Privacy Notice applicable to

Personal Data processed in the context of www.cocacola.co.uk

 

 

 

 

Coca-Cola PRIVACY NOTICE

SUMMARY

This Privacy Notice applies to NV Coca-Cola Services SA, a company with registered office at Chaussée de Mons 1424, 1070 Brussels ("Data Controller", "CCS", "we", "our" and "us"), websites (our “Websites”), mobile sites, applications, widgets, and other mobile interactive features (collectively, our “Apps”) (all collectively, Apps and Websites, the “Sites”) that links to this Privacy Notice. You can read the full version of the Privacy Notice and find a summary below.

Please note that this Privacy Notice does not address, and we are not responsible for, the privacy, information or other practices of any third parties, including any third party operating any site to which these Sites contain a link.  The inclusion of a link on the Sites does not imply endorsement of the linked site by us or by our affiliates. 

HOW DO WE USE PERSONAL INFORMATION AND HOW IS IT COLLECTED?

We collect different categories of personal information. The categories we collect may include: Contact and profile information; Preferences and interests' information; User Generated Content (UGC); Location information; Information provided by social networks and by third parties.

This personal information is collected from you in many ways, a few examples include:

  • When You Submit Personal Information To Us. We collect personal information about you when you actively provide them to us, for example when you register to create an account, or post comments, photos and videos, or record your voice in the context of your participation to a promotion, or chat with users.
  • When You Use Our Sites. We (and third-party partners on our behalf) collect some personal information about you automatically as you use our Sites.
  • When You are Offline: We collect your Personal Data also when you are interacting with us in ways other than through the use of our Sites, for example when you participate to Coca-Cola events or when you contact us through our partners’ Sites;

We may link or combine information that we collect about you from various sources to help ensure a consistent user experience regardless of how you interact with us – online, on mobile, or on social media.

We use personal information for different purposes: for example, to fulfil your requests and contact you; to send you personalised advertising and promotional content and materials; to analyse and improve our Sites and our business; and for other reasons described more fully in our Privacy Notice.

To Learn More about the information we collect and how we use it, see our full Privacy Notice.

HOW DO WE SHARE INFORMATION?

We share information in a variety of circumstances for the functioning of our Sites, to respond to your requests, to improve your experience, and to otherwise conduct our business. For example, we may share information:

  • With our affiliates and companies in the Coca-Cola Group, who may use your information in a manner consistent with this Privacy Notice.
  • With third parties to fulfil your request, such as when you choose to share your activities with your friends and contacts.

To Learn More about these and other ways in which we may share your personal information, please see our full Privacy Notice.

WHAT RIGHTS AND CHOICES DO YOU HAVE?

We want you to understand your rights and choices regarding how we may process your personal information. Depending on how you use the Sites, these rights and choices may include the following:

  • Individual Rights.  You have specific rights under applicable privacy law in respect of your personal information that we hold, including a right of access and erasure and a right to restrict certain processing activities.
  • Interest-based advertising. Visit the European Interactive Digital Advertising Alliance, Network Advertising Initiative’s online resources, and/or the DAA’s resources to learn about how you may opt-out of certain interest-based advertising. Some of these opt-outs may not be effective unless your browser is set to accept cookies. Furthermore, if you use a different device, change browsers or delete cookies, you may need to perform the opt-out task again. You may also be able to limit interest-based advertising through the settings on your mobile device by selecting “limit ad tracking” (iOS) or “opt-out of interest-based ads” (Android).
  • Cookies Settings and Preferences. You may manage cookies and other tracking technologies through the settings in your browser.
  • E-mail Settings and Preferences. If you no longer want to receive marketing e-mails from us, you may choose to unsubscribe at any time. You can also set your e-mail options to prevent the automatic downloading of images that may contain tracking technologies.

To Learn More about your rights and choices, please see our full Privacy Notice.

QUESTIONS ABOUT OUR PRIVACY POLICY?

If you have questions about our Privacy Notice, please feel free to email us at privacy@coca-cola.com.

Before accessing or using our Sites, please ensure that you have read and understood our collection, processing storage, use and disclosure of your personal information as described in this Privacy Notice.

See ANNEX 1 – DATA PROCESSORS

See ANNEX 2 – THIRD PARTY TRACKING TECHNOLOGIES

LAST REVISED: 20 June 2019

 

Coca-Cola PRIVACY NOTICE

Full Statement

 

CONTENTS

1. What is this Privacy Notice about?

2. What Personal Data do we collect about you?

a. The Personal Data we collect and process about you

b. Information automatically collected

c. Third party data collection and interest-based advertising

3. What Personal Data do we not collect about you?

4. Use of Sites by minors and warning for the parents

5. Your choices and control over your information

6. How do we use your Personal Data?

7. To whom your Personal Data are disclosed?

8. What transfers of Personal Data outside the European Economic Area do we carry out?

9. What about links to other websites, applications, platforms and alike?

10. What are your rights with regard to our processing of your Personal Data, how can you exercise them and how can you contact us?

