Attract more consumers, faster
Get the most out of data
Seamless O2O experiences
Stop spray & pray Digital Marketing Budget
Shorten buying cycle
Become top-of-mind and sustain customer engagement
Attract more customers to the store
Cross-selling and upselling
Enhance conversion rate
Increase the win rate
The latest industry news, updates and info
Get up and running on new features and techniques
Learn how our customers are making big changes.
This Policy describes how ByteTech Co., Ltd. stores, processes, protects, and manages data in the course of providing the services of the PangoCDP platform.
Effective date: 20/10/2020 Last updated: 15/07/2026 Version: 1.0
This is an operational policy draft prepared based on PangoCDP’s current service model. ByteTech should carry out a legal review before official publication or before applying it to each specific market, contract, and data group.
This Privacy Policy describes how ByteTech Co., Ltd. (“ByteTech”, “we”) stores, processes, and protects data when customers use the services of the PangoCDP platform.
PangoCDP is a Customer Data Platform (CDP) for enterprises, developed and operated by ByteTech to help customers store, manage, consolidate, analyze, and exploit customer data according to the needs and configuration of each organization.
This Policy applies to PangoCDP services provided through:
PangoCDP does not own the data stored by customers on the system. ByteTech stores and processes data within the scope of the services, configuration, and authorization granted by the customer.
Customers using PangoCDP are the party that decides:
Customers are responsible for:
ByteTech does not determine the business purpose of customer data on its own and does not use customer data for any independent purpose outside the scope of providing, protecting, maintaining, and supporting the PangoCDP service, except where permitted by the customer or required by law.
The actual scope of data depends on the product, module, data source, access rights, and configuration selected by each customer.
Connected sources may include:
Depending on the access rights and functions activated, data from connected platforms may include account or resource information, interaction information, forms, leads, events, messages, comments, analytics data, and related metadata.
Authentication information is used solely to perform the functions that the customer has authorized or configured.
ByteTech stores and processes data in order to:
PangoCDP only accesses and processes data from a third-party platform when the customer:
ByteTech does not expand the scope of access beyond the rights granted on its own initiative. Customers may revoke access on PangoCDP or on the corresponding platform. Revoking access may cause part or all of the integrated functionality to stop working.
PangoCDP may provide templates, configuration tools, SDKs, tracking code, forms, or technical components for customers to deploy on their own channels.
Where a customer uses a PangoCDP template to create a Zalo Mini App or a form, each Mini App or form is created and operated for the corresponding customer, and must also comply with Zalo’s approval process and the relevant requirements of that platform.
When a customer deploys tracking code or an SDK on a website, application, or channel that the customer manages, the customer is responsible for:
PangoCDP stores and processes data generated by these tools according to the customer’s configuration and scope of authorization.
Data is retained for the time necessary to provide the service, meet the customer’s configuration, perform the contract, ensure system safety, and comply with applicable legal requirements.
The retention period may depend on:
Tokens or authentication information that have expired, been revoked, become invalid, or are no longer needed will be disabled, replaced, or deleted in accordance with PangoCDP’s operational and security procedures.
When a connection is disconnected, PangoCDP will stop receiving new data from that connection. Data already stored before the time of disconnection continues to be managed according to the applicable retention configuration, data deletion requests, contract, and legal obligations.
PangoCDP is deployed on cloud computing infrastructure managed and operated by ByteTech.
As of the publication of this Policy, the infrastructure in use includes:
Each customer’s data may be stored and processed at one or more data centers depending on the deployment architecture, service package, technical requirements, and applicable agreement.
ByteTech may add or change infrastructure providers or deployment locations to meet requirements for performance, availability, security, or compliance. Significant changes that materially affect the scope of data processing will be notified or updated in accordance with the applicable agreement and regulations.
Because PangoCDP has infrastructure in Vietnam and Singapore, data may be stored, backed up, transmitted, or processed outside the country where the customer or end user is located.
The customer is responsible for determining whether the use of the corresponding configuration or data center is consistent with the customer’s own legal obligations. ByteTech will apply appropriate technical, organizational, and contractual measures within the scope of the service and the agreement with the customer to protect data in connection with cross-border processing activities.
Where necessary, specific requirements regarding storage location, data transfer, a Data Processing Agreement (DPA), contractual terms, or additional protection mechanisms will be set out in a separate contract or document between ByteTech and the customer.
ByteTech does not sell customer data.
Data may be provided or made accessible in the following cases:
Support service providers are only permitted to process data to the extent necessary to provide services to ByteTech and must comply with appropriate confidentiality obligations.
ByteTech applies technical and organizational measures appropriate to the scope of the service, the type of data, and the level of risk, including:
No method of electronic transmission or storage can guarantee absolute security. ByteTech maintains and improves appropriate measures to minimize the risk of unauthorized access, use, alteration, disclosure, or loss of data.
When a security incident that may affect customer data is detected, ByteTech will carry out activities appropriate to the severity and scope of the incident, including:
Within the scope of the service, contract, and applicable regulations, customers may:
Where ByteTech receives a request directly from an end user regarding data controlled by a customer, ByteTech may forward the request to the corresponding customer or direct the requester to contact the organization that collected the data, unless the law requires ByteTech to handle it directly.
Data deletion is carried out based on a valid request from the customer, the functionality provided on PangoCDP, the contractual terms, and applicable legal regulations.
The verification process, scope of data, processing time, and cases where data must continue to be retained will be described at:
Data Deletion Instructions for PangoCDP Services
URL: https://pangocdp.com/data-deletion
Facebook, Instagram, TikTok, Zalo, Viber, Google, and other platforms have their own policies regarding data, access rights, token lifetimes, APIs, and content. Customers are responsible for complying with the applicable terms and policies of the platforms they connect to.
Changes, restrictions, or revocations of APIs, access rights, or functionality by a third-party platform may alter or interrupt part of the PangoCDP service. ByteTech does not control, and is not responsible for, the independent data processing activities of third-party platforms.
ByteTech may update this Privacy Policy to reflect changes in the service, infrastructure, security requirements, contracts, or law.
The latest version will be published on PangoCDP’s website or service domain, together with the corresponding update date. Where a change has a significant effect on how data is processed, ByteTech may notify customers via email, the system, or another appropriate contact channel.
Any questions or requests relating to this Privacy Policy and to data on PangoCDP may be sent to:
Operating entity: ByteTech Co., Ltd.
Product: PangoCDP
Website: https://pangocdp.com
Support email: hi@bytetech.io
© 2016–2026 ByteTech Co., Ltd. · PangoCDP Platform