top of page

Personal Data and Privacy Policy

STAR KICKBOXING & FITNESS
Effective date: 01 January 2026
Last updated: 31/12/2025

This Privacy Policy is prepared to align with Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 (“PDPL”), which takes effect on 01 January 2026. 

At STAR Kickboxing & Fitness (“STAR”, “we”, “us”), we respect your privacy and are committed to protecting your personal data. This policy explains what we collect, why we collect it, how we use it, and the rights you have.

​​​

1) Who we are and our roles under the PDPL

STAR is the Personal Data Controller for the personal data we collect and use for our business operations.

In some cases, STAR may also act as a Personal Data Controller and Processor (for example, when we both decide the purpose and directly process data in our systems).

We also use trusted service providers who may act as Personal Data Processors (processing data on our instructions) or Third Parties (where legally applicable). 

Contact (data protection contact):
Email: starkickboxingandfitness@gmail.com
Address: 72 Xuân Diệu, Tây Hồ, Hà Nội, Việt Nam

2) What personal data we collect

Depending on how you interact with us, we may collect:

Basic personal data

  • Full name, phone number, email address

  • Date of birth 

  • Emergency contact details

  • Bookings, attendance, membership status

  • Communications with us (messages/emails)

Financial / transaction data

  • Payments, invoices, receipts, purchase history (where relevant)

Sensitive personal data (only if needed for safety)

  • Health or injury information you choose to share so our coaches can keep you safe and adapt training appropriately.

We aim to collect only what is necessary for clear purposes.

3) How we collect your data

We collect data when you:

  • Sign up for a trial or membership

  • Book classes / personal training

  • Make a payment

  • Fill in forms / waivers / questionnaires

  • Contact us online or in person

  • Use our website (cookies/analytics)

4) Why we use your data

We use your personal data to:

  • Manage memberships, bookings, and attendance

  • Provide services safely (including adapting training where needed)

  • Process payments and issue invoices/receipts

  • Meet Vietnamese accounting and tax requirements

  • Communicate service information (e.g., schedule updates, booking changes)

  • Improve our services and customer experience

  • Send promotions and updates only when permitted and/or where you have consented

5) Legal basis for processing

Under the PDPL framework, we process personal data on appropriate grounds, such as:

  • Your consent (especially for marketing and certain optional data)

  • Providing and managing services you request (membership/bookings)

  • Compliance with legal obligations (e.g., tax and accounting)

  • Protection of life/health in emergencies and safety situations (where applicable)

You can withdraw consent at any time where consent is the basis for processing (for example, marketing).

6) Systems we use (Wix, KiotViet, Google Drive)

We use these main systems to run STAR:

Wix (website + membership management + bookings + member app)

We use Wix to host our website and manage memberships, customer profiles, and bookings.

KiotViet (payment processing + invoicing + live tax reporting)

We use KiotViet to process payments, issue invoices/receipts, and support live tax reporting in line with Vietnamese tax requirements.

Google Drive (internal operational storage)

We may store limited operational documents (e.g., trackers or admin records) in Google Drive with controlled staff access.

We restrict access to authorised staff only and aim to minimise duplication of customer data across systems.

7) Sharing and disclosure

We do not sell personal data.

We may share personal data only when necessary:

  • With service providers that help us operate (e.g., Wix, KiotViet, Google services) under appropriate controls

  • Where required by Vietnamese law or competent authorities

  • To protect health, safety, and legal rights where applicable

 

8) Cross-border data transfers

Some of the systems we use may store or process data on servers outside Vietnam.

Where cross-border transfer applies, we will implement required safeguards and, where required, prepare and maintain the appropriate cross-border transfer impact assessment documentation and follow required procedures.

9) Data protection impact assessments and records

Where required, STAR will prepare and maintain:

  • Processing impact assessment documentation; and/or

  • Cross-border transfer impact assessment documentation

and update these records when legally required through the relevant system/portal or with the competent authority, in line with implementing requirements.

10) Data security

We use reasonable technical and organisational measures appropriate to our business size and risk, such as:

  • Access controls (only authorised staff)

  • Secure passwords and account protections

  • Staff rules to avoid storing unnecessary personal data in emails and personal devices

  • Secure handling of sensitive data (health/injury information)

11) Data retention

We keep personal data only as long as necessary for the purposes above, including:

  • Tax/accounting records retained for legally required periods

  • Membership/booking records retained as needed for service and dispute handling

  • Health/injury notes retained only while relevant for safety

  • Marketing contact details retained until you unsubscribe/withdraw consent

When no longer needed, we delete or anonymise data appropriately.

12) Your rights

In line with the PDPL, you can contact us to:

  • Request access to your personal data

  • Request correction/updates

  • Request deletion where legally permitted

  • Withdraw consent (especially for marketing)

  • Raise questions or complaints regarding how we handle your personal data

We will respond in line with applicable legal requirements.

13) Children’s data

For children participating in STAR services, we apply additional care and only collect what is necessary for:

  • Registration and attendance

  • Parent/guardian contact

  • Health and safety during training

14) Personal data breach handling (72-hour notification)

If we detect a personal data protection incident that may cause harm or affect rights and interests as described by law, we will:

  • Take steps to contain and reduce impact

  • Record the incident and cooperate with relevant authorities

  • Notify the competent personal data protection authority within 72 hours where the legal threshold is met

  • Where appropriate, we may also notify affected individuals with practical steps to protect themselves.

15) Updates to this policy

We may update this policy to reflect legal changes, system changes, or operational changes. The latest version will be posted on our website.

16) Contact us

Email: starkickboxingandfitness@gmail.com
Address: 72 Xuân Diệu, Tây Hồ, Hà Nội

Cookies in use:

Cookie Data STAR Kickboxing and Fitness
bottom of page