11. How long do we keep your Personal Data?

12. How we protect your information

13. Applicable Law

14. Updates to this Privacy Notice

ANNEX 1 – DATA PROCESSORS

ANNEX 2 – THIRD PARTY TRACKING TECHNOLOGIES

 

1.                   What is this Privacy Notice about?

NV Coca-Cola Services SA, a company with registered office at Chaussée de Mons 1424, 1070 Brussels ("Data Controller", "CCS", "we", "our" and "us") respects your privacy and wants you to be familiar with how it collects, uses and discloses information directly or indirectly relating to you as an individual ("Personal Data"), and the rights that you have in this regard.

CCS is the data controller (within the meaning of the EU Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter referred to as the "General Data Protection Regulation") responsible for the processing of your Personal Data described in the Privacy Notice.

This privacy notice (the "Privacy Notice ") describes how CCS processes your Personal Data collected in relation to websites (our “Websites”) and any mobile sites, applications, widgets, and other mobile interactive features (collectively, our “Apps”) (all collectively, Apps and Websites, the “Sites”).

You can contact us by using the contact information provided in section 10 of this Privacy Policy.

2.                   What Personal Data do we collect about you?

Through the Sites, either on-line or off-line, we collect and process Personal Data in different ways:

  • When You Submit Personal Information To Us. We collect personal information about you when you actively provide them to us, for example when you register to create an account, or post comments, photos and videos, or record your voice in the context of your participation to a promotion, or chat with users.
  • When You Use Our Sites. We (and third-party partners on our behalf) collect some personal information about you automatically as you use our Sites.
  • When You are Offline: we collect your Personal Data when you are not using our Apps and/or Sites, for example when you participate to Coca-Cola events or when you contact our partner Sites;

a.                   The Personal Data we collect and process about you

  • Contact and profile information: Personal information, such as your first name, last, name, username, date of birth, age, phone number, postal address, business information, country of residence and e-mail address, when you register for our Sites, sign up for our mailing list, enter a contest, redeem a promotion, or enter a sweepstake, or otherwise communicate or interact with us;
  • Preferences and interests' information: Preferences set for notifications, marketing communications and how our site is displayed;
  • Social media profile: When you interact with our Sites through various social media networks, such as when you Log on Facebook on our Sites or you Like us on Facebook or when you follow us or share our content on Facebook, Twitter, Snapchat, LinkedIn, Instagram or other sites, we may receive information from those social networks including your profile information, user ID associated with your social media account, and any other information you allow the social network to share with third parties;
  • User Generated Content (UGC), comments, chat and opinions: When you contact us directly, e.g. by email, phone, mail or by completing an online form or by participating in an online chat, we will record your comments and opinions. We will also record comments and opinions you express when responding to surveys, entering sweepstakes or taking part in promotions we run. These categories of personal data may also include voice recording, photo and video, if you allow the Sites to use live video streams from your device camera.  This functionality is used to provide you with an enhanced interactive experience. We and our service providers do not collect, capture, or record images, the video-stream information or any information about faces in the video stream. The information stays on your device and is removed when you turn off the browser or app. However, we and our service providers may collect other information about how you use the functionality, such as how often and how long you use it.
  • Location data: Our application does not collect, store or read the location data through GPS, Wi-Fi or wireless network triangulation. We or our third-party providers collect only anonymized, randomly generated app id to detect user proximity to our point of sales and send location specific promo messages and discount offered in the stores around you

b.                   Information automatically collected

When you use our Sites, read our emails, or otherwise engage with us through a computer or mobile device, we and our third-party partners may automatically collect information about how you access and use the Sites and information about the device you use to access the Sites.

We use this information to enhance and personalize your user experience, to monitor and improve our Sites, and for other internal purposes.

We typically collect this information through a variety of tracking technologies, including cookies, Flash objects, pixel, web beacons, embedded scripts, location-identifying technologies, and similar technology (collectively, “tracking technologies”).

More in particular, through the tracking technologies we collect your Personal Data when you interact with the Sites; the tracking technologies will allow us, for example, to find nearby products for you, get you real-time offers, and more; to provide you with personalized marketing communications; to combat fraud; to analyze and improve how our products perform; to collect install data (device ID, traffic source, battery level, carrier, device model) to track media investment; and to fulfill other legitimate purposes.

You can accept and reject these technologies (except when necessary for the proper functioning of the App) by adjusting your Mobile phone settings or your privacy preferences on your Profile settings, as explained below in Section 5.

Information we collect automatically about you may be combined with other personal information we collect directly.

Below the information we may collect automatically

  • Information pertaining to your use of the Sites (e.g. how many times and for how long do you interact with the App, what videos you have watched, what raffles or contests you have participated in, which website you came from, how many times you clicked on an item);
  • Personal Data related to your interactions with our marketing communications (e.g. if you open them or not, if you click on them or not);
  • Information about the device(s) you use to access to and interact with the Sites (e.g. this enables us to know if you are using a computer, a tablet or a smartphone, your screen resolution, your operating system, your Wi-Fi connection, your internet browser and your IP address, Server log file information).
  • Behavioral Data: Information derived from the combination of the Device ID and the System events that may be used to identify behavioral trends and patters and send you marketing communications related to the events you have participated to.
  • Participation Data: Personal Data pertaining to your participation to the promotion, prize, poll, sweepstake, instant win promotion, contest and other types of promotions (e.g. type of promotion, date and time of participation to the promotion, outcome of the participation to the promotion, information required for your prize fulfillment, such as t-shirt and/or shoe size).
  • Analytics information: We may collect analytics data, or use third-party analytics tools, to help us measure traffic and usage trends for the Sites and to understand more about the demographics and behaviors of our users.

