SS SiteminderStore

Security whitepaper · Bảo mật

How we protect your data

Bảo mật dữ liệu khách sạn và khách

SiteminderStore Vietnam Company Limited processes personal data of Vietnamese hotel guests and operational data of Vietnamese hotels. This whitepaper describes the technical and organisational measures we apply to protect that data under the Law on Cybersecurity 2018 and Decree 13/2023/ND-CP on Personal Data Protection.

§ 01Data hosting

Personal data of Vietnamese guests is stored in Vietnamese data centres operated by Viettel IDC in Ho Chi Minh City and Hà Nội. Non-personal operational data (aggregate metrics, city-level benchmarks, anonymised time series) may be replicated to Singapore for regional latency, in compliance with Article 26 of the Law on Cybersecurity 2018.

§ 02Encryption

All data is encrypted in transit using TLS 1.3 with modern cipher suites. All data at rest is encrypted with AES-256. Encryption keys are managed in AWS KMS with rotation every twelve months. Sensitive fields (payment references, national ID numbers, contact phone numbers) are additionally encrypted at the application layer with per-tenant keys.

§ 03Access control

Employee access to production systems requires multi-factor authentication and is logged. Access is granted on the principle of least privilege and reviewed quarterly. Contractor access is time-limited and revoked automatically at the end of each engagement. All privileged sessions are recorded.

§ 04Vulnerability management

We run continuous vulnerability scanning against our production infrastructure and dependency graph. Critical vulnerabilities are patched within seventy-two hours; high-severity within one week; medium-severity within one month. Third-party penetration tests are commissioned annually from a Vietnamese-registered security firm.

§ 05Incident response

Our incident-response workflow follows a defined runbook: detection, containment, notification, remediation, post-mortem. Personal-data breaches are notified to the Ministry of Public Security\'s Department of Cybersecurity and High-Tech Crime Prevention (A05) within the deadlines defined by Vietnamese law, and to affected data subjects and hotel customers within seventy-two hours of confirmed incident. Contact security@siteminderstore.org to notify us of a security concern.

§ 06Business continuity

Production data is backed up daily to a separate Vietnamese data centre. Point-in-time recovery is available for the past thirty days. Disaster-recovery drills are conducted quarterly with a recovery-time objective of four hours and a recovery-point objective of fifteen minutes.

§ 07Employee security

All employees complete security training on joining and annually thereafter. Background checks are performed for roles with production access. Confidentiality clauses are included in every employment contract.

§ 08Subprocessors

A list of current subprocessors is maintained in the workspace and updated at least thirty days before any change. Every subprocessor is bound by a data-processing agreement that mirrors our commitments under Decree 13/2023/ND-CP.

§ 09Compliance framework

Our compliance framework is anchored in Vietnamese law: Law on Cybersecurity 2018 (Luật An ninh mạng), Decree 13/2023/ND-CP on Personal Data Protection, Law on E-Transactions 2023, Law on Consumer Protection 2023, Circular 78/2021/TT-BTC and Decree 123/2020/ND-CP on e-invoicing. We hold ourselves to the higher of applicable Vietnamese law and international best practice.