Privacy Policy

Effective: 01.09.2021

Please read this privacy notice (“Notice”) carefully to understand our policies and practices regarding your Personal Data and how we will treat it. This Notice applies to individuals who interact with Nestlé services as users (“you”). This Notice explains how your Personal Data are collected, used, and disclosed by Société des Produits Nestlé S.A (“Nestlé”, “We”, Us”). It also tells you how you can access and update your Personal Data and make certain choices about how your Personal Data are used.

This Notice covers both our online and offline data collection activities, including Personal Data that We collect through our various channels such as websites, apps, third party social networks, Consumer Engagement Service, points of sale and events. Please note that We might aggregate personal data from different sources (website, offline event). As part of this, We combine Personal Data that were originally collected by different Nestlé entities or Nestlé partners. Please see Section 9 for further information on how to object to this.

If you do not provide necessary Personal Data to us (We will indicate to you when this is the case, for example, by making this information clear in our registration forms), We may not be able to provide you with our goods and/or services. This Notice can change from time to time (see Section 11).

This Notice provides important information in the following areas:

  1. SOURCES OF PERSONAL DATA
  2. PERSONAL DATA THAT WE COLLECT ABOUT YOU AND HOW WE COLLECT IT
  3. PERSONAL DATA OF CHILDREN
  4. COOKIES/SIMILAR TECHNOLOGIES, LOG FILES AND WEB BEACONS
  5. USES MADE OF YOUR PERSONAL DATA
  6. DISCLOSURE OF YOUR PERSONAL DATA
  7. RETENTION OF PERSONAL DATA
  8. STORAGE AND/OR TRANSFER OF YOUR PERSONAL DATA
  9. ACCESS TO YOUR PERSONAL DATA
  10. YOUR CHOICES ABOUT HOW WE USE AND DISCLOSE YOUR PERSONAL DATA
  11. CHANGES TO OUR NOTICE
  12. DATA CONTROLLERS & CONTACT

1. SOURCES OF PERSONAL DATA

This Notice applies to Personal Data that We collect from or about you, through the methods described below (see Section 2), from the following sources:

Nestlé websites. User-directed websites operated by or for Nestlé, including sites that We operate under our own domains/URLs and mini-sites that We run on third party social networks such as Facebook (“Websites”).

Nestlé mobile sites/apps. User-directed mobile sites or applications operated by or for Nestlé, such as smartphone apps.

E-mail, text and other electronic messages. Interactions with electronic communications between you and Nestlé.

Data We create. In the course of our interactions with you, we may create Personal Data about you (e.g. records of your purchases from our websites).

Data from other sources. Third party social networks (e.g. such as Facebook, Google), market research (if feedback not provided on an anonymous basis), third party data aggregators, Nestlé promotional partners, public sources and data received when we acquire other companies.

2. PERSONAL DATA THAT WE COLLECT ABOUT YOU AND HOW WE COLLECT IT

Depending on how you interact with Nestlé (online, offline, over the phone, etc.), We collect various types of information from you, as described below.

Personal contact information. This includes any information you provide to Us that would allow Us to contact you, such as your name, postal address, e-mail address, social network details, or phone number

Account login information. Any information that is required to give you access to your specific account profile. Examples include your login ID/email address, screen name, password in unrecoverable form, and/or security question and answer.

Demographic information & interests. Any information that describes your demographic or behavioural characteristics. Examples include your date of birth, age or age range, gender, geographic location (e.g. postcode/zip code), favourite products, hobbies and interests, and household or lifestyle information.

Information from computer/mobile device. Any information about the computer system or other technological device that you use to access one of our Websites or apps, such as the Internet protocol (IP) address used to connect your computer or device to the Internet, operating system type, and web browser type and version. If you access a Nestlé website or app via a mobile device such as a smartphone, the collected information will also include, where permitted, your phone’s unique device ID, advertising ID, geo-location, and other similar mobile device data.

