Our Privacy Notice is set out below.
Introduction
This website www.coca-colahellenic.com (hereinafter, the “website”) is operated by Coca Cola HBC Italia S.r.l., with registered office at Sesto San Giovanni (Milan, Italy), Piazza Indro Montanelli, 30 - 20099 (hereinafter "Coca Cola HBC") which is the data controller. Coca Cola HBC Italia S.r.l. is a member of the Coca‑Cola HBC group of companies, the ultimate holding company of which is Coca‑Cola HBC AG (registered in Switzerland with company number CHE - 235.296.902 and registered address at Turmstrasse 26, 6312 Steinhausen, Switzerland).
All references to 'our', 'us', 'we', or 'company' within this policy and within the opt-in notice are deemed to refer to Coca-Cola HBC.
Coca‑Cola HBC is committed to preserving the privacy of all individuals having an interaction with us and to protecting any personal data that you may provide to us.
We provide this Privacy Notice to help you to understand what we do with any personal data that we obtain from you. By providing your personal data to us, you acknowledge that we collect, use, and disclose your personal data as described in this Privacy. If you do not agree to this Notice, please do not provide your personal details to us.
What is personal data?
Personal data is any information about an identified or identifiable individual, as defined by applicable law, such as name, email address and telephone number.
Personal data that we collect from you and use of data collected
We collect your personal data directly from you or any authorized third party when you interact with us as a business partner, including a client or a prospective client, a consumer or an applicant to our job postings. Also, we collect information on you through the website, even if you can in any case visit this website without telling us who you are or revealing any information about yourself. Our web servers collect the source IP addresses, for IT reasons, enabling you to connect to our platform providing you with our services, not the email addresses, of visitors. In addition, there are parts of this website where we need to collect personal data from you for a specific purpose, such as to provide you with certain information you request and where requested to register you to our website.
We do this through the use of online forms and every time you call our consumer care or email us your details. You will find that it is not compulsory to provide us with any additional information we request which is not necessary or reasonable in order to provide you with the services you have requested.
Data Subject |
Collected Data |
Purposes for the collection |
Justification of the collection |
Visitor of our Website |
IP address, domain name, browser version and operating system, traffic data, location data, web logs |
To analyse the use of the website, measuring the number of visits, average time spent on the website, pages viewed, in order to manage and improve our website and services offered |
Legitimate interest to measure the use and to improve the content of our website |
Name and email address collected through online forms submitted by the visitor of our website |
To provide you with information about our promotional offers, news, events (newsletters and other publications), the Investor Relations or copies of our Annual Reports and to administrate subscription-service records (to a corporate webcast service or to an email alert service) |
Your prior consent by ticking the appropriate box when providing your personal data to us |
|
Name, address, telephone, fax number, and email address collected through online forms submitted by the visitor of our website |
To response to your inquiries or to process your requests of information
|
To take appropriate steps at your request prior to entering into a contract and the performance of subsequent contractual obligations |
|
Name, address, telephone, email address |
To defend our rights against the user and/or other third parties |
Legitimate interest |
|
Business Customer/ Supplier
|
Name, address, telephone, fax number, email address, VAT number, tax data, bank account, directly provided by our business partners
|
For sales and supply of goods and services order taking, delivery execution, invoicing, payment allocation, to provide or receive the requested goods and services, the managing of litigations related to our rights towards the business partners and third parties |
Performance of our mutual contractual obligations |
Name, address, telephone, fax number, email address, directly provided by our business partners
|
For marketing and promotional initiatives and, in particular, to contact the Business Customer by telephone and by visiting its office, on a regular basis, for the promotion of our products and/or services and for carrying out internal statistical analyses and market surveys
|
Legitimate interest
|
|
|
Data on the geo-localization of the display case-fridge, if provided by us on loan for use to the Business Customer, and if installed in the Business Customer's shop |
The disclosure to external providers of consumer analysis platforms (such as, for example, DoveConviene S.r.l.) and their clients, in order to allow the promotion, addressed to consumers, of some products marketed in the Business Customers’ shop, if such consumers are in the proximity of the shop, as well as to allow the collection from these consumers of information about the type of customers and the related analysis, and therefore, the implementation of the product offer through said shop and the sales increase |
Legitimate interest |
|
Creditworthiness, , ID documents, credit ratings
|
Anti-bribery, anti-money laundering, sanctions, Know Your Customer, Credit and Anti-Fraud Checks
|
Legitimate interest
|
|
Name, address, telephone, fax number, email address, VAT number, tax data, bank account |
The disclosure to third parties whose products are marketed via our commercial network, in order to improve the administration management of such Business Customers, thus facilitating the subsequent supply of such products to the Business Customers |
Legitimate interest |
|
Name, address, telephone, email address, VAT number, tax data |
To defend our rights against the user and/or other third parties |
Legitimate interest |
Name, address, telephone, fax number, email address, VAT number, tax data, bank account |
Performance of activities leading to the transfer of business, or branches of business, acquisition, merger, demerger or any other transformation and for the execution of such operations |
Legitimate interest |
|
Potential Business Customer / Potential Supplier |
Name, address, telephone, fax number, Email address, tax data, bank account; received from our business customer/supplier
|
For pre-contractual evaluations & assessments of potential customers and suppliers (e.g. Tender process)
|
To take appropriate steps at your request prior to entering into a contract and the performance of subsequent contractual obligations |
Name, address, telephone, fax number, email address, tax data, bank account, directly provided by our business partners |
To send commercial communications for marketing and promotional initiatives. |
The prior data subject’s consent
|
|
Creditworthiness, , ID documents, credit ratings, |
Anti-bribery, anti-money laundering, sanctions, Know Your Customer, Credit and Anti-Fraud Check. |
Legitimate interest |
|
Contact Person of the Business Customer/ Supplier |
Name, address, telephone, fax number, email address, personal preferences;
Name, address, telephone, fax number, email address, SMS notification preferences |
To contact the customer/supplier for business purpose (e.g. order taking, service request) and for maintenance of the customer relationship
Providing updates to customers for marketing and promotional initiatives.
