PERSONAL DATA PROTECTION POLICY

This Personal Data Protection Policy of customers (the “Policy”) is intended to inform the Customer of the Personal Data processed by PUREHIGH COMPANY LIMITED (“PUREHIGH”), the purposes and methods of processing, the retention period, the sharing of Personal Data, and the Customer’s rights with respect to their own Personal Data in accordance with the personal data protection laws of Vietnam. This Policy also provides recommendations to the Customer to raise awareness of personal data protection and to avoid unwanted damage that may arise in the course of PUREHIGH’s processing of the Customer’s Personal Data.

Legal basis:

  • Law on Personal Data Protection No. 91/2025/QH15, passed by the National Assembly on 26 June 2025;
  • Law on Cyber Security No. 24/2018/QH14, passed by the National Assembly on 12 June 2018;
  • Law on Electronic Transactions No. 20/2023/QH15, passed by the National Assembly on 22 June 2023;
  • Decree No. 356/2025/ND-CP dated 31 December 2025 of the Government detailing a number of articles of, and measures to implement, the Law on Personal Data Protection.

This Policy consists of the following contents:

Article 1. Definitions

Article 2. Processing of personal data

Article 3. Purposes of processing personal data

Article 4. Methods of processing personal data

Article 5. Commencement and termination of personal data processing

Article 6. Sharing of personal data

Article 7. Storage of personal data

Article 8. Control of personal data

Article 9. Protection of personal data

Article 10. Unintended consequences and damage that may occur

Article 11. Processing of personal data without the consent of the data subject

Article 12. Contact information

Article 13. Amendments and modifications

By accessing or using the Website and accepting our use of cookies, you acknowledge that you have read, understood, and agree to be bound by this Commitment, PureHigh’s Privacy Policy, Cookie Policy, Terms of Use, and other applicable policies published by PureHigh

Article 1. DEFINITIONS

For the purposes of this Policy, unless the context otherwise requires, the following terms shall be construed as follows:

1.1. PUREHIGH: Means PUREHIGH COMPANY LIMITED, its branches, representative offices, business locations, and affiliated units within its operating structure located in the territory of Vietnam. Depending on the specific transaction scenario, PUREHIGH acts as the Personal Data Controller or the Personal Data Controller and Processor in accordance with the Law on Personal Data Protection 2025.

1.2. Customer (Data Subject): Means any individual falling within one of the following groups:

  • An individual, or the lawful representative or authorized representative of an individual or organization, who uses and/or proactively expresses interest in PUREHIGH’s training courses, consulting services, or coaching services;
  • An individual, or the lawful representative of an individual, who has accessed, registered, or successfully created a student account on PUREHIGH’s Website (www.purehigh.edu.vn), mobile application, or web-based learning platform, lawfully owned, managed, and operated by PUREHIGH;
  • Definition of an act expressing interest: Includes proactive actions by an individual such as: providing consent on PUREHIGH’s Website; leaving contact information via online chat to request course consultation; sending an email/calling the hotline to request information on a training program; registering to attend a workshop or a trial (demo) class; participating in and/or receiving gifts from PUREHIGH’s programs; or participating in a training-needs survey conducted by PUREHIGH.

1.3. PUREHIGH’s Products and Services: Means the entire ecosystem of training and consulting offered by the Company, including:

  • Training services: Training courses in business, marketing, management, strategy, service, finance, accounting, human resources, and technology; soft-skills training; professional coaching and personal development, delivered in-person, online, or in a hybrid format;
  • Online learning platform: The development, operation, and management of the training platform on PUREHIGH’s website and mobile application, including student accounts, lectures, course materials, assessments, and course-completion certificates;
  • Consulting services and affiliated solutions: Strategic consulting, corporate management consulting, the organization of workshops/training events, or solutions for operating the online training platform, provided by PUREHIGH in cooperation with third parties (instructors, cooperating experts, technology infrastructure providers, and intermediary payment gateways) in order to deliver a complete service to the Customer.

1.4. Personal Data: Means information in the form of symbols, letters, numbers, images, sounds, or similar forms in an electronic environment that is associated with, or capable of identifying, a specific individual, classified into Basic Personal Data and Sensitive Personal Data as detailed in Article 2 of this Policy.

1.5. Processing of Personal Data: Means one or more operations performed on the Customer’s personal data by PUREHIGH, including: collecting, recording, analyzing, storing, modifying, combining, accessing, retrieving, recovering, encrypting, anonymizing, deleting, or destroying data within the territory of Vietnam.

Article 2. PROCESSING OF PERSONAL DATA

2.1. Circumstances in which PUREHIGH processes Personal Data: PUREHIGH collects and processes the Customer’s Personal Data in the following circumstances arising from its training and consulting activities:

  • When the Customer or their lawful representative proactively contacts PUREHIGH via Hotline, Email, Fanpage, or directly at the office to request consultation on a course or a consulting/coaching solution;
  • When the Customer registers for, enters into a service agreement for, pays tuition for, and uses PUREHIGH’s Products and Services;
  • When the Customer accesses, registers for, creates, and uses a student account on the Website (www.purehigh.edu.vn), mobile applications, or the learning Web App lawfully owned and managed by PUREHIGH;
  • When the Customer participates in and proactively provides information at public events organized, sponsored, or co-organized by PUREHIGH, including: workshops, trial classes, customer-appreciation events, minigames, training-needs surveys, or Cookies lawfully collected when accessing PUREHIGH’s Website/learning platform;
  • When the Customer permits technology infrastructure partners or intermediary payment gateways to transfer or share the Customer’s registration and contact information with PUREHIGH for the purpose of completing registration and delivering the course;
  • When there is a legally binding written request from a competent State authority (Tax Authority, Police, education management authority) in accordance with the law;
  • Exemption clause for indirect data sources: When receiving Personal Data from a third party (cooperating instructors, event partners), such third party bears sole responsibility for warranting that the data was lawfully collected, processed, and transferred, and that the consent of the Data Subject was obtained in accordance with applicable law. PUREHIGH is deemed to rely in good faith on the lawfulness of data provided by such third party and is exempted from all legal liability, damages, or claims relating to the origin of such data. Any violation or dispute arising therefrom (if any) shall be the sole responsibility of the third party that provided the data.

2.2. Categories of Personal Data processed: To serve the minimum and legitimate purposes of providing training services, the categories of Customer data processed by PUREHIGH include:

2.2.1. Basic personal data:

  • a) Full name (surname, middle name, and given name);
  • b) Date of birth;
  • c) Gender;
  • d) Permanent address, temporary address, current residential address, address for sending tuition invoices/documents;
  • e) Nationality;
  • f) Personal images (collected via security surveillance cameras at the Company’s offices and classrooms, or images proactively provided by the Customer when attending classes, events, or for the issuance of a course-completion certificate); the front side of the national ID card, where required to authenticate identity for certificate issuance or for entering into a training service agreement;
  • g) Contact phone number, personal identification number/national ID card number/passport number (for entering into a training service agreement or authenticating certificate issuance), personal tax code (for issuing tuition invoices);
  • h) Student account information; learning history, learning outcomes, course-completion progress, and the Customer’s interaction history on PUREHIGH’s Website and learning platforms.

2.2.2. Limitations on Sensitive Personal Data: PUREHIGH does not proactively collect the Customer’s sensitive information. The Company only processes bank account or e-wallet information (excluding passwords and OTP codes) provided by the Customer or transferred by the intermediary payment gateway upon reconciliation, solely for the purpose of verifying tuition payment flows, reconciling accounts, and refunding tuition to the Customer where applicable in accordance with the applicable procedure.

2.3. Mandatory information and disclaimer of service provision: PUREHIGH will clearly display the “Mandatory” information fields required (including full name, phone number, email, and tuition payment information) at the time the Customer registers for a course. The Customer understands and agrees that, if they refuse to provide such mandatory data, PUREHIGH will not have sufficient technical and legal grounds to process the course registration or provide the consulting service package. In such case, PUREHIGH reserves the right to refuse to provide its Products and Services to the Customer and is fully exempted from any liability for damages or contractual penalties.

2.4. Exemption from liability for data provided beyond the Customer’s requirements: The Customer may voluntarily provide additional information beyond the categories requested by PUREHIGH in course reviews, public comments, or consultation chats. By proactively providing such information, the Customer agrees that PUREHIGH may process such data for the purpose of assisting the Customer.

The Customer undertakes not to proactively provide other sensitive personal data (such as data on health status, judicial records, sexual orientation, political views, or religion) beyond the scope requested by the Company. PUREHIGH does not process or intentionally store such data and is fully exempted from legal liability for any risk of leakage or loss relating to such excess sensitive data voluntarily provided by the Customer.

Article 3. PURPOSES OF PROCESSING PERSONAL DATA

PUREHIGH may process the Customer’s Personal Data for one or several of the following purposes (the “Purposes”), including but not limited to:

3.1. Verifying the accuracy and completeness of information provided by the Customer; identifying or authenticating the Customer’s identity and carrying out the Customer authentication process; processing the registration and use of PUREHIGH’s Products and Services;

3.2. Managing and evaluating training activities, including designing, improving, and enhancing the quality of PUREHIGH’s courses and consulting programs; conducting research on training needs, surveys, and data analysis relating to PUREHIGH’s Products and Services;

3.3. Contacting the Customer to exchange information, resolve requests or complaints, send tuition invoices, course materials, or other documents relating to PUREHIGH’s Products and Services through various channels (e.g., email, chat), and to respond to the Customer’s requests;

3.4. Marketing and introducing courses based on the Customer’s proactive interest and choice: PUREHIGH is committed to respecting the Customer’s privacy and choices in all communication activities. PUREHIGH will only use Personal Data to contact, introduce, or advertise courses, tuition discount programs, surveys, or events when, and only when, it has received proactive interest, engagement, or prior consent from the Customer through official interaction channels.

Where the Customer no longer wishes to receive contact, consultation, or marketing communications from PUREHIGH, the Customer may withdraw consent at any time by ticking the box “I do not wish to receive any communication or notification for advertising or marketing purposes from PUREHIGH” on the digital interface, or by sending a direct opt-out notice via the Email/Hotline specified in this Policy. PUREHIGH shall receive, record, and cease all marketing contact activities toward the Customer within 24 hours of receiving such request.

3.5. Preparing financial statements, operational reports, and other statutory reporting obligations: PUREHIGH uses the Customer’s Personal Data to build, compile, and store accounting reports, financial statements, audit reports, and periodic tax settlements in accordance with applicable law;

3.6. Complying with and enforcing legal obligations and requests from State authorities: PUREHIGH stores, processes, and provides the Customer’s Personal Data in order to comply with legal obligations arising from the provision of training services, to resolve Customer complaints, or to serve inspection, examination, and supervision activities of competent State authorities in accordance with the law;

3.7. Preventing fraud and protecting the safety and lawful interests of the Customer: PUREHIGH may use the Customer’s information to identify, prevent, and address fraudulent acts, tuition payment fraud, impersonation of a student’s identity, or abuse of the Company’s discount/scholarship programs;

3.8. Internal administration and operational optimization: Data is processed to serve PUREHIGH’s internal control purposes, including: internal audit, management of data stored on centralized servers, research and development (R&D) of new training programs, KPI evaluation of instructors and staff, and upgrading the security of the Company’s entire information technology infrastructure (LMS/CRM/Website);

3.9. Other lawful and ancillary purposes arising from the transactional relationship: PUREHIGH processes data for any other purpose that is directly, logically, or ancillary related to the purposes set out in Sections 3.1 to 3.8 of this Policy, or for other purposes separately agreed to in writing by the Customer during the course of using PUREHIGH’s Products and Services.

Article 4. METHODS OF PROCESSING PERSONAL DATA

PUREHIGH applies one or more of the following operations to Personal Data: collecting, recording, analyzing, verifying, storing, editing, disclosing, combining, accessing, retrieving, recovering, encrypting, decrypting, copying, sharing, transmitting, providing, transferring, deleting, destroying personal data, or other related actions.

Article 5. COMMENCEMENT AND TERMINATION OF PERSONAL DATA PROCESSING

5.1. Commencement of data processing: PUREHIGH’s processing of the Customer’s Personal Data officially commences from the time the Customer performs one of the following acts:

  • The Customer confirms acceptance of the entire content of this Policy electronically (by ticking the consent box on the Website/Web App) or by signing a direct written consent document;
  • The Customer proactively leaves contact information on PUREHIGH’s system to request consultation on a course or a consulting solution package;
  • A service agreement for training or consulting between PUREHIGH and the Customer is lawfully established.

Data processing activities will be maintained continuously and will apply to all personal data arising throughout the Customer’s use of PUREHIGH’s Products and Services.

5.2. Termination of data processing: PUREHIGH will fully cease processing the Customer’s Personal Data and take the necessary technical measures to permanently delete or fully anonymize such data in the following circumstances:

  • Completion of Purpose: PUREHIGH has fully completed all data-processing purposes set out in Article 3 of this Policy, and the contractual obligations relating to the training/consulting service have terminated;
  • At the request of the Data Subject: The Customer proactively submits a written request to withdraw consent or to delete personal data, and such request has been verified as lawful and not in violation of mandatory storage obligations under applicable law;
  • Dissolution or cessation of the enterprise: PUREHIGH ceases its legal existence in accordance with the law, and the data will be destroyed or transferred in accordance with the procedures set out under the Law on Personal Data Protection 2025;
  • Exception for mandatory retention: Except where specialized Vietnamese law requires PUREHIGH to continue storing data (including the obligation to retain accounting records, invoices, and financial documents for tax settlement purposes under the Law on Accounting and the Law on Tax, or records of learning outcomes/course-completion certificates for future verification purposes upon request), the Customer’s data will no longer be accessible or usable for any other purpose after such termination.

Article 6. SHARING OF PERSONAL DATA

6.1. Recipients and scope of sharing the Customer’s Personal Data: In order to optimally achieve the Purposes set out in this Policy, PUREHIGH may share the Customer’s Personal Data with the following limited categories of recipients:

6.1.1. Subsidiaries, affiliated companies, and units under PUREHIGH: The sharing of data within the internal system of PUREHIGH’s affiliated units is carried out for the purpose of centralized database administration, operational optimization, and coordinated delivery of training programs to the Customer. PUREHIGH undertakes that such units shall strictly comply with internal security standards equivalent to those set out in this Policy.

6.1.2. Third-party service providers and strategic partners: PUREHIGH cooperates with professional organizations and individuals to perform, on the Company’s behalf, work within its operational chain, including:

  • Technology infrastructure partners: Providers of cloud storage services, learning management systems (LMS), CRM/ERP administration solutions, and units operating the technical infrastructure of the Company’s Website and Web App;
  • Marketing and communications partners: Communications companies (agencies) and digital advertising platforms, for the purpose of conducting training-needs surveys, trend analysis, and optimizing marketing campaign content in accordance with Section 3.4;
  • Payment and financial partners: Commercial banks, intermediary payment institutions, and online payment gateways, for the purpose of authenticating and processing tuition payment transactions, managing accounts receivable, and reconciling the Customer’s financial invoices;
  • Instructors, experts, and training cooperation partners: Individuals or organizations participating in teaching or coaching, or affiliated units issuing course-completion certificates, to the extent necessary to deliver the training program.

Such third parties are only permitted to access, collect, and process personal data fields to the minimum extent genuinely necessary to perform their authorized function in accordance with the law. These partners must also undertake in writing or under contractual terms to maintain confidentiality and comply with personal data protection law.

6.1.3. Business transfer and restructuring: In the course of its business development, PUREHIGH may carry out mergers, acquisitions, divisions, consolidations, or corporate restructuring in accordance with the law. In such commercial transactions, the customer database is recognized as a lawful business asset and will be transferred to the transferee. However, the transferee shall remain bound to inherit and strictly comply with the data protection commitments set out in this Policy and under the Law on Personal Data Protection 2025.

6.1.4. Protection of PUREHIGH’s rights, assets, and lawful interests, and those of related parties: PUREHIGH has the right and the obligation to disclose the Customer’s Personal Data in circumstances required by law, including: pursuant to a legally binding written request from an Investigation Agency, Tax Authority, Court, or other competent State authority; to enforce the terms of a training/consulting service agreement; or to protect the security, assets, and lawful interests of PUREHIGH, its staff, and other customers against cyberattacks, sabotage, or fraud.

6.1.5. Sharing of data based on the Customer’s additional choice and consent: Except for cases where the law provides that the consent of the data subject is not required, or the cases already set out in this Policy, the Customer’s Personal Data will not be shared with any other third party without prior notice to, and the consent of, the Customer.

The Customer has the right to refuse such additional sharing of information. Where the Customer refuses, the Customer’s core services (which are capable of independent operation) remain assured; however, PUREHIGH is exempted from any liability if the Customer’s refusal results in the inability to initiate, perform, or leads to the interruption of features, linked services, or promotional programs that depend on data processing with such third party.

6.2. Commitment regarding the non-profit purpose of data sharing: PUREHIGH undertakes not to commercialize, sell, speculate on, or share the Customer’s Personal Data with third parties for the purpose of seeking direct profit from such data in any form, in violation of Vietnamese law.

Article 7. STORAGE OF PERSONAL DATA

7.1. Technical and organizational measures for the security of Personal Data: PUREHIGH undertakes to apply rigorous personal data protection measures, combining administrative management standards with advanced technological solutions, to guard against unauthorized access, theft, alteration, disclosure, or destruction of data. Such measures include:

  • Technological measures: The system operates on the technology infrastructure of reputable partners, satisfying applicable security and information safety standards. Such partners are directly responsible for maintaining technical measures (encryption, firewalls, intrusion prevention) to protect the safety of the Customer’s data within the scope of the platform provided;
  • Administrative measures: Issuing minimum-access authorization procedures, strictly controlling system log history for a minimum of 12 months as set out in this Policy; and organizing periodic security-awareness training programs for staff;
  • Limitation of liability for cyber incidents: The Customer acknowledges that no network infrastructure system or data transmission solution on the Internet can be guaranteed to be 100% secure. In the event of a system disruption or a cyberattack beyond the reasonable control of current technology, PUREHIGH will immediately activate its incident-response procedure and notify the competent authorities and the affected data subjects within the statutory period to minimize damage, and shall be exempted from liability for damages not directly caused by the Company’s fault.

7.2. Storage location and commitment not to transfer data abroad:

The Customer’s Personal Data is stored centrally at PUREHIGH:

  • Company name: PUREHIGH COMPANY LIMITED
  • Address: 2 Alexandre De Rhodes, Sai Gon Ward, Ho Chi Minh City, Vietnam
  • Phone/Hotline: +84 917 464 679
  • Email: [ENTER PUREHIGH’S OFFICIAL CONTACT EMAIL]
  • Website: www.purehigh.edu.vn

PUREHIGH undertakes that all Personal Data of Customers, Partners, and Employees collected in the course of its training and consulting operations is stored, processed, and administered solely within the territory of the Socialist Republic of Vietnam. The Company’s centralized database is securely stored on physical servers located at internationally certified Data Centers within Vietnam and/or on the cloud storage infrastructure of reputable technology service providers with legal entities and infrastructure located in Vietnam, ensuring full compliance with applicable technical security and cybersecurity standards.

