← Back to UPEN
UP — LEGAL DOCUMENTS

Privacy & Data Protection Policy

Applicable to the UP — Unified Platform, funded and operated by ASIF Foundation, and to its member organizations, users, donors, partners, staff, volunteers and beneficiaries.

Mục lục
1General Provisions2Terms and Roles3Governance and Data Protection Principles4Data Classification and Processing5Data Lifecycle and Retention6Rights of Data Subjects7Access Control and User Safety8Infrastructure, Application and Backup Protection9Third Parties, Integrations and Data Transfers10Responsible Use of Artificial Intelligence11Monitoring, Logging and Audit12Incident Management and Response13Business Continuity and Resilience14Responsibilities of the Parties15Limitation of Liability16Training, Compliance and Handling of Violations17Policy Governance18Contact and Handling of RequestsAppendix 1Minimum Responsibility MatrixAppendix 2Minimum Security Requirements for Users

1General Provisions

1.1. Purpose

This Policy establishes a unified governance framework for information security, system safety and data protection for the UP — Unified Platform ("UP"), to protect the lawful rights and interests of ASIF Foundation, member organizations, users, donors, partners, staff, volunteers and beneficiaries.

The Policy is built on the principles of risk-based governance, privacy and security by design and by default, data minimization, need-to-know access, and accountability; and references ISO/IEC 27001, 27002, 27017, 27018 and 27701 practices to the extent appropriate for the scale, resources, and nonprofit nature of UP. This reference should not be understood as a statement that ASIF or UP has been certified against these standards.

1.2. Scope of Application

  • All member organizations, affiliated units and individuals granted access to or use of UP.
  • Staff, volunteers, experts, contractors, technology partners and service providers involved in developing, operating, supporting or maintaining UP.
  • All data entered, created, collected, stored, transmitted, backed up, processed or otherwise used within UP and its ASIF-approved integrations.
  • Devices, accounts, application programming interfaces, connections and the technical environment used to access UP.

1.3. Legal Basis and Reference Documents

This Policy is applied in accordance with the laws of Vietnam in effect from time to time, including but not limited to: the 2015 Civil Code; the 2015 Law on Network Information Security; the 2018 Law on Cybersecurity; the 2023 Law on Electronic Transactions; the 2024 Data Law; the 2025 Law on Protection of Personal Data; Decree No. 13/2023/ND-CP on personal data protection; Decree No. 53/2022/ND-CP; laws on accounting, records retention, intellectual property, children, medical examination and treatment, and their amending or replacing documents.

Where there is a discrepancy between this Policy and a mandatory legal provision, the mandatory legal provision shall prevail. ASIF will review and update this Policy when there is a change in law or a significant change to its data-processing model.

1.4. Interpretation and Order of Priority

This Policy should be read together with UP's Terms of Use, the Memorandum/Partnership Agreement (MOA), and any data-processing addenda. In the event of a conflict, the document with higher legal effect, or the more specific data-protection provision, shall prevail, unless the law provides otherwise.

2Terms and Roles

2.1. Allocation of Roles

For data collected and entered into UP by a member organization, the member organization is responsible for determining the purpose, legal basis, scope, retention period, and for providing notice to data subjects. ASIF and the technology partner process such data only to the extent necessary to provide, maintain, secure, support and improve the service in accordance with the agreement and the law.

Where ASIF independently determines the purpose and means of processing its own data, ASIF acts as the data controller for that activity. Specific roles may be adjusted in the MOA or a data-processing addendum.

Glossary of Terms

TermExplanation
ASIF FoundationThe entity that funds, manages and operates UP; the primary point of governance for the service and coordination with the technology partner.
Member OrganizationA social organization, nonprofit, social enterprise, or lawful entity granted the right to use UP by ASIF under an MOA.
Data SubjectAn individual reflected by personal data, including staff, volunteers, donors, partners, beneficiaries and users.
Data ControllerThe party that determines the purpose and means of processing personal data. A member organization is typically the Data Controller for data it uploads to UP.
Data ProcessorA party that processes personal data on behalf of the Controller, within the scope, purpose and lawful instructions given.
Sub-processorA technology partner or vendor engaged by the Processor to carry out part of the processing activity.
Organizational DataAny data, document, configuration or content created, entered or stored on UP by a member organization or user.
Sensitive Personal DataData requiring a higher level of protection under law, such as health, financial, biometric, children's data, location, or other sensitive personal information.
Data IncidentAn event resulting in the loss, destruction, alteration, disclosure of, or unauthorized access to, data; or that degrades the confidentiality, integrity, or availability of the system.
Integrated AIAn artificial-intelligence feature approved by ASIF and integrated into UP or a related process.

