Privacy policy statement - client

A. INTRODUCTION
Sodexo Pass Česká republika a.s., with its registered office at Spaces SmíchOff, Plzeňská 3350/18, Praha 5 - Smíchov, Postcode 150 00, ID No, 61860476, listed in the Commercial
Register maintained by the Municipal Court in Prague, under File No. B 2947 (hereinafter referred to as the "Company") is dedicated to compliance with the principles and rules
for the protection of individuals in connection with the processing of their personal data.
This Privacy Policy Statement (hereinafter referred to as the "Statement") describes how the Company processes personal data. This Statement ensures that personal data is
processed in compliance with generally binding laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of
natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
(hereinafter referred to as “GDPR“), so that the rights of data subjects are adequately protected. The processing of personal data via cookies is regulated under Annex 2 Sodexo
Benefity Cookie Policy
Pursuant to Articles 13 and 14 of the GDPR, the Company hereby provides data subjects with information on the processing of their personal data.

Company’s contact information:

Mailing address: Sodexo Pass Česká republika a.s., Spaces SmíchOff, Plzeňská 3350/18, Praha 5 - Smíchov, Postcode 150 00

Phone number: 233 113 435

E-mail: gdpr.cz@sodexo.com

Web: www.sodexo.cz

Data Protection Officer: Anne-Cécile Colas, Group Data Protection Officer, Sodexo SA – 255 quai de la Bataille de Stalingrad – 92130 Issy-les-Moulineaux, France (e-mail: dpo.group@sodexo.com)


B. WHAT PRINCIPLES DO WE FOLLOW WHEN PROCESSING PERSONAL DATA?
The Company processes accurate and up-to-date personal data on the basis of law, in a fair and transparent manner, only for specific, explicit and legitimate purposes and with a
restriction to the minimum amount of necessary data, stores it in a form that permits identification of data subjects only for the period of time necessary in relation to the purpose
of the processes and ensures integrity and confidentiality of the data using appropriate technical or organisational precautions and appropriate security against unauthorised or
unlawful processing and against accidental loss, destruction or damage.
The Company ensures that any inaccurate data, taking into account the purpose for which it is processed, is deleted or rectified without delay.
The Company properly documents all activities related to personal data and the protection thereof, in particular, it keeps records of all processing activities and other documents
on the processing of personal data to fulfil the accountability principle laid down under the GDPR. The Company cooperates with the supervisory authority, namely the Office for
Personal Data Protection, with its registered office at Pplk. Sochora 27, 170 00 Prague 7, email: posta@uoou.cz, tel.: +420 234 665 111.
C. WHOSE PERSONAL DATA DO WE PROCESS AND FOR WHAT PURPOSE?
1. USERS OF OUR SERVICES AND JOB APPLICANTS
The Company offers their users a wide range of products and related services, including the Gastro Pass meal voucher and its electronic version, Gastro Pass
CARD, leisure vouchers and cards, the Active Pass card, the e-shop with Cafeteria mojeBenefity benefits and the SayReward incentive programme. In
connection with the provision of its products and services, the Company needs to process the personal data of the users of these products and services as set
out below.
2. HOW DO WE PROCESS YOUR PERSONAL DATA ON THE SODEXO CONNECT PORTAL?
i. User portal
Purpose of processing: providing services to clients,
Legal basis for processing: the processing is necessary in connection with the provision of services under concluded contracts, legitimate interest. Types
of personal data processed: name, e-mail, telephone number. Reason for data provision: if the data is not provided to the Company, the service cannot
be provided in a proper manner or the contract cannot be concluded and performed.
Processing period: for the duration of the user's registration on the web portal.
ii. Two-factor authentication of online payments to ensure strong user authentication
Purpose of processing: to ensure strong user authentication and related security of online payments on the Sodexo payment gateways in the form of
sending an SMS verification code for all online payments.
Legal basis of processing: ensuring strong user authentication when making online payments on the basis of Act No. 370/2017 Coll., on payment
transactions, as amended.
Types of personal data processed: telephone number.
Company’s contact information:
Mailing address: Sodexo Pass Česká republika a.s., Spaces SmíchOff, Plzeňská 3350/18, Praha 5 - Smíchov, Postcode 150 00
Phone number: 233 113 435
E-mail: gdpr.cz@sodexo.com Web: www.sodexo.cz
Data Protection Officer: Anne-Cécile Colas, Group Data Protection Officer, Sodexo SA – 255 quai de la Bataille de Stalingrad – 92130 Issy-les-Moulineaux,
France (e-mail: dpo.group@sodexo.com)
Reason for data provision: Unless the personal data is provided, the Company cannot send an authentication SMS to the user with a view to verifying the
online payment, thereby ensuring strong user authentication in accordance with applicable law.
3. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.SODEXO-UCET.CZ?
i. Sodexo personal account
Purpose of processing: provision of the service, i.e., the relevant benefits on the basis of the contract as set out below and in the context of the
administration of your Sodexo account on the www.sodexo-ucet.cz web portal.
