Privacy notice


Our Privacy Notice is set out below.

Introduction

This website www.coca-colahellenic.com (hereinafter, the “website”) is operated by Coca Cola HBC Italia S.r.l., with registered office at Sesto San Giovanni (Milan, Italy), Piazza Indro Montanelli, 30 - 20099 (hereinafter "Coca Cola HBC") which is the data controller. Coca Cola HBC Italia S.r.l. is a member of the Coca‑Cola HBC group of companies, the ultimate holding company of which is Coca‑Cola HBC AG (registered in Switzerland with company number CHE - 235.296.902 and registered address at Turmstrasse 26, 6312 Steinhausen, Switzerland).

All references to 'our', 'us', 'we', or 'company' within this policy and within the opt-in notice are deemed to refer to Coca-Cola HBC.

Coca‑Cola HBC is committed to preserving the privacy of all individuals having an interaction with us and to protecting any personal data that you may provide to us.

We provide this Privacy Notice to help you to understand what we do with any personal data that we obtain from you. By providing your personal data to us, you acknowledge that we collect, use, and disclose your personal data as described in this Privacy. If you do not agree to this Notice, please do not provide your personal details to us.

 

What is personal data?

Personal data is any information about an identified or identifiable individual, as defined by applicable law, such as name, email address and telephone number.

 

Personal data that we collect from you and use of data collected

We collect your personal data directly from you or any authorized third party when you interact with us as a business partner, including a client or a prospective client, a consumer or an applicant to our job postings. Also, we collect information on you through the website, even if you can in any case visit this website without telling us who you are or revealing any information about yourself. Our web servers collect the source IP addresses, for IT reasons, enabling you to connect to our platform providing you with our services, not the email addresses, of visitors. In addition, there are parts of this website where we need to collect personal data from you for a specific purpose, such as to provide you with certain information you request and where requested to register you to our website.

We do this through the use of online forms and every time you call our consumer care or email us your details. You will find that it is not compulsory to provide us with any additional information we request which is not necessary or reasonable in order to provide you with the services you have requested.

 

Data Subject

Collected Data

Purposes for the collection

Justification of the collection

Visitor of our Website

IP address, domain name, browser version and operating system, traffic data, location data, web logs

To analyse the use of the website, measuring the number of visits, average time spent on the website, pages viewed, in order to manage and improve our website and services offered

Legitimate interest to measure the use and to improve the content of our website

Name and email address collected through online forms submitted by the visitor of our website

To provide you with information about our promotional offers, news, events (newsletters and other publications), the Investor Relations or copies of our Annual Reports and to administrate subscription-service records (to a corporate webcast service or to an email alert service)

Your prior consent by ticking the appropriate box when providing your personal data to us

Name, address, telephone, fax number, and email address collected through online forms submitted by the visitor of our website

To response to your inquiries or to process your requests of information

 

 

To take appropriate steps at your request prior to entering into a contract and the performance of subsequent contractual obligations 

Name, address, telephone, email address

To defend our rights against the user and/or other third parties

Legitimate interest

Business Customer/ Supplier

 

 

Name, address, telephone, fax number, email address, VAT number, tax data, bank account, directly provided by our business partners

 

For sales and supply of goods and services order taking, delivery execution, invoicing, payment allocation, to provide or receive the requested goods and services, the managing of litigations related to our rights towards the business partners and third parties 

Performance of our mutual contractual obligations 

Name, address, telephone, fax number, email address, directly provided by our business partners

 

For marketing and promotional initiatives and, in particular, to contact the Business Customer by telephone and by visiting its office, on a regular basis, for the promotion of our products and/or services and for carrying out internal statistical analyses and market surveys

 

Legitimate interest

 

 

Data on the geo-localization of the display case-fridge, if provided by us on loan for use to the Business Customer, and if installed in the Business Customer's shop

