CShield CShield

PRIVACY POLICY

VERICHAINS JOINT STOCK COMPANY (“Verichains”, “We”, “Us”, “Our”) respects Your privacy. This privacy policy (the “Policy”) applies to the Personal Data that We collect through the Cshield application and explains how Cshield collects, uses, stores and discloses Personal Data, which Personal Data is concerned, and Your rights when using the Cshield application on the Android and iOS operating systems (the “Application”, the “Services”). By downloading or installing the Application, registering an Account, or using any feature of Cshield, You acknowledge that You have read and understood this Policy.

A. DEFINITIONS

  1. Verichains”, “We” means VERICHAINS JOINT STOCK COMPANY, the entity that develops and operates the Cshield Application, acting as the controller and processor of Personal Data.
  2. User”, “You” means an individual who registers an Account and uses the Application.
  3. Personal Data” means digital data, or information in another form, that identifies or assists in identifying a specific natural person, comprising basic Personal Data and sensitive Personal Data.
  4. Community Database” means the collection of reports on telephone numbers suspected of spam or fraud submitted by Users to Our system.
  5. Personal Data Controller”, “Personal Data Processor”, “consent” and “cross-border transfer of Personal Data” have the respective meanings given to them under the Law on Personal Data Protection 2025 and Decree No. 356/2025/ND-CP.
  6. DPO” means the personal data protection officer or the unit responsible for personal data protection.

B. PRINCIPLES OF PERSONAL DATA PROCESSING

  • We process Personal Data in accordance with the following principles: lawfulness and transparency; limitation to the purposes notified; data minimisation; accuracy; storage limitation; security; and accountability, in accordance with the Law on Personal Data Protection 2025.
  • We undertake not to purchase or sell Personal Data in any form.
  • In respect of permissions to access functions or data on Your device, such as contacts, call logs, Accessibility permission, the default phone application and call-screening roles, permission to display over other applications, usage-access permission, notifications, the list of installed applications or other permissions necessary to provide the features of the Application, We shall access such functions or data only after You have granted the relevant permission through the operating system’s permission mechanism or as otherwise provided by law. You may refuse or withdraw any permission granted at any time in the Settings section of Your device. Refusing or withdrawing a permission may cause certain features of the Application not to function, or to function only with limited functionality.

C. PERSONAL DATA COLLECTED

In the course of Your use of the Application, We collect and process only such Personal Data as is necessary and consistent with the processing purposes notified in this Policy, and in compliance with the laws on personal data protection.

The categories of Personal Data collected depend on how You register for, access, use and interact with the Application. When You register a Cshield Account, use the features of the Application, download or update software, contact Us (including through social media platforms), participate in surveys or otherwise interact with the Application, We may collect and process the following categories of Personal Data:

