Privacy Policy - Information Security Policy

The website is operated by Sulwhasoo Vietnam, a subsidiary of Amorepacific Vietnam, located at 4A Floor, Vincom Building, 72 Le Thanh Ton, Ben Nghe Ward, District 1, Ho Chi Minh City. The privacy policy describes how Sulwhasoo collects, uses, and shares the information obtained from you through the online shopping channel and in-store. Please read the following section to understand our policy (we refer to Sulwhasoo Vietnam). Sulwhasoo is committed to handling, managing, and protecting your personal data responsibly and in compliance with the law, and in accordance with social ethics.

GENERAL TERMS AND CONDITIONS REGARDING PROTECTION AND HANDLING OF PERSONAL DATA

TERMS AND CONDITIONS ON PROTECTION AND PROCESSING OF PERSONAL DATA

(Effective from July 1, 2023)
(Valid form 1st July 2023)


The data subject agrees to apply, cooperate, and commit to comply with the General Terms and Conditions on the protection and processing of personal data of Amorepacific Vietnam Co., Ltd.
The data subject agrees to apply, coordinate and commit to comply with the Terms and Conditions on personal data protection and processing of Amorepacific Vietnam Co., Ltd.

I. General Provisions
General Provisions

1.1 The general terms and conditions regarding the protection and processing of personal data (hereinafter referred to as "General Terms and Conditions") are an integral part of the agreements, terms, and conditions governing the relationship between any individual engaging in transactions/individuals using the services, utilities, and any relationship with Amorepacific Vietnam Co., Ltd. (hereinafter referred to as "the Company").
The terms and conditions on personal data protection and processing (collectively referred to as “General Terms and Conditions”) are an integral part of the agreements, terms and conditions governing the relationship between any individual having a transaction/individual using services, utilities, and any relationship with Amorepacific Vietnam Co., Ltd. (collectively referred to as the “Company”).

1.2 The company values and respects the privacy, confidentiality, and security of personal information. At the same time, the company always strives to protect personal information and the privacy of data subjects (including relevant subjects of the data subjects) and complies with Vietnamese legal regulations through personal data protection measures that meet and are consistent with international standards.
The company values and respects the privacy, confidentiality and security of personal information. The Company always strives to protect the personal information and privacy of Data Subjects (including relatives of Data Subjects) and comply with Vietnamese law through personal data protection measures that meet and conform to international standards.
  

1.3 The company only collects, processes, and stores personal data of the data subjects in accordance with the provisions of the law and within the scope of (the) agreements between the company and the data subjects.
The Company only collects, processes and preserves personal data of Data Subjects in accordance with the law and within the scope of agreement(s) between the Company and Data Subjects.

1.4 By providing personal data of that third party (including but not limited to: individuals related to that third party, references, beneficiaries, authorized persons, partners, contacts, or other individuals of the Data Subject) to the Company, the Data Subject assures, guarantees, and is responsible that the Data Subject has obtained the legal consent of that third party for the processing and information that the Company is the processor of personal information for the purposes stated in these General Terms and Conditions.
By personally or on behalf of another third individual providing personal data of that third party (including but not limited to: individuals related to that third party, reference, beneficiary, authorized person, partner, contact points or other individual of the Data Subject) to the Company, the Data Subject represents, warrants and undertakes that the Data Subject data for which the third individual's lawful consent has been obtained for processing and information.
that the Company is the processor of personal information for the purposes stated in this General Terms and Conditions. 
1.5 Depending on the Company's role in each specific situation, it may be (i) the Data Controller; (ii) the Data Processor; or (iii) both the Data Controller and Data Processor, the Company will exercise its corresponding rights and responsibilities in accordance with current legal regulations.

Depending on the Company's role in each specific situation are (i) Personal Data Controller; (ii) Personal Data Processor; or (iii) the Data Controller and Processor, the Company will exercise the corresponding powers and responsibilities according to the provisions of current law.

