DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM

Between: SCO Vietnam Co., Ltd. ("SCO")
and: Customer ("Customer")

This Addendum is a part of the Software & Cloud Services Agreement between the two parties.


1. PURPOSE

The DPA regulates the processing of personal data by SCO on behalf of the Customer in the course of providing SCO Services.

The DPA applies when SCO processes personal data in accordance with the Customer's instructions.


2. ROLES OF THE PARTIES

Depending on the processing activity:

  • The Customer may be the party determining the purposes and means of data processing;

  • SCO may be the party processing data in accordance with the Customer's instructions.

In the event that SCO determines the purposes of data processing for its own activities, SCO shall perform the corresponding responsibilities in accordance with applicable laws.


3. SCOPE OF DATA

Data may include:

  • Identification information;

  • Contact information;

  • Booking information;

  • Customer information;

  • Passenger information;

  • Transaction information;

  • Employee information;

  • CRM data;

  • Tour data;

  • Operational data;

  • Other data determined by the Customer.


4. PURPOSE OF PROCESSING

SCO processes data for:

  • Providing software;

  • Storage;

  • Synchronization;

  • Booking processing;

  • Customer management;

  • Tour management;

  • API;

  • Backup;

  • Support;

  • Security;

  • Troubleshooting.


5. CUSTOMER INSTRUCTIONS

SCO only processes data in accordance with:

  • The Agreement;

  • System configuration;

  • Lawful instructions;

  • Support requests;

  • Operational requests.

SCO will notify if it notices an instruction showing signs of illegality within the scope of SCO's obligation to notify.


6. CONFIDENTIALITY

SCO ensures that persons authorized to access the data:

  • Are bound by confidentiality obligations;

  • Access only to the extent necessary;

  • Comply with security procedures.


7. TECHNICAL MEASURES

SCO maintains appropriate measures such as:

  • Authentication;

  • Authorization;

  • Access control;

  • Logging;

  • Backup;

  • Monitoring;

  • Encryption where appropriate;

  • Security updates;

  • Incident management.


8. SUBPROCESSORS

SCO may use subprocessors to operate the service.

For example:

  • Cloud;

  • Hosting;

  • Database;

  • Email;

  • Monitoring;

  • Security;

  • API;

  • Channel Manager.

SCO selects appropriate providers for the necessary functions.


9. SUBPROCESSOR NOTIFICATION

SCO may update the list of subprocessors in accordance with its policy.

For important changes, SCO will apply an appropriate notification mechanism.


10. DATA SUBJECT REQUESTS

Upon receiving requests related to data processed on behalf of the Customer, SCO may:

  • Forward the request to the Customer;

  • Assist the Customer in processing;

  • Comply with the Customer's lawful requests.


11. DATA INCIDENTS

Upon detecting a security incident affecting data processed on behalf of the Customer, SCO will:

  1. Identify the incident;

  2. Contain;

  3. Remediate;

  4. Mitigate the impact;

  5. Notify the Customer in accordance with the agreement and applicable law.


12. COMPLIANCE SUPPORT

Within a reasonable scope, SCO may assist the Customer:

  • Provide security information;

  • Provide processing information;

  • Support data export;

  • Support request processing;

  • Support incident assessment.

Requests exceeding the scope of standard support may incur costs.


13. CROSS-BORDER DATA TRANSFER

When SCO Services require data processing outside of Vietnam or through international providers, the parties shall perform legal obligations related to cross-border data transfer in accordance with applicable laws.


14. DATA DELETION OR RETURN

Upon termination of the service, at the valid request of the Customer, SCO shall:

  • Provide an appropriate data export mechanism;

  • Delete data from the main system when necessary;

  • Process backups according to the retention cycle.

SCO may retain data if required by law or necessary to protect legitimate rights.


15. INSPECTION AND ASSESSMENT

The Customer may request reasonable information related to SCO's data protection measures.

Requests for direct audits at SCO or in-depth audits must be agreed upon in advance by both parties.


16. TERM

The DPA is effective during the period SCO processes data on behalf of the Customer.

Confidentiality and data obligations shall continue to apply after the termination of the service to the extent necessary.


17. ORDER OF PRECEDENCE

If the DPA conflicts with the Terms of Service regarding personal data processing, the DPA shall prevail with respect to that matter.


18. GOVERNING LAW

The DPA is governed by the laws of Vietnam, unless otherwise agreed by both parties in accordance with applicable laws.


SCO Vietnam Co., Ltd.

Representative: __________________

Date: __________________

CUSTOMER

Representative: __________________

Date: __________________

Zalo WhatsApp