POLITIQUE NESTLÉ SUR LA PROTECTION DES DONNÉES

Date d’entrée en vigueur:25/05/2018

Date de dernière mise à jour:11/10/2021NOUS CONTACTER

NESTLÉ DATA PROTECTION POLICY

Nestlé respects your right to privacy and did not wait for the arrival of the General Data Protection Regulation (“GDPR”) to put in place all the technical and organizational measures necessary to guarantee the security of the personal data that you pass it on to us.
This policy on the protection of personal data (“thePolicy”) explains how your personal data is collected, used and possibly transmitted to third parties by the various companies of the Nestlé group in France (“Nestlé”, “we”). It also describes how you can access and update your personal data and make certain choices about how it is used.
It covers both our online and offline data collection activities, including personal data we collect through our various channels such as our websites, apps, third-party social networks, our Consumer Services and customer relations centres, our stores, events at points of sale and during events organized by our brands. Please be aware that the personal data we collect through one channel of this site in some cases be combined with personal data collected through another channel (for example, an offline event hosted byNESTLÉ® Professional. Similarly, we may aggregate personal data initially collected by a Nestlé group company in France with those collected by other group companies (Nestlé France, Nestlé Purina Petcare France, Cereal Partners France, Nestlé Waters Marketing and Distribution , Herta, Nespresso France…): when this is the case, this allows users of our websites to connect by performing only one authentication. Refer to Question 9 – “What are your rights and how can you exercise them?”to know the procedure to follow if you wish to oppose it.
If we are missing personal data during collection (we will inform you of this if necessary, for example by means of clear messages in our registration forms), we may not be able to provide our products and/or services to you.
This Policy provides answers to the following questions:

1. In which cases Nestlé may collect your personal data?
2. What personal data do we collect and how?
3. What is Nestlé’s policy on the personal data of children?
4. How do we use your personal data?
5. Does Nestlé disclose your personal data and why?
6. How long will your personal data be kept?
7. How does Nestlé store and/or transfer your personal data?
8. What are your rights and how to exercise them?
9. What are your choices about how we use your personal data?
10. Changes to our Policy?
11. Who are the data controllers and how to contact them?

1. In which cases Nestlé may collect your personal data?

The Policy applies to personal data that we obtain from or collect about you, through the methods described in Question 2 – “What personal data do we collect and how?”from the following sources:

* Websites:the online sites that we operate under our own domain names/URLs and the mini-sites/pages/accounts that we have created on third party social networks such as Facebook (“the Websites”).
* Mobile Sites/Apps:Consumer-facing mobile sites or apps operated by Nestlé, such as smartphone apps.
* Emails, text messages and otherelectronicmessages : this includes electronic communications exchanged between you and Nestlé.
* Consumer Services and Customer Relations Centers (“CRCs”):any communication from you with our Consumer Services or our CRCs (letters, calls, emails).
* Offline Registration Forms: Printed registration forms and other similar types of forms through which we collect personal data from consumers, by mail, at in-store events or at other events.
* Adinteractions: interactions with our brands’ banner ads (for example, if you interact with one of our banner ads on a third-party site, we may receive information about that interaction).
* Data that we create:as part of our interactions with you, we may create data associated with your person (for example a follow-up of your online purchases on one of our websites).
* Data from other sources: information about you that we collect through social media (e.g. Facebook or Google), market research (where responses are not anonymized), promotional partners of Nestlé, public sources, or on the occasion of the acquisition of a company.

2.Whatpersonal data do we collect and how?