Legal basis of processing: legitimate interest of the Company – the processing is necessary in connection with the provision of the service on the basis of
a contract concluded with your employer or another person who provides you with our benefits.
Types of personal data processed: name, e-mail, login, password, transaction history (payee, amount of payment, place of payment, date of payment).
Reason for data provision: if personal data is not provided to the Company, the service cannot be properly provided. Processing period: for the duration
of the user's registration on the web portal.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to the Company or consent is granted to the Company, marketing communications cannot be
sent to the user.
Processing period: 5 years or until the consent is revoked.
The user may opt out of receiving the Company’s commercial communications at any time:
a. directly in their Sodexo personal account after logging in, by clicking on User Profile and then revoking the consent next to the Consent to the
processing of user data for marketing purposes field. The edit must be confirmed by clicking on Save;
b. by clicking on the "Unsubscribe" link in each marketing communication, or by sending an email to odhlasit.cz@sodexo.com.
iii. Personalised commercial communications
Purpose of processing: sending the Company’s or its business partner’s personalised commercial communications. Legal basis of processing: consent.
Types of data processed: name, surname, transaction history
Reason for data provision: unless personal data is provided or consent is granted to the Company, personalised commercial communications cannot be
sent to the user.
Processing period: 5 years or until the consent is revoked.
The user can opt out of personalised ads at any time:
a. directly in their Sodexo personal account after logging in, by clicking on User Profile and then revoking the consent next to the Consent to the
processing of user data for the purposes of personalised ads The edit must be confirmed by clicking on Save; or
b. by sending an email to odhlasit.cz@sodexo.cz.
4. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.MOJEBENEFITY.CZ?
i. Cafeteria account
Purpose of processing: provision of services, i.e., the benefits under the below contract and administration of your Cafeteria Account.
Legal basis of processing: the legitimate interest of the Company – the processing is necessary in connection with the provision of the services under a
contract with your employer or another person who provides you with our benefits.
Types of personal data processed: email, transaction history (payee details, payment amount, payment location, date of payment).
Reason for data provision: if personal data is not provided to the Company, the service cannot be properly provided. Processing period: for the duration
of the user's registration in the Cafeteria account.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: e-mail.
Reason for data provision: unless personal data is provided to the Company or consent is granted to the Company, marketing communications cannot be
sent to the user.
Processing period: 5 years or until the consent is revoked.
The user may opt out of receiving commercial communications from the Company at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
5. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.MUJPASS.CZ?
i. "I’ve had a problem with the establishment” contact form
Purpose of processing: answering queries, processing and handling requests from website visitors. Legal basis of processing: processing requests/queries
based on the legitimate interest of the Company.
Types of personal data processed: name, e-mail, telephone number, or other personal data voluntarily provided by the data subject in the contact form.
Reason for data provision: The Company cannot process enquiries/requests unless it has been provided with contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. "Request for change of establishment data” contact form
Purpose of processing: answering queries, processing and handling requests from website visitors. Legal basis of processing: processing requests/queries
based on the legitimate interest of the Company.
Types of personal data processed: e-mail, or other personal data voluntarily provided by the data subject in the contact form. Reason for data provision:
The Company cannot process enquiries/requests unless it has been provided with contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
6. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.SODEXO-BENEFITY.CZ?
i. “Complaint” contact form
Purpose of processing: processing requests and handling complaints.
Legal basis of processing: processing requests/complaints based on the legitimate interest of the Company.
Types of personal data processed: name, e-mail, or other personal data voluntarily provided by the data subject in the contact form for the claim.
Reason for data provision: The Company cannot process enquiries/complaints unless it has been provided with contact personal data.
Processing period: for the time required to complete the processing of any enquiry/complaint plus another 3 months from the completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. "Tip for partner” contact form
Purpose of processing: answering queries, processing and handling messages from website visitors. Legal basis of processing: processing
messages/queries based on the legitimate interest of the Company.
Types of personal data processed: e-mail, or other personal data voluntarily provided by the data subject in the contact form. Reason for data provision:
The Company cannot process enquiries/messages unless it has been provided with the listed personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
7. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.SODEXO.CZ?
i. Career form
Purpose of processing: responding to job inquiries/applications and engaging in communication with a view to initiating and conducting the selection
process. Legal basis of processing: processing requests/queries and communicating with applicants based on the legitimate interest of the Company.
Types of personal data processed: name, e-mail, telephone number, or other personal data contained in the attached CV or cover letter.
Reason for data provision: The Company cannot process job inquiries/applications and contact applicants with an invitation to the selection process
unless it has been provided with contact personal data.
Processing period: during the selection process involving the applicant.
8. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.GPCARD.CZ?
i. "Contact my employer” contact form
Purpose of processing: answering queries, processing and handling messages from website visitors.
