Chính sách quyền riêng tư
1. Chúng tôi là ai
Mỹ Linh Agency Marketing (“chúng tôi”) vận hành ứng dụng web tại https://project.sozoplatform.com (“Dịch vụ”): không gian làm việc nội bộ của agency để lập kế hoạch marketing, quản lý nội dung, lịch hẹn, tệp tài liệu và số liệu hiệu quả, kèm cổng xem dành cho khách hàng. Dịch vụ chỉ dành cho nhân sự agency và khách hàng được mời; không mở đăng ký công khai.
Đơn vị kiểm soát dữ liệu: Mỹ Linh Agency Marketing — email liên hệ: himiilinh24603@gmail.com.
2. Dữ liệu chúng tôi thu thập
- Tài khoản: email đăng nhập (xác thực qua Cloudflare Zero Trust Access bằng mã một lần gửi tới email), họ tên, vai trò, ảnh đại diện (nếu bạn tải lên), thời điểm đăng nhập/hoạt động gần nhất, địa chỉ IP và trình duyệt trong nhật ký bảo mật.
- Dữ liệu dự án: kế hoạch, nội dung, công việc, KPI, bình luận, ghi chú đối soát, dữ liệu tài chính dự án (khoản thu, thanh toán, tài khoản nhận tiền do bạn nhập).
- Lịch hẹn: tiêu đề, thời gian, người tham dự (tên, email), đường dẫn họp, ghi chú/biên bản họp.
- Tệp: tài liệu, hình ảnh thiết kế và tệp kế hoạch bạn tải lên.
- Số liệu mạng xã hội: khi một kênh Facebook, Instagram hoặc TikTok được kết nối — tên/ID trang hoặc tài khoản, số liệu tổng hợp (lượt theo dõi, tiếp cận, tương tác…) và số liệu bài đăng.
- Dữ liệu Google: chỉ khi quản trị viên agency kết nối tài khoản Google của agency — xem mục 3.
- Biểu mẫu yêu cầu dữ liệu trên trang này: họ tên, email, loại yêu cầu, nội dung, quốc gia, trình duyệt và giá trị băm (SHA-256 có muối) của địa chỉ IP để chống spam — không lưu IP gốc.
Chúng tôi không dùng cookie quảng cáo và không bán dữ liệu cho ai. Trang này dùng Cloudflare Turnstile (captcha thân thiện quyền riêng tư) cho biểu mẫu, và cookie phiên đăng nhập của Cloudflare Access khi bạn đăng nhập ứng dụng.
Google Analytics 4 — chỉ trên trang giới thiệu công khai. Từ 11/10/2026, riêng trang giới thiệu tại sozoplatform.com có gắn Google Analytics 4 để chúng tôi biết trang nào được xem, khách đến từ đâu và nội dung nào hữu ích. Công cụ này đặt cookie của riêng nó (dạng _ga) và gửi số liệu truy cập cho Google. Nó KHÔNG chạy bên trong ứng dụng — mọi dữ liệu công việc, dự án và khách hàng của bạn không bao giờ đi qua Google Analytics. Muốn tắt, bạn có thể dùng tiện ích Google Analytics Opt-out hoặc chặn cookie của bên thứ ba trong trình duyệt; trang vẫn chạy bình thường.
3. Dữ liệu người dùng Google
Kết nối Google chỉ do quản trị viên agency thực hiện cho tài khoản Google của chính agency (không phải tài khoản cá nhân của khách hàng). Các quyền (scope) được yêu cầu và mục đích duy nhất:
| Quyền (scope) | Mục đích |
|---|---|
openid, email | Xác định tài khoản Google đã kết nối (hiển thị email tài khoản trong trang quản trị). |
https://www.googleapis.com/auth/calendar.events | Tạo, cập nhật, huỷ sự kiện lịch hẹn của dự án kèm đường dẫn Google Meet và mời người tham dự của dự án. |
https://www.googleapis.com/auth/calendar.readonly | Liệt kê lịch để quản trị viên chọn lịch đồng bộ, đọc lại thay đổi của các sự kiện do Dịch vụ tạo. |
https://www.googleapis.com/auth/gmail.send | Gửi email nhắc lịch hẹn và thông báo lịch hẹn từ tài khoản của agency tới người tham dự. Chỉ gửi — Dịch vụ không đọc, không liệt kê, không xoá hộp thư. |
https://www.googleapis.com/auth/drive.readonly (hoặc hẹp hơn: documents.readonly, spreadsheets.readonly) | Chỉ đọc tài liệu kế hoạch/biên bản họp (Google Docs, Sheets, Slides, tệp) mà agency chủ động chọn hoặc dán đường dẫn, để nhập kế hoạch và hỗ trợ lập kế hoạch bằng AI. Không sửa, không xoá, không duyệt toàn bộ Drive. |
- Dữ liệu Google không bị bán, không dùng cho quảng cáo (kể cả quảng cáo cá nhân hoá hay nhắm mục tiêu lại), không dùng để đánh giá tín dụng hay cho vay.
