This Privacy Policy explains how Actor Company Limited (CÔNG TY TNHH ACTOR, ACTOR CO.,LTD — “ACTOR”, “we”, “us”), a company incorporated in Vietnam, collects, uses, shares and protects personal data, and the choices and rights you have. It is written to meet the requirements of the data protection laws of the places where we and our customers operate, including the EU and UK General Data Protection Regulation (GDPR), Vietnam’s Law on Personal Data Protection (Law No. 91/2025/QH15) and its implementing decrees, the California Consumer Privacy Act as amended by the CPRA (CCPA) and other US state privacy and biometric laws, Brazil’s LGPD, Canada’s PIPEDA and Quebec Law 25, Singapore’s PDPA, Australia’s Privacy Act, Japan’s APPI, South Korea’s PIPA, India’s DPDP Act and China’s PIPL.
Where the law of the place you live gives you more protection than this policy describes, you get that protection.
1. Who we are and what this policy covers
ACTOR builds and operates software. This policy applies to every way you interact with us:
- Website — byactor.com and its subpages.
- Products — our mobile, web and desktop applications, including those distributed through the Apple App Store, Google Play and other stores.
- APIs — APIs we offer or build and run for customers, and their dashboards, documentation and test environments.
- Engineering services — outsourced design and development projects and dedicated teams (“outsourcing”).
- Solutions — software and hardware systems for businesses and venues, such as the self-running gym solution (face-recognition access, automatic payments, multi-bank cash-flow routing).
- Business dealings — sales, support, events, recruitment and supplier relationships.
Actor Company Limited is responsible for your data, unless an order, contract or app store listing names a different ACTOR company for a particular service. A product may have a short supplementary notice for anything specific to it; that notice and this policy are read together.
2. When we are the controller, and when we act for a customer
We are the controller (in Vietnamese law, the bên kiểm soát dữ liệu cá nhân) for data about visitors to our website, people who contact us, our customers’ account administrators and billing contacts, users of products we offer directly to the public, and job applicants.
We act for our business customers (as a processor or service provider — bên xử lý dữ liệu cá nhân) when we process personal data on their behalf and on their instructions: for example, the members of a gym that uses our solution, the end users of an app we built or run for a client, people whose data passes through an API we run for a customer, and any personal data we handle during an outsourcing project. In those cases the customer decides why and how the data is used, their own privacy notice applies, and we process the data only under our contract and data processing agreement with them. If you are one of their users, please contact the business first; we will help them respond to you.
3. The personal data we collect
Data you give us
- Contact and identity — name, email, phone number, company, job title, and messages you send us.
- Account data — login identifiers, hashed passwords, roles and preferences.
- Commercial and billing data — orders, invoices, tax identifiers, billing address, payment method details (card data is handled by our payment processors, not stored by us).
- Project materials — briefs, specifications, credentials to test environments, and content you share with us during engineering work.
- Recruitment — CVs, portfolios and interview notes if you apply to work with us.
Data collected when you use our services
- Technical and usage data — IP address, device and browser type, operating system, app version, crash and diagnostic reports, pages and features used, timestamps, and approximate location derived from the IP address.
- Security logs — sign-ins, API requests, keys used, permission changes and other events kept for auditing and fraud prevention.
- Preferences on this website — your language and light/dark theme choice, stored in your own browser (see section 11).
Financial and banking data (payment features)
- Bank account identifiers, account holder names, virtual account numbers, balances and transaction records (amount, date, reference, counterparty) for accounts that an account holder or a customer has authorised us to access.
- Payment requests we generate (for example bank-transfer QR codes), their status and how each payment was matched and routed between accounts.
- Payout and split rules, and the statements produced from them.
We never ask for or store online banking passwords, card PINs or one-time passwords. Access to bank data happens only through channels the bank or a licensed provider offers for that purpose.
Biometric data (solutions with face recognition)
Some solutions let people enter premises using their face. They process a face image and the numerical template derived from it (“biometric data”), which the law treats as sensitive. For these:
- biometric data is collected only after the person gives explicit, separate, written (including electronic) consent, which the operator of the premises (our customer) obtains and records, and which can be withdrawn at any time;
- it is used only to recognise that person at the entrances of that business — never to identify people elsewhere, never for marketing, never sold, leased, traded or otherwise profited from, and never used to train general-purpose recognition models;
- it is encrypted in transit and at rest, stored on the recognition terminals and in the customer’s encrypted store, and accessible only to systems that need it;
- it is permanently deleted when consent is withdrawn, when the purpose ends (for example after the membership ends and the retention period the customer sets, which by default is at most 180 days), and in any case no later than any maximum period set by the applicable law — for Illinois residents, within three years of the person’s last interaction with the business at most;
- customers must offer a non-biometric way to enter (such as a QR code or card) to anyone who does not consent, where the law requires it.