Legal basis of processing: processing requests/queries and communicating with applicants based on the legitimate interest of the Company. Types of
personal data processed: name, telephone number, e-mail.
Reason for data provision: The Company cannot process enquiries/requests and respond to applicants unless it has been provided with their personal
data.
ii. “I want to report a problem with my card payment” contact form
Purpose of processing: answering inquiries, processing and handling requests or problems.
Legal basis of processing: processing of requests/queries and communication with the user based on the legitimate interest of the Company.
Types of personal data processed: name, e-mail, Gastro Pass CARD number, date of transaction.
Reason for data provision: The Company cannot process enquiries/requests and respond to applicants unless it has been provided with their personal
data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
iii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to the Company or consent is granted to the Company, marketing communications cannot be
sent to the user.
Processing period: 5 years, or until the consent is revoked.
The user may opt out of receiving commercial communications from the Company at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
9. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.TONEJLEPSIZPRACE?
i. "Contact my employer” contact form
Purpose of processing: answering queries, processing and handling messages from website visitors.
Legal basis of processing: processing requests/queries and communicating with applicants based on the legitimate interest of the Company.
Types of personal data processed: name, telephone number, e-mail.
Reason for data provision: The Company cannot process enquiries/requests and respond to applicants unless it has been provided with their personal
data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to the Company or consent is granted to the Company, marketing communications cannot be
sent to the user.
Processing period: 5 years, or until the consent is revoked.
The user may opt out of receiving commercial communications from the Company at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
10. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.MOJEBONUSY.CZ?
i. System login
Purpose of processing: provision of services, i.e., the relevant benefits under the contract referred to below and administration of your account on the
www.mojebonusy.cz web portal.
Legal basis of processing: the legitimate interest of the Company – the processing is necessary in connection with the provision of the services under a
contract with your employer or another person who provides you with our benefits.
Types of personal data processed: name, e-mail.
Reason for data provision: if personal data is not provided to the Company, the service cannot be properly provided. Processing period: for the duration
of the user's registration on the web portal.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to the Company or consent is granted to the Company, marketing communications cannot be
sent to the user.
Processing period: 5 years, or until the consent is revoked.
The user may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com
11. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.MUJSWAP.CZ?
i. System login
Purpose of processing: provision of services, i.e., the relevant benefits provided under the contract referred to below and administration of your account
on the www.mujswap.cz web portal.
Legal basis of processing: the legitimate interest of the Company – the processing is necessary in connection with the provision of the services under a
contract with your employer or another person who provides you with our benefits.
Types of personal data processed: name, e-mail.
Reason for data provision: if personal data is not provided to the Company, the service cannot be properly provided. Processing period: for the duration
of the user's registration on the web portal.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to the Company or consent is granted to the Company, marketing communications cannot be
sent to the user.
Processing period: 5 years, or until the consent is revoked.
The user may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com
12. HOW DO WE PROCESS YOUR PERSONAL DATA ATN WWW.ACTIVEPASS.CZ/BLOG?
i. Newsletter "Subscribe to newsletter"
Purpose of processing: processing of online requests of data subjects to register for the newsletter and subsequent sending of the newsletter.
Legal basis of processing: consent.
Types of personal data processed: e-mail.
Reason for data provision: unless the personal data is provided to the Company, the Company cannot send the newsletters to users. Processing period:
5 years, or until the consent is revoked.
The user may opt out of receiving commercial communications from the Company at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
13. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.ALACARD.CZ?
i. Newsletter "First-Hand News"
Purpose of processing: processing of online requests of data subjects to register for the newsletter and subsequent sending of the newsletter.
Legal basis of processing: consent.
Types of personal data processed: e-mail.
Reason for data provision: unless personal data is provided to the Company, the Company cannot send relevant newsletters to users.
Processing period: 5 years, or until the consent is revoked.
The user may opt out of receiving commercial communications from the Company at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
14. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.PLNIME-PRANI-SENIORUM.CZ?
i. "I want to contribute" form
Purpose of processing: receiving and registering amounts of money, processing and transfer of donations and publication of the donor's name.
Legal basis of processing: performance of contract – the processing is necessary in connection with the processing and transfer of the donations. Types
of personal data processed: name, e-mail, address, bank account number.
Reason for data provision: unless personal data is provided to the Company, the Company cannot accept the donation.
Processing period: for the time necessary to discharge the donation contract referred to above, plus another 3 years from the end of its validity for the
purpose of any claims arising under the agreement.
15. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.PROPLATIT.CZ?
i. Request
Purpose of processing: processing requests for reimbursements of financial amounts.
Legal basis of processing: processing is necessary for the performance of the contract. Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data are provided to the Company, the amount will not be reimbursed.
Processing period: for the time necessary to discharge the contract plus another 3 years from the end of the contract for the purpose of any claims arising
under the contract.
16. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.VOUCHERS-ONLINE.CZ?
i. Orders
Purpose of processing: order processing and deliveries of ordered products.
