Direct answer
This page explains the rules and data practices that apply to d2group.co.
Client proposals and signed agreements can define additional or different terms for a specific engagement. Where a signed agreement conflicts with general website language, the engagement document governs that scope.
Data controller
D2 GROUP SERVICES CO.,LTD
D2 Group operates d2group.co from 3 Nguyen Co Thach Street, An Khanh Ward, Ho Chi Minh City, Vietnam. Privacy and data-related requests can be sent to [email protected].
Data collected
D2 collects information required to respond, measure, secure and deliver services.
Depending on how you interact with D2, this can include company or brand name, contact details, inquiry notes, selected service intent, landing page, referrer, campaign parameters, advertising click identifiers, technical request information used for abuse prevention and consented website analytics or monitoring events.
- Contact and company information submitted through an inquiry.
- Service context, operating problem and project notes you choose to provide.
- Attribution data such as referrer, UTM parameters and supported advertising click identifiers.
- After optional analytics consent, Search OS Monitor can process a session-scoped identifier, page path, browser/device/locale/timezone context, referrer host, viewport or connection context, Core Web Vitals, limited rendered-DOM measurements and browser/runtime errors.
- Necessary technical and consent signals used to operate the website and remember the visitor's privacy choice.
Purpose
Data is used for inquiries, delivery, attribution, website improvement and security.
D2 may use information to respond to requests, prepare proposals, operate Commerce or Automation engagements, measure lead sources, troubleshoot systems, prevent spam and protect infrastructure. D2 does not sell personal data to advertisers.
Website infrastructure
Service providers and D2-owned systems process limited data where needed to operate and measure the website.
The website uses D2 Search OS for consented technical/runtime monitoring and D2's server-side contact workflow for validated inquiry handling and downstream delivery. Hosting, network and other infrastructure providers can process technical request data as needed to serve and secure the site; this policy does not infer a provider or data practice that is not verified by the current implementation.
Automation engagements
Client automation projects can involve additional systems selected for the agreed workflow.
An Automation engagement can require access to client APIs, databases, CRM, email, cloud services, AI providers or other SaaS products. The proposal or implementation scope should identify the systems involved, access method and relevant data categories. Additional data-processing instructions or agreements can be established where required by the engagement.
Credentials & secrets
Credentials are treated differently from ordinary contact data.
D2 aims to use scoped service accounts, tokens and least-privilege access where the connected platform allows it. Secrets should be stored in appropriate credential or environment-secret systems rather than embedded in public website content or case-study artifacts.
Consent
Optional analytics, monitoring and chat scripts are not required for core website functions.
Visitors can choose necessary-only mode. D2 Search OS Monitor and GA4 are loaded only after the website records consent for optional analytics. The preference is stored locally in the browser and can be reset by clearing site data or through available privacy controls.
Security & retention
Security controls are explicit; retention depends on the system and verified purpose.
D2 applies server-side validation, abuse controls and operational access controls. A contact submission is persisted before downstream webhook delivery; if durable persistence fails, the endpoint returns an error. If webhook delivery fails after persistence, the endpoint returns an error/queued state instead of presenting confirmed delivery. This page does not assign a universal retention period from website code: downstream retention depends on the verified system, lead or customer context and applicable requirements. Search OS telemetry retention is controlled by the Search OS system and is not inferred here.
International processing
Some service providers may process or route data across jurisdictions.
Cloud, analytics, SaaS and automation providers may operate infrastructure in multiple countries. Where legal or contractual requirements apply to a client engagement, D2 and the client can define appropriate processing instructions and provider restrictions in the relevant agreement.
Your requests
You can request access, correction, update or deletion.
Contact [email protected]. D2 may need to verify identity or authority before completing a request, and may retain information where required for security, contractual or legal reasons.
Changes
This policy may be updated when D2 systems, providers or legal requirements change.
The current version and update date will be published on this page.