The disclosure to external providers of consumer analysis platforms (such as, for example, DoveConviene S.r.l.) and their clients, in order to allow the promotion, addressed to consumers, of some products marketed in the Business Customers’ shop, if such consumers are in the proximity of the shop, as well as to allow the collection from these consumers of information about the type of customers and the related analysis, and therefore, the implementation of the product offer through said shop and the sales increase 

Legitimate interest 

 

Creditworthiness, , ID documents, credit ratings

 

Anti-bribery, anti-money laundering, sanctions, Know Your Customer, Credit and Anti-Fraud Checks

 

Legitimate interest

 

 

Name, address, telephone, fax number, email address, VAT number, tax data, bank account

The disclosure to third parties whose products are marketed via our commercial network, in order to improve the administration management of such Business Customers, thus facilitating the subsequent supply of such products to the Business Customers 

Legitimate interest 

 

Name, address, telephone, email address, VAT number, tax data

To defend our rights against the user and/or other third parties 

Legitimate interest

Name, address, telephone, fax number, email address, VAT number, tax data, bank account

Performance of activities leading to the transfer of business, or branches of business, acquisition, merger, demerger or any other transformation and for the execution of such operations 

Legitimate interest

Potential Business Customer / Potential Supplier

Name, address, telephone, fax number, Email address, tax data, bank account; received from our business customer/supplier

 

For pre-contractual evaluations & assessments of potential customers and suppliers (e.g. Tender process) 

 

To take appropriate steps at your request prior to entering into a contract and the performance of subsequent contractual obligations 

Name, address, telephone, fax number, email address, tax data, bank account, directly provided by our business partners

To send commercial communications for marketing and promotional initiatives.

The prior data subject’s consent 

 

Creditworthiness, , ID documents, credit ratings, 

Anti-bribery, anti-money laundering, sanctions, Know Your Customer, Credit and Anti-Fraud Check.

 Legitimate interest

Contact Person of the Business Customer/ Supplier

Name, address, telephone, fax number, email address, personal preferences; 

 

 

 

Name, address, telephone, fax number, email address, SMS notification preferences

To contact the customer/supplier for business purpose (e.g. order taking, service request) and for maintenance of the customer relationship 

 

 

Providing updates to customers for marketing and promotional initiatives.

 

Performance of our mutual contractual obligations 

 

Legitimate interest

 

Consumer

Name, address, telephone, address, fax number, and email address

Providing any services consumers’ have requested us

 

To take appropriate steps at your request prior to entering into a contract and the performance of subsequent contractual obligations 

Name, telephone number, address and email address  or any other information communicated by the consumer. In this context, the consumer may also provide for special categories of data, including data related to his/her health status, where the reported issue relates to the quality and safety of our products.

 

To respond to reported issues with products or questions on our products on the toll-free consumer service telephone line

To take appropriate steps at your request, to provide any requested services and ensure our consumers satisfaction. Where the management of the reported issue requires the collection of special categories of data, including data related to consumers’ health status, we process such data in order to comply with our legal obligations to ensure the quality and safety of our products. 

 

Name, address, telephone, email address

To defend our rights against the consumer and/or other third parties

Legitimate interest

Job Applicant

 

 

 

 

Name, address, telephone, email address, professional qualifications, experience and education; submitted by the job applicant 

 

 

 

Candidate management, to assess your application and to contact you via phone or email

 

Legitimate interest to assess your application prior to enteering into To take appropriate steps at your request prior to entering into an employment contract with us 

Consent in order to retain your data for other job opportunities

Publicly available data of the job applicant on contact information, social links, professional qualifications, experience and education

 

Candidate management, to enhance, validate and update applicant data to ensure validity and completeness

 

Consent

 

 

Video interview recording

 

To conduct interview process

 

Consent

 

Results of tests and assessments during the recruitment process

 

Candidate management, to conduct  evaluation of individual skills and competencies

Consent

As concerns all personal data required for the performance of our contract with you / your company, if you do not provide us with this personal data, we may not be able to deliver the requested service as mentioned in the above. On the contrary, for all data processing where you give your consent, you are entitled to refuse or withdraw your consent at any time without any detrimental impact on any contact you may have with us.