    II. Interpretation of Terms
    interpretation

    2.1 "Personal data" is information in the form of symbols, letters, numbers, images, sounds or similar forms in the electronic environment that is associated with a specific person or helps identify a person specifically. Personal data includes basic personal data and sensitive personal data.
    "Dữ liệu cá nhân" là thông tin dưới dạng ký hiệu, chữ viết, chữ số, hình ảnh, âm thanh hoặc dạng tương tự trên môi trường điện tử gắn liền với một con người cụ thể hoặc giúp xác định một con người cụ thể. Dữ liệu cá nhân bao gồm dữ liệu cá nhân cơ bản và dữ liệu cá nhân nhạy cảm.

    2.2 "Basic personal data" including:
    "Dữ liệu cá nhân cơ bản" bao gồm:
    a) Last name, middle name, and given name, other names (if any);
    Name/ surname, other names (if any);
    b) Date, month, year of birth; date, month, year of death or disappearance;
    Date of Birth; Date of Death or missing;
    c) Gender;
    Gender;
    d) Place of birth, place of birth registration, permanent address, temporary address, current residence, hometown, contact address;
    e) Nationality;
    Nationality;
    f) Personal image;
    Personal Image;
    g) Phone number, ID card number, personal identification number, passport number, driver's license number, license plate number, personal tax code, social insurance number, health insurance card number;
    Phone number, ID card number, personal identification number, passport number, driver's license number, license plate number, personal tax code, social insurance number, health insurance card number;
    h) Marital status;
    Marriage status;
    i) Information about family relationships (parents, children);
    Family relationship information (parents; children);
    j) Information about the individual's account number; personal data reflecting activities, activity history in cyberspace;
    Information about individuals' digital accounts; Personal data reflecting activities and history of activities in cyberspace;
    k) Other information associated with a specific individual or that helps identify a specific individual that does not fall under the category of sensitive personal data.
    Other information associated with a specific person or helping to identify a specific person that is not considered sensitive personal data.
    2.3 "Sensitive personal data" is personal data associated with an individual's privacy rights that, when violated, will directly affect the individual's legitimate rights and interests, including:
    a) Political opinions, religious beliefs;
    Political views, religious views;
    b) Health status and personal life recorded in the medical records, excluding information about blood type;
    Health status and private life recorded in medical records, excluding information about blood type;
    c) Information related to racial origin, ethnic origin;
    Information related to racial origin and ethnic origin;
    d) Information about the inherited or acquired genetic characteristics of an individual;
    Information about inherited or acquired genetic characteristics of the individual;
    e) Information about the individual's physical attributes, biological characteristics;
    Information about the individual's physical attributes and biological characteristics;
    f) Information about the individual's sexual life, sexual orientation;
    Information about the individual's sex life and sexual orientation;
    g) Data on crimes and criminal behavior collected and stored by law enforcement agencies;
    Data on crimes and criminal acts collected and stored by law enforcement agencies;
    h) Customer information of credit institutions, foreign bank branches, payment intermediary service providers, and other authorized organizations, including: customer identification information according to the provisions of law, account information, deposit information, deposited asset information, transaction information, information about organizations and individuals that are guarantors at credit institutions, bank branches, organization providing intermediary payment services;
    Customer information of credit institutions, foreign bank branches, payment intermediary service providers, and other authorized organizations, including: customer identification information according to the provisions of law, account information, deposit information, deposited asset information, transaction information, information about organizations and individuals that are guarantors at credit institutions, bank branches, organization providing intermediary payment services;
    i) Data on the location of individuals determined through location services;
    Data on the individual's location determined through location services;
    j) Other personal data as prescribed by law that is specific and requires necessary security measures.
    Other personal data specified by law are special and require necessary security measures.
    2.4 "Processing of personal data" means one or more operations that affect personal data, such as: collection, recording, analysis, verification, storage, editing, disclosure, combination, access, retrieval, recovery, encryption, decryption, copying, sharing, transmission, provision, transfer, deletion, destruction of personal data or other related actions.
    "Personal data processing" means one or more activities affecting personal data, such as: collection, recording, analysis, confirmation, preservation, amendment, disclosure, combination, access, retrieval, encryption, decryption, copying, sharing, transmission, provision, transfer, deletion, destruction of personal data or other related actions.

