ADtok Privacy Policy

ADtok – LHJ Co., Ltd (hereinafter referred to as the "Company") explains in detail through this Privacy Policy (hereinafter referred to as "this Policy") the scope of personal information collected from users, how it is used, shared, stored, and protected, and what rights users have regarding their personal information. All terms used in this Policy have the same meaning as defined in the Company's Terms of Service and apply to all users using the services provided by the Company (hereinafter referred to as the "Service").

The Company has established this Policy in compliance with the Personal Data Protection Law of the Socialist Republic of Vietnam (Law No. 91/2025/QH15) and related decrees (Decree 356/2025/ND-CP), as well as other international and regional data protection laws. This Policy applies to all services provided by the Company through the ADtok mobile application and related websites, including advertising reward services, game services, point accumulation and voucher exchange services, location-based check-in missions, and all other services.

1. Collection of Personal Information

1.1 Definition of Personal Information Collected by the Company

The Company may collect data or combinations of data that can identify a specific individual (hereinafter referred to as "Personal Information") when users use the Company's services (website, mobile application, etc.) or interact with the Company team. This personal information includes information directly provided by users or generated during service use. The Company collects the minimum amount of personal information necessary to provide the service, which is categorized into general personal information and sensitive personal information under the Vietnam Personal Data Protection Law.

  • General Personal Information: Gender, age, email address, account data (Member ID, password), device identification information (Device ID, IMEI, MAC address, advertising identifier, etc.), IP address, browser type, cookies, service usage records (advertisement viewing history, game play records, login records, etc.), transaction data (point accumulation and usage history, GP usage history, voucher/coupon exchange history).
  • Sensitive Personal Information: Due to the nature of the service, the Company may collect precise location data (GPS coordinates, etc.) for location-based check-in missions. In addition, information closely related to personal privacy such as lifestyle habits, hobbies, interests, and consumption patterns voluntarily provided by users for big data analysis services may be included.

1.2 Timing and Methods of Personal Information Collection

The Company collects personal information in the following cases:

  • During membership registration and login: When users voluntarily provide basic information such as email address, name, hobbies, and interests during the membership registration process, create an account through social login (Google, Facebook, etc.), or provide consent for collection.
  • During service use: When information is automatically generated and collected through user activities such as watching advertisements, using check-in features, performing location-based missions, playing games, or exchanging vouchers/coupons.
  • Advertising identifier and viewing records are collected when watching advertisements (Google AdMob, Offerwall, etc.).
  • Location information may be collected when using the 'Check-in' feature.
  • Answers to daily questions (hobbies, habits, lifestyle) are collected.
  • GP (Game Point) usage history and game results are collected when using game content.
  • Transaction history is collected when exchanging vouchers/coupons.
  • When using the referral system: Referral codes and registration status of referred users are collected. Such collection is carried out to support users in using the service smoothly and to provide a personalized experience.

1.3 Exclusion of Direct Personal Information Collection

The Company does not intentionally collect direct financial or identity information such as resident registration numbers, home addresses, social security numbers, bank account numbers, or credit card information. Such information is not essential for general service provision and is excluded from collection under the Company's policy. The Company does not purchase personal information from third parties or collect it through illegal channels without user consent. All information is limited to data directly entered with the user's explicit consent or automatically generated during service use.

1.4 Restriction Policy for Personal Information Protection in Case of Unauthorized Access

The Company allows membership registration and service use only through official websites and mobile applications to maintain service stability and security. If it is confirmed that a user has accessed or created an account through unauthorized platforms, devices, or other paths not approved by the Company, the Company may delete or lock the relevant account.

In addition, the Company has the following restriction policies to protect user information from unauthorized access and hacking attempts:

  • Blocking access from IP ranges where abnormal traffic is detected.
  • Temporarily locking accounts after consecutive failed login attempts.
  • Restricting service use if access via VPN or proxy server is detected.
  • Blocking access from abnormal environments such as emulators, rooted/jailbroken devices.

1.5 One Account per Person Principle

The Company restricts users to one account per person. This is to ensure fairness of the service, fairness of point accumulation, protection of the advertising ecosystem, and consistency in data management. ADtok service strictly applies the one-account-per-person and one-device-per-account principle for fair point accumulation.

To verify this, device unique identification information (Device ID, IMEI, etc.) is collected to prevent duplicate registrations and multiple account creation. If it is confirmed that a user has created or used multiple accounts, the Company may delete or lock the relevant accounts, and all accumulated points and GP will be forfeited. The Company is not responsible for any data loss or service restrictions resulting from this.

