
Applicable to the UP — Unified Platform, funded and operated by ASIF Foundation, and to its member organizations, users, donors, partners, staff, volunteers and beneficiaries.
This Policy establishes a unified governance framework for information security, system safety and data protection for the UP — Unified Platform ("UP"), to protect the lawful rights and interests of ASIF Foundation, member organizations, users, donors, partners, staff, volunteers and beneficiaries.
The Policy is built on the principles of risk-based governance, privacy and security by design and by default, data minimization, need-to-know access, and accountability; and references ISO/IEC 27001, 27002, 27017, 27018 and 27701 practices to the extent appropriate for the scale, resources, and nonprofit nature of UP. This reference should not be understood as a statement that ASIF or UP has been certified against these standards.
This Policy is applied in accordance with the laws of Vietnam in effect from time to time, including but not limited to: the 2015 Civil Code; the 2015 Law on Network Information Security; the 2018 Law on Cybersecurity; the 2023 Law on Electronic Transactions; the 2024 Data Law; the 2025 Law on Protection of Personal Data; Decree No. 13/2023/ND-CP on personal data protection; Decree No. 53/2022/ND-CP; laws on accounting, records retention, intellectual property, children, medical examination and treatment, and their amending or replacing documents.
Where there is a discrepancy between this Policy and a mandatory legal provision, the mandatory legal provision shall prevail. ASIF will review and update this Policy when there is a change in law or a significant change to its data-processing model.
This Policy should be read together with UP's Terms of Use, the Memorandum/Partnership Agreement (MOA), and any data-processing addenda. In the event of a conflict, the document with higher legal effect, or the more specific data-protection provision, shall prevail, unless the law provides otherwise.
For data collected and entered into UP by a member organization, the member organization is responsible for determining the purpose, legal basis, scope, retention period, and for providing notice to data subjects. ASIF and the technology partner process such data only to the extent necessary to provide, maintain, secure, support and improve the service in accordance with the agreement and the law.
Where ASIF independently determines the purpose and means of processing its own data, ASIF acts as the data controller for that activity. Specific roles may be adjusted in the MOA or a data-processing addendum.
| Term | Explanation |
|---|---|
| ASIF Foundation | The entity that funds, manages and operates UP; the primary point of governance for the service and coordination with the technology partner. |
| Member Organization | A social organization, nonprofit, social enterprise, or lawful entity granted the right to use UP by ASIF under an MOA. |
| Data Subject | An individual reflected by personal data, including staff, volunteers, donors, partners, beneficiaries and users. |
| Data Controller | The party that determines the purpose and means of processing personal data. A member organization is typically the Data Controller for data it uploads to UP. |
| Data Processor | A party that processes personal data on behalf of the Controller, within the scope, purpose and lawful instructions given. |
| Sub-processor | A technology partner or vendor engaged by the Processor to carry out part of the processing activity. |
| Organizational Data | Any data, document, configuration or content created, entered or stored on UP by a member organization or user. |
| Sensitive Personal Data | Data requiring a higher level of protection under law, such as health, financial, biometric, children's data, location, or other sensitive personal information. |
| Data Incident | An event resulting in the loss, destruction, alteration, disclosure of, or unauthorized access to, data; or that degrades the confidentiality, integrity, or availability of the system. |
| Integrated AI | An artificial-intelligence feature approved by ASIF and integrated into UP or a related process. |
ASIF does not sell, rent, exchange or commercially exploit organizational data or personal data on UP. Data is processed only to provide the service, ensure safety, provide technical support, comply with legal obligations, or follow the lawful instructions of a member organization.
