Chính Sách Quyền Riêng Tư Smartie TV
1. Giới thiệu & Phạm vi áp dụng
Công ty Cổ phần IIT ("chúng tôi", "IIT") cam kết tôn trọng và bảo vệ quyền riêng tư cũng như an toàn dữ liệu của người dùng, học sinh, giáo viên, cơ sở giáo dục và các gia đình sử dụng ứng dụng học tập tương tác Smartie ("Ứng dụng" hoặc "Dịch vụ").
Chính sách này giải thích cách thức thu thập, sử dụng, bảo vệ dữ liệu trên các nền tảng TV thông minh bao gồm Android TV / Google TV (Google Play), LG webOS và Samsung Tizen.
2. Thông tin chúng tôi thu thập và xử lý
Smartie được thiết kế phục vụ mục đích giảng dạy và học tập. Chúng tôi tuân thủ nghiêm ngặt nguyên tắc tối giản dữ liệu (Data Minimization):
A. Dữ liệu định danh thiết bị & Quản lý bản quyền
- Định danh thiết bị (Device Identifier): Chuỗi mã hóa phần cứng duy nhất (như
ANDROID_ID trên Android TV hoặc DUID trên TV thông minh).
Mục đích: Chỉ sử dụng để xác thực bản quyền trường học được cấp phép, quản lý số lượng thiết bị kích hoạt và hỗ trợ ghép nối điều khiển từ xa qua mã QR.
Lưu trữ: Lưu trữ an toàn trong bộ nhớ cục bộ của thiết bị.
- Mã phiên làm việc (Session Tokens): Token xác thực JSON Web Token (JWT) để duy trì kết nối an toàn với máy chủ. Access token chỉ lưu trên RAM tạm thời; Refresh token được lưu an toàn trên máy.
B. Tiến độ học tập & Tương tác học liệu
- Dữ liệu học tập: Trạng thái hoàn thành bài học, kết quả câu hỏi trắc nghiệm, bài tập và tương tác với các học liệu giáo dục.
- Dữ liệu phát bài giảng: Mốc thời gian phát video/audio bài giảng để người học tiếp tục bài học từ điểm đã dừng trước đó.
C. Dữ liệu kỹ thuật & Nhật ký lỗi
- Thông tin chẩn đoán kỹ thuật ẩn danh (như mã lỗi HTTP, sự cố crash) nhằm phát hiện lỗi hiển thị trên từng dòng TV và đảm bảo ứng dụng vận hành mượt mà.
D. Những dữ liệu chúng tôi TUYỆT ĐỐI KHÔNG thu thập
- KHÔNG thu thập thông tin cá nhân nhạy cảm: Không thu thập CCCD/CMND, thông tin tài chính, thẻ tín dụng hoặc tài khoản ngân hàng.
- KHÔNG theo dõi vị trí địa lý: Không thu thập tọa độ GPS hay định vị vị trí thực tế của người dùng.
- KHÔNG thu thập dữ liệu sinh trắc học: Không nhận dạng khuôn mặt hay vân tay.
- KHÔNG truy cập cảm biến/media: Không tự ý truy cập Micro, Camera, Danh bạ hoặc thư viện ảnh/video cá nhân.
3. Mục đích sử dụng thông tin
Chúng tôi chỉ sử dụng thông tin cho các mục đích kỹ thuật và giáo dục hợp pháp:
- Kích hoạt & Xác thực bản quyền: Quản lý bản quyền phần mềm cho các trường học và lớp học.
- Đồng bộ nội dung bài học: Tải sách giáo khoa, bài tập tương tác, bài giảng video và tài liệu giảng dạy.
- Duy trì phiên học tập liên tục: Lưu trữ tiến độ học của học sinh giữa các lần mở app.
- Nâng cao hiệu năng ứng dụng: Tối ưu hóa điều hướng phím D-pad và độ mượt trên các màn hình TV lớn.
