Privacy Notice
Last Updated: January 2019
SCOPE OF THIS NOTICE
Please read this privacy notice (“Notice”) carefully to understand our policies and practices regarding your Personal Data and how we will treat it. This Notice applies to individuals who interact with Nestlé services as consumers (“you”). This Notice explains how your Personal Data are collected, used, and disclosed by Nestlé Middle East FZE (“Nestlé”, “We”, Us”). It also tells you how you can access and update your Personal Data and make certain choices about how your Personal Data are used.
This Notice covers both our online and offline data collection activities, including Personal Data that We collect through our various channels such as websites, apps, third party social networks, Consumer Engagement Service, points of sale and events. Please note that We might aggregate personal data from different sources (website, offline event).As part of this, We combine Personal Data that were originally collected by different Nestlé entities or Nestlé partners. Please see (Section 9) for further information on how to object to this.
If you do not provide necessary Personal Data to us (We will indicate to you when this is the case, for example, by making this information clear in our registration forms), We may not be able to provide you with our goods and/or services. This Notice can change from time to time (see Section 11).
This Notice provides important information in the following areas:
- SOURCES OF PERSONAL DATA
- PERSONAL DATA THAT WE COLLECT ABOUT YOU AND HOW WE COLLECT IT
- PERSONAL DATA OF CHILDREN
- COOKIES/SIMILAR TECHNOLOGIES, LOG FILES AND WEB BEACONS
- USES MADE OF YOUR PERSONAL DATA
- DISCLOSURE OF YOUR PERSONAL DATA
- RETENTION OF PERSONAL DATA
- STORAGE AND/OR TRANSFER OF YOUR PERSONAL DATA
- ACCESS TO YOUR PERSONAL DATA
- YOUR CHOICES ABOUT HOW WE USE AND DISCLOSE YOUR PERSONAL DATA
- CHANGES TO OUR NOTICE
- DATA CONTROLLERS & CONTACT
1. SOURCES OF PERSONAL DATA
This Notice applies to Personal Data that We collect from or about you, through
the methods described below (see Section 2) from the following sources:
Nestlé websites.Consumer-directed websites operated by or for
Nestlé, including sites that We operate under our own domains/URLs and mini-sites
that We run on third party social networks such as Facebook (“Websites”).
Nestlé mobile sites/apps.Consumer-directed mobile sites or applications
operated by or for Nestlé, such as smartphone apps.
E-mail, text and other electronic messages.Interactions with electronic
communications between you and Nestlé.
NestléCCCC.Communications with our Consumer Conversation and Care
Center (“CCCC”).
Offline registration forms.Printed or digital registration and
similar forms that We collect via, for example, postal mail, in-store demos, contests
and other promotions, or events.
Advertising interactions.Interactions with our advertisements
(e.g., if you interact with on one of our ads on a third party website, we may receive
information about that interaction).
Data We create.In the course of our interactions with you, we
may create Personal Data about you (e.g. records of your purchases from our websites).
Data from other sources. Third party social networks (e.g. such
as Facebook, Google), market research (if feedback not provided on an anonymous
basis), third party data aggregators, Nestlé promotional partners, public sources
and data received when we acquire other companies.
2. PERSONAL DATA THAT WE COLLECT ABOUT YOU AND HOW WE COLLECT IT
Depending on how you interact with Nestlé (online, offline, over the phone, etc.),
We collect various types of information from you, as described below.
Personal contact information. This includes any information you
provide to Us that would allow Us to contact you, such as your name, postal address,
e-mail address, social network details, or phone number
Account login information. Any information that is required to
give you access to your specific account profile. Examples include your login ID/email
address, screen name, password in unrecoverable form, and/or security question and
answer.
Demographic information & interests.Any information that describes
your demographic or behavioural characteristics. Examples include your date of birth,
age or age range, gender, geographic location (e.g. postcode/zip code), favourite
products, hobbies and interests, and household or lifestyle information.
Information from computer/mobile device.Any information about
the computer system or other technological device that you use to access one of
our Websites or apps, such as the Internet protocol (IP) address used to connect
your computer or device to the Internet, operating system type, and web browser
type and version. If you access a Nestlé website or app via a mobile device such
as a smartphone, the collected information will also include, where permitted, your
phone’s unique device ID, advertising ID, geo-location, and other similar mobile
device data.
Websites/communication usage information. As you navigate through
and interact with our Websites or newsletters, We use automatic data collection
technologies to collect certain information about your actions. This includes information
such as which links you click on, which pages or content you view and for how long,
and other similar information and statistics about your interactions, such as content
response times, download errors and length of visits to certain pages. This information
is captured using automated technologies such as cookies and web beacons, and is
also collected through the use of third party tracking for analytics and advertising
purposes. You have the right to object to the use of such technologies, for further
details please see Section 4.