    2.5 "Data subject" is an individual whose personal data is reflected or an individual representing another third party (as mentioned in these General Terms and Conditions) in the process of accessing, learning about, registering, using, or being involved in the operational process, providing products and services of the Company.
    "Data Subject" is the individual whose personal data reflects or who represents another third individual (as referred to in these General Terms and Conditions) in the process of accessing, learning about, registering, using or getting involved in the operating process and provision of products and services of the Company.

    2.6 "Amorepacific Vietnam Co., Ltd." is a legal entity established in Vietnam with the business registration number 0309984165. In addition, Amorepacific Vietnam Co., Ltd. will also include headquarters, offices, branches, parent companies, subsidiaries, affiliated companies, or any company within the Amorepacific Group.
    “Amorepacific Vietnam Co., Ltd.” is a legal entity incorporated in Vietnam with Enterprise Registration code 0309984165. In addition, Amorepacific Vietnam Co., Ltd. will also include headquarters, offices, branches, parent company, subsidiary, member company, associate company or any company within the Amorepacific Group.
    - To clarify further, any terms that have not been explained in this Article will be understood and applied according to Vietnamese law.
    For clarification, any terms not explained in this Article will be interpreted and applied according to Vietnamese law.
    III. Activities for Processing Personal Data
    Personal Data Processing activities

    3.1 Collection of Personal Data
    Collecting of Personal Data
    a) In order for the Company to provide products and services to the Data Subject, the Company may need to and/or be required to collect personal data, including: (i) Basic personal data and (ii) Sensitive personal data related to the Data Subject.

    In order for the Company to provide products and services to Data Subjects, the Company may need and/or be required to collect personal data, including: (i) Basic Personal data and (ii) Sensitive personal data relating to the Data Subject.
    b) The Company may collect these personal data directly or indirectly from one or more sources as listed below, including but not limited to:
    The Company may directly or indirectly collect these personal data from one or more of the sources as listed below, including but not limited to:
    ❖ Through the relationship established between the data subject and the Company when the Company uses the products, services of the Company or participates in the legal programs, activities of the Company;
    Through the relationship established between the Data Subject and the Company when the Company uses the Company's products and services or participates in the Company's legitimacy programs and activities.
    ❖ From the e-commerce platforms operating in the Vietnamese market with which the Company is a partner, or from other partners of the Company that the Data Subject agrees to share;
    From e-commerce platforms operating in the Vietnamese market that the Company is a partner in, or from other partners of the Company which Data Subject approves for the sharing;
    ❖ From third-party sources, which the Data Subject agrees to the sharing/provision of personal data, or from sources where collection is required or permitted by law.
    From third party sources, where the Data Subject consents to the sharing/provision of personal data, or sources where collection is required or permitted by law.

    3.2 Purpose of processing personal data
    Purpose of Personal Data processing
    3.2.1 The company may process personal data for one or more of the following purposes:
    The Company may process personal data for one or multiple of the following purposes:
    a) Verify the accuracy and completeness of the information provided by the Data Subject;
    Verifying the accuracy and completeness of the information provided by the Data Subject;
    b) Providing products and services proposed or supplied by the Company or members of the Amorepacific Group to the Data Subject;
    Providing products and services proposed or provided by the Company or members of the Amorepacific Group to Data Subjects;
    c) Preparing reports that require personal data as per legal regulations;
    Preparing reports that require personal data according to legal regulations;
    d) Protecting the legal interests of the Company and complying with relevant legal regulations;
    Protecting the Company's legitimate interests and comply with relevant regulations;
    e) To meet and comply with the Company's internal policies, procedures, and any rules, regulations, guidelines, directives, or requirements issued by the competent state authority in accordance with the law;
    To meet and comply with the Company's internal policies, procedures and any rules, regulations, instructions, directives or requirements issued by competent authorities according to regulations;
    f) For any other purpose required or permitted by any law, regulation, guideline and/or competent authorities;
    For any other purpose required or permitted by any law, regulation, guideline and/or competent authorities;
    g) To serve other purposes in accordance with legal regulations, and related to the Company's business activities that the Company deems appropriate at each point in time; and
    To serve other purposes in accordance with the provisions of law, and related to the Company's business activities that the Company considers appropriate from time to time; and
    h) Other legal purposes related to the purposes mentioned above.
    Other legitimate purposes related to the purposes mentioned above.
    3.2.2 The Company will request permission from the Data Subject before using the personal data of the Data Subject for purposes other than those stated in these General Terms and Conditions.
    The Company will request permission from the Data Subject before using the Data Subject's personal data for any purposes other than those stated in this General Terms and Conditions.

