Privacy Policy
This Privacy Policy explains how Lao Smart Mobility Co., Ltd. (referred to as the “Company,” “we,” “us,” or “our”) collects, uses, discloses, and processes your Personal Data when you use our application (including KOKKOK), websites, and related services (collectively referred to as the “App” or “Services”).
Please read this Privacy Policy carefully before accessing or using our Services. By using the Services, you acknowledge and agree to the collection, use, disclosure, and processing of your Personal Data as described in this Privacy Policy.
I. COLLECTION OF PERSONAL DATA
- Service Provision and Fee Settlement: Content provision, identity verification, purchase and payment processing.
- Customer Management: Customer service use, personal identification, dispute resolution, notifications, and prevention of underage registration (under 14).
- Marketing and Service Development: New service development, personalized service, user analytics.
- Automatically Collected Data and Generated Data
- Device and Usage Information:
- Browser type, operating system, device model name
- Search items, service usage records, and error logs
- Access and Activity Data:
- IP address, visit date and time, usage history, misuse or violation history, and cookies
- Transaction and Support Data:
- Payment records, Order details, and transaction history
- Inquiry and complaint records submitted via customer support
- Event-Related or Interest-Based Collection:
- Search history, participation in events, and data required for physical fulfillment
- Online Channels: Through the website, mobile application, 1:1 inquiries, emails, and event participation (with prior consent for the use of name and contact information)
- Customer Support: Through the customer service center via email, fax, telephone, live chat, and remote consultation tools
- Third-Party Sources: From affiliated partners and financial institutions (e.g., via IB API integrations for identity verification during top-up or payment services)
- Automated Tools: Using cookies and log analysis tools that collect data during service usage
- Offline Methods: Through in-person interactions with seller or branch staff during service registration or application
1. Collection of Personal Data
The Company collects the minimum amount of personal data necessary for the provision of its services. Sensitive information is not collected unless required by law or explicitly consented to by the user. Customers may refuse to provide personal data; however, refusal of essential data may limit access to certain services.
Registration Type Collection of data Collection and Operation Purpose Personal Customer Registration Essential Name, Password, UUID(Universally Unique Identifier), Contact Number(Mobile number), Email, Date of Birth Optional Gender Marketing, service personalization Mobile App Use & Events Essential APP ID, Push ID, Device Token Delivery of push notifications. Participation in certain events may require consent to receive push notifications. Device Permissions Optional Camera Access Used for Offline QR Payment and Lao Label (Barcode scanning). Images are not stored on our servers. 2. Types of Personal Data Collected
In certain cases, the Company may collect data related to a Customer’s interests or participation in events, including:
3. Methods of Collection
The Company collects personal data through the following lawful and fair means:
II. USE OF PERSONAL DATA
- The Company uses your Personal Data to provide, personalize, maintain, and improve the App, including to:
- Enable service provision across all business verticals.
- Register, identify, manage, and deactivate user accounts.
- Process and verify eligibility for services, promotions, and rewards.
- Conduct due diligence and risk assessments.
- Verify user identity and age, where necessary.
- Process payments and transactions.
- Personalize the user experience (e.g., service recommendations, preference recognition).
- Perform internal operations such as error detection, data analysis, testing, and performance monitoring.
- Safeguard the integrity and security of the App, services, and related systems.
- The Company uses Personal Data to ensure the safety and integrity of all users, including Customers, Sellers, and Branches. This includes:
- Screening and verifying the identity of Sellers and Branches before enabling them to offer services.
- Verifying user identity (including Customers) during login or critical transactions.
- Detecting, preventing, and responding to fraud, misuse, or any unsafe or suspicious activity by analyzing device data, location, profile information, and usage behavior.
- Sharing relevant service provider or delivery personnel details (such as name and location) with Customers for transparency and safety when a service is accepted or underway.
- Monitoring compliance with the Terms and Conditions, operational policies, and applicable legal requirements.
- Implementing safeguards to protect all users from abuse, harassment, or exploitation on the platform.