Legal basis of processing: the processing is necessary for the conclusion and performance of contracts, including delivery of ordered products. Types of
personal data processed: name, telephone number, address, e-mail.
Reason for data provision: unless personal data is provided to the Company, the order cannot be fulfilled on the basis of the contract.
Processing period: for the duration of the contract plus another 3 years from the end of the contract for the purpose of any claims arising under the
contract.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to the Company or consent is granted to the Company, marketing communications cannot be
sent to the user.
Processing period: 5 years, or until the consent is revoked.
The user may opt out of receiving commercial communications from the Company at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
17. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.GRANDPRIX.VWFS.CZ?
i. Grand Prix personal account
Purpose of processing: provision of services, i.e., the relevant benefits under the contract referred to below and administration of your account on the
web portal www.grandprix.vwfs.cz.
Legal basis of processing: legitimate interest of the Company – the processing is necessary in connection with the provision of services on the basis of a
contract with ŠkoFIN s.r.o., with its registered office at Pekařská 6, Postcode 155 00 Prague 5, ID No. 45805369, which provides you with our benefits.
Types of personal data processed: name, e-mail.
Reason for data provision: if personal data is not provided to the Company, the service cannot be properly provided. Processing period: for the duration
of the user's registration on the web portal.
ii. Contact form
Purpose of processing: answering queries, processing and handling requests from website visitors. Legal basis of processing: processing requests/queries
based on legitimate interest of the Company.
Types of personal data processed: name, e-mail, or other personal data voluntarily provided by the data subject in the contact form. Reason for data
provision: The Company cannot process enquiries/requests unless it has been provided with the respective contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
I. OUR CLIENTS
The Company offers a wide range of benefits to company employees. It is our clients who further motivate their employees and provide them with our benefits.
See how we process our clients' personal data:
1. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.MOJEBENEFITY.CZ?
i. Login to the administrator account
Purpose of processing: provision of services.
Legal basis of processing: performance of a contract – the processing is necessary in connection with the provision of a service on the basis of a concluded
contract. Types of personal data processed: name, e-mail, telephone, address, date of birth, gender, personal number, position.
Reason for data provision: if personal data is not provided to the Company, the service cannot be properly provided.
Processing period: the duration of the contract, and an additional 3 years from the end of the contract for the purpose of resolving any disputes arising
from the contract.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to the Company or consent is granted to the Company, marketing communications cannot be
sent to the user.
Processing period: 5 years, or until the consent is revoked.
The user may opt out of receiving commercial communications from the Company at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
2. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.SODEXO-BENEFITS.CZ?
i. Complaint form (employer)
Purpose of processing: answering queries, processing and handling complaints from website visitors. Legal basis of processing: handling
complaints/queries based on legitimate interests of the Company.
Types of personal data processed: name, e-mail, or other personal data voluntarily provided by the data subject in the contact form. Reason for data
provision: The Company cannot process enquiries/requests unless it has been provided with the respective contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. Contact form
Purpose of processing: answering queries, processing and handling requests from website visitors. Legal basis of processing: processing requests/queries
based on legitimate interest of the Company.
Types of personal data processed: name and (i) e-mail if you choose to be contacted by e-mail, (ii) telephone number if you choose to be contacted over
the phone and, where applicable, other personal data voluntarily provided by the data subject in the contact form.
Reason for data provision: The Company cannot process enquiries/requests unless it has been provided with the respective contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
3. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.GPCARD.CZ?
i. "Interest in the card” contact form
Purpose of processing: responding to requests for meal voucher cards or requests for more information about the Gastro Pass CARD.
Legal basis of processing: measures taken prior to contract conclusion – processing requests/queries and communicating with applicants. Types of
personal data processed: name, phone number, e-mail, city.
Reason for data provision: The Company cannot process enquiries/requests and respond to applicants unless it has been provided with their personal
data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to or consent is given to the Company, marketing communications cannot be sent to clients.
Processing period: 5 years, or until the consent is revoked.
The Client may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
4. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.TONEJLEPSIZPRACE.CZ?
i. "Interest in the card” contact form
Purpose of processing: responding to card applications or requests for more information about the card.
Legal basis of processing: measures taken prior to contract conclusion – processing requests/queries and communicating with applicants.
Types of personal data processed: name, phone number, e-mail, company name. Reason for data provision: The Company cannot process
enquiries/requests and respond to applicants unless it has been provided with their personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to or consent is given to the Company, marketing communications cannot be sent to clients.
Processing period: 5 years, or until the consent is revoked.
The Client may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
5. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.MOJESODEXO.CZ?
i. Client account
Purpose of processing: providing services, i.e., the relevant benefits, to your employees and others to whom you provide our benefits, including the
administration of your personal account.
Legal basis of processing: performance of contract – the processing is necessary in connection with the provision of the services and administration of
the account on the basis of the concluded contract.
