HRGs Core Privacy Commitments
Data security
HTTPS/TLS encryption in transit, secure password hashing, and strict role-based access controls.
We do not sell data
We will never share, commercially exchange, or sell your information to third parties.
Your rights
You can access or correct personal information, or withdraw consent to data use at any time.
1. Introduction
This Privacy Policy applies consistently to the HRGs system, website, and platform at hrgs-csv.com, including all associated subdomains, owned and directly operated by Cube System Vietnam Co., Ltd. HRGs is provided as a human resource management software service for enterprise customers.
This document explains how we collect, use, retain, and protect information when you visit the website or operate HRGs. Continued use confirms that this Policy has been made available to you; where processing requires consent, we or the enterprise customer will request it separately through a clear affirmative action before processing begins.
2. Service Model & Data Processing Roles
HRGs operates on a multi-tenant cloud architecture. Users should therefore distinguish between the following two independent data processing roles:
- Main website data at hrgs-csv.com: When you visit the solution website, request a quotation, or submit a trial registration, we act as the Data Controller.
- Management data in a private tenant: For employee information and payroll data uploaded directly by an enterprise customer to its isolated subscription space (for example, tenant-company.hrgs-csv.com), the enterprise customer is the Data Controller and we act as the Data Processor solely under executed instructions and commercial agreements.
3. Information We Collect
To keep HRGs operating smoothly, we collect only the minimum information necessary for each specific context:
Contact data
Name, email address, telephone number, represented company, and the message included in your request.
Account records
System administrator username, access password (secured using one-way hashing), and assigned permissions.
Human resource data
Internal records, fingerprint or facial attendance history, and payroll data entered directly by the customer.
System information
User IP address, browser type, and system operation logs used for security auditing.
4. Purposes for Using Information
We process information collected through HRGs for the following clear and transparent purposes:
5. Legal Basis and Compliance
HRGs processes personal data only on a lawful basis, including the data subject's clear consent, performance of a contract, a legal obligation, or another basis permitted by law. Before requesting consent, the notice will identify the data, purposes, processing parties, data-subject rights and obligations, processing period, and withdrawal method. Silence or failure to respond is not treated as consent.
The current framework includes Vietnam's Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, together with other applicable Vietnamese law. Decree No. 356/2025/ND-CP took effect on January 1, 2026 and replaced Decree No. 13/2023/ND-CP.
6. Sharing, Subprocessors, and Cross-Border Transfers
We do not sell or unlawfully share personal information. Data is shared only in strictly limited circumstances:
- With the enterprise that owns the tenant and users it authorizes.
- With contracted cloud infrastructure, hosting, backup, email delivery, or technical-support providers, under confidentiality and data-protection terms and only as needed to provide the service.
- When disclosure is required by a valid written request from a competent Vietnamese authority.
The current list of subprocessors, services, and countries where data is stored or accessed is included in the customer's order form or data processing agreement, or is available upon request at info@vn-cubesystem.com. We will provide advance notice of a material new subprocessor.
If personal data is transferred to or accessible from outside Vietnam, we will complete the legally required impact assessment, filings, and notifications; bind the recipient to data-protection terms; restrict access by purpose; and apply appropriate technical safeguards. Cross-border transfers occur only in accordance with Law No. 91/2025/QH15, Decree No. 356/2025/ND-CP, and the customer agreement.
7. Data Retention and Security
We retain personal data only as long as needed for the stated purpose, contract, and legal obligations. Unless a contract or law requires a different period, our default schedule is:
- Contact and consultation requests: 24 months after the last interaction.
- Accounts, access logs, and security logs: for the service term and up to 12 months afterward, unless longer retention is needed for incident investigation or a legal obligation.
- Tenant HR, payroll, and biometric data: under the enterprise customer's instructions; after termination, a 30-day export window, deletion from production within the following 60 days, and backup expiry within no more than 90 days.
- Records required by law or an active dispute: for the applicable mandatory period, then deleted or anonymized.
We apply risk-appropriate layers of security, including:
8. Your Rights
Data subjects retain control over their personal information. We respect and protect the following rights:
Right of access
You may request a data export and review the categories of personal information we hold about you.
Right to correction
You may update information directly or ask a system administrator to correct inaccurate data fields.
Right to an explanation
You may request details of the data processing procedure and the purposes for which automated HRGs systems use your data.
Right to withdraw consent
You may withdraw consent through the account mechanism, your tenant administrator or HR team, or by emailing info@vn-cubesystem.com. Withdrawal applies to future processing and does not affect processing lawfully completed beforehand.
We verify identity, record the request, and respond within the period required by law. If a request cannot be fulfilled because of a retention duty, another person's rights, or a legal restriction, we will explain the applicable basis. Withdrawing consent is made as easy as giving it; after verification, we stop processing based on consent except where another lawful basis permits continued processing.
* For HR data in a tenant, the enterprise customer is the Data Controller. Please contact your organization's HR team or administrator first; Cube System Vietnam will assist under the customer's lawful instructions.
9. Data Breach Response and Notice
When we detect an incident that may affect personal data, we isolate and assess it, preserve evidence, mitigate harm, and coordinate with the enterprise customer. Where reporting is legally required, Cube System Vietnam will notify the specialized personal-data protection authority no later than 72 hours after detection; when acting as a Data Processor, we will promptly notify the Data Controller.
For incidents affecting location or biometric data, affected data subjects will be notified within the legally required period. The notice will describe the affected data, potential risks, measures taken, protective steps the individual can take, and a contact point, unless notification is restricted by law.
10. Cookies and Tracking Technologies
HRGs uses only the minimum technical cookies required to keep the software stable and does not use advertising cookies:
Session cookie (necessary)
Maintains sign-in state; expires on sign-out, browser close, or after no more than 24 hours.
Security cookie (necessary)
Prevents CSRF and session abuse; expires with the session or after no more than 24 hours.
Preference cookie
Stores language and interface settings; retained for up to 12 months or until deleted.
We do not use advertising cookies. If non-essential analytics or functional cookies are added, we will update this list and obtain prior consent where required by law.
11. Minors' Data
The website and HRGs administrator accounts are intended for business users aged 18 or older. We do not knowingly collect data directly from children through the website. If an enterprise customer enters a minor employee's record into a tenant, that enterprise is responsible for identifying a lawful basis, providing notice, obtaining a legal representative's consent where required, and restricting access under Vietnamese law.
12. Changes, Review, and Language
This Policy is reviewed at least annually and whenever material changes occur in law, processing purposes, subprocessors, or safeguards. Each release carries a version number and updated date, and the new version is published on this page.
Before a material change, we will email tenant administrators or display an in-product notice a reasonable time before it takes effect. The Vietnamese version is controlling; English and Japanese translations are for convenience unless mandatory law or an executed customer agreement provides otherwise.
13. Personal Data Protection Contact
Cube System Vietnam designates personal-data protection personnel/contact point to receive data-subject requests, coordinate impact assessments, manage incidents, and support compliance. For questions, rights requests, or incident reports, contact:
Address: 4th Floor, ICT2 Office Building, Lot 46, Quang Trung Software Park, Trung My Tay Ward, Ho Chi Minh City, Vietnam
