Privacy & Cookies Policy
This Privacy & Cookies Policy governs the use by Caffè Nero Group Ltd of the personal data we collect from you during your use of the website located at www.caffenero.com (the “Site”) or we otherwise obtain about you (“Personal Information”).
In this Policy, ” Caffè Nero”, “we”, “us” and “our”, refer to Caffè Nero Group Ltd.
Caffè Nero Group Ltd is committed to protecting the security and privacy of third parties (including its customers and all visitors to the Site. We will comply with the requirements of the “Data Protection Legislation”, including (i) the UK Data Protection Act 1998, (ii) from 25 May 2018, the EU General Data Protection Regulation (which will replace the Data Protection Act 1998), (iii) the Privacy and Electronic Communications (EC Directive) Regulations 2003 and (iv) all similar or related legislation relating to the processing of Personal Information and/or privacy applicable in any jurisdiction and will take reasonable steps to ensure that your Personal Information is secure, and monitored with regard to access, both internally and externally.
We will only collect your Personal Information:
- when you give feedback to this site;
- when you purchase products from the site;
- when you join, sign up or subscribe to any of our clubs, panels, forums or other facilities which we run on or from the Site from time to time;
- through cookies; and
- through data aggregation.
We will ensure that your Personal Information is handled in accordance with the Data Protection Legislation. By visiting and/or contacting us through the Website (or otherwise engaging with us), you acknowledge that we may collect, use and transfer your Personal Information as set out in this Policy.
For the purposes of the Data Protection Legislation, we are deemed to be the “data controller” in respect of any Personal Information that you provide to us or we otherwise obtain about you.
- Personal Information that we collect
- Personal Information that we receive from other sources
- What we do with your Personal Information
- How we share your Personal Information
- Our security measures and information about when we delete data
- Transferring Personal Information outside of the EEA
- How you can access and update your Personal Information
- Changes to this Policy
- Our contact information and opting out
1. Personal Information that We Collect
When you engage with us (e.g. sending us emails, contacting us via telephone or visiting or making an enquiry through the Website), you may provide Personal Information about yourself including your name and contact details (e.g. your address, email address and telephone number) and your job title and CV where you apply for a role with us. If you consider purchasing from us, you may also provide us with various other necessary Personal Information (e.g. your bank details). Where you make use of our Site we may also collect information about your use of the Site (e.g. your IP address and choice of web browser). Some of this Personal Information is collected and processed so we can perform a contract with you, some for the purpose of legal compliance and some for the purposes of our legitimate business interests (namely to carry out and improve our business, analyse the use of our Site and services and support our staff and customers).
Where you give feedback to or contact us we will only ever use your Personal Information to respond directly to you in relation to your feedback and/or comment.
We will use your Personal Information to provide you with the products you order from us.
Gift cards and Surveys
If you create an account or register a gift card, we will collect data on your username, password, phone number, date of birth, name and address. If you buy goods at our stores using a Gift Card, we will collect data on where you buy, how frequently you buy.
If you take a survey or interact with us in various other ways – name, address, phone number, date of birth and demographics information. We also ask customers if they would like to provide us with their Post Code and Telephone Number.
If you choose the opt in and sign up to our communications and/or marketing materials, we may collect data on your username, password, contact e-mail address, mailing address, phone number, date of birth, demographics information, and personal interests. Unless you choose to opt out, or communicate the decision to discontinue by contacting us as described below, we will use your Personal Information to send you information which we think may interest you and keep you up to date as to developments relating to the facility operated by us which you have joined, signed-up to or subscribed to.
We also have CCTV in some of our stores and offices for the purpose of crime prevention and where this is used, we will display appropriate notices.
2. Personal Information We Receive from Other Sources
We may receive information from third parties who collect Personal Information from you and pass it on to us, for example, for fraud prevention. Our staff may also give us emergency contact information as part of our emergency scenario planning and may give us details of their dependents and of other people in relation to their employee benefits arrangements. Where this is the case the third party is responsible for obtaining the relevant consents from you to ensure you are happy with the ways in which your Personal Information will be used.
3. What We Do with Your Personal Information
We will only use your Personal Information in order to:
(a) supply the services you have requested and correspond with you,
(b) provide support to you in respect of these services,
(c) improve our Site and services
(d) for our internal business processes, including providing support to our staff,
(e) where relevant, process your application for employment.
(f) where you have explicitly consented at the time we collected your Personal Information or where we otherwise have a right to do so, we may also use your Personal Information to let you know about our services, and job openings that may be of interest to you and/or inform you about important changes or developments to our services, by post, telephone and e-mail.
(g) from time to time, we may also use your Personal Information to contact you for market research purposes. We may contact you by email, phone or mail. This will only happen where you have opted-in to receive such communications.
We may also use the Personal Information to customise the Site according to your interests.
If you change your mind about us using your Personal Information in the ways described in this Policy, please let us know by emailing us.
You may also opt out of receiving marketing emails from us by following the instructions outlined in any marketing email you receive from us.
4. How We Share Your Personal Information
In certain circumstances we may pass your Personal Information to carefully selected third parties. We will never pass your Personal Information for such purposes unless you have allowed us to do so or we have a lawful right to do so.
If after having given us permission to pass your Personal Information to third parties you change your mind you can opt out by contacting us as described below.
In addition, it may be necessary to disclose your Personal Information if we are under a duty to disclose your Personal Information in order to comply with any legal obligation, carry out an internal investigation, enforce our Terms and Conditions and any other agreement, or protect the rights, property, or safety of Caffè Nero, Caffè Nero’s group companies and our customers, directors, employees or other personnel. This includes exchanging information with other companies and organisations for the purposes of fraud protection and prevention.
