PERSONAL DATA PROTECTION POLICY

Orion Food Vina Co., Ltd. and its branches (collectively, the “Company”) respect privacy and are committed to protecting the Personal Data of customers, consumers, employees, candidates, suppliers, partners and other relevant individuals in accordance with Vietnamese law.

This Personal Data Protection Policy (the “Policy”) governs the Company’s collection, processing, use, storage, sharing, transfer and protection of Personal Data in connection with the Company’s manufacturing, business, distribution and supply of food products, employee management, recruitment, relationships with customers, suppliers and partners, and other lawful activities of the Company.

This Policy is established and applied in accordance with the Law on Personal Data Protection No. 91/2025/QH15, its implementing guidance and other relevant laws and regulations as amended, supplemented or replaced from time to time.

  1. DEFINITIONS AND INTERPRETATION

In this Policy, the following terms shall have the meanings set out below:

(i) “Personal Data” means digital data or information in another form that identifies or helps identify a specific individual, including Basic Personal Data and Sensitive Personal Data. Personal Data that has been de-identified is no longer Personal Data;

(ii) “Basic Personal Data” means Personal Data reflecting common personal and biographical information regularly used in transactions and social relationships, falling within the list issued by the Government;

(iii) “Sensitive Personal Data” means Personal Data associated with an individual’s privacy which, if infringed, may directly affect the lawful rights and interests of an agency, organization or individual, and which falls within the list issued by the Government;

(iv) “Personal Data Protection” means the use by agencies, organizations and individuals of personnel, means and measures to prevent and combat acts infringing Personal Data;

(v) “Data Subject” means the individual to whom the Personal Data relates;

(vi) “Processing of Personal Data” means any activity that affects Personal Data, including one or more activities such as collection, analysis, aggregation, encryption, decryption, modification, deletion, destruction, de-identification, provision, disclosure, transfer of Personal Data and other activities affecting Personal Data;

(vii) “Personal Data Controller” means an agency, organization or individual that determines the purposes and means of processing Personal Data;

(viii) “Personal Data Processor” means an agency, organization or individual that processes Personal Data at the request of the Personal Data Controller or the Personal Data Controller and Processor under a contract;

(ix) “Personal Data Controller and Processor” means an agency, organization or individual that determines the purposes and means of processing and directly processes Personal Data;

(x) “Third Party” means an organization or individual other than the Data Subject, Personal Data Controller, Personal Data Controller and Processor, and Personal Data Processor that participates in the processing of Personal Data in accordance with law;

(xi) “De-identification of Personal Data” means the process of changing or deleting information to create new data that cannot identify or help identify a specific individual;

(xii) “Personal Data Processing Impact Assessment” means the analysis and assessment of risks that may arise during the processing of Personal Data in order to apply measures to mitigate risks and protect Personal Data;

(xiii) “Company” means Orion Food Vina Co., Ltd. and its branches, including its units, production sites, offices and other affiliated units lawfully established and operating from time to time.

  1. SCOPE AND APPLICABILITY

This Policy applies to the Company’s collection and processing of Personal Data in connection with its manufacturing, business, distribution and supply of food products, employee management, recruitment, and management of customers, consumers, suppliers and partners, as well as other lawful activities of the Company.

This Policy applies to the Personal Data of (i) customers and consumers; (ii) employees, probationary employees and job applicants; (iii) suppliers, partners, distributors and personnel of such organizations; (iv) visitors coming to work at, visit or contact the Company’s offices, factories and facilities; (v) contact persons of customers, suppliers and partners; (vi) participants in the Company’s promotions, customer care programs, surveys, events or communications activities; (vii) individuals related to the Company’s manufacturing, business or other lawful activities; and (viii) other individuals whose Personal Data is lawfully collected and processed by the Company.

Where an individual provides the Company with Personal Data of another person, such individual shall be responsible for ensuring that there is an appropriate legal basis for providing such Personal Data to the Company and permitting the Company to process such Personal Data in accordance with law.

  1. TYPES OF PERSONAL DATA PROCESSED

Depending on the relationship, activity and purpose of processing, the Company may collect and process different types of Personal Data.