2. Use of Personal Information

2.1 Purposes of Personal Information Use

The Company uses the collected personal information only for strictly limited purposes permitted by relevant laws (such as Vietnam PDPL). Specific purposes of use are as follows:

  • Service provision and contract performance: Member identification, point/GP accumulation and management, voucher/coupon issuance and delivery, game service provision, location-based check-in mission processing.
  • Customer support and personalized features: Providing personalized advertisements using the user's hobbies, interests, and lifestyle patterns (check-in question answer data), rewarding ad viewing, and providing prompt customer support for inquiries.
  • Maintenance of service safety and security: Detecting and sanctioning illegal access, fraudulent activities, system errors, multiple account creation, macro usage, and other misconduct to ensure service stability.
  • Research and development: Analyzing data for service improvement, user experience optimization, and new feature development, within the scope that does not take precedence over users' basic rights or data protection interests.
  • Specific purposes based on user consent: Using information for additional point-based services when the user explicitly consents.
  • Compliance with legal or regulatory obligations: Processing information as required by law, such as compliance with tax laws, consumer protection laws, or future KYC (Know Your Customer) procedures.

Users may withdraw consent at any time for the use of personal information for specific purposes (e.g., marketing, personalized advertising). Consent withdrawal can be done through settings in the user's mobile app or by contacting customer service. However, since the use of personal information is a core operating condition of the ADtok service, withdrawal of consent will be processed as membership withdrawal.

Upon withdrawal of consent, use of some or all services (especially point accumulation and exchange functions) may be restricted. Withdrawal of consent does not affect the legality of personal information processing performed prior to the withdrawal.

2.3 Restriction on Sharing Personal Information for Marketing Purposes

The Company does not sell or rent personal information to third parties for marketing purposes without the user's explicit and specific consent. However, anonymized data may be shared with external advertisers to use users as targets for marketing on the ADtok advertising platform. Anonymized big data (statistical information that cannot identify individuals) collected through check-in questions may be shared with marketing partners. In this case, personally identifiable information such as the user's name and email address is not provided, and data is used only in aggregated form.

2.4 Prohibition of Illegal Programs and Account Use

The use of illegal programs (automation programs, macros, click bots, emulators, etc.) or illegal accounts to falsely exchange or accumulate rewards (e.g., points, GP, etc.) is strictly prohibited. If such acts are detected, the Company may delete the account or restrict service use, and all accumulated points and GP will be forfeited.

This is an essential measure to maintain the fairness and security of the service and to prevent misuse of personal information. The Company monitors usage records to detect such acts and may suspend accounts and take legal action upon detection. The Company is not responsible for any losses resulting from this.

2.5 Possibility of KYC (Know Your Customer) Procedures

The Company may introduce KYC procedures in the future to comply with legal requirements (e.g., anti-money laundering regulations) or to strengthen service security. In the case of high-value voucher exchanges or suspicious transactions, the Company may request additional identity verification (KYC) for anti-money laundering and identity confirmation. In such cases, the Company may request additional information (e.g., copy of ID card, proof of address) and users are obligated to cooperate. KYC procedures will be conducted in compliance with relevant laws and regulations.

2.6 Information for Vietnam Users

Personal information of users using the service in Vietnam is processed in accordance with Vietnamese law. User data in Vietnam is stored on servers in Vietnam in principle, or when transferred abroad, protection measures in accordance with relevant laws are complied with.

3. Sharing of Personal Information

3.1 Sharing Personal Information with Third Parties

The Company may share personal information with third parties when necessary to operate, provide, improve, and market the service. In principle, the Company does not share users' personal information with third parties. However, exceptions are made in the following cases:

  • Service providers: Sharing with website and application development companies, data storage and backup service providers, customer support service providers, business analysis companies, etc.
  • Use of partner services: Providing the minimum necessary information (mobile phone number, transaction history, etc.) to partner companies (coupon delivery agencies, payment processors, etc.) for voucher/coupon issuance and use.
  • Advertising service providers: Sharing advertising identifiers and usage data with advertising platforms such as Google AdMob and Offerwall networks.
  • Legal obligations: Providing information to investigative agencies in accordance with laws and procedures for investigation purposes, or to anti-money laundering (AML) and customer verification (KYC) service providers.
  • Consent-based: When the user has explicitly consented in advance to the provision to third parties.

