Privacy Policy

This Policy describes how ByteTech Co., Ltd. stores, processes, protects, and manages data in the course of providing the services of the PangoCDP platform.

Effective date: 20/10/2020   Last updated: 15/07/2026    Version: 1.0    

This is an operational policy draft prepared based on PangoCDP’s current service model. ByteTech should carry out a legal review before official publication or before applying it to each specific market, contract, and data group.



1. Introduction and Scope of Application

This Privacy Policy describes how ByteTech Co., Ltd. (“ByteTech”, “we”) stores, processes, and protects data when customers use the services of the PangoCDP platform.

PangoCDP is a Customer Data Platform (CDP) for enterprises, developed and operated by ByteTech to help customers store, manage, consolidate, analyze, and exploit customer data according to the needs and configuration of each organization.

This Policy applies to PangoCDP services provided through:

  • pangocdp.com
  • mydatalakes.com and related subdomains
  • Related subdomains, APIs, SDKs, applications, and services of PangoCDP


2. Role and Responsibility Regarding Data

PangoCDP does not own the data stored by customers on the system.  ByteTech stores and processes data within the scope of the services, configuration, and authorization granted by the customer.

Customers using PangoCDP are the party that decides:

  • The type of data collected and entered into PangoCDP.
  • The source of data and the method of data collection.
  • The purpose of using and processing data.
  • The parties entitled to access, exploit, or receive data.
  • The data retention period according to business needs and legal requirements.

Customers are responsible for:

  • Ensuring that data is collected and used lawfully.
  • Providing privacy notices, cookie banners, or end-user consent mechanisms when required by law or by the relevant platform.
  • Ensuring they have full rights, permission, and authority necessary to enter data into PangoCDP and to request ByteTech to store and process that data.
  • Managing accounts, user permissions, and data exploitation activities within the scope of their own organization.
  • Complying with applicable regulations on personal data protection, privacy, advertising, communications, and the policies of third-party platforms.

ByteTech does not determine the business purpose of customer data on its own and does not use customer data for any independent purpose outside the scope of providing, protecting, maintaining, and supporting the PangoCDP service, except where permitted by the customer or required by law.


3. Types of Data Processed on PangoCDP

The actual scope of data depends on the product, module, data source, access rights, and configuration selected by each customer.

3.1. Account and Organization Information

  • Full name.
  • Email address and work contact information.
  • Company or organization name.
  • Account, organization, or tenant identifier.
  • Role, user group, and access rights.
  • Account status and information used to support the service.

3.2. Customer Data Entered by the Organization Into the System

  • Identifying information and attributes of the customer’s own customers.
  • Contact information managed by the customer.
  • Transaction, product, service, or loyalty program data.
  • Event and behavioral data.
  • Interaction data across connected channels and platforms.
  • Segmentation, tag, audience group, and processing result data.
  • Data used for reporting, analysis, and operations.
  • Data models, extended fields, or custom data defined by the customer.

3.3. Data From Connected Platforms and Systems

Connected sources may include:

  • Facebook and Instagram.
  • TikTok.
  • Zalo Official Account and Zalo Mini App.
  • Viber.
  • Google services.
  • CRM, sales, customer service, or marketing systems.
  • Websites, applications, SDKs, APIs, and other data sources managed by the customer.
  • Other platforms supported by PangoCDP from time to time.

Depending on the access rights and functions activated, data from connected platforms may include account or resource information, interaction information, forms, leads, events, messages, comments, analytics data, and related metadata.

3.4. Connection Information

  • Connection identifier.
  • Identifier of the connected account, page, Official Account, application, or resource.
  • Name, type, status, and owner of the connection.
  • Synchronization configuration information.
  • Time of setup, update, and most recent synchronization.
  • Technical metadata used to manage the connection.

3.5. Authentication and Authorization Information

  • Access Token and Refresh Token.
  • OAuth information or an equivalent authentication mechanism.
  • Authorization Scopes or Permissions.
  • Validity period and status of the token.
  • Information on granting, revoking, and re-authenticating access.
  • Other technical information necessary to maintain a valid connection.

Authentication information is used solely to perform the functions that the customer has authorized or configured.