Basic Personal Data means Personal Data reflecting common personal and biographical information regularly used in transactions and social relationships, falling within the list issued by the Government, including: (i) surname, middle name, given name at birth and other names (if any); (ii) date, month and year of birth; date, month and year of death or declaration of disappearance; (iii) gender; (iv) place of birth, place of birth registration, place of permanent residence registration, place of temporary residence registration, current residence, place of origin and contact address; (v) nationality; (vi) images of an individual; (vii) telephone number, personal identification number, passport number, driving licence number and vehicle registration plate number; (viii) marital status; (ix) information about family relationships (including parents, children, spouse); (x) information about an individual’s digital account; and (xi) other information associated with or capable of identifying a specific individual but not falling within the scope of Sensitive Personal Data under Article 4 of Decree No. 356/2025/ND-CP and other relevant laws and regulations.

Sensitive Personal Data means Personal Data associated with an individual’s privacy which, if infringed, may directly affect the lawful rights and interests of an agency, organization or individual, falling within the list issued by the Government, including: (i) data revealing racial or ethnic origin; (ii) political, religious or belief opinions; (iii) information concerning private life, personal secrets and family secrets; (iv) health status; (v) biometric data and genetic characteristics; (vi) data revealing an individual’s sex life or sexual orientation; (vii) data concerning crimes and violations of law collected and stored by law enforcement authorities; (viii) location data of an individual determined through location services; (ix) login information and passwords for an individual’s electronic identification account and images of identity cards, citizen identity cards or identity documents; (x) login information and passwords for bank accounts; bank card information; bank account transaction history; financial and credit information and information concerning financial, securities and insurance activities and transaction history of customers at credit institutions, foreign bank branches, payment intermediary service providers, securities companies, insurance enterprises and other permitted organizations; (xi) data tracking behavior and use of telecommunications services, social networks, online communication services and other services in cyberspace; and (xii) other Personal Data that, under law, must be kept confidential or subject to strict security measures.

  1. PURPOSES, LEGAL BASES AND METHODS OF PERSONAL DATA PROCESSING

The Company may process Personal Data for purposes including, without limitation: (i) managing and maintaining relationships with customers, consumers, suppliers and partners; (ii) receiving, processing and responding to requests, feedback and complaints from customers and consumers; (iii) providing, distributing and managing the Company’s products and services; (iv) conducting promotions, customer care programs, surveys and market research; (v) conducting communications, advertising and marketing activities in accordance with law; (vi) recruiting and managing employees, probationary employees and candidates; (vii) managing security, safety and access control at the Company’s factories, offices and facilities; (viii) conducting activities relating to food safety, product quality, traceability and handling product-related incidents to the extent necessary; (ix) performing and managing contracts, orders, delivery and payment; (x) performing accounting, tax, reporting and other statutory obligations; (xi) preventing, detecting and handling fraud, violations of law and acts affecting the Company’s operations; (xii) protecting the Company’s lawful rights and interests; and (xiii) other lawful purposes in accordance with law.

The Company processes Personal Data on the basis of: (i) the Data Subject’s consent where required by law; (ii) performance of a contract or agreement to which the Data Subject is a party; (iii) compliance with legal obligations; (iv) protection of the lawful rights and interests of the Company, the Data Subject or a third party to the extent permitted by law; and (v) other cases permitted by law.

The Company may process Personal Data electronically, manually, or by a combination of both methods, depending on the nature, purpose and requirements of each processing activity.

  1. PERIOD OF PROCESSING AND RETENTION OF PERSONAL DATA

The Company processes Personal Data from the time it collects or receives the Personal Data on an appropriate legal basis and to the extent necessary for the processing purpose.

The Company shall cease or restrict the processing of Personal Data when: (i) the processing purpose has been fulfilled; (ii) the retention period has expired; (iii) there is a lawful request from the Data Subject; (iv) the contract or relationship between the Company and the Data Subject has terminated and no relevant obligations remain; or (v) in other cases as required by law.

The retention period for Personal Data shall be determined based on: (i) the purpose and nature of the processing; (ii) the type of Personal Data; (iii) the relationship between the Company and the Data Subject; (iv) contractual obligations and legal requirements; and (v) the need to resolve disputes or complaints or protect the Company’s lawful rights and interests.

After the retention period expires, the Company shall delete, destroy or otherwise process the Personal Data in an appropriate manner in accordance with law, unless law requires or permits continued retention.

  1. SHARING, DISCLOSURE AND TRANSFER OF PERSONAL DATA

To the extent necessary to carry out the processing purposes set out in this Policy, the Company may share, disclose or transfer Personal Data to: (i) employees and authorized departments of the Company; (ii) the Company’s branches and affiliated units; (iii) parent companies, affiliated companies or other entities within the same group, if any and to the extent permitted by law; (iv) information technology, data storage, software and system service providers; (v) recruitment, training and human resources management service providers; (vi) transportation, logistics, customer care or related service providers; (vii) consultants, auditors, lawyers and experts; (viii) banks, payment institutions and financial service providers; (ix) competent state authorities; and (x) other Third Parties where there is an appropriate legal basis.

The Company requires parties receiving or accessing Personal Data to implement appropriate protection measures and process Personal Data only within the permitted scope.

Where Personal Data is transferred to or processed overseas, the Company shall carry out the transfer of Personal Data abroad in accordance with the applicable conditions, procedures and obligations prescribed by law, and shall apply necessary measures to ensure the safety and protection of Personal Data.

  1. OUTSOURCING OF PERSONAL DATA PROCESSING

The Company may engage, use or authorize a Personal Data Processor and/or Third Party to process Personal Data to the extent necessary for the Company’s manufacturing, business and management activities.

Such outsourcing shall be carried out on the basis of a contract, agreement or other appropriate document specifying the Personal Data protection requirements in accordance with law.

The Personal Data Processor shall: (i) process Personal Data only within the scope and for the purposes authorized; (ii) comply with applicable law and the Company’s requirements; (iii) apply appropriate protection measures; and (iv) cooperate with the Company in handling incidents and performing obligations relating to Personal Data protection.

The Company shall: (i) select, assess and manage an appropriate Personal Data Processor; and (ii) apply necessary measures to ensure that Personal Data is processed securely, for proper purposes and in accordance with law.

  1. PERSONAL DATA PROTECTION MEASURES

The Company applies managerial, technical and other appropriate protection measures consistent with the nature, scope, purpose and risk level of Personal Data processing to prevent and mitigate Personal Data from being: (i) lost, damaged or destroyed; (ii) stolen, misappropriated or accessed without authorization; (iii) used, disclosed, provided or transferred without authorization; or (iv) processed in violation of law.

The Company’s Personal Data protection measures may include: (i) access control and access-right management; (ii) account, password and authentication management; (iii) authorization for individuals permitted to process Personal Data; (iv) information technology system security measures; (v) data backup, recovery and availability measures; (vi) training, guidance and awareness-raising for persons involved in Personal Data processing; (vii) management and supervision of Third Parties and Personal Data Processors; (viii) inspection, assessment and monitoring of Personal Data protection; and (ix) other measures appropriate to applicable law and the risk level of the processing activity.

Where a breach or potential breach of Personal Data protection requirements occurs, the Company shall: (i) promptly identify, assess and handle the incident; (ii) apply necessary measures to prevent, remedy and mitigate damage; (iii) notify the Data Subject and/or competent authorities where required by law; and (iv) perform other obligations in accordance with the procedures, time limits and requirements prescribed by applicable law.

  1. RIGHTS AND OBLIGATIONS OF DATA SUBJECTS

Under applicable law, the rights of Data Subjects include: (i) the right to be informed about Personal Data processing activities; (ii) the right to consent or refuse consent and the right to request withdrawal of consent to the processing of Personal Data; (iii) the right to view, access, correct or request correction of Personal Data; (iv) the right to request provision of Personal Data; (v) the right to request deletion of Personal Data; (vi) the right to request restriction of Personal Data processing; (vii) the right to object to Personal Data processing; (viii) the right to complain, report, initiate legal proceedings and request compensation for damages in accordance with law; (ix) the right to request competent authorities or agencies, organizations or individuals involved in Personal Data processing to implement measures and solutions to protect the Data Subject’s Personal Data in accordance with law; and (x) other rights prescribed by law.