Data belonging to children, persons with disabilities, patients, the elderly, and other vulnerable groups must be processed with a heightened degree of care. Member organizations must ensure a lawful basis, consent, or the approval of a legal representative as required by law; must limit the display of identifying information; and must not use such data in a way that could stigmatize, harm, or violate the dignity of the individual.
| Principle | Application Requirement |
|---|---|
| Lawfulness, fairness and transparency | Process data only on a lawful basis; provide clear, understandable, and non-misleading notice. |
| Purpose limitation | Data may only be used for its defined purpose; a new purpose must be assessed and have an appropriate basis. |
| Data minimization | Only collect and access data that is necessary, relevant and not excessive for the purpose. |
| Accuracy | Maintain a mechanism to update, correct and remove inaccurate data when needed. |
| Storage limitation | Do not retain data longer than necessary or than required by law. |
| Security, integrity and availability | Apply organizational and technical measures proportionate to the risk. |
| Accountability | Keep evidence of decisions, access permissions, consent, data-subject requests, and incident handling. |
| Privacy and security by design and by default | Assess security and privacy from the design, configuration and deployment stage. |
The business unit that creates the data is the data owner and is responsible for determining classification, approving access, conducting periodic review, and deciding on retention or destruction. The Organization Admin is responsible for configuring system permissions in accordance with the data owner's decisions.
Data must remain protected at its corresponding classification level after being exported from UP. Users must not store confidential or sensitive data on public devices, personal accounts, unapproved storage services, or send it through unsecured channels. Member organizations are responsible for managing copies exported from UP.
| Classification | Example | Minimum Requirement |
|---|---|---|
| Public | Approved communications materials | May be published; version control and copyright must be maintained. |
| Internal | Processes, plans, operational documents | Internal/authorized users only; no external sharing without approval. |
| Confidential | Contracts, budgets, HR data, donor pipeline | Role-based access; encrypted in transit; restricted download and sharing. |
| Restricted / Highly Sensitive | Health data, children's data, identification, bank accounts, safeguarding cases | Access on a strict need-to-know basis; MFA; logging; restricted export; separate approval. |
| Data Category | Reference Period | Principle |
|---|---|---|
| Accounting, financial and voucher data | As required by accounting law and donor requirements; typically 5–10 years or longer where a specific obligation applies | Decided and owned by the member organization. |
| HR and employment records | Per labor law, social insurance, tax law, and the organization's own retention policy | Access restricted after the employment relationship ends. |
| Program/beneficiary data | Per the project lifecycle, donor requirements, safeguarding requirements, and legal basis | Prefer anonymization/pseudonymization once identification is no longer needed. |
| Access logs and security logs | A minimum of 12 months; up to 24 months for critical systems | For investigation, audit and compliance purposes. |
| Operational backup copies | Per the published backup cycle; typically 30–90 days | Backups do not replace formal business records. |
| Data after service termination | Data export period per the MOA; deleted or anonymized thereafter per procedure | Unless retention is required by law or a dispute. |
Deletion must be authorized, verifiable, and consistent with the backup mechanism. Where immediate deletion from a backup copy is not possible, the data must be isolated, not used for another purpose, and overwritten on a rolling cycle. Data used for statistics or improvement must be anonymized or aggregated to a level where an individual cannot reasonably be identified.
To the extent permitted by applicable law, a data subject has the right to be informed; to consent or refuse where consent is required; to withdraw consent; to access, view, or request a copy; to correct; to request deletion; to restrict or object to processing; and to complain, denounce, sue or claim compensation as provided by law.
The member organization is the primary point of contact for requests relating to data it controls. ASIF provides reasonable technical support at the valid request of the member organization. Requests must be identity-verified, logged, classified, handled within the legally required or committed timeframe, and evidence of fulfillment retained.
A data subject's rights may be limited where exercising them would affect the rights of others, an organization's or third party's confidential information, a mandatory retention obligation, an investigation into a violation, fraud prevention, safeguarding, or another case permitted by law. Any refusal must be justified and appropriately explained.
UP applies the principles of least privilege, separation of duties, and need-to-know. Access rights must be role-based, approved by an authorized person, and recorded in the system. Organization Admins must not grant themselves permissions beyond the scope of their own authorization.
Personal devices may only be used where the organization permits it and where minimum requirements are met for screen lock, security updates, anti-malware software, device encryption, and remote-wipe capability where appropriate. Sensitive data must not be accessed over an unsecured public network without additional protective measures.