c.                   Third party data collection and interest-based advertising

  • Interest-Based Advertising: We participate in interest-based advertising and use third party advertising companies to serve you targeted advertisements based on your browsing history. We permit third-party online advertising networks, social media companies and other third-party services to collect information about your use of our websites and mobile apps over time so that they may play or display ads on our Sites, on other Websites and Apps or Sites you may use, and on other devices you may use. Typically, though not always, the information used for interest-based advertising is collected through cookies or similar tracking technologies, which recognize the device you are using and collect information, including click stream information, browser type, time and date you visited the site and other information. We may share a common account identifier (such as an email address or user ID) with our third-party advertising partners to help identify you across devices. We and our third-party partners use this information to make the advertisements you see online more relevant to your interests, as well as to collect advertising-related information such as reporting, attribution, analytics and market research. See Section 10 below to learn more about how you may control interest-based advertising.
  • Social Media Widgets and Advertising: Our Sites may include social media features, such as the Facebook Like button, Google Plus, LinkedIn, Snapchat, Instagram, Twitter or other widgets. These social media companies may recognize you and collect information about your visit to our Sites, and they may set a cookie or employ other tracking technologies. Your interactions with those features are governed by the privacy policies of those companies. We display targeted advertising to you through social media platforms, such as Facebook, Twitter, Google+ and others. These companies have interest-based advertising programs that allow us to direct advertisements to users who have shown interest in our Sites while those users are on the social media platform, or to groups of other users who share similar traits, such as likely commercial interests and demographics. These advertisements are governed by the privacy policies of those social media companies that provide them.
  • User Experience Information: On some of our websites or Sites, we use third party tools to monitor user experience information. These tools automatically collect usage information, including mouse clicks and movements, page scrolling and any text keyed into website forms. The information collected does not include passwords, payment details, or other sensitive personal data. We use this information for site analytics, optimization and to improve website usability. We do not permit this information to be shared with or used by third parties for their own purposes.
  • Please note that our online and email advertising-related vendors may use pixel tags, web beacons, clear GIFs or other similar technologies in connection with the Sites to help manage our online and email advertising campaigns and strengthen the effectiveness of such campaigns. For example, if a vendor has placed a unique cookie on your computer, the vendor may use pixel tags, web beacons, clear GIFs or other similar technologies to recognize the cookie during your visit to the Sites and to learn which of our online advertisements may have brought you to our Sites, and the vendor may provide us with such other information for our use.  Please note we may link such Other Information provided to us by our vendors to Personal Data about you that we have previously collected.
  • We may use third-party advertising companies to serve advertisements on our Sites. These companies may use information (not including your name, address, email address or telephone number) about your visits to this and other websites in order to provide advertisements about goods and services of interest to you.
  • We may link or combine your activities and information collected from you on our websites and mobile apps with information we collect automatically through tracking technologies. This allows us to provide you with a personalized experience regardless of how you interact with us – online, on mobile or social media.

3.                   What Personal Data do we not collect about you?

We do not collect and process Personal Data pertaining to your:

  • racial or ethnic origin;
  • political opinions;
  • religion or philosophical beliefs;
  • health or medical condition;
  • criminal background;
  • trade union membership;
  • genetic or biometric data;
  • sexual life or orientation;

(referred to as "Sensitive Personal Data").

We ask that you not send us, and not to disclose, any Sensitive Personal Data through the Sites or otherwise to us.

4.                   Use of Sites by minors and warning for the parents

The Sites are directed to individuals who are 13 years and above with parents’ consent until 16 years old.

For some Websites or Apps there may be age restrictions, based on what is appropriate viewing for certain ages or what is legally permitted by law.  Where specific age restrictions apply, it will be clearly marked on the relevant Site and we may ask questions to verify your age before proceeding.

This means that individuals under the age of 16 cannot participate to the activities listed in section 6 when these are grounded on consent, such as receiving marketing communications and personalized push notifications based on location, and we will not process their personal data.

5.                   Your choices and control over your information

Profile and data sharing settings: You may update your profile information, such as your user name, address, or billing information, and may change some of your data sharing preferences on your Account Page.

How to control your email preferences: You can stop receiving promotional email communications from us by clicking on the “unsubscribe” link provided in such communications. We make every effort to promptly process all unsubscribe requests. You may not opt out of service-related communications (e.g., account verification, transactional communications, changes/updates to features of the Service, technical and security notices).

Modifying or deleting your information: If you have any questions about reviewing, modifying, or deleting your information, or if you want to remove your name or comments from our website or publicly displayed content, you can contact us directly as further detailed in Section 10 of this Privacy Notice. We may not be able to modify or delete your information in all circumstances.

Geolocation: You may control location tracking by adjusting your location services settings on your mobile device. We may continue to approximate your location based on your IP address when you access the Service through a computer or device.