    3.3 The transfer and disclosure of personal data
    Handover and disclosure of Personal Data
    3.3.1 In order to achieve the purposes and activities of processing personal data under these terms and conditions, the Company may disclose the personal data of the Data Subject or the personal data of third parties related to the Data Subject, to one or more of the parties below:
    In order to carry out the purposes and personal data processing activities in this Terms and Conditions, the Company may disclose personal data of Data Subjects or personal data of third parties related to the Data Subject, to one or more of the parties below:
    a) The companies and/or organizations within the Amorepacific Group;
    Subsidiaries and/or organizations within Amorepacific Corporation;
    b) The competent state agencies in Vietnam or any individual, competent agency, or regulatory body or third party that the Company is permitted or required to disclose under the laws of any country, or under any contract/agreement or other commitment between the third party and the Company;
    Competent authorities in Vietnam or any individual, competent authorities or any
    Departments or third party that the Company is permitted or required to disclose in accordance with laws of any country, or under any other contract/agreement or undertaking between a third party and the Company;
    c) Third parties with whom the Company has a legal basis to share the personal data of the data subject.
    Third parties which the Company has a legitimacy reason to share the Data Subject's personal data.
    3.3.2 On the other hand, the Company will consider the personal data of the Data Subject as private and confidential. Besides the parties mentioned above, the Company will not disclose the Data Subject's data to any other parties, except in the following cases:
    Otherwise, the Company will treat the personal data of the Data Subject as private and confidential. Other than the parties stated above, the Company will not disclose Data Subject data to any other party, except in the following cases:
    a) When there is consent from the Data Subject;
    Prior consent form Data subject;
    b) When the Company is required or permitted to disclose under the law; or according to the decision of a competent state authority.
    When the Company is required or permitted to disclose according to legal regulations; or according to the decision of a competent state agency;
    IV. Transfer of Personal Data Abroad
    Outbound transfer of Personal Data

    4.1 In order to fulfill the purpose of processing personal data under these General Terms and Conditions, the Company will have to provide/share the personal data of the Data Subject to relevant third parties of the Company, and these third parties may be located in Vietnam or any other location outside the territory of Vietnam.
    For the purposes of processing personal data in this General Terms and Conditions, the Company shall provide/share personal data of the Data Subject to relevant third parties of the Company and these third parties may be located in Vietnam or any other location outside the territory of Vietnam.

    4.2 When providing/sharing personal data abroad, the Company will require the receiving party to ensure that the personal data of the Data Subject transferred to them will be kept secure and safe. The Company ensures compliance with legal obligations and regulations related to the transfer of personal data of the Data Subject.
    When providing/sharing personal data abroad, the Company will require the receiving party to ensure that the Data Subject's personal data transferred to them will be confidential and secure. The Company ensures compliance with legal and regulatory obligations regarding the transfer of personal data of Data Subjects.
    V. Rights and Obligations of Data Subjects
    Rights and Obligations of Data Subject

    5.1 Data subjects have the following rights: (i) Right to know; (ii) Right to consent; (iii) Right to access; (iv) Right to withdraw consent; (v) Right to delete data; (vi) Right to restrict data processing; (vii) Right to data portability; (viii) Right to object to data processing; (ix) Right to complain, denounce, and initiate legal action; (x) Right to claim compensation for damages; (xi) Right to self-defense and other related rights as provided by law.
    Data subject is entitled with the following rights: (i) Right to know; (ii) Right to consent; (iii) Right to access; (iv) Right to withdraw consent; (v) Right to delete; (vi) Right to restrict data processing; (vii) Right to provide data; (viii) Right to object to data processing; (ix) Right to complain, denounce and sue; (x) Right to claim compensation for damages; (xi) Right to self-defense and other related rights as prescribed by law.

    5.2 Within the limits of the law, the data subject may exercise their rights by contacting the Company using the information provided in detail in Article 9.
    To the extent permitted by law, Data Subjects may exercise their rights by contacting the Company according to the information provided in detail in Article 9.