  • Account information. Information used to create, manage and authenticate a Cshield Account, such as: full name, date of birth, telephone number, email address, profile picture, social media account information (where You elect to sign in with or link an account), account status and other related information.
  • Device information. Information used to identify the device and to ensure its compatibility and security when using the Application, such as: device name, operating system version, device identifier, device configuration information and other technical information, including without limitation root/jailbreak status, installation information and the list of applications installed on the device (to the extent necessary to provide the features of the Application).
  • Transaction information. Information relating to Your subscription to, purchase, renewal or use of Service Plans and products, and to transactions arising within the Application.
  • Fraud prevention information. Information necessary to detect, prevent, investigate and address fraud, unauthorised access, abuse of the Services, or risks affecting the safety and security of the Application and of Users.
  • Usage data. Data generated in the course of Your use of the Application and the Services, such as: audit logs, system logs, information on access to quarantined applications, the security decisions You make yourself on the device (quarantining an application or releasing it from quarantine; allowing an application to display an overlay over another application) together with the package names of the applications concerned by such a decision, performance data, diagnostic data, incident records and other technical data used for the operation, maintenance and quality improvement of the Services and for information security purposes. The Application does not upload to Our servers any log of the applications You open on Your device; identifying the application currently displayed on screen takes place on the device only, for the purpose of showing You security warnings.
  • Malware scanning data. If the Application identifies an application on Your device that may be suspicious or present a potential security risk, it may automatically transmit certain information to Us or Our service providers for the purpose of malware analysis and security risk assessment. Such information may include, without limitation, the application’s identifying information, version, installation package (where applicable), and other components related to the application. This transmission occurs automatically as part of the malware scanning process and does not require any separate action by You for each transmission.
  • Family Protection data. The Family Protection feature allows a User (the “Protector”) to link the device of a family member (the “Protected Device”) to the Protector’s Account by means of a QR code, on the basis of the consent given by the person using the Protected Device at the time of linking. Once linked, the Protected Device operates within the scope of the Protector’s Account; We do not create a separate Account for, and do not collect the personal identifiers (full name, date of birth, email address, registered telephone number) of, the person using the Protected Device. Security data of the Protected Device — comprising the list of installed applications, telephone numbers derived from the call log, security events, scan results and the status of permissions on the device — is recorded in the Protector’s Account for the sole purpose of enabling the Protector to monitor the security status of that device and to be alerted to risks. Both the Protector and the person using the Protected Device may unlink at any time; following unlinking, We cease recording new data from that device.
  • Other information You provide to Us. Information, documents or content that You voluntarily provide, upload or permit Us to access through Your device settings, including but not limited to: call history (where You use the Application as Your default phone application), contact list information (where You grant access permission), lists of blocked or trusted telephone numbers configured by You, the content of communications with Our Customer Care team, and information provided through media or social media channels.
  • Sensitive Personal Data. Where necessary to provide the Services or at Your election, and on the basis of valid consent in accordance with applicable law, We may collect and process certain sensitive Personal Data, comprising:
    1. data reflecting Your conduct and use of telecommunications services, such as call history; and
    2. such other sensitive Personal Data as You voluntarily provide or consent to Our processing in respect of a specific feature or Service.

      The processing of sensitive Personal Data shall be carried out only to the extent necessary to provide the Services, to ensure information security, to prevent fraud, or for such other lawful purposes as have been notified to You in accordance with applicable law.

      You are under no obligation to provide Personal Data at Our request. However, should You decline to provide, or withdraw Your consent in respect of, Personal Data necessary for the provision of the Services, We may be unable to provide some or all features of the Application, to process Your requests, or to perform obligations arising from Your request to use the Services.

D. PERSONAL DATA WE RECEIVE FROM OTHER SOURCES

In addition to Personal Data that You provide to Us directly, We may collect or receive Your Personal Data from other lawful sources, to the extent necessary to carry out the processing purposes set out in this Policy and in compliance with applicable law. Such sources may include:

  • Other individuals. We may receive Your Personal Data from other individuals where they use features of the Application that relate to You. For example, where a User invites You to use Cshield or shares information necessary to use a feature of the Application.
  • At Your request or with Your permission. Where You request or permit an organisation, individual or third party to share Personal Data with Us for the purposes of registration, authentication or use of the Services, We may receive and process such Personal Data within the scope permitted by You or as provided by law.
  • Our partners. We may receive Personal Data from partners, service providers or organisations cooperating with Us in order to support the verification of information, system security, fraud prevention, risk management or the provision of the Services to You.
  • Publicly accessible sources. We may collect Personal Data from sources lawfully made public in accordance with applicable law, including information published in the mass media, on websites or in other public data sources, to the extent necessary for the processing purposes notified and in compliance with applicable law.

Third-party Personal Data provided by You

Where You provide Us with the Personal Data of another person (including a person who has not registered for or used Cshield), You undertake that:

  • You have a lawful basis to provide or share such Personal Data with Us in accordance with applicable law;
  • the provision of such Personal Data does not infringe the lawful rights and interests of the Data Subject; and
  • where required by law, You have performed or will perform the notification obligations and/or obtain the consent of the Data Subject before providing the Personal Data to Us.

    To the extent permitted by law, We shall process the Personal Data You provide strictly for the purposes notified in this Policy and shall apply personal data protection measures in accordance with applicable law.

