CONTROLLER

Sodexo (Suisse) SA
Hohlstrasse 614, 8048 Zurich
Tel: +41 (0) 44 305 80 60
Email: info.ch@sodexo.com

Guaranteeing the security and confidentiality of your personal data is an absolute priority for Sodexo, and we therefore abide by applicable statutory and regulatory provisions on data protection.

We have implemented the following measures in order to ensure protection for your personal data:

•    Users retain control over their own data. Data are processed transparently, confidentially, and securely.
•    Sodexo endeavours to protect the personal data of its users in accordance with the applicable local data protection legislation and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (“GDPR”). Sodexo has appointed a registered group data protection officer with the CNIL, the French national data protection authority: Anne-Cécile Colas, Sodexo SA, 255 Quai De Stalingrad, 92130 Issy-les-Moulineaux, France. She can be contacted at dpo.group@sodexo.com.

However, you can also contact us directly:

Sodexo (Suisse) SA, Hohlstrasse 614, 8048 Zurich, Tel: +41 (0) 44 305 80 60, Email: info.ch@sodexo.com adding the subject line “Data protection”.

PURPOSE OF THIS PRIVACY POLICY

Sodexo takes the protection of your personal data very seriously.

We have drawn up this Privacy Policy in order to provide you with information concerning the conditions under which we collect, process, use and protect your personal data. Please read this statement carefully in order to identify the categories of personal data that we collect and process. You will find out how we use these data and with whom we are likely to share them. This Policy also informs you concerning your rights and how you can contact us in order to exercise rights or submit questions to us.

This Privacy Policy may be amended, supplemented or updated, in particular in order to take account of any legal, administrative or technical developments. However, unless provided otherwise by law, your personal data will always be processed in accordance with the privacy law applicable at the time the data were collected.

Please note that data transmission over the internet (e.g. in relation to communication by email) may feature security vulnerabilities. It is not possible to protect data seamlessly against third party access.

FURTHER DEFINITIONS

“Personal Data”

means any information relating to an identified or identifiable natural person (hereafter, “Data Subject”), who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“We” or “Our”

Sodexo

“You”

Any user of/visitor to the Website

“Website”

The mobile app Bite

COLLECTION AND ORIGIN OF DATA

We may collect your Personal Data in the following manner:

We shall not process any data without your consent, and You may also object to the processing of your data for specific purposes.

CATEGORIES OF DATA

We collect and process in particular the following types of Personal Data:

Any Personal Data marked by an asterisk in data registration forms are mandatory as they are necessary in order to fulfil orders. Unless We receive this mandatory information We will be unable to process the transaction concerned.

RECORDING OF DATA ON OUR WEBSITE

We automatically collect certain types of information whenever You visit the Website for the purpose of personalising and improving your experience. We collect this information using various methods such as:

Cookies

Parts of the Website use so-called “cookies”. Cookies do not cause any harm to your computer and do not contain any viruses. Cookies help to make Our content more user friendly, effective and secure. Cookies are small text files that are lodged on your computer and stored by your browser whenever You visit Our Website. These files contain information, such as user’s domain name, internet access provider and operating system, as well as the date and time of access.

Cookies are not used in order to establish the identity of any person who has visited Our Website. We can use cookies in particular to identify your geographical location and the language for displaying content in order to improve your online experience. They also enable us to process information concerning your visit to Our Website, e.g. the pages viewed and the searches carried out, in order to improve the content of Our Website, to identify your interests and to propose content that is more appropriate for you.
Most of the cookies used by Us are so-called “session cookies”. They are automatically erased after your visit has ended. Other cookies remain stored on your end device until You erase them. These cookies enable us to identify your browser again the next time You visit.

You can configure your browser settings in such a manner as to be informed whenever a cookie is stored and only to allow cookies in specific individual cases, to object to the storage of cookies, either under particular circumstances or as a general rule, and to enable the automatic erasure of cookies when the browser is closed. You can also actively consent to the usage of cookies that are not absolutely necessary for Website operation. If cookies are disabled, the proper operation of this Website may be impaired or some of the services offered by us may no longer be usable. Should this occur, We shall not incur any liability for any consequences arising due to the impaired functioning of Our services or Our inability to store the cookies necessary for the seamless operation of the Website.