|
Performance of our mutual contractual obligations
Legitimate interest
|
Consumer |
Name, address, telephone, address, fax number, and email address |
Providing any services consumers’ have requested us
|
To take appropriate steps at your request prior to entering into a contract and the performance of subsequent contractual obligations |
Name, telephone number, address and email address or any other information communicated by the consumer. In this context, the consumer may also provide for special categories of data, including data related to his/her health status, where the reported issue relates to the quality and safety of our products.
|
To respond to reported issues with products or questions on our products on the toll-free consumer service telephone line |
To take appropriate steps at your request, to provide any requested services and ensure our consumers satisfaction. Where the management of the reported issue requires the collection of special categories of data, including data related to consumers’ health status, we process such data in order to comply with our legal obligations to ensure the quality and safety of our products. |
|
|
Name, address, telephone, email address |
To defend our rights against the consumer and/or other third parties |
Legitimate interest |
Job Applicant
|
Name, address, telephone, email address, professional qualifications, experience and education; submitted by the job applicant
|
Candidate management, to assess your application and to contact you via phone or email
|
Legitimate interest to assess your application prior to enteering into To take appropriate steps at your request prior to entering into an employment contract with us Consent in order to retain your data for other job opportunities |
Publicly available data of the job applicant on contact information, social links, professional qualifications, experience and education
|
Candidate management, to enhance, validate and update applicant data to ensure validity and completeness
|
Consent
|
|
|
Video interview recording
|
To conduct interview process
|
Consent
|
Results of tests and assessments during the recruitment process
|
Candidate management, to conduct evaluation of individual skills and competencies |
Consent |
As concerns all personal data required for the performance of our contract with you / your company, if you do not provide us with this personal data, we may not be able to deliver the requested service as mentioned in the above. On the contrary, for all data processing where you give your consent, you are entitled to refuse or withdraw your consent at any time without any detrimental impact on any contact you may have with us.
When we process your personal data for the pursuit of our legitimate interest according to Article 6(f) of the GDPR, our legitimate interest is adequately balanced with your interest since the data processing is performed within the limits strictly necessary to perform the activities mentioned above. Such data processing activity is not mandatory and you can object to it at any time through the modalities as per this Privacy Policy. In such case no data processing will be carried out by us for such purposes, except in case where we demonstrates the existence of legitimate prevailing arguments or the exercise of our right pursuant to Article 21 of the GDPR.
In any case, we reserve our right to provide individuals with any additional privacy information notices in exceptional cases where further specific processing activities are carried out on their personal data.
Disclosures. Who are the recipients of your personal data?
The personal data you provide to us will be held in a Data center hosted in Crawley, UK, by a company named Rackspace, whose secondary site is in Ireland, and can be accessed by or given to our staff working outside UK and to third parties, to business partners, government bodies and law enforcement agencies, successors in title to our business and suppliers we engage to process data on our behalf, some of whom are located outside the European Economic Area, who act for us for the purposes and justifications set out in this policy.
Categories of the recipient |
Purpose of the sharing |
Companies within the Coca‑Cola Hellenic group of companies and/or third-party service providers (i.e. provider of IT services, consultants, etc.) that process data on our behalf as data processors |
To provide our products and services |
Any third-party service providers (i.e. provider of IT services, consultants, etc.) and/or any subsidiary/affiliate of Coca‑Cola HBC involved by us in the provision of the services you requested or requested by us for the purposes above listed in their quality as data processors |
Performance of the services you requested |
Business partners which process personal data on our behalf as data processors |
Performance of the services you requested |
Government bodies in their quality as autonomous data controllers |
To fulfil a legal obligation |
Law enforcement agencies in their quality as autonomous data controllers |
To fulfil a legal obligation |
successors in title to our business and suppliers in their quality as autonomous data controllers |
Performance of the services you requested |
Credit reference agencies, fraud prevention agencies, companies within the Coca‑Cola Hellenic group of companies and/or third-party service providers that process data on our behalf acting as data processors |
anti-bribery, anti-money laundering, sanctions, Know Your Customer, Credit and Anti-Fraud Check |
All of the parties outside the EU to which personal data will be transferred process data, fulfil and deliver orders and provide support services on our behalf. We may also pass aggregate information on the usage of our site to third parties, but this will not include information that can be used to identify you. We reserve the right to disclose your personal data as required by law, or when we believe that disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, request from a regulator or any other legal process served on us.
