This Personal Data Protection Policy (the “Policy”) is issued by BRAVO Software Joint Stock Company (“BRAVO”) to set out and ensure transparency regarding how BRAVO collects, uses, shares, and processes personal data of customers, partners, job applicants, and users (“You” or “Data Subjects”) when accessing or using BRAVO’s website, products, or services, or when interacting with BRAVO in any form.

This Policy is developed in accordance with applicable laws of Vietnam, including Law No. 91/2025/QH15, Decree No. 356/2025/ND-CP on personal data protection, and other relevant legal instruments. This Policy forms an integral part of the contracts for the provision of products and services between BRAVO and its customers.

Depending on each specific circumstance, BRAVO may act as a Personal Data Controller, Personal Data Processor, Personal Data Controller and Processor, or a Third Party involved in personal data processing activities.

Where consent of the Data Subject is required by law, BRAVO shall obtain such consent by appropriate means before processing personal data. Consent may be expressed through ticking a checkbox on the website, confirming via email, registering to use services, entering into a contract, or through other methods as agreed by the parties and in accordance with applicable laws.

1. Definitions

1.1. Personal Data means digital data or information in another form that identifies or helps identify a specific individual, including Basic Personal Data and Sensitive Personal Data. Personal Data that has been de-identified shall no longer be considered Personal Data.

1.2. Basic Personal Data means Personal Data reflecting commonly used identity and background information in transactions and social relations, as listed by the Government, including:

a. Full name at birth, including surname, middle name and given name, and other names, if any;
b. Date of birth; date of death or missing date;
c. Gender;
d. Place of birth, place of birth registration, permanent residence, temporary residence, current residence, hometown, and contact address;
e. Nationality;
f. Personal image;
g. Phone number, personal identification number, passport number, driving license number, and vehicle registration plate number;
h. Marital status;
i. Information on family relationships, including parents, children, spouse;
j. Information on personal digital accounts;
k. Other information associated with or capable of identifying a specific individual, which is not classified as Sensitive Personal Data.

1.3. Sensitive Personal Data means Personal Data associated with an individual’s privacy which, when infringed, may directly affect the legitimate rights and interests of agencies, organizations, or individuals, as listed by the Government, including:

a. Data revealing racial or ethnic origin;
b. Political opinions, religious views, or beliefs;
c. Information on private life, personal secrets, and family secrets;
d. Health status;
e. Biometric data and genetic characteristics;
f. Data revealing an individual’s sex life or sexual orientation;
g. Data on crimes and legal violations collected and stored by law enforcement agencies;
h. Personal location data identified through location services;
i. Usernames and passwords for accessing an individual’s electronic identification account; images of identity cards, citizen identification cards, or identity documents;
j. Usernames and passwords for bank accounts; bank card information; transaction history of bank accounts; financial and credit information; and information on financial, securities, and insurance activities and transaction history of customers at credit institutions, foreign bank branches, payment intermediary service providers, securities companies, insurance companies, and other licensed organizations;
k. Data tracking behavior and activities related to the use of telecommunications services, social networks, online communication services, and other services in cyberspace;
l. Other Personal Data that is required by law to be kept confidential or subject to strict security measures.

1.4. Personal Data Subject means the individual to whom the Personal Data relates.

1.5. Personal Data Processing means any activity performed on Personal Data, including one or more of the following activities: collection, analysis, aggregation, encryption, decryption, modification, deletion, destruction, de-identification, provision, disclosure, transfer of Personal Data, and other activities affecting Personal Data.

1.6. Personal Data Controller means an agency, organization, or individual that determines the purposes and means of Personal Data Processing.

1.7. Personal Data Processor means an agency, organization, or individual that processes Personal Data on behalf of a Personal Data Controller or a Personal Data Controller and Processor under a contract.

1.8. Personal Data Controller and Processor means an agency, organization, or individual that determines the purposes and means of processing and directly processes Personal Data.

1.9. Third Party means an organization or individual other than the Personal Data Subject, Personal Data Controller, Personal Data Controller and Processor, or Personal Data Processor, who participates in Personal Data Processing in accordance with applicable laws.

2. Personal Data Collected by BRAVO

2.1. BRAVO collects, uses, or processes different types of Your Personal Data depending on the circumstances, Your role, and applicable legal requirements. Such Personal Data may include:

2.2. BRAVO undertakes to collect only data that is strictly necessary and appropriate for the purposes specified in Article 3 of this Policy, and to fully comply with applicable legal requirements.

