PRIVACY AND PERSONAL DATA PROTECTION POLICY
Applicable to the Blogbio Platform
PREAMBLE
Metaconex Ltd (“Metaconex,” “we,” “us,” or “our”) is committed to respecting the privacy and protecting the personal data of all individuals and organizations using the Blogbio platform.
This Policy sets out how Blogbio collects, records, uses, stores, shares, protects, and otherwise processes users’ personal data during account registration, website creation, service usage, and transactions conducted on the platform.
By accessing, registering an account with, or continuing to use Blogbio, the User acknowledges that they have read, understood, and agreed to this Policy.
1. SCOPE OF APPLICATION
This Policy applies to all individuals, organizations, or lawful representatives who access, register for, or use the Blogbio platform at https://blogb.io, including but not limited to the following activities:
-
Registering an account;
-
Verifying user information;
-
Creating a website;
-
Managing a website;
-
Uploading content;
-
Managing domain names;
-
Using Blogbio’s artificial intelligence features;
-
Making service payments;
-
Renewing service plans;
-
Contacting customer support;
-
Submitting complaints or requesting technical support;
-
Carrying out any other activities arising during the use of Blogbio.
Blogbio is a Website Builder platform operating under a Software as a Service (“SaaS”) model.
Metaconex provides the technical infrastructure and tools that enable Users to build, manage, and operate websites.
Users retain ownership of and are solely responsible for all content, data, images, videos, files, and information uploaded to or published on their websites.
2. DATA PROCESSING PRINCIPLES
Metaconex processes personal data in accordance with the following principles:
2.1 Transparency
Users will be informed of:
-
The types of data collected;
-
The purposes for which the data is used;
-
The data retention period;
-
The parties with whom the data may be shared;
-
The User’s rights in relation to their data.
2.2 Purpose Limitation
Personal data shall only be used for the purposes disclosed in this Policy or as otherwise required or permitted by applicable law.
Metaconex shall not use Users’ data for any other purpose unless an appropriate legal basis has been established.
2.3 Data Minimization
We only collect the amount of data reasonably necessary to:
-
Provide the services;
-
Verify user accounts;
-
Protect the system;
-
Process transactions;
-
Comply with legal obligations.
2.4 Accuracy
Users are responsible for providing accurate, complete, and up-to-date information.
Metaconex reserves the right to request additional information or verify the information provided whenever necessary.
2.5 Security and Confidentiality
Metaconex implements appropriate technical and administrative measures to prevent:
-
Unauthorized access;
-
Data breaches or unauthorized disclosure;
-
Unauthorized alteration of data;
-
Data loss;
-
Use of data for improper or unauthorized purposes.
2.6 Storage Limitation
Personal data shall only be retained for as long as necessary to:
-
Provide the services;
-
Perform contractual obligations;
-
Resolve disputes;
-
Comply with legal obligations;
-
Protect the lawful rights and interests of Metaconex and Users.
Upon expiry of the applicable retention period, the data shall be deleted or anonymized in accordance with Metaconex’s data management procedures.
3. DATA COLLECTED
During the use of Blogbio, Metaconex may collect the following categories of data:
3.1 Account Data
This may include:
-
Full name;
-
Email address;
-
Telephone number;
-
Profile picture;
-
Display name;
-
Business name, if applicable;
-
Account identifier;
-
User role;
-
Verification status;
-
Service plan;
-
Login history;
-
History of changes to account information.
Metaconex does not store passwords in plain text. Passwords are encrypted or hashed in accordance with appropriate security standards.
3.2 Website Data
This may include, but is not limited to:
-
Website name;
-
Domain name;
-
Subdomain;
-
Layout;
-
Theme;
-
Menus;
-
Categories;
-
Posts;
-
Pages;
-
Media;
-
Images;
-
Videos;
-
Documents;
-
Uploaded files;
-
Website settings;
-
SEO configurations;
-
Metadata;
-
Revision history;
-
Publication status.