4. Cam kết An toàn dữ liệu theo chuẩn Google Play (Data Safety)
| Loại dữ liệu |
Thu thập |
Chia sẻ bên thứ ba |
Mục đích |
Mã hóa / Bảo mật |
Định danh thiết bị (ANDROID_ID) |
Có |
Không (0%) |
Quản lý bản quyền, Ghép nối QR |
Mã hóa khi truyền tải (HTTPS / TLS 1.3) |
| Tiến độ & Hoạt động học |
Có |
Không (0%) |
Đồng bộ bài học, Tính năng giáo dục |
Mã hóa khi truyền tải (HTTPS / TLS 1.3) |
| Nhật ký lỗi (Crash logs) |
Có |
Không (0%) |
Bảo trì & Tối ưu hiệu năng TV |
Mã hóa khi truyền tải (HTTPS / TLS 1.3) |
| Dữ liệu cá nhân / Tài chính |
Không |
Không (0%) |
Không áp dụng |
Không áp dụng |
Các biện pháp an toàn bảo mật:
- Mã hóa đường truyền: 100% dữ liệu truyền tải giữa ứng dụng và máy chủ được mã hóa qua chuẩn HTTPS / TLS 1.3.
- Chặn kết nối không an toàn: Ứng dụng khóa hoàn toàn giao thức HTTP thông thường (
usesCleartextTraffic = false).
5. Quảng cáo & Chia sẻ dữ liệu với bên thứ ba
- 0% Quảng cáo thương mại: Smartie hoàn toàn không chứa quảng cáo, banner hoặc video tiếp thị.
- Không sử dụng SDK theo dõi của bên thứ ba: Không tích hợp các mạng lưới quảng cáo hay cookie theo dõi người dùng.
- Tuyệt đối không bán dữ liệu: Chúng tôi không bao giờ bán, cho thuê hay trao đổi dữ liệu học tập của học sinh cho bất kỳ bên thứ ba nào.
6. Bảo vệ quyền riêng tư của Trẻ em (COPPA / GDPR-K / Family Policy)
Do Smartie được sử dụng trong môi trường giáo dục và gia đình:
- Chúng tôi tuân thủ nghiêm ngặt Đạo luật Bảo vệ Quyền riêng tư của Trẻ em trên Mạng (COPPA), Quy định GDPR-K và Chính sách Gia đình của Google Play Families Policy.
- Ứng dụng không yêu cầu trẻ em dưới 13 tuổi cung cấp thông tin liên lạc cá nhân.
- Mọi nội dung bài học và học liệu đều được kiểm duyệt an toàn, mang tính giáo dục thuần túy.
- Nhà trường, giáo viên và phụ huynh giữ toàn quyền kiểm soát các liên kết thiết bị.
7. Quyền của người dùng & Xóa dữ liệu (Data Deletion)
- Thời gian lưu trữ: Dữ liệu liên kết thiết bị và tiến độ học chỉ được lưu trữ trong thời hạn bản quyền còn hiệu lực.
- Hủy liên kết thiết bị: Người dùng có thể chủ động hủy liên kết bất cứ lúc nào trong ứng dụng bằng nút Hủy kích hoạt (Deactivate Device).
- Yêu cầu xóa dữ liệu: Nhà trường, giáo viên, phụ huynh và người dùng có quyền yêu cầu xóa vĩnh viễn dữ liệu tài khoản bằng cách gửi email tới info@iit.vn với tiêu đề "Yêu cầu xóa dữ liệu". Yêu cầu sẽ được xử lý trong vòng 30 ngày.
8. Thông tin liên hệ
Nếu bạn có bất kỳ câu hỏi hoặc yêu cầu nào về quyền riêng tư, vui lòng liên hệ:
Privacy Policy for Smartie TV
1. Introduction & Scope
IIT JSC ("we", "us", "our", or "IIT") is committed to protecting the privacy and data security of users, students, teachers, educational institutions, and families who use the Smartie interactive TV learning application (the "Application" or "Service").
This Privacy Policy explains the nature, scope, purpose, and security measures regarding any data processed through the Application on connected TV platforms, including Android TV / Google TV (Google Play), LG webOS, and Samsung Tizen.
2. Information We Collect and Process
Smartie operates as an educational client designed for institutional classrooms and home study. We adhere strictly to data minimization principles:
A. Device Identification & Licensing Data
- Device Identifier: A unique hardware-derived string (e.g.,
ANDROID_ID on Android TV devices, or platform DUID on Smart TVs).
Purpose: Used exclusively to validate active educational licenses, manage seat allocations, and enable QR-code mobile-to-TV pairing.
