> For the complete documentation index, see [llms.txt](https://docs.avis.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.avis.net/guide/terms-and-conditions/personal-data-protection-policy.md).

# PERSONAL DATA PROTECTION POLICY

*Last updated: 05/6/2026*

AVIS AI Joint Stock Company, tax code 0318832218, with its head office at No. 2 Truong Quoc Dung, Phu Nhuan Ward, Ho Chi Minh City, Vietnam (hereinafter referred to as the “Company”, “we”) is committed to protecting the personal data (“PD”) of Users in accordance with the Law on Personal Data Protection No. 91/2025/QH15 and its implementing, amending and supplementing documents, together with other relevant provisions of Vietnamese law from time to time, or the laws applicable in the User’s home country (the “Applicable Law”).

This personal data protection policy (the “Policy”) describes how the Company collects, uses, processes, stores, shares and protects Users’ PD when they access, register for and use the AI video generation and editing platform at <https://www.avis.xyz/> (the “Service”). This Policy also serves as the privacy policy and the PD processing agreement under the Applicable Law.

By accessing, registering an Account and using the Service, the User confirms that they have read, understood and agreed to the contents of this Policy. Please do not access, register an Account or provide us with any PD if you do not agree with this Policy.

## ARTICLE 1. DEFINITIONS

1. “PD Controller” means an organisation or individual that determines the purposes and means of processing PD.
2. “PD Controller and Processor” means an organisation or individual that both determines the purposes and means of, and directly carries out, the processing of PD.
3. “PD Processor” means an organisation or individual that processes data on behalf of the Data Controller, under a contract or agreement with the Data Controller.
4. “Data subject” means the individual to whom the PD relates.
5. “PD” or “PD” means information in the form of symbols, letters, numbers, images, sounds or similar forms in the electronic environment that is associated with a specific person or that helps identify a specific person, including basic PD and sensitive PD as prescribed by the Applicable Law. PD that has been de-identified is no longer PD.
6. “User” means an end user, including individuals and organisations that register for, use or interact with the Service. Within the scope of this Policy, the User is the Data subject.
7. “Group of Companies” includes the Company and its affiliates, parent company, subsidiaries, partners, contractors and service providers acting on behalf of the Company.
8. “Processing of PD” means one or more activities affecting PD, such as: collecting, recording, analysing, confirming, storing, editing, disclosing, combining, accessing, retrieving, recovering, encrypting, decrypting, copying, sharing, transmitting, providing, transferring, deleting or destroying PD, or other related actions.

## ARTICLE 2. PERSONAL DATA PROCESSING ROLES

For the PD processing activities described in this Policy, the Company acts as the PD Controller and Processor, determining the purposes and means of, and directly carrying out, the data processing. In certain cases, the Company may act as a PD Processor when carrying out processing at the request of organisational customers.

## ARTICLE 3. SCOPE AND TYPES OF PERSONAL DATA COLLECTED

Depending on how the User interacts with the Services, the Company may collect the following types of PD:

### Basic PD provided by the User:

1. Full name; and/or
2. Display name; and/or
3. Email address; and
4. Phone number; and
5. Country/region;
6. Account information and information in the data message environment, including but not limited to: username, profile picture, account settings, Input Content and Output Content when using the Service;
7. Payment information: name on the card, the last four digits of the card, the issuing country code, transaction history. The Company does not store payment information; payment information is processed by a third-party payment gateway;
8. Business contact information for organisational Users: information about the legal representative or the person authorised/appointed to carry out the Service;
9. Contents of communications with the Customer Care Department: emails, call recordings, support messages.

### Data relating to the use of AI services

10. Input Content uploaded or entered into the Service by the User;
11. Reference files, character images, portrait photos and voice samples provided by the User to generate Output Content;
12. Output Content generated based on the User’s Input Content;
13. Service usage history: features used, time, duration, Credit consumption;
14. The User’s feedback, ratings and error reports in respect of Output Content.

### Technical and device data

16. IP address, device type, operating system, browser type, browser language, screen resolution, and/or;
17. Device identifiers, advertising and marketing preferences (if applicable), and/or;
18. Login data, connection history, system log data, and/or;
19. Cookies and similar technologies.