Access and presence data
Entry events (time, door, device, result), membership status and visit history are recorded so that access rules can be enforced and the business can see how its premises are used.
Data from others
- Our business customers, who give us data about their users so we can provide the service to them.
- Banks and payment providers, when an account holder or customer authorises a connection.
- App stores, which report purchases and subscription status (not your card details).
- Public and professional sources, such as company registries and professional networks, for business contacts.
Children
Our services are for businesses and adults. We do not knowingly collect personal data from children under 13 (or the higher age of digital consent where you live, such as 16 in parts of the EU). Where a customer’s own users include minors — for example a gym with teenage members — the customer is responsible for obtaining verifiable consent from a parent or guardian as the law requires, including under Vietnam’s rules for children under 16 and the US COPPA. If you believe a child has given us personal data without that consent, contact us and we will delete it.
4. How we use personal data, and our legal bases
| Purpose | Examples | Legal basis (GDPR and similar laws) |
|---|---|---|
| Provide the services | Run accounts, apps and APIs; deliver engineering projects; operate and support solutions | Performance of a contract; for customers’ users, the customer’s instructions |
| Payments and cash flow | Generate payment requests, confirm and match transfers, route funds between the account holder’s own accounts, produce statements | Contract; legal obligation (accounting, tax) |
| Biometric access | Recognise a member at the door | Explicit consent (GDPR Art. 9(2)(a)); consent under Law 91/2025/QH15; written release under US biometric laws |
| Security and fraud prevention | Detect abuse, protect accounts and money, keep audit trails | Legitimate interests; legal obligation |
| Support and communication | Answer questions, send service and security notices | Contract; legitimate interests |
| Improve our services | Fix bugs, measure performance, plan features — using aggregated or de-identified data where possible | Legitimate interests |
| Marketing to businesses | News about our products and solutions | Consent where required; otherwise legitimate interests, always with an easy opt-out |
| Legal and compliance | Tax and accounting records, responding to lawful requests, sanctions and anti-money-laundering checks on API customers | Legal obligation; legitimate interests |
We do not use personal data for purposes that are incompatible with the purpose for which it was collected without telling you and, where required, asking for your consent.
5. Automated decisions and AI
Some of our services make automated decisions by design: a door opens or stays closed depending on whether a membership is valid; an incoming transfer is matched to an order; a payment is routed to an account by rules the business sets. These decisions follow rules the business can see and change. You can ask the business, or us, for human review of any automated decision that affects you and to contest it.
We do not use personal data that we process for customers to train general-purpose artificial intelligence models. If we use AI features inside a product, the product tells you and the data stays within the purpose of that product.
6. Who we share personal data with
We do not sell personal data and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. We share it only as follows:
- Service providers (sub-processors) that host and run our services under contract and confidentiality — for example cloud hosting and content delivery (such as Cloudflare), email delivery, customer support tools, and payment processors.
- Banks and payment providers needed to complete or confirm a payment or payout you or a customer asked for.
- Our business customers, for data about their own users and their own operations.
- Device manufacturers, only where needed for warranty or technical support of a device, and never including biometric data unless the law and the customer allow it.
- Professional advisers — lawyers, auditors, insurers — under confidentiality.
- Authorities, when the law requires it, following a valid legal process; we push back on requests that are overbroad.
- A buyer or successor in a merger, acquisition or sale of assets, who must keep honouring this policy.
A current list of our sub-processors is available to customers on request.
7. International transfers
We serve customers worldwide, so personal data may be processed in Vietnam and in other countries where we or our providers operate. When data leaves the country where it was collected, we use the safeguards the law requires, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss equivalents, the cross-border transfer impact assessment and filing required by Vietnamese law, and the consent or contract requirements of laws such as the PIPL and APPI. Customers can ask for a copy of the relevant safeguards.
8. How long we keep personal data
| Data | Kept for |
|---|---|
| Account data | While the account is open, then up to 12 months to handle closing matters and disputes |
| Transaction, invoice and accounting records | As long as tax, accounting and anti-money-laundering laws require — typically 5 to 10 years |
| Biometric data | Until consent is withdrawn or the purpose ends plus the customer’s retention period (default at most 180 days), and never longer than the law allows |
| Entry events | As set by the customer, by default no longer than 24 months |
| Security and API logs | Up to 12 months, longer only while investigating an incident |
| Enquiries and sales contacts | Up to 24 months after our last contact |
| Marketing preferences | Until you opt out; the opt-out itself is kept so we respect it |
| Data processed for customers | For the term of our contract, then returned or deleted as the customer instructs, normally within 30 days |
| Recruitment | Up to 12 months after the process ends, unless you agree to longer |
When the period ends we delete the data or make it anonymous.
