Privacy Policy

BanaNext is committed to protecting customer information and operational data through appropriate measures, maintaining transparency on how data is collected, used, stored, and safeguarded throughout your platform usage.

Last updated: August 11, 2026

1. Operating Entity

BanaNext is developed and operated by KAILUMI TECH COMPANY LIMITED.

Company Name: KAILUMI TECH CO., LTD

Tax Identification Number: 1102180106

Address: No. 143 B2-H7 Street, Rivera 2 Area, Waterpoint Township, Ben Luc Commune, Tay Ninh Province, Vietnam

Email: tech@bananext.com

Website: bananext.com

Depending on the category of data and processing context, KaiLumi Tech acts as:

  • Personal Data Controller: For user account credentials and profiles (Admin, Area Production Supervisor, Team Leader) collected directly to provide access to the platform.
  • Personal Data Processor: For farm operational records (production plans, daily logs, inventory, lot-based traceability logs) submitted by the customer (farm). This data remains owned and controlled by the customer; KaiLumi Tech processes it strictly under the instructions and scope agreed upon in the B2B Service Contract. KaiLumi Tech adheres strictly to the least-privilege access principle - we do not inspect or monetize customer operational data beyond what is strictly necessary for service maintenance, technical support, or authorized requests.

2. Enterprise Accounts and Access Control

BanaNext implements dedicated enterprise governance for B2B operations:

  • BanaNext features 3 fixed hierarchical roles: Administrator (Admin), Area Production Supervisor (GSSX), and Team Leader (Tổ trưởng).
  • Public self-registration is disabled. Only Farm Admins (authorized representatives of contracted customers) can provision accounts for internal staff.
  • The Farm Admin maintains full governance over staff access lifecycle (creating, modifying, suspending, or deleting accounts).
  • Staff usage of BanaNext may be subject to the customer farm's internal workplace policies in addition to this Privacy Policy.

3. Personal Data Collected

3.1. Account Data

Full name/display name, username, email address, phone number, encrypted password, and avatar.

3.2. Workforce Management Data

Worker full name, employment contract category (Permanent, Seasonal, Intern, Contractual, Other), team/crew assignments, and work task allocations.

3.3. Farm Operational Data

Plot-level cultivation configurations, weekly/daily production schedules, daily execution logs (work volume, inputs consumed, labor allocated), warehouse inventory records, and lot-level traceability histories.

3.4. Field Incident / Pest Reporting Data (Upcoming)

Field inspection photographs captured when Team Leaders report disease or pest incidents on specific plots.

3.5. Farm / Plot Geographic Coordinates

Manually configured coordinates entered by Admins during farm onboarding (e.g., plot boundaries), not real-time user GPS tracking. This represents fixed physical farm asset data, not personal location tracking.

3.6. Automatically Collected Data

  • Google Analytics (web and mobile application): Usage patterns, device telemetry, partially anonymized IP addresses, for product performance analytics and optimization.
  • Firebase Crashlytics (mobile application): Device specifications (model, OS version, app release), stack traces, and crash diagnostics to isolate bugs. Crash reports never ingest farm operational contents.

4. Purposes of Data Processing

  • Account creation, authentication, role-based authorization, and user directory management.
  • Powering platform modules: production scheduling, operational logging, inventory balancing, and workforce coordination.
  • Generating lot-based traceability certificates and audit dossiers for international export compliance (GlobalGAP, buyer audits).
  • Executing B2B service agreements and onboarding custom farm deployments.
  • Delivering technical support, incident troubleshooting, and client relationship management.
  • Complying with statutory regulatory mandates, fraud prevention, and system security safeguarding.
  • Refining product usability and performance based on aggregate system metrics.

Not applicable at current release: Automated profiling or behavioral advertising, as BanaNext does not participate in third-party advertising ecosystems.

5. Third-Party Data Sharing

  • Cloud Hosting & Compute: Google Cloud Run, region asia-southeast1 (Singapore) - Google Cloud Platform infrastructure under enterprise data processing terms.
  • Diagnostic & Analytics Tools: Google Analytics and Firebase Crashlytics (Google LLC) for technical monitoring.
  • Payment Gateways: Currently not integrated - transactions occur via direct corporate bank transfers under B2B contracts.
  • Regulatory & Law Enforcement Bodies: Only when required under mandatory legal process or statutory obligations.

KaiLumi Tech strictly prohibits selling, renting, or leasing user personal data to third parties for commercial advertising purposes.

