In this Customer Privacy Policy (Privacy Policy):
and includes the Five Guys app; and
If you are a customer of Five Guys in the USA or Canada, this Privacy Policy will not apply to you. Please instead refer to our privacy notice at www.fiveguys.com.
This Privacy Policy sets out the basis on which we collect and use personal information about you through your use of the Website and when you visit a FIVE GUYS® Restaurant.
This Privacy Policy describes:
This is to make sure you have a full picture of how we collect and use your personal information.
In this Privacy Policy where we use the words personal information we use these words to describe information that is about you and is information which identifies you or them.
Our Website is not intended for children and we do not knowingly collect personal information relating to children.
You have the right to object to our use of your personal information in certain circumstances. A summary of your right to object (along with your other rights under data protection law) and details of who to contact if you want to exercise this right can be found at the How to Contact us section below. For further information on your rights see the Your rights section below.
For the purpose of data protection law, we are the controller in respect of your personal information collected and used through your use of the Website and when you visit a FIVE GUYS® Restaurant. This is because we dictate the purpose for which your personal information is used and how we use your personal information.
We collect and use personal information about you in the course of providing the Website and when you visit a FIVE GUYS® Restaurant and you provide us with your personal information. We may also collect certain personal information from you via our Website or when you choose to interact with us.
The information that we hold about you may include the following:
Type of Personal Information |
Examples |
General |
|
Contact information. |
Name, title, address, email address and telephone number. |
Telephone recordings |
Recordings of telephone calls with our representatives and call centres. |
Register to use our online services |
Username and account number for access to our Website. |
Details of complaints and compliments you make |
Name, address, e-mail address or telephone number, details about the service you received/your experience. |
Financial |
|
Financial information and account details |
Details regarding products purchased, price, payment method and other financial account details. |
Other |
|
CCTV footage |
Images captured on CCTV if you visit a FIVE GUYS® Restaurant. |
Order data |
Information regarding the online order(s) that you place with us through a Website (e.g. products that you order, date of order, delivery address, payment information). |
Photographs |
Images that you share with us via social media. |
Customer satisfaction/feedback surveys |
Your views and opinions about your visit to a FIVE GUYS® Restaurant and your dining experience as well as your views about the Website. |
Technical Information |
Technical Information from any device you use in our stores Belgium and the Netherlands. |
We also collect information from other third party sources and or publicly available sources such as:
We collect identity and contact information about you from the above, and any other available sources (as updated from time to time).
We may also collect certain sensitive personal information about you from you (including any special categories of personal data). This may include information concerning your health such as food allergies or intolerances which you provide to us. Where we do so we will rely on your explicit consent or we will notify you if we can rely on a different legal basis for processing this type of information.
In the course of using the Website and when you visit a FIVE GUYS® Restaurant, you may provide us with personal information relating to third parties.
We will use this personal information in accordance with this Privacy Policy. If you are providing personal information to us relating to a third party, you confirm that you have the consent of the third party to share such personal information with us and that you have made the information in this Privacy Policy available to the third party.
We use your personal information in connection with the provision of the Website; to supply our products to you when you visit a FIVE GUYS® Restaurant and/or when you have placed an online order with us through the Websites, and in order to execute such online order. In particular, your personal information may be used by us, our employees, service providers, and disclosed to third parties for the purposes set out in the table below. For each of these purposes, we have set out the legal basis on which we use your personal information. This is because under data protection law, we can only use your personal information if we have a legal basis to do so.
Examples of where we have a legal basis to process your personal information includes when:
We must tell you which legal basis we are relying on when we use your personal information. The legal basis we typically rely on and the main purposes for which we use your personal information are set out below.
