Privacy Policy
What we collect, why we collect it, and the rights you have over it. Written for the GDPR, Singapore’s PDPA, and US state privacy laws.
Last updated 1 August 2026
Who we are
AgileTech Vietnam is a software development company headquartered in Hanoi, Vietnam, with a presence in Irvine, California. This policy explains what we do with personal data when you visit this website, contact us, or apply for a role with us.
For visitors in the European Economic Area and the United Kingdom, AgileTech Vietnam is the controller of the personal data described in this policy. Where we build or operate software for a client, that client is the controller and we act as a processor on their documented instructions. That distinction matters, and it is explained in personal data inside client projects.
Our contact details are at the end of this policy.
What we collect, and what we do not
We collect very little, and we would rather tell you exactly what that is than describe it in categories.
This website does not run analytics, advertising tags, tracking pixels, session recording, or heat mapping. It sets one cookie, and only to remember the cookie choice you make yourself. Our web fonts are served from our own servers rather than a font network, so simply loading a page does not disclose your visit to a third party. The one piece of content we would load from another company is the Google map of our Hanoi office on the Contact page, and it does not load until you allow it or press the button on that page. There is more detail in the Cookie Policy.
| Data | Where it comes from | Whether it is required |
|---|---|---|
| Name | You type it into the contact form | Required |
| Work email address | You type it into the contact form | Required |
| Company name | You type it into the contact form | Optional |
| The service you are interested in | You choose it from a list on the contact form | Required |
| Your project description | You type it into the contact form | Required |
| Date and time of your enquiry | Recorded automatically when the form is submitted | Automatic |
| Email address, if you subscribe to our newsletter | You type it into the newsletter form in the footer | Required to subscribe |
| Your name, if you subscribe to our newsletter | You type it into the newsletter form in the footer | Optional |
| The topic you are most interested in, if you subscribe | You choose it from a list on the newsletter form | Optional |
| Your consent to receive the newsletter, and when you gave it | Recorded when you tick the consent box and submit | Automatic |
That table is the complete set. The contact form stores those fields and nothing else. We do not ask for, and neither form can capture, your postal address, phone number, date of birth, government identifiers, payment details, or any special category data.
The newsletter is separate from the contact form. Subscribing does not create an enquiry, and sending an enquiry does not subscribe you.
Only your email address and your consent are needed to subscribe. The name and topic fields are genuinely optional: you can leave both blank and still receive the newsletter. We ask for them so we can address you properly and send you the topic you actually chose rather than everything we publish. If you leave them blank we store nothing in their place, and we do not infer either of them from your email address, your employer, or anything else.
If you email, call, or message us on a social platform instead, we will hold whatever you chose to put in that message for as long as we need it to answer you.
If you apply for a job, we process the CV and application details you send us. We use them to assess your application and for nothing else.
Your cookie choice
When you answer the cookie prompt, your answer is stored in a cookie on your own device named at_consent. It holds the categories you allowed, the time you answered, and the version of the choice, so the site can act on what you decided and stop asking. Because it is a cookie, your browser returns it to us with each request. It contains no name, no email address, and no identifier for you. Delete it in your browser and the choice is erased, and we will simply ask again.
Server logs
Like any website, ours is served by infrastructure that records technical request data such as IP address, user agent, requested URL, and timestamp. These logs exist to keep the service available and to detect abuse. They are not joined to your contact enquiry, are not used to build a profile of you, and are not used for advertising.
Why we use it, and our lawful basis
Under the GDPR, every use of personal data needs a stated lawful basis. Here is ours, purpose by purpose.
| Purpose | Data used | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Replying to your enquiry and discussing your project | Contact form fields, or the content of your email | Steps taken at your request before entering into a contract, Art. 6(1)(b) |
| Delivering a project once we are engaged | Business contact details of the people we work with | Performance of a contract, Art. 6(1)(b) |
| Keeping the website available and secure | Server log data | Legitimate interests, Art. 6(1)(f), in operating a secure service |
| Assessing a job application | Your CV and application details | Steps taken at your request before entering into a contract, Art. 6(1)(b) |
| Meeting legal, accounting, and tax obligations | Contract and billing records | Legal obligation, Art. 6(1)(c) |
| Sending you our newsletter | The email address you gave on the newsletter form | Consent, Art. 6(1)(a), which you can withdraw at any time |
| Addressing the newsletter to you by name, and sending the topic you chose | The name and topic you optionally gave on the newsletter form | Consent, Art. 6(1)(a), which you can withdraw at any time |
| Remembering the cookie choice you made, and being able to show that you made it | The cookie choice record on your own device | Legal obligation, Art. 6(1)(c), read with Art. 7(1). Storing the record of a decision is strictly necessary to honour it, so it needs no separate consent of its own |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not profile you. Choosing a newsletter topic is not profiling: it is a preference you stated yourself and can change or clear at any time, and we do not analyse your behaviour, infer anything about you, or evaluate you against other subscribers.