Depending on how you interact and communicate with Nestlé (online, offline, over the phone, etc.), we may collect different types of information from you as described below:

* Personalcontact details: this includes any information you give us so that we can contact you personally, such as your name, postal address, e-mail address or telephone number.
* Account logindata :the data necessary for you to access your profile on your account. This may be your username/email address, password and/or your security question and answer.
* Demographics and Interests Information:This is information about your demographic or behavioral characteristics. This includes, for example, your date of birth, your age, where you live (eg your postcode), your favorite products, your hobbies and interests as well as information about your household and your lifestyle.
* Technical information about your computer/mobile device:information about your computer system or any other technological device you use to access one or more of our websites or applications, such as the Internet Protocol (IP) address used to connect your computer or device to the Internet, the type of operating system, and the type and version of your web browser. If you access a Nestlé site or application from a mobile device such as a smartphone, the information collected will include, where permitted, your phone’s unique identifier, advertising identifier, geolocation and other details. other similar mobile device data.
* Website Usage/Interaction Information: When you browse and interact with our websites or our newsletters, we use automatic data collection technologies to collect certain information relating to your actions. This includes information such as the links you click on, the pages or content you view and for how long, and other similar information, as well as statistics about your interactions such as content response times, download errors and the length of visits to certain pages. This information is captured using automated technologies such as cookies (browser cookies, flash cookies) and web beacons, and is also collected using third-party tracking devices. You have the right to object to the use of these technologies; for more information on this subject, please consult our “Nestlé Cookie Policy”.
* Market Research and Consumer Feedback:This includes information you consent to share with us about your experience as a user of our products and services.
* Consumer Generated Content: This refers to any content that you create and share with us on third-party social networks or by posting it to any of our websites or apps, including by using apps third-party social networks such as Facebook. This includes photos, videos, personal stories or other similar content or media. If you have agreed, we collect and publish content generated by you through various activities, such as games or other promotional activities, website community features, consumer reviews and comments, and presence on third-party social networks.
* Financial and payment data: any information that we need to fulfill an order, or that you use to make a purchase, such as your credit card information (name of cardholder, card number, date of expiration, etc.) or information about other payment methods (if available). In all cases, we or our payment processor(s) manage and process financial and payment data in accordance with applicable security regulations and standards, such as the Payment Card Industry Security Standard .
* Calls to Consumer Services/customer relations centres:your communications with our Consumer Services or a CRC may be recorded or listened to for quality control or staff training purposes. You will be informed of this recording at the start of your call. Credit card information is not saved.
* Sensitive personal data: We have no reason to collect or process sensitive personal data (e.g. health data) in the course of our normal business activities. If we were required to do so for the purposes of sending marketing or medical communications, we would do so in strict compliance with the provisions of the GDPR relating to the processing of special categories of data, and in particular only with your explicit consent to the regard to specific and legitimate purposes pursued by Nestlé.

3.What is Nestlé’s policy on the personal data of children?

We believe it is extremely important to protect the privacy of children accessing the Internet and encourage parents or guardians to spend time with them to participate in and manage their online activities .
Make sure that your children do not give out your personal data on the Internet without first asking your permission.
On some of our websites (in particular our e-commerce sites) the creation of an account is reserved for adults.
We do not collect personal data from children under the age of 13. If we become aware that we have accidentally collected personal data from children under the age of 13, we delete it from our databases as soon as we become aware of it.
The only exception is the collection of personal data from children under 13 directly through a parent or guardian, with their explicit consent.
You can at any time check, modify, delete your child’s personal data. You can also request the deletion of data relating to your child by sending the request by post to the address given in the contacts indicated in Question No. 8 – “Whatare your rights and how can you exercise them?””.

4.How do we use yourpersonal data?

You will find in the table below the list of the purposes pursued by Nestlé when collecting and processing your personal data and the different types of personal data that are collected for each purpose. Please be aware that some people may not be affected by some of the uses listed below.

What uses?

Principles on which this use is based

Our legitimate interests

Consumer services and/or customer relations center: we use your personal data to respond to your requests. This involves knowing certain personal details and information relating to the nature of your request (order status, technical problem, question/complaint about a product, general question, etc.).

. Compliance with our contractual obligations

· Legal obligations

Our legitimate interests

. Improve and develop new products and services

. Gain in efficiency

Marketing communications, games, contests and other promotions: with your consent (where necessary), we use your personal data to provide you with information about our products or services (for example, in the context of marketing or promotional communications/campaigns). We may do this by means of, for example, advertisements, emails, text messages, telephone calls and postal mail to the extent permitted by applicable law. Some of our campaigns and promotions are carried out on third-party websites and/or social networks. This use of your personal data is voluntary on your part, which means that you can object to the processing of your personal data for these purposes.What are your rights and how to exercise them?» and n°9 – «What are your choices about the use we make of your personal data?”. To find out more about our games, contests and other promotions, please refer to the rules and information accompanying each game, contest or promotion.

