Chính sách bảo mật — Peram Chat
Đơn vị vận hành: CÔNG TY TNHH NGHIÊN CỨU CÔNG NGHỆ PERAM (thương hiệu Peram Software) · Cập nhật ngày 05/09/2026
Peram Chat là sản phẩm mang thương hiệu Peram Software, do CÔNG TY TNHH NGHIÊN CỨU CÔNG NGHỆ PERAM phát triển và vận hành. Đây là công cụ nội bộ dành cho nhân viên doanh nghiệp, dùng để đọc và trả lời tin nhắn công việc trên các tài khoản nhắn tin mà doanh nghiệp đã cấp quyền. Tài liệu này mô tả đúng những gì ứng dụng làm với dữ liệu — không hơn, không kém.
1. Đơn vị vận hành
Peram Chat là sản phẩm mang thương hiệu Peram Software, do CÔNG TY TNHH NGHIÊN CỨU CÔNG NGHỆ PERAM (tên quốc tế: PERAM TECHNOLOGY RESEARCH COMPANY LIMITED) phát triển và vận hành.
Trụ sở: 21 Phan Kế Bính, Phường Đa Kao, Quận 1, Thành phố Hồ Chí Minh, Việt Nam.
Trong toàn bộ tài liệu này, “chúng tôi” nghĩa là CÔNG TY TNHH NGHIÊN CỨU CÔNG NGHỆ PERAM — pháp nhân chịu trách nhiệm về ứng dụng và về việc xử lý dữ liệu mô tả dưới đây.
Liên hệ: info@peram-software.com
- Cần phân biệt: CÔNG TY TNHH NGHIÊN CỨU CÔNG NGHỆ PERAM (thương hiệu Peram Software) là đơn vị cung cấp phần mềm. Nội dung hội thoại công việc thuộc về doanh nghiệp đã cấp tài khoản cho người dùng — trong tài liệu này gọi là “doanh nghiệp”.
2. Dữ liệu ứng dụng gửi đi
Ứng dụng kết nối tới máy chủ Peram Chat qua HTTPS. Tuỳ chức năng được sử dụng, dữ liệu cần thiết cũng có thể đi qua hạ tầng nền tảng nhắn tin gốc, dịch vụ thông báo đẩy hoặc nhà cung cấp AI được doanh nghiệp cấu hình; các trường hợp này được mô tả tại mục 5.
- Khi đăng nhập: mã công ty, tên đăng nhập, mật khẩu và mã xác thực 6 số gửi qua email.
- Khi dùng ứng dụng: mã tài khoản và mã hội thoại đang mở, từ khoá gõ trong ô tìm kiếm.
- Khi gửi tin: nội dung tin nhắn người dùng soạn.
- Khi gửi ảnh: đúng tấm ảnh người dùng tự chọn, kèm tên tệp và định dạng.
- Khi bật thông báo: mã thông báo đẩy, nền tảng thiết bị, tên thiết bị do hệ điều hành cung cấp và phiên bản ứng dụng được gửi tới máy chủ để đăng ký đúng thiết bị nhận tin.
3. Dữ liệu ứng dụng KHÔNG thu thập
- Không có công cụ đo lường hành vi, thống kê sử dụng hay báo cáo sự cố tự động.
- Không có quảng cáo và không có mã theo dõi quảng cáo.
- Không thu thập mã quảng cáo hoặc tạo dấu vân tay thiết bị để quảng cáo hay theo dõi hành vi.
- Không truy cập vị trí, danh bạ, lịch, micro hay camera — các quyền này bị chặn trong cấu hình ứng dụng.
- Không đọc toàn bộ thư viện ảnh; ứng dụng dùng bộ chọn ảnh của hệ điều hành và chỉ nhận đúng tấm được chọn.
4. Dữ liệu lưu trên thiết bị
- Chỉ lưu một thứ: mã phiên đăng nhập, đặt trong kho khoá được hệ điều hành mã hoá (Keychain trên iOS, EncryptedSharedPreferences trên Android).
- Tin nhắn, danh sách hội thoại và danh bạ không được ghi xuống bộ nhớ máy; chúng mất đi khi đóng ứng dụng.
- Ảnh và ảnh đại diện có thể được hệ thống lưu tạm để hiển thị nhanh hơn; gỡ ứng dụng sẽ xoá phần này.
- Đăng xuất sẽ xoá mã phiên khỏi thiết bị.
