Legal · Processor obligations
Data Processing Agreement
Thoả thuận xử lý dữ liệu · Version 3.6, in force 12 August 2026This Data Processing Agreement ("DPA") governs the processing of personal data that SiteminderStore Vietnam Company Limited carries out on behalf of a Customer whose Module reads or writes personal data through the Customer's SiteMinder Workspace. It is drafted in line with Decree 13/2023/ND-CP on Personal Data Protection (Nghị định 13/2023/NĐ-CP), which sets the ground rules for controller-processor relationships in Vietnam, and it supplements the master Terms of Service to which it is annexed by reference. Where the two documents disagree, this DPA prevails on questions of personal data.
§ 01Parties and roles
The parties to this DPA are: (i) the Customer, being the hotel, hostel, resort, property-management company, or corporate group that has opened an account on siteminderstore.org and installed one or more Modules; and (ii) SiteminderStore Vietnam Company Limited (Công ty TNHH SiteminderStore Việt Nam), Business Registration Certificate No. 0316854921, registered office at 235 Nguyễn Văn Cừ, Phường Nguyễn Cư Trinh, Quận 1, TP. Hồ Chí Minh. The Customer acts as controller (Bên Kiểm soát dữ liệu cá nhân) for the personal data of its guests and staff that flows through the Modules. SiteminderStore acts as processor (Bên Xử lý dữ liệu cá nhân) on the Customer's documented instructions.
§ 02Scope of processing
SiteminderStore processes personal data solely to (i) deliver the Modules the Customer has subscribed to, (ii) provide support, (iii) meet legal obligations, and (iv) improve the reliability and security of the service through aggregated telemetry that does not identify individuals. Any processing outside this scope requires a fresh written instruction from the Customer or a fresh legal ground.
§ 03Nature and purpose of processing
The nature of the processing depends on the specific Modules the Customer has installed. Typical operations include: reading reservation data from the SiteMinder Workspace, computing derived indicators (occupancy, ADR, RevPAR), writing back rate updates, sending automated messages to guests via the Customer's mail server, generating end-of-month reports, exporting invoices to accounting connectors, and reconciling payments with the Customer's bank statements. The Marketplace page of each Module documents in detail the exact operations it performs.
§ 04Categories of data subjects and personal data
| Data subject | Categories of personal data |
|---|---|
| Hotel guests of the Customer | Full name, e-mail, phone, nationality (when required by law), reservation reference, arrival and departure dates, room type, special requests, loyalty programme identifier, historical booking behaviour |
| Staff of the Customer | Full name, work e-mail, work phone, role in the SiteMinder Workspace, activity log within the Module |
| Corporate clients and travel agencies | Company name, contact name, contact e-mail, contact phone, contract reference, commission structure |
§ 05Duration of processing
SiteminderStore processes personal data for the duration of the Module subscription and for a further ninety days during which the Customer retains read-only access to its historical data. At the end of that ninety-day window personal data is deleted from live systems and from backups within the standard rotation cycle of thirty-five days, save where a legal retention obligation applies (invoices, e-invoicing records, accounting archives).
§ 06Processor obligations
SiteminderStore undertakes to:
- Process personal data only on documented instructions from the Customer, including for transfers to a country outside Vietnam.
- Ensure that persons authorised to process personal data are bound by written confidentiality obligations.
- Implement the technical and organisational security measures described in Annex 2.
- Assist the Customer in responding to data-subject rights requests received under Chapter II of Decree 13.
- Notify the Customer of any personal data breach without undue delay and in any event within seventy-two hours of becoming aware of it, providing all the information reasonably required to enable the Customer to comply with its own notification obligations under Article 43 of Decree 13.
- Not engage a new subprocessor without prior general or specific written authorisation from the Customer.
- Cooperate with any supervisory authority of competent jurisdiction, in particular the Department of Cybersecurity and High-Tech Crime Prevention (A05) of the Ministry of Public Security.
Seventy-two hours is a target we design for, not a ceiling we push against. Most incidents are notified within the first eight hours of detection.
§ 07Subprocessors and change management
The Customer grants SiteminderStore a general authorisation to engage the subprocessors listed in Annex 1. When SiteminderStore intends to add or replace a subprocessor, it will notify the Customer at least thirty days in advance by e-mail to the account owner and by a public entry in the Marketplace changelog. If the Customer objects on reasonable grounds within that thirty-day window, the parties will discuss in good faith; failing agreement, the Customer may terminate the affected Module subscription without penalty and receive a pro-rated refund of any unused prepayment.