Types of personal data processed: name, e-mail.
Reason for data provision: if personal data is not provided to the Company, the service cannot be properly provided.
Processing period: duration of the client's registration on the web portal or the duration of the contract between you and the Company.
6. HOW DO WE PROCESS YOUR PERSONAL DATA AT APP.SODEXO.CZ/CLIENT-PORTAL/RECON?
i. Client portal
Purpose of processing: providing services, i.e., the relevant benefits, to your employees and others to whom you provide our benefits, including the
administration of your personal account.
Legal basis of processing: performance of contract – the processing is necessary in connection with the provision of the services and administration of
the account on the basis of the concluded contract.
Types of personal data processed: name, e-mail.
Reason for data provision: if personal data is not provided to the Company, the service cannot be properly provided.
Processing period: duration of the client's registration on the web portal or the duration of the contract between you and the Company.
7. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.ALACARD.CZ?
i. Newsletter – "First-Hand News"
Purpose of processing: processing clients' requests to subscribe for the newsletter. Legal basis of processing: consent.
Types of personal data processed: e-mail.
Reason for data provision: unless personal data is provided to the Company, the latter cannot send the newsletters to clients. Processing period: 5 years,
or until the consent is revoked.
The client may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
8. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.PLNIME-PRANI-SENIORUM.CZ?
i. "I want to contribute" form
Purpose of processing: receiving and registering amounts of money, processing and transferring the donations.
Legal basis of processing: performance of contract – the processing is necessary in connection with the processing and transfer of the donations. Types
of personal data processed: name, e-mail, address, company (employer).
Reason for data provision: unless personal data is provided to the Company, the Company cannot accept the donation.
Processing period: the time necessary to perform the aforementioned donation contract, plus an additional 3 years from the end of its validity for the
purpose of resolving any disputes arising from the contract.
9. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.ACTIVEPASS.CZ?
i. “Let us know about you!” form
Purpose of processing: answering queries, processing and handling requests from website visitors. Legal basis of processing: processing requests/queries
based on legitimate interest of the Company.
Types of personal data processed: name, e-mail, company (employer), or other personal data voluntarily provided by the data subject in the contact form.
Reason for data provision: The Company cannot process enquiries/requests unless it has been provided with the respective contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to or consent is given to the Company, marketing communications cannot be sent to clients.
Processing period: 5 years, or until the consent is revoked.
The Client may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
II. OUR PARTNERS
The Company works with a large number of partners such as restaurants, businesses, sports venues, etc. See how we process our partners’ personal data:
1. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.MUJPASS.CZ?
i. "Request for change of establishment data” contact form
Purpose of processing: processing and handling requests from website visitors.
Legal basis of processing: processing requests based on legitimate interests of the Company.
Types of personal data processed: name, e-mail, telephone number, or other personal data voluntarily provided by the data subject in the contact form.
Reason for data provision: The Company cannot process the request unless it is provided with personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
2. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.SODEXO-BENEFITS.CZ?
i. Complaint form (Partner)
Purpose of processing: answering questions, processing and handling complaints from website visitors. Legal basis of processing: handling
complaints/queries based on legitimate interests of the Company.
Types of personal data processed: name, e-mail, or other personal data voluntarily provided by the data subject in the contact form. Reason for data
provision: The Company cannot process complaints/queries unless it is provided with contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. Contact form
Purpose of processing: answering queries, processing and handling requests from website visitors. Legal basis of processing: processing requests/queries
based on legitimate interest of the Company.
Types of personal data processed: name and (i) e-mail if you choose to be contacted by e-mail, (ii) telephone number if you choose to be contacted over
the phone and, where applicable, other personal data voluntarily provided by the data subject in the contact form.
Reason for data provision: The Company cannot process enquiries/requests unless it has been provided with the respective contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
3. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.GPCARD.CZ?
i. “I want more information“ contact form
Purpose of processing: processing, handling and responding to enquiries/requests regarding the Gastro Pass CARD.
Legal basis of processing: processing requests/queries and communicating with applicants based on the legitimate interests of the Company.
Types of personal data processed: company, name, telephone number, e-mail. Reason for data provision: The Company cannot process
enquiries/requests and respond to applicants unless it has been provided with their personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to or consent is granted to the Company, marketing communications cannot be sent to clients.
Processing period: 5 years, or until the consent is revoked.
The partner may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email toodhlasit.cz@sodexo.com.
4. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.E-SODEXO.CZ?
i. Partner account
Purpose of processing: conclusion and performance of contract or administration of partner account.
Legal basis of processing: performance of a contract – the processing is necessary in connection with the provision of a service on the basis of a concluded
contract. Types of personal data processed: name, address, company, e-mail, telephone number.
Reason for data provision: unless the data are provided to the Company, the service cannot be provided in a proper manner or the contract cannot be
concluded and performed.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to or consent is granted to the Company, marketing communications cannot be sent to clients.
