The following information is provided to you to inform you of Sodexo Belgium SA/NV. commitments in terms of Personal data protection. Sodexo Belgium SA/NV. belongs to Sodexo Group (hereafter “SODEXO”). SODEXO builds strong, lasting relationships with its customers, partners and consumers based on mutual trust: making sure that their Personal data is safe and remains confidential is an absolute priority for SODEXO.
SODEXO is committed to comply with all applicable regulatory and legal provisions governing the protection of Personal data.
SODEXO enforces a very strict privacy policy to guarantee the protection of the Personal data of those who use its websites, portals, applications, and platforms (our “Sites”):
•
Users remain in control of their own data. The data is processed in a transparent, confidential and secure manner.
•
SODEXO is committed to a continuing quest to protect its users’ Personal data in accordance with the EU GDPR.
•
SODEXO has a Global Data Protection Office dedicated to data protection, supported by a network of local data protection single points of contact or data protection officers.
PURPOSE OF THIS POLICY
SODEXO takes the protection of your Personal data very seriously.
We have developed this policy to inform you of the conditions under which we collect, process, use and protect your Personal data on our App and in the context of the services provided by Sodexo Belgium SA/NV. (the "Services"). This policy covers all users, including those who use the App and the Services without being registered or subscribing to a specific service or account (hereinafter collectively, the "Users").
Please read it carefully to familiarize yourself with the categories of Personal data that are subject to collection and processing, how we use this Personal data and with whom we are likely to share it. This policy also describes your rights and how you can get in touch with us to exercise these rights or to ask us any questions you might have concerning the protection of your Personal data.
This policy may be amended, supplemented or updated, in particular to comply with any legal, regulatory, case law or technical developments that may arise. However, your Personal data will always be processed in accordance with the policy in force at the time of the data collection, unless a compulsory legal prescription determines otherwise and must be enforced retroactively.
IDENTITY AND CONTACT DETAILS OF THE CONTROLLER The data Controller is:
Sodexo Belgium SA/NV.
Registered No: 0407.246.778,
Registered office at Rue Ravenstein, 36, 1000 Brussels
Email : dataprivacy.OSS.BE@sodexo.com
DEFINITIONS “
Account” The User’s dedicated personal area within the App, which he or she accesses when he or she registers and connects to the App. It enables the User to access the Services.
“
Controller” The Sodexo entity which determines the purposes and means of the processing of personal data.
“
Cookies” As defined in the
Cookies Policy “
Personal data” Means any information relating to an identified natural person or one that can be directly or indirectly identified by reference to an identification number or to one or more factors specific to this person.
“
Processing” Any operation or set of operations which is performed on Personal data or on sets of Personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“
Processor” A legal person which processes personal data on behalf of the controller.
“
App” The Everyday application of Sodexo Belgium SA/NV. available on the AppStore and Google Play
“
us” “
we” or “
our” Sodexo Belgium SA/NV (hereinafter “
Sodexo Belgium”), acting as controller
“
you” or “
Users” Any App user
COLLECTION AND SOURCE OF PERSONAL DATA
We will most likely collect your Personal data directly (in particular via the data collection forms on our App) or indirectly via our service providers and/or technologies on our App. We undertake to obtain your consent and/or to allow you to refuse the use of your data for certain purposes whenever necessary. You will in any event be informed of the purposes for which your data is collected via the various online data collection forms and via the
Cookies Policy
TYPES OF PERSONAL DATA COLLECTED AND USED BY US
We may specifically collect and process the following types of Personal data:
- the information that you provide when filling in the forms on the App, or corresponding with us by phone, email or via the app, (for example, for subscription purposes, to participate in surveys, for marketing purposes, when downloading the application, etc.)- the information that you provide for authentication purposes;
- the information that you provide for order fulfillment or to receive a service
- the data relating to your purchases such as products, quantity, price, billing and delivery addresses including health information about you only where you volunteer and consent to this, for example if you report any specific food allergies;
- the transaction data such as payment information and credit/debit card information that is transmitted directly to third parties who process your requests (a “Payment Processor”);
- the information provided via “posts”, comments or other content that you post on the App, or when you use the chat function on our App;
- the information regarding your location at a specific moment (where activated and you have agreed to this on your mobile device) so that the appropriate venues serving your physical location (office or otherwise) can be shown in the App;
- your preferences in receiving marketing from us and our third parties and your communication preferences
- information collected through Cookies as defined in our
Cookies Policy.Personal data identified by an asterisk in the data collection forms is compulsory as these are necessary to fulfill any orders placed.In the absence of this compulsory information, these transactions cannot be processed. We may combine this information with information we receive from other sources. We may use this information and the combined information for the purposes set out below (depending on the types of information we receive). Please find details of the different data collected for the various purposes in the chart (Annex 1).