Photos, video and voice recording: You may control, including to exclude, the functionalities of the Sites concerning processing of photos, video, live streaming and voice recording by preventing the Sites from accessing the camera and or the microphone of your device.

Cookies, tracking and interest-based advertising preferences:

  • Cookies and Flash cookies. Most browsers allow you to adjust your browser settings to: (i) notify you when you receive a cookie, which lets you choose whether or not to accept it; (ii) disable existing cookies; or (iii) set your browser to automatically reject cookies.
  • Blocking or deleting cookies may negatively impact your experience using the Sites, as some features on our Sites may not work properly.
  • You may set your e-mail options to prevent the automatic downloading of images that may contain technologies that would allow us to know whether you viewed or engaged with our emails.
  • Deleting cookies does not delete Local Storage Objects (LSOs) such as Flash objects and HTML5. To manage Flash cookie settings and preferences, you must use the settings manager on Adobe’s website. If you choose to delete Flash objects from our Sites, then you may not be able to access and use all or part of the Sites or benefit from the information and Sites offered.
  • Interest-based advertising. To learn about interest-based advertising and how you may be able to opt-out of some of this advertising, you may wish to visit the NAI - Network Advertising Initiative’s online resources, at http://www.networkadvertising.org/choices, the DAA’s resources at www.aboutads.info/choices and/or Your Online Choices at http://www.youronlinechoices.com
  • Cross-device linking. Please note that opting-out of receiving interest-based advertising through the NAI’s and DAA’s or Your Online Choices online resources will only opt-out a user from receiving interest-based ads on that specific browser or device, but the user may still receive interest-based ads on his or her other devices. You must perform the opt-out on each browser or device you use.
  • Mobile advertising. You may also be able to limit interest-based advertising through the settings on your mobile device by selecting “limit ad tracking” (iOS) or “opt-out of interest-based ads” (Android). You may also be able to opt-out of some – but not all – interest-based ads served by mobile ad networks by visiting http://youradchoices.com/appchoices and downloading the mobile AppChoices app.   
  • Some of these opt-outs may not be effective unless your browser is set to accept cookies. If you delete cookies, change your browser settings, switch browsers or computers, or use another operating system, you will need to opt-out again.
  • Some of these opt-outs may not be effective unless your browser is set to accept cookies. If you delete cookies, change your browser settings, switch browsers or computers, or use another operating system, you will need to opt-out again.

6.                   How do we use your Personal Data?

a.                   To respond to your inquiries and requests:

  • To respond to your inquiries, complaints and suggestions regarding the Sites, that you send us via customer Sites or other communication channels.

Legal basis for processing: our legitimate interests to handle, adequately and in a timely manner, customers' inquiries, complaints and suggestions regarding the Sites.

b.                   To inform you about changes to the Sites' terms and conditions and to this Privacy Notice:

  • To send you information about the changes to the Sites’ terms and conditions and to this Privacy Notice.

Legal basis for processing: our legitimate interests to inform you well in advance of those changes taking effect.

c.                   Marketing communications:

  • To send you or have our commercial partners (individually a "Commercial Partner" and collectively "Commercial Partners") send you direct marketing communications by email and push notifications. Direct marketing communications inform you, among others, about promotions or other similar activities, about Coca-Cola and affiliated brands' products and Sites (or those of our Commercial Partners), and ask you to complete questionnaires and surveys.

Direct marketing communications sent by our Commercial Partners may either be:

o   Fully handled and managed by our Commercial Partners. In such circumstances, the relevant Commercial Partner in charge of each direct marketing communication will act as data controller for the processing of your Personal Data. This processing will be subject to a data privacy notice, distinct from this Privacy Notice, established by such Commercial Partner;

o   Handled and managed jointly by us and our Commercial Partners. In such circumstances, we and the relevant Commercial Partner will act as joint controllers for the processing of your Personal Data. We will enter into appropriate joint-controllership agreement with relevant Commercial Partner and the essence of this agreement will be made available to you. 

Legal basis for processing: your consent.

You can accept or refuse to receive direct marketing communications by using the privacy dashboard available at https://www.cocacola.co.uk/en/edit-profile/ or in the Profile Settings of the App (you just have to activate the relevant toggle button if you want to receive marketing communications, and deactivate it if you do not).

You can also withdraw your consent to receive direct marketing communications, by clicking on the link "Unsubscribe" at the bottom of every marketing email. Alternatively, you can let us know that you wish to withdraw your consent by email, by calling us or writing to us using the contact information listed in section 10 of this Privacy Notice.

d.                   Personalization of marketing communications:

  • We may tailor our marketing communications to you (including personalization of ads and recommendation of content displayed on our digital properties and third-party websites (desktop and mobile) and mobile applications) based on (i) your profile information, (ii) how you interact with our Sites (e.g. logging in, entering a promotion, winning, quiz participation, uploading content) and / or (iii) your interactions with our marketing communications (e.g. if you open them or not, if you click on them or not, if you watch them or not, if you engage with them or not).

Legal basis for processing: your consent.

You can accept or refuse personalization of marketing communications, by using the privacy dashboard available at https://www.cocacola.co.uk/en/edit-profile/ or in the Profile Settings of the App (you just have to activate the relevant toggle button if you want to receive marketing communications and deactivate the toggle button if not).

You can withdraw your consent to have your marketing communications personalized by letting us know that you wish to withdraw your consent by email, by calling us or writing to us using the contact information listed in section 10 of this Privacy Notice.

e.                   Promotions, special offers, loyalty programs, prize draws and other offers/promotions:

  • To allow you to participate to promotions, special offers, loyalty programs, prize draws and other offers/promotions (e.g. for sending you reminder emails, transferring your Personal Data to fulfilment partners). Personal Data that must be provided to register to an offer/promotion usually comprise your email address, user ID and password.

Legal basis for processingThe processing of your Personal Data for this purpose is based on performance of the relevant promotion terms and conditions.

f.                    Data analytics to derive trends & improve Coca-Cola products and Sites:

  • We collect your Personal Data to measure your engagement with the Sites (e.g. to know how you use our Sites, when do you use our Sites, using what device), analyze consumer behavior, derive consumption trends and patterns. This helps us to know better the Sites' users, segment them into meaningful groups and better adapt our content to the identified preferences of the users.

Legal basis for processing: your consent

You can accept or refuse this collection and use of Personal Data for the purpose of performing data analytics to derive trends and improve our App and more generally Coca-Cola products and Sites by setting your privacy preferences on your Profile settings. You just have to activate the relevant toggle button if you want to have your Personal Data processed for the purpose of allowing us to perform data analytics to derive trends and improve our App and more generally Coca-Cola products and Sites and deactivate the toggle button if not.

You can withdraw your consent to the abovementioned purpose by acceding this page https://www.cocacola.co.uk/en/edit-profile/ and deactivating the relevant toggle button. You can also let us know that you wish to withdraw your consent by email, by calling us or writing to us using the contact information listed in section 10 of this Privacy Notice. Once you withdraw your consent, we will stop the processing for the concerned purpose.

g.                   Data analytics for reporting and analysis purposes

  • We collect your Personal Data on our websites and/or mobile applications to create aggregated and anonymized reports and measure the performance of our physical products, digital properties, and marketing campaigns. From this analysis, we derive market trends for our digital activities and use them to improve and adapt our Coca-Cola products and services.

For this purpose, we may collect information pertaining to your use of our websites and/or mobile applications and information about the device(s) you use to access to and interact with the Services, including:

-     When you registered, verified your email address, verified your phone number, logged out, or logged in to one of our websites and/or mobile applications.

-     When you accepted a website’s and/or mobile application’s legal terms, such as its Terms & Conditions and Privacy Policy.

-     When you interacted with a website’s and/or mobile application’s content, such as clicking on a link, liking content, or sharing content.

-     When you entered into a game, competition, or promotion, typed in a pin code, scanned a pin code, barcode, or QR code from a product, collected loyalty points, spent loyalty points, or selected a prize.

Legal basis for processing: our legitimate interests to improve our products and services

h.                   Personalized push notifications based on your location

  • We will use beacon technology to detect your proximity to our point of sales and send you real-time notifications about our promotions and discounts offered in the stores around you. We will not collect or whatsoever process your geolocation data “GPS” data.

Legal basis for processing: your consent

You can accept or refuse this collection and use of Personal Data for the purpose of sending you personalized location-based push notifications by setting your privacy preferences on your Profile settings. You just have to activate the relevant toggle button if you want to have your Personal Data processed for the purpose of sending you personalized location-based push notifications and deactivate the toggle button if not. The toggle button is deactivated by default.

You can withdraw your consent to the abovementioned purpose by acceding this page https://www.cocacola.co.uk/en/edit-profile/ and deactivating the relevant toggle button. You can also let us know that you wish to withdraw your consent by email, by calling us or writing to us using the contact information listed in section 10 of this Privacy Notice. Once you withdraw your consent, we will stop the processing for the concerned purpose.

i.                    Technical functioning of the Sites

  • We collect and use your Personal Data to technically administer the Sites and ensure that they function properly. In particular, we collect device state information when the App crashes (such as unique device identifiers, physical location of the device at the time of the crash) to identify the cause of the crash and do what is necessary so that it does not happen again.

Legal basis for processing: our legitimate interests in ensuring that the Sites properly function from a technical / IT point of view.

j.                    Compliance with our legal obligations

  • To comply with our legal obligations, legal proceedings or government authorities' orders which can include orders from government authorities outside your country of residence, when we reasonably believe that we are legally required to do so and when disclosing your Personal Data is strictly necessary to comply with the said legal obligations, proceedings or government orders.

Legal basis for processing: compliance with our legal obligations.

k.                   Lawful protection of our interests:

  • To lawfully enforce our terms and conditions, protect our operations or those of any of our affiliates, protect our rights, privacy, safety or property, and/or that of our affiliates, and allow us to pursue available legal remedies or limit the damages that we may sustain.

Legal basis for processing: our legitimate interests to lawfully protect our organization.

l.                    Fraud detection

  • We process you profile information, information pertaining to your use of the Sites and information about the device(s) you use to access to and interact with the Sites, to identify if any fraudulent installations of the Sites are being committed.

