H
HimiTek
  • Trang chủHome
  • Dịch vụServices
  • InsightsInsights
  • Giới thiệuAbout
← Quay về Trang chủ ← Back to Home

Chính Sách Bảo Mật

Privacy Policy

Cập nhật ngày: 03/09/2026

Last updated: September 3, 2026

Chào mừng bạn đến với CÔNG TY TNHH CÔNG NGHỆ HIMITEK ("HimiTek", "chúng tôi"). Chúng tôi coi trọng quyền riêng tư và cam kết bảo vệ dữ liệu cá nhân của khách hàng, đối tác và người dùng các nền tảng website cũng như ứng dụng di động của chúng tôi (bao gồm nền tảng du lịch thông minh Himitravel). Chính sách Bảo mật này mô tả cách chúng tôi thu thập, sử dụng, lưu trữ và bảo vệ thông tin cá nhân của bạn theo quy định của pháp luật Việt Nam (Luật An ninh mạng, Nghị định 13/2023/NĐ-CP về Bảo vệ dữ liệu cá nhân) cùng các tiêu chuẩn bảo mật quốc tế của Apple App Store và Google Play Store.

1. Thông tin chúng tôi thu thập

Chúng tôi có thể thu thập các loại dữ liệu sau đây khi bạn truy cập website, cài đặt ứng dụng di động hoặc sử dụng các dịch vụ của HimiTek:

  • Thông tin liên hệ cá nhân: Họ và tên, số điện thoại, địa chỉ email, địa chỉ liên lạc hoặc ảnh đại diện khi bạn đăng ký tài khoản.
  • Thông tin doanh nghiệp & hợp tác: Tên công ty, mã số thuế, chức vụ công tác khi bạn đăng ký tư vấn giải pháp B2B.
  • Dữ liệu kỹ thuật tự động: Địa chỉ IP, loại trình duyệt, phiên bản hệ điều hành, thời gian truy cập và nhật ký tương tác thông qua cookies và các công cụ phân tích bảo mật.
  • Dữ liệu đặc thù trên Ứng dụng di động (Himitravel & Hệ sinh thái HimiTek):
    • Vị trí địa lý (Geolocation): Chúng tôi chỉ thu thập dữ liệu vị trí khi bạn đang mở ứng dụng (Foreground Location / While Using the App) nhằm hiển thị các địa điểm du lịch, khách sạn, nhà hàng lân cận và lập lộ trình chuyến đi. Chúng tôi tuyệt đối không thu thập vị trí chạy ngầm (Background Location) khi bạn đã đóng ứng dụng trừ khi bạn kích hoạt tính năng dẫn đường trực tiếp và cấp quyền rõ ràng.
    • Thông báo đẩy (Push Notifications): Mã định danh thiết bị (Device Token) được sử dụng để gửi cập nhật trạng thái đặt tour, nhắc nhở lịch trình chuyến đi và các cảnh báo an toàn du lịch. Bạn có thể tắt thông báo này bất kỳ lúc nào trong cài đặt máy.
    • Camera và Thư viện ảnh: Chỉ được truy cập khi bạn chủ động cấp quyền để tải ảnh hồ sơ, đính kèm vé/chứng từ du lịch hoặc quét mã QR check-in dịch vụ.

2. Mục đích sử dụng thông tin

HimiTek chỉ sử dụng thông tin cá nhân cho các mục đích hợp pháp và minh bạch sau:

  • Cung cấp, vận hành và tối ưu hóa nền tảng du lịch Himitravel (tạo lịch trình AI, hỗ trợ chỉ đường, xác nhận đặt chỗ dịch vụ).
  • Vận hành các dịch vụ công nghệ, AI Compliance, Blockchain Traceability và hệ thống tự động hóa HimiFlow™.
  • Phản hồi yêu cầu hỗ trợ, gửi báo giá và giải quyết sự cố kỹ thuật trong vòng 8-24 giờ làm việc.
  • Gửi các cập nhật dịch vụ quan trọng, thông báo chính sách mới hoặc bản tin hữu ích (chỉ khi có sự đồng ý của bạn).
  • Tuân thủ các nghĩa vụ pháp lý, chứng từ kế toán, thuế và quy định an ninh mạng của Việt Nam.

3. Bảo mật thông tin dữ liệu

Chúng tôi áp dụng các biện pháp bảo mật kỹ thuật và tổ chức nghiêm ngặt:

  • Toàn bộ dữ liệu truyền tải giữa ứng dụng di động/website với máy chủ đều được mã hóa bằng giao thức SSL/TLS tiêu chuẩn cao.
  • Cơ sở dữ liệu được lưu trữ trên hạ tầng đám mây chuyên biệt có tường lửa bảo vệ 24/7 và sao lưu định kỳ.
  • Mật khẩu người dùng được mã hóa một chiều (hashing với Salt) và không bao giờ được lưu dưới dạng văn bản thô.
  • Quyền truy cập dữ liệu nội bộ được phân quyền theo nguyên tắc đặc quyền tối thiểu (Least Privilege).

4. Chia sẻ thông tin với bên thứ ba

HimiTek cam kết không bán, cho thuê hay thương mại hóa dữ liệu cá nhân của bạn. Dữ liệu chỉ được chia sẻ trong các phạm vi giới hạn:

  • Các đối tác thanh toán được cấp phép (VNPay, MoMo, ZaloPay, tổ chức thẻ quốc tế) để hoàn tất giao dịch thanh toán vé/dịch vụ do bạn chủ động khởi tạo.
  • Các nhà cung cấp hạ tầng đám mây và bản đồ (Google Maps APIs, AWS, Cloud VPS) dưới thỏa thuận xử lý dữ liệu bảo mật.
  • Khi có yêu cầu bằng văn bản từ cơ quan thực thi pháp luật có thẩm quyền của Nhà nước Việt Nam.

5. Quyền của chủ thể dữ liệu

Theo Nghị định 13/2023/NĐ-CP, bạn có đầy đủ các quyền: xem, chỉnh sửa, yêu cầu cung cấp bản sao dữ liệu, phản đối xử lý dữ liệu và rút lại sự đồng ý bất kỳ lúc nào.

6. Cơ chế Xóa tài khoản & Xóa dữ liệu ứng dụng di động

Nhằm tuân thủ nghiêm ngặt Hướng dẫn kiểm duyệt của Apple App Store (Guideline 5.1.1(v)) và Chính sách Google Play Data Safety, người dùng ứng dụng Himitravel có toàn quyền chủ động xóa tài khoản và dữ liệu cá nhân của mình thông qua các phương thức sau:

  • Xóa trực tiếp ngay trong ứng dụng: Mở ứng dụng Himitravel → vào mục Hồ sơ / Cài đặt (Settings) → chọn Tài khoản (Account) → chọn Xóa tài khoản (Delete Account) và xác nhận. Tài khoản của bạn sẽ ngay lập tức được khóa và bắt đầu quy trình xóa dữ liệu.
  • Gửi yêu cầu qua Web / Email: Bạn có thể gửi email yêu cầu xóa tài khoản về: hieu@himitek.com hoặc hieu@himitek.vn với tiêu đề "Yêu cầu xóa tài khoản Himitravel".
  • Thời hạn xử lý và phạm vi xóa dữ liệu: Toàn bộ dữ liệu hồ sơ cá nhân, lịch sử chuyến đi, dữ liệu vị trí đã lưu và ảnh đính kèm sẽ được xóa vĩnh viễn khỏi cơ sở dữ liệu hoạt động trong vòng 30 ngày. Các thông tin hóa đơn giao dịch (nếu có) sẽ được lưu trữ riêng biệt theo thời hạn luật định của Luật Kế toán và Luật Quản lý Thuế Việt Nam, sau đó sẽ được tự động tiêu hủy.

7. Thay đổi Chính sách bảo mật

Chúng tôi có thể cập nhật Chính sách Bảo mật này định kỳ để phản ánh các tính năng mới của ứng dụng hoặc thay đổi quy định pháp lý. Ngày cập nhật mới nhất sẽ luôn được hiển thị ở phần đầu trang.

Welcome to HIMITEK TECHNOLOGY COMPANY LIMITED ("HimiTek", "we", "us"). We respect your privacy and are committed to safeguarding the personal data of our customers, partners, and users across our websites and mobile applications (including the Himitravel smart travel platform). This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with Vietnamese laws (Cybersecurity Law, Decree 13/2023/ND-CP on Personal Data Protection) and international mobile platform policies including the Apple App Store Guidelines and Google Play Store Data Safety standards.