UP is deployed on cloud infrastructure or a data center approved by ASIF. ASIF and the technology partner aim to apply appropriate measures within available resources, which may include network segmentation, firewalls, configuration management, encryption in transit, encryption at rest where feasible, key management, anti-malware, patching, monitoring, backup, and privileged access control.
Software changes must be recorded, tested and approved before deployment. Source code, application secrets and access keys must not be stored in public repositories. Vulnerabilities are classified by risk level and remediated within internal timeframes; emergency changes must be reviewed after deployment.
The technology partner performs backups according to the agreed architecture and service level. Backup copies must be protected from unauthorized access, reasonably separated from the production environment, with a recovery-testing plan carried out on an internal schedule depending on resources and the risk level at the time. Specific recovery objectives (RTO/RPO) are set out in the MOA or a technical agreement document, and should not be presumed to be an absolute commitment unless recorded in writing.
ASIF commits to conducting a risk-proportionate assessment before selecting or changing a data-processing vendor, within available resources. Vendor contracts should address the scope of processing, security, authorized personnel, incident handling, support for data-subject rights, data deletion or return, audit rights, and obligations upon termination.
An integration may only be enabled with appropriate approval. The member organization is responsible for assessing the purpose and lawfulness of any data sharing arising from an integration it requests. ASIF has the right to disable an integration that poses a security risk, violates the law, or affects UP.
Because UP uses international cloud infrastructure services, part of the Platform's technical operations may be processed at data centers located outside the territory of Vietnam, in line with the provider's standard operating architecture. ASIF Foundation and the technology partner will comply with the Vietnamese laws applicable to this activity, and will carry out the necessary procedures required by law or a competent authority when a corresponding obligation arises.
The UP Platform does not currently have a built-in artificial intelligence (AI) feature. The principles below are recommendations and reminders for users at member organizations who use external AI tools (such as ChatGPT, Copilot, etc.) while working with data on UP, and will become mandatory principles should UP integrate an AI feature in the future.
Where content or a decision of significant consequence is AI-assisted, the member organization must be appropriately transparent, retain a record of its use, and ensure a human-review channel exists. Users are responsible for how they use AI-generated output.
All data on UP belongs to the member organization (per Section 7.3 of the Terms of Use). The member organization is therefore responsible for managing and monitoring how its own staff and volunteers use AI. ASIF Foundation has no obligation to monitor, detect, or bear legal liability for a violation of the above principles by a user of a member organization, consistent with the limitation of liability set out in Sections 14.2 and 15 of this Policy.
UP may log logins, access, data changes, data exports, permission changes, administrative actions, and security events. Logs are accessible only to authorized personnel, protected from tampering, and used for security, support, audit, compliance, and incident-investigation purposes.
ASIF may monitor performance, traffic, anomalies, and compliance without reading business content beyond what is necessary. Where access to data is required for support or investigation, such access must be restricted, logged, and terminated immediately once complete.
ASIF commits to working with the technology partner toward reviewing configurations, scanning for vulnerabilities, testing recovery, assessing access rights, and conducting security checks at a level of risk and resourcing appropriate for a nonprofit organization. Penetration testing may be carried out when needed, upon a major change, or at the reasonable request of a donor/partner, subject to an agreed scope and cost.
Users must immediately report to the Organization Admin and the ASIF point of contact upon discovering a lost device, a compromised password, misdirected data, abnormal access, malware, missing records, or any other sign of an incident. Do not unilaterally delete evidence, contact outside parties, or disclose an incident without authorization.
| Stage | Main Activities |
|---|---|
| Intake and classification | Record, verify, determine severity and identify affected parties. |
| Containment and evidence preservation | Lock accounts, revoke sessions, restrict connectivity, preserve logs. |
| Impact assessment | Determine data type, number of subjects, consequences, scope, and legal obligations. |
| Remediation and recovery | Eliminate the cause, patch, restore service, and verify it is safe. |
| Notification | Notify the member organization, competent authorities, and data subjects where the law or risk level requires it. |
| Lessons learned and improvement | Root-cause analysis, corrective actions, updated controls, and record-keeping. |
ASIF endeavors to notify a member organization as soon as reasonably possible after confirming an incident is likely to have a significant impact on the organization's data. The notice will include what is known, the expected impact, measures already taken, and recommended actions. Deadlines for notifying a state authority or a data subject follow applicable law and are coordinated between the parties according to their legal role.