5. Our Security Measures and Information about When We Delete Data
We take steps to protect your Personal Information from unauthorised access and against unlawful processing, accidental loss, destruction and damage.
We will only keep your Personal Information for as long as we reasonably require and, in any event, only for as long as the Data Protection Legislation allows.
Where you have chosen a password which allows you to access certain parts of the Site, you are responsible for keeping this password confidential. We advise you not to share your password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure and, although we will take steps to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted via the Website; any transmission is therefore at your own risk.
6. Transferring Personal Information Outside of The EEA
The Personal Information you provide to us will be transferred to and stored on our servers, which sits within the EEA.
In processing your Personal Information, it will sometimes be necessary for us to transfer your Personal Information outside the European Economic Area (“EEA“) to our staff and our third party service providers. It may also be accessed by staff operating outside the EEA who work for us or for one of our suppliers or group companies. This includes people engaged in, among other things, the provision of support services to us.
We will take all steps reasonably necessary to ensure that your Personal Information is treated securely and in accordance with this Policy and the Data Protection Legislation when it is processed in, or otherwise accessed from, a location outside the EEA. This means that we will only transfer your Personal Information to third parties based outside the EEA if that party:
(a) is situated in a country that has been confirmed by the European Commission to provide adequate protection to Personal Information,
(b) has agreed (by way of written contract) to provide all protections to your Personal Information as required by the Data Protection Legislation or,
(c) we have your explicit consent to do so (such as where you have requested a service from one of our partners situated outside the EEA). Where any transfer takes place under a written contract, you have the right to request a copy of that contract and may do so by contacting us at Caffè Nero.
For the avoidance of doubt, in the event that the UK is no longer a part of the EEA, references in this paragraph to the EEA shall mean the EEA and the UK.
7. Accessing and Updating Your Personal Information
You have the right to ask us not to process your Personal Information for marketing or research purposes. We will usually inform you (before collecting your Personal Information) if we intend to use your Personal Information for such purposes or if we intend to disclose your Personal Information to any third party for such purposes.
You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your Personal Information. If you wish to see your data, you may also complete this form. Your request will be processed within 30 calendar days upon receipt of a fully completed form and proof of identity may be required. You can also exercise the right at any time by contacting us at the details set out as below.
You have the right to see the Personal Information we hold about you and to ask us to:
(a) make any changes to ensure that any Personal Information we hold about you is accurate and up to date;
(b) erase or stop processing any Personal Information we hold about you where there is no longer a legal ground for us to hold it; or
(c) in some cases, transfer any information we hold about you to a specified third party.
(d) we will, within the legally required timeframe, provide you with a complete list of all the personal data held on you upon request.
If you wish to exercise any of these rights, please contact us at Caffè Nero /using the contact details as described below.
Should you have any queries or complaints in relation to how we use your Personal Information, please contact us at Caffè Nero /using the details set out as described below. Should you wish to take any complaints or queries further, you have the right to contact the Information Commissioner’s Office regarding such issues.
Our Site may, from time to time, contain links to and from third party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these websites or their related policies. Please check these policies before you submit any Personal Information via these websites.
A cookie in no way gives us access to your computer or any information about you, other than information about how you use the Site and the Personal Information you choose to share with us (including Personal Information you automatically share with us by way of your browser settings).
To enable us to monitor and improve the Site, we gather certain aggregated information about you when you use it, including details of your operating system, browser version, domain name and IP address, the URL you came from and go to and the parts of our Site you visit. We may aggregate statistics, traffic patterns and related site information and disclose such aggregate data to third parties for marketing, advertising or other promotional purposes but such aggregate data will not include any Personal Information.
For the same reason, we may obtain information about your general internet usage by using a cookie file which is stored on the hard drive of your computer. Cookies contain information that is transferred to your computer’s hard drive. They help us to improve our site and to deliver a better and more personalised service.
In particular, we use the following cookies:
- Strictly necessary cookies. These cookies are essential in order to enable you to move around the Site and use its features, such as accessing secure areas.
- Performance cookies. These cookies collect information about how visitors use our Site, for instance which pages visitors go to most often and if they get error messages from the web pages. These cookies don’t collect information that identifies a visitor; all information these cookies collect is aggregated and therefore anonymous. It is only used to improve how our Site works.
- Functionality cookies. These cookies allow our Site to remember choices you make (such as your user name, language or the region you are in) and provide enhanced, more personal features. These cookies can also be used to remember changes you have made to text size, fonts and other parts of the Site that you can customise. The information these cookies collect is anonymised and they cannot track your browsing activities on other websites.
- Sharing cookies. These cookies allow you to interact with third party services such as Caffè Nero. Information collected by these cookies is aggregated and therefore anonymous.
You will normally see a message on our Site before we store a cookie on your computer. We may also use banners and pop-ups from time to time to give you options around cookies use.
You can also manage cookie use via your browser settings (this will allow you to refuse the setting of all or some cookies) and your browser provider may ask you to confirm your settings. Note, however, that if you block all cookies (including essential cookies) via your browser settings you may not be able to access all or parts of our Site.
You can also find more information about cookies generally here: www.allaboutcookies.org.
10. Changes to Our Privacy and Cookies Policy
Caffè Nero may amend this Policy at any time without notice. By continuing to use the Website and making use of our services you agree to the updated Policy. If you do not agree to any changes that we make, you should not use or access (or continue to use or access) the Site and/or our services. Any changes to this Policy will be posted on the Site.
11. Our Contact Information and Opting Out
You can opt out of receiving various communications from us by emailing us at firstname.lastname@example.org.
If you have any questions (including relating to transfers of your Personal Information outside the EEA), please feel free to contact us by email at email@example.com. If you wish to see your data, you may also complete this form. Your request will be processed within 30 calendar days upon receipt of a fully completed form and proof of identity may be required.