When we process your personal data for the pursuit of our legitimate interest according to Article 6(f) of the GDPR, our legitimate interest is adequately balanced with your interest since the data processing is performed within the limits strictly necessary to perform the activities mentioned above. Such data processing activity is not mandatory and you can object to it at any time through the modalities as per this Privacy Policy. In such case no data processing will be carried out by us for such purposes, except in case where we demonstrates the existence of legitimate prevailing arguments or the exercise of our right pursuant to Article 21 of the GDPR.

In any case, we reserve our right to provide individuals with any additional privacy information notices in exceptional cases where further specific processing activities are carried out on their personal data. 

 

Disclosures. Who are the recipients of your personal data?

The personal data you provide to us will be held in a Data center hosted in Crawley, UK, by a company named Rackspace, whose secondary site is in Ireland, and can be accessed by or given to our staff working outside UK and to third parties, to business partners, government bodies and law enforcement agencies, successors in title to our business and suppliers we engage to process data on our behalf, some of whom are located outside the European Economic Area, who act for us for the purposes and justifications set out in this policy.

 

Categories of the recipient

Purpose of the sharing

Companies within the Coca‑Cola Hellenic group of companies and/or third-party service providers (i.e. provider of IT services, consultants, etc.)  that process data on our behalf as data processors 

To provide our products and services

Any third-party service providers (i.e. provider of IT services, consultants, etc.) and/or any subsidiary/affiliate of Coca‑Cola HBC involved by us in the provision of the services you requested or requested by us for the purposes above listed in their quality as data processors 

Performance of the services you requested

Business partners which process personal data on our behalf as data processors

Performance of the services you requested

Government bodies in their quality as autonomous data controllers 

To fulfil a legal obligation

Law enforcement agencies in their quality as autonomous data controllers 

To fulfil a legal obligation

successors in title to our business and suppliers in their quality as autonomous data controllers 

Performance of the services you requested

Credit reference agencies, fraud prevention agencies, companies within the Coca‑Cola Hellenic group of companies and/or third-party service providers that process data on our behalf acting as data processors 

anti-bribery, anti-money laundering, sanctions, Know Your Customer, Credit and Anti-Fraud Check

All of the parties outside the EU to which personal data will be transferred process data, fulfil and deliver orders and provide support services on our behalf. We may also pass aggregate information on the usage of our site to third parties, but this will not include information that can be used to identify you. We reserve the right to disclose your personal data as required by law, or when we believe that disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, request from a regulator or any other legal process served on us.

Unless required to do so by law, we will not otherwise share, sell or distribute any of the personal data you provide to us without your consent.

Finally, if our business enters into a joint venture with or is sold to or merged with another business entity, your data will be disclosed to our new business partners or owners.

 

Are your personal data transferred outside the EU?

Since Coca‑Cola HBC operates in many countries, your personal data can be accessed by staff or suppliers in, transferred to, and/or stored at, a destination outside the EU in which data protection laws may be of a lower standard than in the EU and, in particular, in Armenia, Belarus, Bosnia and Herzegovina, Moldova, Montenegro, Nigeria, Russia, Serbia, Switzerland, Ukraine. However we always seek to ensure that your personal data receives the same level of protection as it would had it stayed within the EU, including seeking to ensure that it is kept secure and used only in accordance with our instructions and for the agreed purpose(s). 

Certain countries outside the EU have been approved by the European Commission as providing essentially equivalent protections to EU data protection laws and therefore no additional safeguards are required to export personal information to these jurisdictions (see the full list here http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.htm). In countries which have not had these approvals (such as Russia), we will transfer personal data subject to European Commission approved contractual terms that impose equivalent data protection obligations directly on the recipient unless we are permitted under applicable data protection law to make such transfers without such formalities.