Legal basis for processing: our legitimate interests to protect our organization against fraud

7.                   To whom your Personal Data are disclosed?

Your Personal Data are disclosed to the recipients listed in Annex 1.

8.                   What transfers of Personal Data outside the European Economic Area do we carry out?

To achieve the purposes described in this Privacy Notice, we transfer your Personal Data to countries that do not offer an adequate level of protection, such as the United States and Serbia.

Our data transfers to the countries that do not offer an adequate level of protection are subject to either of the following appropriate safeguards in accordance with the GDPR, to guarantee that your personal data are adequately protected:

- Standard data protection clauses adopted by the EU Commission under article 46 paragraph 2 of the GDPR (click here to access the EU Commission's decision on standard contractual clauses for transfers to processors established in third countries); and

- EU-U.S. Privacy Shield for transfers to entities located in the United States (click here to access to the EU Commission's decision pertaining to the EU-U.S. Privacy Shield).

To obtain any relevant information regarding any transfers of your Personal Data to third countries (including the relevant transfer mechanisms), please contact our Privacy Office at this address privacy@coca-cola.com

9.                   What about links to other websites, applications, platforms and alike?

When using the Sites, you can come across links to other websites, applications and platforms that are not provided by us but by other companies. We are not responsible for such websites, applications and platforms, and this Privacy Notice does not apply to them. You should read the policies and rules that such companies have posted on their websites, applications and platforms to understand how they protect your privacy.

10.               What are your rights in relation to our processing of your Personal Data, how can you exercise them and how can you contact us?

a.                   Your rights in relation to our processing of your Personal Data

With regard to our processing of your Personal Data described in this Privacy Notice, you have the right under certain circumstances:

  • to be provided with a copy of any Personal Data that we hold about you, and receive information about our processing of your Personal Data;
  • to require us to update or correct any inaccurate Personal Data, or complete any incomplete Personal Data;
  • to require that we stop processing your Personal Data (i) for personalization of marketing push notifications, (ii) for the purpose of performing data analytics to derive consumer behaviors' trends and patterns and improve our Coca-Cola products and Sites, (iii) for personalization of location-based push notifications, (iv) for the purpose of sending you direct marketing communications.

You also have the right, in certain circumstances:

  • to object to the processing of your Personal Data;
  • to require us to delete your Personal Data;
  • to restrict our processing of your Personal Data; and
  • to require us to transmit your Personal Data to you or to transfer or have them transferred to another data controller.

b.                   Contacting us to exercise your rights

If you wish to exercise any of your above rights, you can contact us using one of the options below.

  • You can contact us by using the Contact form, when made available on our Sites
  • You can send us an email to the following address: gbcic@coca-cola.com
  • You can call us on: 0800 227711
  • You can write to the following postal address: Consumer Interaction Centre, PO Box 73229, London E14 1RP.

Please specify clearly which information you would like us to provide you with, review, amend, stop processing, or delete.

You can also contact us if you have any questions or queries about our processing of your Personal Data, using the contact options above.

c.                   Our Data Protection Officer (DPO) contact details

You can contact our Data Protection Officer (DPO) at the following address: dpo@coca-cola.com.

d.                   Right to lodge a complaint to the competent data protection authority

You have a right to lodge a complaint with the relevant supervisory authority (in particular in the Member State of your habitual residence, place of work or place of the alleged infringement), if you are of the opinion that any of your Personal Data is processed in a manner constituting an infringement of the EU General Data Protection Regulation n. 2016 / 679 dated 27 April 2016.

11.               How long do we keep your Personal Data?

a.                   We intend to keep your Personal Data accurate and up-to-date. We will delete the Personal Data that we hold about you when we no longer need it.

b.                   We keep your Personal Data that we use for the purposes described in this Privacy Notice for a period of 2 years maximum, except:

  • where legal requirements imposing that we keep your Personal Data longer or less time apply;
  • your Personal Data that we use for the purpose of allowing you to participate to promotions, loyalty programs and similar programs, carrying out the promotions and similar programs until their fulfillment, for a period of 10 years maximum;
  • your personal data that we use for the purpose of responding to your requests for a period of 10 years maximum; and
  • your personal data that we use in connection with a personal data access request for a maximum of 5 years from the day we provided the information to you.

c.                   Consent-based cookies and technologies similar to cookies are kept 13 months maximum in your terminal equipment (except for session cookies and similar technologies which are kept during your browsing session).

d.                   Accounts in connection with our central Consumer Interaction Database that are not used for 1 month as from their creation (i.e. no consent provided to the processing of your data when such processing is grounded on consent - such as sending you marketing communications-, and/or no participation to promotions) will be deleted within 2 months as from their creation.

12.               How we protect your information

The security of your information is very important to us, and we have put in place safeguards to preserve the integrity and security of information we collect and that we share with our Sites providers.

