MANIVO PRIVACY POLICY
Version: 1.1 Effective date: 2 September, 2026 Last updated: 5 September, 2026
1. Introduction
1.1. Manivo ("we", the "Platform") is operated by Công ty TNHH Avio Group — business registration/tax number: 5702128465, registered office at Thôn 11, Đặc khu Vân Đồn, tỉnh Quảng Ninh, Vietnam — and is committed to respecting User privacy and protecting personal data.
1.2. This Policy explains how we collect, use, share, store and protect personal data when Users interact with the Platform (website, mobile app, API).
1.3. This Policy applies together with the Manivo Terms of Service and forms an integral part of the agreement between Manivo and the User.
1.4. By using the Platform, the User acknowledges that they have read and agreed to this Policy and consents to Manivo processing personal data as described.
2. Definitions
- "Personal data": any information in the form of symbols, letters, numbers, images, sound or similar electronic form attached to, or used to identify, a specific individual, including basic and sensitive personal data under Vietnamese law.
- "Data subject": the individual to whom the personal data relates.
- "Data controller": Manivo, which determines the purposes and means of processing.
- "Data processor": a third party that processes personal data on behalf of Manivo under a written agreement.
- "Processing": collection, recording, analysis, storage, alteration, disclosure, transmission, sharing, deletion, destruction and related operations.
3. Data we collect
3.1. Data from the Zalo account (with the User's consent)
Most Users sign in to Manivo with Zalo. When they do, Manivo receives from Zalo, only within what the User approves on Zalo's permission screen:
- Display name and avatar — used as the name and picture on the Manivo profile.
- Zalo identifier (zaloId) — to recognise the User on later visits, and so that the web account and the Zalo Mini App account are one and the same.
- Phone number — only when the User approves it on a separate permission screen. Declining still allows the User to browse and edit their profile; it only means they cannot post a job and cannot quote, because a verified phone number is the precondition for transacting.
Manivo does not store Zalo access tokens and does not read messages, contacts or any other data in the User's Zalo account.
3.1bis. Data the User enters
- Account information (for email sign-up): full name, email, password (hashed — Manivo cannot see the original).
- Posting content: job description, field, area, budget range, desired deadline. Postings are publicly visible to all other users — private information does not belong there.
- Quote content: price, number of days, message to the Client.
- Freelancer profile: field, experience, introduction, portfolio photos, service area, indicative pricing.
- Additional identification (Select Pros only): identity documents, tax code, practising certificates — collected if and only if the Pro joins the Manivo Select tier.
- Reviews, feedback, complaints and supporting documents.
3.2. Automatically collected data
- Device and technical data: IP address, device type, operating system, device identifiers, browser version, language.
- Usage logs: access time, click behaviour, features used, error logs.
- Approximate location based on IP, or precise location where permitted.
- Cookies and similar technologies (see Section 9).
3.3. Data from third parties
- Information from authentication providers (Zalo, Google) within the scope authorised by the User — see Section 3.1.
- Information from anti-fraud and analytics partners.
- Publicly available information used for professional verification.
3.4. Sensitive personal data
Manivo minimises processing of sensitive personal data. Where processing is required (e.g., ID numbers for identity verification under the 2025 E-commerce Law), Manivo discloses the purpose and obtains specific consent.
4. Purposes and legal bases
Manivo processes personal data for the following purposes:
- Providing and operating the Platform: account creation and management, authentication, Pro profile display, Client–Pro connection, transaction support. Basis: performance of contract.
- Charging Select Fees: quoting, invoicing and reconciliation for Select Requests. The Open tier is free, so no payment data is processed for it. Basis: performance of contract and legal obligation.
- Customer support and dispute facilitation: complaint handling, facilitation between Clients and Pros. Basis: legitimate interest and consent.
- Security and fraud prevention: detecting unusual behaviour, preventing fraud, protecting accounts. Basis: legitimate interest and legal obligation.
- Legal compliance: complying with the 2025 E-commerce Law, tax law, anti-money-laundering rules, and providing information to competent authorities upon lawful request. Basis: legal obligation.
- Product improvement: statistical analysis, UX improvement, feature testing. Basis: legitimate interest, without disproportionate impact on privacy.
- Marketing communications: product announcements, promotions, surveys. Basis: consent — the User may withdraw consent at any time.
Manivo does not use personal data for fully automated decision-making that produces legal or similarly significant effects on the User without an appropriate legal basis.
5. Data sharing
Manivo only shares personal data in the following cases:
- Between Client and Pro — phone numbers are released only after a match. This is the rule Manivo enforces most strictly:
- Before the Client chooses a Pro: Pros see the posting content and the Client's display name; Clients see the Pro's public profile (name, picture, field, area, rating, completed jobs, portfolio). Neither party's phone number appears anywhere — not in postings, not in public profiles, not in the quote list. - After the Client chooses a Pro: those two parties — and only those two — see each other's phone number in order to talk on Zalo. Manivo releases it through a dedicated function and records when it was released. - Phone numbers are never shared with Pros who were not chosen, with other users, or with third parties for marketing.
- Service providers (processors): cloud infrastructure, email providers, analytics, anti-fraud tools, customer support — bound by written data processing agreements that meet PDPA requirements.
- Competent authorities: upon lawful request under Vietnamese law (tax authorities, police, courts, e-commerce regulators).
- Operational partners: payment providers used to collect Select Fees, and SMS/email providers used when Manivo sends verification codes or notifications — note: Manivo does not share card data with any party other than a licensed payment provider.