3.2 Obligations of Third Parties

All third parties receiving personal information must comply with the Vietnam Personal Data Protection Law and this Policy, and may not use or process personal information for purposes other than the service provision purposes specified by the Company. In addition, third parties must implement and maintain reasonable technical and administrative security measures to protect the confidentiality, integrity, and availability of personal information.

3.3 Management and Supervision of Third Parties

The Company takes reasonable measures to ensure that all third-party service providers provide personal information protection at a level higher than that specified in this Policy. The Company manages and supervises third parties through contracts to ensure compliance with personal information protection laws. If a third party is found to fail to meet these requirements or violate them, the Company may suspend sharing of personal information with that third party or take appropriate measures to prevent non-compliant acts.

3.4 Sharing of Aggregated or Anonymized Data

The Company may share aggregated data or anonymized data that cannot identify individuals with third parties for the purposes of service improvement, research, analysis, and profiling. The Company may share statistical data processed in a form that cannot identify individuals (e.g., statistics on interests by age group, check-in frequency by region) with partners such as advertisers and research institutions. This is processed as statistical data, not personal information, and is used only in a form where personal identification is impossible.

3.5 Precautions When Using Third-Party Software

When users use third-party software (e.g., payment apps, external advertising platforms) within the service, the relevant third-party providers may have access to the user's personal information. Third-party advertising SDKs such as Google AdMob and Offerwall networks may be included in the service. These third parties may independently collect user information according to their own privacy policies. Their personal information processing policies and procedures are outside the Company's control and this Policy does not apply to them. Therefore, users are advised to review the privacy policies of the relevant providers before using third-party software.

The service may contain links to third-party websites not controlled by the Company. When moving to other sites through external website or advertising links included in the service, the privacy policy of the relevant site applies. The Company strongly recommends that users check the relevant policy before submitting information to third-party websites and assumes no responsibility for the personal information processing practices of external sites.

In emergency situations or legal requirements stipulated by Vietnamese law, such as national security, national defense, or public safety, the Company may provide personal information to relevant authorities.

3.8 Disclaimer of Responsibility for P2P Transactions

The Company is not responsible for personal information leakage or financial damage arising from direct transactions (P2P) or point trading between users outside of official functions.

4. Storage of Personal Information

4.1 Storage Location of Personal Information

The Company stores users' personal information in encrypted databases to ensure safe protection. Data of Vietnam users is managed in compliance with relevant laws (Cybersecurity Law and data localization regulations, etc.).

4.2 Retention Period of Personal Information

In principle, the Company destroys the information without delay after the purpose of collection and use of personal information is achieved. However, the following information is retained for the specified periods:

  • Upon membership withdrawal: Device identification information and withdrawal history are retained for 6 months from the withdrawal date to prevent fraudulent use.
  • Retention under relevant laws: Information is retained for the period stipulated by law when required under regulations such as the Act on Consumer Protection in Electronic Commerce (e.g., 3 years for records related to contracts or withdrawals, 5 years for payment and supply of goods).
  • Inactive accounts: Accounts with no service usage records for more than 1 year may be converted to dormant status or deleted, with prior notice provided.

5. International Transfer of Personal Information

5.1 Scope of Personal Information Transfer

For global service operation, the Company may transmit or store users' personal information outside Vietnam (e.g., cloud servers located in Singapore, Korea, etc.). The information transmitted is limited to the minimum data essential for service operation.

5.2 Protection Measures for International Transfer

In accordance with Article 25 of the Vietnam Personal Data Protection Law (PDPL) and Decree 356/2025/ND-CP, the Company takes the following measures when transferring personal information abroad:

  • Cross-Border Transfer Impact Assessment (CTIA): Assess the impact of cross-border personal information transfer on users' rights and submit the assessment report to the Ministry of Public Security (MPS) of Vietnam.
  • Conclusion of Protection Contracts: Conclude contracts with overseas data recipients that mandate personal information protection at a level equivalent to Vietnamese law.
  • User Consent: Obtain separate explicit consent from users for cross-border transfer.

6. User Rights

6.1 Rights Held by Users

In accordance with the Vietnam PDPL, users have the following rights regarding their personal information:

  • Right to receive information (processing history, etc.)
  • Right to consent or not consent to data processing
  • Right to withdraw consent for data processing
  • Right to access, correct, or request correction of their data
  • Right to request deletion of data (right to be forgotten)
  • Right to restrict data processing
  • Right to object to data processing
  • Right to file complaints, reports, and lawsuits

6.2 Direct Modification of Personal Information

Users can view and modify their basic information at any time through the 'My Page' or 'Settings' menu in the app.

