Privacy Statement

Effective date: 24 August 2026
Last updated: 24 August 2026
1. Introduction
We encourage you to read this Statement in full. If you have questions after reading it, Section 17 explains how to contact us.
2. Data Controller
For the purposes of applicable data protection law, CodeLink acts as the data controller of your personal data. Where personal data is shared within CodeLink’s corporate group, it is shared only to the extent necessary to fulfill the purposes described in this Statement, under a shared Intra-Group Agreement that maintains a consistent standard of protection across the group.
3. Our Commitment to Data Protection and Security
We implement technical and organizational security measures designed to protect the personal data we process, appropriate to the sensitivity of that data and the risks involved. As with any system that transmits or stores information electronically, no method of transmission or storage can be guaranteed to be completely secure. We continually review and update our safeguards to reduce this risk, and Section 12 explains what we do if a breach nonetheless occurs.
4. Categories of Personal Data We Collect
Depending on your relationship with us, we may collect:
- Identity and contact details — name, contact details, gender, photographs
- Professional details — company name, job title, employment status, service requirements
- Recruitment data — application letters, CVs/resumes, employment history, references, education history, professional qualifications, and test or assessment results
- Other relevant skills and evaluation results collected during recruitment or engagement processes
5. How We Collect Your Personal Data
We may collect personal data from the following sources:
- Directly from you — through an application, engagement, or any form or communication you provide to us
- From CodeLink group entities or subsidiaries, in connection with your application, partnership, or consultancy relationship
- Through your activities in the course of your engagement — for example, your interactions with our employees, customers, or systems
- From third parties — including references, former employers, public authorities, background-check providers, recruitment agencies, and professional or social media platforms such as LinkedIn
6. Purposes and Legal Bases for Processing
We process personal data only for specific, legitimate purposes, and only on a valid legal basis.
| Purpose | Examples | Legal Basis |
|---|---|---|
| Recruitment | Applications, interviews, candidate assessment | Consent; pre-contractual steps |
| Website use | Cookies, analytics, reporting | Consent |
| Form submissions | Service inquiries, meeting scheduling | Consent; contractual necessity |
| Business operations | IT systems, vendor management, asset management, strategic planning | Legitimate interests; contractual necessity |
| Communications | Newsletters, internal/partner communications | Consent; legitimate interests |
| Compliance | Tax, insurance, audits, government inspection | Legal obligation |
7. Cookies and Similar Technologies
When you visit our website, we use cookies and similar technologies to support internal analytics and reporting. Where required by applicable law, we will request your consent before placing non-essential cookies, and you will be able to manage your preferences through our cookie banner or browser settings.
8. Video Surveillance
CodeLink operates video surveillance at the entrances of its premises for security purposes. Footage is used solely for the security and safety of our premises, employees, and visitors, and is retained only for as long as necessary for that purpose.
9. Sharing and Disclosure of Personal Data
We share personal data only where necessary to fulfill the purposes described in this Statement or where required by law. We may share your data with third-party service providers, suppliers, or agents who perform services on our behalf. We have contracts in place with these parties that restrict them from using your personal data other than as we instruct, from sharing it with anyone else, and that require them to protect it and retain it only for the period we specify.
Current categories of recipients include:
- Cloud computing service providers — currently Google Cloud Platform
- Professional advisers, auditors, and public authorities, where required by law
10. International and Cross-Border Data Transfers
Some of our service providers, including Google Cloud Platform, may store or process personal data outside Vietnam. Where we transfer personal data across borders, we take steps to ensure it remains protected consistent with applicable law, which may include cross-border transfer documentation and impact assessments where required.
11. Data Retention
We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, or as required by law. In particular:
- Unsuccessful candidate data is deleted or destroyed after the recruitment process concludes, unless you have agreed we may retain it for future opportunities
- Employee data is deleted or destroyed upon termination of employment, unless retention is otherwise agreed or required by law (for example, statutory tax or labor record-keeping)
- Business and compliance records are retained for the periods required under applicable tax, labor, and corporate law
12. Data Security Measures
We maintain technical and organizational security measures appropriate to the risk associated with the personal data we process, including access controls, contractual safeguards with our service providers, and physical security at our premises.
If we become aware of a personal data breach, we will assess its severity and take prompt corrective action. Where required by law, we will notify the Ministry of Public Security within 72 hours of detecting the breach, and we will notify affected individuals where the breach is likely to result in a risk to their rights and freedoms.
13. Your Rights as a Data Subject
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Request rectification of inaccurate or incomplete personal data
- Request erasure of your personal data
- Object to, or request restriction of, our processing of your personal data
- Request portability of your personal data, in a structured, commonly used format, where technically feasible
- Withdraw your consent at any time (see Section 14)
💡 To exercise any of these rights, contact CodeLink’s Operations Team using the details in Section 17. We will respond within the statutory timeframe — currently 72 hours under Vietnamese law for access, rectification, erasure, and restriction requests — and may need to verify your identity before acting on your request.
14. Withdrawal of Consent
Where we rely on your consent to process your personal data, you may withdraw that consent at any time by contacting us. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and does not affect processing that continues to rely on another valid legal basis, to the extent permitted by applicable law.
15. Marketing Communications
Where we send you marketing or promotional communications, we do so only with your prior opt-in consent, and we will tell you what content you will receive, how, and how often. You may opt out at any time using the unsubscribe link in our communications or by contacting us directly.
16. Automated Decision-Making
CodeLink does not currently use automated decision-making or profiling that produces legal or similarly significant effects on individuals without human involvement. If this changes, we will update this Statement and provide the information required by applicable law.
17. Contact Us
Questions or concerns about this Privacy Statement can be sent to:
- Legal entity: CodeLink Company Limited
- Head Office: Level 8, VINA Building, 131 Xo Viet Nghe Tinh Street, Gia Dinh Ward, Ho Chi Minh City, Vietnam.
- Hotline: (+84)28-393-3314
- Email: privacy@codelink.io
18. Governing Law
This Statement, and CodeLink’s processing of personal data, is governed by the Law on Personal Data Protection (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP of Vietnam, together with other applicable Vietnamese law. Where CodeLink processes personal data of individuals located in other jurisdictions (for example, the European Union), the data protection law of that jurisdiction (such as GDPR) may also apply.
19. Changes to This Statement
We may update this Privacy Statement periodically, including to reflect changes in applicable law. The current version’s effective date is shown in the Document Control table at the front of this Statement. We encourage you to review this page periodically.
Engineering Excellence.
Built for Enterprise and Institutional Innovation.
