GenNova Dev GenNova Dev
  • About
  • From Haravan

    • Haravan.com → MeInvoice
    View all solutions →
  • Pricing
  • Privacy
  • Refund
  • Contact
VI EN
Sign in Start free
Home About

Integration solutions

From Haravan

Haravan.com → MeInvoice View all solutions →
Pricing Privacy policy Refund policy Contact
Choose language
VI EN
Light / dark theme
Sign in →

Legal

Privacy policy

GenNova Dev Co., Ltd. is committed to protecting the privacy and personal data of customers under the Law on Personal Data Protection No. 91/2025/QH15, Decree 356/2025/ND-CP (effective 01/01/2026, replacing Decree 13/2023/ND-CP), and other applicable Vietnamese law. Last updated: 16/09/2026. See also the Community guidelines and Vulnerable customers policy.

This policy applies to websites, applications and services operated by GenNova Dev Co., Ltd. (“GenNova Dev”, “we”). Terms and duties follow the Law on Personal Data Protection No. 91/2025/QH15 and Decree 356/2025/ND-CP (effective 01/01/2026). Decree 13/2023/ND-CP expired on the same date. Consent or agreements validly given under Decree 13 before 01/01/2026 remain valid; re-consent is not required (Article 39 of Law 91/2025).

  • Data subject: an individual identified or identifiable through data (e.g. account registrant, contact person).
  • Personal data: information linked to a specific person or that helps identify that person.
  • Basic personal data (Article 3 of Decree 356): includes name, date of birth, gender, contact address, nationality, image, phone, ID/passport numbers (if you provide them), digital account information, and other identifying information that is not sensitive. For GenNova Dev, typical basic data are name, email, contact phone and login-account information per Section 2.
  • Sensitive personal data (Article 4 of Decree 356): includes (non-exhaustive) racial/ethnic origin; political or religious views; private life; health; biometrics and genetics; sexual life/orientation; law-enforcement crime data; location via positioning services; e-ID account login and password; images of ID cards; bank/card data and financial transaction history; behavioral tracking of online-service use; and other types the law requires to be kept strictly confidential. GenNova Dev does not intentionally collect religion, health, biometrics, GPS location, ID-card images or e-ID passwords. Technical logs (IP, endpoint, access time) are used for security and operations under restricted access, not for advertising profiles. Payment/invoice records (transaction ID, amount) are kept for accounting duties; we do not store card numbers.

Data processing roles. When business customers configure sync between systems, the business customer is usually the controller of their business data (e.g. orders, end customers they manage). GenNova Dev processes data per customer instructions and configuration as a technical platform provider (processor / controller-and-processor depending on scope) — see Section 5 on API integration.

Legal bases (one or more may apply): performing the service contract; consent where the law requires it (verifiable methods under Article 6 of Decree 356 — no default-on consent); legal obligations (accounting, tax, retention); legitimate interests (security, fraud prevention) within lawful limits; and processing without consent where Article 19 of Law 91/2025 applies.

Consent. We retain consent records (who, when, what) when you register, acknowledge the policy notice, or enable features. We do not use default-on consent. Withdrawal does not affect the lawfulness of prior processing.

Cross-border transfers (Article 17 of Decree 356 / Article 20 of Law 91) include storing data collected in Vietnam on servers or cloud services abroad, transferring to a foreign recipient, or further processing on a platform outside Vietnam. Core business data is stored and processed on servers in Vietnam. Some technical data (OTP email, monitoring, CDN) may pass through international providers. We apply TLS encryption, contractual data-protection terms and access control, and prepare/submit a cross-border transfer impact assessment where required (typically within 60 days of starting the transfer). Enterprise contracts may detail infrastructure in annexes.

Artificial intelligence. When you enable AI features (e.g. content/report assistance), data is processed automatically on infrastructure we control or on bound contractors. Inferences that can identify a person are protected as personal data. You/your organization may opt out of non-essential AI features. We do not use your content to train public advertising models.

Your end customers. If personal data belongs to your employees or customers, notice and consent (where required) is usually your responsibility. GenNova Dev supports technical aspects per Sections 7 and 9.