Cookies that are necessary in order to operate electronic communication processes or to provide particular functions desired by You (e.g., basket function) are stored on the basis of Our legitimate interest. The operator of the application has a legitimate interest in storing cookies for the technically flawless and optimised provision of its services. Insofar as any other cookies (e.g., cookies for analysing your browsing patterns) are stored, these are dealt with specifically in this Privacy Policy.

Contact form

If You submit any queries to us using the contact form, your details contained in the contact form, including the contact information provided there, will be stored for the purpose of processing the enquiry and in the event of any follow-up enquiries. We shall not pass on these data without your consent.

Processing of the data entered into the contact form thus occurs exclusively on the basis of your consent. You can freely withdraw this consent at any time. In order to do so, it is sufficient to contact us by email, without any further formal requirements. The lawfulness of any data processing carried out prior to withdrawal of consent will not be affected by that withdrawal of consent.

The data entered by You into the contact form will be retained by us until You ask us to erase it, until You withdraw your consent to storage or if the purpose for which the data were stored no longer applies (e.g. after your enquiry has been dealt with). The foregoing is without prejudice to any mandatory statutory requirements, including in particular retention periods.

Processing of customer and contractual data

We only collect, process and use Personal Data insofar as necessary in order to establish, structure the content of or alter a legal relationship. This fulfils the purpose of performance of a contract or taking steps prior to entering into a contract. We only collect, process and use Personal Data relating to usage of Our Website (usage data) insofar as necessary in order to enable users to use the service.

The customer data collected are erased after fulfilment of the order or termination of the business relationship. The foregoing is without prejudice to statutory retention periods.

IP address and server log files

An IP address is a unique identifier that is used by individual electronic devices in order to identify themselves and communicate with other devices over the internet. Whenever You visit Our Website, We are able to use the IP address of the device used by You to connect You to the Website. We use this information in order to determine the general physical location of the device and to identify the geographical area in which the visitor is situated.

The Website provider also automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

These data are not crossed referenced with data from other sources.

Registration on this Website

You can register on Our Website in order to use additional functions on the Website. We only use the data entered for this purpose for the purpose of using the relevant offer or service for which You have registered. The mandatory information requested upon registration must be provided in full. Otherwise, We will refuse the registration request.

We use the email address provided upon registration in order to inform You concerning important changes, for instance in relation to the extent of the offer, or any changes that are technically necessary.

Processing of the data entered upon registration occurs on the basis of your consent. You can withdraw at any time consent that You have previously granted. In order to do so, it is sufficient to contact us by email, without any further formal requirements. The lawfulness of any data processing carried out previously will not be affected by that withdrawal of consent.

The data collected upon registration are stored by us for as long as You are registered on Our Website. The foregoing is without prejudice to statutory retention periods.

If You have consented to the usage of cookies by clicking on Our cookie banner, this Website uses functions from the following web services:

Google Tag Manager

Google Tag Manager is a solution which enables us to manage Website tags via an interface – and thus e.g., incorporate Google Analytics into Our online offer. Google Tag Manager (which implements the tags) does not itself process any Personal Data of users. The user is entitled to consult the following information concerning the processing of Personal Data in relation to Google services. Use Policy:     https://www.google.com/intl/de/tagmanager/use-policy.html.

Google Analytics

If You have consented to the usage of performance cookies by clicking on Our cookie banner, this Website uses the functions of the web analysis service Google Analytics (the provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland) in order to generate statistics.

These statistics establish for instance how many users have visited the Website, which pages have been visited and in which geographical areas the visitors to the Website are situated. Information collected via the statistics may include for instance your IP address, the website visited by You before arriving at Our Website and the device type used by You.

Google Analytics uses so-called “analysis cookies” for this purpose. These are text files that are stored on your computer and enable your usage of the Website to be analysed. The information generated by the cookie concerning your usage of this Website is generally transferred to a Google server in the USA and stored at that location.

Google Analytics cookies are stored in accordance with Our legitimate interest. The operator of this application has a legitimate interest in analysing user conduct in order both to optimise its online offer as well as its advertising.

Further information on how user data are handled by Google Analytics may be found in the Google Privacy Policy: https://support.google.com/analytics/answer/6004245?hl=de.

IP anonymisation

Your IP address is recorded on Our Website anonymously and is only used if required in order to resolve a technical problem, to manage the Website or to gain information concerning Our users’ preferences. Information relating to browsing on this Website is only available to authorised employees. We do not use any of this information in order to identify users and do not share this information with third parties.

The IP anonymisation function has been activated in relation to usage of Google Analytics. This involves the truncation of your IP address by Google within a Member State of the European Union or within another state party to the Agreement on the European Economic Area prior to transmission to the USA. The full IP address is only transmitted to a Google server in the USA and truncated at that location under exceptional circumstances. Google uses this information on behalf of the operator of this Website in order to compile reports concerning activities on the Website and to provide the operator of this application with further services related to usage of the Website and of the internet. The IP addresses transmitted by your browser within the ambit of Google Analytics are not cross-referenced with any other data held by Google.

Subcontracted data processing

We have concluded a data processing agreement with Google and comply in full with the strict requirements imposed by the German data protection authorities in relation to the usage of Google Analytics.

Google Analytics and Demographics

This Website uses the “Demographics” function of Google Analytics. This enables reports to be generated concerning statements relating to the age, gender and interests of visitors to the Website. These data are obtained from Google’s interest-based advertising as well as from the visitor data of third party providers. These data cannot be allocated to any specific person. You can disable this function at any time via the advertising settings in your Google account, or as a general rule prevent your data from being displayed by Google Analytics as described under the point “Object to data processing”.

BASES FOR PROCESSING

We collect, process and use Personal Data insofar as necessary in order to establish, structure the content of or alter a legal relationship (inventory data).

This fulfils the purpose of performance of a contract or taking steps prior to entering into a contract.

We only collect, process and use Personal Data relating to usage of Our Website (usage data) insofar as necessary in order to enable users to use the service.

The customer data collected are erased after fulfilment of the order or termination of the business relationship. The foregoing is without prejudice to statutory retention periods.

SHARING OF DATA

Ensuring the security and confidentiality of your Personal Data is an important concern for us. For this reason, We limit access to your Personal Data to employees who require the relevant information in order to process your orders or to provide the service requested.

We do not share your Personal Data with unauthorised third parties. However, We may share your Personal Data with companies within the Sodexo Group and with authorised service providers (for example technical service providers that offer services such as hosting, maintenance and advice), insofar as We avail ourselves of such service providers in order to provide Our services.

We do not authorise Our service providers to use or share your data unless this is necessary in order to provide the services in Our name or to comply with statutory obligations. In addition, we may share Personal Data concerning You (i) if this is required by law or a court order, (ii) upon request by the authorities or any other official or (iii) if We take the view that the transmission of these data is necessary or appropriate in order to avoid personal injury or financial loss or for any investigation concerning suspected or proven unlawful activity.

RETENTION PERIOD

We only store your data for as long as is necessary for the fulfilment of the purposes for which they were collected and processed. Where appropriate, this period may be extended for a period of time prescribed under legislative or administrative requirements.

SPECIAL CATEGORIES OF PERSONAL DATA

As a general rule, We do not collect any sensitive Personal Data through Our Website. “Sensitive Personal Data” means information concerning the racial or ethnic origin of a person, political opinions, religious or philosophical beliefs, trade union membership, data concerning health or data concerning a natural person’s sex life or sexual orientation. This definition also includes Personal Data relating to criminal convictions and offences.
If it is absolutely necessary for such data to be collected in order to achieve the purpose for which processing occurs, We shall do so in accordance with the local legal requirements on the protection of Personal Data, and in particular with your express, prior consent and in accordance with the terms set forth in this Privacy Policy.

PERSONAL DATA OF CHILDREN

The Website is intended for adults who are legally capable of concluding a contract.
Any users under the age of 18 must obtain the approval of their parent or guardian before submitting their data.