3.3 Usage Data
This may include:
-
IP address;
-
Browser information;
-
Operating system;
-
Device type;
-
Language;
-
Time zone;
-
Screen size;
-
Cookies;
-
Session data;
-
Access tokens;
-
Login times;
-
Duration of use;
-
Traffic sources;
-
Activity history;
-
System logs;
-
Error reports.
3.4 Payment Data
When a User uses paid services, Blogbio may collect:
-
Transaction ID;
-
Order ID;
-
Service plan;
-
Payment amount;
-
Payment date and time;
-
Payment status;
-
Billing information;
-
Refund information.
Bank card details or other sensitive payment information shall be processed through licensed payment service providers and shall not be stored in full by Metaconex on its systems, unless otherwise required by applicable law.
3.5 Customer Support Data
This may include:
-
Content of support requests;
-
Email correspondence;
-
Screenshots;
-
Attachments;
-
Support handling history;
-
Complaint history;
-
Resolution outcomes.
4. METHODS OF DATA COLLECTION
Metaconex may collect data through one or more of the following methods:
4.1 Data Provided Directly by Users
Data may be entered or provided directly by Users when they:
-
Register an account;
-
Create a website;
-
Update their profile;
-
Upload content;
-
Make payments;
-
Submit support requests;
-
Participate in surveys;
-
Use AI-powered features.
4.2 Automatic Data Collection
During the use of Blogbio, the system may automatically record:
-
Access logs;
-
IP addresses;
-
Cookies;
-
Device information;
-
Activity history;
-
System performance data;
-
Error diagnostic data;
-
Security data.
4.3 Data Obtained From Third Parties
Metaconex may receive data from:
-
Payment gateways;
-
Email service providers;
-
SMS or OTP service providers;
-
Cloud service providers;
-
Content Delivery Networks (“CDNs”);
-
Authentication service providers;
-
Analytics service providers;
-
Security service providers;
-
Other services that Users voluntarily connect to Blogbio.
4.4 System-Generated Data
During its operation, Blogbio may automatically generate technical data necessary for the functioning of the platform, including:
-
Internal identifiers;
-
Processing logs;
-
Statistical data;
-
Risk assessment scores;
-
Security alerts;
-
Synchronization history;
-
System audit information.
5. PURPOSES OF PERSONAL DATA PROCESSING
Metaconex processes Users’ personal data only to the extent necessary to provide, operate, secure, and improve the Blogbio services. Personal data may be processed for one or more of the following purposes:
5.1 Provision of Services
Data may be used to:
-
Create and manage Blogbio accounts;
-
Create websites at the User’s request;
-
Manage websites, domain names, and platform features;
-
Store content, images, files, and data created by Users;
-
Provide AI-powered features, design tools, and other Blogbio utilities;
-
Manage access rights, user roles, and permissions.
5.2 Account Verification and Protection
Data may be used to:
-
Verify a User’s identity;
-
Authenticate accounts;
-
Send OTP codes;
-
Detect unusual login activity;
-
Prevent unauthorized access;
-
Prevent account impersonation;
-
Protect high-risk actions and transactions.
5.3 Payment Processing
Data may be used to:
-
Confirm transactions;
-
Process payments;
-
Renew services;
-
Issue invoices;
-
Reconcile transactions;
-
Process refunds;
-
Resolve payment disputes.
5.4 Customer Support
This may include:
-
Receiving support requests;
-
Resolving technical issues;
-
Handling complaints;
-
Verifying account ownership;
-
Responding to User requests.
5.5 System Security
Metaconex may use data to:
-
Detect spam;
-
Block bots;
-
Defend against Distributed Denial-of-Service (“DDoS”) attacks;
-
Prevent fraud;
-
Detect malware;
-
Investigate security incidents;
-
Protect system resources.
5.6 Service Improvement
Data may be used to:
-
Analyze system performance;
-
Evaluate user experience;
-
Improve the interface;
-
Optimize system speed;
-
Develop new features;
-
Conduct statistical research using aggregated or anonymized data.
5.7 Compliance With Legal Obligations
Metaconex may process data to:
-
Fulfill tax obligations;
-
Fulfill accounting obligations;
-
Comply with cybersecurity regulations;
-
Respond to requests from competent government authorities;
-
Protect the lawful rights and interests of Metaconex or its Users.
