I. General Principles
2. “Customer Information” means any information, data that can be used to identify the Customer or upon which the Customer is identified, such as name, nationality, telephone number, payment card and bank details, personal preferences, email address, location, photo, ID card/citizen identity card, date of birth, marital status, insurance information, transactional information, access history, customer journey, health/medical records, biometric data.
5.1. Customer Information We Collect
5.2. How We Secure Customer Information
5.3. How We Use Customer Information
5.4. How We Share Customer Information
5.5. Access and Choice
5.6.Contacts, Notices, and Revisions
5.7. Additional Information for the EU
5.8. Appendix 1 – Customer information to be collected in the course of use of Myvinmec application
II. Customer Information We Collect
We collect your personal information in the course of providing Services to you
Here are the types of information we gather:
1.Information You Give Us:
a) We collect any information you provide in relation to Services during the course of (i) use of Services or participate in science research projects and/or clinical trial projects carried out by Vinmec; (ii) account registration, logging in, interaction with Vinmec Channel; (iii) participation in seminars, customer events, contests, games, surveys or other events organized by Vinmec; (iv) use of biometric functions for individual identification and transaction authentication, etc.
b) The Customer is responsible for ensuring that the information provided by the Customer is complete, accurate and up-to-date to ensure the interests of the Customer in accordance with the use of the corresponding service. Vinmec will not be held responsible in case the Customer provides inaccurate or incomplete information pursuant to the relevant terms of Services.
2. Automatic Information: We automatically collect certain types of information when you interact with Services.
Vinmec reserves the right to collect information, data related to the activities performed by the Customer within the Services, including but not limited to information, data about service and good providers for the Customer, information of transactions performed by the Customer (type of goods, service, location, time of transaction), payment method (excluding important data of payment cards which includes detailed card number, CVV number and other verification numbers with the same legal validity), device information (such as IP address, operating system, browser type, hardware specifications, UDIDs, MEIDs, location, address of referring website (if any), pages visited by the Customer from Vinmec Channel and mobile applications, number of visits, responses, file’s name, versions and advertising identities and other relevant information (if any)).
b) Recognizing you when you sign in use Services. This allows us to provide you with recommendations, display personalized content, and provide other customized features and services.
c) Keeping track of your specified preferences. This allows us to honor your likes and dislikes, such as your language and configuration preferences.
d) Conducting research and analysis to improve Services.
e) Preventing fraudulent activity.
f) Improving security.
g) Delivering content, including ads, relevant to your interests on our sites and third-party sites.
h) Measure and analyze the performance of Services.
i) Cookies allow you to take advantage of some of our essential features. For instance, if you block or otherwise reject our cookies, you might not be able to use certain offerings that require you to sign in, or you might have to manually adjust some preferences or language settings every time you visit our sites.
k) You can manage browser cookies through your browser settings. The 'Help' feature on most browsers will tell you how to prevent your browser from accepting new cookies, how to have the browser notify you when you receive a new cookie, how to disable cookies, and when cookies will expire. If you disable all cookies on your browser, neither we nor third parties will transfer cookies to your browser. If you do this, however, you may have to manually adjust some preferences every time you visit a site and some features and services may not work.
4. Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources.
III. How We Secure Customer Information
2. When collecting data, Vinmec will exert its best endeavours to the permitted extent to store and secure Customer Information at a server system and these information is secured by firewalls, access control measure and data encryption. We employ appropriate technical and security measures to prevent as much as possible to the permitted extent unauthorized access and use of Customer Information. Vinmec also regularly cooperates with security experts to be updated with the latest information on network security to ensure the safety of Customer Information.
3. The information of your payment card issued by the relevant financial institution is protected by us in accordance with international standards on the principle that no important data of the payment card (card numbers, full names, CVV number or other verification numbers with the same legal) is recorded in our system. Your payment transaction is made by the relevant bank system.
4. The Customer may not use any tools, programs or methods to illegally interfere with the system or alter the data structure of any Services, nor carry out any other activities to spread, promote activities with purpose of intervening, sabotaging or infiltrating Vinmec system’s data, as well as activities violating Vietnamese laws. In case we detect a violation, we reserve the right to transfer information about the violation to the competent authorities in accordance with the laws.
5. You are responsible for protecting your account information and shall not provide any information related to your account, password or authentication methods (eg., OTP) accessed on websites, applications, software, and other tools (if any).
IV. How We Use Personal Information
We use your personal information to operate, provide, and improve Services for the purposes (“Purposes”) include:
1.Provide Services: We use your Customer Information
a) to provide Services and process transactions related to Services, including registrations, subscriptions, and payments;
b) to recommend Services that might be of interest to you, identify your preferences, and personalize your experience with Services;
c) to perform internal operations necessary to provide services, including troubleshooting software failures and operational issues, conducting data analysis, testing and diagnosis, monitoring and analyzing the usage trends and activities;
d)to protect the security or integrity of the Service and any facilities or equipment used to provide the Services;
e) to confirm transactions and process payments; (vi) to create, administer and update the Customer’s accounts, verify the Customer’s identity;
f) to create, administer and update the Customer’s accounts, verify the Customer’s identity;
g) To enable interactions between Customers and Vinmec or between Customers and associated partners (if any); and
2. Measure, Support, and Improve Services: We use your Customer Information to measure use of, analyze performance of, fix errors in, provide support for, improve, and develop Services.
3. Comply with Legal Obligations: We have a legal obligation to collect, use or store your Customer Information in certain circumstances, including when required, when consulted, recommended or required by legal advisors or any legal provisions, bylaws, documents or requests of the government or local or foreign authorities, at the request of competent authorities, including without limitation to the obligation to disclose information and reports in accordance with the law on sales promotion, record keeping, audit, investigation and settlement of complaints or disputes, and compliance with court order or legal requirements, documents or requests of the government or other regulations; enforcing other agreements; and protect our rights or property in the event of a complaint or dispute.
4. Communicate with You: We use your Customer Information to communicate with you in relation to Services via different channels (e.g., email, chat) and to respond to your requests.
5. Marketing: We use your Customer Information to market and promote Services. We might display interest-based ads for Services.
6. Fraud and Abuse Prevention and Credit and Property Risks: We use your Customer Information to prevent and detect fraud and abuse in order to protect the security of our customers, us, and others. We may also use scoring methods to assess and manage credit and property risks.
7. Purposes for Which We Seek Your Consent: We may also ask for your consent to use your Customer Information for a specific purpose that we communicate to you.
V. How We Share Customer Information
1. Complying at the request of the competent state authority, or as required by laws;
2. Transactions Involving Third Parties: We make available to you services, software, and content provided by third parties for use on or through Services. You can tell when a third party is involved in your transactions, and we share information related to those transactions with that third party.
5. Protection of Us and Others: We release account and other Customer Information when we believe release is appropriate to comply with the law, enforce or apply our terms and other agreements, or protect the rights, property, or security of us, our customers, or others. This includes exchanging information with other companies and organizations for fraud prevention and detection and credit risk reduction.
6. At Your Option: Other than as set out above, you will receive notice when Customer Information about you might be shared with third parties, and your choice on sharing the information.
7. Sharing Without Your Consent: As per prevailing laws, your Customer Information as part of your medical information, subject to permission by the head of the medical examination and treatment facility, might be shared among practitioners of a group directly providing treatment to patients for quality improvement of diagnosis, care and treatment of patients; or to certain persons including apprentices, researchers, practitioners in the medical facility who are allowed to borrow the medical records for reading on site or copying for research or technical and professional matters; or as required by Vietnamese competent authorities.
VI. Access and Choice
1. Unless otherwise provided by laws, you can view, update, and delete certain information about your account and your interactions with Services. If you cannot access or update your information yourself, you can always contact us for assistance.
2. You have choices about the collection and use of your Customer Information. Many of Services include settings that provide you with options as to how your information is being used. You can choose not to provide certain information, but then you might not be able to take advantage of some of Services.
a) Account Information: If you want to add, update, or delete information related to your account, please follow Vinmec’s instructions from time to time. When you update or delete any information, we usually keep a copy of the prior version for our records for technical purpose.
b) Communications: If you do not want to receive promotional messages from us, please unsubscribe or adjust your communication preferences please follow Vinmec’s instructions from time to time. If you do not want to receive in-app notifications from us, please adjust your notification settings in the app or your device.
c) Advertising: If you don’t want to see interest-based ads, please follow Vinmec’s instructions from time to time.
d) Browser and Devices: The Help feature on most browsers and devices will tell you how to prevent your browser or device from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether.