Processing period: 5 years, or until the consent is revoked.
The partner may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email toodhlasit.cz@sodexo.com.
5. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.ALACARD.CZ?
i. Newsletter – "First-Hand News"
Purpose of processing: processing partners’ online requests to subscribe for the newsletter. Legal basis of processing: consent.
Types of personal data processed: e-mail.
Reason for data provision: unless the data is provided to the Company, the latter cannot send newsletters to partners. Processing period: 5 years, or until
the consent is revoked.
The user may opt out of receiving commercial communications from the Company at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email to odhlasit.cz@sodexo.com.
6. HOW DO WE PROCESS YOUR PERSONAL DATA AT WWW.PLNIME-PRANI-SENIORUM.CZ?
i. "I want to contribute" form
Purpose of processing: receiving and registering amounts of money, processing and transferring the donations.
Legal basis of processing: performance of contract – the processing is necessary in connection with the processing and transfer of the donations.
Types of processed personal data: employer (company identification), name, e-mail, address, payment data (credit card number, bank account number).
Reason for data provision: unless personal data is provided to the Company, the Company cannot accept the donation.
Processing period: the time necessary to perform the aforementioned donation contract, plus an additional 3 years from the end of its validity for the
purpose of resolving any disputes arising from the contract.
7. HOW DO WE PROCESS YOUR PERSONAL DATA ATWWW.ACTIVEPASS.CZ?
i. "Become a partner" form
Purpose of processing: answering queries, processing and handling requests from website visitors. Legal basis of processing: processing requests/queries
based on legitimate interest of the Company.
Types of personal data processed: name, e-mail, company (employer) or other personal data voluntarily provided by the data subject in the contact form.
Reason for data provision: The Company cannot process enquiries/requests unless it has been provided with the respective contact personal data.
Processing period: the period of time required to complete the processing of any enquiry/request plus another 3 months from its completion for the
purposes of recording and evaluating enquiries and for the purposes of further related communication on the matter.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to or consent is granted to the Company, marketing communications cannot be sent to clients.
Processing period: 5 years, or until the consent is revoked.
The partner may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email toodhlasit.cz@sodexo.com.
8. HOW DO WE PROCESS YOUR PERSONAL DATA AT APP.SODEXO.CZ/PARTER-PORTAL?
i. Partner portal
Purpose of processing: conclusion and performance of a contract or partner account administration.
Legal basis of processing: the processing is necessary in connection with the provision of services under the concluded contract. Types of personal data
processed: name, address, company, e-mail, telephone number.
Reason for data provision: unless the data are provided to the Company, the service cannot be provided in a proper manner or the contract cannot be
concluded and performed.
Processing period: while the partner is registered on the web portal or the duration of the contract concluded between you and the Company.
ii. Marketing communications
Purpose of processing: sending the Company’s or its business partners’ marketing communications. Legal basis of processing: consent.
Types of personal data processed: name, e-mail.
Reason for data provision: unless personal data is provided to or consent is granted to the Company, marketing communications cannot be sent to clients.
Processing period: 5 years, or until the consent is revoked.
The partner may opt out of receiving the Company’s commercial communications at any time by clicking on the "Unsubscribe" link in each commercial
communication or by sending an email toodhlasit.cz@sodexo.com.
D. WHAT RIGHTS DO YOU HAVE IN RELATION TO THE PROCESSING OF YOUR PERSONAL DATA?
RIGHT OF ACCESS AND RECTIFICATION You can request access to your personal data. You may also demand that any inaccurate personal data be
rectified and any incomplete data supplemented.
You can request any available information as to the source of your personal data, and you may also request
a copy of your personal data being processed by the Company.
In accordance with the GDPR, the Company reserves the right to charge a fee for the exercise of these
rights. The Company may charge a fair and reasonable fee taking into account the Company's
administrative costs if the request is manifestly unfounded or unreasonable. The Company will inform the
data subject of the fees before processing the request.
RIGHT TO ERASURE Your right to erasure allows you to request the erasure of your personal data where:
I. the data is no longer necessary in relation to the purposes of its collection or processing;
II. you choose to withdraw your consent;
III. you object to processing by automated means using technical specifications;
IV. your personal data has been processed unlawfully;
V. a legal obligation exist to erase your personal data;
VI. the erasure is required to ensure compliance with applicable laws.
RIGHT TO RESTRICTION OF PROCESSING You may request restriction of processing where:
I. you contest the accuracy of the personal data;
II. the Company no longer needs the personal data for the relevant purposes of the processing;
III. you have objected to the processing on legitimate grounds.
RIGHT TO DATA PORTABILITY Where applicable, you can request data portability for the personal data you have provided to the
Company so that it is available in a structured, commonly used and machine-readable format. You can also
demand that your personal data be transmitted to a third party of your choice (where technically feasible).
RIGHT TO OBJECT You may object (the right to “opt-out”) to the processing of your personal data (namely for profiling or
marketing communications). If we process your personal data on the basis of your consent, you can
withdraw your consent at any time.