3Governance and Data Protection Principles

3.1. No Commercialization of Data

ASIF does not sell, rent, exchange or commercially exploit organizational data or personal data on UP. Data is processed only to provide the service, ensure safety, provide technical support, comply with legal obligations, or follow the lawful instructions of a member organization.

3.2. Data of Children and Vulnerable Individuals

Data belonging to children, persons with disabilities, patients, the elderly, and other vulnerable groups must be processed with a heightened degree of care. Member organizations must ensure a lawful basis, consent, or the approval of a legal representative as required by law; must limit the display of identifying information; and must not use such data in a way that could stigmatize, harm, or violate the dignity of the individual.

Core Data Protection Principles

PrincipleApplication Requirement
Lawfulness, fairness and transparencyProcess data only on a lawful basis; provide clear, understandable, and non-misleading notice.
Purpose limitationData may only be used for its defined purpose; a new purpose must be assessed and have an appropriate basis.
Data minimizationOnly collect and access data that is necessary, relevant and not excessive for the purpose.
AccuracyMaintain a mechanism to update, correct and remove inaccurate data when needed.
Storage limitationDo not retain data longer than necessary or than required by law.
Security, integrity and availabilityApply organizational and technical measures proportionate to the risk.
AccountabilityKeep evidence of decisions, access permissions, consent, data-subject requests, and incident handling.
Privacy and security by design and by defaultAssess security and privacy from the design, configuration and deployment stage.

4Data Classification and Processing

4.1. Labeling and Data Owner Responsibility

The business unit that creates the data is the data owner and is responsible for determining classification, approving access, conducting periodic review, and deciding on retention or destruction. The Organization Admin is responsible for configuring system permissions in accordance with the data owner's decisions.

4.2. Export, Download and Sharing Outside the System

Data must remain protected at its corresponding classification level after being exported from UP. Users must not store confidential or sensitive data on public devices, personal accounts, unapproved storage services, or send it through unsecured channels. Member organizations are responsible for managing copies exported from UP.

Data Classification Levels

ClassificationExampleMinimum Requirement
PublicApproved communications materialsMay be published; version control and copyright must be maintained.
InternalProcesses, plans, operational documentsInternal/authorized users only; no external sharing without approval.
ConfidentialContracts, budgets, HR data, donor pipelineRole-based access; encrypted in transit; restricted download and sharing.
Restricted / Highly SensitiveHealth data, children's data, identification, bank accounts, safeguarding casesAccess on a strict need-to-know basis; MFA; logging; restricted export; separate approval.

5Data Lifecycle and Retention

5.1. Collection and Entry of Data

  • Member organizations must determine the purpose, legal basis and required notice to data subjects before collecting data.
  • Do not enter unlawful, irrelevant, excessive, or prohibited data into UP.
  • Sensitive data may only be entered once the relevant function, process, and access permissions have been approved.

5.2. Reference Retention Periods

Data CategoryReference PeriodPrinciple
Accounting, financial and voucher dataAs required by accounting law and donor requirements; typically 5–10 years or longer where a specific obligation appliesDecided and owned by the member organization.
HR and employment recordsPer labor law, social insurance, tax law, and the organization's own retention policyAccess restricted after the employment relationship ends.
Program/beneficiary dataPer the project lifecycle, donor requirements, safeguarding requirements, and legal basisPrefer anonymization/pseudonymization once identification is no longer needed.
Access logs and security logsA minimum of 12 months; up to 24 months for critical systemsFor investigation, audit and compliance purposes.
Operational backup copiesPer the published backup cycle; typically 30–90 daysBackups do not replace formal business records.
Data after service terminationData export period per the MOA; deleted or anonymized thereafter per procedureUnless retention is required by law or a dispute.

5.3. Deletion, Destruction and Anonymization

Deletion must be authorized, verifiable, and consistent with the backup mechanism. Where immediate deletion from a backup copy is not possible, the data must be isolated, not used for another purpose, and overwritten on a rolling cycle. Data used for statistics or improvement must be anonymized or aggregated to a level where an individual cannot reasonably be identified.