§ 08International transfers
Personal data of Vietnamese data subjects is stored in Vietnam in the Viettel IDC datacentres in Hồ Chí Minh City and Hà Nội. A limited category of aggregated, de-identified operational data is replicated to a Singapore region operated by Amazon Web Services. Before this replication began SiteminderStore completed the Cross-Border Transfer Impact Assessment required by Article 25 of Decree 13; the assessment is on file with our Data Protection Officer and available to Customers on request under a confidentiality undertaking. Where the Customer specifically requests that no operational data related to its account be replicated to Singapore, we honour the request within thirty business days.
§ 09Audit rights
The Customer may audit SiteminderStore's compliance with this DPA once per calendar year, or more frequently if a personal data breach has been notified in the previous twelve months. Audits may be conducted by the Customer directly or by an independent auditor appointed by the Customer, subject to a written confidentiality undertaking. SiteminderStore will make available its ISO 27001 certificate (when granted), its most recent penetration-test report (redacted for third-party findings), its business-continuity documentation, and any other reasonable information required to demonstrate compliance. Where an audit reveals a material breach of this DPA, SiteminderStore bears the reasonable and documented costs of the audit.
§ 10Return or deletion at the end of the contract
At the end of the Module subscription the Customer may, within the ninety-day read-only window, export its data using the export tools built into the Module or by requesting a raw dump from our support team. After the window closes the data is deleted from live systems within seven days and from backups within thirty-five days, save where a legal retention obligation applies. At the Customer's written request SiteminderStore will provide a signed deletion attestation.
§ 11Liability
The liability of the parties under this DPA is governed by the limitation of liability clause of the master Terms of Service. Nothing in this DPA limits the liability of a party for fraud, wilful misconduct, or breach of the confidentiality obligations of clause 6. Administrative fines imposed by A05 or by another competent authority are borne by the party at fault; where both parties have contributed to the breach they are borne in proportion to that contribution.
§ 12Term and termination
This DPA takes effect on the day the Customer installs its first Module and remains in force for as long as SiteminderStore processes personal data on behalf of the Customer. It survives the termination of the master Terms of Service for as long as any personal data of the Customer remains in the systems of SiteminderStore.
§ 13Governing law and jurisdiction
This DPA is governed by the laws of the Socialist Republic of Vietnam. Any dispute is subject to the exclusive jurisdiction of the People's Court of Ho Chi Minh City, in line with the master Terms of Service.
§ 14Annex 1 — List of subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Viettel IDC | Primary infrastructure hosting for the Marketplace and Modules | Hồ Chí Minh City and Hà Nội, Vietnam |
| Amazon Web Services Singapore | Key management (AWS KMS) for control-plane secrets and disaster-recovery replication of aggregated operational data | Singapore |
| MoMo | Payment processing for e-wallet transactions | Vietnam |
| VNPay | Payment processing for domestic cards | Vietnam |
| Vietcombank | Bank-transfer settlement and refunds | Vietnam |
| Postmark | Transactional e-mail delivery for account-level e-mails | United States, on the basis of the standard contractual framework published in Annex 3 |
§ 15Annex 2 — Security measures
SiteminderStore applies the following technical and organisational security measures:
- Encryption in transit — TLS 1.3 for all HTTPS traffic; the Marketplace scores A+ on the Qualys SSL Labs test.
- Encryption at rest — AES-256 for all databases and object stores.
- Key management — AWS KMS in Singapore for control-plane secrets; hardware-security-module-backed keys for signing e-invoices.
- Access control — least-privilege model with mandatory multi-factor authentication for every administrator, quarterly re-attestation, and immediate deprovisioning on departure.
- Network segmentation — separate subnets for the ingress, application, and data layers; only the application layer talks to the data layer.
- Vulnerability management — weekly automated scans of container images; quarterly penetration testing by an independent Vietnamese firm accredited by A05.
- Business continuity — hourly incremental backups; nightly full backups; monthly restore drills.
- Incident response — a written run-book tested twice per year; a rotational on-call schedule; a dedicated communication channel with the DPO of every Customer subscribed to the enterprise tier.
- Employee training — mandatory annual training on Decree 13, on the Law on Cybersecurity 2018, and on the internal secure-development guidelines.
§ 16Annex 3 — International transfer framework
Transfers of aggregated, de-identified operational data to Singapore are covered by a written data-processing agreement with Amazon Web Services in the form of the AWS Data Processing Addendum and by the Cross-Border Transfer Impact Assessment SiteminderStore completed under Article 25 of Decree 13. Transfers of account-level e-mail metadata to Postmark in the United States are covered by Postmark's own data-processing addendum and by supplementary contractual clauses that oblige Postmark to notify us of any government access request and to refuse it where legally possible. The Cross-Border Transfer Impact Assessment is refreshed every twelve months and after any material change in the legal environment of the destination country.
§ 17Contact
Questions about this DPA can be sent to dpo@siteminderstore.org. For urgent security matters please use security@siteminderstore.org and mark the subject "DPA — urgent". The Data Protection Officer replies within one Vietnamese business day.