Skip to content
Corpshore Vietnam

Legal

Data processing agreement

Effective

This data processing agreement (DPA) sets out the terms on which Corpshore Vietnam processes personal data on behalf of a client (the controller) when providing services. It forms part of the services agreement between the parties and reflects the requirements of Vietnam's PDPD and, where applicable, the GDPR.

Roles of the parties

For personal data processed in the course of the services, the client is the controller and Corpshore Vietnam is the processor, acting only on the client's documented instructions. Where Corpshore Vietnam determines the purposes and means of processing, for example for its own business administration, it acts as an independent controller under its privacy policy.

Scope and purpose of processing

Corpshore Vietnam processes personal data only to provide the agreed services and as instructed by the controller. The subject matter, duration, nature and purpose of processing, the categories of data subjects and the types of personal data are set out in the applicable order or statement of work, which forms part of this agreement.

Processor obligations

Corpshore Vietnam will process personal data only on documented instructions, ensure persons authorized to process it are bound by confidentiality, implement appropriate technical and organizational security measures, assist the controller with data subject requests and with its own compliance obligations, and make available the information needed to demonstrate compliance.

Subprocessing

The controller authorizes Corpshore Vietnam to engage subprocessors, including other Corpshore group entities and infrastructure providers, subject to written terms imposing data protection obligations equivalent to those in this agreement. Corpshore Vietnam will inform the controller of intended changes to subprocessors and give the controller the opportunity to object on reasonable data protection grounds.

Cross-border transfer

Where processing involves transfer of personal data across borders, including transfers of Vietnamese personal data subject to PDPD or transfers subject to the GDPR, the parties will put in place the assessments and transfer mechanisms the applicable law requires, such as a PDPD transfer impact assessment or GDPR standard contractual clauses.

Security

Corpshore Vietnam maintains a security program including encryption in transit and at rest, access control under least privilege with multi-factor authentication, network and endpoint protection, logging and monitoring, personnel security and training, and a documented incident response capability, reviewed and updated as risks evolve.

Personal data breach

Corpshore Vietnam will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, provide the information reasonably available to support the controller's obligations, and cooperate in investigation, mitigation and notification.

Audit

Corpshore Vietnam will make available information necessary to demonstrate compliance and, on reasonable notice and subject to confidentiality, allow for and contribute to audits by the controller or a mandated auditor, which may be satisfied by up-to-date certifications and reports where available.

Return and deletion

On termination of the services, Corpshore Vietnam will, at the controller's choice, return or delete the personal data it processes on the controller's behalf, and delete existing copies, unless retention is required by law.

Execution

This DPA is a template that is executed as part of a signed services agreement. The definitive terms, including the processing details and the signatories, are set out in that agreement.