- The Company uses Personal Data to manage customer service and resolve support issues. This includes:
- Investigating and resolving complaints or disputes.
- Monitoring and improving support service quality.
- Responding to inquiries, feedback, and comments.
- Informing users about the status or outcome of their support requests.
- The Company may process Personal Data for purposes such as:
- Conducting tests, analysis, and research.
- Understanding user needs and preferences.
- Enhancing the security and functionality of the App.
- Developing new products, features, or service offerings.
- Facilitating development of financial or insurance-related solutions.
- The Company may use your Personal Data to comply with legal obligations or defend its rights, including to:
- Investigate or resolve claims or disputes.
- Prevent, detect, and prosecute criminal or unlawful conduct.
- Comply with applicable laws, court orders, or requests from regulatory authorities.
- Enforce the Terms and Conditions or other contractual obligations.
- Protect Company assets, personnel, and interests.
- The Company may use Personal Data to send marketing or promotional communications about services that may be relevant to you or offered by third-party partners, including to:
- Calculate Membership Levels based on actual payment amounts.
- Send promotional materials, offers, updates, newsletters, and marketing communications related to the Service or partner benefits.
- Marketing communications may be delivered through various channels, including SMS, email, push notifications, social media, phone calls, or other communication channels operated by the Company.
- Customers may opt out of receiving marketing communications at any time by using the unsubscribe option in messages or adjusting notification settings in the App. However, service-related notifications (e.g., transaction alerts, membership updates, or reward notifications) may still be delivered as necessary for the operation of the Service.
The Company may use your Personal Data for the purposes outlined below (the “Purposes”). If you use multiple KOKKOK services (for example, as both a Customer and a Seller or Branch), the Company may link your Personal Data across these roles to ensure seamless service delivery and effective support for the Purposes.
1. Provision of Services and Features
2. Safety and security
3. User support
4. Research, Development, and Security
5. Legal and Compliance Purposes
6. Marketing and Promotions
III. DISCLOSURE OF PERSONAL DATA
- The Company will not disclose users’ Personal Data to external parties without prior consent, except in the following cases:
- When the user has given explicit consent;
- When it is necessary to perform a contract or provide services requested by the user, and obtaining prior consent is impractical due to economic or technical constraints;
- When required by law, or in response to lawful requests by government or investigative authorities;
- When personal information is provided to third-party service providers essential to operating the app, with separate user consent acquired for such provision.
- We may disclose Personal Data to trusted business partners and service providers who assist us in delivering our services, including:
- Payment gateways and financial institutions;
- Credit bureaus and scoring agencies;
- Debt collection agencies;
- Cloud hosting and data storage providers;
- Background screening and anti-fraud solution providers;
- Analytics and advertising partners;
- Customer support and training institutions;
- Marketing and event partners;
- Insurance and financing companies.
- We may disclose Personal Data to legal advisors, enforcement agencies, or regulatory authorities when necessary for:
- Compliance with legal obligations, court orders, or investigations;
- Protection of the rights, property, or safety of the Company, its users, or the public;
- Response to emergencies involving health or safety risks;
- Fulfillment of obligations in the public interest, such as public health measures or contact tracing.
- In the event of a business transaction such as a merger, acquisition, asset sale, financing, or corporate restructuring, your Personal Data may be transferred to another entity. Any such transfer will be subject to the commitments made in this Privacy Policy, unless otherwise agreed.
- Users may choose to share certain Personal Data through specific functions within the App (such as referrals, delivery instructions, or gifting services). In such cases, the Company facilitates this sharing at the user's discretion and is not responsible for third-party usage outside the agreed scope.
We may need to share Personal Data with third parties in order to operate effectively, fulfill our legal obligations, and deliver our services. The Company ensures that all disclosures are made in accordance with applicable laws and with due regard to the protection of users' privacy. Such third parties may include trusted business partners and service providers who assist us in operating the Service, including Indochina Bank (for payment gateways and Wallet/Account linkage), cloud hosting providers, and legal advisors.
