1. Scope & Definitions
This policy applies to all services at Huayuesc (huayuesc.vn), including the B2B website, the mobile app (iOS/Android coming soon), and every offline interaction with the Huayue team at the Hanoi headquarters and the Guangzhou procurement representative office. Definitions: 'Personal data' = information that can directly or indirectly identify an individual (per Article 2 of Decree 13/2023). 'User' = Buyer (Vietnamese individual/business), Supplier (Chinese supplier), Visitor (not registered). 'Data controller' = Huayue Supply Chain (Vietnam) Co., Ltd. (Tax ID 0111453693, headquartered at Bao Ngoc Building, Xuan Phuong, Hanoi). 'Data processor' = authorized service providers (cloud hosting, payment processors, logistics partners). 'Consent' = informed, voluntary and explicit approval per Article 11 of Decree 13/2023.
βPrivacy is not a checkbox β it is a process. Huayue is committed to being transparent about how Vietnamese Buyers' data is handled across the VietnamβChina border, with no secrets and no legal language designed to trick you.β
2. Information We Collect
We collect 5 main data groups:
- Account information β full name, email, phone number, company, tax ID, delivery address, password (bcrypt-hashed).
- Transaction information β RFQs, orders, favorited products, payment history (status only, no card numbers stored β handled by the partner payment processor), tracking numbers, dispute history.
- Device & log information β IP address, user agent, OS, browser, language, access time, pages viewed (kept 90 days for analytics and security audit).
- Communication content β chat with suppliers via the platform, video call transcripts (saved only when the user confirms), email sent through the system, and review comments.
- Third-party information β when signing in via Google/Apple/Facebook, Huayue receives: email, name, avatar (only the fields you agree to share via the OAuth consent screen). We do NOT collect: national ID/passport numbers (except when KYC is required for transactions of $10K or more), biometric data, medical data, religion or political opinions (per the definition of 'sensitive personal data' in Article 2.4 of Decree 13/2023).
3. Purposes & Legal Basis for Processing
Huayue processes data on 4 legal bases under Article 11 of Decree 13/2023:
- Consent β you check 'I agree' at registration and may withdraw at any time.
- Contract performance β processing data needed to provide the agreed B2B services (RFQs, ordering, shipping, after-sales).
- Legal obligation β retaining tax records for 10 years under Vietnam's Tax Administration Law, and storing e-invoices under Decree 123/2020/NΔ-CP.
- Legitimate interest β fraud prevention, system security, product improvement (only where it does not infringe your fundamental rights). Specific purposes: providing and personalizing services, connecting Buyers and Suppliers, processing payment and shipping, sending transaction notifications, preventing fraud/abuse, improving products through aggregate-data analysis, marketing (only with the Buyer's opt-in consent), and complying with the law and requests from authorities.
4. Cookies & Tracking Technologies
Huayuesc uses 4 cookie groups with a clear policy and a cookie management panel at /info/quan-ly-cookies:
- Essential cookies β maintain login, the RFQ cart and language; no consent required under Article 6 of Decree 13/2023 (necessary for service). Examples: csr_session, csr_locale, csr_csrf.
- Analytics cookies β Google Analytics 4 (anonymized IP), Hotjar session replay (masks sensitive fields), Mixpanel funnel. Opt-in required. Kept 24 months.
- Marketing cookies β Facebook Pixel, Google Ads, LinkedIn Insight, TikTok Pixel. Opt-in required. Kept 12 months.
- Supplier partner cookies β activated only when you click into a Supplier's product page (rare). A cookie consent banner appears on your first visit, with 3 options: Accept all / Essential only / Customize. You can change your choice at any time at /buyer-center/settings/privacy.
5. Sharing with Third Parties
Huayue shares data with 5 third-party groups, each bound by a Data Processing Agreement (DPA) requiring compliance with Decree 13/2023 plus GDPR-equivalent standards:
- Suppliers β only the minimum information needed to complete the order is shared (contact name, company, delivery address, requested SKU); email and phone are NOT shared directly β all communication goes through Huayue's relay.
- Partner banks in Vietnam and China for the Trade Assurance escrow service; payment processors for international payments β they see only the minimum information needed to process the transaction and meet KYC.
- Logistics partners and the Hai Phong port customs partner β delivery address, tracking number and customs declaration contents are shared.
- Service providers β AWS Singapore (hosting), Cloudflare (CDN, anti-DDoS), Twilio (SMS OTP), SendGrid (transactional email), Sentry (error tracking, scrubs PII).
- Government authorities β only upon a lawful written request (a search order, a prosecution notice); Huayue publishes an annual Transparency Report on the number of requests received. We NEVER sell data to data brokers or third parties for marketing.