PURPOSES FOR WHICH WE USE PERSONAL DATA
Personal data may be collected for the following general purposes (a more precise description of the processing of your data can be found in the Annex 1 below):
· Cookies· Account creation and management
· Customer Relationship Management
· Marketing Management
· Legal Obligation
In addition, please note that you have the option to click on the dedicated icons of social networks such as Twitter, Facebook, LinkedIn, etc. that appear on our App. When you click on these icons, we may have access to the Personal data that you have made public and accessible via your profiles on the social networks in question. We neither create nor use any separate databases from these social networks based on the Personal data that you have published there, and we do not process any Personal data relating to your private life through these means. If you do not want us to have access to your Personal data published in the public spaces of your profile or your social accounts, then you should use the procedures provided by the social networks in question to limit access to this information. These links to other websites should not be considered as navigation tracking and we decline any responsibility concerning the Personal data protection practices implemented by these third-party companies, each of which acts as a separate Controller of your Personal data on their own perimeter. Once you leave our App or click on the logo/link to one of these social networks, it is your responsibility to check the privacy policy applicable to that other platform.
LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA We process your Personal data as part of the performance and management of our contractual relationship with you, in our legitimate interest to improve the quality and operational excellence of the Services we offer to you or in compliance with certain regulatory obligations depending on the purpose of processing as identified in the chart in Annex 1. Your Personal data may also be processed based on your prior consent in the event that under certain circumstances, your consent would be requested (e.g., regarding health data or for certain communication sent you way or certain types of Cookies). Please find more information about the legal basis for each of our processing in the Annex 1 below.
DISCLOSURE OF PERSONAL DATA The security and confidentiality of your Personal data is of great importance to us. This is why we restrict access to your Personal data, through different access levels, only to members of our staff and only to the extent strictly necessary to process your orders or to provide the requested Services. We ensure that persons authorized to process the Personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. We will not disclose your Personal data to any unauthorized third parties. We may, however, share your Personal data with entities within SODEXO and with authorized service providers (for example: technical service providers [hosting, maintenance], consultants, etc.) whom we may call upon for the purpose of providing our Services. In addition, we will need to pass your details to the Payment Processor in order for you to make payments on the App. We ensure that every disclosure of your Personal data to an authorized service provider is framed by a data processing agreement, reflecting the commitments laid out in this policy. We do not authorize our service providers to use or disclose your data, except to the extent necessary to deliver the Services on our behalf or to comply with legal obligations. Furthermore, we may share your Personal data (i) if the law or a legal procedure requires us to do so, (ii) in response to a request by public authorities or other officials or (iii) if we are of the opinion that transferring these data is necessary or appropriate to prevent any physical harm or financial loss or in respect of an investigation concerning a suspected or proven unlawful activity.
STORAGE PERIOD OF YOUR PERSONAL DATA We will store your Personal data only for as long as necessary to fulfill the purposes for which it was collected and processed. This period may be extended, if applicable, for any amount of time prescribed by any legal or regulatory provisions that may apply. To determine the retention period of your Personal data, we take into consideration several criteria such as:
· The purpose for which we hold your Personal data (e.g., when you purchase products on our App, we keep your Personal data for the duration of our contractual relationship);
· Our legal and regulatory obligations in relation to that Personal data (e.g., accounting reporting obligations);
· Whether you are an active user of our Services, you continue to receive marketing communications, or you regularly browse or purchase off our Sites or whether you do not open our emails or visit our Sites; For instance, if you have agreed to receive marketing communications, we keep your Personal data until you: (i) unsubscribe from receiving marketing communications (ii) request we delete your Personal data, or (iii) after a period of inactivity (i.e. where you have not interacted with us for a period of time). This period is defined in accordance with local regulations and guidance;
· Any specific requests from you in relation to the deletion of your Personal data or Account;
· Any statutory limitation periods allowing us to manage our own rights, for example the defense of any legal claims in case of litigation; and
· Any local regulations or guidance (e.g., regarding cookies). Please find more information about the storage period of your Personal data in Annex 1 below.