Storage: Stored in volatile runtime memory and secure device local storage.
- Session Tokens: Cryptographic JSON Web Tokens (JWT) used to maintain authenticated sessions with our backend API. Access tokens are kept in memory only; refresh tokens are securely persisted on the local device.
B. Educational Activity & Learning Progress
- Learning Logs: Subject topic completion, practice quiz scores, and student interactions with educational curriculum materials.
- Playback Telemetry: Media playback timestamps and resume points to allow students to continue video and audio lessons where they left off.
C. Technical Diagnostics & Error Logs
- Non-identifying operational telemetry (such as crash logs, HTTP response error codes, and network reachability status) to detect platform-specific rendering anomalies and ensure stable TV playback.
D. Information We DO NOT Collect
- NO Government Identification or Financial Details: We do not collect credit cards, banking information, or national identity numbers.
- NO Geolocation Tracking: We do not collect or monitor GPS or real-time location data.
- NO Biometric or Facial Recognition: We do not capture or process biometric records.
- NO Background Sensor / Media Access: The Application does not access device microphones, cameras, contacts, or local personal media libraries.
3. How We Use Collected Information
We process collected information strictly for legitimate educational and technical purposes:
- License & Device Authentication: Authenticating device bindings and managing institutional school subscriptions.
- Curriculum & Content Delivery: Synchronizing textbooks, interactive exercises, video lectures, and learning resources.
- Session Continuity: Retaining user progress across sessions and handling seamless token rotation.
- App Quality & Performance: Diagnosing platform-specific bugs and maintaining high-performance spatial navigation on TV hardware.
4. Google Play Data Safety Commitments
| Data Type |
Collected |
Shared with 3rd Parties |
Purpose |
Security / Encryption |
Device or other IDs (ANDROID_ID) |
Yes |
No (0%) |
App functionality, License validation, Device pairing |
Encrypted in transit (HTTPS / TLS 1.3) |
| App Activity & Progress |
Yes |
No (0%) |
Educational sync, Feature functionality |
Encrypted in transit (HTTPS / TLS 1.3) |
| Crash & Diagnostic Logs |
Yes |
No (0%) |
App performance & maintenance |
Encrypted in transit (HTTPS / TLS 1.3) |
| Personal / Financial / Contacts |
No |
No (0%) |
N/A |
N/A |
Security Measures:
- Encryption in Transit: All network requests to backend services use industry-standard HTTPS / TLS 1.3 encryption.
- Strict Network Policy: Cleartext HTTP traffic is disabled by default (
usesCleartextTraffic = false).
- Memory-Safe Token Management: Short-lived access tokens reside solely in volatile memory; refresh tokens are rotated via single-flight authenticated endpoints.
5. Third-Party Sharing & Commercial Advertising
- Zero Commercial Ads: Smartie contains NO advertisements, banner ads, interstitial videos, or commercial ad networks.
- No Third-Party Trackers: We do not integrate third-party ad SDKs, analytics brokers, or cross-app tracking beacons.
- No Data Selling: We will never sell, rent, monetize, or disclose user data or student records to any third party for commercial or marketing purposes.
6. Children's Privacy & Families Policy Compliance (COPPA / GDPR-K)
Because Smartie is utilized in educational environments as well as households with children:
- We comply strictly with the Children’s Online Privacy Protection Act (COPPA), the EU General Data Protection Regulation (GDPR-K), and the Google Play Families Policy.
- The Application does not solicit or collect personal contact information from children under the age of 13.
- All educational tools, learning materials, and interactive content are designed to be safe, non-commercial, and family-friendly.
- Parents, guardians, and school administrators retain full control over device bindings and data deletion.
7. Data Retention and Deletion (User Rights)
- Retention Period: Device identifiers and learning records are retained only for the duration of the active school license or user subscription.
- Device Deactivation: Users can release device licenses at any time directly within the TV UI (Settings > Deactivate Device).
- Data Deletion Requests: Educational institutions, teachers, parents, and users may request the permanent deletion of their account records, device bindings, or progress logs by emailing info@iit.vn with the subject line "Data Deletion Request". Requests are verified and processed within 30 days.
8. Contact Information
For any inquiries, feedback, or data privacy requests, please contact our Data Protection Office: