Legal
Privacy and Data Protection Policy
Effective from: 01 June 2026
This policy explains how we collect, use, store, share, transfer, and protect personal data when you visit the Duall Master website or use Duall Master Cloud Service. We are committed to processing personal data for specific purposes, within proper scope, transparently, and in accordance with relevant data protection rules, including Vietnam's 2025 Personal Data Protection Law (Law No. 91/2025/QH15, effective from 01 January 2026), Decree 13/2023/ND-CP to the extent still applicable, the Republic of Korea Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR) where applicable, and other relevant laws and regulations.
This document has two parts: Part A applies to visitors to the Duall Master website; Part B applies to users and customers of Duall Master Cloud Service. This policy does not replace the service contract, data processing agreement, or separate notice that a customer/building operator must provide to its employees, residents, visitors, or end users.
Part A — Duall Master Website
1. Who we are
This website introduces Duall Master, a building security and operations platform developed by Duali. For data collected directly through this website, the data controller is:
Duali Inc
1-309, 306 Sinwon-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do 16675, Republic of Korea
Email: sales@duali.com
Duali Inc is headquartered in Suwon, Gyeonggi-do, South Korea, and has an office in Hanoi, Vietnam, serving customers in Korea, Vietnam, and Southeast Asia.
2. Website data scope
Part A applies to personal data of website visitors — for example, people who submit an enquiry through our contact form or whose visit is measured by analytics tools. For website data, Duali acts as the data controller.
3. What we collect on the website
Contact form submissions. When you contact us through the website, we collect the information you provide: your name, company, work email, phone number, country, the modules you are interested in, and your message.
Analytics data (only with your consent). If you accept the cookie banner, we use privacy-conscious analytics tools (Google Analytics 4 with IP anonymisation, and/or Plausible) to understand how visitors use the website. Analytics scripts are loaded only after you consent. We do not use advertising cookies or cross-site profile tracking.
Server and security logs. Our hosting and content-delivery provider records technical information such as IP address and request metadata to operate, secure, and protect the website against abuse.
4. Why we use website data
- To respond to your enquiry and follow up about Duall Master — on the basis of taking steps at your request before entering into a contract, and our legitimate interest in responding to sales and product enquiries.
- To measure and improve the website through analytics — on the basis of your voluntary, clear, and withdrawable consent; silence or non-response is not treated as consent.
- To secure and operate the website — on the basis of our legitimate interest in keeping the website available, stable, and protected against abuse.
- To comply with legal obligations — including keeping appropriate processing records, receiving data-subject requests, and handling security incidents as required by law.
5. Cookies
We use a small number of essential cookies for language preference and security, and — only with your clear consent — analytics cookies. You can refuse, withdraw, or change your cookie choice at any time; continued silence/non-response is not treated as consent. For details and to manage your choice, see our Cookie Policy.
6. Sharing website data
We do not sell your personal data. We share data only with service providers that help us operate the website, under appropriate data protection terms:
- Web3Forms — processes contact form submissions and delivers them to us.
- Google Analytics 4 and/or Plausible — website analytics, loaded only after you consent.
- Cloudflare Pages — website hosting and content delivery, including security logging.
Part B — Duall Master Cloud Service
7. Scope for the cloud service
Part B applies when your organisation uses Duall Master Cloud Service — a cloud software service for operating modules such as access control, visitor management, attendance, parking, video management, intercom, device monitoring, and operational logs.
In most deployments, the customer/building operator is the data controller because it decides the purposes and means of processing data relating to employees, residents, visitors, contractors, or end users. Duali acts as the data processor, providing infrastructure, software, security, technical support, and processing functions under its agreement with the customer.
If the service contract, Data Processing Agreement (DPA), or separate terms between Duali and the customer contain more specific provisions, those documents take precedence for the relevant service scope.
8. Categories of data that may be processed in the service
Depending on the configuration and modules enabled by the customer, Duall Master Cloud Service may process the following categories of data:
- User and identity information: name, employee/resident/visitor code, company/department, job title, email, phone number, profile photo, permission groups, permitted access areas, and account status.
- Credentials and card information: card codes, QR codes, PINs, or device identifiers. Sensitive values are access-limited and, where practicable, are not written in raw form to application logs.
- Biometric or biometric-related data: fingerprint templates, face-recognition tokens, facial images, or recognition enrolment data, if the customer enables these functions. This is sensitive data and requires an appropriate lawful basis/consent from the data subject under applicable law.
- Access-control and operational events: entry/exit times, doors/gates/elevators, grant or denial results, event images if applicable, permission-change history, and audit logs.
- Visitor data: visitor name, contact information, visiting organisation, host, registration/entry/exit times, and photo or identity-document information if the customer configures collection.
- Attendance and parking data: working times, check-in/check-out history, licence plates, vehicle information, parking lanes/gates, and related events.
- Video, image, and intercom data: snapshots, video clips, event images, or intercom call logs if the relevant module is deployed.
- Technical data: IP address, device information, device identifiers, API logs, security logs, connection status, and error information used for operations, support, and system safety.
