1. Scope
This document is effective as of 11 October 2026.
This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service and any service contract between the Customer business and CMC Media Joint Stock Company. It governs the Provider's processing of personal data that the Customer enters, synchronises or collects through Yofatik CRM.
This DPA is prepared in accordance with the Law on Personal Data Protection No. 91/2025/QH15, Decree 13/2023/ND-CP and related regulations of Vietnam. In case of conflict between this DPA and the Terms of Service on personal data matters, this DPA prevails.
2. Definitions
- Controller: the Customer — the party that determines the purposes and means of processing end customers' personal data.
- Processor: the Provider — the party that processes data on the Customer's behalf under this DPA.
- Sub-processor: a third party engaged by the Provider to carry out part of the processing.
- Personal data breach: a security incident leading to unauthorised access to, disclosure, alteration, loss or destruction of personal data.
3. Roles of the parties
For personal data of end customers and of the Customer's staff within the Service, the Customer is the controller and the Provider is the processor. For the Provider's own account, billing and website visitor data, the Provider is the controller under the Privacy Policy.
4. Details of processing
| Item | Description |
|---|---|
| Data subjects | End customers (people who message, comment, order or visit landing pages); the Customer's staff; carriers and suppliers the Customer records |
| Data categories | Name, profile picture and page-scoped ID (PSID) from Facebook; message and comment content; phone numbers and delivery addresses; order and shipment history; landing-page visit data (anonymous visitor ID, ad source, IP address used temporarily for measurement) |
| Purposes | Providing the Service's features as configured by the Customer: inbox, order and customer management, shipping, landing pages, conversion tracking, reporting, technical support |
| Duration | For the term of the Service and the post-termination period in section 12 |
The Service is not designed to process sensitive personal data. The Customer will not deliberately place sensitive data in the Service unless the parties agree on additional safeguards.
5. Customer (controller) obligations
- Ensure a lawful basis, provide notices and obtain data subjects' consent where required by law, including for cookies and tracking codes on landing pages.
- Give only lawful processing instructions; be responsible for connection settings, automated rules and staff permissions.
- Receive and respond to data subjects' requests regarding their rights.
- Carry out the impact assessments and processing records that are the controller's responsibility under the law.
6. Provider (processor) obligations
- Process data only on the Customer's documented instructions, as expressed in this DPA, the contract and the Customer's configuration of the Service; inform the Customer if an instruction appears unlawful.
- Not use the data for its own purposes, and not sell or share it beyond this DPA.
- Ensure that personnel with access are bound by confidentiality and access data only when needed (support, operations, incident handling).
- Apply appropriate technical and organisational measures as described in section 9.
- Reasonably assist the Customer in meeting its obligations towards data subjects and competent authorities.
7. Sub-processors
The Customer authorises the Provider to use the sub-processors below. Platforms marked "when connected" receive data only when the Customer enables the corresponding integration.
| Sub-processor | Role | Data involved | When |
|---|---|---|---|
| Server / data-centre infrastructure provider in Vietnam | Hosting and operating the system | All Service data (isolated per business) | Always |
| Cloudflare | CDN, DNS, proxy, attack protection | Traffic passing through (IP address, HTTP requests) | For some deployments |
| Meta Platforms (Graph API, Messenger Platform, Marketing API, Conversions API) | Receiving and sending messages and comments; ad management; sending conversion events | Messages, page-scoped IDs, conversion events with hashed contact data | When connected |
| TikTok (Events API) | Sending conversion events | Conversion events, hashed contact data | When connected |
| Google (Google Analytics 4 Measurement Protocol) | Sending purchase events | Conversion events, Google Analytics client ID | When connected |
| Nhanh.vn | Creating and tracking orders and shipments | Recipient name, phone, address, goods, cash-on-delivery amount | When connected |
| Viettel Post | Creating and tracking shipments | Recipient name, phone, address, goods, cash-on-delivery amount | When connected |
| Telegram | Sending operational notifications to groups the Customer configures | Notification content (figures, possibly order codes) | When configured |
When adding or replacing a sub-processor, the Provider updates this list and notifies the Customer in advance. The Customer may object on reasonable grounds via support@cmcmedia.com.vn; if no solution is found, the Customer may terminate the affected part of the Service.
8. Storage and cross-border transfer
Service data is stored in Vietnam. Data exchanges with platforms whose servers are outside Vietnam (such as Meta, Google, TikTok, Telegram) occur only when the Customer enables the corresponding connection. The parties cooperate on the formalities for cross-border transfer of personal data required by law, each according to its role.
9. Security measures
- Encryption in transit with HTTPS;
- Per-business isolation at the database layer using row-level security;
- Encryption at rest of access keys and tokens for connected platforms; passwords stored hashed;
- Role-based access, permission-based phone masking, team-based data scoping;
- An immutable audit log; incident monitoring and alerting.
See the Security page for details.
10. Breach notification
On becoming aware of a personal data breach affecting the Customer's data, the Provider notifies the Customer without undue delay with what is known about the nature of the incident, the categories and scope of data affected, and the measures taken or planned. The parties cooperate to notify the competent personal data protection authority within 72 hours as required by law, and data subjects where necessary.
11. Assistance with data subject requests
The Service gives the Customer tools to look up, correct, export (Excel) and delete end-customer data. If the Provider receives a request directly from an end customer, we forward it to the relevant Customer and do not respond on its behalf unless required by law. Instructions for deleting data obtained from Facebook are on the Data Deletion page.
12. Return and deletion on termination
When the Service ends, the Customer has 30 days (unless the contract says otherwise) to export its data. After that, the Provider deletes or anonymises the Customer's data in production systems; any backups are purged on their rotation cycle. Data the law requires us to retain (for example logs needed for investigations, accounting records) is kept for the statutory period and used only for that purpose.
13. Audits and information
On a reasonable written request, the Provider supplies the information needed to demonstrate compliance with this DPA. Any on-site audit is agreed in advance as to scope, timing, cost and confidentiality, and must not affect other businesses' data.
14. Contact information
For personal data matters, sub-processors or incident notifications, contact:
| Item | Details |
|---|---|
| Company | CMC Media Joint Stock Company |
| Address | No. 9, Lane 160 Luong The Vinh Street, Thanh Xuan Ward, Hanoi, Vietnam |
| support@cmcmedia.com.vn | |
| Phone | 097 102 1266 |
| Website | yofatik.com |
| Application | crm.yofatik.com |
You can also reach us through the Contact page.