The personal data are encrypted at rest using asymmetric and symmetric encryption, and they are encrypted in transit using a security technology called Secure Sockets Layer, abbreviated as SSL. The SSL technology encrypts the information before it is exchanged via the Internet between the user's device and the central systems of the Company, making them incomprehensible to the unauthorized and thus guaranteeing the confidentiality of the information transmitted. The use of SSL also requires a compatible browser capable of performing the "exchange" of a security key with a minimum length of 128 bits, necessary to establish the aforementioned secure connection with the central co-owner systems.

However, no security system is impenetrable, and we cannot guarantee the security of our systems 100%. If any information under our control is compromised as a result of a breach of security, we will take reasonable steps to investigate the situation and, where appropriate, notify those individuals whose information may have been compromised and take other steps, in accordance with any applicable laws and regulations.

13.               Applicable Law

This Privacy Notice is governed by and shall be construed in accordance with the laws of Belgium and any other mandatory provisions of applicable laws in the European Union.

14.               Updates to this Privacy Notice

You can find out when this Privacy Notice was last amended by checking "LAST REVISED" at the top of this page.

All material changes to this Privacy Notice will be communicated to you well in advance of the changes taking effect.

If you object to any changes, you may close your account. Continuing to use our Sites after we publish changes to this Privacy Notice means that you have read and understood the changes.

You can print, download or otherwise retain a copy of this Privacy Notice (and of any revised version) for your records.

 

15.               ANNEX 1 – DATA PROCESSORS

 

APP

WEBSITES

Beverage Services Limited which helps us in the management of our App.

Beverage Services Limited which helps us in the management of our Sites and in respect of our communications to you.

Coca-Cola European Partners Great Britain Limited which jointly handles the CIC with us.

Coca-Cola European Partners Great Britain Limited which jointly handles the CIC with us.

Endava, which helps us with the development of the Apps. Endava plc is located in 125 Old Broad Street, London, EC2N 1AR, United Kingdom.

MRM McCann, for technical support of our Consumer Relationship Management (CRM) system, sending of email communications, and analytics on email campaigns.

MRM McCann provides us two lines of support. Our first line of support services is provided from MRM McCann, located in calle Enrique Jardiel Poncela, 6, Madrid, Spain. Our second line of support services is provided from MRM McCann located in 360 W Maple Rd, Birmingham, MI 48009,

 

Adobe, for the hosting of our (i) Content Management System (CMS), (ii) Consumer Relationship Management (CRM) system, (iii) personalisation of ads displayed on our digital properties and third-party websites (desktop and mobile) and mobile applications and (iv) direct marketing communications via email or push notifications. Appsflyer Ltd. is located in 100 1st St 25th floor, San Francisco, CA 94105, USA. The servers of our Adobe Campaign instance are hosted on Amazon Web Services’ infrastructure in Oregon.

 

 

 

Akamai Identity Cloud (Janrain), which hosts our Consumer Identity & Access Management (CIAM) system where we store user profiles on our sites and apps. Akamai Technologies, Inc. is located in 150 Broadway, Cambridge, Massachusetts 02142 USA

 

 

Reply AG, which operates reporting solutions and performs data analytics. Reply AG is located in Berlin, Germany

Epam, which operates and handles the Consumer Interaction Database.

EPAM Systems, Inc. in London, Great Britain. The team itself is physically located in Hungary.

SaaStory (ItsAlive.io), which collects and manages your personal data when you use and interact with our chatbot on the Messenger Platform. SaaStory is located in 43 Rue Beaubourg, 75003 Paris, France.

SaaStory (ItsAlive.io), which collects and manages your personal data when you use and interact with our chatbot on the Messenger Platform. SaaStory is located in 43 Rue Beaubourg, 75003 Paris, France.

 

Microsoft Azure, which we use for secondary (data lake storage), data cleaning, consolidation and to perform data analysis and reporting. Microsoft is located in 2624 NE University Village St, Seattle, Washington State, USA.

 

Akamai Identity Cloud (Janrain), which hosts our Consumer Identity & Access Management (CIAM) system where we store user profiles on our sites and apps. Akamai Technologies, Inc. is located in 150 Broadway, Cambridge, Massachusetts 02142 USA

 

Amazon Web Services Ireland Ltd (AWS), which hosts the Sites/ (or) which hosts our IT systems and provides system support.  It is located in Burlington Plaza, Burlington Rd, Dublin 4, Ireland.

 

Amazon Web Services Ireland Ltd (AWS), which provides cloud computing technology. It is located in Burlington Plaza, Burlington Rd, Dublin 4, Ireland.

Google, for (i) cloud storage, big query databases and personalization of ads displayed on our digital properties and third-party websites (desktop and mobile) and mobile applications, for engagement tracking and (ii) hosting of Apigee, our Application Programming Interfaces (APIs). Google Ireland Limited is located in Gordon House, Barrow Street, Dublin 4, Ireland.

CIC contractors:

• Comdata Holding France, which supports the Customer Interaction Center activities. It is located in Avenue du General de Gaulle

92635, Gennevilliers Cedex, France.

• CCC Holding GmbH, which supports the Customer Interaction Center activities. It is located in Spengergasse 37, 1050 Vienna, Austria.

• Findasense España SL, which supports the Customer Interaction Center activities. It is located in Plaza de Callao, 28013, Madrid, Spain.