Marketing
We do not add contact form enquiries to a marketing list. Sending us an enquiry does not subscribe you to anything.
We do run one newsletter, and the only way onto it is the form in our footer. It requires a separate, positive opt-in: an unticked box you have to tick yourself, which we record along with the time you ticked it. Every message carries a one-click unsubscribe, and you can also ask us to remove you by emailing hello@agiletech.vn. We do not need a reason.
The form also offers two optional fields, your name and the topic you care about most, so the mail can be addressed to you and narrowed to what you asked for. Leaving them blank changes nothing about your subscription. To correct or remove either one later, email us and we will do it; see your rights.
How long we keep it
| Record | Kept for | Why |
|---|---|---|
| A contact enquiry that does not lead to an engagement | 24 months from your last contact with us | Business enquiries often resume after a long gap, and a returning enquirer should not have to repeat their context |
| Records relating to a client engagement | The engagement, then the period required by the contract and by Vietnamese accounting and tax law | Contractual and legal obligation |
| Unsuccessful job applications | 12 months, unless you ask us to delete them sooner | So we can consider you for a role that opens shortly afterwards |
| Server logs | A short operational window, then rotated and discarded | They exist for availability and abuse detection only |
| A newsletter subscription | Until you unsubscribe, then we delete the address and keep only the fact that it opted out | So that an address you asked us to stop mailing is not re-added by a later import |
| The optional name and topic on a newsletter subscription | Deleted with the rest of the subscription when you unsubscribe; neither is kept on the opt-out record | They exist only to personalise mail we are no longer sending you |
| Your cookie choice | 180 days, then we ask again, or until you change or delete it yourself | A privacy decision should be refreshed rather than treated as permanent |
You can ask us to delete your enquiry at any point before those periods expire, and we will, unless we are required to keep it. See your rights.
Who we share it with
We do not sell personal data. We never have. We do not share it for anyone else's advertising.
Your data is seen by our own staff who need it to answer you or run your project, and by the service providers who run the infrastructure underneath our website and business email. Those providers act on our instructions under contract, and they may not use your data for their own purposes.
The current list of infrastructure providers is published on our Sub-processors page, so you can see who they are rather than being asked to trust a category.
We will also disclose personal data where the law genuinely requires it, for example in response to a valid legal order, or to establish or defend a legal claim. If we are ever compelled to disclose data about you, we will tell you unless we are legally prohibited from doing so.
International transfers
We are based in Vietnam and we work with clients in Europe, Singapore, the United States, and elsewhere. If you contact us from the EEA or the UK, your enquiry will be read by our team in Vietnam.
Vietnam is not the subject of a European Commission adequacy decision. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where UK data is involved, together with the technical and organisational measures described in how we protect it. You can ask us for information about the safeguards that apply to a specific transfer.
How we protect it
We operate an information security management system certified to ISO/IEC 27001:2013, alongside quality management certified to ISO 9001:2015. In practice, the measures that protect the data described in this policy include:
- Encryption in transit. This site is served over HTTPS, and both the contact form and the newsletter form are submitted to our own origin.
- Access on a need-to-know basis, so enquiry data is reachable only by the people who handle enquiries.
- Data minimisation by design. The contact form captures five fields because five is what answering you requires.
- Security headers on every response, including a strict referrer policy, MIME-type sniffing protection, framing protection, and a permissions policy that switches off camera, microphone, and geolocation access.
- Staff confidentiality obligations and security awareness training.
- Vulnerability management and patching as part of our certified process.
No system is perfectly secure, and we will not claim otherwise. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where the GDPR requires it, and we will tell you directly where the risk is high. Our approach to security is described further on the Security page.
Your rights
Wherever you are, you can ask us to show you the personal data we hold about you, correct it, or delete it. Email hello@agiletech.vn and we will respond within 30 days.
We will not charge you for exercising a right, and we will not treat you differently because you did. We may need to verify your identity before acting on a request, and we will only ask for what is necessary to do that.
The sections below set out the additional specific rights that apply depending on where you are.
If you are in the EU or UK
The General Data Protection Regulation and the UK GDPR give you the following rights over your personal data.
| Right | What it means in practice |
|---|---|
| Access, Art. 15 | Ask us for a copy of the personal data we hold about you, and for the information in this policy as it applies to you specifically. |
| Rectification, Art. 16 | Have inaccurate data corrected and incomplete data completed. |
| Erasure, Art. 17 | Have your data deleted where we no longer need it, where you withdraw consent that we were relying on, or where you successfully object. |
| Restriction, Art. 18 | Have us pause processing while a dispute about accuracy or legitimate interests is resolved. |
| Portability, Art. 20 | Receive the data you gave us in a structured, commonly used, machine-readable format. |
| Objection, Art. 21 | Object to processing we base on legitimate interests. We will stop unless we can show compelling legitimate grounds that override your interests. |
| Withdraw consent, Art. 7(3) | Where we rely on consent, withdraw it at any time. This does not affect processing carried out before you withdrew. |
| Complain, Art. 77 | Lodge a complaint with your national supervisory authority, or with the Information Commissioner’s Office in the UK. We would appreciate the chance to resolve it with you first. |
We have not appointed a Data Protection Officer, because our processing does not meet the criteria in Article 37 that would require one. Privacy enquiries are handled by our privacy contact at hello@agiletech.vn.