Purpose |
Legal Basis |
To communicate with you and other individuals. |
Legitimate interests. We require your personal information in order to enable us to manage and carry out our operations as a business. Necessary to enter into or perform a contract we have with you. |
To manage complaints, feedback and queries and provide customer support. |
Legitimate interests. We require your personal information in order to enable us to manage and carry out our operations as a business. |
To improve the quality of the Website and your dining experience. |
Legitimate interests. We require your personal information to enhance, modify and personalise the Website and your dining experience for your benefit. |
To perform any contract entered into with you to fulfil your orders for food and drink and the process payment for those orders. |
Legitimate interests. We require your personal information in order to enable us to manage and carry out our operations as a business. Necessary to enter into or perform a contract we have with you. |
To comply with any legal or regulatory obligations (including in connection with a court order). |
Necessary for compliance with a legal obligation to which we are subject. |
To engage with you via social media. |
Legitimate interests. We require your personal information in order to enable us to manage and carry out our operations as a business. Consent. |
To analyse and improve our products to evaluate and develop our business. |
Legitimate interests. We require your personal information in order to enable us to manage and carry out our operations as a business. |
To protect against fraud or other criminal activity, as well as dealing with Government authorities/law enforcement agencies. |
Necessary for compliance with a legal obligation to which we are subject. Legitimate interests. We require your personal information in order to enable us to manage and carry out our operations as a business. |
To provide you with access to free Wi-Fi in our stores. |
Legitimate Interests. We require your personal information in order to enable us to provide you with a convenient and pleasurable experience in our stores and to enable us to manage and carry out our operations as a business. |
We may share your personal information with:
Type of third party |
Examples |
General |
|
Our group companies |
Other companies and entities that are part of the Five Guys Group. |
Our service providers |
Our business partners, suppliers and sub-contractors for the performance of any contract we enter into with you for example:
A current list of these third party service providers with whom we share your personal information can be provided to you on application to the Legal Department at legal@fiveguys.nl. |
Our professional advisers |
Including accountants, lawyers and other professional advisers that assist us in carrying out our business activities, a current list of these third parties can be provided to you on application to the Legal Department at legal@fiveguys.nl. |
Our franchisees |
These are individuals or organisations who enter into an agreement with us to operate a FIVE GUYS® Restaurant under the Five Guys brand in various jurisdictions all over the world. Your personal information will not be shared with all of our franchisees but only those that are relevant to you. |
Social media related parties |
We have different social media related parties for each area of the world in which we operate – your personal information may be shared with the social media related parties in our area but not all. A list of our current social media related parties and the countries in which they operate is set out below:
|
We may also disclose your personal information to other third parties, for example:
Where we act as an independent controller of your personal information we will use your personal information for our own purposes. Sometimes franchisees, third parties and other companies in the Five Guys group will act as controllers of your personal information that we collect. This is where they determine the purposes and means of processing your personal information. They will use your personal information for their own legitimate purposes as described in their respective privacy notices. Please refer to their individual privacy notices for full information about how they collect and process your personal information. The privacy notices for our other group companies can be accessed via the applicable Five Guys websites.
We will process your personal information both within and outside the European Economic Area (EEA) (this includes Bahrain, Kuwait, Oman, Qatar, the United Arab Emirates, Hong Kong and the United States of America, as amended from time to time).
When we transfer personal information outside the EEA, we will implement appropriate and suitable safeguards to ensure that such data will be protected as required by applicable data protection law, for example we will seek to anonymise it. If we can't anonymise your personal information, we will take reasonable steps to ensure that your personal information is protected. To do this we may use a set of standard data protection clauses which have been approved by the European Commission in accordance with Article 46 of the GDPR. For further information as to the safeguards we implement and to obtain a copy please contact the Legal Department at legal@fiveguys.nl.
We will retain your personal information for no longer than is necessary for the purposes for which the personal information are processed. The length of time we hold on to your personal information will vary according to what that information is and the reason for which it is being processed.
To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means. We also consider any applicable legal, regulatory, tax, accounting or other requirements which may specify how long we should retain your personal information for.
Subject to the above, personal information about our customers will be retained by us for seven years from, the date of your communication with us to allow us to:
For further information on our policy and how long we will keep your information for, please contact the Legal Department at legal@fiveguys.nl or by one of the other means of communication set out in the How to Contact Us section below.
We have put in place appropriate security measures to seek to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality. Details of these measures may be obtained from the Legal Department at legal@fiveguys.nl.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
The rights below are rights that apply under the EU General Data Protection Regulation and so will predominantly apply if your personal data is used by an entity established in the EEA. Therefore, the rights may not apply to everyone who reads or receives this policy. The rights may only apply in certain circumstances and are subject to certain exemptions. Please see the table below for a summary of your rights. You can exercise these rights using the contact details below.
Summary of your rights |
|
Right of access to your personal information |
You have the right to receive a copy of your personal information that we hold about you, subject to certain exemptions. We may require further information in order to respond to your request (for instance, evidence of your identity and information to enable us to locate the specific personal information you require). |
Right to rectify your personal information |
You have the right to ask us to correct your personal information that we hold where it is incorrect or incomplete. |
Right to erasure of your personal information: |
You have the right to ask that your personal information be deleted in certain circumstances. For example:
|
Right to restrict the use of your personal information |
You have the right to suspend our use of your personal information in certain circumstances. For example:
|
Right to data portability |
You have the right to obtain your personal information in a structured, commonly used and machine-readable format and for it to be transferred to another organisation, where it is technically feasible. The right only applies:
|
Right to object to the use of your personal information (including to object to direct marketing, automated decision making and profiling) |
You have the right to object to the use of your personal information in certain circumstances and subject to certain exemptions. Examples of this right include;
|
Right to withdraw consent |
You have the right to withdraw your consent at any time where we rely on consent to use your personal information. |
Right to complain to the relevant data protection authority |
You have the right to complain to the relevant Data Protection Authority where you think we have not used your personal information in accordance with data protection law. This will depend on factors such as which FIVE GUYS® Restaurant you visited and the country in which it is located, where you work or reside, or where the infringement occurred. Please see the list of Data Protection Authorities set out in Annex 1 to this Notice for details of the Data Protection Authorities which may be relevant in the event that you have a complaint. |
If you think there is a problem with how your personal information is being handled, please contact us by using the details set out in the How to Contact Us section below.
