Privacy Policy
Last updated: 5 September 2026
This Privacy Policy explains how PATTRANS COMPANY LIMITED (Tax code 0111399245), Unit 0315, C2 Building, 119 Tran Duy Hung Street, Yen Hoa Ward, Hanoi, Vietnam, ("Pattrans", "we") handles personal data when you use Pattrans.Ai (the "Service"). It forms part of our Terms of Service and is presented before you create an account. We process personal data under Vietnam's Law on Personal Data Protection (Law No. 91/2025/QH15) and its implementing regulations. For users outside Vietnam we aim to align with applicable data-protection standards; we do not claim GDPR or APPI compliance. Some data is necessary to create an account, process a document, or issue an invoice — without it we cannot provide those functions; other data is optional. In this Policy, "Customer Content" means the documents, text, terminology and My Termbase entries you submit to or store in the Service, the Output, and any intermediate representations of that material created solely to provide the Service. It does not include account, billing, project metadata (including project names or folder labels), security or service-telemetry data, even where such metadata is supplied by you or reflects a document title; however, any document text, terminology, My Termbase content, Output or intermediate representation embedded in those records remains Customer Content.
1. Who we are and scope
Pattrans is the operator of the Pattrans.Ai website, applications and translation software. This Policy applies to all of them. Contact details are in §17.
2. What information the Service uses, and why
- Account and contact — your name, email, organisation and billing contact, so we can create and run your account and reach you about it.
- Sign-in data — your credentials (stored using industry-standard protection; we do not store readable passwords) and a record of sign-ins and sessions, so we can keep your account secure and show you where it has been used.
- Customer Content — the documents, text, terminology and My Termbase entries you submit to or store in the Service, together with the Output and any intermediate representations, as defined above. We use this material to perform and return the translation you request, to operate the related Service functions, and for the limited support, security and legal purposes described in this Policy. A technical document usually contains no personal data, but it may include personal data of third parties (for example, a name on a cover page) and occasionally sensitive personal data (§11).
- Technical data — IP address, device identifiers and operating logs, needed to run the Service, keep it secure and investigate faults.
- Support messages — what you send us when you ask for help, used to answer you.
- Cookie and similar-technology identifiers (§14).
- Invoices and records — invoice, tax and order records, records of your acceptance of these documents, and complaint records, kept to run the business and to meet the accounting, tax and record-keeping duties required by law.
- Payment data — handled by the seller of your transaction and its payment providers (§13); we receive only limited transaction records, not full card details.
Where this comes from, and where it does not go. Most of this information comes directly from you or from your use of the Service. Limited transaction information may also come from the seller of your transaction or its payment providers (§13). We do not buy personal data from data brokers or other sources for enrichment, marketing or resale. We do not sell, rent, license or exchange personal data as a product, and we do not disclose it for third-party advertising or marketing. This does not prevent the limited disclosures described in this Policy to contracted sub-processors acting for us, to sellers or payment providers involved in your transaction, or to authorities where disclosure is required by law. Personal data is not a product or service we offer; where we process it, we do so only as necessary to provide and secure the Service you use or to meet our legal obligations.
3. Our roles
For processing we independently determine — account, billing, security and legal compliance — Pattrans is the controller. Any new purpose that requires your consent will be described to you and your consent obtained before that processing begins (§16). For Customer Content processed on your instructions, Pattrans generally acts as a processor under your documented instructions — including these Terms, any applicable Data Processing Agreement, and your use and configuration of the Service — except where required by law or where Pattrans independently determines a separate purpose. You are responsible for the personal data in your documents and for a lawful basis to process it. Roles are determined by purpose, not by whether you are an organisation.
4. Purposes and legal bases
Section 2 explains in practical terms what information is involved and why. This section states the corresponding processing purposes and legal bases.
- Provide the Service to you — including managing your account and Standard Words, processing the documents you submit, running requested translations, and storing and applying terminology in your own My Termbase — to perform your agreement with us, as permitted by applicable personal-data law.
- Check your job for processing faults and retry, to deliver you a usable result — to perform your agreement with us, as permitted by applicable personal-data law.
- Detect, reproduce and fix processing faults, and improve the shared processing used by the Service, including authorised personnel viewing Output and related Customer Content — where necessary for Pattrans's legitimate interests in operating and improving the Service, or on another basis permitted by applicable law; otherwise, with consent where required.
- Translate documents that may contain third-party personal data — where such data is present, we process it on your instructions as processor, solely as necessary to perform the translation you request; you are responsible for an applicable lawful condition (§10).
- Issue invoices and meet tax and accounting duties — legal obligation.
- Protect the Service and prevent, detect and address fraud, abuse, security incidents and attacks — where necessary to protect Pattrans's, users' or other persons' lawful rights and interests against infringement, or under another condition permitted by applicable law; otherwise, with consent where required.
- Investigate and respond to support requests you make, including access by authorised personnel to the Customer Content reasonably necessary for that request — to perform your agreement with us, as permitted by applicable personal-data law.
- Send you service and legal notices — necessary to perform our agreement / legal obligation.
We rely on consent where the law requires it, and you may withdraw it at any time.
5. Sub-processors
To provide the Service we use contracted sub-processors in these categories: AI translation providers; cloud hosting and infrastructure; operational tools (logging, error monitoring, support); electronic invoicing providers; transactional email delivery (verification emails, login codes, notifications); domain management and serving of the marketing site (the marketing site only; application components connect directly to our servers); and third-party account sign-in, where you choose that sign-in method. Some process Customer Content; some are located outside Vietnam (§6). Our sub-processors may not use Customer Content to train, fine-tune or improve models or services for themselves or others, and process it only to perform their function for us. We disclose the current categories of sub-processors in this Policy; processing locations are set out in §6 and current recipient categories are available on request, and a current detailed sub-processor list is available to business customers on reasonable request, subject to appropriate confidentiality obligations. We give business customers reasonable advance notice of a new sub-processor that materially changes how Customer Content is processed, and we will notify affected users of a material change to the categories of recipients, processing locations or use of Customer Content where required by law. We may change providers, including processing on infrastructure we operate ourselves.
6. Cross-border transfer
Some sub-processors are located outside Vietnam, so your content and any personal data it contains may be transferred to and processed in other countries or regions. For each transfer we assess the recipient, purpose and protections, apply appropriate contractual and security safeguards — which may include purpose limitation, confidentiality, access controls, security requirements, retention limits, deletion obligations and restrictions on onward transfer — and comply with the cross-border-transfer requirements of Vietnamese personal-data law, including any impact assessment and filing. These safeguards reduce but do not eliminate transfer risk. Servers and storage: Singapore. Our AI translation, transactional email, third-party sign-in and domain providers are entities in the United States; transactional email is delivered through a sub-contractor's infrastructure in Japan. We do not speculate that data is stored anywhere other than the locations our providers publish. Current recipient categories are available on request; a current detailed sub-processor list is available to business customers on reasonable request, subject to appropriate confidentiality obligations.
7. How long we keep it
Your own device remains the primary home for your files. On our servers, processing-cache copies of source files, Output and intermediate representations created solely to provide the Service are deleted automatically after your project reaches a final state (completed, cancelled or failed) and the copies are no longer needed — normally within 7 days. Where storage on our servers runs low, these processing-cache copies may be removed sooner, and a server-side copy of a project that has not reached a final state may also be removed once it has been inactive for more than 30 days. Project records or other copies retained in your account remain until you delete the project; a deleted project remains in trash, where you can restore it, for up to 90 days unless you empty the trash earlier, after which its remaining account copies are permanently deleted, subject to the limited backup and legal-retention exceptions below. My Termbase entries remain in your account until you delete them or close your account. When you close your account, the account enters a 14-day waiting period during which you can restore it. After that period, the account and any remaining Customer Content are deleted from active systems, subject to completion of any active support request and the backup, security-log and legal-retention exceptions below; you should export any content you wish to retain before closing the account. Where you request support or a technical investigation, related project data may be kept for the duration of that request and deleted within the stated period after it is resolved, unless a longer period is legally required. Support messages you send us through the in-app support request feature are kept for up to 90 days after the request is closed. Where a request relates to a refund, a dispute or a legal claim, we may keep the related messages for as long as needed to resolve that matter, and delete them when it ends. Database backups are encrypted and kept for up to 120 days (14 days on the server; 30 days in a second store in the same region; up to 120 days on a Company device in Vietnam); operating logs (including security logs) are kept on a separate, limited cycle and are removed within 90 days. Records we must keep by law (such as invoices and tax records) are retained for the legally required period. Certain transaction records also retain the project folder name associated with the transaction. A project folder name includes a system-generated timestamp and a label you supply, which may reflect a document title; we retain it with the transaction record so that your own transaction history remains readable after the project itself has been deleted. These records do not retain your source documents, translations or intermediate files themselves. You can delete active project copies, or empty your trash, at any time; residual backup and log copies are removed under the cycle above.
8. Improving the Service
We work to improve the quality of the Service.
(a) As part of producing your translation, our systems automatically check your job for processing faults — such as missed or untranslated segments, empty output, or formatting errors — and retry so we can deliver you a usable result. This is part of providing the Service and concerns technical processing, not the linguistic accuracy of the Output.
(b) Authorised Pattrans personnel may view Output and related Customer Content in order to detect, reproduce and fix processing faults, and to improve the shared processing used by the Service.
(c) We do not copy, extract or embed your source documents, translations, intermediate text, or the terminology in your My Termbase into any shared resource — such as prompts, dictionaries or terminology resources — including by manual transcription.
