Welcome to Cadbury Secret Santa!
Find my message
You lucky thing! A very generous person has sent you a Cadbury Secret Santa. Now you can find out if they have left you a message.
Full Privacy Notice
At Mondelēz International, we value your trust when sharing your personal data with us and recognize that you may be concerned about the information provided to us and about how we handle that information.
If you are reading this Privacy Notice ("Privacy Notice") it is because you may have visited a Website, a Mobile App or any other place within any Social Media (all of them referred to hereinafter as “Sites”) operated by any of the European entities of Mondelēz International Group ("Mondelēz International " or "us" or "we") or, because you may have contacted us directly by phone or in writing.
This Privacy Notice sets out (in full transparency and in accordance with applicable laws and regulations, especially the General Data Protection Regulation -Regulation (EU) 2016/679- "GDPR"), the basis on which we process your Personal Data ("Personal Data") when you access our Sites or contact us.
Speed Read on key Mondelēz International data processing
Mondelēz International collects and uses Personal Data which you provide or which we collect about you when you navigate through our Sites for the purposes of advertising, supplying you with our products and services, making contact with you for marketing or other commercial purposes, answering your enquiries regarding our products, facilitating your participation in our offers and promotions, analysing and improving the quality of our products or services.
Your access to and use of our Sites is subject to the terms and conditions of our Privacy Notice and all applicable laws. Your Personal Data processing will be limited to what it is necessary in relation to the purposes abovementioned. We will be collecting your expressed consent only where necessary by opt-ins so that you exert full control on the information we process and hold about you. Otherwise, we will only process your Personal Data if necessary for the performance of a contract with you, for compliance with a legal obligation of Mondelēz International and /or for the purposes of legitimate interests of Mondelēz International.
We usually process your Personal Data in the European Union but, it may also be stored in systems based around the world, and may be processed by third party service providers acting on our behalf. These systems and providers may be based on territories, such as the USA, that do not provide an equivalent level of protection over privacy as that enjoyed in the EU. In that case Mondelēz International will provide for adequate technical and organizational measures to protect your Personal Data and ensure a level of safeguards that is equivalent to the one of the country of origin. You can seek for further information and exercise your rights of access, rectification, cancellation, objection, and data portability in respect of your Personal Data, by clicking in our Contact Us feature or contacting our Data Protection Officer (please see contact details below).
We may change this Privacy Notice from time to time by posting the updated version of the Privacy Notice on our Sites. We will inform of any material change so that you can fully understand the changes that are actually implemented. Please visit frequently this Privacy Notice to stay informed about how we use your personal data.
This Privacy Notice is dated 11.04.2018
What Personal Data do we collect from you?
The type of information and Personal Data that we collect about you when you visit our Sites or interact with us may include the following:
- Personal details provided by you - such as your name, postal address and other contact details, such as your telephone number and email address, your requests, any complaints you may have and any other data we receive if we communicate with you via email, online or via social media, and any other information you provide - for example, when you register with our Sites, sign up for our newsletters, participate in our offers and promotions, provide customer feedback, reply to surveys or purchase our products or services;
- Payment information - including data to make purchases, such as your payment account details, credit card and debit card numbers, expiration date, shipping and billing address;
- Account login information - including any information that is required for you to establish a user account, such as user name, password and security question and answer;
Why do we collect Personal Data?
We collect and use your Personal Data for the purposes below and on lawful basis. Please know that insofar as we already hold information about you, we may use that information for the same purposes.
For legitimate commercial interests: we may use your Personal Data (both on an aggregated and on an individual basis), such as your contact details, your account and electronic identification data, information regarding your purchases in our stores and online, for the purpose of advertising and for analysing and improving the quality of our products or services, as well as, to understand you as a customer.
This also means that we analyse the information that you provide to us together with your use of our Sites or of our products and services and we use all this information to improve the same and to give you a better user experience (for example, we analyse what web pages you visit, which products and services you use and like, how you use these products and services).
We may also use your Personal Data, for legitimate commercial interests such as, to generate aggregated statistics about the users of our products and services; to assist in security and fraud prevention; for system integrity purposes; to remind you per email of your abandoned cart or send you an order confirmation; to facilitate our business operations, to operate company policies and procedures; to enable us to make corporate transactions, such as any merger, sale, reorganization, transfer of Mondelēz International assets or businesses, acquisition, bankruptcy, or similar event; and for other legitimate business purposes permitted by applicable law, on which we would provide the relevant information at the time.
