Huayuesc
All ▾
All ▾
All ▾
HomeInformationPrivacy Policy & Personal Data Protection
🔒
LEGAL

Privacy Policy & Personal Data Protection

Huayuesc — the trade name of HUAYUE VIET NAM SUPPLY CHAIN COMPANY LIMITED (Tax Code 0111453693) — commits to securing user data in accordance with ISO/IEC 27001:2022, Vietnam's Decree 13/2023/NĐ-CP, China's Personal Information Protection Law (PIPL), and the EU GDPR where applicable. This policy describes how we collect, use, store, share, and protect your personal data — in clear language, without hidden meanings.

v1.0 (2026)Version
01/01/2026Effective from
CT TNHH Chuỗi Cung Ứng Huayue VN (MST 0111453693)Controlling legal entity
NĐ 13/2023Vietnam compliance
PIPL 2021China compliance
TLS 1.3 + AES-256Encryption
mcy@huayuesc.comDPO email
000-000-000DPO hotline

1. Scope & Definitions

This policy applies to all services at Huayuesc (huayuesc.vn), including the B2B website, mobile app (iOS/Android coming soon), and all offline interactions with the Huayue team at the Hanoi head office + the Guangzhou procurement representative office. Definitions: 'Personal data' = information that can directly or indirectly identify an individual (under Article 2 Decree 13/2023). 'User' = Buyer (Vietnamese individual/enterprise), Supplier (Chinese supplier), Visitor (unregistered). 'Data controller' = HUAYUE SUPPLY CHAIN VIETNAM COMPANY LIMITED (Tax ID 0111453693, registered address Ecolife Building, Dai Mo, Hanoi). 'Data processor' = authorized service providers (cloud hosting, payment processors, logistics partners). 'Consent' = informed, voluntary, and clear approval under Article 11 Decree 13/2023.

Security is not a checkbox — it is a process. Huayue is committed to transparency about how Vietnamese Buyer data is processed cross-border between Vietnam and China, no secrets, no confusing legal jargon.
Information Security Team — Huayue Vietnam

2. Information We Collect

We collect 5 main data categories:

  • Account information — full name, email, phone number, company, tax ID, shipping address, password (bcrypt hashed).
  • Transaction information — RFQ, orders, favorite products, payment history (status only, no card numbers — handled by payment processor), tracking number, dispute history.
  • Device & log information — IP address, user agent, OS, browser, language, access time, pages visited (stored 90 days for analytics + security audit).
  • Communication content — chat with supplier on platform, video call transcript (only saved when user confirms), emails sent through system, comments on reviews.
  • Third-party information — when logging in via Google/Apple/Facebook, Huayue receives: email, name, avatar (only fields you consent to share via OAuth consent screen). We do NOT collect: national ID/passport (unless KYC required for transactions ≥$10K), biometric data, medical data, religion, political views (as defined as 'sensitive personal data' under Article 2.4 of Decree 13/2023).

Huayue processes data based on 4 legal bases under Article 11 of Decree 13/2023:

  • Consent — you check 'I agree' when registering, you can withdraw at any time.
  • Contract performance — processing necessary to provide agreed B2B services (RFQ, ordering, shipping, after-sales).
  • Legal obligation — storing tax documents for 10 years per Vietnam Tax Management Law, storing e-invoices per Decree 123/2020/ND-CP.
  • Legitimate interest — fraud prevention, system security, product improvement (only when not infringing your fundamental rights). Specific purposes: provide & personalize services, connect Buyer–Supplier, process payment & shipping, send transaction notifications, prevent fraud/abuse, improve products through aggregate data analysis, marketing (only with Buyer opt-in), comply with laws + authorities' requests.

4. Cookies & Tracking Technologies

Huayuesc uses 4 cookie categories with a clear policy and cookie management table at /info/quan-ly-cookies:

  • Essential cookies — maintain login, RFQ cart, language, no consent required per Article 6 of Decree 13/2023 (necessary for service). Examples: csr_session, csr_locale, csr_csrf.
  • Analytical cookies — Google Analytics 4 (anonymized IP), Hotjar session replay (mask sensitive fields), Mixpanel funnel. Require opt-in. Stored 24 months.
  • Marketing cookies — Facebook Pixel, Google Ads, LinkedIn Insight, TikTok Pixel. Require opt-in. Stored 12 months.
  • NCC partner cookies — only activated when you click on a Supplier's product page (per partner). Cookie consent banner appears on first visit, with 3 choices: Accept All / Essential Only / Customize. You can change choice anytime at /buyer-center/settings/privacy.