(d) We do not use Customer Content to train or fine-tune AI models, and we contractually require applicable AI providers not to use it for those purposes.
When you ask for support on a specific issue, we may ask you to grant scoped, time-limited access to the projects concerned. You can decline, and you can revoke access you have granted at any time.
9. Your rights
Subject to law, you may ask us to: know how we process your data; give or withdraw consent; access, correct or update your data; delete or restrict processing; object to processing; and provide personal data relating to you in the form and scope required by law. You may also make a denunciation, bring proceedings, seek compensation and request other protective measures as provided by law. To protect you, we may verify your identity before acting. The applicable response period depends on the right exercised and the circumstances; details are available in our data-rights-request procedure or on request. A request to delete personal data is acknowledged within 2 working days and carried out within 20 days of receipt, in accordance with clause 4 Article 5 of Decree No. 356/2025/ND-CP; copies remaining in backups are removed under the cycle in §7, and the deletion request is re-applied if data is restored from backup. We may decline a request only on grounds permitted by law and will explain why. Where we process Customer Content only as a processor, we will assist and may direct you to the customer who controls that data. You may also complain to the competent authority for personal-data protection in Vietnam (§17).
10. Your responsibilities
Your documents may contain personal data of third parties, sometimes sensitive. Business customers represent that they have established the lawful conditions and authority required to process Customer Content through the Service and to give us the related instructions. Other users must not knowingly submit personal data they are not entitled to submit, and should not upload sensitive personal data unless necessary and lawfully authorised. These obligations do not limit our own obligations under applicable law.
11. Sensitive personal data
Customer Content may contain sensitive personal data (for example, health or genetic information in medical or pharmaceutical patents, or identification and financial details). Submit such data only where necessary and lawfully authorised. Because we may not be able to identify every item of sensitive data within technical documents, we apply strong baseline protections to all Customer Content and additional controls where sensitive processing is identified.
Beyond Customer Content, some data we collect ourselves to operate the Service may fall within the descriptive scope of the sensitive personal data categories under Vietnamese law: payment-transaction reconciliation data, and account sign-in, session and device logs. We apply the protections for sensitive data to this data on a precautionary basis, as the classification has no official guidance.
12. Security
We use technical and organisational measures appropriate to the risk, including: encryption in transit and, where applicable, at rest; access control on a least-privilege basis; logging and monitoring; logical access separation between customer accounts; secure deletion; sub-processor due diligence; and periodic review. Access to Customer Content is limited to authorised personnel and sub-processors bound by confidentiality, and only where necessary to provide, improve, secure or support the Service, or for incident response or legal compliance. If a personal-data breach occurs, we will investigate and mitigate it, notify the competent authority within the legally prescribed period where required, and notify affected persons where the applicable legal conditions for individual notice are met.
13. Payment and invoicing data
Payments are concluded by the seller of your transaction: for purchases made directly from Pattrans, Pattrans (with our payment provider); where a purchase is concluded with a Merchant of Record, that party. The seller and payment providers process payment data under the roles described in their applicable privacy terms and contractual arrangements, and may be located outside Vietnam; a Merchant of Record generally acts as an independent controller for the sale it concludes. Pattrans separately processes the limited order and account data it receives to provision Standard Words, reconcile transactions, and provide support.
Invoicing. For purchases made directly from Pattrans, we issue a Vietnamese electronic invoice. The billing details you provide are sent to the electronic invoicing provider we use to prepare and issue the invoice, and are transmitted to the tax authority as required by law. We limit the information sent to the billing details needed to prepare and issue the invoice. Where a purchase is concluded with a Merchant of Record, that party issues its own invoice under its own policies.
When you pay, your device loads the payment-code image directly from the collecting gateway and, if you use international checkout, opens the Merchant of Record's payment layer; those parties see your IP address and device information at this step without passing through our servers.
14. Cookies
Our website does not currently use cookies or similar technologies for analytics, profiling or advertising. It uses local storage in your browser only to remember display preferences you set, such as your chosen currency, and any cookie set by the Service is limited to what is necessary to operate and secure it. If we later introduce non-essential cookies or similar technologies, we will ask for your consent where required and provide controls for them before we start using them.
15. Automated decisions
We do not use the Service to make decisions about you that produce legal or similarly significant effects. Generating a translation is not such a decision.
16. Changes
We may update this Policy; material changes will be notified and the "last updated" date will change. Where a change introduces a new purpose that requires your consent, we will ask for that consent before starting the new processing.
17. Contact and complaints
For privacy questions or to exercise your rights, contact [email protected]. We aim to acknowledge general privacy enquiries within 5 business days. Requests to exercise your data-protection rights are handled within the response and completion periods required by applicable law, as described in §9; those periods take precedence over this general service target. You may also submit a complaint or request to the competent Vietnamese authority responsible for personal-data protection, including the Ministry of Public Security or the authority designated under applicable law.