6. LEGAL BASES FOR DATA PROCESSING
Metaconex processes personal data on the basis of one or more of the following legal grounds:
-
The User’s consent;
-
The performance of a contract or the provision of services at the User’s request;
-
Compliance with legal obligations;
-
The need to ensure system security;
-
Metaconex’s legitimate interests, provided that such interests do not unduly prejudice the lawful rights and interests of the User.
7. ACCOUNT VERIFICATION AND OTP CODES
7.1 Purpose of Verification
To protect user accounts and meet system security requirements, Blogbio may apply verification mechanisms using email, telephone numbers, One-Time Passwords (“OTPs”), or other authentication methods from time to time.
Verification is carried out to:
-
Confirm account ownership;
-
Prevent impersonation;
-
Protect personal data;
-
Reduce unauthorized transactions;
-
Comply with applicable legal requirements.
7.2 Circumstances Requiring OTP Verification
Blogbio may require Users to enter an OTP in the following circumstances:
-
Registering a new account;
-
Verifying a telephone number or email address;
-
Logging in from an unusual device or location;
-
Recovering an account;
-
Changing a password;
-
Changing security information;
-
Changing a payment method;
-
Upgrading or changing a service plan;
-
Publishing a website or public content, where required by the system;
-
Performing actions assessed by the system as presenting a high level of risk.
Blogbio reserves the right to add or modify the circumstances in which OTP verification is required in order to enhance security, without the need to amend this Policy.
7.3 OTP Verification Process
The standard OTP verification process includes the following steps:
-
The User performs an action requiring verification.
-
Blogbio generates a random OTP.
-
The OTP is sent via:
-
SMS;
-
Email; or
-
Another authentication method supported by the system.
The User enters the OTP on the verification interface.
The system verifies:
-
The validity of the OTP;
-
Its expiration period;
-
The number of entry attempts;
-
Its usage status.
If the OTP is valid, the requested action will be completed.
7.4 OTP Validity
Each OTP:
-
May only be used once;
-
Remains valid only for the period specified by the system;
-
Automatically expires after use or upon expiry of its validity period.
Blogbio may limit the number of incorrect OTP entry attempts in order to protect user accounts.
7.5 User Responsibilities
Users are responsible for:
-
Keeping OTPs confidential;
-
Not sharing OTPs with any person;
-
Not providing OTPs to anyone claiming to be a Blogbio employee;
-
Promptly notifying Blogbio upon detecting any indication that their account may have been compromised.
Metaconex shall not be liable for any loss or damage arising from a User’s voluntary disclosure of an OTP or failure to implement necessary security measures.
8. COOKIES AND TRACKING TECHNOLOGIES
To improve the operation and performance of the platform, Blogbio uses cookies and similar storage technologies.
These technologies help to:
-
Maintain login sessions;
-
Remember User preferences;
-
Enhance security;
-
Measure performance;
-
Improve the user experience.
8.1 Essential Cookies
Essential cookies are used to:
-
Maintain login status;
-
Authenticate Users;
-
Support load balancing;
-
Prevent request forgery;
-
Protect the system.
Disabling essential cookies may cause certain Blogbio features to function improperly.
8.2 Functional Cookies
Functional cookies are used to remember:
-
Language preferences;
-
Interface settings;
-
Display preferences;
-
Personal settings.
8.3 Analytics Cookies
Blogbio may use cookies to:
-
Measure website traffic;
-
Analyze performance;
-
Detect errors;
-
Improve service quality.
Such data is generally processed in aggregated form and is not intended to identify individual Users.
8.4 Marketing Cookies
Where permitted by applicable law or with the User’s consent, Blogbio may use cookies to:
-
Measure campaign effectiveness;
-
Analyze browsing behavior;
-
Personalize content;
-
Provide information relevant to the User’s needs and interests.
8.5 Cookie Management
Users may:
-
Accept cookies;
-
Reject cookies; or
-
Delete cookies through their browser settings.
Rejecting certain cookies may affect the User’s experience when using Blogbio.
9. DATA SHARING
Metaconex does not sell, rent, or trade Users’ personal data for commercial purposes.
Personal data may only be shared, to the extent necessary, with the following categories of recipients:
9.1 Service Providers
These may include providers of:
-
Cloud infrastructure;
-
Server hosting;
-
Content Delivery Networks (“CDNs”);
-
Backup systems;
-
Email services;
-
SMS services;
-
OTP services;
-
Payment services;
-
Data analytics;
-
Security services;
-
System monitoring.
Such service providers are permitted to process personal data only in accordance with Metaconex’s instructions and are required to comply with confidentiality and data protection obligations under applicable contracts and laws.
9.2 Competent Government Authorities
Metaconex may disclose personal data where:
-
A written request is made by a competent government authority;
-
The disclosure is required for an investigation, prosecution, or judicial proceeding;
-
The disclosure is necessary to comply with legal obligations;
-
The disclosure is necessary to protect the lawful rights and interests of Metaconex, Users, or third parties.
9.3 Services Connected by Users
Where a User voluntarily connects Blogbio to third-party platforms or services, such as custom domain services, social media platforms, analytics tools, advertising platforms, or other integrated services, the necessary data may be transferred to such services at the User’s request.
Once data has been transferred to a third party’s system, the collection and processing of that data will be governed by the third party’s own privacy policy.
10. CROSS-BORDER DATA TRANSFERS
10.1 General Principles
In the course of providing its services, Blogbio may use cloud computing infrastructure, Content Delivery Networks (“CDNs”), storage services, email services, security services, system monitoring services, or other technical services provided by partners located within or outside Vietnam.
As a result, certain User data may be stored, processed, or transmitted through servers located outside the territory of Vietnam.
Any cross-border data transfer shall only be carried out to the extent necessary to:
-
Provide the services;
-
Maintain system stability;
-
Back up and restore data;
-
Protect information security;
-
Provide technical support;
-
Process payments;
-
Improve service quality.
10.2 Safeguards
When transferring personal data outside Vietnam, Metaconex may implement one or more of the following safeguards:
-
Entering into data processing agreements with relevant partners;
-
Including confidentiality and data protection clauses in contracts;
-
Encrypting data during transmission;
-
Applying access controls;
-
Maintaining access logs;
-
Limiting the scope of data shared;
-
Applying security standards appropriate to the nature and sensitivity of the data.
10.3 Legal Compliance
Cross-border transfers of personal data shall be carried out in accordance with applicable law.
Where applicable law requires User consent or completion of legal procedures before transferring personal data, Metaconex shall comply with such requirements.
11. DATA SECURITY
Metaconex implements multiple layers of technical and administrative safeguards to protect personal data against unauthorized access, misuse, disclosure, alteration, or destruction.
However, no system can guarantee absolute security. Users are also responsible for taking reasonable measures to protect their account information.
11.1 Security Measures Implemented by Metaconex
Metaconex may implement one or more of the following measures:
a. Data Transmission Security
-
Encrypting connections using HTTPS/TLS;
-
Encrypting data during transmission;
-
Applying appropriate security protocols from time to time.
b. Protection of Authentication Information
-
Storing passwords in hashed or encrypted form in accordance with appropriate security standards;
-
Not storing passwords in plain text;
-
Not sending passwords via email or SMS.
c. Access Control
Metaconex applies the principle of least privilege, under which only authorized personnel may access the data necessary to perform their assigned duties.
Access activities may be logged for audit and security purposes.
d. Security Monitoring
The system may implement measures such as:
-
Detecting unusual login activity;
-
Limiting unsuccessful login attempts;
-
Temporarily locking accounts where risks are detected;
-
Monitoring unauthorized access;
-
Detecting anomalous behavior;
-
Protecting against Distributed Denial-of-Service (“DDoS”) attacks;
-
Scanning for malware;
-
Monitoring security vulnerabilities.
e. Backup and Recovery
Metaconex performs periodic data backups to:
-
Ensure service continuity;
-
Restore data in the event of an incident;
-
Reduce the risk of data loss.
The existence of backup copies does not mean that deleted data will be restored at the User’s request.
f. Staff Training and Internal Management
Personnel authorized to access personal data are required to comply with rules relating to:
-
Information security;
-
Access management;
-
Data leakage prevention;
-
Personal data protection.
Metaconex may conduct inspections and monitoring and may take appropriate disciplinary or remedial action in response to violations of its internal policies.
11.2 User Responsibilities
Users are responsible for:
-
Using passwords of appropriate strength;
-
Changing passwords periodically or whenever compromise is suspected;
-
Not sharing passwords or OTP codes with any person;
-
Logging out when using public or shared devices;
-
Protecting access devices through appropriate measures, including passwords, biometric authentication, and screen locks;
-
Keeping browsers and operating systems up to date to reduce security risks;
-
Promptly notifying Metaconex upon detecting signs of unauthorized access or unusual activity.
Metaconex shall not be liable for any loss or damage arising from a User’s failure to implement necessary security measures or voluntary disclosure of authentication information to a third party.
12. DATA RETENTION, BACKUP, AND DELETION
12.1 Retention Principles
Personal data shall be retained for as long as necessary to:
-
Provide the services;
-
Perform contractual obligations;
-
Process payments;
-
Resolve complaints;
-
Prevent fraud;
-
Protect the lawful rights and interests of the relevant parties;
-
Comply with legal obligations.
Once there is no longer a valid purpose for retention, the data shall be deleted, destroyed, or anonymized in accordance with Metaconex’s data management procedures.
12.2 Retention Periods
Data retention periods may depend on:
-
The period during which the account remains active;
-
The duration of the applicable service plan;
-
Technical support requirements;
-
Accounting, tax, and transaction-related obligations;
-
Applicable limitation periods for dispute resolution;
-
Requests from competent government authorities.
12.3 Retention of Posts and Media Files
For posts, images, videos, attachments, and other media files uploaded by Users to Blogbio, the system applies a data retention policy for management, monitoring, and retrieval purposes.
Accordingly:
-
Post records and media files may be retained for up to thirty (30) days from the date on which the relevant post is published or from the date on which the data is generated in the system, depending on the type of data and the applicable operational procedures.
-
Upon expiry of the retention period, the data may be automatically deleted in accordance with Metaconex’s data lifecycle management procedures, unless a longer retention period is required by law or the data is required for the resolution of complaints, disputes, investigations, or other legal obligations.
-
Users are responsible for creating and retaining copies of important content before the applicable retention period expires.
12.4 Data Deletion
Users may submit a request to delete personal data or account data in accordance with Blogbio’s support procedures.
Metaconex may refuse or delay a deletion request where:
-
Continued retention is required by law;
-
The data is required for dispute resolution;
-
The data is relevant to an investigation into suspected violations;
-
The data is required for accounting or tax obligations;
-
The data is necessary to protect the lawful rights and interests of Metaconex or a third party.
12.5 Backup Data
Even after data has been deleted from the active system, it may remain in backup copies for a certain period in accordance with the system’s backup cycle.
Data stored in backups shall only be used for:
-
System restoration;
-
Incident investigation;
-
Maintaining data integrity;
-
Compliance with legal obligations.
13. RIGHTS OF DATA SUBJECTS
Users have certain rights in relation to their personal data.
13.1 Right to Be Informed
Users have the right to be informed of:
-
The data being collected;
-
The purposes of processing;
-
The applicable retention period;
-
The recipients of the data;
-
The relevant rights and obligations.
13.2 Right of Access
Users have the right to request that Metaconex confirm whether their personal data is being processed and provide information about such data to the extent permitted by law.
13.3 Right to Rectification
Users have the right to request the updating or correction of personal data that is inaccurate, incomplete, or no longer current.
Metaconex may require Users to provide information or documents necessary to verify the request before taking action.
13.4 Right to Request Deletion
Users may request the deletion of their personal data where permitted by law.
This right shall not apply where the data must continue to be retained in accordance with legal requirements or to protect the lawful rights and interests of the relevant parties.
13.5 Right to Restrict or Object to Processing
Users have the right to request the restriction of or object to the processing of their personal data in circumstances provided for by law.
Metaconex shall assess each request on a case-by-case basis and respond within an appropriate period.
13.6 Right to Withdraw Consent
Where the processing of personal data is based on the User’s consent, the User may withdraw such consent at any time.
The withdrawal of consent shall not affect the lawfulness of any processing carried out before the withdrawal became effective.
13.7 Right to Lodge a Complaint
Users have the right to submit feedback, complaints, or requests for resolution regarding the processing of personal data through Blogbio’s official support channels.
Metaconex may require Users to verify their identity before processing requests relating to personal data in order to protect the User and prevent unauthorized access.
14. MINORS
14.1 Scope of Application
Blogbio is not primarily designed for children and is not intended to collect personal data from minors.
Users of Blogbio must have full legal capacity in accordance with applicable law or otherwise satisfy the legal requirements for using the services.
Where a minor uses the services, the registration and use of Blogbio must take place with the consent, supervision, or representation of a parent, guardian, or lawful representative in accordance with applicable law.
14.2 Collection of Data
Metaconex does not knowingly collect personal data from minors in violation of applicable law.
Where Metaconex determines that an account has been created or data has been provided without satisfying the applicable conditions for using the services, Metaconex may:
-
Request additional verification;
-
Suspend or restrict access to the services;
-
Delete the relevant data or terminate the account in accordance with applicable law and the Terms of Service.
14.3 Responsibilities of Lawful Representatives
Parents or lawful representatives are responsible for supervising a minor’s use of the services and for information provided by the minor through an account under their supervision or management.
15. SECURITY INCIDENT RESPONSE
15.1 Detection and Assessment
Upon detecting or receiving information about an incident that may affect personal data or system security, Metaconex shall:
-
Receive and verify the relevant information;
-
Assess the level of impact;
-
Determine the scope of the data affected;
-
Implement necessary measures to mitigate the risks.
15.2 Incident Remediation
Depending on the nature of the incident, Metaconex may implement one or more of the following measures:
-
Isolate affected systems;
-
Temporarily lock accounts suspected of being compromised;
-
Restore data from backups, where necessary;
-
Patch security vulnerabilities;
-
Strengthen monitoring and preventive measures.
15.3 Notification
Where required by law or where an incident is likely to have a material impact on the lawful rights and interests of Users, Metaconex may provide notice through one or more of the following methods:
-
Email;
-
Account notifications;
-
Notices published on the Website;
-
SMS messages, where necessary;
-
Other appropriate methods.
15.4 User Responsibilities
Users must promptly notify Metaconex upon detecting:
-
Signs of unauthorized access to an account;
-
Loss of control over an account;
-
Suspected data leakage;
-
A security vulnerability or unauthorized use of the services.
When submitting a support request, Users should not provide passwords, OTP codes, or any other active authentication credentials through email or other support channels.
16. POLICY UPDATES
Metaconex reserves the right to amend, supplement, or update this Policy in order to:
-
Comply with legal requirements;
-
Reflect changes to products or services;
-
Update operational procedures;
-
Strengthen personal data protection;
-
Improve the User experience.
The updated version shall be published on the Blogbio Website and shall take effect upon publication or on the effective date specified in the relevant notice.
Where changes materially affect the rights and interests of Users, Metaconex shall provide appropriate notice in accordance with applicable law or the notification mechanisms then in use on Blogbio.
A User’s continued use of the services after this Policy has been updated shall constitute acknowledgment that the User has read, understood, and agreed to the updated version, unless otherwise provided by law.
17. FINAL PROVISIONS
This Policy forms an integral part of the Blogbio Terms of Service.
In the event of any inconsistency between this Policy and any mandatory provision of applicable law, the applicable legal provision shall prevail.
If any provision of this Policy is determined by a competent authority to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
This Policy is made in the Vietnamese language. Where a translation into another language is provided, the Vietnamese version shall prevail in the event of any discrepancy in meaning or interpretation, unless otherwise required by law.