3. Purposes of Personal Data Processing

3.1. For job applicants and collaborators

BRAVO may process Personal Data of this group of Data Subjects for purposes including but not limited to:

3.2. For customers, partners, website/software users, potential customers, and other individuals who contact or interact with BRAVO

BRAVO may process Personal Data of this group of Data Subjects for purposes including but not limited to:

4. Personal Data Processing Activities

4.1. Methods of Collecting Personal Data

a. BRAVO may collect Your Personal Data from various sources, including but not limited to:

b. Where a Data Provider provides BRAVO with the Personal Data of another individual, the Data Provider represents, warrants, and undertakes that:

4.2. Sharing of Personal Data

We recognize that Personal Data is important information and are committed to exercising due care when sharing such data. However, where necessary, Personal Data may be shared with:

All recipients of Personal Data are required to comply with applicable confidentiality obligations and may use such Personal Data only for the purposes for which it was disclosed.

BRAVO does not sell, trade, or otherwise disclose customers' Personal Data to any third party for commercial purposes beyond the scope notified to the Data Subject, unless otherwise consented to by the Data Subject or required by applicable laws.

4.3. Cross-border Transfer of Personal Data

In certain circumstances, Personal Data may be stored or processed through servers, cloud platforms, or technology services located outside the territory of Vietnam.

BRAVO shall implement appropriate measures to ensure that any cross-border transfer of Personal Data complies with Vietnamese laws and that appropriate safeguards are in place to protect Personal Data.

Where required by applicable laws, BRAVO shall conduct impact assessments and complete notification or registration procedures relating to cross-border transfers of Personal Data.

4.4. Retention and Security of Personal Data

BRAVO shall commence processing Personal Data from the time it is collected and shall retain such data only for the period necessary to fulfill the purposes specified in this Policy.

Commencement of Processing

Personal Data processing begins from the time You access, inquire about, contact, register for, or use BRAVO's website, software, products, or services, or otherwise communicate, interact, conduct transactions, or exchange information with BRAVO through any communication channel.

Retention Period

Termination of Processing

Personal Data shall cease to be processed and shall be permanently deleted or irreversibly anonymized where:

BRAVO has implemented an Information Security Management System compliant with ISO/IEC 27001:2022.

We adopt appropriate technical and organizational measures, including access control, data encryption, system access monitoring, regular data backup, and employee training to safeguard Personal Data.

Personal Data may also be retained where necessary for contractual performance, dispute resolution, compliance with legal obligations, or in response to requests from competent authorities.

5. Rights of Data Subjects

In accordance with applicable laws, You are entitled to the following rights regarding Your Personal Data:

You may exercise these rights by submitting a written request or email to dpo@bravo.com.vn.

BRAVO respects and facilitates the exercise of these rights to the extent permitted by applicable laws.

You also have the following responsibilities:

6. Children's Personal Data

BRAVO places particular importance on protecting children's Personal Data.

Where the processing of a child's Personal Data is necessary, BRAVO shall process such data in accordance with applicable laws and only upon obtaining the consent of the child's parent or lawful guardian where required.

7. Potential Risks

Although BRAVO continuously applies appropriate security measures, the transmission of data over the Internet may still involve inherent risks beyond our reasonable control, including cyberattacks, viruses, malware, system failures, network disruptions, or unauthorized access.

Where any incident involving Personal Data is likely to affect the lawful rights and interests of Data Subjects, BRAVO shall promptly assess the incident, implement appropriate remedial measures, coordinate incident response activities, and fulfill its notification and reporting obligations to competent authorities and affected parties in accordance with applicable personal data protection laws.

8. Personal Data Breach Management

Upon becoming aware of any Personal Data breach or unauthorized disclosure, BRAVO shall assess the impact, implement appropriate remedial measures, and notify the competent authorities and/or affected Data Subjects as required by applicable laws.

9. Policy Updates

This Policy may be amended or updated from time to time to reflect changes in applicable laws, BRAVO's business operations, technological developments, or service delivery processes.

The latest version of this Policy shall be published on BRAVO's official website.

10. Contact Information

If You have any questions, comments, or requests relating to the protection of Personal Data, please contact us:

BRAVO Software Joint Stock Company
Personal Data Controller for the processing activities described in this Policy.

Address: 7th Floor, 311–313 Truong Chinh Office Building, Phuong Liet Ward, Hanoi City, Vietnam

Tax Code: 0100947771

Hotline: (+84) 243 776 2742

Website: https://www.bravo.com.vn

Email: dpo@bravo.com.vn

BRAVO shall respond to requests from Data Subjects within a maximum period of 72 hours, or within such other timeframe as prescribed by applicable laws depending on the nature of the request.

11. Effective Date

This Personal Data Protection Policy shall take effect from 23 June 2026.

Version: 1.0