Data Subjects may exercise their rights by contacting the Company using the contact details set out in this Policy. The Company shall receive, verify and process valid requests in accordance with law.

Under applicable law, the obligations of Data Subjects include: (i) protecting their own Personal Data; (ii) respecting and protecting the Personal Data of others; (iii) providing complete and accurate Personal Data in accordance with law, contract or when consenting to the processing of their Personal Data; and (iv) complying with Personal Data protection laws and participating in the prevention and combating of acts infringing Personal Data.

When exercising their rights and obligations, Data Subjects must: (i) comply with law and contractual obligations, and exercise their rights and obligations for the purpose of protecting their own lawful rights and interests; (ii) not obstruct or hinder the exercise of the legal rights and obligations of the Personal Data Controller, Personal Data Controller and Processor or Personal Data Processor; and (iii) not infringe upon the lawful rights and interests of the State, agencies, organizations or other individuals.

Where a Data Subject provides the Company with another person’s Personal Data, the Data Subject must ensure that such provision has an appropriate legal basis and complies with Personal Data protection laws.

  1. WITHDRAWAL OF CONSENT, DELETION AND DESTRUCTION OF PERSONAL DATA

Where consent is required by law, the Data Subject has the right to withdraw consent to the processing of Personal Data in accordance with law; withdrawal of consent shall not affect the lawfulness of processing carried out before the withdrawal; where a Data Subject withdraws consent or requests deletion, restriction or objection to the processing of Personal Data, the Company shall consider and process such request in accordance with law; however, the Company may continue to retain or process Personal Data to the extent permitted or required by law, or where continued processing is necessary to perform legal obligations or protect the Company’s lawful rights and interests.

Failure by a Data Subject to provide necessary Personal Data or to consent to the Company’s processing of Personal Data where such processing is necessary and has an appropriate legal basis may result in the Company being unable to: (i) provide products or services; (ii) process requests or complaints; (iii) perform contracts; (iv) perform payment obligations; (v) carry out recruitment or employment management procedures; (vi) conduct security and access control; (vii) perform legal obligations; or (viii) provide related services or benefits.

As a general principle, the Company shall delete or destroy Personal Data when the processing purpose has been fulfilled or the retention period has expired, unless law requires or permits continued retention. Personal Data stored electronically may be deleted using technical methods that ensure the data cannot be recovered or unlawfully reused. Personal Data stored in physical form may be destroyed by appropriate methods, including destruction, shredding or other methods ensuring that the data cannot be recovered.

Where law requires the Company to continue retaining Personal Data after the processing purpose has been fulfilled, the Company shall continue to retain such Personal Data within the scope and for the period prescribed by law.

  1. CONTACT INFORMATION

Data Subjects may contact the Company to exercise their rights or submit requests or complaints relating to the processing of Personal Data using the following information:

ORION FOOD VINA CO., LTD.

Address: 22nd Floor, Pearl Plaza, 561A Dien Bien Phu Street, Thanh My Tay Ward, Ho Chi Minh City, Vietnam.

Email: CSKH_Orion@orionworld.com

Telephone: 1900633637

The Company shall receive, verify and process requests relating to Personal Data in accordance with law and this Policy.

  1. AMENDMENTS AND SUPPLEMENTS TO THE POLICY

The Company may amend or supplement this Policy when necessary to: (i) ensure compliance with laws and regulations as amended, supplemented or replaced; (ii) reflect changes in the Company’s manufacturing, business activities and organizational structure; (iii) reflect changes in technology, systems or methods of Personal Data processing; or (iv) enhance measures for protecting Personal Data and the rights and lawful interests of Data Subjects.

Any amendment or supplement to this Policy shall be published by the Company on its website or through other appropriate means and shall take effect from the date of publication or such other date as notified by the Company, in accordance with applicable law.