1. Our Commitment To Privacy
1.1 Your privacy is very important to us at SodaStream Worldwide Trading Company and our subsidiaries and affiliates,“we” and/or “us” and/or “SodaStream”. To better protect your privacy we provide this notice we provide this notice (“"Privacy Notice") explaining our information practices and the choices you can make about the way your information is collected and used in connection with our digital properties that link to this Privacy Notice, including our websites (the “Site”, “our website” or “this website”) and our other products and services (collectively, the “Service”). To make this notice easy to find, we make it available on our homepage and at every point where personal data may be requested.
1.2 We strongly urge you read this notice and make sure you fully understand our practices in relation to personal data, before you access or use any of our services. If you read and fully understand this Privacy Notice, but remain opposed to our practices, you must immediately leave our website, and avoid or discontinue all use of any of our services. Where you have read this notice but would like further clarification, please contact us at email@example.com.
2. Important information
2.1 The purpose of this Privacy Notice is to provide you with clear explanation of what personal data we collect, when, why and how we collect, use and share your personal data and it explains your rights under applicable data privacy laws. This Privacy Notice is not intended to override the terms of any contract you have with us, nor any rights you might have under applicable data privacy laws.
2.2 Protecting the privacy of the very young is especially important. For that reason, we do not voluntarily collect any personal data from anyone under 16, and no part of our website is structured to attract anyone under 16. Parents and guardians should supervise their children’s activities at all times. If we learn we have collected or received personal data from a person under 16 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a person under 16, please contact us at firstname.lastname@example.org.
2.3 Note that our website contains links to third party websites which we are not responsible for. These links are not an endorsement of, or representation that we are affiliated with, any third party. In addition, our content may be included on web pages or in mobile applications or other online services that are not associated with us. We do not control websites, mobile applications or online services operated by third parties, and we are not responsible for their actions. Please review the privacy policies of such third party websites should you visit these websites. This Privacy Notice does not address the privacy or information practices of any third parties.
3. What information do we collect and how do we collect it?
3.1 Personal data is collected when you voluntarily submit it through a website form, contact our support services, if you register with or use one of our website or related online services.
3.2.1 If you register or contact us as an individual, we will collect your name, date of birth, email address, telephone number, address information (together, “identification data”); information about your household (“household composition data”), the consumption habits of you and members of your household (“consumption data”), information about the device you use to access our website or online services (“device data”), payment and credit card information (“payment data”), information to set up and access your SodaStream account (“login data”) correspondence with us, any feedback on our products and services which you provide, and your customer support records (“communication data”) and additional information you will voluntarily provide to us in response to market survey we invite you to participate in (“survey data”).
3.2.2 If you register or contact us as an individual, we will collect your name, date of birth, gender, email address, telephone number, address information together, “identification data”); information about your household (“household composition data”), the consumption habits of you and members of your household (“consumption data”), information about the device you use to access our website or online services (“device data”), payment and credit card information (“payment data”), information to set up and access your SodaStream account (“login data”) correspondence with us, any feedback on our products and services which you provide, and your customer support records (“communication data”) and additional information you will voluntarily provide to us in response to market survey we invite you to participate in (“survey data”).
3.2.2 If you register or contact us on behalf of a company, we will collect company identification data, identification data from the company representative, company composition and consumption data, device data, payment data and login data.
3.3 If you contact us by other offline methods in order to buy our products or services or by using one or more of the contact means provided offline, we will collect identification and payment data as relevant for the sale and delivery of the goods and services or to respond to your query or complaint and, as far as necessary, for the handling and fulfilment of the order and ongoing provision of our services.
3.5 If you apply to one of our open positions published in our careers sites, by sending us contact details and CV (“applicants personal data”) via the relevant application on our careers website, or through any other means provided by us (e.g. social media), we will collect such applicants personal data in order to process your application according to the Candidate Privacy Notice.
3.6 If you invite others to use the Services, for example by sending an invitation email from the Site to the recipient’s external email address, you will be providing us with personal data about the recipient, such as their email address or online account username. We will process such personal data to provide this interactive Service. You are responsible for ensuring that the recipient’s information is accurate, and you should only provide the information of a recipient if you know or believe they would be interested in our Services.