    5.3 The Company, with reasonable effort, will fulfill the legal and valid requests from the Data Subject within the legally prescribed timeframe upon receiving a complete and valid request and any related processing fees (if applicable) from the Data Subject, subject to the Company's rights to invoke any exemptions and/or exceptions under the law.
    The Company, with reasonable endeavors, will comply with a lawful and valid request from a Data Subject within the statutory period since the receipt of a complete and valid request and the associated processing fee (if any) from the Data Subject, subject to the Company's right to invoke any exemptions and/or exceptions under the law.

    5.4 In the event that the Data Subject withdraws their consent, requests the deletion of data and/or exercises other related rights regarding any or all personal data of the Data Subject. Actions taken by the Data Subject under this provision may affect the ability to continue providing products and services of the Company to the Data Subject, while the Company reserves its legal rights and remedies in such cases. Accordingly, the Company shall not be liable to the Data Subject and/or any third parties related to the Data Subject for any losses incurred, and the legal rights of the Company shall be expressly reserved regarding the limitation, suspension, cancellation, or prevention of the processing of the Data Subject's data.
    In the event the Data Subject withdraws consent, requests data deletion and/or exercises other relevant rights in respect of any or all of the Data Subject's personal data. Actions taken by Data Subjects under this provision may affect the Company's ability to continue to provide products and services to Data Subjects, and the Company reserves the rights and legal remedies in such circumstances. Accordingly, the Company shall not be liable to the Data Subject and/or third parties related to the Data Subject for any losses arising, and the Company's legal rights shall be expressly reserved to limit, suspend, cancel or prevent the processing of data by Data Subjects.

    5.5 For safety purposes, the Data Subject may need to submit their request in writing or use another method to prove and verify the identity of the Data Subject. The company may require the Data Subject to verify their identity before processing the request of the Data Subject.
    For safety purposes, it may be necessary for the Data Subject to make his or her request in writing or use another method to prove and authenticate the Data Subject's identity. The Company may require the Data Subject to verify their identity before processing the Data Subject's request.
    VI. Measures for Personal Data Security
    Personal data protection measures

    6.1 The Company considers the personal data of the Data Subject as the most important information of the Company and ensures confidentiality, safety, legal compliance, and limits the consequences and unwanted damages that may occur (including but not limited to: data leaks or improper data processing that harms the rights and legitimate interests of the Data Subject). The responsibility for the confidentiality of the personal data of the Data Subject is a mandatory requirement that the Company imposes on all employees.
    The Company considers the personal data of Data Subjects as the most important information of the Company and the Company ensures confidentiality, safety, compliance with the law, and limits the consequences and damages (including but not limited to: data leakage or inappropriate data processing that damages the legitimate rights and benefits of the Data Subject). The responsibility to protect the personal data of the Data Subject is mandatory.
    requirement that the Company sets for all employees.

    6.2 The company shall fulfill its responsibility to protect personal data in accordance with current legal regulations using the best security methods according to international standards and shall regularly review and update management and technical measures when processing personal data of the data subjects (if any).
    The Company carries out its responsibility to protect personal data in accordance with current laws with the best security methods according to international standards and regularly reviews and updates management and technical measures when processing personal data of Data Subjects (if any).
    VII. Storage of Personal Data
    Preservation of Personal Data

    7.1 The personal data of the data subject stored by the Company will be kept confidential. The Company will take reasonable measures to protect the personal data of the data subject.
    'Data Subjects' personal data held by the Company will be kept confidential. The Company will take reasonable measures to protect the personal data of Data Subjects.'

    7.2 The company will apply the international data security standards of the Amorepacific Group based on ensuring compliance with current legal regulations.
    The Company will apply international standards on data security of Amorepacific Corporation on the basis of ensuring compliance with current regulations.

