Policy
Privacy Policy
📅 Effective: 01 January 2025
🔄 Updated: 26 May 2026
🌐 Version: 2.0
Noi Bai International Airport (NBIA), operated by the Airports Corporation of Vietnam (ACV), is committed to protecting the privacy and personal information of users who access and use the website noibaiairport.vn.
This policy describes how we collect, use, store, and protect your personal data in accordance with Vietnamese law, including Decree No. 13/2023/ND-CP on Personal Data Protection.
By continuing to use the website, you confirm that you have read, understood, and agreed to this policy.
We may collect the following types of information when you use the website:
- Identity data: Full name, email address, phone number — when you contact us, submit feedback, or subscribe to notifications.
- Technical data: IP address, browser type, operating system, pages visited, timestamps, and session duration.
- Behavioral data: Flight search history, schedule inquiries, and pages viewed during your visit.
- Cookies and session data: See our Cookie Policy for full details.
We do not collect sensitive data such as financial records, health information, or passport numbers through this website.
Information is collected and used for the following specific purposes:
- Providing and improving airport information services for passengers and partners.
- Responding to inquiries, support requests, and complaints from users.
- Analyzing website traffic and user behavior to enhance the user experience.
- Sending service alerts, incident notifications, or important updates (only if you have subscribed).
- Complying with legal obligations under applicable Vietnamese regulations.
- Protecting the security and integrity of NBIA and ACV information systems.
We do not sell or rent your personal information to any third party for commercial purposes. We share data only in the following circumstances:
- Government authorities: When required by a lawful request from a competent authority under applicable law.
- Technical service partners: Hosting, analytics, and security providers, bound by strict confidentiality agreements.
- Within ACV: Only with departments directly involved in the stated processing purpose.
- With your consent: Where you have given explicit prior consent for a specific purpose.
We implement appropriate technical and organizational measures consistent with industry standards to protect your personal data:
- End-to-end HTTPS/TLS 1.3 encryption across the entire website.
- Internal access control based on the Principle of Least Privilege.
- Regular security audits and penetration testing by qualified professionals.
- Automated data backups and a documented Disaster Recovery Plan.
- Security awareness training for all personnel who handle personal data.
No system can guarantee absolute security. In the event of a data breach, we will notify affected users within 72 hours in accordance with applicable regulations.
Under Decree No. 13/2023/ND-CP, you have the following rights regarding your personal data:
- Right to know: Be informed about how your data is being processed.
- Right to consent / withdraw consent: Grant or revoke consent for data processing at any time.
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your data (except where retention is legally required).
- Right to restriction: Request a temporary suspension of processing while a complaint is reviewed.
- Right to object: Opt out of processing your data for direct marketing purposes.
To exercise any of these rights, please contact us using the details in Section 8. We will respond within 15 working days.
We retain personal data only for as long as necessary to fulfil the stated purposes, or as required by law:
- Technical access logs: Maximum 12 months.
- Contact and feedback data: Maximum 3 years from the last interaction.
- Notification subscription data: Until you unsubscribe.
- Legally mandated data: As specified by applicable Vietnamese law.
After the retention period expires, data is securely deleted or irreversibly anonymized.
If you have questions about this policy, wish to exercise your data rights, or need to report a security incident, please contact: