Legal, Privacy and Security
Everything we are obliged to tell you, and a few things we are not. Written to be read, not to be skipped.
Last updated 4 August 2026
Privacy Policy
What we collect, why we collect it, and the rights you have over it. Written for the GDPR, Singapore’s PDPA, and US state privacy laws.
Cookie Policy
This site carries one analytics tag, and it stays switched off until you allow it. Until then it sets one cookie, to remember the choice you make. Here is how that choice is asked for, recorded, and withdrawn.
Terms of Use
The terms that govern your use of this website. Client engagements are governed by their own signed agreement, not by this page.
Security
How this website is secured, how security works in the software we deliver, and how to report a vulnerability to us.
Accessibility Statement
We aim to meet WCAG 2.1 Level AA. Here is what we have built in, and the limitations we know about.
Sub-processors
Who processes personal data on our behalf, how we govern them, and how clients get the definitive list for their engagement.
The short version
- This website carries one analytics tag, Google Analytics, and it stays switched off until you allow it. There is no advertising of any kind: no ad tag, no tracking pixel, no session recording, and Google's advertising features are switched off on every request. Until you allow Analytics it sets one cookie: the record of your own cookie choice.
- Our fonts are self-hosted, so loading a page does not disclose your visit to anyone else.
- The one thing we load from another company is the Google map of our Hanoi office, and only on the Contact page, and only after you allow it or press the button.
- The only personal data we collect directly is what you type into our forms: five fields and a timestamp from the contact form, or your email address and consent if you subscribe to the newsletter, plus an optional name and topic you can leave blank. If you allow Analytics, Google also collects usage data described in the Privacy Policy.
- We do not sell or share personal data, and we never have.
- We are certified to ISO/IEC 27001:2013 and ISO 9001:2015.
- For data inside systems we build for clients, the client is the controller and we act as processor under a GDPR Article 28 agreement.
If you want the reasoning behind any of this, each page explains itself rather than reciting a template. Start with the Privacy Policy.
Need something for procurement?
Security questionnaires, ISO certificates, our standard data processing agreement, and a signed NDA before detailed discussions are all things we provide as a matter of course.