Market research & consumer feedback.Any information that you voluntarily
share with Us about your experience of using our products and services.
Consumer-generated content.Any content that you create and then
share with Us on third party social networks or by uploading it to one of our Websites
or apps, including the use of third party social network apps such as Facebook.
Examples include photos, videos, personal stories, or other similar media or content.
Where permitted, We collect and publish consumer-generated content in connection
with a variety of activities, including contests and other promotions, website community
features, consumer engagement, and third party social networking.
Third party social network information. Any information that you
share publicly on a third party social network or information that is part of your
profile on a third party social network (such as Facebook) and that you allow the
third party social network to share with Us. Examples include your basic account
information (e.g. name, email address, gender, birthday, current city, profile picture,
user ID, list of friends, etc.) and any other additional information or activities
that you permit the third party social network to share. We receive your third party
social network profile information (or parts of it) every time you download or interact
with a Nestlé web application on a third party social network such as Facebook,
every time you use a social networking feature that is integrated within a Nestlé
site (such as Facebook Connect) or every time you interact with Us through a third
party social network. To learn more about how your information from a third party
social network is obtained by Nestlé, or to opt-out of sharing such social network
information, please visit the website of the relevant third party social network.
Payment and Financial information.Any information that We need
in order to fulfil an order, or that you use to make a purchase, such as your debit
or credit card details (cardholder name, card number, expiration date, etc.) or
other forms of payment (if such are made available). In any case, We or our payment
processing provider(s) handle payment and financial information in a manner compliant
with applicable laws, regulations and security standards such as PCI DSS.
Calls to Consumer Conversation and Care Center. Communication with
a CCCC can be recorded or listened into, in accordance with applicable laws, for
local operational needs (e.g. for quality or training purposes). Payment card details
are not recorded. Where required by law, you will be informed about such recording
at the beginning of your call.
Sensitive Personal Data.We do not seek to collect or otherwise
process sensitive personal data in the ordinary course of our business. Where it
becomes necessary to process your sensitive personal data for any reason, we rely
on your prior express consent for any processing which is voluntary (e.g. for marketing
purposes). If we process your sensitive personal data for other purposes, we rely
on the following legal bases: (i) detection and prevention of crime (including the
prevention of fraud); and (ii) compliance with applicable law (e.g. to comply with
our diversity reporting).
3. PERSONAL DATA OF CHILDREN
We do not knowingly solicit or collect personal data from children below the age of 13. If we discover that we have unintentionally collected personal data from a child below 13, we will remove that child’s personal data from our records promptly. However, Nestlé may collect personal data about children below the age of 13 years of age from the parent or guardian directly, and with that person’s explicit consent.
4. COOKIES/SIMILAR TECHNOLOGIES, LOG FILES AND WEB BEACONS
Cookies/Similar Technologies.Please see our Cookie Notice to learn how you can manage your cookie settings
and for detailed information on the cookies We use and the purposes for which We
use them.
Log Files.We collect information in the form of log files that
record website activity and gather statistics about your browsing habits. These
entries are generated automatically, and help Us to troubleshoot errors, improve
performance and maintain the security of our Websites.
Web Beacons. Web beacons (also known as “web bugs”) are small strings
of code that deliver a graphic image on a web page or in an email for the purpose
of transferring data back to Us. The information collected via web beacons will
include information such as IP address, as well as information about how you respond
to an email campaign (e.g. at what time the email was opened, which links you click
on in the email, etc.). We will use web beacons on our Websites or include them
in e-mails that We send to you. We use web beacon information for a variety of purposes,
including but not limited to, site traffic reporting, unique visitor counts, advertising,
email auditing and reporting, and personalisation.
5. USES MADE OF YOUR PERSONAL DATA
The following paragraphs describe the various purposes for which We collect and use your Personal Data, and the different types of Personal Data that are collected for each purpose. Please note that not all of the uses below will be relevant to every individual.