While providing data sync services, GenNova Dev collects:

a) Personal identification

  • Name, email when registering an account or requesting consulting.
  • Company name, tax ID, address when subscribing to paid plans.
  • Contact phone (if voluntarily provided).

b) Technical and session information

  • IP address, browser type, OS and access times.
  • Login session cookies and auth tokens (JWT / session token).
  • API access logs: call time, endpoint, response code — for debug and performance monitoring.

c) Integration data from third-party platforms

  • API credentials: access tokens, API keys, client secrets for platforms you authorize (Haravan, Nhanh.vn, MISA AMIS, MeInvoice…). Protected by business access controls, not shown publicly, transmitted over HTTPS. Encryption at rest (if any) depends on deployment configuration.
  • Synced business data (orders, products, customers, inventory, invoices): stored only temporarily in processing buffers, not long-term on GenNova Dev.

d) Payment information

  • GenNova Dev does not directly store card numbers, CVV or sensitive payment data. Payments are processed via third-party gateways complying with applicable security standards (e.g. PCI where applicable).
  • We retain transaction IDs, time and amount for reconciliation and receipts.

Collected information is used for:

  • Service delivery and operation: account authentication, API connections, executing sync flows per customer configuration.
  • Technical support and customer care: responding to support requests, debugging, sync status notifications, incident alerts by email.
  • Billing and invoices: recurring payments, receipts, renewal reminders.
  • Product improvement: aggregated, anonymized usage analysis to optimize performance and develop features.
  • Security and fraud prevention: detecting abnormal access, blocking brute-force, API rate limiting.
  • Legal compliance: retaining transaction records per Vietnamese law (minimum 5 years for financial records).

GenNova Dev does not use customer data for third-party advertising, does not sell data, and does not analyze customer business data beyond agreed service scope.

GenNova Dev applies technical and organizational safeguards consistent with Law 91/2025 and Decree 356/2025 (encryption, access control, monitoring — Articles 9 and 12):

a) Encryption and transmission

  • Public network traffic is protected by TLS (HTTPS).
  • Sensitive login and integration data is handled with account-based access control.
  • User login uses OTP via email (no static password in the default model). Codes expire and have attempt limits.
  • Cloud/email/CDN contracts require compliance with Vietnamese personal-data law, encryption in transit and (where the provider supports it) at rest, access control, and deletion/destruction on schedule.

b) Access control

  • Email OTP for login sessions.
  • Least privilege — each account accesses only its own API data.
  • Session tokens expire after inactivity.
  • Sensitive personal data (if any arises) has restricted access and access logs.

c) Infrastructure and monitoring

  • Firewalls and tight security groups; internal service ports are not published to the Internet.
  • Periodic database backups in a separate location.
  • Monitoring and alerts for abnormal access.
  • Technical logs retained per Section 8, then deleted.

d) Personal-data incidents (Article 28 of Decree 356)

When we detect a personal-data protection violation, we record the incident, mitigate harm, and:

  • Notify the specialized personal-data protection authority (Ministry of Public Security) using the prescribed form, covering the nature of the incident, data types/volume, contact point, possible consequences and measures taken.
  • Notify affected customers/data subjects within a reasonable time; for location or biometric incidents: notify data subjects within 72 hours of detection (Article 29). Incident records are kept at least 5 years after remediation where Article 29 applies.

e) Account safety

  • GenNova Dev staff never ask for OTP, passwords, API tokens or recovery codes via chat, phone, social media or unknown email.
  • Do not scan unknown QR codes, install unofficial remote-support software, or pay “activation fees” outside an official invoice.
  • Official channels: gennovadev.com and *.gennovadev.com, email @gennovadev.com. Report impersonation to info@gennovadev.com and see the Community guidelines.

As a data sync platform, GenNova Dev acts as a processor under customer instructions (Data Processor) between systems customers use. We commit to:

  • Minimum access scope: apps request only necessary permissions from third parties (Haravan, Nhanh.vn, MISA AMIS…).
  • No long-term business data storage: orders, products, inventory and customer data are processed in temporary memory/queues during sync, then removed. GenNova Dev does not build a warehouse from customer business data.
  • Sync logs: summary logs (order ID, status, time) kept up to 90 days for lookup and confirmation, then auto-deleted.
  • Account isolation: each account’s data in separate schemas, logically isolated.
  • Revoking access: customers may revoke API access on source platforms or delete connections on GenNova Dev; sync stops immediately.

Using GenNova Dev means the customer — as controller of data they put into sync flows (Data Controller in that relationship) — authorizes GenNova Dev to process business data within configured scope.

GenNova Dev does not sell, rent or share personal data for commercial purposes. Data is shared only when:

  • Technical service providers: cloud hosting, email delivery, monitoring — under data protection contracts, processing only per GenNova Dev instructions.
  • Mandatory legal requests: from competent authorities per lawful procedure.
  • Protecting legitimate interests: preventing fraud, terms violations, or harm to other users.
  • Business transfer: merger, acquisition or asset sale — after notice and equivalent privacy commitments from the recipient.