5. Bên thứ ba
Ảnh và ảnh đại diện trong hội thoại có thể được tải từ hạ tầng phân phối nội dung của nền tảng nhắn tin gốc; hạ tầng đó có thể nhìn thấy địa chỉ IP của thiết bị khi hiển thị ảnh.
Thông báo đẩy đi qua Expo Push và dịch vụ thông báo của hệ điều hành (Google cho Android, Apple cho iOS). Tên người gửi hoặc nhóm và đoạn xem trước tối đa 150 ký tự nằm trong thông báo để hiển thị theo lựa chọn của người dùng. Có thể tắt thông báo trong cài đặt hệ điều hành.
Khi doanh nghiệp kết nối Fanpage Facebook, ứng dụng dùng Đăng nhập Facebook chính thức của Meta để nhận quyền quản lý tin nhắn của Fanpage đó (các quyền pages_show_list, pages_messaging, pages_manage_metadata, pages_read_engagement). Máy chủ Peram Chat nhận tin nhắn Messenger của Fanpage qua webhook của Meta và gửi câu trả lời qua Send API của Meta; dữ liệu nhận về gồm mã người dùng theo Fanpage (PSID), tên hiển thị, ảnh đại diện công khai, nội dung và tệp đính kèm của tin nhắn. Mã truy cập Fanpage được mã hoá khi lưu và bị xoá khi gỡ kết nối. Việc xử lý dữ liệu Facebook tuân theo Điều khoản Nền tảng Meta; người dùng có thể gỡ kết nối bất cứ lúc nào trong ứng dụng hoặc thu hồi quyền tại phần Cài đặt ứng dụng và trang web trên Facebook.
Khi doanh nghiệp kích hoạt AI Agent, máy chủ có thể chuyển nội dung tin nhắn và phần lịch sử hội thoại cần thiết qua cổng AI 9Router và nhà cung cấp AI được cấu hình để tạo câu trả lời. Không dùng AI Agent thì luồng này không được kích hoạt cho tài khoản đó.
6. Bảo mật
- Mọi trao đổi với máy chủ đi qua HTTPS.
- Đăng nhập hai bước: mật khẩu, rồi mã xác thực 6 số gửi tới email.
- Phiên đăng nhập tự hết hạn và có thể bị quản trị viên thu hồi bất cứ lúc nào.
- Tệp đính kèm nội bộ dùng vé truy cập media có thời hạn ngắn, giới hạn theo đúng đường dẫn và thao tác; mã phiên đăng nhập không được đặt trong địa chỉ tệp.
- Nội dung tin nhắn lưu trên máy chủ được mã hoá xác thực bằng AES-256-GCM; máy chủ vẫn giải mã trong bộ nhớ khi người có quyền đọc, gửi, tìm kiếm hoặc sử dụng AI Agent.
7. Dữ liệu trên máy chủ
Nội dung hội thoại công việc được lưu trên máy chủ của doanh nghiệp để người dùng xem lại lịch sử. Quyền xem do doanh nghiệp cấp và giới hạn theo từng tài khoản nhắn tin. Tệp gửi đi không được giữ lại trên máy chủ: sau khi nền tảng nhắn tin nhận tệp, bản sao tạm trên máy chủ sẽ bị xoá.
8. Quyền của người dùng
- Yêu cầu xem, sửa hoặc xoá dữ liệu cá nhân.
- Yêu cầu xoá tài khoản và dữ liệu liên quan — xem trang Xoá tài khoản.
- Rút lại sự đồng ý bằng cách ngừng sử dụng và yêu cầu xoá tài khoản.
9. Liên hệ
Mọi câu hỏi hoặc yêu cầu liên quan tới dữ liệu cá nhân, vui lòng gửi tới info@peram-software.com. Chúng tôi phản hồi các yêu cầu về quyền riêng tư và các báo cáo nội dung vi phạm trong vòng 24 giờ làm việc.
Privacy Policy — Peram Chat
Operated by PERAM TECHNOLOGY RESEARCH COMPANY LIMITED (brand Peram Software) · Last updated 05/09/2026 (dd/mm/yyyy)
Peram Chat is a product under the Peram Software brand, developed and operated by PERAM TECHNOLOGY RESEARCH COMPANY LIMITED. It is an internal tool for a company's staff, used to read and reply to work messages on the messaging accounts that the company has granted them access to. This document describes exactly what the app does with data — no more, no less.