5. Sharing with Third Parties

Huayue shares data with 5 third-party groups, each with a Data Processing Agreement (DPA) binding compliance with Decree 13/2023 + GDPR-equivalent:

  • Suppliers/NCC — only share minimum information necessary to complete the order (contact person name, company, shipping address, requested SKU); do NOT share direct email/phone — all communication goes through Huayue's relay.
  • Partner banks in Vietnam and China for Escrow Service; payment processors for international payments — they only see minimum information to process transactions + comply with KYC.
  • Logistics partners + customs brokers at Hai Phong port — share shipping address + tracking number + customs declaration content.
  • Service providers — AWS Singapore (hosting), Cloudflare (CDN, anti-DDoS), Twilio (SMS OTP), SendGrid (transactional email), Sentry (error tracking, scrubs PII).
  • Government authorities — only upon lawful written request (search warrant, prosecution document), Huayue publishes an annual Transparency Report on the number of requests received. We NEVER sell data to data brokers or third parties for marketing.

6. Cross-Border Data Transfer VN–CN

Huayue operates cross-border between Vietnam and China: Vietnamese Buyer data may be transferred to the Guangzhou sourcing office for Huayue team to assist with sourcing, factory audits, inspection, and dispute handling. Cross-border data transfer is protected by 3 layers:

  • Standard Contractual Clauses (SCCs) — internal document between Hanoi headquarters and Guangzhou representative office of HUAYUE VIETNAM SUPPLY CHAIN COMPANY LIMITED, compliant with the reference template of Vietnam's Ministry of Justice.
  • Encryption-in-transit — all VN↔CN traffic via TLS 1.3, certificate pinning, non-interceptable.
  • Cross-border data transfer registration with the Authority of Information Security under Article 25 of Decree 13/2023 — Huayue is completing the registration process. You have the right to request Huayue NOT to transfer data to China — we will respect it but may limit on-site factory audit services (performed by the Guangzhou team).

7. Data Storage & Lifecycle

Personal data lifecycle at Huayue follows the 'minimum necessary' principle:

  • Active account — stored continuously, updated on your request.
  • Inactive account for ≥18 months — send warning email + auto-delete if no response within following 90 days.
  • Completed orders — store details for 7 years per Vietnamese tax obligations, then anonymize.
  • Transaction documents + invoices — stored 10 years per Tax Management Law.
  • Communication logs (chat, email) — stored 24 months for dispute resolution, then permanently deleted.
  • Server logs — 90 days, then aggregated into analytics reports (no PII).
  • Cookies — per time-to-live stated in Section 4. When you request account deletion (right under Section 9), Huayue performs hard-delete within 30 days + confirmation via email + provides 'Certificate of Erasure' upon request (for businesses needing audit trail).

8. Technical & Organizational Security Measures

Technical security measures:

  • Transmission encryption — TLS 1.3 with forward secrecy, HSTS preload, certificate transparency monitoring.
  • Storage encryption — AES-256-GCM for database at rest, key management via AWS KMS with 90-day key rotation.
  • Password hashing — bcrypt with work factor 12 + per-user salt + pepper.
  • Intrusion detection — Cloudflare WAF layer 7, AI anomaly detection for login patterns, automatic rate limiting to block brute-force.
  • Internal access control — principle of least privilege, role-based access control (RBAC), mandatory 2FA for all Huayue employees with production access.
  • Audit logging — every data access logged with timestamp, IP, user, action; logs stored on write-once system for 12 months.
  • Penetration testing — 2 times/year by independent security partner.
  • Bug bounty program — report vulnerabilities to mcy@huayuesc.com + bounty $100-5,000 depending on severity. Organizational measures: Huayue employees sign NDA + attend security training quarterly; data centers AWS Singapore + Vietnam certified ISO 27001; incident response process with RTO 4h, RPO 1h; automatic hourly backup + daily offsite backup.

9. 11 Rights under Decree 13/2023

Under Articles 9–22 of Decree 13/2023, you have 11 basic rights regarding your personal data:

  • Right to be informed — know what data is collected, purpose, retention period.
  • Right to consent — approve or refuse processing.
  • Right to access — request to view your data (export JSON/CSV file within 30 days).
  • Right to withdraw consent — at any time, no explanation needed.
  • Right to erasure — 'right to erasure', delete account + all data within 30 days (except records required by tax law).
  • Right to restrict processing — request Huayue to temporarily stop processing data while resolving a complaint.
  • Right to data portability — request transfer of data to another provider (data portability).
  • Right to object — object to processing for marketing, profiling purposes.
  • Right to complain — file a complaint with the Authority of Information Security (Ministry of Information and Communications) or with us.
  • Right to claim damages — if Huayue's violation causes damage.
  • Right to self-protection — implement data protection measures yourself (change password, enable 2FA, opt-out cookies). To exercise any right, send email to mcy@huayuesc.com — response within 7 business days, processing completed within 30 days.

10. Protection of Children Under 16

Huayuesc is a B2B platform for businesses, NOT intended for children under 16. When registering, users must confirm they are at least 18 years old (or the age of majority under the law of their country of residence). If a child's account is detected, Huayue will immediately disable it and delete all data within 7 days. Parents who discover their child has created an account can contact mcy@huayuesc.com — we will verify and prioritize deletion at no charge.