ASIF and the technology partner aim to build and maintain an incident-response plan appropriate to the scale and resources of a nonprofit organization, including identifying critical services, dependencies, communication roles, and recovery options. This plan is reviewed periodically per an internal schedule and after any major incident. Member organizations must maintain an alternative business process for essential activities and must not rely solely on UP in an emergency.
UP's availability is affected by cloud infrastructure, connectivity, vendors, and other factors beyond reasonable control. Any specific operational targets, if any, are set out in the MOA or an addendum; this is not an absolute guarantee of uninterrupted service.
The technology partner carries out development, maintenance, technical operation, and data processing under contract, ASIF's instructions, security principles, and the approved scope; must not use data for its own purposes; must control its personnel; must report incidents; and must support deletion, return, and audit as agreed.
To the extent permitted by law, ASIF is not liable for damage arising from: unlawful or inaccurate data entered by a member organization; the acts or omissions of a user; devices, networks, or accounts outside ASIF's control; data already exported from UP; an integration requested by a member organization; a force majeure event; or a member organization's failure to fulfill its own security and compliance obligations.
Nothing in this Section excludes liability that the law does not permit to be excluded, or exempts liability for intentional misconduct, fraud, or breach of a mandatory obligation. Specific liability limits, compensation mechanisms and financial caps, if any, are set out in the MOA or a related contract.
Users and personnel with data access must complete security and data-protection training appropriate to their role. A violation may result in a warning, retraining, revocation of access, account suspension, disciplinary action, termination of the relationship, a claim for damages, or referral to a competent authority, depending on severity and applicable rules.
ASIF has the right to require a member organization to remediate a weakness, provide evidence of controls, or temporarily suspend part of its access where there is a serious risk to the system, data, or data subjects.
ASIF Foundation's technical operations unit is the document owner, coordinating with relevant departments (Legal, HR, Finance, Programs) and the technology partner on implementation. This Policy is approved under the authority of ASIF Foundation.
This Policy is reviewed periodically per an internal schedule, and whenever there is a significant change in law, UP's architecture, data types, vendors, a serious incident, or an audit requirement. A revised version is communicated by email, through the UP interface, or via an official channel before it takes effect, except for an urgent change that must take immediate effect to protect the system or ensure legal compliance.
An exception must be documented in writing, stating its scope, rationale, risk assessment, compensating controls, approver, and duration. An exception must not reduce a mandatory legal obligation.
Requests relating to security, privacy, incidents, or data-subject rights should be sent through the official channel published by ASIF on UP, in the MOA, or on the website. Member organizations must maintain up-to-date contact information for their Organization Admin and data-protection lead (where required by law or the scale of processing).
In an emergency, a user must prioritize locking the account, disconnecting the suspected compromised device, and contacting the Organization Admin/ASIF point of contact immediately through the published emergency channel.
| Contact Channel | Details |
|---|---|
| Support email | support@asif.foundation |
| Website | https://asif.foundation |
| Activity | Member Organization | ASIF | Technology Partner |
|---|---|---|---|
| Determine purpose/legal basis for processing | Primary responsibility | Advise/coordinate where within ASIF's scope | Does not independently determine purpose |
| Notice and consent | Primary responsibility | Support templates/process where available | Technical support |
| User access permissions | Approve and review | Establish the platform framework/permissions | Technical implementation |
| Infrastructure security | Coordinate | Monitor and govern | Technically responsible under contract |
| Data-subject requests | Receive/decide | Technical support | Support per instruction |
| Data incident | Coordinate, notify per its role | Coordinate and assess | Detect, contain, technical remediation |
| Retention/deletion of business data | Decide and be responsible | Provide tools/process | Technical execution |