 

Our third-party service providers who provide services such as support in communications, auditing and consulting.

Crashlytics, which collects information when the App crashes (such as your device identifier, device hardware and OS information, version of the App, physical location of the device at the time of crash) to report the crash to us. Crashlytics is part of Google Ireland Limited, which is located in Gordon House, Barrow Street, Dublin 4, Ireland.

Our Commercial Partners with whom we may enter into a special relationship, for the conduct of their own marketing communications.  Because these third parties will use your Personal Data in accordance with their own privacy practices, you should check their websites for information regarding their privacy practices.

MRM McCann, for technical support of our Consumer Relationship Management (CRM) system, sending of email communications, and analytics on email campaigns. MRM//McCann is located in New York City, New York, USA The teams that provide services to Consumer Data & Precision Marketing portfolio are located in Detroit, Michigan, USA, and in Madrid, Spain.

A third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).

Appsflyer, which processes your Personal Data (i) for mobile marketing analytics and attribution (i.e. determining which channels, campaigns, partners delivered each App install) and (ii) [to detect fraudulent App installations].

Appsflyer Ltd. is located in San Francisco, California, USA.

 

As we believe to be necessary or appropriate relevant authorities, affiliates and third parties: (a) to comply with our legal obligations; (b) to respond to requests from public and government authorities which may include public and government authorities outside your country of residence; (c) to enforce our terms and conditions; (d) to protect our operations or those of any of our affiliates; (e) to protect our rights, privacy, safety or property, and/or that of our affiliates, you or others; and (f) to allow us to pursue available remedies or limit the damages that we may sustain.

Competent authorities: we can disclose your Personal Data to the extent strictly required by the law to competent authorities.

Salesforce, which hosts the platform in which responses to "contact us" inquiries are kept. It is located in Castellana 79, 28046 Madrid, Spain.

Adobe, for the hosting of our (i) Content Management System (CMS), (ii) Consumer Relationship Management (CRM) system, (iii) personalisation of ads displayed on our digital properties and third-party websites (desktop and mobile) and mobile applications and (iv) direct marketing communications via email or push notifications. Adobe Inc. is located in 345 Park Avenue San Jose, CA 95110-2704, USA

 

Our third-party Sites providers who provide Sites such as support in communications, auditing and consulting.

 

Our Commercial Partners with whom we may enter into a special relationship, for the conduct of their own marketing communications.  Because these third parties will use your Personal Data in accordance with their own privacy practices, you should check their websites for information regarding their privacy practices.

 

A third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).

 

As we believe to be necessary or appropriate relevant authorities, affiliates and third parties: (a) to comply with our legal obligations; (b) to respond to requests from public and government authorities which may include public and government authorities outside your country of residence; (c) to enforce our terms and conditions; (d) to protect our operations or those of any of our affiliates; (e) to protect our rights, privacy, safety or property, and/or that of our affiliates, you or others; and (f) to allow us to pursue available remedies or limit the damages that we may sustain.

 

Microsoft Azure, which we use for secondary (data lake storage), data cleaning, consolidation and to perform data analysis and reporting. Microsoft is located in 2624 NE University Village St, Seattle, Washington State, USA.  

 

 

Epam, which operates and handles the Consumer Interaction Database. EPAM Systems, Inc. is located in London, Great Britain.

 

Firebase, which processes your Personal Data for the purposes of analyzing the App's usage and users' engagement (e.g. how people use our App, when, with what device), [deriving trends and patterns from this analysis to personalize push notifications and delivering push notifications to the App's users]. Firebase is part of Google Ireland Limited, which is located in Gordon House, Barrow Street, Dublin 4, Ireland

 

 

16.               ANNEX 2 – THIRD PARTY TRACKING TECHNOLOGIES

 

Third Party Partner

Partner Product

Type of Tracking Technology

Description

Google

Google Analytics

Cookies, Tags, Pixels and IDs

 

Google Analytics, which tracks your engagement with the Website (e.g. to know how you use our Website, when do you use them, using what device), derive general consumption trends and patterns from this analysis, to allow us improve Coca-Cola products and services. Google Ireland Limited is located in Gordon House, Barrow Street, Dublin 4, Ireland

 

Appsflyer

Appsflyer

Recording events, sessions and clicks in the app

 

Appsflyer, which processes your Personal Data (i) for mobile marketing analytics and attribution (i.e. determining which channels, campaigns, partners delivered each App install) and (ii) to detect fraudulent App installations. Appsflyer Ltd. is located in 100 1st St 25th floor, San Francisco, CA 94105, USA.

 

Google

Firebase

Recording events, sessions and clicks in the app

 

Firebase, which processes your Personal Data for the purposes of analyzing the App's usage and users' engagement (e.g. how people use our App, when, with what device), [deriving trends and patterns from this analysis to personalize push notifications and delivering push notifications to the App's users]. Firebase is part of Google Ireland Limited, which is located in Gordon House, Barrow Street, Dublin 4, Ireland.

 

Salesforce

Audience Studio

Tracking scripts

 

Audience Studio, which processes your personal data for marketing analytics and interest-based advertising. Salesforce is located in Castellana 79, 28046 Madrid, Spain.