1. Disclosure to Third Parties
2. Disclosure to Business Partners and Service Providers
3. Disclosure to Legal Advisors and Government Authorities
4. Business Transfers
5. User-Initiated Sharing
IV. RETENTION OF PERSONAL DATA
- Your Personal Data may be retained for the following reasons:
- To provide services and fulfill transactions.
- To comply with legal, tax, accounting, or regulatory obligations.
- To resolve disputes, enforce our agreements, or protect our rights.
- For fraud prevention, security monitoring, or business continuity purposes.
- The specific retention period may vary depending on the type of Personal Data, your relationship with us (e.g. customer, seller, branch, or business partner), and applicable legal requirements.
- When a Customer requests account termination, the account may undergo a "Soft Delete" process. To prevent abuse and fraudulent promotional gains, the Customer's mobile number hash may be retained for seven (7) days, during which re-registration is prohibited. After this period, the data will be permanently deleted or anonymized unless legal retention is required.
We retain your Personal Data for as long as it is necessary to fulfill the purposes outlined in this Privacy Policy. Once your Personal Data is no longer needed for these purposes, we will take reasonable steps to delete, anonymize, or restrict access to your data, unless a longer retention period is required or permitted by law.
1. Retention Period
2. Secure Disposal and Soft Deletion
V. INTERNATIONAL TRANSFERS OF PERSONAL DATA
- We may transfer Personal Data across borders to support the following:
- Processing orders involving international import/export or delivery fulfillment.
- Payment processing or verification through international partners.
- Operation of centralized infrastructure, including cloud servers or customer service centers located abroad.
- Providing services to users accessing the KOKKOK platform from outside the Home Country.
- If you access or use our services from outside of Laos (or your primary registration country), please note that your Personal Data may be transferred to and processed in Laos or other jurisdictions where we or our partners are based.
- By using our services, you acknowledge and agree to such international transfers, which are necessary for contract performance or service delivery.
- We implement appropriate legal and technical safeguards to protect your Personal Data during such transfers, including:
- Ensuring that the recipient country has laws affording comparable data protection.
- Requesting your express consent where required by applicable law.
- Transfers are carried out on one of the following legal bases:
- Your explicit consent, where required.
- The necessity of the transfer for the performance of a contract with you.
- Legal obligations or legitimate business interests that comply with privacy regulations.
- We transfer only the minimum amount of data necessary for the stated purpose.
- Sensitive or special categories of data are not transferred internationally without adequate protection and specific legal basis.
- You may have rights under applicable laws to request more information about the international transfer of your Personal Data or to object to such transfers under certain circumstances.
- If you have questions, please contact us using the details provided in Article IX.
Your Personal Data may be transferred to, stored in, or processed in countries other than your country of residence or location (“Home Country”), including jurisdictions where our Branches, service providers, or business partners operate. This may also involve interactions with Sellers who are independent from the Company but participate in cross-border transactions on the platform.
This applies particularly to cross-border transactions, international deliveries, and services involving overseas users, Sellers, Branches, or payment processors.
1. Purpose of International Transfers
2. International Users
3. Safeguards and Legal Basis
4. Data Minimization
5. Your Rights
VII. PROTECTION OF PERSONAL DATA
- The Company implements appropriate legal, organizational, and technical measures to protect your Personal Data against unauthorized access, collection, use, disclosure, copying, modification, disposal, or other similar risks.
- These measures include, but are not limited to:
- Data encryption and secure data storage protocols
- Firewalls, anti-malware software, and intrusion detection systems
- Secure authentication and access controls
- Routine system monitoring, vulnerability assessments, and audits
- Access to your Personal Data is strictly limited to authorized personnel of the Company and only on a need-to-know basis.
- All employees and authorized personnel who process Personal Data are bound by confidentiality obligations and are subject to internal disciplinary procedures or legal actions in the event of any violation.
- The Company provides regular training and awareness programs to employees and contractors regarding Personal Data protection, security best practices, and compliance responsibilities.
- The Company maintains a formal incident response plan to detect, manage, and respond to Personal Data breaches.
