after successful confirmation or within a reasonable period in accordance with our operational procedures.

Response timeframes:

9.1. Data breach notification:

We will notify you within 72 hours of discovering the incident, pursuant to Article 23 of the Personal Data Protection Law 91/2025/QH15.

9.2. Other data subject requests:

We will respond within 72 hours of receiving a valid request and complete the request within a reasonable period as required by law. For complex requests, processing may take up to 30 days; in such cases we will inform you of any extension.

Complaint handling procedure:

If you wish to lodge a complaint or make a request regarding your personal data, please follow the procedure below:

  1. Submit complaint/request: Email info@sintex.com with the subject line: “Personal Data Complaint” and include:
    • Your full name and contact information
    • A description of your complaint or request
    • Any supporting documentation (if applicable)
    • A copy of identity verification documents
  2. Initial acknowledgment: We will acknowledge receipt of the complaint within 24 hours.
  3. Investigation and response: Our Data Protection Officer will investigate and provide a detailed response within 72 hours.
  4. Resolution: If you are satisfied with our response, the complaint will be closed. If not, you may lodge a complaint with the competent authority.

Complaint to the supervisory authority:

If you are not satisfied with our response or believe your personal data protection rights have been infringed, you have the right to complain to:

Personal Data Protection Supervisory Authority

Contact point: Ministry of Science and Technology

Website: https://mst.gov.vn/

10. Data Security

We apply appropriate technical and organizational measures (encryption, access control, monitoring, backup, periodic risk assessments…). However, no method is absolutely safe on the Internet; please:

  • Protect the personal information you provide to us and be cautious when accessing our website from public devices or unsecured networks.
  • Notify us immediately if you believe your personal data has been accessed, disclosed, or used without your authorization.

Incident handling for data leaks (if any):

We will inform the affected individuals and the competent authorities as required; at the same time we will implement remedial measures and provide guidance to mitigate risk.

11. Individuals Under 16 Years Old

The website/service is not directed at users under 16 years of age. If we inadvertently collect data from a person under 16 without valid parental/guardian consent, we will delete it as soon as possible upon notification.

12. Voluntary/mandatory nature

Some data fields are mandatory for the provision of services (marked when you submit a CV, request recruitment or consulting services, upload a Job Description (JD), register for training or events, subscribe to newsletters, or submit other enquiries through our website). If you refuse to provide them or withdraw consent for core purposes, we may be unable to continue providing the corresponding service.

Personal data processing impact assessment

In accordance with legal provisions, we conduct a Data Protection Impact Assessment (DPIA) before carrying out data processing activities that may pose a high risk to the rights and legitimate interests of data subjects.

When a DPIA is mandatory:

Pursuant to Article 27 of the Personal Data Protection Law No. 91/2025/QH15, a DPIA must be carried out for the following processing activities:

  • Systematic and comprehensive evaluation of personal aspects concerning an individual based on automated processing, including profiling
  • Large-scale processing of special categories of personal data (sensitive data) as defined in Article 15
  • Large-scale processing of data related to criminal offenses and violations of law
  • Systematic monitoring of publicly accessible areas on a large scale
  • Any other processing activity that could result in a high risk to the rights and legitimate interests of the data subject

The impact assessment shall include:

1. Description of the intended data processing activity

Details of the types of data to be processed, the purposes of processing, the scope of processing, and the parties involved.

2. Assessment of necessity and proportionality of the processing

Analysis of whether the data processing is necessary and proportionate to the stated purposes.

3. Risk assessment for the rights and interests of the data subject

Identification of potential risks and the extent of impact on the data subject’s privacy.

4. Risk mitigation measures

Proposed and implemented technical and organisational measures to mitigate the identified risks.

13. Third-Party Links

The website may contain links to third-party websites or services. Their privacy policies will govern the data you provide on those platforms. We encourage you to review the privacy policies of those third-party websites before providing any personal data.

14. Policy Changes

We may update the Policy to reflect changes in the law or operational procedures. The updated version will be posted on the website together with the effective date. Your continued use of the service after the effective date constitutes your acceptance of the changes.

15. Contact

SINTEX Vietnam Trading and Services Company Limited

Address: 58 Street 56, Binh Trung Ward, Ho Chi Minh City, Vietnam

Phone: +84 96 281 0724

Email: info@sintex.com

Working hours: Monday – Friday, 08:00 – 17:00

Competent authority for personal data protection:

If you wish to lodge a complaint regarding personal data protection violations, please contact:

Specialized authority for personal data protection

Contact point: Ministry of Science and Technology

Website: https://mst.gov.vn/