Data sent to integrated platforms (Haravan, Nhanh.vn, MISA, etc.) is per customer configuration — GenNova Dev is a technical intermediary, not an independent sharer.

Data subjects have the rights in Article 4.1 of Law 91/2025/QH15 (time limits in Article 5 of Decree 356/2025), within the law and except where the law allows refusal or processing without consent:

  • To be informed about processing — through this policy and in-product information.
  • To consent, refuse or withdraw consent (withdrawal does not affect prior lawful processing).
  • To view and correct inaccurate personal data.
  • To request provision, deletion or restriction of processing, and to object to processing for specific purposes (e.g. optional statistics, marketing email — we do not use data for third-party advertising).
  • To receive a copy of personal data in common formats (JSON/CSV) where technically feasible (portability).
  • To complain, denounce, sue and claim damages under Vietnamese law.
  • To request protective measures for their personal data.

Full removal of integration configuration per mapping/shop follows Section 9 when eligible.

Handling time limits (Article 5 of Decree 356; from a procedurally valid request; initial acknowledgement within 2 working days):

  • Withdraw consent, restrict or object: complete within 15 days (20 days if a processor/third party must be instructed); one extension of up to 15 days with reasons.
  • View, correct or provide data: complete within 10 days (15 days if a third party is involved); one extension of up to 10 days.
  • Deletion: complete within 20 days (30 days if a third party is involved); one extension of up to 20 days. Data the law requires us to keep (e.g. 5-year financial records) is retained for that purpose only.
  • Protective-measure requests: complete within 15 days; one extension of up to 15 days.

Send requests to info@gennovadev.com with subject "[Data rights request] — [Name] — [Account email]". We may verify identity. Personal-data protection contact: the same email.

We retain data only as long as necessary:

  • Account data (email, name, company info): while the account is active and up to 2 years after deletion (for dispute resolution).
  • API credentials: while the connection is valid; deleted immediately on disconnect.
  • Sync logs: up to 90 days, then auto-deleted.
  • Payment and invoice records: 5 years per Vietnamese accounting law.
  • System access logs: up to 30 days for security monitoring, with restricted access.
  • Reviews and feedback: indefinitely unless deletion requested — to improve service.

On an account-deletion request, personal data is removed (except legally required retention) within the time limits in Section 7 (typically 20 days; up to 30 days if a third party is involved). Integration data removal per shop/mapping follows Section 9.

GenNova Dev applies a data removal policy for each connection configuration (mapping — a Haravan shop, Nhanh store or AMIS/MeInvoice integration). This supplements Section 7 (deletion rights) and Section 8 (retention).

9.1. When removal applies

  • Customer request: formal request via info@gennovadev.com or verified Super Admin process.
  • Non-renewal: all licenses for subscribed sync topics expired and the latest expiry date was at least 90 days ago with no renewal. GenNova Dev may plan removal after notice if a valid contact email exists.

We do not remove a mapping while any license remains active for any sync topic, unless the customer explicitly requests early termination and accepts consequences.

9.2. Scope of removal

  • External disconnect: cancel Haravan webhooks, revoke OAuth/API tokens stored for that mapping.
  • Configuration and catalogs: sync settings, branch/warehouse mapping, cached AMIS/MeInvoice/Nhanh catalogs, callbacks and reports tied to mapping_id.
  • Logs: sync and webhook logs for the mapping/shop within remaining retention.
  • Shop cache: Haravan/Nhanh cache deleted only when no other mapping references the same shop ID.
  • Licenses and linked accounts: license records, email mapping config, internal permissions; unlink mapping_id from user accounts (full email account deletion only on separate request per Section 7).
  • Mapping record: delete the root mapping after the above steps.

Not removed: shared master location data; payment/invoice records (Section 8); audit snapshots of the removal process.

9.3. Process

  • Performed by Super Admin with multi-step confirmation and preview counts per data group.
  • Background task execution; completion time depends on data volume.
  • After completion, mapping no longer appears; sync and webhooks stop permanently.

9.4. Irreversible

Removal under this section is irreversible for deleted configuration and business data on GenNova Dev. Back up data on source platforms before requesting removal.

9.5. Contact

Removal requests: info@gennovadev.com — subject: [Data removal request] — [Shop name / mapping_id] — [Account email]. Initial acknowledgement within 2 working days; technical completion follows the deletion time limits in Section 7 (typically 20 days; up to 30 days if a third party is involved), except unusually large volumes (we will state reasons if we extend under Article 5 of Decree 356).

GenNova Dev uses:

  • Strictly necessary cookies: session login, CSRF token — required for security. Cannot be disabled.
  • Functional cookies: UI preferences (theme, font size), language.
  • Analytics cookies: aggregated, anonymized usage to improve the product.

We currently do not use third-party advertising cookies (Google Ads, Facebook Pixel, etc.). Analytics cookies, if any, are aggregated/anonymized; we do not default-on identifiable behavioral tracking. Technical security logs are processed under restricted access per Article 4 of Decree 356.

You may delete or block cookies in browser settings. Blocking necessary cookies will disrupt login and security.

By using GenNova Dev, customers agree to:

  • Account security: protect the email inbox receiving OTP and login sessions. One email links to one API connection database. Do not share accounts with unauthorized third parties.
  • Lawful use: service for lawful purposes only; no fraud, IP infringement, or violation of integrated platform terms.
  • Data responsibility: customers control business data in sync flows and ensure lawful processing including end-customer data where applicable.
  • Plans and payment: fees per chosen billing cycle. Payment delay over 7 days may suspend service. Price changes with 30 days notice.
  • Suspension and termination: we may suspend or terminate for terms violations, prolonged unpaid fees, authority requests, or maintenance/security. Post-termination data handled per Sections 8 and 9.
  • Operational liability limits: we provide the sync platform with reasonable commercial effort but are not liable for third-party API incidents (changes, downtime of Haravan, Nhanh.vn, MISA…). Force majeure handled per Section 12.

License. Within the subscribed plan and paid fees (if any), GenNova Dev grants a non-exclusive, non-transferable, revocable right to use the software/service via the provided interface. No sublicensing, resale or rental without written consent.

Restrictions. Customers must not: (i) use the service unlawfully; (ii) attempt unauthorized access, security breaches, overload or disruption; (iii) reverse engineer except where law permits; (iv) remove or alter copyright/trademark notices.

Intellectual property. UI, server code, architecture, trademarks and documentation belong to GenNova Dev or licensors. Customer configuration and business content remain the customer’s within legal limits.

Disclaimer and liability cap. To the extent permitted by law, GenNova Dev is not liable for indirect damages, lost profits, or data loss beyond reasonable control, or third-party events. Total cumulative liability per customer per calendar year shall not exceed total service fees actually paid to GenNova Dev in the twelve (12) months before the claim (or minimum as mandatory law requires for free/unpaid plans).

Force majeure. Events beyond reasonable control (natural disasters, war, global Internet/cloud outages, government action) may interrupt service; parties excused for delay during such events with mitigation efforts.

Governing law. These terms are governed by Vietnamese law. Disputes resolved by negotiation first; failing that, competent People's Court in Hanoi, Vietnam, unless mandatory law requires otherwise.

GenNova Dev may update this Privacy Policy to reflect operational, legal or product changes.

  • Non-material changes (clarifications, examples): effective upon posting with updated date at top.
  • Material changes (processing purposes, retention, new data types): notice to registered email at least 30 days before effective date. Customers may object or request account deletion during that period.

Continued use after the effective date constitutes acceptance. Prior versions available on request.

For questions, complaints or requests regarding this Privacy Policy and personal data, contact our personal-data protection point:

  • Company: GenNova Dev Co., Ltd.
  • Tax ID: 0111039570
  • Address: 4th Floor, Building No. 12-16 Doc Ngu Street, Ngoc Ha Ward, Hanoi, Vietnam
  • Privacy email: info@gennovadev.com
  • Initial response: within 2 working days; completion time limits in Section 7 (Article 5 of Decree 356/2025).

If you believe we processed your data improperly and the issue is unresolved, you may complain, denounce or sue under Vietnamese law, including to the specialized personal-data protection authority under the Ministry of Public Security or via the National Portal on Personal Data Protection.

GenNova Dev GenNova Dev Co., Ltd

Data synchronization services

GenNova Dev builds Gennova Platform — API connectivity and data sync between Haravan.com, MISA AMIS, MeInvoice, Nhanh.vn.vn and retail/accounting systems in Vietnam. Sync orders, products, inventory, customers and invoices per shop mapping configuration.

Company information

GENNOVA DEV COMPANY LIMITED

Mã số thuế
0111039570
Địa chỉ
4th Floor, Building No. 12-16 Doc Ngu Street, Ngoc Ha Ward, Hanoi, Vietnam
Email
info@gennovadev.com
Zalo
097 9578 197 · 096 2914 136
© GenNova Dev. All rights reserved. Gennova Platform — Enterprise data sync platform by GenNova Dev. Powered by Python · FastAPI · Jinja2 · Tailwind CSS · Celery · Redis · PostgreSQL
Thông báo
  • 🔔
    Chưa có thông báo nào
Thông báo