11. Data Incidents & Notification Procedure

Data Breach Response Plan complying with Article 23 of Decree 13/2023: (Step 1) Detection — 24/7 Security team monitors 365/365, or receives report from Bug Bounty / employees / partners. (Step 2) Containment — within 4 hours, identify scope, stop leak, lock affected systems. (Step 3) Assessment — security forensic determines how many users affected, what data, severity level. (Step 4) Notify authorities — within 72 hours of detection, send report to the Authority of Information Security (Ministry of Information and Communications) using standard template. (Step 5) Notify users — send email/SMS to all affected users within 72 hours, describing incident + exposed data + remediation measures + recommendations (change password, enable 2FA, monitor account). (Step 6) Remediation — fix vulnerability, audit entire system, make post-mortem report public within 30 days. (Step 7) Compensation — if user proves direct damages, Huayue has a transparent compensation policy.

12. Policy Updates & DPO Contact

This policy is reviewed by Huayue at least once a year and updated when there are changes in law, technology, or services. The current version is v1.0, effective January 1, 2026. Previous versions are archived at /info/privacy-policy/lich-su for reference. When material changes occur (affecting user rights), Huayue will notify via:

  • Email to all active users at least 30 days before implementation.
  • Banner displayed on website/app for 60 days.
  • Request user re-consent if processing purpose changes. Contact DPO (Data Protection Officer): Email mcy@huayuesc.com (response <72h), hotline 000-000-000 (business hours), postal mail 'DPO — Huayue Supply Chain Vietnam Company Limited', Ecolife Building, 58 To Huu, Dai Mo Ward, Nam Tu Liem District, Hanoi City, Vietnam. Competent authority for independent complaints: Authority of Information Security (Ministry of Information and Communications), 18 Nguyen Du, Hanoi — website ais.gov.vn.
Huayuesc's Commitment
  • Data Controller Entity: Huayue Supply Chain Vietnam Co., Ltd. (Tax Code 0111453693)
  • Compliant with Decree 13/2023/NĐ-CP (Vietnam) + PIPL 2021 (China) + GDPR where applicable
  • Aiming for ISO/IEC 27001:2022 certification
  • Encryption: TLS 1.3 (in transit) + AES-256-GCM (at rest), bcrypt for passwords
  • 11 data subject rights — response within 7 days, resolution within 30 days
  • Cross-border transfer VN-CN via SCCs + registration with the Authority of Information Security in progress
  • Pen-test 2 times/year + Bug Bounty $100-5,000
  • Data breach notification within 72 hours per Article 23 of Decree 13/2023
  • DPO: mcy@huayuesc.com — hotline 000-000-000

FAQs

Does Huayue sell my data to third parties?

ABSOLUTELY NOT. Huayue's business model relies on supply chain services (commission from transactions, logistics fees, customs clearance fees), NOT on selling data. We do not share data with data brokers, marketing aggregators, or any third parties not directly involved in your transaction.

Can I request deletion of all my data?

Yes. Send an email to mcy@huayuesc.com with subject 'Data Deletion Request — [account name/email]'. Huayue verifies identity (via OTP), performs hard-delete within 30 days, and provides a 'Certificate of Erasure' upon request. Note: tax records (invoices) must be retained for 10 years under Vietnam Tax Administration Law — this part cannot be deleted.

Is my data transferred to China?

It may be, if your transaction requires support from Huayue's Guangzhou representative office (factory audits, product inspection, dispute handling). Cross-border data transfer between Vietnam and China is protected by internal Standard Contractual Clauses (SCCs) and TLS 1.3 encryption; Huayue is in the process of completing registration with the Vietnam Information Security Authority under Article 25 of Decree 13/2023. You have the right to request NO transfer — email the DPO, and we will respect that, although it may limit on-site audit services.

Is my password safe if Huayue gets hacked?

Yes. Huayue uses bcrypt hashing with work factor 12 + per-user salt + pepper — even if the database is leaked, passwords would take billions of years of computer power to crack. However, we still recommend you: (1) use a strong and unique password, (2) enable 2FA at /buyer-center/settings/security, (3) change your password if you hear of a breach at other sites where you use the same email.

I received a strange email claiming to be from Huayue — how can I verify?

Official Huayue emails always come from the @huayuesc.vn domain. Transaction emails come from mcy@huayuesc.com. Emails from DPO/HR have the @huayuesc.vn domain. If in doubt, forward the email to mcy@huayuesc.com and we will verify within 4 hours. Golden rule: Huayue NEVER asks for a password via email/phone.

Ready to start sourcing?

Send a free RFQ, get quotes from 5–10 suppliers within 24h. No middlemen, no hidden fees.