E. PURPOSES OF PERSONAL DATA PROCESSING

We process Your Personal Data only to the extent necessary to carry out the lawful purposes notified in this Policy and in compliance with the laws on personal data protection. Specifically, Your Personal Data may be processed for the following purposes:

  1. Account registration, authentication and management: to create, authenticate and manage Your Cshield Account, to verify identity (where necessary), to administer account information and to assist You in the course of using the Application.
  2. Provision and operation of the Services: to provide, maintain and operate the Application and to ensure the functioning of the products, Services and features that You request or elect to use, including but not limited to analyse, compare, and assess applications that may pose security risks on Your device for the purpose of detecting, alerting You to, and preventing malware, malicious software, and other cybersecurity threats, thereby protecting the security of Your device and the data stored on it.
  3. Development and operation of the Community Database: to build, update, maintain and operate the Community Database in order to support the identification, alerting, prevention and blocking of spam calls, fraudulent calls, spoofed calls and conduct showing signs of fraud, thereby contributing to the safety of the user community.
  4. Customer care and communications: to receive, process and respond to Your requests, complaints or feedback; to contact You in relation to Your Account and the Services; and to send important notices regarding use of the Application, changes to terms or policies, or other information necessary for the provision of the Services.
  5. Safety, security and fraud prevention: to detect, prevent, investigate and address fraud, abuse of the Services, unauthorised access or breaches of the Terms of Service; and to ensure cybersecurity and safety and to protect the systems, data and lawful rights and interests of Us, of Users and of related parties.
  6. Improvement and development of products and Services: to analyse, evaluate and compile statistics on usage data; to monitor system performance; to remedy defects; and to research, develop and improve the quality, features and user experience of, and the operational efficiency of, the Application and related Services.
  7. Performance of legal obligations: to comply with obligations under applicable law, including without limitation the retention of information, reporting, the provision of information at the lawful request of competent State authorities, and the resolution of disputes, complaints, denunciations and other legal proceedings.
  8. Other lawful purposes: in respect of processing purposes not falling within the cases set out above, We shall clearly notify You of the purpose of processing and the categories of Personal Data to be processed and, where required by law, shall obtain Your consent before carrying out such processing.

    Save as otherwise provided by law or where the processing of Personal Data is carried out on another legal basis under applicable law, We shall process Your Personal Data only in accordance with the purposes notified, and shall obtain Your consent before using Personal Data for a new purpose that is incompatible with the purpose originally notified.

F. STORAGE AND DISCLOSURE OF PERSONAL DATA

1. Storage of Personal Data

  • We store Your Personal Data only for such period as is necessary to carry out the processing purposes notified in this Policy or for such period as is prescribed by law. Once the processing purpose has been fulfilled and We no longer have a legal basis to continue storing the Personal Data, We shall delete, destroy, de-identify or apply such other appropriate measures to the Personal Data as are provided by law.
  • Where necessary, We may continue to store Personal Data in order to:
    1. perform obligations under applicable law;
    2. resolve complaints or disputes, or respond to requests of competent State authorities; or
    3. establish, exercise or defend the lawful rights and interests of Us or of related parties.
  • The retention periods applicable to each category of data are as follows:
Category of dataRetention period
Transaction informationUp to 10 years, or such other period as is prescribed by the laws on accounting and taxation and other relevant laws.
Information used to verify and handle User requests or complaintsUp to 12 months from the date on which the request or complaint is resolved, unless a longer retention period is required by law.
Information on Personal DataWithdrawal of consent / restriction of processing / objection to processing
Response time limit: 02 working days.
Completion time limit: 15 days (20 days where coordination with a processor / third party is required)
Maximum extension: 01 time, up to 15 days.
Access to, rectification of, or a request to rectify / provide data
Response time limit: 02 working days.
Completion time limit: 10 days (where a data processor or a third party is involved, the time limit is 15 days)
Maximum extension: 01 time, up to 10 days.
Request for erasure of Personal Data
Response time limit: 02 working days.
Completion time limit: 20 days (where a processor or a third party is involved, the time limit is 30 days)
Maximum extension: 01 time, up to 15 days.
Request to implement Personal Data protection measures
Response time limit: 02 working days.
Completion time limit: 15 days.
Maximum extension: 01 time, up to 15 days.
Other informationFor the period during which the Account remains active and up to 12 months from the date on which the Account is deleted, for the purposes of system security and the performance of legal obligations. Following that period, the data shall be deleted, destroyed or de-identified in accordance with applicable law.