1. Who operates the app
Peram Chat is a product under the Peram Software brand, developed and operated by
PERAM TECHNOLOGY RESEARCH COMPANY LIMITED (Vietnamese legal name: CÔNG TY TNHH NGHIÊN CỨU
CÔNG NGHỆ PERAM).
Registered office: 21 Phan Ke Binh Street, Da Kao Ward, District 1, Ho Chi Minh City, Vietnam.
Throughout this document, “we” means PERAM TECHNOLOGY RESEARCH COMPANY LIMITED — the legal entity
responsible for the app and for the data processing described below.
Contact: info@peram-software.com
- An important distinction: PERAM TECHNOLOGY RESEARCH COMPANY LIMITED (brand Peram Software) is the software provider. The content of work conversations belongs to the company that issued the user's account — referred to in this document as “the company”.
2. Data the app sends out
The app connects to the Peram Chat server over HTTPS. Depending on which features are used, the necessary data may also pass through the infrastructure of the underlying messaging platform, the push notification service, or the AI provider configured by the company; those cases are described in section 5.
- When signing in: company code, username, password, and the 6-digit verification code sent by email.
- While using the app: the account id and the id of the conversation currently open, and the terms typed into the search box.
- When sending a message: the message content the user composes.
- When sending an image: exactly the image the user selected, together with its file name and format.
- When notifications are enabled: the push token, the device platform, the device name provided by the operating system, and the app version are sent to the server so that notifications reach the right device.
3. Data the app does NOT collect
- No behavioural analytics, no usage statistics, and no automatic crash reporting.
- No advertising and no advertising tracking code.
- No advertising identifiers are collected and no device fingerprinting is performed for advertising or behavioural tracking.
- No access to location, contacts, calendar, microphone, or camera — these permissions are disabled in the app configuration.
- The photo library is never read in full; the app uses the operating system's photo picker and receives only the image that was selected.
4. Data stored on the device
- Only one item is stored: the session token, kept in the storage encrypted by the operating system (Keychain on iOS, EncryptedSharedPreferences on Android).
- Messages, the conversation list, and contacts are not written to device storage; they are lost when the app is closed.
- Images and profile pictures may be cached by the system so they display faster; uninstalling the app removes that cache.
- Signing out deletes the session token from the device.
5. Third parties
Images and profile pictures inside conversations may be loaded from the content delivery infrastructure of the underlying messaging platform; that infrastructure can see the device's IP address when an image is displayed.
Push notifications are delivered through Expo Push and the operating system's notification service (Google for Android, Apple for iOS). The sender's or group's name and a preview of up to 150 characters are included in the notification so it can be displayed according to the user's own preference. Notifications can be turned off in the operating system settings.
When a company connects a Facebook Page, the app uses Meta's official Facebook Login to obtain permission to manage that Page's messages (the pages_show_list, pages_messaging, pages_manage_metadata and pages_read_engagement permissions). The Peram Chat server receives the Page's Messenger messages through Meta's webhook and sends replies through Meta's Send API; the data received consists of the Page-scoped user id (PSID), the display name, the public profile picture, and the content and attachments of the message. The Page access token is encrypted at rest and deleted when the Page is disconnected. Processing of Facebook data follows the Meta Platform Terms; users can disconnect at any time inside the app, or revoke access under Apps and Websites in their Facebook settings.
When a company enables the AI Agent, the server may pass message content and the necessary part of the conversation history through the 9Router AI gateway and on to the configured AI provider in order to generate a reply. If the AI Agent is not used, this flow is not activated for that account.
6. Security
- All communication with the server goes over HTTPS.
- Two-step sign-in: password, then a 6-digit verification code sent to the user's email.
- Sessions expire on their own and can be revoked by an administrator at any time.
- Internal attachments are served through short-lived media tickets that are bound to the exact path and method; the session token is never placed in a file URL.
- Message content stored on the server is encrypted with authenticated AES-256-GCM; the server still decrypts it in memory when an authorised person reads, sends, searches, or uses the AI Agent.
7. Data on the server
The content of work conversations is stored on the company's server so that users can review history. Viewing rights are granted by the company and limited per messaging account. Files that are sent out are not retained on the server: once the messaging platform has accepted the file, the temporary copy on the server is deleted.
8. User rights
- Request access to, correction of, or deletion of personal data.
- Request deletion of the account and related data — see the account deletion page.
- Withdraw consent by stopping use of the app and requesting account deletion.
9. Contact
For any question or request concerning personal data, please write to info@peram-software.com. We respond to privacy requests and to reports of violating content within 24 working hours.