RIGHT NOT TO BE SUBJECTED TO AUTOMATED
DECISIONS
You have the right not to be subjected to decisions based solely on automated processing, including
profiling, which produces legal effects concerning you or similarly significantly affects you.
E. HOW CAN YOU EXERCISE THE ABOVE RIGHTS?
These rights can be exercised by filling in the Complaint Request Form, electronically at the following e-mail address gdpr.cz@sodexo.com, over the phone at 233 113
435 or in writing at the Company's registered office address above. You also have the right to lodge a complaint with the Office for Personal Data Protection or another
competent supervisory authority in the context of the processing of your personal data.
F. WHO ARE THE RECIPIENTS OF YOUR PERSONAL DATA AND OTHER SUBJECTS?
1. PERSONAL DATA RECIPIENTS
For purposes of providing Company services, third parties are involved in the processes that are crucial for ensuring the provision of our services at the highest
standard. The main reasons for providing personal data to third parties include administration of services, promotion of services, or communication with our users,
partners or clients. The Company does not sell or lend personal data in exchange for payment.
The Company shares personal data with the following parties:
I. Operators and administrators of websites and cloud storages: in certain cases, third parties may have access to personal data that is stored under user
accounts on the Company’s website. Furthermore, personal data may be shared with third parties that provide the Company with services related to cloud
storage.
II. Partners providing info-line services: for the purpose of providing our users, clients and partners with quality customer service, the Company may share
personal data with third parties that provide call centre services for the Company.
III. Suppliers of services related to the provision of benefits: In certain cases, the Company may transfer your personal data to third parties that prepare and
manufacture personalised benefits for the Company (i.e. namely personalised vouchers or cards). The Company may also provide certain personal data to
a third party that processes payments with Gastro Pass CARD. At the same time, the Company shares personal data with companies that provide supply
services for users, clients or partners.
IV. Public Authorities: The Company complies with applicable laws and thus, in certain cases, shares personal data with state authorities, if required so by law.
The Company may make personal data available to other parties in order to secure and protect their rights and assets or the rights and assets of their
business partners.
V. Other companies within Sodexo Group: in order to improve the services provided by the Company, personal data may be shared within Sodexo Group. In
this respect, Sodexo ensures the maximum level of protection and confidentiality when transferring your personal data.
VI. Partners providing marketing and PR services: To a limited extent, the Company shares personal data with third parties that help the Company improve and
promote its services. These third parties prepare business or marketing communications for our users, clients, or partners and/or provide services regarding
online forms and web applications. For purposes of considerable determination, the Company shall provide data subjects with the highest possible rights
and protection of personal data, in which case the Company shall list third parties with which it shares your information for purposes mentioned above:
1. KINDRED GROUP s.r.o., with its registered office at Drtinova 557/10, Smíchov, 150 00 Prague 5, Company Reg. No. 06024491, registered in the
Commercial Register maintained by the Municipal Court in Prague under File No. C 274199;
2. Boomerang Communication s.r.o., with its registered office at Nad Kazankou 708/37, Trója, 171 00 Prague 7, Company Reg. No. 26447657, registered
in the Commercial Register maintained by the Municipal Court in Prague under File No. C 82867;
3. AMI Communications, spol. s r.o., with its registered office at Týn 641/4, Old Town, 110 00 Prague 1, Company Reg. No. 63077370, registered in the
Commercial Register maintained by the Municipal Court in Prague under File No. C 36493;
4. E-mail: Machine s.r.o., with its registered office at Londýnské náměstí 881/6, Štýřice, 639 00 Brno, Company Reg. No. 03568831, registered in the
Commercial Register maintained by the Regional Court in Brno under File No. C 85521;
5. Re-Hab / creative boutique s.r.o., with its registered office at Bajkalská 672/14, Vršovice, 100 00 Prague 10, Company Reg. No. 02896991, registered in
the Commercial Register maintained by the Municipal Court in Prague under File No. C 225186;
6. ART living s.r.o., with its registered office at Koněvova 2499/246, 130 00 Prague 3, Company Reg. No. 45787875, registered in the Commercial Register
maintained by the Municipal Court in Prague under File No. C 17303;
7. DATOR3 Services, a.s., with its registered office at Stýblova 253/13, Chodov, 149 00 Prague 4, Company Reg. No. 25788612, registered in the
Commercial Register maintained by the Municipal Court in Prague under File No. B 6067;
8. brainz.cz s.r.o., with its registered office at Fibichova 13/2, Žižkov, 130 00 Prague 3, Company Reg. No. 27869032, registered in the Commercial Register
maintained by the Municipal Court in Prague under File No. C 122935;
9. IPSOS s.r.o., with its registered office at Topolská 1591, Černošice, 252 28 Praha-západ district, Company Reg. No. 26738902, registered in the
Commercial Register maintained by the Municipal Court in Prague under File No. C 90694.