. Your consent (when necessary)

. Compliance with our contractual obligations

Our legitimate interests

. Determine which of our products and services may interest you and tell you about them

. Define consumer or customer profiles for new products or services

Third- party social networks:We use your personal data when you use third-party social network functions, such as the “Like” function, in order to serve you advertisements and to interact with you on these third-party social networks. To learn more about how these features work, the profile data we obtain about you, and how to opt out of this use of your personal data, please read the privacy policies of the relevant third-party social networks.

. Your consent (when necessary)

Our legitimate interests

. Determine which of our products and services may interest you and tell you about them

. Define consumer or customer profiles for new products or services

Personalization (offline and online):with your consent, we use your personal data (i) to analyze your preferences and habits; (ii) to anticipate your needs based on our analysis of your profile; (iii) to improve and personalize your experience on our websites and applications; (iv) to ensure that content from our websites or applications is most suitable for you and your computer or device; (v) to provide you with targeted advertisements and content; and (vi) to allow you to participate in interactive activities, when you choose to do so. For example, we remember your login ID/email address or nickname so that you can quickly log in during your next session or so that you can easily find items previously placed in your basket. Based on this type of information, and with your consent, we also show you Nestlé content or promotions tailored to your interests. This use of your personal data is voluntary on your part, which means that you can object to the processing of your personal data for this purpose. For detailed information on how to opt out of this processing, see Question 9 – “What are your choices about how we use your personal data?”.

. Your consent (when necessary)

Our legitimate interests

. Determine which of our products and services may interest you and tell you about them

. Define consumer or customer profiles for new products or services

Order Processing: We use your personal data to process and ship your orders, notify you of the status of your orders, verify that we have the correct addresses, verify your identity and perform other anti-fraud checks. This involves using certain personal data and payment information.

. Compliance with our contractual obligations

Your consent (when required )

. Legal obligations

Our legitimate interests

. Improve and develop new products and services

. Gain in efficiency

. Protecting our operating systems, networks and people

Other general uses (internal or market research, analysis, security, etc.):In accordance with the laws in force, we use your personal data for other general commercial purposes, in particular to carry out internal studies or market and measure the effectiveness of our advertising campaigns. If you have multiple “Club Member” accounts for Nestlé brands, we reserve the right to combine these accounts into one account. We also use your personal data to ensure the security of our operating systems, networks and security systems.

. Compliance with our contractual obligations

Your consent (when required )

. Legal obligations

Our legitimate interests

. Improve and develop new products and services

. Gain in efficiency

. Protecting our operating systems, networks and people

Legal grounds or merger/acquisition:In the event that Nestlé or its assets are acquired by, or merged with, another company, including in the event of bankruptcy, we will share your personal data with any of our legal successors. We will also disclose your personal data to third parties (i) where required by law; (ii) in response to legal proceedings; (iii) in response to a request from a law enforcement agency; (iv) to protect our rights, privacy, safety or property, or the public; or (v) to enforce the terms of any agreement or the terms of use of our website.

. Legal obligations

Our legitimate interests

. Protecting our assets and our people

5. Does Nestlé disclose your personal data and why?

In addition to the legal entities of the Nestlé group mentioned in Question n°11 – “Who are the data controllers and how can I contact them?”” , we may share your personal data with different groups of third-party companies:
Service providers:these are external companies that we use to help us carry out our activities (order fulfillment, payment processing, anti-fraud detection, identity verification, website operation, market research, support services, promotions management, website development, data analytics, consumer services and/or customer services, etc.). These service providers, and certain members of their staff, are authorized to use your personal data on our behalf only for the specific tasks for which they have been requested, according to our instructions, and are obligated to protect the confidentiality and security of your information. personal data. When required by law, you can obtain a list of the service providers processing your personal data (see Question n°11 – “Who are the data controllers and how to contact them?”).
Credit Reporting/Collection Agencies:the extent permitted by law, credit reporting agencies and collection agencies are outside companies that we use to assist us in verifying your creditworthiness (particularly for orders with invoice) or to collect debts resulting from unpaid invoices.
Third party companies using personal data for their own marketing purposes:except where you have given your consent, we do not sell your personal data to third party companies for their own marketing purposes. If applicable, the identity of these third-party companies will be communicated at the time your consent is sought.
Third party recipients using personal data for legal reasons or due to merger/acquisition:we will disclose your personal data to third parties for legal reasons or in connection with an acquisition or merger (see Question no. 4 – “Howdo we use your personal data?”to find out more).