3.6. System Operation, Security, and Service Usage Information

  • IP address, browser, device, and operating system.
  • Login and system access logs.
  • API logs, synchronization logs, data processing logs, and system task logs.
  • Audit logs, error logs, and diagnostic information.
  • Information used for monitoring performance, safety, and technical support.


4. Purpose of Data Processing

ByteTech stores and processes data in order to:

  • Provide the features and services of PangoCDP.
  • Store, manage, and consolidate data according to the customer’s configuration.
  • Synchronize data from sources the customer has connected and authorized.
  • Standardize, reconcile, analyze, segment, and process stored data.
  • Provide reports, operational information, and processing results to customers.
  • Manage accounts, tenants, users, access rights, and connections.
  • Maintain the stability, performance, and availability of the service.
  • Detect, prevent, and handle errors, fraud, or unauthorized access.
  • Provide technical support and resolve customer requests.
  • Fulfill obligations under applicable contracts and law.


5. Connections to Third-Party Platforms and Systems

PangoCDP only accesses and processes data from a third-party platform when the customer:

  • Proactively selects and sets up the connection.
  • Grants access via OAuth, an API key, a token, or a corresponding authentication mechanism.
  • Has administrative rights or lawful rights over the connected account and resources.
  • Activates the functions to be used on PangoCDP.

ByteTech does not expand the scope of access beyond the rights granted on its own initiative. Customers may revoke access on PangoCDP or on the corresponding platform. Revoking access may cause part or all of the integrated functionality to stop working.


6. Mini Apps, Forms, and Tracking Code

PangoCDP may provide templates, configuration tools, SDKs, tracking code, forms, or technical components for customers to deploy on their own channels.


6.1. Zalo Mini App and Forms

Where a customer uses a PangoCDP template to create a Zalo Mini App or a form, each Mini App or form is created and operated for the corresponding customer, and must also comply with Zalo’s approval process and the relevant requirements of that platform.


6.2. Website Tracking, SDK, and Event Tracking

When a customer deploys tracking code or an SDK on a website, application, or channel that the customer manages, the customer is responsible for:

  • Notifying end users about the tracking activity and data processing involved.
  • Providing a consent mechanism or cookie choice where necessary.
  • Only activating the types of data and events consistent with the stated purpose.
  • Complying with the law and the policies of the relevant platform or device.

PangoCDP stores and processes data generated by these tools according to the customer’s configuration and scope of authorization.


7. Data Storage and Retention Period

Data is retained for the time necessary to provide the service, meet the customer’s configuration, perform the contract, ensure system safety, and comply with applicable legal requirements.

The retention period may depend on:

  • The type of data and the module used.
  • The customer’s service package and retention configuration.
  • The duration of the account or contract.
  • Backup, audit, security, and incident-handling requirements.
  • Retention obligations under law or under the agreement with the customer.

Tokens or authentication information that have expired, been revoked, become invalid, or are no longer needed will be disabled, replaced, or deleted in accordance with PangoCDP’s operational and security procedures.

When a connection is disconnected, PangoCDP will stop receiving new data from that connection. Data already stored before the time of disconnection continues to be managed according to the applicable retention configuration, data deletion requests, contract, and legal obligations.


8. Storage Infrastructure and Data Centers

PangoCDP is deployed on cloud computing infrastructure managed and operated by ByteTech.

As of the publication of this Policy, the infrastructure in use includes:

Each customer’s data may be stored and processed at one or more data centers depending on the deployment architecture, service package, technical requirements, and applicable agreement.

ByteTech may add or change infrastructure providers or deployment locations to meet requirements for performance, availability, security, or compliance. Significant changes that materially affect the scope of data processing will be notified or updated in accordance with the applicable agreement and regulations.


9. Cross-Border Data Transfer

Because PangoCDP has infrastructure in Vietnam and Singapore, data may be stored, backed up, transmitted, or processed outside the country where the customer or end user is located.

The customer is responsible for determining whether the use of the corresponding configuration or data center is consistent with the customer’s own legal obligations. ByteTech will apply appropriate technical, organizational, and contractual measures within the scope of the service and the agreement with the customer to protect data in connection with cross-border processing activities.

Where necessary, specific requirements regarding storage location, data transfer, a Data Processing Agreement (DPA), contractual terms, or additional protection mechanisms will be set out in a separate contract or document between ByteTech and the customer.