VII. Contacts, Notices, and Revisions
If you have any concern about privacy at Vinmec or want to contact one of our data controllers, please contact us and we will try to resolve it. You may also contact us at the address below: firstname.lastname@example.org.
VIII. Additional Information for the EU
We provide additional information about the privacy, collection, and use of Customer Information of prospective and current customers of Services located in the European Economic Area.
2. Processing. We process your Customer Information on one or more of the following legal bases:
a) as necessary to enter into a contract with you or a legal entity you represent, to perform our contractual obligations, to provide Services, to respond to requests from you, or to provide customer support;
c) as necessary to comply with relevant law and legal obligations;
d) respond to lawful requests and orders; or
e) with your consent.
3. Your Rights. Subject to applicable law, you have the right to:
a) ask whether we hold Customer Information about you and request copies of such Customer Information and information about how it is processed;
b) request that inaccurate Customer Information be corrected;
c) request removal of Customer Information that is no longer necessary for the purposes underlying the processing, processed based on withdrawn consent, or processed in non-compliance with applicable legal requirements;
d) request us to restrict the processing of Customer Information where the processing is inappropriate;
e) object to the processing of personal data;
f) request portability of Customer Information that you have provided to us (which does not include information derived from the collected information), where the processing of such Customer Information is based on consent or a contract with you and is carried out by automated means; and
g) lodge a complaint with the supervisory authority if you believe that we violate your privacy rights.
You can exercise your rights of access, rectification, erasure, restriction, objection, and data portability by contacting us. If you wish to do any of these things and you are our customer, please contact us. If you are not our customer, please contact us at the address under Section V above.
When you consent to our processing your Customer Information for a specified purpose, you may withdraw your consent at any time, and we will stop any further processing of your data for that purpose.
APPENDIX 1 – CUSTOMER INFORMATION TO BE COLLECTED
IN THE COURSE OF USE OF MYVINMEC APPLICATION
When Customer use MyVinmec application, we collect the following Customer Information:
1. Information you give us: when Customer creates and administers your account, we will ask you to provide information including: the name, age, email address, date of birth, permanent and contact address, phone number and other similar contact information; usernames, aliases, roles, and other authentication and security credential information; information relating identity, including government-issued identification information, nationality;..
2. Information about the visits, vaccination history, examination and test results (including Covid-19 test results) which are supplied by Vinmec facilities. This information will be used by us to suggest services that Customer may be interested in, identify your preferences and personalize your experience with MyVinmec application (“Application”).
3. Information we receive from Customer use of our Application, including:
3.1 Information about Application usage behavior: the content Customer viewed or searched for, page response times, and page interaction information (such as scrolling, clicks) to perform internal operations necessary to provide services, including troubleshooting software failures and operational issues, optimize the experience during use, conducting data analysis, testing and diagnosis;
3.2 Device information: network and connection information (SSID/ BSSID), such as the Internet protocol (IP) address used to connect your computer (or other device) to the Internet and information about your Internet service provider or status of your phone (READ_PHONE_STATE) in order to the doctor know your call status in telehealth feature, the connection is available to perform the consultation or not, support telehealth video call to be uninterrupted by any calls from other platforms on the device.
3.3 Bluetooth information: the Application requires permission to access Bluetooth (BLUETOOTH/ BLUETOOTH_ADMIN) on your phone so that you can connect to audio devices (wireless speakers/headphones) to serve the interaction between doctors and customers when using remote health consulting feature.
3.4 Access the CAMERA on the device: The Application requires access permission to use CAMERA on your phone to read and recognize the Barcode - the medical code that identifies the customer at Vinmec, the QRCode on the Health Insurance card to help speed up data entry in the process of using the software, when using telehealth feature, serving the interaction between doctors and customers.
3.5 Access the AUDIO on device: The Application requests permission to use AUDIO access (RECORD_AUDIO) on your phone to make voice calls between doctor and client when using telehealth feature.
3.6 Other information: Access device memory: photos, files, videos (READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE) so that Vinmec can provide the most accurate support services for Customer needs, or help doctors give accurate advice with your information health through pictures, videos. We will ask you to allow the Application to access the images, files in the local storage with the features that need to access this data. Without permission you will not be able to take advantage of these features.