6. How long will your personal data be kept?

Your personal data will be kept by Nestlé only for the time that is reasonably necessary for the purposes described in this Policy. The criteria we use to determine the retention periods for your personal data are as follows:
has. Nestlé will keep your personal data in a form by which you can be identified for the duration of your participation in one or more of our loyalty programs, or for the duration of your membership in one of our online services. They may then be kept and processed for 3 years following the last contact from you, to allow us to send you marketing or commercial solicitations.
b.Your personal data may however be kept for longer under specific legal obligations or with regard to applicable legal limitation periods. By way of example, the data will be retained for:

* 6 years for tax documents;
* 10 years for accounting documents;
* Throughout the duration of the litigation and until exhaustion of the means of appeal.

c. Personal data used to provide you with a personalized experience (see Question 4 – “Howdo we use your personal data?” for more details) will be retained for the period permitted by applicable law.
Beyond the retention periods mentioned above, your personal data will either be securely deleted from all Nestlé databases or anonymized.

7. How does Nestlé store and/or transfer your personal data?

We use all the necessary technical and organizational measures to guarantee the confidentiality and security of your personal data. Please note, however, that these measures do not apply to the information you choose to share in public spaces, in particular on third-party social networks.

Persons having access to your personal data:your personal data will be processed by our staff or our dedicated service providers, and only for the purposes which were described to you when your personal data was collected (for example, our staff in charge of questions relating to consumer services or customer relations will only have access to your file corresponding to this purpose).
Measures taken in operating environments:We store your personal data in operating environments where appropriate security measures are implemented to prevent unauthorized access. We comply with applicable standards to protect your personal data. Unfortunately, the transmission of information via the internet cannot be completely secure, and although we will do our best to protect your personal data, we cannot guarantee the security of your data during transmission via our websites or applications. .
What we expect from you: you too have an essential role to play in guaranteeing the security of your personal data. When creating an online account, be sure to choose a password that is hard to guess and never reveal your password to anyone. You are responsible for keeping this password confidential and you are responsible for any use you make of your account. If you use a shared or public computer, make sure that the option to remember login ID, email address or password is never checked, and always log out of your counts every time you step away from the computer.
Transfer of your personal data:the storage and processing of your personal data requires that your personal data be, at one time or another, transferred to and stored in a country other than that in which you reside, in particular to Switzerland. , Luxembourg, Germany, Portugal, Spain. We are also likely to transfer your personal data to countries outside the European Economic Area (EEA), for example to other legal entities of the groupNestlé or ad hoc partners, including to countries whose personal data protection standards differ from those applied in the EEA. In this case, we (i) have put in place “standard contractual clauses” approved by the European Commission to protect your personal data (and you have the right to ask us for a copy of these clauses, by contacting us at the contact details indicated below -after) and/or we (ii) will rely on your consent.

8. What are your rights and how to exercise them?

Access to your personal data:you, your descendants, representatives and/or proxies have the right to access, consult and request a physical or electronic copy of the information that we hold about you. You also have the right to request information about the source of your personal data.
You can exercise these rights:

* by post: Nestlé France Consumer Service, rue Guynemer, Issy-les-Moulineaux
* by telephone by calling our Consumer Service on * by Internet:

We will ask you to attach a copy of your identity document or any other proof of identity to your request. If the request is submitted by someone other than you, without proof that the request is legally made on your behalf, the request will be rejected.
Please be aware that any identifying information provided to us will be processed only in accordance with, and to the extent permitted by, applicable law.

