Rifena Privacy Policy
This Policy explains how Rifena (Dynamix Joint Stock Company — Dynamix JSC, “Rifena”, “we”) collects, uses, stores, shares and protects personal data when you use the Rifena applications, the rifena.com website and related services. It follows Vietnam’s Law on Personal Data Protection No. 91/2025/QH15, Law on Cybersecurity No. 116/2025/QH15, Law on Electronic Transactions No. 20/2023/QH15 and their guiding regulations.
1. Roles
- For HR data your organisation puts into Rifena: the organisation is the personal data controller (it decides the purpose and scope of processing); Rifena is the personal data processor, processing only under the service agreement and the organisation’s lawful instructions. The specific scope and safeguards are set out in the personal-data processing agreement attached to the contract.
- For data you give Rifena directly (trial sign-up, consultation requests, support requests, sign-in credentials, technical logs): Rifena is the controller.
2. Personal data we process
| Category | Examples | Source |
|---|---|---|
| Identity and contact | full name, date of birth, gender, national ID number, address, phone, email, profile photo | entered by your organisation or updated by you |
| Employment | job title, department, employment contract, work history, reviews, training, discipline | your organisation |
| Attendance and schedules | clock-in/out times, shifts, leave, GPS location at clock-in, face image at clock-in | collected by the app when you clock in (if enabled by your organisation) |
| Payroll, tax, insurance | salary, allowances, deductions, tax code, social-insurance number, bank account | your organisation |
| Health and dependants | health information relevant to employment benefits, dependants for tax relief | your organisation (if entered) |
| Account and security | username, password (hashed), authentication methods (MFA, passkey), sessions | you and the system |
| Technical data | IP address, device type, browser, access times, activity logs | recorded by the system |
| Conversations with Rifena AI | questions you send and the assistant’s answers in the app | you |
Categories in bold are sensitive personal data (biometric, location, health, financial). Rifena processes sensitive data only when your organisation enables the corresponding feature and has a lawful basis for it.
3. Purposes and legal bases
- Providing HR services to your organisation: records, attendance, leave, payroll, insurance, tax, reviews, training — under the service agreement.
- Creating and protecting accounts, authenticating sign-in and detecting unusual access — under the agreement and our legitimate interest in information security.
- Sending operational notifications (approvals, payslips, schedules, changes to terms) in the app, by email or push notification.
- Technical support, incident handling, backup and recovery.
- Complying with legal obligations (log retention, lawful requests from competent authorities).
- For trial sign-ups and consultation requests: contacting you, provisioning the environment and sending account details — based on your consent.
Rifena does not sell personal data, does not use organisation data for advertising and does not use organisation data to train artificial-intelligence models.
Rifena AI (the in-app assistant). The assistant is available only when the organisation’s plan includes it. When you ask a question, the question and the data needed to answer it — limited to what you yourself may see, because the assistant works through your own session and holds no rights of its own — are sent to the language-model provider Rifena contracts with (see Section 4) to generate the answer; email addresses, phone numbers and long digit strings are masked before indexing steps. The assistant never changes data by itself: every write is shown to you for confirmation and re-authorised at the moment you confirm. You can delete a conversation, or all of your assistant data, at any time in the app.
4. Sharing and sub-processors
- Rifena shares personal data only: (a) with your organisation and the users it authorises; (b) with sub-processors that operate the service; (c) with competent state authorities on a lawful request, to the minimum extent required, notifying the organisation unless the law prohibits it.
- Current sub-processors:
- Amazon Web Services — servers, file storage, backups and system email delivery;
- Language-model provider for Rifena AI (through a business API, under terms that exclude training on the data) — receives only the content of a turn needed to produce the answer; applies only to organisations that have enabled Rifena AI. The specific provider is named in the personal-data processing agreement attached to the contract.
- Every sub-processor is bound by confidentiality and data-protection obligations no weaker than Rifena’s. Before adding or replacing a sub-processor, Rifena notifies the organisation at least 30 days in advance and the organisation may object under the agreement.
- Rifena Auth — Rifena’s own sign-in service (passwords, multi-factor authentication, passkeys and, on the Enterprise plan, single sign-on through the organisation’s identity provider) — is operated by Dynamix JSC on the infrastructure described in Section 5 and is not a sub-processor.