For the performance of the terms and conditions of a contract: to purchase our products or services or to develop a contest, competition or promotion in which you may have entered, to conduct the promotion and contact to you if you became a winner, to be able to answer to any information request performed using our Contact Us features.
We may also use your information based on your consent, where granted, for instance for marketing purposes and for tailoring our communications with you based on your profiles via email, SMS, other electronic means or otherwise. You can withdraw your consent any time; see What rights do you have regarding the Personal Data we hold about you?
To comply with our legal obligations, such as maintaining appropriate business records, handling complaints made to our customer service, complying with lawful requests by public authorities and with applicable laws and regulations or as otherwise required by law.
How long do we retain your Personal Data?
We will only retain your Personal Data for as long as it is necessary to satisfy the purpose for which it was provided by you or collected by us (for example, for the time necessary for us to answer queries or resolve problems).
We may therefore retain your Personal Data for a reasonable period after your last interaction with us. When the Personal Data that we collect is no longer required in this way, we destroy or delete it in a secure manner. We may, instead of destroying or erasing your Personal Data, make it anonymous so that it cannot be associated with or tracked back to you. In certain cases, we may have legal or regulatory obligations that require us to retain specific records for a set period of time.
Who might we share your Personal Data with?
We may share your Personal Data with:
- Mondelēz International entities. Your Personal Data could be shared between the responsible Mondelēz International companies that may use your Personal Data as described in this Privacy Notice.
- Service Providers and Processors. We may engage third party vendors, agents, service providers, and affiliated entities to provide services to us on our behalf, such as support for the internal operations of our websites, Mobile Apps or online stores (including social media services providers, payment processors, brand activation agencies, data analytics providers and third parties we use for sending your orders to your home address, such as postal courier vendors) or for the technical processing (for example, hosting services or data storage) or for customer relationship management services, as well as related offline product or promotional support services, (for example, competitions, sweepstakes and contests organizers, winner draws providers, events management agencies, prize or compensation packages vendors) and, other related services.
- In providing their services, they may access, receive, maintain or otherwise process Personal Data on our behalf. Our contracts with these service providers do not permit use of your information for their own purposes, including their marketing purposes. Consistent with applicable legal requirements, we take commercially reasonable steps to require third parties to adequately safeguard your Personal Data and only process it in accordance with our instructions.
- Partners. We may sometimes offer you a service or application in co-operation with partners (for example, co-sponsors or licensors, licensees or distributors of our branded products). We may therefore need to disclose your Personal Data to those partners. Consistent with applicable legal requirements, we take commercially reasonable steps to require third parties to adequately safeguard your Personal Data and only process it in accordance with our instructions or as co-controllers. In those cases in which the disclosure of your Personal Data with third partners takes place based on your consent or your request to do so, where relevant, we will clearly notify you of the sharing, and you will have the choice not to participate or to otherwise object to such sharing.
- Third parties in case of legal requirement. We may also disclose your Personal Data if we believe we are required to do so by law, or that doing so is reasonably necessary to comply with legal processes; when we believe necessary or appropriate to disclose Personal Data to law enforcement authorities, such as to investigate actual or suspected fraud or violations of law, breaches of security, or breaches of this Privacy Notice; to respond to any claims against us; and, to protect the rights, property, or personal safety of Mondelēz International, our customers, or the public.
- Third Parties in case of a corporate transaction. In addition, information about our customers, including Personal Data, may be disclosed as part of any merger, sale, reorganization, transfer of Mondelēz International assets or businesses, acquisition, bankruptcy, or similar event.
International transfers of your Personal Data
We will normally process your Personal Data within the European Union. Notwithstanding this, the global nature of our business involves that your Personal Data may occasionally be disclosed to non-European entities of the Mondelēz International Group for which they have entered into a data transfer agreement regulating these cross-border transfers.
We also use some third party suppliers to help us provide business services. These third parties may have access to or merely host your Personal Data, but will always do so under our instructions and subject to a contractual relationship. When these third parties are located in territories (such as the USA) which may not offer an equivalent level of protection to privacy as that applicable within the EU, we will take all the necessary steps to verify that your Personal Data receives an adequate level of protection. This, either by entering into data transfer agreements or by ensuring that third parties are certified under appropriate data protection schemes.