User-generated content. Any content that you create and then share with Us on third party social networks or by uploading it to one of our Websites or apps, including the use of third party social network apps such as Facebook. Examples include photos, videos, personal stories, or other similar media or content. Where permitted, We collect and publish user- generated content in connection with a variety of activities, including contests and other promotions, website community features, user engagement, and third party social networking.

Sensitive Personal Data. We do not seek to collect or otherwise process sensitive personal data in the ordinary course of our business. Where it becomes necessary to process your sensitive personal data for any reason, we rely on your prior express consent for any processing which is voluntary (e.g. for marketing purposes). If we process your sensitive personal data for other purposes, we rely on the following legal bases: (i) detection and prevention of crime (including the prevention of fraud); and (ii) compliance with applicable law (e.g. to comply with our diversity reporting).

4. COOKIES/SIMILAR TECHNOLOGIES

Cookies/Similar Technologies. We do not use cookies.

5. USES MADE OF YOUR PERSONAL DATA

The following paragraphs describe the various purposes for which We collect and use your Personal Data, and the different types of Personal Data that are collected for each purpose. Please note that not all of the uses below will be relevant to every individual.

What We use your Personal Data for Our reasons Our legitimate interests
User service. We use your Personal Data for consumer user service purposes, including responding to your enquiries. This typically requires the use of certain personal contact information and information regarding the reason for your inquiry (e.g. order status, technical issue, product question /complaint, general question, etc.).
  • Fulfilling contractual obligations
  • Legal obligations
  • Our legitimate interests
  • Improving and developing new products and services
  • Being more efficient
Legal reasons or merger/acquisition. In the event that Nestlé or its assets are acquired by, or merged with, another company including through bankruptcy, we will share your Personal Data with any of our legal successors. We will also disclose your Personal Data to third parties (i) when required by applicable law; (ii) in response to legal proceedings; (iii) in response to a request from a competent law enforcement agency; (iv) to protect our rights, privacy, safety or property, or the public; or (v) to enforce the terms of any agreement or the terms of our Website
  • Legal obligations
  • Our legitimate interests
  • Compliance with legal obligations
  • Protect our assets and staff

6. DISCLOSURE OF YOUR PERSONAL DATA

In addition to the Nestlé entities mentioned in the data controllers & contact section (see Section 12), We share your Personal Data with the following types of third party organisations:

Service providers. These are external companies that We use to help Us run our business (e.g. order fulfilment, payment processing, fraud detection and identity verification, website operation, market research companies, support services, promotions, website development, data analysis, CRC, etc.). Service providers, and their selected staff, are only allowed to access and use your Personal Data on Our behalf for the specific tasks that they have been requested to carry out, based on our instructions, and are required to keep your Personal Data confidential and secure. [Where required by applicable law, you can obtain a list of the providers processing your Personal Data (see Section 12 to contact Us).

Credit reporting agencies/debt collectors. To the extent permitted by applicable law, credit reporting agencies and debt collectors are external companies that We use to help Us to verify your creditworthiness (in particular for orders with invoice) or to collect outstanding invoices.

Third party recipients using Personal Data for legal reasons or due to merger/acquisition. We will disclose your Personal Data to third parties for legal reasons or in the context of an acquisition or a merger (see Section 5 for details).

Third party recipients using Personal Data for calculating greenhouse gas emissions. We will disclose your Personal Data to third parties for calculating your farm emission factor. Third party will not store your data after the calculation it will be removed from their database.

7. RETENTION OF YOUR PERSONAL DATA

In accordance with applicable laws, We will use your Personal Data for as long as necessary to satisfy the purposes for which your Personal Data was collected (as described in Section 5 above) or to comply with applicable legal requirements. Personal data used to provide you with a personalized experience (see Section 5 above for details) will be kept for a duration permitted by applicable laws.

8. DISCLOSURE, STORAGE AND/OR TRANSFER OF YOUR PERSONAL DATA

We use appropriate measures (described below) to keep your Personal Data confidential and secure. Please note, however, that these protections do not apply to information you choose to share in public areas such as third party social networks.

People who can access your Personal Data. Your Personal Data will be processed by our authorised staff or agents, on a need to know basis, depending on the specific purposes for which your Personal Data have been collected (e.g. our staff in charge of user care matters will have access to your user record).

Measures taken in operating environments. We store your Personal Data in operating environments that use reasonable security measures to prevent unauthorised access. We follow reasonable standards to protect Personal Data. The transmission of information via the Internet is, unfortunately, not completely secure and although We will do our best to protect your Personal Data, We cannot guarantee the security of the data during transmission through our Websites/apps.

Measures We expect you to take. It is important that you also play a role in keeping your Personal Data safe and secure. When signing up for an online account, please be sure to choose an account password that would be difficult for others to guess and never reveal your password to anyone else. You are responsible for keeping this password confidential and for any use of your account. If you use a shared or public computer, never choose to have your login ID/email address or password remembered and make sure to log out of your account every time you leave the computer. You should also make use of any privacy settings or controls We provide you in our Website/app.

Transfer of your Personal Data. Because of the international nature of our business, we may need to transfer your personal data within the Nestlé group, and to third parties as noted in Section 6 above, in connection with the purposes set out in this Privacy Notice. For this reason, we may transfer your personal data to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located.

9.YOUR RIGHTS

Access to Personal Data. You have the right to access, review and request a physical or electronic copy of information held about you. You also have the right to request information on the source of your Personal Data.

These rights can be exercised by sending Us an e-mail [GLOBALMilkSolutionOffshore@nestle.com], attaching a copy of your ID or equivalent details (where requested by Us and permitted by law). If the request is submitted by a person other than you, without providing evidence that the request is legitimately made on your behalf, the request will be rejected. Please note that any identification information provided to Us will only be processed in accordance with, and to the extent permitted by applicable laws.

Additional rights (e.g. modification, deletion of Personal Data). Where provided by law, you can (i) request deletion, the portability, correction or revision of your Personal Data; (ii) limit the use and disclosure of your Personal Data; and (iii) revoke consent to any of our data processing activities.

Subject to applicable law, you may also have the following additional rights regarding the use of your Relevant Personal Data:
  • the right to object, on grounds relating to your particular situation, to the use of your Relevant Personal Data by us, or on our behalf; and
  • the right to object to the Processing of your Relevant Personal Data by us, or on our behalf, for direct marketing purposes.

Please note that, in certain circumstances, We will not be able to delete your Personal Data without also deleting your user account. We may be required to retain some of your Personal Data after you have requested deletion, to satisfy our legal or contractual obligations. We may also be permitted by applicable laws to retain some of your Personal Data to satisfy our business needs.

Where available, our Websites have a dedicated feature through which you can review and edit the Personal Data that you have provided. Please note that We require our registered users to verify their identity (e.g. login ID/email address, password) before they can access or make changes to their account information. This helps prevent unauthorised access to your account.

We hope that We can satisfy queries you may have about the way we process your Personal Data. However, if you have unresolved concerns you also have the right to complain to competent data protection authorities.

10. YOUR CHOICES ABOUT HOW WE USE AND DISCLOSE YOUR PERSONAL DATA

We do not use cookies.

11. CHANGES TO THIS NOTICE

If We change the way We handle your Personal Data, We will update this Notice. We reserve the right to make changes to our practices and this Notice at any time, please check back frequently to see any updates or changes to our Notice.

12. DATA CONTROLLERS & CONTACT

To ask questions or make comments on this Notice and our privacy practices or to make a complaint about our compliance with applicable privacy laws, please contact Us at: GLOBALMilkSolutionOffshore@nestle.com or writing to us at Avenue Nestlé 55, 1800 Vevey, Switzerland

You can also contact our Data Protection contact via email at: dataprotectionoffice@nestle.com or post: Data Protection Office Nestlé S.A., Avenue Nestlé 55, 1800 Vevey, Switzerland

We will acknowledge and investigate any complaint about the way We manage Personal Data (including a complaint that We have breached your rights under applicable privacy laws).