Important Notice
This Policy explains how NGAN HA PHAT TRADING COMPANY LIMITED processes personal data in connection with Dudu VPN. The policy, actual data flows, SDK configuration, and App Store Connect privacy label must stay aligned and be updated when features change.
This Policy applies to the Dudu VPN app, website, and related support services. Third-party app stores, operating systems, and external sites are governed by their own policies.
2. Processing Principles
- Data minimization: process only what is needed for accounts, subscriptions, connectivity, security, and support;
- Purpose limitation: do not use VPN traffic for advertising, profiling, or unrelated purposes;
- Transparency and control: explain categories, purposes, retention, and deletion;
- Security: use reasonable controls such as encrypted transport, access restriction, separation, and auditing.
3. Information We May Process
3.1 Account and Contact Information
Registration email, account ID, sign-in state, security-verification result, and support contact information you provide.
3.2 Device and App Information
Device type, OS version, app version, language, limited device identifier, and installation or instance identifier. Purposes include device management, guest access, security, compatibility, and entitlement verification.
3.3 Purchase and Subscription Information
Product ID, order or transaction identifier, subscription state, expiry, and purchase platform. Complete bank or payment-card details are handled by Apple, Google, or the payment provider and are not received by us.
3.4 Connection and Usage Information
Where implemented, this may include app launch, selected route or region, connection-attempt time, result, duration, network type, and coarse region. It supports routing, capacity, security, and troubleshooting and does not include browsing destinations or content.
3.5 Diagnostics and Support Information
Crash logs, performance metrics, error codes, and descriptions, screenshots, or diagnostic files you voluntarily submit. Support attachments are used only to address the request.
4. VPN Traffic and Browsing Content
Network data must be processed transiently by the infrastructure to establish and carry the VPN tunnel. However, we do not record, retain, or create persistent logs containing:
- URLs, domain-query history, or browsing history;
- page bodies, downloads, chats, emails, or other communication content; or
- VPN traffic behavior for advertising profiles.
We do not sell VPN traffic data, disclose it to unrelated third parties, or use it for advertising, marketing, or purposes unrelated to providing the network service.
5. Purposes and Legal Bases
- Service performance: create accounts, provide connectivity, sync devices, and verify entitlements;
- Security and abuse prevention: identify abnormal sign-ins, fraud, attacks, and resource abuse;
- Troubleshooting and improvement: address crashes, compatibility, and connection faults;
- Support: respond to feedback, privacy requests, and account assistance;
- Legal obligations: satisfy applicable finance, tax, consumer-protection, or lawful authority requirements.
Depending on local law, bases may include contract performance, legitimate interests, legal obligation, or consent. Permission or consent is requested before processing when required.
6. Service Providers and Disclosure
We transfer data only as necessary to instructed providers, for example:
- Apple App Store / StoreKit and Google Play for purchases and entitlement verification;
- cloud, network, and content-delivery providers to operate accounts, APIs, and connectivity infrastructure;
- crash and performance diagnostic providers for necessary error and performance information;
- email or support providers to deliver service messages and handle requests.
We do not sell personal information to advertisers or data brokers. Necessary disclosure may occur where required by law, to protect users, or during a corporate transaction, with reasonable safeguards.
7. International Processing
The Service may use infrastructure outside your country or region. Where data is processed internationally, we use contractual, encryption, access-control, or other safeguards required by applicable law.
8. Retention
- Account data: while the account is active; generally deleted or de-identified within 30 days after deletion;
- device and security records: generally no more than 180 days, unless a security event or law requires longer;
- connection and diagnostic records: generally no more than 90 days;
- support records: generally no more than 12 months;
- orders, tax, and dispute records: restricted for the period required by applicable law.
After the retention period, data is deleted, anonymized, or aggregated so it no longer identifies a person.
9. Your Rights and Choices
Depending on local law, you may request access, correction, deletion, restriction, objection, withdrawal of consent, or a copy of your data. Use in-app settings or email us. Necessary identity verification may be required, and we respond within the legally applicable time.
Optional permissions and optional diagnostics can be disabled in system or app settings. Disabling a necessary permission may prevent the relevant feature.
10. Account Deletion
Registered users can initiate deletion in Me / Account & Security / Delete Account. Email is a fallback if access is unavailable. Account deletion does not automatically cancel an Apple or Google store subscription, which should be managed first. See the Account Deletion Statement.
11. Children’s Privacy
The Service is not directed primarily to children. Where guardian consent is legally required, users below the age of digital consent must not register independently. If information was collected without appropriate consent, we take steps to delete or restrict it.
12. Security
We use reasonable organizational and technical measures, including encrypted transport, least privilege, access controls, environment separation, logging and audit, and security updates. No system can guarantee absolute security. Legally notifiable data incidents will be handled as required.
13. Policy Changes
Feature, SDK, legal, or operational changes may require updates. Material changes will be explained through the App, website, or another reasonable channel, and the effective date will be updated.