5. Storage location and transfers
Organisation data — the database, attachments and backups — is stored and processed on Amazon Web Services infrastructure located in Vietnam (AWS Local Zone Hanoi; see the AWS Local Zones locations). Rifena does not transfer personal data outside Vietnam, with one stated exception: when an organisation enables Rifena AI, the content of each turn is processed by the language-model provider named in Section 4 on that provider’s infrastructure abroad, within the service agreement and the cross-border transfer impact assessment Rifena files as the law requires. If an organisation requests in writing another service that requires processing abroad, the transfer happens only after the same assessment is completed and it is recorded in the service agreement. System email (notifications, payslips) is sent through Amazon Simple Email Service to addresses provided by the organisation and carries only the information needed. Each organisation’s data is logically separated from every other organisation’s data.
6. Safeguards
- Encryption in transit (TLS) and at rest for sensitive data, credentials and payroll data; passwords are stored only as hashes.
- Multi-factor authentication and passkeys; mandatory for administrator accounts.
- Role-based, least-privilege access; access, administrative and personal-data activity logs kept for at least 12 months.
- Patch and vulnerability management: vulnerabilities are rated by severity and tested in a staging environment before deployment; critical vulnerabilities are fixed or mitigated first and organisations are informed when their data is affected.
- Regular encrypted backups kept separate from production, with restore testing.
- Separate development, test and production environments; no un-anonymised real data in development or testing.
- Rifena and sub-processor staff who access data sign confidentiality undertakings and receive only the minimum access needed.
7. Retention
- Organisation data is kept for the term of the service agreement. Before the end date, the organisation exports its own data from the application in an open format (CSV, XLSX or JSON). Rifena permanently deletes the data, including backups, within 30 days of termination and issues a deletion certificate on request.
- Technical and access logs: at least 12 months.
- Rifena AI conversations: kept until you delete them in the app or the service agreement ends; the parameters of scheduled actions are scrubbed 7 days after completion.
- Trial sign-up and consultation data: until the request is completed or you withdraw consent, except where the law requires retention.
- Where the law requires longer retention, Rifena keeps only that data, for the statutory period and purpose, and informs the organisation.
8. Your rights
Under personal-data-protection law you have the right to be informed; to consent and withdraw consent; to access, view and correct; to delete; to restrict processing; to obtain your data; to object; to complain, denounce or sue; to claim compensation; and to self-protect as provided by law.
For HR data you exercise these rights through your organisation (its HR department or Rifena administrator); Rifena helps the organisation respond within 5 working days of the organisation’s request. For data you gave Rifena directly, write to privacy@rifena.com; we verify your identity and respond within the statutory period. Some requests (for example deleting payroll records still within a mandatory retention period) may be limited by law; Rifena or the organisation will explain the basis.
9. Data incidents
When an incident leads to, or risks, unauthorised access, disclosure, alteration or loss of personal data, Rifena: notifies the affected organisation no later than 24 hours after detection; delivers a report on cause, scope and remediation within 72 hours; preserves logs and evidence; and cooperates so the organisation can meet its notification duties towards the authorities and data subjects.
10. Cookies and on-device storage
The Rifena applications use only cookies and browser storage needed to operate: keeping a secure session, protecting against request forgery (CSRF), remembering interface preferences (theme, language) and caching assets. Rifena uses no advertising or cross-site tracking cookies. The mobile app may ask for location, camera and notification permissions; you can refuse them in your device settings, in which case the related features (location- or face-based clock-in) will not work.
11. Children
Rifena is for the employees and managers of an organisation and is not directed at children. Where an organisation employs minors, the organisation ensures the lawful basis for processing their data under labour and personal-data law.
12. Changes to this Policy
Rifena may update this Policy when the law, the service or security practice changes. A new version is published in the application and on rifena.com with its effective date.
13. Contact
- Rifena support: support@rifena.com
- Sales and implementation: sales@rifena.com
- Personal-data protection contact: privacy@rifena.com
- Dynamix Joint Stock Company (Dynamix JSC)
- Registered address: [registered address]
- Enterprise code: [enterprise code]
- Phone: [phone number]
- Website: rifena.com