### Sensitive PD that may arise

Depending on the User’s needs, the Input Content or Output Content provided/generated by the User may contain one or more items of sensitive PD such as:

1. Facial images, biometric characteristics;
2. Location data (if embedded in image/video EXIF files).

The User undertakes not to upload third-party sensitive PD without the lawful and express consent of that Data subject. The Company does not encourage Users to provide sensitive PD to the Service. Where the User does provide it, the User agrees that the Company may process it for the purposes set out in Article 4.

The Company does not intentionally collect such sensitive PD; the provision of such sensitive PD depends entirely on the usage needs of the User and the Data subject. Accordingly, the User is not required to provide such sensitive PD, and the collection and processing of such sensitive PD is solely for the purpose of performing the Service and ensuring the quality of the Service as requested by the User, and is not for the purpose of determining and identifying the identity of the Data subject.

### Data collected from third parties

1. Login account information from Google, Apple or other authentication providers (to the extent permitted by the User);
2. Information from payment gateways: transaction status, transaction code;
3. Information from advertising partners and analytics partners (encrypted and anonymised);
4. Information from competent State authorities in accordance with the law.

## ARTICLE 4. PURPOSES OF PERSONAL DATA PROCESSING

The Company processes PD for the following specific purposes:

### Providing and operating the Service:

1. Registering, authenticating and managing the Account; providing AI features for generating and editing video, images and audio;
2. Processing Input Content and generating Output Content;
3. Storing Input Content and Output Content in the User’s account;
4. Synchronising data across the User’s devices and sessions.

### Payment and Service Package management

5. Processing payment, renewal and cancellation of Service Packages;
6. Issuing invoices, receipts and accounting vouchers;
7. Preventing payment fraud and handling chargeback claims.

### Customer support and communications

8. Receiving and resolving complaints and support requests;
9. Sending service notices, security notices, and updates to the Terms and Policies;
10. Sending marketing, promotional and survey information (only where the User consents or within the scope permitted by law).

### Safety, security and abuse prevention

11. Detecting and preventing fraud, intrusion, cyber attacks and breaches of the Terms;
12. Reviewing and filtering content that breaches the law, the rights of third parties, or the acceptable use policy;
13. Protecting the lawful rights and interests of the Company, Users and third parties.

### Improving and developing the service

14. Analysing and measuring effectiveness and usage behaviour in order to enhance the quality of the Service;
15. Researching and developing new features and products;
16. Training, fine-tuning and evaluating AI Models - only where the User has given consent, or where the Company has offered an opt-out option and the User has not opted out. The User may manage this option in the Account Settings section.

### Legal compliance and requests from competent authorities

17. Complying with obligations relating to taxation, accounting, anti-money laundering and counter-terrorist financing;
18. Meeting lawful requests from competent State authorities of Vietnam;
19. Protecting and enforcing lawful rights in disputes and legal proceedings.

## ARTICLE 5. PRINCIPLES OF PERSONAL DATA PROCESSING

The Company processes the User’s PD on the basis of one or more of the following legal grounds:

1. The User’s consent under the Applicable Law;
2. Performance of the contract entered into between the Company and the User (the Terms and Conditions of Service);
3. Compliance with the Company’s legal obligations;
4. Protection of the life and health of the User or of other persons in emergency situations;
5. The Company’s legitimate interests in ensuring system safety, preventing fraud and combating crime - provided that this does not infringe the lawful rights and interests of the Data subject.
6. Other relevant provisions of law.

## ARTICLE 6. METHODS OF COLLECTING PERSONAL DATA

The Company collects PD through the following methods:

1. Directly from the User when the User registers an Account, uses the Service, or contacts the Customer Care Department;
2. Automatically when the User accesses and uses the Service, through cookies, system logs and analytics tools;
3. From permitted third parties such as authentication providers, payment gateways and advertising partners;
4. From competent State authorities or the public (within the scope permitted by law).