10. Instinct Agency s.r.o., with its registered office at Domažlická 1232/3, 130 00, Prague 3, Company Reg. No. 06978941, registered in the Commercial
Register maintained by the Municipal Court in Prague under File No. C 292417.
2. OTHER SUBJECTS
Independent controllers of personal data
In addition to the above, the Company holds the position of an independent controller of personal data along with Company’s clients, i.e., the companies to whose
employees the Company provides a wide range of employee benefits.
With these clients, the Company holds the position of independent controllers, as each of them is capable of determining the purpose and means of processing of
the personal data processed and stored under their control in accordance with their privacy policy. The Company enters into agreements with these clients between
personal data controllers that set a framework for sharing personal data between the controllers and defines the policies and procedures that the controllers
comply with and the mutual responsibilities between the controllers.
G. JOINT CONTROLLERS
In order to be able to provide our services to a high standard, we must in some cases establish cooperation with other entities with whom we jointly determine the
purpose and means of processing your personal data. In such case, we become joint controllers of your personal data. In accordance with Article 26 of the GDPR, we
will always enter into a joint controllership with such entities, through which we will define between us the responsibilities for the fulfilment of the obligations under
the GDPR.
You can exercise your rights under the GDPR in accordance with Article 26(3) of the GDPR both with us and with the other joint controller of your personal data.
We are currently in the position of joint controllers with the following entities:
I. E Corp innovations s.r.o., with its registered office at: Klatovská 638, 340 22 Nýrsko, ID No.: 077 12 014, registered in the Commercial Register maintained by
the Regional Court in Plzeň, File No. C 37222 (hereinafter referred to as “E Corp innovations”). Together with this company, we operate and ensure the
functioning of the Active Pass card.
E Corp innovations has the following obligations towards you:
I. provide you with information in accordance with Article 13 of the GDPR where your personal data has been obtained directly from you;
II. provide you with information in accordance with Article 14 of the GDPR where your personal data has not been obtained directly from you;
III. seek your consent for themselves and for our Company to processing your personal data covering all purposes for processing such personal data as collectively
defined by us and E Corp innovations where consent is required under the GDPR for such data processing, and to keep proper records of such consent for as
long as it remains valid;
IV. inform you of any essential elements of the contract when providing information pursuant to Article 13 or Article 14 of the GDPR;
V. put in place appropriate technical and organisational measures within the meaning of the GDPR to ensure and be able to demonstrate that the processing of
personal data is carried out in accordance with the GDPR, and review and update those measures; and
VI. act as a common point of contact for both controllers.
VII. maintain and, from time to time, review and update records on data processing within the meaning of the GDPR;
VIII. implement appropriate technical and organisational measures within the meaning of the GDPR to ensure and be able to demonstrate that the data processing
is carried out in accordance with the GDPR, as well as review and update these measures;
IX. report, properly and in a timely manner, any possible data security breaches to the supervisory authority and cooperate with the authority to the necessary
extent; and
X. notify you of any data security breaches in a proper and timely manner.
H. DEFINITIONS
Applicable data protection legislation denotes all applicable laws and regulations relating to the protection and processing of personal data, including Regulation (EU)
2016/79 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the
free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), and other legislation adopted in the Czech Republic and the
European Union.
Complaint denotes a complaint lodged by the data subject with the supervisory authority if the data subject believes their rights under the applicable data protection
laws have been infringed.
Company denotes Sodexo Pass Česká republika a.s., with its registered office at Spaces SmíchOff, Plzeňská 3350/18, Praha 5 - Smíchov, Postcode 150 00, ID No.:
61860476, listed in the Commercial Register maintained by the Municipal Court in Prague, under File No. B 2947.
Data subject’s rights denote the rights granted to data subjects by the applicable data protection laws, such as the right of access, right to rectification, right to erasure,
right to restriction of Processing, right to data portability or the right to object.
General Data Protection Regulation or GDPR denotes Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of
natural persons with regard to the processing of Personal data and on the free movement of such data, and repealing Directive 95/46/EC
Personal data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified,
directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more factors specific
to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as
collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise
making available, alignment or combination, restriction, erasure or destruction.
Request refers to one of the mechanisms provided by the GDPR to data subjects to allow them to exercise their rights (such as the right of access, to rectification,
erasure, etc.). A data subject may lodge a request against any person which processes their personal data, the controller or the processor, if relevant.
This Statement comes into force on 2 December 2019. This Statement shall be reviewed and updated periodically after the lapse of 12 months from the date on which it came
into force or from the last review and update, or more frequently if the need for review and update arises. The current version of the Statement is always available on the Internet
at https://cz.sodexo.com/files/live/sites/com-cz/files/Prohlaseni/zasady_ochrany_osobnich_udaju_CZ_EN.pdf
Annex 1 Complaint Request Form
Annex 2 Sodexo Benefity Cookie Policy

Back to the list