Other rights (eg, modification or deletion of personal data):you, your descendants, representatives and/or proxies can (i) request the deletion, portability, rectification or modification of your personal data; (ii) object to data processing; (iii) limit the use and disclosure of your personal data; and (iv) withdraw your consent to any of our processing activities of your personal data.
Be aware that, in some cases, the deletion of your personal data will necessarily involve the deletion of your user account. We may also be obliged to keep some of your personal data, after your deletion request, in order to meet our legal or contractual obligations (see Question 6 – “Howlong will your personal data be kept?” ).
Where possible, our websites include a dedicated function allowing you to consult and modify the personal data that you have provided to us. Be aware that, before being able to access or modify their account information, people registered on a website must prove their identity (for example, by giving their login ID/e-mail address, password); this in order to prevent unauthorized access to an account.
We hope to be able to answer any questions and queries you may have regarding how we process your personal data. However, if we are unable to dispel all your fears, you also have the right to file a complaint with the CNIL (/fr/plaintes)

9. What are your choices about how we use your personal data?

We are committed to enabling you to make the most informed choices possible when it comes to the personal data you provide to us. The following mechanisms give you control over your personal data:
Cookies/similar technologies:you manage your consent via (i) our consent management solution or (ii) your browser in order to decide whether you authorize or refuse the use of some or all of the cookies/similar technologies, or if you want to be alerted when cookies/similar technologies are used. Please see our “Nestlé Cookie Policy” for more information.
Advertising, marketing and promotions: sIf you wish your personal data to be used by Nestlé to send you promotional communications about its products or services, you can indicate this by ticking the relevant box(es) in the online registration form, or by responding to the to questions asked on this subject by our Consumer Services and customer relations centres, our store representatives, our sales demonstrators during events at points of sale or during events organized by our brands. If you no longer wish to receive these promotional communications, you may unsubscribe from marketing communications at any time by following the instructions provided in each such communication. An unsubscribe link is included at the bottom of any marketing communication you receive from Nestlé. At any time, you can opt out of receiving marketing communications from any medium. To do this, contact our Consumer Services or our customer relations centers, or log in to the third-party websites, applications or social networks in question and modify your user preferences in your account profile by unchecking the corresponding boxes. Please be aware that, even if you opt out of receiving marketing communications, you may still receive administrative communications from us, such as order confirmations or other transactions, notifications about your account activities (account confirmations , password changes, etc.), and
Personalization (offline and online):If you would like your personal data to be used by Nestlé to provide you with a personalized experience/targeted advertisements and content, you can indicate this by ticking the relevant box(es) in the registration form or by responding to the questions asked on this subject by our Consumer Services and customer relations centres, our store representatives, our sales demonstrators during events at points of sale or during events organized by our brands. You can request at any time to no longer benefit from this personalization. To do this, contact our Consumer Services or our customer relations centers,
Targeted advertising:we may partner with advertisers displaying advertising banners on the Internet for one of our brands or brands of companies outside the Nestlé group. These banner ads are targeted to your areas of interest, based on information collected from Nestlé or third-party websites. You can visit the website/choicesto learn more about this type of targeted advertising, and how you can block the appearance of these targeted advertisements (“opt-out”) for companies that participate in the “Digital Advertising Alliance” self-regulatory program (“DAA”). You can similarly download this DAA application to your mobile device to block these targeted advertisements. We also remind you that you can block the collection of geolocation data at any time by modifying the settings on your mobile device.

10. Changes to our Policy

If there is a change in the way we manage and process your personal data, we will update this Policy. We reserve the right to modify our practices and this Policy at any time. Please check regularly for updates or changes to our Policy.

11. Who are the data controllers and how to contact them?

To ask questions, share your comments about this Policy and our personal data protection practices, or to file a complaint for non-compliance with applicable privacy laws, you can contact our Data Protection Officer by e-mail:

We will process and investigate any complaint relating to the way We handle your personal data (including a complaint that We have breached your rights under applicable privacy laws).

Data controller

Responsible for

Nestle France

All activities