2. Disclosure of Your Personal Data

  • We disclose or transfer Your Personal Data only to the extent necessary to carry out the processing purposes notified or in the cases permitted by law. Your Personal Data may be disclosed to the following categories of recipient:
    1. between units within the same agency or organisation, for the processing of Personal Data consistent with the established processing purposes;
    2. the parent company, subsidiaries or affiliates of Verichains Joint Stock Company, to the extent necessary to provide the Services, to administer operations or to carry out lawful processing purposes;
    3. service providers (including without limitation providers of information technology, cloud computing, data storage, security, customer care, payment, data analytics, marketing, advertising or other support services). Such parties may process Personal Data only in accordance with Our instructions, to the extent necessary to perform the services assigned to them, and must comply with confidentiality and data security obligations under contract and under applicable law;
    4. third parties, where required by law or by a competent authority; and
    5. other organisations and individuals, where You have given express consent or have made a direct request for the disclosure of Personal Data.
  • We shall enter into an agreement on the disclosure of Personal Data with the data recipient in order to specify the scope and purposes of processing, confidentiality obligations, personal data protection measures and the responsibilities of the parties in accordance with applicable law. In respect of the disclosure of sensitive Personal Data, We apply appropriate protective measures in accordance with applicable law, including physical security measures for storage and transmission equipment, encryption, anonymisation (where appropriate) and such other technical and organisational measures as are necessary to ensure the security of Personal Data throughout the process of transfer and processing.
  • In the event of a division, merger, consolidation, sale of business, transfer of assets or restructuring, Personal Data may be transferred to the transferee in order to continue providing the Services or to carry out the processing purposes notified, provided that such transfer fully complies with the laws on personal data protection.

G. NOTIFICATION OF PERSONAL DATA BREACHES

Upon detecting a breach of the personal data protection regulations affecting Your Personal Data, We shall notify the Department of Cybersecurity and High-Tech Crime Prevention (A05) – Ministry of Public Security within seventy-two (72) hours from the time of detection of the breach, in accordance with Decree No. 356/2025/ND-CP. In respect of breaches that seriously affect Your lawful rights and interests, We shall notify You directly within the corresponding time limit, or shall make a public announcement and notify You as soon as possible, specifying the categories of Personal Data affected, the scope and level of risk, the cause (where it can be determined) and the remedial and preventive measures that have been and will be applied.

H. CROSS-BORDER TRANSFER OF PERSONAL DATA

  • Certain third-party services used by the Application to provide and operate the Services maintain their headquarters, infrastructure, or servers outside the territory of Vietnam. Accordingly, when You use the Application, certain Personal Data may be transferred to and processed outside Vietnam. Any cross-border transfer of Your Personal Data will be carried out based on Your consent and in accordance with the applicable laws of Vietnam governing the protection of Personal Data.
  • Where a transfer of Your Personal Data outside the territory of Vietnam falls within the cases requiring a cross-border personal data transfer impact assessment dossier under applicable law, We shall prepare such dossier and submit it to the Department of Cybersecurity and High-Tech Crime Prevention (A05) – Ministry of Public Security in accordance with applicable law before carrying out such transfer. We shall transfer Personal Data to an overseas recipient only on the basis of a written agreement specifying the purposes of processing, the categories of Personal Data, the processing period, the data protection measures and the responsibilities of the parties, in accordance with the laws of Vietnam on personal data protection.

I. DATA SECURITY

  • We apply appropriate technical and organisational measures to protect Personal Data, including encryption of data in transit and at rest in respect of sensitive data, internal access controls on a need-to-know basis, and system security monitoring. In respect of sensitive Personal Data, We apply enhanced protective measures appropriate to applicable law and to the information security standards that We adopt.
  • Although We consistently endeavour to apply appropriate security measures to protect Personal Data, no information technology system or method of data transmission can guarantee absolute security. In the event of an incident affecting Personal Data, We shall implement remedial and notification measures in accordance with applicable law and shall take such measures as are necessary to mitigate loss and to prevent recurrence.

