POLICY

Information on the processing of personal data of customers

Privacy Notice on the Processing of Personal Data of Customers and Prospective Customers

Coca-Cola HBC Italia S.r.l., in its capacity as Data Controller (the “Controller”), hereby informs you that the personal data of the data subject (where the data subject is a natural person or sole proprietorship), as well as that of its partners, employees, or representatives (hereinafter, the “Data Subjects”), communicated for the purposes of new customer acquisition activities (so-called prospecting), promotion of its services and/or products, and activities carried out in connection with contractual services, including, by way of example and not limitation, commercial, product supply and service activities (hereinafter, the “Activities”) between the Controller and the other party (hereinafter referred to, as applicable, as the “Prospective Customer” or the “Customer”), during the performance of such Activities and related activities, will be processed in accordance with this Privacy Notice.

Personal data will be processed in full compliance with the principles of fairness, lawfulness, transparency, and with due regard for the rights and confidentiality of the Customer.

1. Data Controller

The Data Controller is:

Coca-Cola HBC Italia S.r.l.
Piazza Indro Montanelli 30
20099 Sesto San Giovanni (Milan), Italy

The Controller has appointed data processors where necessary in accordance with applicable legislation. The complete list of data processors is available upon written request to the email address indicated below.

The Controller has appointed a Data Protection Officer (“DPO”) pursuant to Article 37 of Regulation (EU) 2016/679 (the “GDPR”), who may be contacted at:

DataProtectionOffice@cchellenic.com

2. Personal Data Collected

The Controller collects and processes the following personal data regarding the Data Subjects (collectively, the “Data”):

  1. Identification and contact data of the Prospective Customer and/or Customer, including, for example, company name or business name, registered office, address, telephone number, fax number, email address, VAT number, tax code, names of customer contacts, and information relating to the Customer’s points of sale;

  2. Economic and financial data relating to the Customer, such as financial solvency information, bank account details (IBAN), payment information, commercial invoices issued for the supply of goods and services and related payments (accounting transactions), customer satisfaction ratings, responses to questionnaires, and customer service-related information;

  3. Geographical location data concerning the Customer’s business premises, enriched with aggregated demographic and commercial information obtained from public sources or through processing by third parties or by the Controller;

  4. Geolocation data relating to refrigerated display units that may be provided on a loan-for-use basis by the Controller and installed at the Customer’s premises;

  5. Personal data provided by users during activation of the point-of-sale user account/profile on the website www.v-orders.com or its related web application (“Website/Web-App”), and during use of the related services (e.g., transfer order management), including:

    • first name;
    • last name;
    • login credentials;
    • email address; and
    • password.

The Data may be provided directly by the Data Subjects, obtained from independent third-party controllers such as business information providers, or derived from public registers, directories or databases for the processing purposes described below.

3. Purposes of Processing

The Data are processed for the following purposes:

3.1 Contractual Purposes

To:

i. perform the contract with the Customer and fulfil contractual and pre-contractual obligations, as well as specific activities requested by the Customer;

ii. provide customer support services;

iii. manage Customer administration, including customer master data management, order management, contract and invoice management, accounting, and credit management;

iv. contact the Customer via telephone communications with an operator in connection with contractual and pre-contractual activities;

v. organize periodic visits to the Customer’s premises and/or point of sale for the promotion of the Controller’s products and services.

(“Contractual Purposes”)

3.2 Consent for Product Offer Optimization on Third-Party Online Platforms

To allow the sharing of the identification data referred to in Section 2.1 with third-party companies operating in the food delivery sector in order to optimize the offering of the Controller’s products by the Customer on food delivery apps and platforms, subject to the Customer’s free, specific, informed and unambiguous consent.

Data Subjects may withdraw consent at any time free of charge without affecting the lawfulness of processing carried out before withdrawal.

3.3 Marketing Legitimate Interest Purposes

To:

i. visit Prospective Customers and conduct prospecting activities following their expression of interest in the Controller’s products and services;

ii. carry out internal statistical analyses and market research;

iii. communicate the geographic location data referred to in Section 2.3 to operators of external consumer analytics platforms (e.g., DoveConviene S.r.l.) and their customers, in order to promote products sold through the Customer’s point of sale to consumers located nearby, collect data regarding consumer profiles, conduct related analyses, optimize product offerings, and increase sales;

iv. improve products and services based on customer satisfaction indicators and questionnaire feedback;

v. improve product placement in vending machines and other systems and achieve additional operational efficiencies.

(“Marketing Legitimate Interest Purposes”)

3.4 Business Legitimate Interest Purposes

To:

i. share Customer identification data with affiliated companies within the Hellenic Group whose products are marketed through the Controller’s commercial network, for administrative and logistics purposes;

ii. protect, manage and recover receivables through out-of-court, quasi-judicial and judicial activities;

iii. analyze corporate credit performance overall, by customer, or by homogeneous customer groups;

iv. assess Customer payment behavior through accounting information;

v. carry out activities related to company transfers, business unit transfers, acquisitions, mergers, demergers or other corporate reorganizations;

vi. manage Customer relationships and provide efficient customer care services;

vii. classify Customers into clusters with similar characteristics through the combination of geographical and aggregated demographic/commercial information;

viii. perform internal statistical analyses and business performance evaluations aimed at improving services.

(“Business Legitimate Interest Purposes”)

3.5 General Legitimate Interest

For litigation management and the exercise of the Controller’s rights and legitimate interests against Customers and/or third parties, including legal defense, complaint handling, and fraud or unlawful activity prevention.

3.6 Website/Web-App User Account Activation

To activate the point-of-sale user account/profile allowing access to activities managed through the Website/Web-App.

3.7 Legal Compliance

To comply with legal and regulatory obligations.

(“Legal Purposes”)

4. Nature of Data Provision and Legal Basis

The provision of Data is mandatory for:

  • Contractual Purposes, as it is necessary to perform the Activities with the Customer; and
  • Legal Purposes, as required by applicable laws and regulations.

Failure to provide such Data will prevent the Controller from establishing a contractual relationship and fulfilling Customer requests.

The provision of Data for the purpose described in Section 3.2 is optional. Refusal to provide consent will not affect the relationship between the parties, although product offer optimization on food delivery platforms may not be available.

Processing for Marketing Legitimate Interest Purposes, Business Legitimate Interest Purposes and General Legitimate Interest Purposes is based on the Controller’s legitimate interests, balanced against the rights and freedoms of the Data Subjects.

The provision of Data for Website/Web-App account activation is voluntary. However, failure to provide the Data will prevent the user from accessing and using the Website/Web-App and related services.

By activating a profile and logging into the Website/Web-App, the Data Subject accepts the applicable terms and conditions and the processing activities described in this Privacy Notice.

5. Methods of Processing

Data are processed in paper, electronic and telematic form and stored in company databases (e.g., customer databases, administrative databases).

Processing operations include:

  • collection;
  • recording;
  • organization;
  • structuring;
  • storage;
  • consultation;
  • use;
  • processing; and
  • comparison.

Data will be:

  • processed lawfully and fairly;
  • collected for specified, explicit and legitimate purposes;
  • adequate, relevant and limited to what is necessary;
  • retained only for the time necessary to achieve the purposes for which they were collected and processed.

6. Disclosure of Data

Data may be disclosed, only where necessary, to:

  1. Employees and collaborators of the Controller involved in commercial, technical assistance, production, administration and related activities;

  2. Data processors, including:

    • administrative and tax consultants;
    • suppliers of electronic tools, applications and tracking systems;
    • external professional consultants;
    • customer care support providers;
    • customer satisfaction analysis providers;
    • debt recovery providers;
    • credit monitoring services;
    • customer segmentation service providers;
  3. Independent data controllers, including:

    • banks and insurance companies;
    • commercial information companies (including Cerved Group S.p.A.);
    • law firms;
    • consumer analytics platform providers and their clients;
    • public authorities;
    • law enforcement authorities and judicial authorities;
  4. Other companies within the Coca-Cola Hellenic Group located in Italy or abroad for the management of data processing, payments and credit activities.

The Controller will not disclose the Data to the public under any circumstances.

7. International Data Transfers

Data may be freely transferred within the European Union.

Data may also be transferred outside the European Union, including to Coca-Cola Hellenic Group companies located in countries outside the European Economic Area, including Armenia, Belarus, Bosnia and Herzegovina, North Macedonia, Moldova, Montenegro, Nigeria, Russia, Serbia and Ukraine.

Any transfers outside the European Union will be carried out in compliance with the safeguards provided for under Articles 45 and 46 of the GDPR.

Data Subjects have the right to obtain a copy of the Data transferred abroad and information regarding where such Data are stored.

8. Data Retention Periods

The Controller retains Data only for as long as necessary to achieve the purposes outlined above.

Specifically:

  1. Contractual Purposes: throughout the duration of the contract and for 10 years thereafter;

  2. Legal Purposes: for the period required by applicable law;

  3. General Legitimate Interest Purposes: for the duration of the contractual relationship and 10 years thereafter;

  4. Marketing Legitimate Interest Purposes: throughout the duration of the service used and for 2 years following the last purchase and/or termination of the service;

  5. Business Legitimate Interest Purposes: for the duration of the contractual relationship and 10 years thereafter.

Aggregated demographic and commercial information associated with customer geolocation data is updated frequently and therefore subject to significantly shorter retention periods.

9. Rights of Data Subjects

Data Subjects may, at any time and free of charge:

  • obtain confirmation as to whether their personal data are being processed;
  • access their personal data;
  • learn the origin, purposes, methods and logic of the processing;
  • request rectification, updating or completion of their data;
  • request erasure, anonymization or restriction of unlawfully processed data;
  • object to processing on legitimate grounds;
  • object to direct marketing activities carried out through automated or traditional means;
  • withdraw consent at any time where processing is based on consent;
  • request restriction of processing under Article 18 GDPR;
  • request data portability;
  • lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) where applicable.

For any questions regarding this Privacy Notice or to exercise their rights, Data Subjects may contact the Data Protection Officer at the email address indicated above.

10. Amendments and Updates

The Controller may amend and/or supplement this Privacy Notice at any time, including as a consequence of changes to applicable privacy legislation.

Any amendments will be communicated in advance and may be made available through the Controller’s communication channels or websites, which should be consulted periodically.

Last updated: January 2026.