## ARTICLE 7. ORGANISATIONS AND INDIVIDUALS WITH ACCESS TO DATA

The Company may share, transfer or jointly process the User’s PD with the following parties, to the minimum extent necessary to achieve the processing purposes:

1. Members of the Group of Companies;
2. Cloud infrastructure providers, data centres and hosting services;
3. Providers of AI Models and third-party AI services integrated by the Company into the Service;
4. Payment gateways, banks, credit institutions and anti-fraud services;
5. Analytics, measurement and marketing tool providers;
6. The Company’s professional advisers: auditors, lawyers, tax consultants;
7. Business partners and developers where the User permits an account connection;
8. Competent State authorities in accordance with the law;
9. Purchasers, successors or related entities in the event that the Company undertakes a sale, merger or corporate restructuring.

## ARTICLE 8. CROSS-BORDER TRANSFER OF PERSONAL DATA

1. As the Service operates on global cloud infrastructure and uses AI Models with servers in multiple countries, the User’s PD may be transferred abroad and stored and processed in other countries.
2. Cross-border transfers of PD are made solely for the purpose of providing and ensuring the quality of the Service as requested and required by the User. The Company undertakes to transfer only the minimum necessary PD, within the scope of the User’s consent.
3. The Company carries out cross-border transfers of PD in accordance with the Applicable Law and its guiding documents, including:
4. Preparing and retaining a cross-border data transfer impact assessment dossier or equivalent documents, depending on the Applicable Law;
5. Applying standard contractual clauses or appropriate safeguards with the data recipient;
6. Ensuring that the data recipient maintains protective measures equivalent to those required by Vietnamese law.
7. The User agrees to the cross-border transfer of PD as described in this Article through their use of the Service. If the User does not agree, the User may cease using the Service.

## ARTICLE 9. PERSONAL DATA RETENTION PERIOD

The Company retains PD only for as long as necessary to fulfil the processing purposes under this Policy or as required by law:

1. Account data: retained for as long as the Account remains active and deleted within ninety (90) days after the User requests deletion of the Account, except for data that must be retained under the law;
2. Transaction and invoice data: retained for at least ten (10) years in accordance with the law on accounting and taxation;
3. Input Content and Output Content: retained according to the configuration of the Account and the Service Package; the User may delete it at any time in Settings;
4. System logs and security logs: retained for a maximum of eighteen (18) months;
5. Other data: retained for the periods prescribed by specialised laws.

After the retention period, PD will be permanently deleted, destroyed, de-identified or anonymised.

## ARTICLE 10. RIGHTS OF THE DATA SUBJECT

Under the Applicable Laws, the User has the following rights in respect of their PD:

### Right to be informed

The User has the right to be informed of the processing of their PD, except where otherwise provided by law.

### Right to consent/withhold consent

The User has the right to consent or not to consent to the processing of their PD, except where otherwise provided by law.

### Right to view, edit or request editing

The User has the right to access and view, request to view, edit or request the editing of their PD, except where otherwise provided by law.

### Right to withdraw consent

The User has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing activities previously carried out on the basis of valid consent.

### Right to erasure

The User has the right to delete or request the deletion of their PD, except where otherwise provided by law. Some data may not be deleted immediately (for example, accounting data) due to the Company’s legal obligations.

### Right to restrict processing

The User has the right to request restriction of the processing of their PD. A request to restrict the processing of PD will be handled by the Company within 72 hours of receipt of the request, except where otherwise provided by law.

### Right to data provision

The User has the right to request the Company to provide their PD in a structured, machine-readable format.

### Right to object to data processing

The User has the right to object to the processing of their PD, except where otherwise provided by law.

### Right to complain, denounce and initiate legal proceedings

The User has the right to complain, denounce or initiate legal proceedings in accordance with the law where they consider that their rights have been infringed.

### Right to claim damages

The User has the right to claim compensation for actual damage arising from breaches of the regulations on PD protection in accordance with the law.

The right to request competent authorities, or the agencies, organisations and individuals involved in the processing of PD, to implement measures and solutions to protect their PD in accordance with the law. The User has the right to complain to, or request, competent authorities and related parties to intervene and deploy the necessary PD protection solutions in order to prevent and stop unlawful data processing or processing that is harmful to the User.

To exercise the rights above, the User may send a request to the Company by email at <hi@avis.xyz> or by hotline at (028) 9999 9898. The Company will verify the User’s identity and respond to the request within the time limit prescribed by law.