- In the event of a breach, the Company will notify affected users and relevant regulatory authorities in accordance with applicable laws and regulations.
- Despite the Company’s efforts, please be aware that no method of transmission over the internet or method of electronic storage is completely secure.
- While the Company will make reasonable efforts to protect your Personal Data, any transmission is at your own risk.
1. Security Measures
2. Access Control
3. Employee Training and Awareness
4. Incident Response
5. Limitations
VIII. YOUR RIGHTS WITH RESPECT TO YOUR PERSONAL DATA
- Access: Request information regarding the processing of your Personal Data and obtain a copy of such data.
- Correction and Deletion: Request the correction of inaccurate Personal Data or the deletion of Personal Data where permitted.
- Restriction and Objection: Request the restriction of processing or object to the processing of your Personal Data in certain circumstances.
- Consent Withdrawal: Withdraw your consent to the processing of your Personal Data where such processing is based on consent.
- Data Portability: Request to receive or have your Personal Data transmitted to another organization in a structured, commonly used, and machine-readable format, where processing is based on consent or contract.
- Lodge a Complaint: File a complaint with a relevant data protection authority if you believe your data rights have been infringed or your Personal Data has been unlawfully processed.
- Where you are given the choice to provide your Personal Data, you may choose not to do so.
- If you withdraw your consent or object to the processing of your Personal Data, we will respect your decision in accordance with applicable laws.
- However, such withdrawal or refusal may affect your ability to access or use certain services, functionalities, or features of the KOKKOK app, particularly where the processing is essential to service delivery, as outlined in Article II (Use of Personal Data).
- In particular, if you withdraw your consent to receive push notifications or marketing communications, you may be restricted from participating in certain promotional events or in-app programs offered through the Service.
- All data subject requests will be screened and verified. To confirm your identity or authority to make the request, we may require supporting documentation or information.
- Upon successful verification, we will respond to and process your request within the timeframe prescribed by applicable laws and regulations.
1. Overview of Data Subject Rights
In accordance with applicable data protection laws and regulations, you may exercise the following rights with respect to your Personal Data, subject to legal limitations and verification procedures:
2. Implications of Withholding or Withdrawing Consent
3. Verification and Processing of Requests
4. Legal Basis for Continued Processing
Even if you withdraw your consent, the Company may continue to process your Personal Data if required or otherwise permitted by applicable laws, such as for legal obligations, fraud prevention, or the establishment, exercise, or defense of legal claims.
IX. AMENDMENTS AND UPDATES
- The Company may amend, update, or revise the terms of this Privacy Policy at any time to reflect changes in legal requirements, business operations, or service offerings.
- Any such amendments will be communicated to you through the KOKKOK app and/or other appropriate channels at least seven (7) business days prior to the effective date of the changes.
The updated version of the Privacy Policy will be posted on our official website at https://laosmartmobility.com.
- It is your responsibility to periodically review the Privacy Policy to stay informed about any updates or changes.
1. Changes to the Privacy Policy
2. Notification and Effectiveness
3. Continued Use as Agreement
Your continued use of the KOKKOK app, or continued communication or engagement with the Company following the effective date of any amendments, constitutes your acceptance of and agreement to be bound by the revised Privacy Policy, regardless of whether you have reviewed it.
X. HOW TO CONTACT US
E-mail: contact@laosmartmobility.com
- Company Name: Lao Smart Mobility Co., Ltd (Attention: Lao Smart Mobility Privacy Office)
- Address: ASEAN Road (T2), Nongdouang Village, Sikhottabong District, Vientiane Capital, Lao PDR
1. Contact Information
If you have any questions, concerns, or requests related to this Privacy Policy, or if you wish to exercise any of your rights regarding your Personal Data, please contact our Data Protection Officer using the details below:
2. Language Version
This Privacy Policy is originally written in English. In the event of any discrepancy or conflict between the English version and any translated version, the English version shall prevail.
3. Effective Date
This Privacy Policy was last updated on April 1, 2026.