Unless required to do so by law, we will not otherwise share, sell or distribute any of the personal data you provide to us without your consent.
Finally, if our business enters into a joint venture with or is sold to or merged with another business entity, your data will be disclosed to our new business partners or owners.
Are your personal data transferred outside the EU?
Since Coca‑Cola HBC operates in many countries, your personal data can be accessed by staff or suppliers in, transferred to, and/or stored at, a destination outside the EU in which data protection laws may be of a lower standard than in the EU and, in particular, in Armenia, Belarus, Bosnia and Herzegovina, Moldova, Montenegro, Nigeria, Russia, Serbia, Switzerland, Ukraine. However we always seek to ensure that your personal data receives the same level of protection as it would had it stayed within the EU, including seeking to ensure that it is kept secure and used only in accordance with our instructions and for the agreed purpose(s).
Certain countries outside the EU have been approved by the European Commission as providing essentially equivalent protections to EU data protection laws and therefore no additional safeguards are required to export personal information to these jurisdictions (see the full list here http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.htm). In countries which have not had these approvals (such as Russia), we will transfer personal data subject to European Commission approved contractual terms that impose equivalent data protection obligations directly on the recipient unless we are permitted under applicable data protection law to make such transfers without such formalities.
Please contact us as set out in Contact us section below if you would like to see a copy of the specific safeguards applied to the export of your personal data.
How we protect your personal data
Users aged 16 and under
If you are aged 16 or under, please get your parent's or guardian's permission before you provide any personal data to us. Users without this consent are not allowed to provide us with personal data.
Other websites
Our website contains links to other websites which are outside our control and are not covered by this Privacy Notice. If you access other sites using the links provided, the operators of these sites may collect information from you which will be used by them in accordance with their Privacy Policies, which may differ from ours. We do not accept any responsibility or liability for their policies or processing of your personal data. We encourage you to read the privacy and cookie notices and terms and conditions of any linked, referenced, or interfacing websites you enter before you submit any personal data to such third-party websites.
Security of data collected and data retention
We employ strict physical, electronic, and administrative security measures to protect your data from access by unauthorised persons and against unlawful processing, accidental loss, destruction and damage both online and offline. We will retain your data for as long as necessary for said purpose of the collection and after that we will retain your data as long as the law requires.
In particular, we retain personal data in an identifiable format only for the interval that is necessary as identified by the purposes of processing for which data are collected.
We must not keep personal data for longer than necessary to fulfil the identified lawful business purposes or as long as required by applicable law.
We establishes a personal data retention period in accordance with relevant laws and regulations as part of the record of processing activities.
We must justify the requirements to retain personal data for periods longer than the maximum retention period as per business and regulatory requirements if required.
Some data must be retained in order to protect the company's interests, preserve evidence, and generally conform to good business practices. Some reasons for data retention include:
- • Litigation
- • Accident investigation
- • Security incident investigation
- • Regulatory requirements
- • Intellectual property preservation
Internet-based transfers and disclaimer
Whereas we employ reasonable measures to protect against viruses and other harmful components, the nature of the internet is such that it is impossible to ensure that your access to the website will be uninterrupted or error-free, or that this website, its servers or emails which may be sent by us are free of viruses or other harmful components.
Contacting us and your rights on the processing of personal data, including the right to access and update your personal data
Accessing, updating and deleting data
You are entitled to see the personal data we hold about you; you can also ask us to make any necessary changes to ensure that it is accurate and kept up to date or to delete the personal data we hold about you. You can also inform us if you would like to restrict the data processing or object to the processing of personal data, we hold about you. If you wish to do this, please contact us using the contact details provided at the Contact us section below. You are also entitled to provide the personal data we hold about you to another service provider of your choice.
Withdrawing the consent
In case we asked you for your consent to process personal data we hold about you, you can withdraw your consent at any time, without affecting the lawfulness of processing based on consent before the withdrawal. If you wish to do this, please contact us using the contact details provided at the Contact us section below.
Complaint
You have the right to lodge a complaint before the national data protection authority by sending your claim to it. In particular, the Italian Data Protection Authority is the Garante per la protezione dei dati personali, whose contact details are available at the following link https://www.garanteprivacy.it/.
Contacting us
If you have any comments relating to our use of your personal data or any questions about this Privacy Notice, please contact us using the following e-mail address: [email protected]. We welcome your questions and any suggestions you may have about our Privacy Notice.
To formally exercise your rights in relation to your personal data we process, please submit a request accessing the below link:
or contact us using the following email address: [email protected]
Furthermore, please note that we have designated a Data Protection Officer who may be contacted to the following address [email protected].
How changes to this Privacy Policy will be made
Please check this Privacy Notice periodically to be informed of any changes. Although we reserve the right to modify or supplement this Privacy Policy, we will provide notice to you on this website of any major changes for at least 30 days following the change and, where appropriate, through email notification.