    7.3 The company stores the personal data of the data subject for the necessary period to fulfill the purposes set out in these General Terms and Conditions, unless a longer storage period for personal data is required or permitted by applicable laws and regulations.
    The Company preserves the personal data of Data Subjects for the period necessary to fulfill the purposes under the General Terms and Conditions, unless a longer storage period of personal data is requested or permitted by applicable laws.
    VIII. Amendments
    Amendment

    The company may modify, update, or adjust the terms of these General Terms and Conditions from time to time. Notice of any modifications, updates, or adjustments will be updated and posted on the company's website: https://vn.sulwhasoo.com/ and/or notified to the data subject via the email address that the data subject has provided to the company.
    The Company may amend, update or modify the provisions of the General Terms and Conditions from time to time. Notice of any amendments, updates or adjustments will be updated and posted on the Company's website: https://vn.sulwhasoo.com/ and/or notified to the Data Subject via email address that the Data Subject has provided to the Company.
    IX. Contact information for personal data processing
    Contact information for Personal Data processing.

    In the event that the Data Subject has any questions regarding the General Terms and Conditions or issues related to the rights of the Data Subject or the processing of the personal data of the Data Subject, please contact us using the information below:
    Sulwhasoo Brand
    Customer Service Hotline: 0865 000 770
    Email CSKH: sulwhasoovietnam@vn.amorepacific.com
    In case a Data Subject has any questions regarding the General Terms and Conditions or matters relating to data subject rights or the processing of the Data Subject's personal data, the Data Subject Please contact us using the information below:
    Sulwhasoo Brand
    Hotline CS: 0865 000 770
    Email CS: sulwhasoovietnam@vn.amorepacific.com
    GHÉ THĂM SULWHASOO SPA TẠI VINCOM ĐỒNG KHỞI
    Địa điểm

    Tầng 1, Vincom Đồng Khởi 72 Đ. Lê Thánh Tôn, Bến Nghé, Quận 1, Thành phố Hồ Chí Minh

    Địa điểm

    Tầng 1, Vincom Đồng Khởi 72 Đ. Lê Thánh Tôn, Bến Nghé, Quận 1, Thành phố Hồ Chí Minh

    GHÉ THĂM SULWHASOO SPA TẠI TAKASHIMAYA
    Địa điểm

    Tầng 1 TTTM Takashimaya 94 Đ. Nam Kỳ Khởi Nghĩa, Bến Nghé, Quận 1, Thành phố Hồ Chí Minh

    Địa điểm

    Tầng 1 TTTM Takashimaya 94 Đ. Nam Kỳ Khởi Nghĩa, Bến Nghé, Quận 1, Thành phố Hồ Chí Minh

    GHÉ THĂM SULWHASOO SPA TẠI VINCOM LANDMARK 81
    Địa điểm

    Tầng 1, TTTM Vincom Center Landmark 81, 772 Điện Biên Phủ, P.2, Q, Bình Thạnh, Thành phố Hồ Chí Minh

    Địa điểm

    Tầng 1, TTTM Vincom Center Landmark 81, 772 Điện Biên Phủ, P.2, Q, Bình Thạnh, Thành phố Hồ Chí Minh

    GHÉ THĂM SULWHASOO SPA TẠI CRESCENT MALL
    Địa điểm

    Tầng trệt TTTM Crescent Mall 101 Tôn Dật Tiên, Tân Phú, Quận 7, Thành phố Hồ Chí Minh

    Địa điểm

    Tầng trệt TTTM Crescent Mall 101 Tôn Dật Tiên, Tân Phú, Quận 7, Thành phố Hồ Chí Minh

    Ghé THĂM SULWHASOO SPA TẠI DIAMOND PLAZA
    Địa điểm

    Tầng trệt Diamond Plaza 34 Đ. Lê Duẩn, Bến Nghé, Quận 1, Thành phố Hồ Chí Minh

    Địa điểm

    Tầng trệt Diamond Plaza 34 Đ. Lê Duẩn, Bến Nghé, Quận 1, Thành phố Hồ Chí Minh

    GHÉ THĂM SULWHASOO TẠI LOTTE TÂY HỒ
    Địa điểm

    Tầng 1, Lotte Mall Tây Hồ (272 Võ Chí Công, Tây Hồ, Hà Nội)

    Liên hệ (84) 24 6686 0920

    Địa điểm

    Tầng 1, Lotte Mall Tây Hồ (272 Võ Chí Công, Tây Hồ, Hà Nội)

    Contact

    (84) 24 6686 0920