9. Processing purposes in the cloud service
Data in Duall Master Cloud Service is processed to:
- Provide, operate, and maintain the Duall Master modules subscribed to by the customer.
- Authenticate users, authorise access, synchronise permissions to devices, and record operational events.
- Support building security, visitor management, workforce/attendance management, parking operations, video/intercom, and related workflows.
- Keep audit logs, detect anomalies, investigate incidents, protect the system, and prevent unauthorised access.
- Provide technical support, troubleshoot errors, back up, restore, and improve service stability.
- Comply with legal obligations, valid requests from competent authorities, or contractual obligations to the customer.
10. Responsibilities of customers and end users
The customer is responsible for ensuring that the collection and use of data in Duall Master Cloud Service has an appropriate lawful basis, is limited to the notified purposes, and remains within the notified scope. Before entering data into the system, the customer should inform employees, residents, visitors, contractors, or end users about the types of data processed, processing purposes, controller/processor roles, the rights and obligations of data subjects, retention period, possible sharing/transfers, and contact channels for exercising rights.
For sensitive data such as biometrics, facial images, location data, or video, the customer must obtain separate consent or establish another valid lawful basis under the law of the country where the service is used. Consent must be voluntary, clear, purpose-specific, recorded/verifiable, and must not be bundled mandatorily with purposes that are not necessary for the service.
End users should first contact the organisation that manages their building or Duall Master account to exercise rights related to personal data, because that organisation is usually the data controller and has decision-making authority over data in the system.
11. How we protect service data
We apply appropriate technical and organisational measures to protect data in Duall Master Cloud Service, including:
- Role-based access control and the principle of least privilege.
- Customer/tenant data separation and internal access limits.
- Encryption or equivalent protection for data in transit and data at rest, appropriate to the deployment architecture.
- Audit logs for administrative actions and important security events.
- System monitoring, backup, restore, and incident-response processes.
- Maintaining personal-data processing impact records and cross-border transfer impact records to the extent required by law.
- Notifying and coordinating on personal-data breach incidents; when the law requires, notifying the competent authority within the legally required period, including the 72-hour marker for reportable incidents.
- Not buying or selling personal data; not using customer data for behavioural advertising.
No system is completely secure, but we work to maintain protection appropriate to the nature of the data and the risk of the service.
12. Sub-processors and international transfers
To provide the cloud service, we may use providers for cloud infrastructure, storage, security, monitoring, email notifications, or technical support. When using sub-processors, we apply appropriate data protection terms and limit processing to what is necessary to provide the service.
Data may be processed or accessed from countries different from where the customer or user resides. When personal data collected in Vietnam is transferred overseas, stored on systems located outside Vietnam, or processed on platforms located outside Vietnam, we and/or the customer will take appropriate measures under applicable law, including preparing/updating cross-border transfer impact records and submitting them to the competent authority within the legally required period where applicable.
13. Retention, deletion, and return of data
Data in Duall Master Cloud Service is retained according to the configuration, customer retention policy, operational needs, legal requirements, and contractual terms. We retain data only for a period appropriate to the processing purposes, unless law, contract, security needs, or audit-record requirements provide otherwise. Some data, such as audit logs or security logs, may need to be retained for a defined period to protect the system, investigate incidents, demonstrate compliance, or meet legal obligations.
When the service ends, data return, export, deletion, or temporary retention for backup/restore purposes will be handled according to the applicable service contract and DPA. Data in backups may be deleted according to the backup cycle and secure retention policy.
14. Data-subject rights
Under applicable law, including Vietnam's 2025 Personal Data Protection Law where applicable, you may have rights to be informed about personal-data processing; to consent or refuse consent; to withdraw consent; to access/view, correct, or request correction; to request provision, deletion, or restriction of processing; to object to processing; and to complain, denounce, bring legal action, or claim damages as provided by law. For data in Duall Master Cloud Service, requests should be sent to the organisation that manages your building or account. If Duali receives a request relating to data controlled by a customer, we will forward or support the customer in handling that request within the scope permitted by contract and law.
15. AI, analytics, and sensitive data
Some Duall Master deployments may use analytics, AI assistant features, big data, cloud computing, or third-party integrations. These features are enabled only according to configuration and agreement with the customer, must be limited to necessary purposes, and must apply authorisation, authentication, and security measures appropriate to the level of risk. We do not use customers' biometric, video, or operational data to train public AI models or for advertising unless there is a separate agreement and a valid lawful basis.
General Provisions
16. Children
This website and Duall Master Cloud Service are intended for organisations/business customers. We do not knowingly collect personal data directly from children through the website. If the system is deployed in a school, residential community, or other environment involving children, the customer/building operator must ensure appropriate notice, consent, and lawful basis before processing children's data. For children from 7 years old and above, in cases involving publication/disclosure of private-life information or personal secrets, the customer must ensure consent from the child and the legal representative where required by law.
17. Changes to this policy
We may update this policy from time to time. When we do, we will revise the effective/updated date above and, where necessary, provide additional notice.
18. Contact
If you have any questions about this policy or personal data, please contact sales@duali.com. For requests relating to data in Duall Master Cloud Service, please provide the organisation/customer name, system, or building involved so we can route the request appropriately.