3.7 If you create user generated content, we will process such personal data, such as posts, messages, rating our products, providing customer feedback, and other content that you can choose to upload to our forums or otherwise make available on the Service, as well as associated metadata.
3.8 We will process information regarding your marketing preferences, if you communicate them to us.
3.9 We may process information related to your direct interactions and communications with us including recordings and transcripts of your calls, emails, form submissions, and chats with us for different purposes such as providing customer support, feedback, understanding our customer needs or training purposes.
3.10 If you provide other information which is not specifically listed here, which we will use as described in this Privacy Notice or as otherwise disclosed at the time of collection. We may also combine personal data we receive from you with personal data we obtain from other sources.
4. How do we use your personal data?
We may use your personal data for the following purposes or as otherwise described at the time we collect it:
4.1 Service delivery:
We may use your personal data to:
- offer, operate and improve our products and/or Service and our business (e.g., validate your order or subscription);
- process your payment and complete transactions with you (e.g., of a monthly fee in the case of a subscription);
- provide the products and services that you requested or ordered or to which you subscribed. We will also use your personal data as far as necessary for the handling and fulfilment of your order;
- provide support for the Service, and respond to your requests, questions and feedback as well as to provide customer support;
- provide our customer management services, to maintain our relationship with you, with a view to providing stellar customer experience;
- verify your identity, establish and set up your account, verify or re-issue a password, log your activity or authenticate your access and use of the Site or the Service;
- verify your identity, establish and set up your account, verify or re-issue a password, log your activity or authenticate your access and use of the Site or the Service;
- communicate with you about the Service, including by sending announcements, updates, security alerts, and support and service messages.
4.2 Research and development:
We and our service providers may use your personal data for research and development purposes, including to improve our products in order to make them fit for our customers’ needs, understand your interests, and to analyze and improve the Service and our business. As part of these activities, we may create aggregated, de-identified or other anonymous data from personal data we collect. We make personal data into anonymous data by removing information that makes the data personally identifiable to you. We may use this anonymous data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business. This may include storing and tracking your visits across websites, such as number of visits, average time spent, and which pages have been opened; or analyzing our marketing and referrals.
4.3 Compliance and protection:
We may use your personal data to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities;
- protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims);
- audit our internal processes for compliance with legal and contractual requirements or our internal policies; and
- enforce the terms and conditions that govern the Service and prevent, identify and investigate fraudulent, harmful, unauthorized activities, including cyberattacks and identity theft, and other inappropriate activities and monitor content integrity on our website.
4.4 To process job applications:
We collect applicants personal data solely for SodaStream’s internal recruitment purposes including for: identifying applicants, evaluating their applications, making hiring and employment decisions, and contacting applicants by phone or in writing as indicated in Sodastream’s Candidate Privacy Notice.
4.5 Carrying out Marketing and Advertising:
We and our third-party advertising partners may use your personal data, including information related to your order, such as your address for direct marketing and advertising purposes:
- Direct marketing. We may for example send you emails to inform you of news and updates about our products and services. This may be in the form of email, post, SMS, or telephone. Where required by law, we will obtain your consent prior to sending you such marketing information.
5. Opting Out:
To protect your privacy and ensure you have control over the use of your personal data, we will always give you the opportunity to “opt out” of direct marketing when you contact us in relation to a product or service or you receive any email, text or other direct marketing communication.
You have a right to prevent direct marketing of any form at any time - this can be exercised by following the opt-out link attached to each communication, or by sending an email to email@example.com. If you want to review or update the information you have provided us, you can click “my profile” at our website’s home page, and edit the information. If you have not been asked already to provide your email address and a password, we will ask you to do it before changes are made, so as to prevent others from accessing and altering your personal data.
6. Legal basis for processing personal data:
The legal bases of our processing of your personal data as described in this Privacy Notice will depend on the type of personal data and the specific context in which we process it. However, the legal bases we typically rely on are set out in the table below. If you have questions about the legal basis of how we process your personal data, contact us at firstname.lastname@example.org:
|Processing purpose (click link for details)||Legal basis|
|Service delivery: We need to process your personal data (e.g., your identification data, payment data, login data, address data) to operate the Service, including managing your account or transactions, responding to your requests or inquiries, providing you with access to content or information you requested, etc.||Processing is necessary to perform the contract governing our provision of the Service or to take steps that you request prior to signing up for the Service.|
|Marketing and advertising: We and our third-party advertising partners may collect and use your personal data for marketing and advertising purposes.||Processing is based on your consent where that consent is required by applicable law. Where such consent is not required by applicable law, we process your personal data for these purposes based on our legitimate interests in promoting our business.|
|Research and development: We may use your personal data (e.g., your household composition data, consumption data, device data) for research and development purposes, including to analyze and improve the Service and our business.||These activities constitute our legitimate interests. We do not use your personal data for these purposes where our interests are overridden by the impact on you.|
|We may need to process your personal data for additional purposes, such as:
||We rely on our legitimate interests to process your personal data when performing these processing activities. We do not use your personal data for these purposes where our interests are overridden by the impact on you.|
|Compliance with legal obligations: We are subject to certain legal obligations that may oblige us to disclose your Personal data to courts, law enforcement or regulatory authorities.||Processing is necessary to comply with our legal obligations.|
|Actions we take with your consent:
||In these scenarios, the processing of the personal data you voluntarily provide to us is based on your consent. Where we rely on your consent, you have the right to withdraw it any time in the manner indicated when you consent to the processing.|
7. Use for new purposes:
We may use your personal data for purposes not described in this Privacy Notice where permitted by law and the reason is compatible with the purpose for which we collected it. If we need to use your personal data for an unrelated purpose, we will notify you and explain the applicable legal basis.
8. Special categories of data / sensitive data:
We ask that you not provide us with any sensitive personal data (e.g., information related to racial or ethnic origin, political opinions, religion or other beliefs, biometrics or genetic characteristics, criminal background or trade union membership) through the Service or otherwise.
9. Data Security:
9.1 To prevent unauthorised access, maintain data accuracy, and ensure the correct use of information, we have put in place physical, electronic, and managerial procedures to safeguard and secure the information we collect. Some of the steps we take are: placing confidentiality requirements on our staff and service providers; destroying or permanently anonymising personal data if it is no longer needed for the purposes for which it was collected. Sodastream will comply with applicable laws in the event of any breach of the security, confidentiality or integrity of your personal data and, where we consider appropriate or where required by applicable law, notify you via email, text or conspicuous posting on our website in the most expedient time possible and without unreasonable delay, in so far as it is consistent with (i) the legitimate needs of law enforcement, or (ii) any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
9.2 However, security risk is inherent in all internet and information technologies and we cannot guarantee the security of your personal data. We make commercially reasonable efforts to make the collection and security of information consistent with this Privacy Notice and all applicable laws and regulations. Where you have a SodaStream username, login or password, you are responsible for keeping this information confidential. We ask you not to share a username, login or password with anyone.
10. Data Retention:
10.1 We may retain your data as long as necessary to provide our products and services, and beyond such time to the extent legally permitted and based on our legal obligations (e.g. in relation to invoice retention) or legitimate interests (eg in retaining data for the purposes of responding to possible disputes or complaints or for possible reactivation of subscriptions).
In addition, we maintain a data retention policy which we apply to information in our care. Where your data is no longer required we will ensure it is securely deleted or anonymised.
11. We may share your personal data
SodaStream may share your personal data with third parties in the following manners and instances and as otherwise described in this Privacy Notice or at the time of collection:
11.1 with our corporate parent, or other SodaStream affiliates and subsidiaries for the purposes mentioned in this Privacy Notice.
11.2 with any third parties to whom the relevant SodaStream entity subcontracts all or part of this processing. The purpose of this transfer will be to help manage our business and deliver services. For instance, we may transfer your personal data to a service provider to the extent necessary to complete an order and deliver your product, and to process the payment of your order. Other instances may include transfers to e-marketing service providers, hosting providers and any other relevant roles. Note that we will never sell your personal data to a third party. These third parties have agreed to confidentiality restrictions and use any personal data we share with them or which they collect on our behalf solely for the purpose of providing the contracted service to us.
11.3 we may sometimes share your personal data with partners or enable partners to collect information directly via our Service.
11.4 with third party advertising companies that collect information about your activity on the Service and other online services to help us advertise our services, and/or use customer lists that we share with them to deliver ads on their platforms on our behalf to those customers and similar users.