6. Rights of Data Subjects

Users hold standard data protection rights regarding their personal data under applicable laws:

  • Right to be informed regarding processing activities of your personal data.
  • Right to access and correct personal details via the in-app User Profile settings.
  • Right to withdraw consent, restrict processing, or object to processing.
  • Right to request data erasure subject to legal and contractual limits.

Data Erasure Workflow and Limitations

For Farm-provisioned accounts (Team Leaders, Supervisors): Please contact your Farm Administrator first to request account deactivation or removal - this represents the fastest escalation path as Admins manage workforce lifecycles directly.

Direct Escalation to KaiLumi Tech: If your Admin is unresponsive or in case of a dispute, submit a verified request directly to privacy@bananext.com. Validated requests are processed at the platform level within 30 business days.

Identifiable Personal Data: Full names, phone numbers, email addresses, login passwords, and avatars are purged completely upon verified request.

Operational Records Tied to Export Compliance: Under Vietnamese law and export standard covenants, historical operational logs, chemical sprays, and lot records vital to maintaining the integrity of GlobalGAP export audits cannot be completely expunged. Instead, personal identifiers are fully anonymized (replaced with generic system aliases), while objective operational metrics remain preserved.

Full Farm Data Purge Requests: Must be officially executed by the legal representative of the farm entity, verified via corporate channels, and governed by the termination terms in the B2B Service Agreement. Tax invoices and fiscal accounting records are retained for a statutory minimum of 10 years per Vietnamese Accounting Law.

7. Data Retention Schedule

Data CategoryPost-Termination Retention Period
User Account Profile Data (Name, Email, Phone)30 calendar days, preceded by email notification before permanent deletion
Farm Operations / Lot Traceability Audit HistoryMinimum 3 months, extendable upon written customer request prior to expiration

Where specific statutes mandate longer retention (e.g., retaining security incident dossiers for 5 years pursuant to Decree 356/2025/ND-CP), KaiLumi Tech strictly complies with the prevailing legal mandate.

8. Data Security Architecture

KaiLumi Tech deploys enterprise-grade technical and organizational safeguards:

  • Multi-Tenant Isolation: Every record is segmented by farm_id and enforced at the database layer (Row-Level Security) to guarantee Farm A can never view Farm B's records.
  • Granular Role-Based Access: Team Leaders only access assigned plots; Supervisors and Admins have permission-governed scopes.
  • Robust Authentication: Passwords are protected using secure cryptographic hashing before storage.
  • Encryption in Transit: All client-server transmissions are strictly encrypted via TLS/HTTPS protocols.

While we enforce rigorous defensive security controls, no internet communication can be guaranteed 100% immune from unauthorized intrusions. KaiLumi Tech pledges prompt response, transparency, and full legal incident reporting.

9. Breach Notification and Incident Response

  • Affected Customer Notification: Within 24 business hours from confirmed security incident validation - exceeding statutory minimum standards.
  • Cybersecurity Authority Notification (Ministry of Public Security): Within 72 hours from incident detection per Decree 356/2025/ND-CP Form 08.
  • Geographic Coordinate Breach Special Notice: Direct notification to impacted subjects within 72 hours alongside regulatory reporting.
  • Incident Record Archival: Complete incident audit logs are preserved for at least 5 years following resolution.

10. Cookies and Tracking Technologies

  • Session Cookies: Strictly necessary cookies storing session tokens to sustain secure user authentication states across browser refreshes.
  • Analytical Cookies: Google Analytics cookies evaluating aggregate product interactions to guide platform feature enhancements.

KaiLumi Tech does not deploy third-party advertising cookies or cross-site tracking scripts.

11. Data Protection Officer (DPO)

KaiLumi Tech has appointed a designated data protection lead to receive and handle inquiries, rights exercises, and grievances:

Email: privacy@bananext.com

Operational Lead: Supervised directly by our CTO, ensuring strict adherence to response SLAs (30 days for erasure requests, 24 business hours for security incidents).

12. Policy Revisions

KaiLumi Tech may revise this Privacy Policy periodically to reflect evolving platform features or regulatory updates. Substantial amendments will be notified via email or platform banners before taking effect. The date of the latest update is always displayed at the top of this document.

13. Contact Channels

Technical and Product Support: tech@bananext.com

Data Protection and Subject Rights: privacy@bananext.com

How is your plantation currently managed?

If the answer is still Excel and Zalo - let us show you a better way!

Book a Demo