## ARTICLE 11. OBLIGATIONS OF THE USER

The User agrees that, in addition to the Company’s obligations, the User is also responsible for performing the following obligations while using the Service:

1. Providing PD that is accurate, complete, truthful and updated when changes occur;
2. Protecting their own PD, keeping login information confidential, and not sharing the Account with others;
3. Respecting and protecting the PD of others, and not providing the PD of any third party without that party’s lawful consent;
4. Complying with the law on PD protection, participating in the prevention of activities that infringe PD, and notifying the Company upon discovering acts that breach the law on PD protection.

## ARTICLE 12. COOKIES AND SIMILAR TECHNOLOGIES

1. When the User accesses the Website, the Company and certain third parties may place cookies or similar technologies (pixels, web beacons, local storage) on the User’s device. Cookies help remember settings, maintain login sessions, analyse traffic and personalise the experience.
2. The main types of cookies used:
3. Essential cookies: necessary for the Website to operate; cannot be disabled;
4. Performance cookies: collect information about how the User uses the Website in order to optimise the experience;
5. Functional cookies: remember the User’s preferences;
6. Marketing cookies: display advertising that matches the User’s interests.
7. The User may manage cookies through their browser settings or the cookie preferences panel on the Website. Disabling certain types of cookies may degrade the experience of using the Service.

## ARTICLE 13. PERSONAL DATA SECURITY

1. The Company applies appropriate technical and managerial measures to protect PD, including:
2. Encrypting data in transit (TLS/HTTPS) and at rest;
3. Access control on a least-privilege basis;
4. Log monitoring and intrusion detection;
5. Periodic risk assessments and data protection impact assessments;
6. Staff training on PD protection;
7. Preparing and retaining PD processing impact assessment dossiers, cross-border PD transfer impact assessment dossiers in accordance with the law, and other related documents as required by the Applicable Law from time to time.
8. Although the Company applies appropriate protective measures, no system can guarantee absolute security. Some potential risks include:
9. Technical incidents, hardware and software errors;
10. Cyber attacks, zero-day vulnerabilities;
11. Users being defrauded or having their login credentials stolen.
12. In the event of a PD breach incident, the Company will notify the specialised PD protection authority and the affected Users within the time limits and by the methods prescribed by the Law on Personal Data Protection No. 91/2025/QH15.

## ARTICLE 14. PROTECTION OF CHILDREN’S DATA

1. The Service is not directed at Users under eighteen (18) years of age. The Company does not actively collect the PD of children under sixteen (16) years of age.
2. Where it is discovered that the PD of a child under sixteen (16) years of age has been collected without the valid consent of a parent or guardian, the Company will delete that data.

## ARTICLE 15. PROCESSING OF PERSONAL DATA IN SPECIAL CASES

1. In respect of the PD of persons declared missing or deceased, the Company will process it in accordance with the law and the requests of the persons concerned as prescribed by law.
2. In emergency situations threatening the life or health of the User or of other persons, or in other cases permitted by law, the Company may process PD without the consent of the Data subject.

## ARTICLE 16. LINKS TO THIRD-PARTY WEBSITES AND SERVICES

The Website and the Service may contain links to, and content from, third-party websites and services. The User’s access to and use of such websites and services is governed by the third party’s own privacy policy and terms. The Company is not responsible for the privacy practices of third parties.

## ARTICLE 17. CONTACT INFORMATION FOR PERSONAL DATA PROTECTION

The User may contact the Company regarding matters relating to this Policy, or to exercise their rights, through the following channels:

* Name of the PD Controller and Processor: AVIS AI Joint Stock Company
* Address: No. 2 Truong Quoc Dung, Phu Nhuan Ward, Ho Chi Minh City, Vietnam
* Email: <hi@avis.xyz>
* Hotline: (028) 9999 9898

## ARTICLE 18. CHANGES TO THE POLICY

1. The Company may change the contents of this Policy from time to time to align with its business activities, the needs of Users and the Applicable Law. When the Policy is updated, the Company will amend the “Last updated” date at the top of the page.
2. For changes that materially affect the rights of Users, the Company will give notice by email, by notice on the Website or by other appropriate means. The User’s continued use of the Service after the Policy has been updated means that the User has read, understood and agreed to the updated version.
3. If one or more provisions of the Policy are declared invalid, the remaining provisions shall remain in full force and effect.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.avis.net/guide/terms-and-conditions/personal-data-protection-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