6.3 Opt-out of Marketing Materials

Users can refuse to receive promotional information by changing push notification and email reception settings in the app settings menu. However, essential service-related notices cannot be refused.

6.4 Identity Verification Procedure

When users wish to exercise their rights regarding personal information (access, deletion, etc.), the Company may request a copy of ID or identity verification procedure to confirm that the requester is the data subject.

6.5 Request Processing and Fees

The Company processes legitimate requests to exercise user rights without delay. In principle, no fees are charged, but reasonable fees may be charged for repetitive or excessive requests.

6.6 Response Period for Requests

The Company takes measures or notifies the processing plan within the period stipulated by law (usually 72 hours or the period specified by law) from the date of receiving the user's request.

7. Policy Changes

7.1 Amendment of Privacy Policy

The Company may amend this Privacy Policy in accordance with changes in laws or services. When the policy is changed, it will be announced through in-app notices or email at least 7 days before the effective date (30 days in case of significant changes). If a member does not agree to the amended policy, they may request membership withdrawal. Continued use of the service will be deemed as consent to the amended policy.

8. Vietnam Users - PDPL Compliance

8.1 PDPL Application and International Transfer

The Company strictly complies with the Personal Data Protection Law (Law No. 91/2025/QH15) and related decrees (Decree 356/2025/ND-CP) to protect the rights of data subjects in Vietnam. International transfers follow the procedures specified in Section 5.

The Company processes personal information based on the following legal grounds:

  • Consent: Explicit and voluntary consent of the data subject.
  • Contract performance: Service provision and settlement in accordance with the Terms of Service.
  • Compliance with legal obligations: Compliance with tax laws, consumer protection laws, etc.
  • Legitimate interests: Pursuit of the Company's legitimate interests such as service security maintenance, prevention of misconduct, and service improvement (except where the data subject's rights take precedence).

Membership Registration and Account Management — Email, Password — Contract Performance, Consent

Point/GP Accumulation and Management — Ad Viewing Records, Device Information — Contract Performance, Legitimate Interests

Check-in and Location-based Missions — Location Information (Sensitive Information) — Separate Explicit Consent

Big Data Collection and Analysis — Answers on Hobbies, Habits, Lifestyle Patterns — Consent

Voucher Exchange and Delivery — Phone Number, Transaction History — Contract Performance

8.4 User Rights under Vietnamese Law

Vietnam users may exercise the following rights under the PDPL:

  • To request access, correction, update, or deletion of personal information, users may contact admin@adtok.ai or submit a written request to the Company.
  • Users may object to or restrict processing of personal information and may request data portability in cases based on legitimate interests. However, processing may not be stopped if there are legitimate reasons such as fulfilling legal obligations.
  • Where personal information is processed based on consent, consent may be withdrawn at any time (withdrawal is processed as membership withdrawal).
  • Users may refuse to receive marketing communications.

These rights apply to users whose rights are protected under Vietnamese law.

8.5 Role of the Data Controller

The Company operating ADtok acts as the 'Data Controller' for personal information related to the service and is responsible for all personal information except that processed by third-party service providers. The Company performs the roles of 'Personal Data Controller' and 'Personal Data Processor'. The Company designates a Data Protection Officer (DPO) to manage data processing responsibilities. Users may contact the Company using the contact information below if they have any concerns regarding this Policy or personal information processing.

9. Contact Information

For inquiries related to personal information processing, complaint handling, rights exercise, or questions regarding this Policy, please contact us at the following:

  • Company Name: ADtok – LHJ Co., Ltd
  • Address: 29, Cheongsu-ro 40-gil, Suseong-gu, Daegu, Republic of Korea
  • Data Protection Officer: Edward Lee
  • Email: admin@adtok.ai

This Privacy Policy takes effect from February 1, 2026 and may be changed in accordance with amendments to the Vietnam Personal Data Protection Law (PDPL - Law No. 91/2025/QH15) and related regulations.

Join our community

Zalo Community

Zalo Community

Join the AdTok community.

Facebook fanpage

Facebook fanpage

Get the latest news from Adtok.

;

Get the latest news from Adtok

Facebook fanpage

Join the Adtok community

ZALO community

Copyright © 2026 Adtok | ADTOK Co., Ltd.