Your browser is too old, so this page may render incorrectly. Please update your browser.
Skip navigation, go to main content

Data Processing Agreement (DPA)

For business customers who use vne.email to process the personal data of their employees and partners. This Agreement defines each party's role, obligations, and data-protection measures under Vietnam's Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP.

Last updated: Jun 16, 2026

vne.email is operated by CÔNG TY TNHH THƯƠNG MẠI VÀ DỊCH VỤ TRIPLES (Tax ID 0316579552), address 201 Nguyễn Văn Lượng, Gò Vấp Ward, Ho Chi Minh City — referred to below as “TRIPLES” or the “Processor.” This Data Processing Agreement (“DPA”) supplements and forms an integral part of the Terms of Service, and applies whenever the Customer is a business using vne.email to process the personal data of third parties (the Customer's employees, customers, or partners).

This is a template provided for transparency about how TRIPLES processes data on the Customer's behalf, and for the Customer's review. Business customers who require a separately executed DPA should contact legal@vne.email. Specific legal terms should be confirmed with legal counsel before formal execution.

1. Roles of the parties

Under the Law on Personal Data Protection No. 91/2025/QH15 (“PDPL”) and Decree No. 356/2025/ND-CP (“Decree 356”):

  • Customer = Personal Data Controller: determines the purposes and means of processing the personal data of its mailbox users and partners.
  • TRIPLES = Personal Data Processor: processes data only on behalf of, and per the lawful instructions of, the Customer in order to provide the email/Drive service, and does not use it for its own purposes.
  • Data subjects: the Customer's mailbox users and the individuals who exchange mail with them.

For the personal data of the Customer itself (the account holder: name, email, phone number, tax ID), TRIPLES acts as the Controller, and our Privacy Policy applies.

2. Scope & categories of data processed

Data categoryProcessing purpose
Identity & contact (name, email address, display name)Creating and managing user mailboxes
Mail content & attachments; files stored on DriveStorage, sending/receiving, and sharing as directed by the user
Send/receive metadata (timestamp, sender/recipient, size)Mail routing, anti-spam/anti-spoofing, technical support
Technical access logs (IP, User-Agent, timestamp)Security, incident investigation (retained 90 days)

3. Purpose & duration of processing

TRIPLES processes personal data only to provide and operate the email/Drive service under the Customer's domain, to automatically filter spam/malware/phishing (via our in-house Rspamd — no third party ever sees mail content), and to provide technical support. Processing continues for the duration of the service agreement; after termination, data is handled per Section 8 below.

4. Sub-processors

TRIPLES uses a limited number of sub-processors for infrastructure functions. These partners do not have access to the Customer's mail content unless stated otherwise below:

PartnerFunctionLocation
FPT TelecomData center, primary server infrastructureVietnam
Backblaze B2Encrypted secondary backups (disaster recovery)United States
Casso.vn / SepayBank-transfer reconciliation (transaction details only)Vietnam

TRIPLES will notify the Customer at least 30 days in advance when adding or replacing a sub-processor, giving the Customer the right to object in writing.

5. Security measures

  • Data isolation between organizations at the database layer (per-tenant PostgreSQL Row-Level Security).
  • TLS 1.2+ enforced on every protocol (IMAP, SMTP, HTTPS); off-site backups are end-to-end encrypted.
  • Passwords are stored as irreversible Argon2id hashes.
  • Nightly, block-level encrypted backups (restic + Age); the restore process has been tested in practice.
  • DKIM + DMARC sign every outgoing message to prevent spoofing; fail2ban blocks unauthorized access attempts (SSH, SMTP, IMAP).
  • The operations team only accesses data when investigating an incident; every access is recorded in a tamper-proof audit log.

6. Cross-border data transfers

All primary user data is stored domestically (data centers in Vietnam), in compliance with Decree No. 53/2022/ND-CP. Only encrypted, end-to-end secondary backups are located outside Vietnam (Backblaze B2, United States), under a separate Age encryption key that vne.email controls. TRIPLES maintains a cross-border personal-data-transfer impact assessment under Decree 356 for this backup component.

7. Breach notification

Upon discovering a personal-data-protection breach, TRIPLES will notify the Customer without undue delay, within 72 hours of confirming the breach, including information on its scope and remediation measures; TRIPLES will also assist the Customer in meeting its notification obligations to the competent authority (Ministry of Public Security — Department A05) under Decree 356.

8. Data subject rights & support for the Controller

TRIPLES provides self-service tools for the Customer and the Customer's users to exercise data subject rights (access, rectification, erasure, restriction of processing, data portability): one-click Drive export (ZIP) and full mail download via IMAP in standard MBOX/EML format — importable into any provider. For requests beyond the scope of the self-service tools, contact privacy@vne.email.

9. Personnel security, audit & cooperation

  • Personnel with data access are bound by confidentiality obligations.
  • The Customer has the right to request reasonable evidence of compliance, or an audit, by prior agreement.
  • TRIPLES will only disclose data to a government authority upon a written request that follows proper legal process, and will notify the Customer unless prohibited by law.

10. Deletion or return of data upon termination

Upon service termination, data is retained for 30 days for recovery; during this period, the Customer can export its own data using self-service tools (Drive → Download all; mail via IMAP as .mbox/.eml). After 30 days, data is permanently deleted from the operating system, and removed from backups within the backup retention cycle (90 days).

11. Effect, amendments & contact

For material changes to this DPA, TRIPLES will provide at least 30 days' notice by email before they take effect. For any questions about this DPA, contact legal@vne.email or privacy@vne.email. This Agreement is governed by the laws of Vietnam, consistent with Section 9 of the Terms of Service.