If you are in Singapore
We handle personal data in line with the Personal Data Protection Act 2012. Under the PDPA you may:
- Ask what personal data we hold about you and how it has been used or disclosed in the past year.
- Ask us to correct an error or omission in that data.
- Withdraw consent for a purpose, on reasonable notice. We will tell you the likely consequences before the withdrawal takes effect, for example that we may no longer be able to progress your enquiry.
As the PDPA requires, we have designated a person responsible for ensuring our compliance with it. You can reach our Data Protection Officer at hello@agiletech.vn, marking your message for the attention of the Data Protection Officer. We will respond to an access or correction request within 30 days, and where we cannot, we will tell you when we will.
We take reasonable steps to ensure personal data we transfer out of Singapore is protected to a standard comparable to the PDPA, consistent with the Transfer Limitation Obligation.
If you are not satisfied with our response, you may contact the Personal Data Protection Commission of Singapore.
If you are in the United States
Several US states, including California, Virginia, Colorado, Connecticut, Utah, and Texas, give residents rights over their personal information. We apply the following to any US resident who asks, rather than checking which state you live in first.
- Know and access. Ask what categories of personal information we have collected about you, why, and who we disclosed it to.
- Delete. Ask us to delete the personal information we collected from you.
- Correct. Ask us to fix inaccurate personal information.
- Opt out of sale, sharing, and targeted advertising. See the paragraph below.
- Non-discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a right.
- Appeal. If we refuse a request, you may ask us to reconsider, and we will explain the outcome in writing.
Sale, sharing, and targeted advertising
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not process it for targeted advertising. There is therefore no "Do Not Sell or Share My Personal Information" mechanism to offer you, because there is nothing to opt out of. This is a statement about how the site is actually built. It runs no advertising or analytics tags of any kind, as described in the Cookie Policy.
We honour an opt-out preference signal in any case. If your browser sends Global Privacy Control, our cookie prompt does not ask you to opt in to anything: the optional categories are recorded as refused, and the prompt tells you that is what happened. Respecting the signal now, before we have anything that would need to read it, is cheaper than remembering to respect it later.
We do not knowingly collect or process sensitive personal information through this website. Under California law you may designate an authorised agent to make a request on your behalf, and we may ask that agent for proof of your authorisation.
Personal data inside client projects
This is the distinction that matters most for a software development company, and it is worth stating plainly.
When we build or operate a system for a client, that system may hold personal data about the client's own customers, patients, students, policyholders, or staff. For that data:
- Our client is the controller. They decide what is collected and why.
- AgileTech Vietnam is a processor. We act only on the client's documented instructions, under a data processing agreement that meets GDPR Article 28.
- We do not use client project data for our own purposes, and we do not use it to train models unless a client has specifically instructed us to.
- If you are an individual whose data sits in a system we built, your rights run against our client, not against us. If you contact us, we will pass your request to the relevant controller and support them in answering it.
Clients who need our standard data processing agreement, our sub-processor list, or details of our ISO 27001 scope can request them at hello@agiletech.vn.
Children
This website is aimed at businesses, and we do not direct it at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.
Where we build education software for a client, any handling of student data is governed by that client's instructions and their own obligations as controller, as described in personal data inside client projects.
Changes to this policy
If we change how we handle personal data, we will update this page and change the date at the top. Where a change materially affects your rights, we will say what changed rather than quietly replacing the text.
In particular, if we ever introduce analytics or any other non-essential cookie, this policy and the Cookie Policy will be updated before that goes live, and it will not run until the cookie prompt has your permission for the category it belongs to. That prompt shipped ahead of anything needing it, so the control already exists rather than being promised.
How to contact us
For any question about this policy, or to exercise a right, contact us:
- Email hello@agiletech.vn
- Phone (+84) 989 324 830
- Vietnam Floor 3 & 4, No 82/116, Nhan Hoa, Thanh Xuan, Hanoi, Vietnam
- United States 3812 Family Tree, Irvine, CA 92618, USA
We aim to acknowledge privacy requests within five working days and to resolve them within 30 days.
Common questions
Does AgileTech Vietnam sell my personal data?
What personal data does the AgileTech Vietnam website actually collect?
Is AgileTech Vietnam a controller or a processor?
How are transfers of personal data out of the EU or UK protected?
How do I ask AgileTech Vietnam to delete my data?
Who is AgileTech Vietnam’s Data Protection Officer?
Still have a question?
If anything here is unclear, or you want our data processing agreement, ISO certificates, or a signed NDA before we talk, just ask. We would rather answer than have you guess.