6Rights of Data Subjects

To the extent permitted by applicable law, a data subject has the right to be informed; to consent or refuse where consent is required; to withdraw consent; to access, view, or request a copy; to correct; to request deletion; to restrict or object to processing; and to complain, denounce, sue or claim compensation as provided by law.

6.1. Receiving and Handling Requests

The member organization is the primary point of contact for requests relating to data it controls. ASIF provides reasonable technical support at the valid request of the member organization. Requests must be identity-verified, logged, classified, handled within the legally required or committed timeframe, and evidence of fulfillment retained.

6.2. Exceptions

A data subject's rights may be limited where exercising them would affect the rights of others, an organization's or third party's confidential information, a mandatory retention obligation, an investigation into a violation, fraud prevention, safeguarding, or another case permitted by law. Any refusal must be justified and appropriately explained.

7Access Control and User Safety

7.1. Accounts and Authentication

  • Each user has one identified individual account; shared accounts are prohibited.
  • MFA must be applied to Admins, privileged accounts, and sensitive data wherever the system supports it.
  • Passwords must be sufficiently strong, not reused, and changed immediately if compromise is suspected. Periodic password rotation is recommended.
  • Accounts must be locked or revoked promptly when staff leave, change roles, or no longer need access.
  • Access rights are reviewed periodically according to an internal plan, depending on available resources and the risk level at the time, and more frequently for privileged access.

7.2. Access Permissions

UP applies the principles of least privilege, separation of duties, and need-to-know. Access rights must be role-based, approved by an authorized person, and recorded in the system. Organization Admins must not grant themselves permissions beyond the scope of their own authorization.

7.3. Personal Devices and Remote Access

Personal devices may only be used where the organization permits it and where minimum requirements are met for screen lock, security updates, anti-malware software, device encryption, and remote-wipe capability where appropriate. Sensitive data must not be accessed over an unsecured public network without additional protective measures.

8Infrastructure, Application and Backup Protection

8.1. Cloud Infrastructure Security

UP is deployed on cloud infrastructure or a data center approved by ASIF. ASIF and the technology partner aim to apply appropriate measures within available resources, which may include network segmentation, firewalls, configuration management, encryption in transit, encryption at rest where feasible, key management, anti-malware, patching, monitoring, backup, and privileged access control.

8.2. Secure Development and Change Management

Software changes must be recorded, tested and approved before deployment. Source code, application secrets and access keys must not be stored in public repositories. Vulnerabilities are classified by risk level and remediated within internal timeframes; emergency changes must be reviewed after deployment.

8.3. Backup and Recovery

The technology partner performs backups according to the agreed architecture and service level. Backup copies must be protected from unauthorized access, reasonably separated from the production environment, with a recovery-testing plan carried out on an internal schedule depending on resources and the risk level at the time. Specific recovery objectives (RTO/RPO) are set out in the MOA or a technical agreement document, and should not be presumed to be an absolute commitment unless recorded in writing.

9Third Parties, Integrations and Data Transfers

9.1. Vendor and Sub-processor Management

ASIF commits to conducting a risk-proportionate assessment before selecting or changing a data-processing vendor, within available resources. Vendor contracts should address the scope of processing, security, authorized personnel, incident handling, support for data-subject rights, data deletion or return, audit rights, and obligations upon termination.

9.2. Third-Party Integrations

An integration may only be enabled with appropriate approval. The member organization is responsible for assessing the purpose and lawfulness of any data sharing arising from an integration it requests. ASIF has the right to disable an integration that poses a security risk, violates the law, or affects UP.

9.3. Location of Data Processing

Because UP uses international cloud infrastructure services, part of the Platform's technical operations may be processed at data centers located outside the territory of Vietnam, in line with the provider's standard operating architecture. ASIF Foundation and the technology partner will comply with the Vietnamese laws applicable to this activity, and will carry out the necessary procedures required by law or a competent authority when a corresponding obligation arises.

10Responsible Use of Artificial Intelligence

10.1. Scope of Application

The UP Platform does not currently have a built-in artificial intelligence (AI) feature. The principles below are recommendations and reminders for users at member organizations who use external AI tools (such as ChatGPT, Copilot, etc.) while working with data on UP, and will become mandatory principles should UP integrate an AI feature in the future.