What We use your Personal Data for |
Our reasons |
Our legitimate interests |
---|---|---|
Consumer service.We use your Personal Data for consumer service purposes, including responding to your enquiries. This typically requires the use of certain personal contact information and information regarding the reason for your inquiry (e.g. order status, technical issue, product question/complaint, general question, etc.). |
|
|
Contests, marketing and other promotions. With your consent (where required), We use your Personal Data to provide you with information about goods or services (e.g. marketing communications or campaigns or promotions). This can be done via means such as email, ads, SMS, phone calls and postal mailings to the extent permitted by applicable laws. Some of our campaigns and promotions are run on third party websites and/or social networks. This use of your Personal Data is voluntary, which means that you can oppose (or withdraw your consent in certain countries) to the processing of your Personal Data for this purposes. For detailed information on how to modify your preferences about marketing communication, please see Sections 9 and 10 below. For more information about our contests and other promotions, please see the official rules or details posted with each contest/promotion. |
|
|
Third party social networks: We use your Personal Data when you interact with third party social networking features, such as “Like” functions, to serve you with advertisements and engage with you on third party social networks. You can learn more about how these features work, the profile data that We obtain about you, and find out how to opt out by reviewing the privacy notices of the relevant third party social networks. |
|
|
Personalisation (offline and online). With your consent (where
required), We use your Personal Data (i) to analyse your preferences and habits,
|
||
Order fulfilment. We use your Personal Data to process and ship your orders, inform you about the status of your orders, correct addresses and conduct identity verification and other fraud detection activities. This involves the use of certain Personal Data and payment information. |
|
|
Other general purposes (e.g. internal or market research, analytic, security). In accordance with applicable laws, We use your Personal Data for other general business purposes, such as maintaining your account, conducting internal or market research and measuring the effectiveness of advertising campaigns. We reserve the right, if you have Nestlé accounts, to reconcile those accounts into one single account. We also use your Personal Data for management and operation of our communications, IT and security systems. |
||
Legal reasons or merger/acquisition. In the event that Nestlé or its assets are acquired by, or merged with, another company including through bankruptcy, we will share your Personal Data with any of our legal successors. We will also disclose your Personal Data to third parties (i) when required by applicable law; (ii) in response to legal proceedings; (iii) in response to a request from a competent law enforcement agency; (iv) to protect our rights, privacy, safety or property, or the public; or (v) to enforce the terms of any agreement or the terms of our Website. |
|
|
6. DISCLOSURE OF YOUR PERSONAL DATA
In addition to the Nestlé entities mentioned in the data controllers & contact section
(see Section 12), We share your Personal Data with the following types of third
party organisations:
Service providers.These are external companies that We use to
help Us run our business (e.g. order fulfilment, payment processing, fraud detection
and identity verification, website operation, market research companies, support
services, promotions, website development, data analysis, CRC, etc.). Service providers,
and their selected staff, are only allowed to access and use your Personal Data
on Our behalf for the specific tasks that they have been requested to carry out,
based on our instructions, and are required to keep your Personal Data confidential
and secure. [Where required by applicable law, you can obtain a list of the providers
processing your Personal Data (see Section 12 to contact Us).
Credit reporting agencies/debt collectors. To the extent permitted
by applicable law, credit reporting agencies and debt collectors are external companies
that We use to help Us to verify your creditworthiness (in particular for orders
with invoice) or to collect outstanding invoices.
Third party companies using Personal Data for their own marketing purposes.
Except in situations where you have given your consent, We do not license or sell
your Personal Data to third party companies for their own marketing purposes. Their
identity will be disclosed at the time your consent is sought.
Third party recipients using Personal Data for legal reasons or due to merger/acquisition.
We will disclose your Personal Data to third parties for legal reasons or in the
context of an acquisition or a merger (see Section 5 for details).
7. RETENTION OF YOUR PERSONAL DATA
In accordance with applicable laws, We will use your Personal Data for as long as necessary to satisfy the purposes for which your Personal Data was collected (as described in Section 5 above) or to comply with applicable legal requirements. Personal data used to provide you with a personalized experience (see Section 5 above for details) will be kept for a duration permitted by applicable laws.
8. DISCLOSURE, STORAGE AND/OR TRANSFER OF YOUR PERSONAL DATA
We use appropriate measures (described below) to keep your Personal Data confidential and secure. Please note, however, that these protections do not apply to information you choose to share in public areas such as third party social networks. People who can access your Personal Data. Your Personal Data will be processed by our authorised staff or agents, on a need to know basis, depending on the specific purposes for which your Personal Data have been collected (e.g. our staff in charge of consumer care matters will have access to your consumer record). Measures taken in operating environments. We store your Personal Data in operating environments that use reasonable security measures to prevent unauthorised access. We follow reasonable standards to protect Personal Data. The transmission of information via the Internet is, unfortunately, not completely secure and although We will do our best to protect your Personal Data, We cannot guarantee the security of the data during transmission through our Websites/apps. Measures We expect you to take. It is important that you also play a role in keeping your Personal Data safe and secure. When signing up for an online account, please be sure to choose an account password that would be difficult for others to guess and never reveal your password to anyone else. You are responsible for keeping this password confidential and for any use of your account. If you use a shared or public computer, never choose to have your login ID/email address or password remembered and make sure to log out of your account every time you leave the computer. You should also make use of any privacy settings or controls We provide you in our Website/app. Transfer of your Personal Data. Because of the international nature of our business, we may need to transfer your personal data within the Nestlé group, and to third parties as noted in Section 6 above, in connection with the purposes set out in this Privacy Notice. For this reason, we may transfer your personal data to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located.
