Skip to main content
D2 Group
D2 Group · LegalUpdated 26 Sep 2026

Privacy Policy

D2 GROUP SERVICES CO.,LTD (Tax ID 3603788837) operates d2group.co. This policy explains how D2 handles personal, business and technical data across website inquiries and service delivery.

Controller

D2 GROUP SERVICES CO.,LTD

Primary use

Inquiries, delivery, attribution, security and consented website improvement

Direct answer

This page explains the rules and data practices that apply to d2group.co.

Client proposals and signed agreements can define additional or different terms for a specific engagement. Where a signed agreement conflicts with general website language, the engagement document governs that scope.

01

Data controller

D2 GROUP SERVICES CO.,LTD

D2 Group operates d2group.co from 3 Nguyen Co Thach Street, An Khanh Ward, Ho Chi Minh City, Vietnam. Privacy and data-related requests can be sent to [email protected].

02

Data collected

D2 collects information required to respond, measure, secure and deliver services.

Depending on how you interact with D2, this can include company or brand name, contact details, inquiry notes, selected service intent, landing page, referrer, campaign parameters, advertising click identifiers, technical request information used for abuse prevention and consented website analytics or monitoring events.

  • Contact and company information submitted through an inquiry.
  • Service context, operating problem and project notes you choose to provide.
  • Attribution data such as referrer, UTM parameters and supported advertising click identifiers.
  • After optional analytics consent, Search OS Monitor can process a session-scoped identifier, page path, browser/device/locale/timezone context, referrer host, viewport or connection context, Core Web Vitals, limited rendered-DOM measurements and browser/runtime errors.
  • Necessary technical and consent signals used to operate the website and remember the visitor's privacy choice.
03

Purpose

Data is used for inquiries, delivery, attribution, website improvement and security.

D2 may use information to respond to requests, prepare proposals, operate Commerce or Automation engagements, measure lead sources, troubleshoot systems, prevent spam and protect infrastructure. D2 does not sell personal data to advertisers.

04

Website infrastructure

Service providers and D2-owned systems process limited data where needed to operate and measure the website.

The website uses D2 Search OS for consented technical/runtime monitoring and D2's server-side contact workflow for validated inquiry handling and downstream delivery. Hosting, network and other infrastructure providers can process technical request data as needed to serve and secure the site; this policy does not infer a provider or data practice that is not verified by the current implementation.

05

Automation engagements

Client automation projects can involve additional systems selected for the agreed workflow.

An Automation engagement can require access to client APIs, databases, CRM, email, cloud services, AI providers or other SaaS products. The proposal or implementation scope should identify the systems involved, access method and relevant data categories. Additional data-processing instructions or agreements can be established where required by the engagement.

06

Credentials & secrets

Credentials are treated differently from ordinary contact data.

D2 aims to use scoped service accounts, tokens and least-privilege access where the connected platform allows it. Secrets should be stored in appropriate credential or environment-secret systems rather than embedded in public website content or case-study artifacts.

08

Security & retention

Security controls are explicit; retention depends on the system and verified purpose.

D2 applies server-side validation, abuse controls and operational access controls. A contact submission is persisted before downstream webhook delivery; if durable persistence fails, the endpoint returns an error. If webhook delivery fails after persistence, the endpoint returns an error/queued state instead of presenting confirmed delivery. This page does not assign a universal retention period from website code: downstream retention depends on the verified system, lead or customer context and applicable requirements. Search OS telemetry retention is controlled by the Search OS system and is not inferred here.

09

International processing

Some service providers may process or route data across jurisdictions.

Cloud, analytics, SaaS and automation providers may operate infrastructure in multiple countries. Where legal or contractual requirements apply to a client engagement, D2 and the client can define appropriate processing instructions and provider restrictions in the relevant agreement.

10

Your requests

You can request access, correction, update or deletion.

Contact [email protected]. D2 may need to verify identity or authority before completing a request, and may retain information where required for security, contractual or legal reasons.

11

Changes

This policy may be updated when D2 systems, providers or legal requirements change.

The current version and update date will be published on this page.

Questions about this policy

Need clarification about privacy, cookies or website terms?

Contact D2 directly. For client-specific processing, access or contractual requirements, include the relevant engagement or system context.

[email protected]