10.2. Recommended Principles

  • AI only assists the user; final decisions — particularly on finance, recruitment, health, safeguarding, and beneficiary rights — must be reviewed by an authorized person.
  • Do not use organizational data to train a third party's AI model without a lawful basis, approval, and appropriate protective terms.
  • Do not enter confidential, restricted, or sensitive personal data into public AI tools, except with the written consent of ASIF Foundation or the Organization Admin.
  • AI-generated output must be checked for accuracy, bias, copyright, security, and contextual fit before use.
  • Any integrated AI feature must undergo a risk assessment and include a logging mechanism and human oversight capability.

10.3. Transparency and Accountability

Where content or a decision of significant consequence is AI-assisted, the member organization must be appropriately transparent, retain a record of its use, and ensure a human-review channel exists. Users are responsible for how they use AI-generated output.

10.4. Responsibility of the Member Organization

All data on UP belongs to the member organization (per Section 7.3 of the Terms of Use). The member organization is therefore responsible for managing and monitoring how its own staff and volunteers use AI. ASIF Foundation has no obligation to monitor, detect, or bear legal liability for a violation of the above principles by a user of a member organization, consistent with the limitation of liability set out in Sections 14.2 and 15 of this Policy.

11Monitoring, Logging and Audit

11.1. Logging

UP may log logins, access, data changes, data exports, permission changes, administrative actions, and security events. Logs are accessible only to authorized personnel, protected from tampering, and used for security, support, audit, compliance, and incident-investigation purposes.

11.2. Reasonable Monitoring

ASIF may monitor performance, traffic, anomalies, and compliance without reading business content beyond what is necessary. Where access to data is required for support or investigation, such access must be restricted, logged, and terminated immediately once complete.

11.3. Assessment and Testing

ASIF commits to working with the technology partner toward reviewing configurations, scanning for vulnerabilities, testing recovery, assessing access rights, and conducting security checks at a level of risk and resourcing appropriate for a nonprofit organization. Penetration testing may be carried out when needed, upon a major change, or at the reasonable request of a donor/partner, subject to an agreed scope and cost.

12Incident Management and Response

12.1. Reporting Obligation

Users must immediately report to the Organization Admin and the ASIF point of contact upon discovering a lost device, a compromised password, misdirected data, abnormal access, malware, missing records, or any other sign of an incident. Do not unilaterally delete evidence, contact outside parties, or disclose an incident without authorization.

12.2. Response Process

StageMain Activities
Intake and classificationRecord, verify, determine severity and identify affected parties.
Containment and evidence preservationLock accounts, revoke sessions, restrict connectivity, preserve logs.
Impact assessmentDetermine data type, number of subjects, consequences, scope, and legal obligations.
Remediation and recoveryEliminate the cause, patch, restore service, and verify it is safe.
NotificationNotify the member organization, competent authorities, and data subjects where the law or risk level requires it.
Lessons learned and improvementRoot-cause analysis, corrective actions, updated controls, and record-keeping.

12.3. Incident Notification

ASIF endeavors to notify a member organization as soon as reasonably possible after confirming an incident is likely to have a significant impact on the organization's data. The notice will include what is known, the expected impact, measures already taken, and recommended actions. Deadlines for notifying a state authority or a data subject follow applicable law and are coordinated between the parties according to their legal role.

13Business Continuity and Resilience

ASIF and the technology partner aim to build and maintain an incident-response plan appropriate to the scale and resources of a nonprofit organization, including identifying critical services, dependencies, communication roles, and recovery options. This plan is reviewed periodically per an internal schedule and after any major incident. Member organizations must maintain an alternative business process for essential activities and must not rely solely on UP in an emergency.

UP's availability is affected by cloud infrastructure, connectivity, vendors, and other factors beyond reasonable control. Any specific operational targets, if any, are set out in the MOA or an addendum; this is not an absolute guarantee of uninterrupted service.

14Responsibilities of the Parties

14.1. ASIF Foundation

  • Maintain the governance framework, access permissions, coordinated support, and security controls appropriate to risk and resources.
  • Limit access by ASIF personnel and the technology partner; require security obligations of them.
  • Manage incidents, vendors, changes, and policy review.
  • Support member organizations in exporting data and fulfilling lawful requests within reasonable technical scope.