PUREHIGH undertakes not to transfer, transmit, store, or permit any organization or individual to extract the Customer’s Personal Data outside the territorial borders of Vietnam in any form, except where the Customer has given consent or as otherwise provided by law.

7.3. Specific data retention periods:

  • Data used for marketing purposes: Data relating to behavioral history, preferences, and contact information used for marketing purposes will be retained for as long as the Customer maintains proactive interest and engagement with the Company, or until the Customer submits a request to delete data or withdraw consent under the applicable procedure;
  • Data used to fulfil mandatory legal obligations: Identification information, course-registration history, payment records, financial invoices, and records of learning outcomes/course-completion certificates will be retained for the period prescribed under the applicable Law on Accounting and Law on Tax, or for such period as necessary to verify certificates upon request, regardless of whether the Customer has ceased using the service. After such period, the data will be destroyed or fully anonymized.

Article 8. CONTROL OF PERSONAL DATA

8.1. Right to be informed and right to consent: By way of this Policy, PUREHIGH fulfils its obligation to transparently inform the Customer of the purpose, scope, method, and parties involved in the processing of Personal Data prior to collection and processing. The Customer has the right to freely express consent or refusal by ticking or not ticking the box “I have read, understood, and agree to PUREHIGH’s Personal Data Protection Policy” set out on the digital interface, or by signing a written confirmation.

8.2. Right of access and to request the provision of Personal Data: The Customer has the right to directly access their personal account on PUREHIGH’s Website/Web App to review and extract their own data. Where this cannot be done due to technical limitations, the Customer may submit a written request or contact PUREHIGH directly using the information set out in Article 12 of this Policy to receive support within 72 hours.

8.3. Right to correction of Personal Data: The Customer has the right to correct or amend their own personal data directly on the system, or to submit a request to PUREHIGH. Upon verifying the identity of the requester, PUREHIGH will update the data accurately in accordance with its internal procedures within a maximum of 72 working hours. Such correction or amendment shall apply only to future matters and shall not alter, distort, or affect the legal validity of records or documents already completed.

8.4. Right to object, restrict, and withdraw consent to processing: With respect to marketing communications regarding courses or consulting services based on the Customer’s interest (under Section 3.4), the Customer has the right to object to or withdraw consent to such processing at any time by ticking the box “I do not wish to receive any communication or notification for advertising or marketing purposes from PUREHIGH” on the digital interface, or by contacting the Company via Email/Hotline. PUREHIGH shall immediately cease all marketing contact with the Customer within 24 hours of receiving such request.

8.5. Right to deletion of Personal Data: The Customer has the right to request that PUREHIGH permanently delete their Personal Data from its servers and CRM system. However, the right to deletion may only be exercised where doing so does not violate document-retention obligations under the Law on Tax and the Law on Accounting.

The Customer acknowledges and understands that the deletion of core personal data (such as phone number, address, financial history) may result in PUREHIGH no longer having the technical means to continue providing training/consulting services under the agreement. In such case, PUREHIGH has the right to unilaterally terminate the service agreement without liability for damages arising from the change in performance conditions resulting from the Customer’s choice. PUREHIGH will complete the deletion or anonymization of eligible data within 72 hours of the request being approved.

8.6. Right to complain: Where the Customer has grounds to demonstrate that PUREHIGH has processed data for improper purposes, caused a data leak, or violated the commitments in this Policy, the Customer has the right to submit a complaint directly to the Company’s Board of Directors for resolution through an internal mediation process.