J. RIGHTS AND OBLIGATIONS OF DATA SUBJECTS

  • A Data Subject has the following rights:
    1. to be informed of Personal Data processing activities;
    2. to consent or to withhold consent, and to request the withdrawal of consent, to the processing of Personal Data;
    3. to access, rectify or request the rectification of Personal Data;
    4. to request the provision, erasure or restriction of processing of Personal Data, and to submit an objection to the processing of Personal Data;
    5. to lodge complaints and denunciations, to initiate legal proceedings and to claim compensation for damage in accordance with applicable law; and
    6. to request that competent authorities, or the agencies, organisations and individuals involved in the processing of Personal Data, implement measures and solutions to protect that person’s Personal Data in accordance with applicable law.
  • A Data Subject has the following obligations:
    1. to protect that person’s own Personal Data;
    2. to respect and protect the Personal Data of others;
    3. to provide that person’s Personal Data fully and accurately in accordance with applicable law, under contract, or upon consenting to the processing of that person’s Personal Data; and
    4. to comply with the laws on personal data protection and to participate in the prevention of conduct infringing Personal Data.
  • In order to exercise the rights and perform the obligations set out above, You may contact Us using the details set out in Section M. In respect of a request for the erasure of data, You may act directly through the “Delete account” function within the Application.

K. PERSONAL DATA OF INDIVIDUALS UNDER 18 YEARS OF AGE

  • We do not offer the Services to individuals under the age of 18 and do not knowingly collect or process the Personal Data of individuals under the age of 18. The Family Protection feature is offered to Users who are adults, acting in the role of Protector. Where a Protected Device is used by an individual under the age of 18, the linking of that device and the processing of Personal Data arising from it are carried out on the basis of the consent of that individual’s parent or lawful guardian, who acts as the Protector and is the Account holder. We do not create an Account for an individual under the age of 18. If We discover or are notified that Personal Data of an individual under the age of 18 has been provided to Us inadvertently or without the legally required consent of his/her parent(s) and/or legal guardian, where such consent is required by applicable law:
    1. We shall immediately cease processing and shall permanently delete such data from Our systems as soon as possible, save as otherwise provided by law; and
    2. the Data Subject, or the parent or lawful guardian of the child, may contact Us immediately using the details set out in Section M in order to request an inspection, the erasure of data, or the exercise of the related rights set out in Section J.

L. PERSONAL DATA OF PERSONS LACKING OR WITH LIMITED CIVIL ACT CAPACITY

In respect of a Data Subject who lacks civil act capacity, who has difficulties in cognition and behaviour control, or who has limited civil act capacity under the Civil Code, the processing of that person’s Personal Data shall be carried out on the basis of the consent and/or request of the lawful guardian, save as otherwise provided by law. The lawful guardian may exercise, on behalf of the Data Subject, the rights set out in Section J of this Policy.

M. CONTACT INFORMATION

For any comment or enquiry, please contact Us using the details below:

VERICHAINS JOINT STOCK COMPANY

Address: 2nd Floor, Saigon Paragon Building, 3 Nguyen Luong Bang, Tan My Ward, Ho Chi Minh City, Vietnam

Email: info@verichains.io

PERSONAL DATA PROTECTION OFFICER (DPO)

Email: dpo@verichains.io

Requests relating to the exercise of the Data Subject rights set out in Section J of this Policy shall be handled as a priority through the contact point specified above. Should You disagree with the manner in which We handle Your request, You have the right to lodge a complaint or denunciation with the Department of Cybersecurity and High-Tech Crime Prevention (A05) – Ministry of Public Security, or with such other competent State authority as is provided by law.

N. CHANGES TO THIS POLICY

  • We may amend, supplement or update this Policy from time to time in order to reflect changes in Our business operations, in the provision of products and Services, in technical requirements, or in order to ensure compliance with applicable law.
  • Where this Policy is updated, We shall publish the new version in the Application and on Our website, and/or shall notify You by email, telephone or such other means of communication as You have provided (where appropriate having regard to the nature of the change).
  • Your continued use of the Application after this Policy has been updated shall not be construed as Your consent in respect of any matter for which the separate consent of the Data Subject is required by law. In such cases, We shall obtain Your consent in accordance with applicable law before carrying out the processing of Personal Data.