11.5 we may disclose or otherwise allow others access to your personal data pursuant to a legal request, such as a subpoena, legal proceedings, search warrant or court order, or in compliance with applicable laws, if we have a good faith belief that the law requires us to do so, with or without notice to you. If warranted, we may also allow access to this information in special emergencies where physical safety is at risk.
11.6 we may disclose any personal data or other information obtained from or about you, to third parties in connection with a merger, acquisition, bankruptcy or sale of all or substantially all of our assets, to the extent that this is necessary for the process.
11.7 we may share your personal data with professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us.
11.8 certain personal data and any content that you make publicly available on or via the Site or Services, is visible to other users of the Service and the public. Where your personal data can be seen, collected, and used by others, including being cached, copied, screen captured or stored elsewhere by others (e.g., search engines), we are not responsible for any such use of data. We therefore encourage you only to post information that you are sure you want to be publicly accessible.
12. Transferring personal data globally:
Sodastream is a global company operating in multiple locations and may use service providers that operate in other countries. Your personal data may be transferred and stored outside your place of residence, that are subject to different standards of data protection. In particular, if you live in the EU, you should be aware that your personal data may be transferred to locations outside the EU. We will take appropriate steps to ensure that transfers of personal data are in accordance with applicable law and carefully managed to protect your privacy rights and interests and transfers are limited to countries which are recognised as providing an adequate level of legal protection or where we can be satisfied that alternative arrangements are in place to protect your privacy rights. To this end:
- we will ensure that transfers within SodaStream and its affiliates will be covered by an agreement entered into by members of SodaStream Group (an intra-group agreement) which contractually obliges each member to ensure that personal data receives an adequate and consistent level of protection wherever it is transferred within the Group;
- where we transfer your personal data outside SodaStream or to third parties who help provide our products and services, we will obtain contractual commitments from them to protect your personal data; or
- where we receive requests for information from law enforcement or regulators, we will carefully validate these requests before personal data is disclosed.
You have a right to contact us for more information about the safeguards we have put in place (including a copy of relevant contractual commitments) to ensure the adequate protection of your personal data when this is transferred as mentioned above.
13. Your rights in relation to your personal data:
Subject to certain exemptions, and in some cases dependent upon the processing activity we are undertaking, you may have the following rights under data protection laws:
- to request that we provide you with a copy of your personal data that we hold and you have the right to be informed of; (a) the source of your personal data; (b) the purposes, legal basis and methods of processing; (c) the data controller’s identity; and (d) the entities or categories of entity to whom your personal data may be transferred;
- to request that we cease processing your personal data, in whole or in part, as you direct us, for any purpose, save to the extent it is lawful to do so without consent;
- to request that we restrict the processing of your personal data where: (a) the accuracy of the personal data is contested; (b) the processing is lawful but you object to the processing of the personal data; (c) we no longer require the personal data for the purposes for which it was collected, but it is required for the establishment, exercise or defence of a legal claim;
- to request that we erase your personal data in limited circumstances where it is no longer necessary in relation to the purpose(s) for which it was collected or processed;
- to challenge processing which we have justified on the basis of a legitimate interest;
- to request that we not transfer your personal data to unaffiliated third parties for the purposes of direct marketing or any other purposes;
- to request that we change the manner in which we contact you for marketing purposes;
- to request that we correct any errors in your personal data;
- to request that we update your personal data as required. Note that you may also correct, update or remove certain parts of such personal data by yourself, or completely deactivate your SodaStream account, through your account settings;
- to obtain a copy of the safeguards under which your personal data is transferred outside the EU; and
- to lodge a complaint with your local supervisory authority for data protection. However, we encourage you to first contact us.
We may ask you for additional information to confirm your identity and for security purposes, before disclosing the personal data requested to you. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive.
If you would like to exercise your rights, there may be tools that we make available via the Services. Otherwise, please contact us at email@example.com to make your request, containing adequate details of the request. We will treat your request in accordance with applicable laws.
14. Changes to this Privacy Notice:
We may update and change this Privacy Notice from time to time, to keep it up to date with legal requirements and the way we operate our business. Please regularly check these pages for the latest version of this Privacy Notice.
15. Contact information:
Protecting your privacy online is an evolving area, and we try to evolve our Site and Services to meet these demands. If you have any comments or questions about this Privacy Statement, you can contact us at:email address: firstname.lastname@example.org