Rifena Terms of Use
Rifena is a human-resources platform developed and operated by Dynamix Joint Stock Company (Dynamix JSC, “Rifena”, “we”). These Terms govern the use of the Rifena applications (web and mobile) by users — employees, HR staff and managers — who receive an account from their organisation.
By choosing “Agree and continue” you confirm that you have read, understood and accepted these Terms together with the Rifena Privacy Policy. If you do not agree, do not use Rifena and contact your organisation’s administrator.
1. Definitions
- Organisation: the company or entity that has signed a service agreement (including a trial deployment agreement) with Rifena and issued your account.
- User: an individual who signs in to Rifena with an account issued by an organisation.
- Organisation data: everything the organisation or its users enter, upload, create or generate while using Rifena — personnel records, attendance, payroll, employment contracts, documents and business configuration.
- Personal data and sensitive personal data: as defined by Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 and its guiding regulations.
- Service agreement: the contract between Rifena and your organisation, including the personal-data processing agreement and service levels attached to it. Where they conflict, the service agreement prevails for the organisation; these Terms govern each user’s own use.
2. Accounts and sign-in
- Accounts are created, permissioned and revoked by your organisation. Rifena does not issue accounts to individuals outside an organisation.
- Use only your own account; do not share, lend or transfer it. Everything done with your account is treated as done by you.
- You are responsible for keeping your password and authentication factors secret. Change your password after your first sign-in; we recommend enabling multi-factor authentication (MFA) or a passkey. Administrator accounts must use multi-factor authentication.
- If you discover or suspect that your account has been exposed or taken over, notify your organisation’s administrator and Rifena support within 24 hours.
- Rifena may temporarily lock an account on signs of unauthorised access, a breach of these Terms, or at the organisation’s request, and will inform your organisation.
3. Licence and prohibited conduct
- Rifena grants you a limited, non-exclusive, non-transferable right to use the service within the permissions your organisation assigns and for as long as the service agreement is in force.
- You must not:
- copy, decompile, reverse-engineer or otherwise attempt to access Rifena’s source code or internal structure;
- sublicense, distribute or let anyone outside your organisation use Rifena;
- use Rifena, its documentation or information obtained from it to build a competing product or service;
- run vulnerability scans, penetration tests, load tests or otherwise interfere with the system without Rifena’s written consent;
- access or extract data beyond your assigned permissions, including colleagues’ data you are not authorised to see;
- upload unlawful content, malware or data classified as state secrets.
- Rifena AI (the in-app assistant) answers only from data you are allowed to see within your organisation, makes no change without your confirmation, and processes the content of each turn as described in the Privacy Policy (Sections 3 and 4). Its answers are assistive; business decisions, payroll results and legal compliance remain the responsibility of the organisation and its authorised staff. Do not feed the assistant data outside the scope of your work.
4. Organisation data
- Organisation data belongs to the organisation. Rifena’s storage, transmission and processing of that data create no ownership or exploitation rights for Rifena.
- Rifena processes data only as needed to provide the service and on the organisation’s lawful instructions. Rifena does not use organisation data to train artificial-intelligence models, to build commercial derived data, for marketing, or to supply third parties, unless the organisation agrees separately in writing.
- For employees’ personal data the organisation is the personal data controller and Rifena is the personal data processor. You exercise your data-subject rights (access, correction, deletion, withdrawal of consent, and so on) through your organisation; Rifena helps the organisation respond within the statutory time limits.
- You are responsible for ensuring that data you enter into Rifena is accurate, lawful and within the scope of your work.
5. Intellectual property
- Rifena, its source code, interfaces, documentation, trademarks and all related intellectual-property rights belong to Dynamix JSC or its licensors. These Terms transfer no intellectual-property rights to you or your organisation.
- Business configuration, forms, payroll formulas and workflows built by the organisation belong to the organisation.
- Feedback and improvement suggestions you send to Rifena may be used to improve the service without any payment obligation, provided no organisation data is disclosed.
6. Security and incidents
- Rifena applies appropriate technical and organisational measures: encryption in transit, encryption at rest for sensitive data and credentials, role-based least-privilege access, access and activity logging, regular backups and environment separation. Details are in the Privacy Policy.
- When a data incident affects your organisation, Rifena notifies the organisation no later than 24 hours after detection and cooperates on remediation under the service agreement.
- If you discover a security weakness or vulnerability, report it privately to Rifena through the support channel and do not disclose it publicly before Rifena has fixed it.
7. Service availability
- Rifena works to keep the service continuously available at the service levels agreed with your organisation.
- Planned maintenance is announced at least 48 hours in advance and carried out outside working hours, except in a cybersecurity emergency.
- Rifena may add, change or retire features; changes that materially affect how you work are announced in the application or through your organisation.
8. Responsibility and limitation of liability
- Rifena provides tools that support HR administration, attendance and payroll. The organisation and its authorised staff remain ultimately responsible for input data, configuration, computed results and compliance with labour, tax and social-insurance law.
- To the extent permitted by law, Rifena is not liable for indirect damages, lost profits or damage arising from use contrary to these Terms. This limitation does not apply to breaches of confidentiality or personal-data obligations, wilful misconduct, or cases where the law does not allow liability to be limited.
- The specific liability between Rifena and your organisation is set out in the service agreement.
9. Suspension and termination
- Your organisation may revoke your account at any time. Once revoked you can no longer access Rifena; your personal data continues to be managed by the organisation under the service agreement and the Privacy Policy.
- When the service agreement ends, the organisation exports its own data from the application before the end date; Rifena deletes the data within 30 days of termination, except where the law requires continued retention.
- Rifena may suspend a specific user’s access when it detects conduct prohibited by Section 3 or conduct that endangers the system, and informs the organisation.
10. Changes to these Terms
Rifena may update these Terms when the law, the service or security practice changes. A new version is published in the application with its effective date.
11. Governing law and disputes
These Terms are governed by the law of Vietnam. Disputes between Rifena and your organisation are resolved under the service agreement; disputes involving an individual user are first addressed by negotiation and mediation and, failing that, by the competent People’s Court under civil-procedure law.
12. Contact
- Rifena support: support@rifena.com
- Sales and implementation: sales@rifena.com
- Personal-data protection contact: privacy@rifena.com
- Dynamix Joint Stock Company (Dynamix JSC)
- Registered address: [registered address]
- Enterprise code: [enterprise code]
- Phone: [phone number]
- Website: rifena.com