9. How we protect personal data
We design for security from the start: encryption in transit (TLS) and at rest, including authenticated encryption (AES-GCM) for biometric data; passwords stored only as salted, slow hashes; signed and replay-protected device communication; least-privilege access with deny-wins permissions; audit logs; separation of test and production environments; automated tests that must pass before any change ships; and staff bound by confidentiality. No system is perfectly secure, so we also plan for failure.
If a personal data breach happens, we contain it, assess it and notify the competent authority and the people affected within the time limits the law sets — for example within 72 hours under the GDPR and Vietnamese law — and we notify affected customers without undue delay so they can meet their own duties.
10. Your rights
Depending on where you live, you have some or all of these rights over your personal data:
- to be informed of how it is processed, and to access a copy of it;
- to have it corrected or completed;
- to have it deleted;
- to restrict or object to its processing, including for direct marketing at any time;
- to data portability — to receive it in a machine-readable format or have it sent to another provider;
- to withdraw consent at any time, without affecting processing done before;
- not to be subject to a decision based solely on automated processing with legal or similarly significant effects, and to get human review;
- to complain to a data protection authority and to seek compensation where the law provides it.
Specific regions
- EEA, UK and Switzerland — you may complain to your local supervisory authority. If the law requires us to appoint a representative in the EU or UK, we will publish their details here.
- Vietnam — you have the rights of data subjects under Law 91/2025/QH15, including to be informed, to consent or withdraw consent, to access, correct, delete and restrict, to object, to complain, denounce and sue, and to claim compensation.
- California and other US states — you may request to know the categories and specific pieces of personal information we collected, the sources, purposes and recipients (sections 3–6 describe them for the past 12 months); to delete and correct it; to opt out of sale, sharing and targeted advertising (we do none of these); and to limit the use of sensitive personal information (we use it only for the purposes the law permits). You may use an authorised agent, and we will not discriminate against you for exercising a right. If we decline your request, you may appeal by replying to our decision; if the appeal is denied you may contact your state attorney general.
- Biometric laws (Illinois BIPA, Texas CUBI, Washington and similar) — section 3 is our public retention and destruction schedule for biometric data; we obtain a written release before collection and never sell or profit from biometric data.
- Canada, Brazil, Singapore, Australia, Japan, South Korea, India and China — you have the access, correction, deletion, portability and complaint rights those laws provide, and in India you may use our grievance contact below or nominate someone to exercise your rights.
How to exercise them
Email hello@byactor.com with the subject “Privacy request”. We will verify your identity in a way proportionate to the request, and answer within the time the law that applies to you sets (for example one month under the GDPR, 45 days under the CCPA). Requests are free unless they are clearly unfounded or excessive. If we process your data for a business customer, we will pass your request to them and help them answer it.
11. Cookies and similar technologies
This website uses no advertising or analytics cookies and no cross-site tracking. It stores only two preferences in your browser’s local storage — your language (actor.lang) and your light or dark theme (actor.theme) — which never leave your device. The site loads fonts from Google Fonts and scripts from the jsDelivr content network, and is served through Cloudflare; these providers receive your IP address and browser details as part of delivering the files.
Our products use strictly necessary cookies or storage to keep you signed in and secure. If a product uses optional analytics, it asks for your consent first where the law requires, and you can change your choice at any time. We honour Global Privacy Control signals as an opt-out where the law recognises them.
12. Marketing
We send marketing only to business contacts, and only where the law allows it. Every message has an unsubscribe link, and you can also opt out by emailing us.
13. Third-party services and links
Our services connect to banks, payment providers, app stores, device manufacturers and websites that we do not control. Their own privacy policies govern what they do with your data; please read them.
14. Changes to this policy
We will update this policy when our services or the law change. We post the new version here with a new “last updated” date and, if the changes are material, we tell customers and account holders in advance by email or in the product.
15. Contact
For any question, request or complaint about privacy — including to reach our personal data protection contact and our grievance officer — email hello@byactor.com with the subject “Privacy”. We answer every message.
This policy is published in English and Vietnamese. If the versions differ, the English version prevails, unless the law that applies to you requires another language version to prevail.