1. Scope
This policy applies to personal data processed through the ttaisolutions.com website, consultation forms, email, phone calls, direct communication channels and activities related to TT AI Software Solutions products and services.
This policy is prepared with reference to Vietnamese personal-data protection law, particularly Decree No. 13/2023/ND-CP and other applicable legal instruments in force from time to time.
2. Categories of personal data we may collect
Depending on how you interact with us, TT AI Software Solutions may collect and process the following categories of data:
- Identity and contact information: full name, phone number, email, company or organization name, and contact address if provided.
- Deployment consultation information: organization size, current role, system deployment needs, communications, and technical or business requirements.
- Transaction and service information: products of interest, support-request history, warranty or maintenance details, contracts, invoices, or payment information where applicable.
- Website technical data: IP address, browser type, access time, viewed pages, technical error information, and logs necessary to protect the system.
- Data from locally deployed systems: where customers use deployment services, the data processed depends on the particular system and is described in the relevant contract or technical agreement.
We do not proactively request sensitive personal data unless it is necessary for deployment, support or legal compliance. If a project processes sensitive data, additional safeguards will be agreed with the customer.
3. Processing purposes
Personal data is processed for clear, appropriate purposes and only to the extent necessary, including:
- Receiving, responding to and advising on deployments of software, Edge AI, embedded systems, local ERP, IPCam and related solutions.
- Contacting you, verifying information, preparing quotations, proposing technical configurations, and entering into and performing contracts.
- Providing, operating, maintaining, technically supporting and upgrading products and services.
- Sending service notices, support information, user guidance, security alerts or important product and service changes.
- Improving the website, consultation process, product quality and system security.
- Meeting accounting, tax and records-retention duties, resolving disputes, and responding to lawful requests from competent authorities.
4. Legal bases and consent
TT AI Software Solutions processes personal data on one or more lawful bases, including the data subject’s consent, performance of a contract or pre-contractual steps, legal obligations, legitimate interests in protecting systems and providing services, or cases where law permits processing without consent.
When you voluntarily submit a consultation form, email or other information to us, you confirm that it is accurate and agree that we may process it to respond to, advise on and manage the relevant request.
You may withdraw consent to the extent permitted by law. Withdrawal does not affect the lawfulness of processing completed before the withdrawal.
5. Data sharing with third parties
We do not sell personal data. Data may be shared where necessary with:
- Providers of infrastructure, transactional email, storage, security, technical analytics or services supporting website and system operations.
- Consultants, accountants, legal advisers, auditors or deployment partners where necessary to perform a contract or service.
- Competent authorities where there is a lawful request or where we must meet a legal obligation.
For website consultation forms, internal notification emails may be delivered through the Mailgun SMTP transactional email provider. That provider may use data only to deliver email and secure its systems under the relevant service agreement.
6. Data retention, security and deletion
Personal data is retained only for periods appropriate to the processing purpose, contract requirements, accounting, tax and records-retention obligations, and applicable law.
Safeguards
- Restricting access according to work needs.
- Using server-side configuration for API keys and secrets; never embedding email-service credentials in the frontend.
- Applying appropriate technical measures such as access controls, logging, anti-spam controls, form rate limits and secure infrastructure configuration.
- Prioritizing local and on-premises processing for customer deployments where appropriate to business requirements.
Deletion or anonymization
When data is no longer necessary for the processing purpose, or when you make a valid deletion or restriction request, we will delete, destroy or anonymize it to the extent technically and legally permitted.
7. Data-subject rights
With reference to Decree No. 13/2023/ND-CP, data subjects have rights relating to their personal data, including:
- The right to be informed about personal-data processing.
- The right to consent to or refuse processing, except where law provides otherwise.
- The right to access, review, correct or request correction of data.
- The right to withdraw consent.
- The right to delete or request deletion of data.
- The right to restrict processing.
- The right to request provision of personal data.
- The right to object to processing in order to prevent or limit disclosure or use for advertising and marketing, except where law provides otherwise.
- The right to complain, report, bring legal action, seek compensation and self-protect as provided by law.
Some rights may be limited where law permits, for example due to document-retention duties, authority requests, protection of legitimate interests, or technical constraints relating to data already anonymized or aggregated.
8. How to make a personal-data request
You may send requests to access, correct, delete, restrict processing, withdraw consent or object to processing by email:
When making a request, please provide enough information for us to verify the requester and relevant data, such as your name, the email address or phone number used to contact us, the request details, and related products or services. We may ask for reasonable additional verification before fulfilling the request.
We will respond within a reasonable period according to applicable law and the nature of the request. For restriction or objection requests within the scope of Decree No. 13/2023/ND-CP, we will endeavor to act within the period required by law unless a different rule applies.
9. Legal sources and references
This policy is based on TT AI Software Solutions operational needs and references the following public legal sources:
- Government Decree No. 13/2023/ND-CP: Personal Data Protection — issued on 17 April 2023 and effective from 1 July 2023.
- Full text of Decree No. 13/2023/ND-CP on the Government Portal.
- Decree No. 356/2025/ND-CP: Detailed provisions and measures implementing the Personal Data Protection Law — referenced for its applicable implementation period.