1. Information We Collect

We may collect the following categories of personal data when you interact with our websites, install our mobile applications, or utilize HimiTek services:

  • Personal Contact Details: Full name, phone number, email address, physical address, or profile photos provided during account registration.
  • Business & B2B Inquiries: Organization name, enterprise tax code, job title, and service requirements when requesting enterprise solutions.
  • Technical & Usage Analytics: IP address, device type, operating system version, browser type, interaction logs, and security telemetry collected via standard cookies and diagnostic tools.
  • Mobile Application Data (Himitravel & HimiTek Ecosystem):
    • Geolocation Data: We collect precise or approximate location information only while you are actively using the application (Foreground Location / While Using the App) in order to provide nearby travel attractions, curated local recommendations, and routing assistance. We never collect background location data when the application is closed unless you have explicitly initiated a turn-by-turn navigation feature and granted continuous location permissions.
    • Push Notification Identifiers: Device tokens are utilized to deliver real-time travel itinerary alerts, booking confirmation status, and critical safety notifications. You may disable push notifications at any time in your device system settings.
    • Camera and Photo Library: Accessed exclusively upon explicit user authorization to upload profile avatars, attach digital travel vouchers, or scan QR validation codes.

2. Purpose of Information Use

HimiTek uses your personal information solely for transparent and legitimate business purposes:

  • Operate, deliver, and personalize the Himitravel platform (AI-driven itinerary generation, booking coordination, and interactive mapping services).
  • Maintain and deliver enterprise technology services, AI compliance systems, and HimiFlow™ workflow automations.
  • Respond to customer support inquiries and provide technical assistance within our 8-24 hour SLA window.
  • Deliver critical service notices, policy updates, or optional newsletters where prior consent has been provided.
  • Comply with applicable legal, accounting, tax, and cybersecurity statutory requirements under Vietnamese jurisdiction.

3. Data Security & Storage

We apply robust administrative and technical safeguards to ensure data protection:

  • All data in transit between mobile applications/browsers and backend endpoints is encrypted utilizing modern SSL/TLS cryptographic standards.
  • Production databases are housed within isolated cloud infrastructure protected by continuous firewalls and automated access monitoring.
  • User credentials and passwords are irreversibly hashed with unique cryptographic salts; plain-text passwords are never stored.
  • Internal administrative access is strictly governed under role-based least-privilege security protocols.

4. Third-Party Disclosures

HimiTek strictly maintains a policy of never selling, renting, or monetizing personal data to third parties. Limited disclosures occur strictly under the following scenarios:

  • Licensed domestic and international payment gateways (e.g., VNPay, MoMo, ZaloPay, credit card processors) solely to execute bookings initiated by you.
  • Essential cloud infrastructure and mapping service providers (e.g., AWS, Cloud VPS, Google Maps APIs) bound by strict data processing confidentiality agreements.
  • Competent regulatory authorities or law enforcement agencies when mandated by formal legal processes under Vietnamese law.

5. Rights of Data Subjects

Pursuant to Decree 13/2023/ND-CP, you maintain full statutory rights to access, inspect, correct, request portability of, or withdraw consent regarding your personal data at any time.

6. Mobile App Account & Data Deletion Policy

To fully adhere to Apple App Store Review Guideline 5.1.1(v) and Google Play Data Safety requirements, users of Himitravel and any mobile application published by HimiTek have the unabridged right to permanently delete their account and associated data:

  • Direct In-App Deletion: Open the Himitravel app → navigate to Profile / Settings → select Account → tap Delete Account and confirm. Your account will be immediately deactivated and scheduled for permanent removal.
  • Web / Email Submission: You may submit an account and data removal request at any time by contacting us at: hieu@himitek.com or hieu@himitek.vn with the subject header "Himitravel Account Deletion Request".
  • Purge SLA & Retention Scope: Upon request confirmation, all personally identifiable information, trip history, saved geolocations, and uploaded media are permanently purged from active production servers within 30 days. Transactional and tax-relevant billing records will be archived in encrypted, isolated cold storage strictly for the statutory retention period required by Vietnamese tax and accounting laws, after which they are systematically destroyed.

7. Amendments to This Policy

We may update this Privacy Policy periodically to reflect enhancements in application features or changes in international regulatory standards. The effective date of the latest revision will always remain visible at the top of this document.

© 2026 HimiTek. All rights reserved.