How do we ensure the security of your Personal Data?
We use a variety of physical, technical and administrative security standards, technologies and procedures to help protect your Personal Data from loss, misuse, alteration, destruction or damage to an appropriate level depending on the sensitivity of the information.
We take steps to limit access to your Personal Data to those persons who need to have access to it for one of the purposes listed in this Privacy Notice. Furthermore, we contractually ensure that any third party processing your Personal Data equally provide for confidentiality and integrity of your data in a secure way.
What rights do you have regarding the Personal Data we hold about you?
You have the following rights:
- to obtain a copy of your Personal Data together with information about how and on what basis that Personal Data is processed;
- to rectify inaccurate Personal Data (including the right to have incomplete Personal Data completed);
- to erase your Personal Data in limited circumstances where it is no longer necessary in relation to the purposes for which it was collected or processed;
to restrict processing of your Personal Data where:
- the accuracy of the Personal Data is contested;
- the processing is unlawful, but you object to the erasure of the Personal Data;
- we no longer require the Personal Data for the purposes for which it was collected, but it is required for the establishment, exercise or defense of a legal claim;
- you challenge the processing which is justified on the basis of a legitimate interest;
- to object to decisions which are based solely on automated processing, including profiling;
- to receive a portable copy of your Personal Data, or to have a copy transferred to a third party controller where technically feasible and this does not involve unreasonable costs;
In case you may have a complaint about how we process your Personal Data, you can send it by clicking in our Contact Us form or contacting our Data Protection Officer (please see contact details below).
Alternatively, you have the right to lodge a complaint with the supervisory data protection authority.
If you have any questions regarding the processing of your Personal Data, this Privacy Notice or if you wish to exercise any of the above mentioned rights, please contact us. Either you can send it by clicking in our Contact Us form or contacting our Data Protection Officer (please see contact details below). Whenever reasonably possible and required, we will strive to grant your rights within one month.
You may revoke your consent for receiving newsletter or marketing communications at any time, free of charge by following the instructions in any marketing communication or even now by using the deregistration option within our Contact Us form. You can also control these preferences in your profile settings, where applicable.
Social Media and Other Websites
When you participate in any of our MDLZ profiles or wherever MDLZ is present in any of the various social media forums like Facebook, Twitter, Yammer, Pinterest, Instagram, LinkedIn, Youtube, etc., you should be familiar with and understand the tools provided by those sites that allow you to make choices about how you share the Personal Data in your social media profile(s).
Subsequently our Sites may contain links to third-party websites; if you follow these links, you will exit our websites and mobile applications. While these third-party websites are selected with care, Mondelēz International cannot accept liability for the use of your Personal Data by these organisations. For more information and details, please consult the Section Data Privacy Notices of third parties and the privacy statement of the website you are visiting (if such a statement is provided).
How do we process Children’s Personal Data?
In general terms, our Sites are not intended to Children under 12 years old. Above that age, as we take the protection of children’s privacy seriously, we operate our Sites in compliance with all applicable law in each corresponding Jurisdiction. Any time children under the age of 16 years old or below, as per the appropriate applicable law for each Site, should have a parent/guardian’s consent before providing any Personal Data to us to the website. If we determine upon collection that a user is under said age and has not provided a parent/guardian’s consent before providing any Personal Data, we will not use or maintain his/her Personal Data without the parent/guardian’s consent. Without such consent, though, the child may not be able to participate in certain activities. However, in certain circumstances, we may maintain and use such information (in accordance with the rest of this Notice and applicable law) in order to notify and obtain consent from the parent/guardian and for certain safety, security, liability and other purposes permitted under applicable law. A parent/ guardian can review, remove, change or refuse further collection or use of their child’s Personal Data by contacting us by clicking in our Contact Us form or contacting our Data Protection Officer (please see contact details below), including child’s name, address and e-mail address.
Mondelēz International 's Data Protection Officer
Mondelēz International has a Data Protection Officer ("DPO") who is responsible for the compliance with data protection law. You may contact Mondelēz International 's Data Protection Officer or their office securely and confidentiality at any time if you have questions, general concerns about the processing of your Personal Data, or any data protection issue.
You can contact the DPO's by emailing to MDLZDataProtectionOfficeMEU@mdlz.com