- Corporate restructuring: in the event of merger, spin-off, transfer or similar event, data may be transferred to the successor with a commitment to continued protection.
- User's explicit consent: for any sharing beyond the scope above.
Manivo does not sell personal data to any third party.
6. Cross-border data transfers
6.1. Some of Manivo's infrastructure is located in Singapore (e.g., cloud services, backups). As a result, personal data may be transferred, stored and processed outside the territory of Vietnam.
6.2. When transferring data abroad, Manivo undertakes the following:
- Conducts a cross-border data transfer impact assessment under Decree 13/2023/ND-CP;
- Submits the cross-border transfer impact assessment dossier to the Department of Cyber Security and High-Tech Crime Prevention (A05) of the Ministry of Public Security, as required;
- Signs standard data processing agreements with the receiving party, containing protection obligations equivalent to Vietnamese law.
6.3. For data subjects in the EU/EEA, Manivo relies on valid transfer mechanisms under GDPR (e.g., EU Standard Contractual Clauses).
7. Retention
7.1. Manivo retains personal data only for as long as necessary to fulfil the purposes of processing or to meet legal requirements:
- Active account data: for as long as the account remains active.
- Closed account data: up to 12 months after closure, unless law requires longer retention (e.g., tax records must generally be kept for at least 10 years under the Accounting Law).
- Transaction and invoice records: in line with tax and accounting legislation (typically 5–10 years).
- Technical and security logs: 12 to 24 months for incident investigation.
- Marketing data: until the User withdraws consent.
7.2. After the retention period ends, Manivo deletes or anonymises the data through an internal technical procedure.
8. Data subject rights
Under Vietnamese law and the GDPR (where applicable), Users have the following rights in respect of their personal data:
- Right to be informed about processing.
- Right to give and withdraw consent.
- Right to access personal data.
- Right to rectification of inaccurate data.
- Right to erasure (where permitted by law).
- Right to restriction of processing.
- Right to object to processing in certain cases.
- Right to lodge complaints with competent authorities.
- Right to data portability — applicable under GDPR.
- Right not to be subject to purely automated decisions that produce legal effects.
- Right to seek compensation for damages in accordance with the law.
Exercising rights — three routes, any of them works:
- Message Manivo's Zalo Official Account — fastest, and Manivo recognises you immediately because the account is linked to Zalo.
- Email legal@manivo.co.
- Do it yourself in the app: view and edit your profile under Profile; request account deletion under Settings.
Manivo responds within 72 hours or within the period required by law, and may request identity verification first — so that nobody can obtain your data by impersonating you.
Note on the right to erasure: Manivo deletes your profile and personal data, but retains completed transaction records in anonymised form (no name, picture or phone number). The reason: a review your counterparty received is their reputation, and erasing it would take away something that is not yours. Such retention follows Section 7.
9. Cookies and similar technologies
9.1. Manivo uses cookies and similar technologies (pixels, local storage) to:
- Maintain login sessions;
- Remember language and preferences;
- Measure product performance;
- Support anti-fraud features.
9.2. Cookie categories:
- Strictly necessary cookies: cannot be declined as they are essential for core functionality.
- Optional cookies: analytics, personalisation, marketing — require User consent.
9.3. Users may manage cookies through the cookie banner on the Platform or through browser settings. Disabling strictly necessary cookies may make some features unavailable.
10. Data security
10.1. Manivo applies reasonable technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS) and encryption at rest for sensitive fields;
- Access control based on the principle of least privilege;
- Logging, monitoring and anomaly detection;
- Security incident response procedures;
- Staff training on personal data protection;
- Periodic reviews and risk assessments.
10.2. Despite these efforts, no system can guarantee absolute security. In the event of a personal data incident, Manivo notifies Users and the competent authorities within the statutory deadline (e.g., within 72 hours under Decree 13/2023/ND-CP and GDPR).
11. Children's data
The Platform is not intended for anyone under 18. Manivo does not knowingly collect children's personal data. If we become aware of such data, we will delete it and notify the guardian where appropriate.
12. Data Protection Officer (DPO)
Manivo appoints a Data Protection Officer (DPO) to oversee compliance and serve as the contact point for Users and regulators.
- Name: [TBD]
- Title: Data Protection Officer
- Email: legal@manivo.co
- Address: Thôn 11, Đặc khu Vân Đồn, tỉnh Quảng Ninh, Vietnam
- Target response time: 72 hours from receipt of the request
13. Information for EU/EEA users (GDPR)
Where Manivo processes the data of EU/EEA data subjects, Manivo additionally applies:
- Legal bases in accordance with Article 6 GDPR (performance of contract, legal obligation, legitimate interests, consent).
- EU representative: to be appointed and published when Manivo offers services directly in the EU.
- Right to lodge complaints with the supervisory authority in the Member State of residence.
- Cross-border transfers outside the EEA are safeguarded by Standard Contractual Clauses or other lawful mechanisms.
14. Changes to this Policy
14.1. Manivo may update this Policy to align with legal or operational changes. Updates will be posted on the Platform with an effective date.
14.2. Material changes will be notified by email or in-app notice at least [X] days before taking effect. Continued use of the Platform constitutes acceptance of the updated Policy.
15. Contact
- Operating entity: Công ty TNHH Avio Group
- Business registration/tax number: 5702128465
- Registered office: Thôn 11, Đặc khu Vân Đồn, tỉnh Quảng Ninh, Vietnam
- Support email: support@manivo.co
- Data protection / DPO email: legal@manivo.co
- Hotline: 0899772886
- Website: https://manivo.co