14.2. Member Organization

  • Ensure the lawfulness, accuracy, and appropriateness of data uploaded to UP.
  • Provide privacy notices, manage consent, and fulfill data-subject rights.
  • Manage its own accounts, permissions, devices, exported data, and user conduct.
  • Do not enter data that exceeds what is needed, falls within a prohibited category, or lacks a lawful basis for processing.
  • Cooperate on investigation, remediation, and notification obligations according to its legal role.

14.3. Technology Partner

The technology partner carries out development, maintenance, technical operation, and data processing under contract, ASIF's instructions, security principles, and the approved scope; must not use data for its own purposes; must control its personnel; must report incidents; and must support deletion, return, and audit as agreed.

15Limitation of Liability

To the extent permitted by law, ASIF is not liable for damage arising from: unlawful or inaccurate data entered by a member organization; the acts or omissions of a user; devices, networks, or accounts outside ASIF's control; data already exported from UP; an integration requested by a member organization; a force majeure event; or a member organization's failure to fulfill its own security and compliance obligations.

Nothing in this Section excludes liability that the law does not permit to be excluded, or exempts liability for intentional misconduct, fraud, or breach of a mandatory obligation. Specific liability limits, compensation mechanisms and financial caps, if any, are set out in the MOA or a related contract.

16Training, Compliance and Handling of Violations

Users and personnel with data access must complete security and data-protection training appropriate to their role. A violation may result in a warning, retraining, revocation of access, account suspension, disciplinary action, termination of the relationship, a claim for damages, or referral to a competent authority, depending on severity and applicable rules.

ASIF has the right to require a member organization to remediate a weakness, provide evidence of controls, or temporarily suspend part of its access where there is a serious risk to the system, data, or data subjects.

17Policy Governance

17.1. Ownership and Approval

ASIF Foundation's technical operations unit is the document owner, coordinating with relevant departments (Legal, HR, Finance, Programs) and the technology partner on implementation. This Policy is approved under the authority of ASIF Foundation.

17.2. Review and Updates

This Policy is reviewed periodically per an internal schedule, and whenever there is a significant change in law, UP's architecture, data types, vendors, a serious incident, or an audit requirement. A revised version is communicated by email, through the UP interface, or via an official channel before it takes effect, except for an urgent change that must take immediate effect to protect the system or ensure legal compliance.

17.3. Exceptions

An exception must be documented in writing, stating its scope, rationale, risk assessment, compensating controls, approver, and duration. An exception must not reduce a mandatory legal obligation.

18Contact and Handling of Requests

Requests relating to security, privacy, incidents, or data-subject rights should be sent through the official channel published by ASIF on UP, in the MOA, or on the website. Member organizations must maintain up-to-date contact information for their Organization Admin and data-protection lead (where required by law or the scale of processing).

In an emergency, a user must prioritize locking the account, disconnecting the suspected compromised device, and contacting the Organization Admin/ASIF point of contact immediately through the published emergency channel.

Contact ChannelDetails
Support emailsupport@asif.foundation
Websitehttps://asif.foundation

Appendix 1Minimum Responsibility Matrix

ActivityMember OrganizationASIFTechnology Partner
Determine purpose/legal basis for processingPrimary responsibilityAdvise/coordinate where within ASIF's scopeDoes not independently determine purpose
Notice and consentPrimary responsibilitySupport templates/process where availableTechnical support
User access permissionsApprove and reviewEstablish the platform framework/permissionsTechnical implementation
Infrastructure securityCoordinateMonitor and governTechnically responsible under contract
Data-subject requestsReceive/decideTechnical supportSupport per instruction
Data incidentCoordinate, notify per its roleCoordinate and assessDetect, contain, technical remediation
Retention/deletion of business dataDecide and be responsibleProvide tools/processTechnical execution

Appendix 2Minimum Security Requirements for Users

  • Use an identified individual account and MFA when required.
  • Never share passwords, OTP codes, tokens, or privileged access links.
  • Verify the recipient and any attachment before sending data.
  • Never use personal email, personal drives, or unapproved messaging apps to store or share confidential data.
  • Lock your screen when stepping away from a device; keep the OS and software up to date.
  • Immediately report phishing emails, a lost device, misdirected data, or abnormal access.
  • Do not install unapproved add-ons, integrations, or automation tools on UP.
  • Do not enter sensitive data into public AI tools, except with the written consent of ASIF Foundation or the Organization Admin.

This document should be read together with the Terms of Use for the UP Platform.

← Back to UP