9. YOUR RIGHTS
Access to Personal Data.You have the right to access, review and
request a physical or electronic copy of information held about you. You also have
the right to request information on the source of your Personal Data. These
rights can be exercised by sending Us an e-mail:ask@nestle-family.com
or writing to us at P.O Box 17327 Jebel Ali Free Zone – Dubai, United Arab Emirates,
attaching a copy of your ID or equivalent details (where requested by Us and permitted
by law). If the request is submitted by a person other than you, without providing
evidence that the request is legitimately made on your behalf, the request will
be rejected. Please note that any identification information provided to Us will
only be processed in accordance with, and to the extent permitted by applicable
laws.
Additional rights (e.g. modification, deletion of Personal Data).
Where provided by law, you can
(i) request deletion, the portability, correction
or revision of your Personal Data;
(ii) limit the use and disclosure of your Personal
Data; and
(iii) revoke consent to any of our data processing activities.
Please note that, in certain circumstances, We will not be able to delete your Personal
Data without also deleting your user account. We may be required to retain some
of your Personal Data after you have requested deletion, to satisfy our legal or
contractual obligations. We may also be permitted by applicable laws to retain some
of your Personal Data to satisfy our business needs.
Where available, our Websites have a dedicated feature through which you can review
and edit the Personal Data that you have provided.
Please note that We require our
registered consumers to verify their identity (e.g. login ID/email address, password)
before they can access or make changes to their account information. This helps
prevent unauthorised access to your account.
We hope that we can satisfy queries you may have about the way we process your Personal
Data. However, if you have unresolved concerns you also have the right to complain
to competent data protection authorities.
10. YOUR CHOICES ABOUT HOW WE USE AND DISCLOSE YOUR PERSONAL DATA
We strive to provide you with choices regarding the Personal Data that you provide
to Us. The following mechanisms give you the following control over your Personal
Data:
Cookies/Similar Technologies.You manage your consent via
(i) our
consent management solution or
(ii) your browser so as to refuse all or some cookies/similar
technologies, or to alert you when they are being used.
Please see Section 4 above.
Advertising, marketing and promotions.You can consent for your
Personal Data to be used by Nestlé to promote its products or services through tick-box(es)
located on the registration forms or by answering the question(s) presented by our
CCCC representatives. If you decide that you no longer wish to receive such communications,
you can subsequently unsubscribe from receiving marketing-related communications
at any time, by following the instructions provided in each such communication.
To unsubscribe from marketing communications sent by any medium, including third
party social networks, you can opt-out at any time by unsubscribing through links
available in our communications, logging into the Websites/apps or third party social
networks and adjusting your user preferences in your account profile by unchecking
the relevant boxes or by calling our CCCC. Please note that, even if you opt-out
from receiving marketing communications, you will still receive administrative communications
from Us, such as order or other transaction confirmations, notifications about your
account activities (e.g. account confirmations, password changes, etc.), and other
important non marketing related announcements.
Personalization (offline and online): Where required by law, if
you wish to have your Personal Data used by Nestlé to provide you with a personalized
experience/targeted advertising & content, you can indicate so through the relevant
tick-box(es) located on the registration form or by answering the question(s) presented
by our CCCC representatives. If you decide that you no longer wish to benefit from
this personalization, you can opt-out at any time by logging into the Websites/apps
and adjusting your user preferences in your account profile by unchecking the relevant
boxes or by calling our CCCC.
Targeted Advertising.We partner with ad networks and other ad
serving providers (“Advertising Providers”) that serve advertising on behalf of
Us and other non-affiliated companies on the Internet. Some of those advertisements
are tailored to your interests based on information collected on Nestlé sites or
on non-affiliated websites over time. You can visit www.aboutads.info/choices to
learn more about this type of advertising, as well as about how to opt-out of interest-based
advertising practices from companies that participate in the Digital Advertising
Alliance’s (“DAA”) self-regulatory program. Additionally, you can opt-out of this
type of advertising in mobile applications from companies that participate in the
DAA’s AppChoices app by downloading the app from the iOS or Android app store. You
can also stop the collection of precise location data from a mobile device by accessing
your device location service settings.
11. CHANGES TO THIS NOTICE
If we change the way We handle your Personal Data, We will update this Notice. We reserve the right to make changes to our practices and this Notice at any time, please check back frequently to see any updates or changes to our Notice.
12. DATA CONTROLLERS & CONTACT
To ask questions or make comments on this Notice and our privacy practices or to make a complaint about our compliance with applicable privacy laws, please contact Us at: +97148100000 or writing to us at ask@nestle-family.com
You can also contact our Data Protection champion via email at: ask@nestle-family.com or writing to us at P.O Box 17327, Jebel Ali Free Zone – Dubai, United Arab Emirates
We will acknowledge and investigate any complaint about the way We manage Personal Data (including a complaint that We have breached your rights under applicable privacy laws).
Data controllers |
Responsible for |
---|---|
Nestlé Middle East FZE |
All activities |