Privacy Policy

Your privacy matters to us. This comprehensive policy explains how Smartplusflow protects and manages your personal information in accordance with Vietnamese data protection laws.

1

Information Collection and Usage

Smartplusflow collects personal information that you voluntarily provide when using our budget consolidation platform. This includes information you share during account registration, profile setup, and ongoing use of our financial management tools.

Personal Information We Collect:

Full name and contact information including email address and phone number
Account credentials and authentication information for secure access
Financial account information necessary for budget consolidation services
Transaction data and spending patterns to provide personalized insights
Device information and IP addresses for security and technical support
Communication preferences and customer service interactions

We use this information primarily to deliver our core budget consolidation services, helping you track expenses across multiple accounts and gain insights into your spending habits. Your financial data enables us to categorize transactions, identify trends, and provide meaningful budgeting recommendations.

Important Note:

We never collect sensitive financial information such as account passwords or PINs. Our secure integration methods protect your banking credentials while allowing us to access only the transaction data necessary for budget analysis.

2

Data Processing and Legal Basis

Under Vietnamese data protection regulations, we process your personal information based on several legal grounds. Our primary basis is your explicit consent, which you provide when creating an account and agreeing to our terms of service.

We also process certain data based on legitimate business interests, particularly for fraud prevention, security monitoring, and service improvement. When processing is necessary for contract performance – such as providing you with budget analysis reports – we rely on contractual necessity as our legal basis.

Processing Activities Include:

Account management and customer authentication procedures
Financial data analysis and budget recommendation generation
Security monitoring and fraud prevention measures
Customer support and technical assistance provision
Service improvement research and platform optimization
Legal compliance and regulatory reporting requirements

For sensitive financial data, we always obtain explicit consent before processing. You maintain control over this consent and can withdraw it at any time through your account settings or by contacting our privacy team directly.

3

Data Sharing and Third-Party Relationships

Smartplusflow maintains strict controls over data sharing and only works with carefully vetted third-party service providers who meet our high standards for data protection and privacy compliance.

We Never Share Your Data With:

Marketing companies, data brokers, social media platforms for advertising purposes, or any organization that would use your information for commercial gain without your explicit permission.

Authorized Third-Party Services:

Our platform integrates with legitimate financial institutions and certified payment processors to facilitate secure account connections. These partnerships operate under strict data processing agreements that limit access to only the information necessary for providing our services.

Bank integration services for secure transaction data retrieval
Cloud infrastructure providers with Vietnamese data residency requirements
Customer support platforms for handling your service inquiries
Security services for fraud detection and account protection
Analytics providers for service improvement (with anonymized data only)

All third-party processors must comply with Vietnamese data protection laws and maintain equivalent security standards to our own. We regularly audit these relationships and can provide additional details about specific partnerships upon request.

4

Your Privacy Rights and Control Options

Vietnamese data protection law grants you comprehensive rights regarding your personal information. We've designed our platform to make exercising these rights straightforward and accessible through multiple channels.

Your Rights Include:

Access Rights: Request complete copies of all personal data we hold about you
Correction Rights: Update or correct any inaccurate information in your profile
Deletion Rights: Request removal of your data when no longer needed for service provision
Portability Rights: Receive your data in a structured, machine-readable format
Restriction Rights: Limit how we process your information in certain circumstances
Objection Rights: Object to processing based on legitimate interests

How to Exercise Your Rights:

Most privacy controls are available directly through your account dashboard, where you can modify data sharing preferences, update personal information, or download your data history. For more complex requests or account deletion, our privacy team responds to requests within 15 business days.

Quick Access Options:

Log into your account and visit the Privacy Settings section for immediate control over data sharing, marketing communications, and account visibility preferences.

5

Security Measures and Data Protection

Protecting your financial information requires robust security measures that go beyond basic encryption. We've implemented multiple layers of protection designed specifically for financial data handling and storage.

Technical Security Measures:

Bank-grade 256-bit SSL encryption for all data transmission
Advanced tokenization to replace sensitive account numbers
Multi-factor authentication for all account access
Regular security audits and penetration testing procedures
Automated threat detection and response systems
Secure Vietnamese data centers with physical access controls

Our security team monitors systems continuously for unusual activity and maintains incident response procedures that can isolate and address potential threats within minutes. We also conduct regular training for all staff members who handle customer data.

Data Access Controls:

Access to your personal information is strictly limited to authorized personnel who require it for their specific job functions. All access is logged and regularly reviewed to ensure compliance with our internal data handling policies.

Breach Notification Commitment:

In the unlikely event of a security incident affecting your data, we will notify you within 72 hours and provide clear information about what happened, what data was involved, and what steps we're taking to address the situation.