- Dữ liệu Google không được dùng để huấn luyện, phát triển hay cải thiện các mô hình AI/ML tổng quát — của chúng tôi hay của bên thứ ba.
- Không có người nào đọc dữ liệu Google, trừ khi: (a) bạn đồng ý rõ ràng cho từng nội dung cụ thể; (b) cần thiết cho mục đích bảo mật (điều tra lạm dụng, sự cố); (c) để tuân thủ pháp luật; hoặc (d) dữ liệu đã được tổng hợp, ẩn danh dùng cho vận hành nội bộ.
- Dữ liệu Google chỉ được chuyển giao khi cần để cung cấp hoặc cải thiện các tính năng hướng tới người dùng nêu trên (ví dụ: nội dung tài liệu được gửi tới trợ lý AI mà chính người dùng đã kết nối — mục 5), khi pháp luật yêu cầu, hoặc trong trường hợp sáp nhập/mua lại với cam kết bảo mật tương đương.
- Mã truy cập Google (refresh token) được mã hoá AES-256-GCM trước khi lưu. Nội dung tài liệu Drive chỉ được đọc khi cần và chỉ phần được trích xuất vào kế hoạch/bộ nhớ dự án mới được lưu.
- Thu hồi quyền: quản trị viên có thể bấm “Ngắt kết nối Google” trong Quản trị › Hệ thống › Google (Dịch vụ xoá token và gọi thu hồi token phía Google), hoặc thu hồi bất kỳ lúc nào tại myaccount.google.com/permissions.
4. Dữ liệu Meta (Facebook/Instagram) và TikTok
Khi agency kết nối một Trang Facebook, tài khoản Instagram doanh nghiệp hoặc tài khoản TikTok của khách hàng (với sự cho phép của chủ tài khoản), Dịch vụ chỉ đọc thông tin trang/tài khoản và số liệu hiệu quả (insights) để báo cáo KPI cho dự án tương ứng. Chúng tôi không đăng bài, không nhắn tin, không đọc tin nhắn riêng. Token được mã hoá AES-256-GCM. Xoá kênh trong Dịch vụ sẽ xoá token (bản lưu tạm trong thùng rác tự xoá hẳn sau 30 ngày); bạn cũng có thể gỡ ứng dụng trong cài đặt Facebook (Ứng dụng và trang web) hoặc TikTok. Việc sử dụng tuân theo Điều khoản nền tảng của Meta và TikTok.
5. Xử lý bằng AI
Người dùng có thể tự kết nối trợ lý AI (Claude của Anthropic, ChatGPT của OpenAI) với Dịch vụ qua giao thức MCP bằng quy trình ủy quyền OAuth do chính họ phê duyệt. Trợ lý AI chỉ truy cập dữ liệu dự án trong phạm vi quyền của người dùng đó và mọi thay đổi do AI đề xuất đều được ghi lại để người dùng xem xét, áp dụng hoặc hoàn tác. Khi bạn dùng trợ lý AI, dữ liệu được gửi tới nhà cung cấp AI theo tài khoản và điều khoản của chính bạn với nhà cung cấp đó. Dữ liệu người dùng Google chỉ được gửi tới AI khi cần cho tính năng bạn yêu cầu (ví dụ: tóm tắt một tài liệu kế hoạch bạn đã chọn) và vẫn chịu các giới hạn tại mục 3.
6. Chia sẻ dữ liệu
Chúng tôi không bán dữ liệu cá nhân. Dữ liệu chỉ được xử lý bởi các nhà cung cấp hạ tầng cần thiết để vận hành Dịch vụ: Cloudflare (máy chủ Workers, cơ sở dữ liệu D1, lưu trữ tệp R2, đăng nhập Zero Trust, Turnstile), Google (lịch, email, tài liệu khi được kết nối), Meta, TikTok (số liệu khi được kết nối) và nhà cung cấp AI do người dùng tự kết nối. Khách hàng chỉ thấy dữ liệu của dự án mình được mời. Chúng tôi có thể tiết lộ dữ liệu khi pháp luật bắt buộc.
7. Lưu trữ, bảo mật và thời hạn lưu
- Dữ liệu lưu trên Cloudflare D1 và R2 (mã hoá khi lưu trữ và khi truyền bằng HTTPS/TLS). Token của Google, Meta, TikTok được mã hoá thêm bằng AES-256-GCM.
- Truy cập được giới hạn qua Cloudflare Zero Trust Access, phân quyền theo vai trò và theo dự án, có nhật ký thao tác.
- Dữ liệu dự án được giữ trong suốt thời gian hợp tác và xoá hoặc trả lại theo yêu cầu khi kết thúc. Dữ liệu đã xoá nằm trong thùng rác 30 ngày rồi bị xoá hẳn.
- Bản sao lưu tự động hằng ngày được giữ 30 ngày (kèm bản tháng tối đa 12 tháng) để khôi phục sự cố; dữ liệu đã xoá sẽ biến mất khỏi bản sao lưu khi bản sao lưu hết hạn.
- Token Google bị xoá ngay khi ngắt kết nối. Yêu cầu gửi qua biểu mẫu được giữ tối đa 24 tháng để chứng minh việc xử lý.
8. Quyền của bạn và yêu cầu xoá dữ liệu
Bạn có quyền yêu cầu truy cập / nhận bản sao, sửa, xoá dữ liệu cá nhân, thu hồi quyền truy cập (Google, Meta, TikTok) và phản đối việc xử lý. Gửi yêu cầu bằng biểu mẫu bên dưới hoặc email himiilinh24603@gmail.com. Chúng tôi có thể xác minh danh tính qua email và sẽ phản hồi trong vòng 30 ngày.
Tự thu hồi quyền Google: myaccount.google.com/permissions. Quản trị viên agency: Quản trị › Hệ thống › Google › Ngắt kết nối; kênh mạng xã hội: Dự án › Số liệu › Kênh › Xoá kênh.
9. Trẻ em
Dịch vụ dành cho doanh nghiệp, không hướng tới và không cố ý thu thập dữ liệu của trẻ em dưới 13 tuổi (hoặc dưới 16 tuổi tại nơi luật yêu cầu).
10. Thay đổi chính sách
Chúng tôi có thể cập nhật chính sách này; ngày “Cập nhật lần cuối” ở đầu trang sẽ thay đổi. Thay đổi quan trọng liên quan tới dữ liệu Google sẽ được thông báo trong ứng dụng và xin lại sự đồng ý khi cần.
11. Liên hệ
Mỹ Linh Agency Marketing — himiilinh24603@gmail.com
Privacy Policy (English)
1. Who we are
Mỹ Linh Agency Marketing (“we”) operates the web application at https://project.sozoplatform.com (the “Service”): an internal agency workspace for marketing planning, content, meetings, files and performance reporting, with a read-only portal for invited clients. Access is by invitation only. Data controller contact: himiilinh24603@gmail.com.
2. Data we collect
- Account: sign-in email (authenticated by Cloudflare Zero Trust Access one-time codes), name, role, optional avatar, last sign-in/activity time, IP address and browser in security logs.
- Project data: plans, content items, tasks, KPIs, comments, reconciliation notes, project finance records you enter.
- Meetings: title, time, attendees (name, email), meeting link, notes/minutes.
- Files: documents, design images and plan files you upload.
- Social metrics: when a Facebook, Instagram or TikTok account is connected — page/account name and ID, aggregate insights and post metrics.
- Google user data: only when an agency administrator connects the agency’s Google account — see section 3.
- Data request form on this page: name, email, request type, message, country, browser and a salted SHA-256 hash of the IP address for abuse prevention (the raw IP is not stored).
We use no advertising cookies and never sell data. This page uses Cloudflare Turnstile for the form, and the Cloudflare Access session cookie once you sign in to the app.
Google Analytics 4 — public marketing page only. Since 11 October 2026 the public marketing page at sozoplatform.com carries Google Analytics 4 so we can see which pages are read, where visitors come from and which content helps. It sets its own cookies (the _ga family) and sends visit statistics to Google. It does NOT run inside the application — your work, project and client data never passes through Google Analytics. To opt out, use the Google Analytics Opt-out add-on or block third-party cookies; the page keeps working.
3. Google user data
Google is connected only by an agency administrator, for the agency’s own Google account. Requested scopes and their sole purposes:
| Scope | Purpose |
|---|---|
openid, email | Identify the connected Google account (its email is shown on the admin page). |
https://www.googleapis.com/auth/calendar.events | Create, update and cancel project meeting events with Google Meet links and invite the project’s attendees. |
https://www.googleapis.com/auth/calendar.readonly | List calendars so the administrator can choose which one to sync; read back changes to events the Service created. |
https://www.googleapis.com/auth/gmail.send | Send meeting reminder and meeting notification emails from the agency account to attendees. Send only — the Service never reads, lists or deletes mail. |
https://www.googleapis.com/auth/drive.readonly (or the narrower documents.readonly, spreadsheets.readonly) | Read only the plan and meeting documents (Google Docs, Sheets, Slides, files) that the agency explicitly selects or links, to import plans and support AI-assisted planning. No edits, no deletion, no browsing of the whole Drive. |
- Google user data is never sold, never used for advertising (including personalized or retargeted ads), and never used to determine creditworthiness or for lending.
- Google user data is not used to develop, improve or train generalized AI and/or ML models, ours or anyone else’s.
- No human reads Google user data unless (a) we have your affirmative consent for specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations.
- Google user data is transferred only as necessary to provide or improve the user-facing features above (for example, document text sent to the AI assistant the user connected — section 5), to comply with law, or as part of a merger or acquisition with equivalent protections.
- Google refresh tokens are encrypted with AES-256-GCM before storage. Drive content is fetched on demand; only the extracted parts that users save into a plan or project memory are stored.
- Revoking access: an administrator can click “Disconnect Google” in Admin › System (Hệ thống) › Google (the Service deletes the tokens and revokes them at Google), or anyone can revoke access at any time at myaccount.google.com/permissions.
4. Meta (Facebook/Instagram) and TikTok data
When the agency connects a client’s Facebook Page, Instagram business account or TikTok account (with the account owner’s permission), the Service only reads page/account information and insights to report KPIs for that project. We do not post, message, or read private messages. Tokens are encrypted with AES-256-GCM and deleted when the channel is removed (the temporary trash copy is purged after 30 days); you may also remove the app in your Facebook “Apps and Websites” or TikTok settings. Use is subject to the Meta and TikTok platform terms.
5. AI processing
Users may connect their own AI assistant (Anthropic Claude, OpenAI ChatGPT) to the Service via MCP using an OAuth authorization they approve. The assistant can only access project data within that user’s permissions, acting on that user’s authorization, and every AI-proposed change is recorded for the user to review, apply or revert. Data sent to an AI provider is processed under your own account and terms with that provider. Google user data is sent to an AI assistant only when needed for a feature you request (e.g., summarizing a plan document you selected) and remains subject to section 3.
6. Sharing
We do not sell personal data. Data is processed only by the providers needed to run the Service: Cloudflare (Workers hosting, D1 database, R2 file storage, Zero Trust sign-in, Turnstile), Google, Meta and TikTok (when connected) and the AI provider a user connects. Clients see only the projects they are invited to. We may disclose data where required by law.
7. Storage, security and retention
- Data is stored in Cloudflare D1 and R2, encrypted at rest and in transit (HTTPS/TLS); third-party tokens are additionally encrypted with AES-256-GCM.
- Access is restricted by Cloudflare Zero Trust Access and role/project permissions, with audit logs.
- Project data is kept for the duration of the engagement and deleted or returned on request afterwards. Deleted items stay in the trash for 30 days, then are permanently removed.
- Daily backups are kept for 30 days (plus monthly copies for up to 12 months) for disaster recovery; deleted data disappears from backups as they expire.
- Google tokens are deleted immediately on disconnect. Data requests submitted through the form are kept for up to 24 months as a record of handling.
8. Your rights and data deletion
You may request access/a copy, correction or deletion of your personal data, revoke access (Google, Meta, TikTok) and object to processing. Use the form below or email himiilinh24603@gmail.com. We may verify your identity by email and will respond within 30 days.
9. Children
The Service is a business tool; it is not directed to, and we do not knowingly collect data from, children under 13 (or under 16 where required by law).
10. Changes
We may update this policy and will change the “Last updated” date above. Material changes affecting Google user data will be announced in the app and consent will be requested again where required.
11. Contact
Mỹ Linh Agency Marketing — himiilinh24603@gmail.com
Gửi yêu cầu về dữ liệu · Data request
Xoá, truy cập, sửa dữ liệu hoặc thu hồi quyền. Chúng tôi phản hồi qua email trong vòng 30 ngày. / Deletion, access, correction or revocation requests — we reply by email within 30 days.