Candy & Co is committed to respecting the privacy rights of all visitors to our Website.
Personal data generally means information that can be used to individually identify a person, and processing generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. We are the controller of your personal data processed in connection with the Website.
Personal Data We Collect
In running and maintaining our Website, we may collect and process the following information:
Personal Data Collected Directly From You
We receive personal data directly from you when you provide it to us through placing a food order, including, but not limited to:
- email address;
- mailing address;
- telephone number;
- username; and
- payment details.
You may also include details in your food order that indicate your health information or religious beliefs.
Personal Data Collected We Automatically Collect
Some personal data is automatically collected when you use the Website, such as:
- IP address;
- device identifiers;
- browser information; and
How We Use Personal Data
We process personal data to operate, improve, understand and personalise our services e.g. we use personal data to:
- complete orders including delivery or collection of food;
- personalise content based on your preferences;
- contact you about our offers, subject to your marketing preferences;
- communicate with you;
- protect against or deter fraudulent, illegal or harmful actions;
- respond to user inquiries;
- provide support and assistance;
- comply with our legal or contractual obligations;
- enforce our terms and conditions; and
- resolve disputes.
Lawful Basis for Processing
|Purpose of Processing||Lawful Basis under GDPR|
|Administration purposes||Such processing is necessary for the performance of a contract between us and you, where necessary for the purpose of complying with our legal obligations and where you have consented to providing certain information in relation to your food order preferences at the time of purchase.|
|Training, quality monitoring or evaluating the services we provide||Such processing is necessary for the legitimate interests pursued by us in monitoring and improving our Website"s services and their usage and ensuring that our users use the Website in accordance with our terms and conditions and policies.|
|Website services, including for troubleshooting, data analysis, and survey purposes||We have a legitimate interest in operating and maintaining the Website and for related purposes including improving our services.|
|Statistical information that cannot be related back to individuals to help us improve the services we offer||We have a legitimate interest in having access to certain analytics to ensure the products and services we provide are adequate.|
|Enforcing and Defending Our Rights||
We have a legitimate interest in ensuring that our services
and the Website are used in accordance with our terms and
conditions of use and policies.
Where necessary for the purpose of complying with our legal obligations.
Where necessary for the purpose of establishing, exercising or defending a legal claim, a prospective legal claim, legal proceedings or prospective legal proceedings.
We will not use your personal data for marketing purposes without your consent. If you wish to stop receiving marketing communications from us, you can opt out at any time by clicking the "opt-out" link at the bottom of any marketing communication from us or by contacting us at the e-mail provided on our website.
Individual Data Subject Rights
Data Protection Laws provide certain rights in favour of data subjects (the "Data Subject Rights").
Data Subject Rights include the right of a data subject to:
- access personal data;
- rectify or erase personal data (i.e. right to be forgotten);
- restrict processing;
- data portability;
- object to processing; and
- object to automated decision making (including profiling).
These Data Subject Rights will be exercisable by you subject to limitations as provided for under Data Protection Laws.
You may make a request to us to exercise any Data Subject Right by contacting the e-mail address provided on our website. Your request will be dealt with in accordance with Data Protection Laws.
How we Share Data with our Partners
We do not share any personally identifying data with third parties and will not disclose your personal data to any other party except as set out in this policy.
We and Flipdish, our online ordering partner, are joint controllers of your personal data processed in connection with food orders placed through the Flipdish Platform on the Website. If you have queries regarding how your personal data is processed by Flipdish or wish to address your rights, please contact Flipdish.
Flipdish acts as a processor in assisting us with managing users" consent to our marketing communications. Flipdish also acts as a processor when it assists us to manage our analytics.
We may be required to disclose personal data in some scenarios e.g. when you violate our terms and conditions or other policies. We may disclose such personal data, at our sole discretion, if we believe it necessary or appropriate in connection with investigation of fraud, IP infringement, piracy, or other unlawful activity. This may require disclosure of your name, address, phone number, email or company name.
We may engage other companies and people to perform tasks on our behalf (i.e. processors) and may need to share your information with them to provide you with our services.
In some cases, we may buy or sell its assets which may involve the transfer of customer information. We will transfer such information if we are acquired by or merged with another company. In this event, we will notify you by email.
Without limiting the above, in an effort to respect your privacy and our ability to keep the community free from bad actors, we will not otherwise disclose your personal data to law enforcement, other government officials, or other third parties without a court order, law enforcement request, legal process, or substantially similar legal procedure, except when we believe in good faith that the disclosure of information is necessary to protect our rights or the rights of third parties, prevent physical harm or financial loss, or to report suspected illegal activity.
Third Party Links
Service-related Announcements and Changes
While you may make a complaint in respect of our compliance with Data Protection Laws to the Data Protection Commission, we ask that you contact us in the first instance to give us the opportunity to address your concerns.
This Policy was last updated on September 2020.