Please contact us as set out in Contact us section below if you would like to see a copy of the specific safeguards applied to the export of your personal data.

 

How we protect your personal data

Users aged 16 and under

If you are aged 16 or under, please get your parent's or guardian's permission before you provide any personal data to us. Users without this consent are not allowed to provide us with personal data.

Other websites

Our website contains links to other websites which are outside our control and are not covered by this Privacy Notice. If you access other sites using the links provided, the operators of these sites may collect information from you which will be used by them in accordance with their Privacy Policies, which may differ from ours. We do not accept any responsibility or liability for their policies or processing of your personal data. We encourage you to read the privacy and cookie notices and terms and conditions of any linked, referenced, or interfacing websites you enter before you submit any personal data to such third-party websites.

Security of data collected and data retention

We employ strict physical, electronic, and administrative security measures to protect your data from access by unauthorised persons and against unlawful processing, accidental loss, destruction and damage both online and offline. We will retain your data for as long as necessary for said purpose of the collection and after that we will retain your data as long as the law requires.

In particular, we retain personal data in an identifiable format only for the interval that is necessary as identified by the purposes of processing for which data are collected.

We must not keep personal data for longer than necessary to fulfil the identified lawful business purposes or as long as required by applicable law. 

We establishes a personal data retention period in accordance with relevant laws and regulations as part of the record of processing activities. 

We must justify the requirements to retain personal data for periods longer than the maximum retention period as per business and regulatory requirements if required. 

Some data must be retained in order to protect the company's interests, preserve evidence, and generally conform to good business practices. Some reasons for data retention include:

  • • Litigation
  • • Accident investigation
  • • Security incident investigation
  • • Regulatory requirements
  • • Intellectual property preservation

Internet-based transfers and disclaimer

Whereas we employ reasonable measures to protect against viruses and other harmful components, the nature of the internet is such that it is impossible to ensure that your access to the website will be uninterrupted or error-free, or that this website, its servers or emails which may be sent by us are free of viruses or other harmful components.

 

Contacting us and your rights on the processing of personal data, including the right to access and update your personal data

Accessing, updating and deleting data

You are entitled to see the personal data we hold about you; you can also ask us to make any necessary changes to ensure that it is accurate and kept up to date or to delete the personal data we hold about you. You can also inform us if you would like to restrict the data processing or object to the processing of personal data, we hold about you. If you wish to do this, please contact us using the contact details provided at the Contact us section below. You are also entitled to provide the personal data we hold about you to another service provider of your choice.

Withdrawing the consent

In case we asked you for your consent to process personal data we hold about you, you can withdraw your consent at any time, without affecting the lawfulness of processing based on consent before the withdrawal. If you wish to do this, please contact us using the contact details provided at the Contact us section below.

Complaint

You have the right to lodge a complaint before the national data protection authority by sending your claim to it. In particular, the Italian Data Protection Authority is the Garante per la protezione dei dati personali, whose contact details are available at the following link https://www.garanteprivacy.it/

Contacting us

If you have any comments relating to our use of your personal data or any questions about this Privacy Notice, please contact us using the following e-mail address: DataProtectionOffice@cchellenic.com. We welcome your questions and any suggestions you may have about our Privacy Notice.

To formally exercise your rights in relation to your personal data we process, please submit a request accessing the below link:

Web Form

or contact us using the following email address: DataProtectionOffice@cchellenic.com

Furthermore, please note that we have designated a Data Protection Officer who may be contacted to the following address DataProtectionOffice@cchellenic.com.  

 

How changes to this Privacy Policy will be made

Please check this Privacy Notice periodically to be informed of any changes. Although we reserve the right to modify or supplement this Privacy Policy, we will provide notice to you on this website of any major changes for at least 30 days following the change and, where appropriate, through email notification.