10. Data Sharing and Support Service Providers

ByteTech does not sell customer data.

Data may be provided or made accessible in the following cases:

  • At the request, instruction, or with the permission of the customer.
  • Where necessary to carry out a connection, synchronization, or function activated by the customer.
  • Where necessary for infrastructure, security, monitoring, backup, or technical service providers supporting the operation of PangoCDP.
  • Where there is a lawful request from a competent state authority or an obligation under the law.
  • Where necessary to protect the system, the customer, or ByteTech, or to prevent unlawful conduct.
  • In connection with a restructuring, merger, or transfer of business operations, provided that appropriate security measures are applied.

Support service providers are only permitted to process data to the extent necessary to provide services to ByteTech and must comply with appropriate confidentiality obligations.


11. Data Security

ByteTech applies technical and organizational measures appropriate to the scope of the service, the type of data, and the level of risk, including:

  • Encryption of data in transit.
  • Identity management, authentication, and access authorization.
  • Data separation and access scope by organization or tenant.
  • Audit logs, operational logs, and system monitoring.
  • Backup, recovery, and maintenance of service availability.
  • Management of authentication information, tokens, and system secrets.
  • Internal access control based on role and need-to-know.
  • Procedures for handling errors, vulnerabilities, and security incidents.

No method of electronic transmission or storage can guarantee absolute security. ByteTech maintains and improves appropriate measures to minimize the risk of unauthorized access, use, alteration, disclosure, or loss of data.


12. Data Security Incident Notification and Handling

When a security incident that may affect customer data is detected, ByteTech will carry out activities appropriate to the severity and scope of the incident, including:

  • Recording, classifying, and assessing the scope of impact.
  • Implementing containment, mitigation, and remediation measures.
  • Preserving the information and logs necessary to support investigation.
  • Notifying affected customers within a reasonable time or within the period specified in the applicable contract and law.
  • Providing reasonable information to enable the customer to assess risk and fulfill its own obligations to end users or competent authorities.
  • Implementing preventive measures to reduce the risk of recurrence.


13. Customer Rights and Requests

Within the scope of the service, contract, and applicable regulations, customers may:

  • Manage their accounts, users, and access rights.
  • Manage data within their own scope of control.
  • Set up, update, or disconnect data connections.
  • Revoke access rights granted to PangoCDP.
  • Request assistance to export, correct, or delete data where the functionality or contract allows.
  • Request information regarding the storage and processing of their organization’s data.

Where ByteTech receives a request directly from an end user regarding data controlled by a customer, ByteTech may forward the request to the corresponding customer or direct the requester to contact the organization that collected the data, unless the law requires ByteTech to handle it directly.


14. Data Deletion Requests

Data deletion is carried out based on a valid request from the customer, the functionality provided on PangoCDP, the contractual terms, and applicable legal regulations.

The verification process, scope of data, processing time, and cases where data must continue to be retained will be described at:

Data Deletion Instructions for PangoCDP Services

URL: https://pangocdp.com/data-deletion


15. Third-Party Platform and Service Policies

Facebook, Instagram, TikTok, Zalo, Viber, Google, and other platforms have their own policies regarding data, access rights, token lifetimes, APIs, and content. Customers are responsible for complying with the applicable terms and policies of the platforms they connect to.

Changes, restrictions, or revocations of APIs, access rights, or functionality by a third-party platform may alter or interrupt part of the PangoCDP service. ByteTech does not control, and is not responsible for, the independent data processing activities of third-party platforms.


16. Changes to the Privacy Policy

ByteTech may update this Privacy Policy to reflect changes in the service, infrastructure, security requirements, contracts, or law.

The latest version will be published on PangoCDP’s website or service domain, together with the corresponding update date. Where a change has a significant effect on how data is processed, ByteTech may notify customers via email, the system, or another appropriate contact channel.


17. Contact Information

Any questions or requests relating to this Privacy Policy and to data on PangoCDP may be sent to:

Operating entity: ByteTech Co., Ltd.

Product: PangoCDP

Website: https://pangocdp.com

Support email: hi@bytetech.io


© 2016–2026 ByteTech Co., Ltd. · PangoCDP Platform