TRANSMISSION OF DATA ABROAD

Since Sodexo is an international corporate group, your Personal Data may be transmitted to internal or external recipients based in countries outside the European Union or the European Economic Area without an adequate level of protection for personal data that are entitled to provide services in Our name.

In order to guarantee the security and confidentiality of the Personal Data transmitted in this manner, we shall take all necessary action to ensure that these data are appropriately protected, for instance by obtaining the signature of the standard contractual clauses of the European Commission or by any other equivalent measures.

YOUR RIGHTS

Sodexo undertakes to ensure that your rights are protected in accordance with applicable laws. You can find a summary below of the various options for exercising your rights:

Right of access:

You can obtain information concerning the processing of your Personal Data. You can also obtain the rectification of inaccurate Personal Data collected, or have incomplete Personal Data completed.
You can request all available information concerning the source of the Personal Data, and You can also request a copy of your Personal Data that are being processed by Sodexo.

Right to erasure:

You have the right to request the erasure of your Personal Data where:

Right to restriction of processing:

You may request the restriction of processing under the following circumstances:

Right to data portability:

Where applicable, you may request the transfer of Personal Data that You have made available to Sodexo. Where they have been stored in a structured, commonly used and machine-readable format, you have the right to obtain the transfer of these data without impediment by Sodexo to another provider if:

You can also request that your Personal Data be transmitted directly to a third party of your choosing (if technically possible). In order to exercise your rights, You can send an email to info.ch@sodexo.com adding the subject line “Data protection”.

SECURITY

We take all possible technical and organisational measures in order to guarantee the security and confidentiality of the processing of your Personal Data.

For this purpose, irrespective of the type of Personal Data and the risks associated with their processing, We take all necessary precautions in order to guarantee data security and in particular to prevent any alterations, damage or unauthorised third party access (through the physical protection of premises, authentication procedures involving personal, secured access via identifiers and confidential passwords, connection logs, the encryption of particular data etc.).
Only authorised persons, to whom data are provided on a “need-to-know” basis only, have access to the IT systems of Sodexo. Security and access rights are monitored in accordance with pre-defined user requirements. The system limits user access to the content and services for which the relevant user has entitlement.

MANAGEMENT OF CUSTOMER RELATIONS (“CRM DATABASE”)

We use a database in order to manage Our relations with existing and prospective customers. This database contains the Personal Data of employees of Our customers or other partners with which We have business relations or with which We intend to establish such relations. These data, which are only used for this purpose, include in particular: contact data (surname, first name, telephone number, email address etc.), publicly accessible information, the answers to specific emails and other information collected and recorded by Our employees in relation to their interactions with Our customers and partners. If You would like to be removed from Our CRM database, please write to: info.ch@sodexo.com

LINKS TO EXTERNAL WEBSITES

We offer links on Our applications to websites that may be of interest for you, although We do not have any influence over the content of those websites. We do not provide any warranty for this third party content. The linked pages are examined at the time the link is created for any potential breaches of the law. No such breaches were apparent at the time the link was created. However, it is not reasonable for the contents of linked pages to be monitored on an ongoing basis, unless there are tangible grounds to suspect a breach of the law. As soon as We become aware of any breaches by the law on the linked websites, We shall remove the links concerned promptly.

UNSUBSCRIBING FROM NOTIFICATIONS

If You have signed up via Our Website for services such as for example the newsletter or other notifications and no longer wish to receive any emails, You can terminate this service using the “unsubscribe” function on the Website concerned.

OBJECTION BY US TO ADVERTISING EMAILS

The use of the contact data published in the legal notice in order to send any advertising or information materials that have not been expressly solicited is hereby objected to. The operators of the Website expressly reserve the right to launch legal action in the event of the unsolicited transmission of any advertising information, for instance through spam emails.

CONTACT

If You have any questions or comments concerning this Privacy Policy, please do not hesitate to contact us at the following address: info.ch@sodexo.com.

How can we help?

Do you have a question?

Sodexo (Suisse) SA

Hohlstrasse 614 – 8048 Zürich – info.ch@sodexo.com

Follow us on LinkedIn