6. Cross-Border VietnamβChina Data Transfers
Huayue operates across the VietnamβChina border: Vietnamese Buyer data may be transferred to the Guangzhou procurement representative office so the Huayue team can support sourcing, factory audits, goods inspection and dispute handling. Cross-border data transfers are protected by 3 layers:
- Standard Contractual Clauses (SCCs) β an internal instrument between the Hanoi headquarters and the Guangzhou representative office of Huayue Supply Chain (Vietnam) Co., Ltd., conforming to the reference template from Vietnam's Ministry of Justice.
- Encryption-in-transit β all VietnamβChina traffic over TLS 1.3 with certificate pinning, cannot be intercepted.
- Cross-border data transfer registration with the Authority of Information Security under Article 25 of Decree 13/2023 β Huayue is in the process of completing this registration. You have the right to ask Huayue NOT to transfer your data to China β we will respect this but may have to limit the on-site factory audit service (which is carried out by the Guangzhou team).
7. Storage & Data Lifecycle
Personal data lifecycle at Huayue follows the 'minimum necessary' principle:
- Active accounts β stored continuously, updated at your request.
- Accounts inactive for 18 months or more β a warning email is sent plus automatic deletion if there is no response within the next 90 days.
- Completed orders β details kept 7 years per Vietnamese tax obligations, then anonymized.
- Transaction records and invoices β kept 10 years under the Tax Administration Law.
- Communication logs (chat, email) β kept 24 months for dispute resolution, then permanently deleted.
- Server logs β 90 days, then aggregated into analytics reports (no PII).
- Cookies β per the time-to-live noted in Section 4. When you request account deletion (a right in Section 9), Huayue hard-deletes within 30 days plus email confirmation plus a 'Certificate of Erasure' on request (for businesses that need an audit trail).
8. Technical & Organizational Security Measures
Technical security measures:
- Transport encryption β TLS 1.3 with forward secrecy, HSTS preload, certificate transparency monitoring.
- Storage encryption β AES-256-GCM for the database at rest, key management via AWS KMS with 90-day key rotation.
- Password hashing β bcrypt with work factor 12 plus per-user salt plus pepper.
- Intrusion detection β Cloudflare layer-7 WAF, AI anomaly detection for login patterns, rate limiting that automatically blocks brute-force attacks.
- Internal access control β principle of least privilege, role-based access control (RBAC), mandatory 2FA for every Huayue employee with production access.
- Audit logging β all data access is logged with timestamp, IP, user and action; logs are kept on a write-once system for 12 months.
- Penetration testing β twice a year by an independent security partner.
- Bug bounty program β report vulnerabilities to privacy@huayuesc.vn for a reward of $100-5,000 depending on severity. Organizational measures: Huayue staff sign an NDA and attend quarterly security training; the AWS Singapore and Vietnam data centers are ISO 27001 certified; the incident response process has an RTO of 4h and RPO of 1h; automatic backups run hourly plus offsite daily.
9. Your 11 Rights under Decree 13/2023
Under Articles 9β22 of Decree 13/2023, you have 11 basic rights over your personal data:
- Right to be informed β knowing what data is collected, why, and for how long.
- Right to consent β approving or declining processing.
- Right of access β requesting to view your data (exported as JSON/CSV within 30 days).
- Right to withdraw consent β at any time, without explanation.
- Right to erasure β 'right to be forgotten', deleting your account and all data within 30 days (except records that must be kept under tax law).
- Right to restrict processing β asking Huayue to temporarily halt data processing while a complaint is resolved.
- Right to data portability β requesting transfer of your data to another provider.
- Right to object β objecting to processing for marketing or profiling.
- Right to complain β filing a complaint with the Authority of Information Security (Ministry of Information & Communications) or with us.
- Right to claim damages β if a Huayue violation causes harm.
- Right to self-protection β taking your own data protection measures (changing your password, enabling 2FA, opting out of cookies). To exercise any right, email privacy@huayuesc.vn β a response within 7 business days, fully processed within 30 days.
10. Protection of Children Under 16
Huayuesc is a B2B platform for businesses and is NOT directed at children under 16. At registration, users must confirm they are 18 or older (or the age of majority under the law of their country of residence). If a child's account is found, Huayue will deactivate it immediately and delete all data within 7 days. Parents who discover their child has created an account can contact privacy@huayuesc.vn β we verify and delete on a priority basis at no charge.
11. Data Incidents & Notification Process
Our Data Breach Response Plan complies with Article 23 of Decree 13/2023: (Step 1) Detection β a 24/7 Security team monitors year-round, or receives reports from the Bug Bounty program / staff / partners. (Step 2) Containment β within 4 hours, identify the scope, stop the leak, lock affected systems. (Step 3) Assessment β security forensics determine how many users are affected, what data, and the severity. (Step 4) Notify the authorities β within 72 hours of detection, file a report with the Authority of Information Security (Ministry of Information & Communications) using the standard template. (Step 5) Notify users β email/SMS to every affected user within 72 hours, describing the incident plus the exposed data plus remediation plus recommendations (change password, enable 2FA, monitor your account). (Step 6) Remediation β fix the vulnerability, audit the whole system, publish a public post-mortem within 30 days. (Step 7) Compensation β if a user proves direct harm, Huayue has a transparent compensation policy.
12. Policy Amendments & DPO Contact
Huayue reviews this policy at least once a year and updates it when the law, technology or services change. The current version is v1.0, effective 01/01/2026. Old versions are archived at /info/privacy-policy/lich-su for reference. For material changes (affecting user rights), Huayue notifies users via:
- Email to every active user at least 30 days before it takes effect.
- A banner on the website/app for 60 days.
- A request for user re-consent if the purpose of data processing changes. Contact the DPO (Data Protection Officer): email privacy@huayuesc.vn (response within 72h), hotline +86 181-2225-6999 (business hours), or by post to 'DPO β Huayue Supply Chain (Vietnam) Co., Ltd.', Floor 07, Bao Ngoc Building, No. 02 Thanh Lam Street, Xuan Phuong Ward, Hanoi, Vietnam. Independent complaints authority: the Authority of Information Security (Ministry of Information & Communications), 18 Nguyen Du, Hanoi β website ais.gov.vn.
- βData controlling entity: Huayue Supply Chain (Vietnam) Co., Ltd. (Tax ID 0111453693)
- βCompliance with Decree 13/2023/NΔ-CP (Vietnam) + PIPL 2021 (China) + GDPR where applicable
- βWorking toward ISO/IEC 27001:2022 certification
- βTLS 1.3 (transit) + AES-256-GCM (rest) encryption, bcrypt for passwords
- β11 data-subject rights β response in 7 days, processed in 30 days
- βCross-border VietnamβChina transfers via SCCs + registration with the Authority of Information Security in progress
- βPen-tests twice a year + Bug Bounty $100-5,000
- βData breach notification within 72 hours per Article 23 of Decree 13/2023
- βDPO: privacy@huayuesc.vn β hotline +86 181-2225-6999
β Frequently Asked Questions
Does Huayue sell my data to third parties?βΎ
ABSOLUTELY NOT. Huayue's business model is based on supply chain services (transaction commission, logistics fees, customs fees), NOT on selling data. We do not share data with data brokers, marketing aggregators, or any third party not directly involved in your transaction.
Can I request deletion of all my data?βΎ
Yes. Email privacy@huayuesc.vn with the subject 'Data deletion request β [account name/email]'. Huayue verifies your identity (via OTP), hard-deletes within 30 days, and sends a 'Certificate of Erasure' on request. Note: tax records (invoices) must be kept 10 years under Vietnam's Tax Administration Law β that portion cannot be deleted.
Is my data transferred to China?βΎ
Possibly, if your transaction needs support from Huayue's Guangzhou representative office (factory audit, goods inspection, dispute handling). Cross-border VietnamβChina transfers are protected by internal Standard Contractual Clauses (SCCs) and TLS 1.3 encryption; Huayue is in the process of completing its registration with Vietnam's Authority of Information Security under Article 25 of Decree 13/2023. You have the right to ask us NOT to transfer β email the DPO, and we will respect it, though we may have to limit the on-site audit service.
Is my password safe if Huayue is hacked?βΎ
Yes. Huayue uses bcrypt hashing with work factor 12 plus per-user salt plus pepper β even if the database leaks, the passwords would take billions of years of computing power to crack. Still, we recommend you: (1) set a strong, unique password, (2) enable 2FA at /buyer-center/settings/security, (3) change your password if you hear of an incident at other sites where you use the same email.
I received a suspicious email claiming to be from Huayue β how do I verify it?βΎ
Official Huayue email always comes from the @huayuesc.vn domain. Transactional email comes from no-reply@huayuesc.vn. DPO/HR email uses the @huayuesc.vn domain. If in doubt, forward the email to privacy@huayuesc.vn and we will verify it within 4 hours. The golden rule: Huayue will NEVER ask for your password by email or phone.
Send a free RFQ and get quotes from 5-10 suppliers within 24h. No middlemen, no hidden fees.