Article 9. PROTECTION OF PERSONAL DATA

9.1. Limitation of obligations and disclaimer of liability of PUREHIGH:

  • PUREHIGH applies administrative management measures, internal access-authorization procedures, and such technological solutions as the Company is reasonably capable of, to protect the Customer’s Personal Data and to prevent unauthorized access or information leakage within the Company’s actual practical control;
  • The Customer acknowledges and unconditionally agrees that, in the cyberspace and Internet environment, no technical security system or cloud storage solution is 100% absolutely secure. Accordingly, PUREHIGH makes no absolute warranty that its system will never be attacked, unlawfully accessed, or subject to a force majeure incident;
  • PUREHIGH is exempted from legal liability and liability for damages towards the Customer and any third party in force majeure incidents such as: disruption, leakage, loss, or alteration of data on the servers, CRM, ERP, Website, or Web App due to deliberate cyberattacks by third parties (hackers, malware, viruses, DDoS attacks), nationwide Internet connectivity failures, widespread power grid failures, or other force majeure events as provided by law; or data leakage incidents arising from software defects or security flaws of technology infrastructure providers lawfully engaged by PUREHIGH.

9.2. Obligations and responsibilities of the Customer: The Customer undertakes and is responsible for fully performing the following mandatory obligations in order to protect information security and to safeguard the interests of both the Customer and PUREHIGH:

  • Obligation to self-secure authentication information: The Customer is responsible for managing the passwords, accounts, and personal devices used to access PUREHIGH’s system, and for keeping login credentials strictly confidential. PUREHIGH is exempted from liability where the Customer’s account is accessed, altered, or data is misappropriated by a third party due to the Customer’s exposure of their password, loss of a device, or shared use of an account;
  • Obligation to ensure the accuracy and lawfulness of data provided: The Customer is obligated to provide Personal Data accurately, truthfully, completely, and on an up-to-date basis. The Customer shall not use a false identity or another person’s phone number or information without that person’s lawful consent to register for a course at PUREHIGH;
  • Indemnification of PUREHIGH: Where the Customer provides inaccurate, outdated, or unlawful information that results in PUREHIGH issuing an incorrect VAT invoice, issuing an incorrect course-completion certificate, or in the Company being subject to an administrative penalty by a competent State authority for a personal data protection violation, the Customer shall be liable to fully indemnify PUREHIGH for all actual material damages, handling costs, and fines incurred;
  • Obligation to proactively stay informed of policy updates: PUREHIGH has the right to amend, supplement, and update this Policy from time to time to reflect changes in the law and its training/consulting business model. Amended versions will be publicly posted on the official Website (www.purehigh.edu.vn). The Customer’s continued use of the service after the posting of an amended version shall be deemed as the Customer’s acceptance of such amendments;
  • Respect for the data of other data subjects: The Customer undertakes to respect the privacy and personal data of related parties (such as instructors, PUREHIGH staff, or other students). It is strictly prohibited to collect, film, photograph, use, or disclose the personal information of others without their consent. Upon discovering any sign of system error or security violation, the Customer is responsible for immediately notifying PUREHIGH via the hotline so that the Company can promptly prevent the incident.

Article 10. UNINTENDED CONSEQUENCES AND DAMAGE THAT MAY OCCUR

10.1. Technology risk management and exemptions from liability for force majeure consequences: PUREHIGH applies technological solutions appropriate to the actual infrastructure capacity available in Vietnam to minimize the risk of unauthorized access or unintended information leakage. However, the Customer acknowledges and agrees that, in the electronic cyberspace environment, no security solution is absolutely secure. Accordingly, PUREHIGH is exempted from legal liability and any obligation to pay damages arising from incidents beyond the Company’s reasonable control, including but not limited to:

  • Force majeure technical incidents: Widespread network system failures, national Internet connectivity disruptions, large-scale power grid failures, or hardware/software failures arising from an intermediary infrastructure provider lawfully engaged by PUREHIGH;
  • Deliberate and organized cyberattacks by third parties (hackers, viruses, malware, ransomware, DDoS attacks) exceeding the defensive capability of standard security technologies at the time of the incident;
  • Errors, negligence, or omissions of the Customer themselves: The Customer disclosing their own authentication information, being deceived by a scam, accessing counterfeit websites, or downloading applications of unknown origin containing malware that leads to account infection and takeover.