SENSITIVE PERSONAL DATA
As a general rule, we do not collect sensitive Personal data via our App. “Sensitive Personal data” refers to any information concerning a person’s racial or ethnic origins, political opinions, religious or philosophical beliefs, union membership, health data or data relating to the sexual life or the sexual orientation of a natural person. This definition also includes personal data relating to criminal convictions and offenses. Nonetheless, you can, on a voluntary basis provide information regarding your allergies or dietary preferences. We only collect this data strictly to achieve the purpose for which the processing is performed, and we do so in accordance with local legal requirements for the protection of Personal data and, in particular, with your explicit prior consent and under the conditions described in this policy.
TRANSFER OF PERSONAL DATA As SODEXO is an international group, your Personal data may be transmitted to internal or external recipients that are authorized to perform Services on our behalf. Some of these recipients are located in countries outside of the European Union or the European Economic Area which do not offer an adequate level of Personal data protection. To guarantee the security and confidentiality of Personal data thus transmitted, we will take all necessary measures to ensure that this data receives adequate protection, such as entering into data transfer agreements with the recipients of your personal data based on the European Commission's standard contractual clauses (“EU SCCs”) or other valid transfer mechanisms and we carry out, in accordance with the European Court of Justice's decision of 16 July 2020 "Schrems II" (Case C 311-18) and with the guidance of the European Data Protection Board, a risk assessment of the transferred data. In addition, all entities of SODEXO have entered into an Intra-Group Data Processing Agreement, based on the EU SCCs, that provides for an equivalent protection of Personal data by all entities of SODEXO wherever it is established.
YOUR RIGHTS
SODEXO is committed to ensure protection of your rights under applicable laws. You will find below a table summarizing your different rights:
You can use this form to make a request:
Privacy Web Form
This electronic system allows you to log in and see the progress of your request, see and send messages and review your documents securely. This system is called One Trust and after making the request you will be sent details about how to log on.
Alternatively, you can also send your request by filling in
this form and sending it by email to dataprivacy.OSS.BE@sodexo.com. The team will liaise with you about how you to contact you about your request and receive information. Please note that it is usually necessary to arrange a telephone appointment to discuss your request once it has been made.
If you wish to unsubscribe to marketing emails communications, you can also do so by using the unsubscribe function on the email.
SECURITY
We implement all possible technical and organizational security measures to ensure security and confidentiality in processing your Personal data in accordance with Our Group Information & Systems Security Policy.
To this end, we take all necessary precautions given the nature of the Personal data and the risks related to its processing, in order to maintain data security and in particular to prevent distortion, damage or unauthorized third-party access (physical protection of the premises, authentication procedures with personal, secured access via identifiers and confidential passwords, a connection log, encryption of certain data, etc.).
In addition, if we contract with Processors for all or part of the Processing of your Personal data, we require a contractual agreement from our service providers to guarantee the security and confidentiality of the Personal data that we transmit to them or that they collect on our behalf, in accordance with the applicable regulations on the protection of Personal data.
We regularly conduct audits to verify the proper operational application of the rules relating to the security of your Personal data.
Nevertheless, you also have a responsibility to ensure the security and confidentiality of your Personal data, so we invite you to remain vigilant, especially when using an open system such as the Internet.
LINKS TO OTHER SITES
Occasionally, we provide links to other platforms for practical and informative purposes. These platforms operate independently from our App and are not under our control. These platforms have their own privacy policy or terms of use which we strongly advise you to read. We do not accept any liability with regards to the content on these platforms, for the products and services that may be offered there or for any other use thereof.
UPDATES OF OUR ONLINE PRIVACY POLICY
We may update or amend this policy as and when needed. In this case, amendments will only become applicable after a period of 30 business days from the date of the amendment. Please consult this page from time to time if you want to be informed of any possible changes.
HOW TO CONTACT US
If you have any questions or comments with regard to this policy, please do not hesitate to contact us at the following address: dataprivacy.OSS.BE@sodexo.com.
Last updated: January 7
th 2025