6

Data Retention and Deletion Procedures

We retain your personal information only as long as necessary to provide our services and comply with Vietnamese legal requirements. Our retention policies balance your privacy interests with practical needs for account management and regulatory compliance.

Retention Periods by Data Type:

Account Information: Retained during active account period plus 3 years after closure
Transaction Data: Maintained for 7 years to comply with financial record requirements
Communication Records: Stored for 2 years after last customer interaction
Marketing Preferences: Retained until you withdraw consent or close account
Security Logs: Maintained for 1 year for fraud prevention purposes
Support Tickets: Archived after 18 months of case resolution

When data reaches the end of its retention period, we use secure deletion procedures that make information unrecoverable. For accounts you choose to close, most personal information is deleted within 30 days, though some financial records may be retained longer to meet legal obligations.

Active Data Management:

Our systems automatically flag data approaching retention limits and prompt appropriate action. You can also request early deletion of specific information types if they're no longer needed for active service provision.

Account Closure Process:

When you close your account, we provide a 60-day grace period during which you can reactivate without data loss. After this period, we begin permanent deletion procedures for non-essential information.

7

International Data Transfers and Compliance

While Smartplusflow primarily operates within Vietnam and stores data in Vietnamese facilities, certain technical services may involve international data transfers. We ensure all such transfers meet strict adequacy requirements and provide equivalent protection to Vietnamese data protection standards.

Transfer Safeguards Include:

Adequacy decisions recognizing equivalent protection levels in destination countries
Standard contractual clauses with international service providers
Binding corporate rules for any transfers within corporate families
Explicit consent for transfers that don't meet other adequacy requirements
Regular monitoring of international privacy law changes affecting transfers

Any international transfers are limited to essential technical functions such as cloud backup services or specialized security monitoring. We maintain detailed records of all international data flows and can provide specific information about transfer destinations upon request.

Regulatory Compliance:

Our privacy practices align with Vietnamese data protection regulations while also considering international standards where relevant. We regularly update our procedures to reflect changes in local and international privacy law requirements.

8

Children's Privacy and Age Restrictions

Smartplusflow is designed for adults managing personal finances and is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors and have implemented age verification procedures during account registration.

If we become aware that we have inadvertently collected information from someone under 18, we will take immediate steps to delete such information from our systems and prevent further data collection from that individual.

Parental Rights:

If you believe your child has provided personal information to Smartplusflow, please contact us immediately at info@smartplusflow.com. We will work with you to verify the situation and remove any inappropriate data collection.

Age Verification Process:

Our registration process includes age confirmation requirements and may request additional verification for accounts where age cannot be clearly established. This helps ensure our platform is used only by individuals legally able to enter into financial service agreements.

9

Policy Updates and Change Notifications

We periodically update this privacy policy to reflect changes in our services, legal requirements, or privacy practices. Significant changes that affect how we collect, use, or protect your information will be communicated through multiple channels to ensure you're fully informed.

How We Notify You of Changes:

Email notifications to your registered address for material changes
In-app notifications when you next log into your account
Website banners highlighting policy updates for 30 days
Updated version dates clearly displayed on this page
Summary of changes provided in plain language explanations

For minor updates that don't affect your rights or our core privacy practices, we may implement changes with notice through our standard communication channels. Major changes that require new consent will include clear opt-in procedures.

Version History:

We maintain a detailed changelog of privacy policy updates, including dates of changes and descriptions of what was modified. This information helps you track how our privacy practices evolve over time.

10

Cookies and Tracking Technologies

Smartplusflow uses cookies and similar tracking technologies to enhance your experience, maintain session security, and analyze platform usage patterns. We provide granular controls over cookie preferences and honor your choices about tracking technologies.

Types of Cookies We Use:

Essential Cookies: Required for basic platform functionality and security
Performance Cookies: Help us understand how you use our platform for improvements
Preference Cookies: Remember your settings and customization choices
Security Cookies: Protect against fraud and unauthorized access attempts

You can manage cookie preferences through your browser settings or our cookie preference center, accessible from any page footer. Disabling certain cookies may limit some platform functionality, but core budgeting features remain available.

Third-Party Tracking:

We don't allow third-party advertising networks to track you through our platform. Any third-party cookies are limited to essential services like fraud prevention or customer support functionality, and we regularly audit these relationships.

Cookie Consent:

When you first visit our platform, you'll see a cookie consent banner allowing you to accept or customize your cookie preferences. You can change these settings at any time through your account preferences.

Privacy Questions or Concerns?

Contact our Privacy Team

Email: info@smartplusflow.com

Phone: +84 917 675 358

Address: 567 Nguyễn Trung Trực, P. An Hoà
Rạch Giá, Kiên Giang, Vietnam

This Privacy Policy was last updated on January 15, 2025 and is effective immediately for all users.