10.2. Recommendation for the Customer to fulfil self-protection obligations: PUREHIGH strongly recommends that the Customer proactively and strictly comply with the self-security obligations for their account, devices, and passwords as set out in Article 9.2 of this Policy.

10.3. Emergency response procedure for data breach incidents: In the event that the data storage system is detected to have been unlawfully accessed, leading to the risk of loss or leakage of the Customer’s Personal Data, PUREHIGH will immediately activate its emergency response procedure as follows:

  • Technical remediation: PUREHIGH coordinates with its service providers and cybersecurity experts to promptly identify the affected data, isolate the compromised system component, halt the flow of the data leak, and patch the system vulnerability;
  • Reporting to the competent authorities: In accordance with applicable law;
  • Notification to the Customer: PUREHIGH will make a public announcement of the incident or send direct notice to affected Customers via official channels (Website, Email, or SMS), to guide the Customer on proactive measures to prevent further damage (such as changing passwords or temporarily locking accounts). PUREHIGH is fully exempted from liability for damages if it has correctly and fully implemented this emergency response procedure.

Article 11. PROCESSING OF PERSONAL DATA WITHOUT THE CONSENT OF THE DATA SUBJECT

The Customer acknowledges and agrees that, in the specific circumstances below, PUREHIGH may collect, record, store, use, or share the Customer’s Personal Data without obtaining the Customer’s prior or additional consent, in accordance with applicable law:

  • Protecting the life and health of the Customer or others in an emergency: PUREHIGH may use and provide the Customer’s contact and transactional information to medical authorities or competent State authorities for the purpose of emergency response to situations directly threatening the life or health of the Customer or the community;
  • Public disclosure of personal data pursuant to specialized law: PUREHIGH discloses the Customer’s personal data (if any) where such disclosure is mandatory under specialized law, including announcing the list of Customers who won prizes in an event/minigame, or publishing the list of students who obtained a course-completion certificate where the Customer has consented;
  • Processing at the request of a competent State authority in an emergency: PUREHIGH provides and extracts the Customer’s data at the mandatory request of a competent State authority to serve national defense, national security, or an emergency arising from a natural disaster, catastrophe, or epidemic outbreak;
  • Serving the operations of a competent State authority as prescribed by law: PUREHIGH fulfils its obligation to provide the Customer’s Personal Data (including course-registration history, identification information, outstanding financial obligations, and invoices/documents) at the legally binding written request of an Investigation Agency, People’s Procuracy, Court, Tax Authority, or specialized Inspectorate for the purpose of inspection, examination, investigation, resolution of complaints or litigation, or corporate tax settlement in accordance with the law.

Article 12. CONTACT INFORMATION

Should the Customer have any questions regarding this Policy, or wish to exercise their rights in relation to Personal Data, please contact PUREHIGH using the following details:

12.1. Direct contact: PUREHIGH COMPANY LIMITED

  • Address: 2 Alexandre De Rhodes, Sai Gon Ward, Ho Chi Minh City, Vietnam
  • Phone/Hotline: +84 917 464 679
  • Official website: www.purehigh.edu.vn

12.2. Other contact channels such as Livechat, PUREHIGH’s official fanpage, or the customer-care email provided to the Customer.

Article 13. AMENDMENTS AND MODIFICATIONS

PUREHIGH may amend this Policy at any time and will publicly post the amended Policy on PUREHIGH’s official information channels. The Customer’s continued use of PUREHIGH’s Products and Services, without raising any complaint regarding the amended Policy, shall be deemed as the Customer’s acceptance of such amended Policy.

 

Note: By accessing or using the Website and accepting our use of cookies, you acknowledge that you have read, understood, and agree to be bound by this Commitment, PureHigh’s Privacy Policy, Cookie Policy, Terms of Use, and other applicable policies published by PureHigh.