You also have a right to complain to the Data Protection Authority as specified in the table immediately above. Annex 1 attached to this Notice contains a list of all the Data Protection Authorities in the jurisdictions where Five Guys has its operations as at the date of this Policy. However, there may be other Data Protection Authorities that are relevant to you. Please get in touch using the How to Contact us section below if you require further information.
We will review this Privacy Policy regularly and we reserve the right to make any changes at any time to take account of changes in our business activities and legal requirements and the manner in which we process personal information.
Any changes we make to this Privacy Policy in the future will be posted on the applicable Website.
If you have any questions regarding this Privacy Policy or the way we use your personal information (outside of the USA and Canada), you can contact us by e-mail to the Legal Department at legal@fiveguys.nl, or by mail to:
Attention: Legal Department
Piet Heinkade 55
1019GM Amsterdam, the Netherlands.
This Privacy Policy was last updated in August 2020.
Annex 1
(Data Protection Authorities (DPA))
Country |
DPA |
Belgium |
Commision de la protection de la vie privée Commissie voor de bescherming van de persoonlijke levenssfeer Rue de la Presse 35 / Drukpersstraat 35 |
France |
Commission Nationale de I'Informatique et deds Libertés – CNIL 8 Rue Vivienne, CS 30223 |
Germany |
Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit Husarenstraße 30 |
Ireland |
Data Protection Commissioner Canal House |
Italy |
Garante per la protezione del dati personali Piazza du Monste Citorio, 121 |
Luxembourg |
Commission Nationale pour la Protection des Données 1, avenue du Rock 'n' Troll |
Netherlands |
Autoriteit Persoonsgegevens Prins Clauslaan 60 |
Portugal |
Comissão Nacional de Protecção de Dados – CNPD R. de São, Bento, 148-3° |
Spain |
Agencia de Protección de Datos C/Jorge Juan, 6 |
Switzerland |
Data Protection and Information Commissioner of Switzerland |
UK |
The Information Commissioner's Office Water Land, Wycliffe House |
In this Franchisee Privacy Policy (Privacy Policy):
This Privacy Policy (together with any agreements entered into between Five Guys and the organisation you are employed or engaged by), sets out the basis on which we collect and use personal information about you in connection with an application to operate or operation of a Five Guys Franchise.
This Privacy Policy describes:
This is to make sure you have a full picture of how we collect and use your personal information.
In this Privacy Policy where we use the words personal information we use these words to describe information that is about you and other individuals (for example, your business referees whose names and contact details are provided in relation to your application to operate a Five Guys Franchise) and is information which identifies you or them.
You have the right to object to our use of your personal information in certain circumstances. A summary of your right to object (along with your other rights under data protection law) and details of who to contact if you want to exercise these rights can be found at the How to Contact us section below. For further information on your rights see the Your rights section below.
For the purpose of data protection law, we are the controller in respect of your personal information collected and used in connection with an application to operate, or the operation of, a Five Guys Franchise. This is because we dictate the purpose for which your personal information is used and how we use your personal information.
The personal information that we hold about you may include the following:
Type of Personal Information |
Examples |
General |
|
Contact information. |
Name, address, email address, telephone number and job title. |
Communications between you and Five Guys. |
Communications between you and us in relation to a Five Guys Franchise. |
Details of your expertise. |
Details relating to your skills and expertise, previous work experience and qualifications and details included in your application to operate a Five Guys Franchise. |
Telephone recordings. |
Recordings of telephone calls with our representatives and call centres. |
CCTV recordings. |
CCTV recordings captured by equipment on our premises. The personal information is available for up to 28 days after our external IT company, ComputerHulp logs in to access the recordings. The data will be automatically deleted after this time period. |
Financial |
|
Credit checks. |
We may ask a third party to carry out credit background identity checks about you. |
Financial information from all financial institutions holding funds or property on your behalf (to the extent that this constitutes personal information). |
Records, statements and all documentation showing the source of any deposited sums. |
Financial information and account details (to the extent that this constitutes personal information). |
Bank account number, or other financial details so that we can make payments to you pursuant to the terms of the contract between you and Five Guys. |
In the course of your involvement, engagement and interaction with us you may provide us with personal information relating to third parties.
We will use this personal information in accordance with this Privacy Policy. If you are providing personal information to us relating to a third party, you confirm that you have the consent of the third party to share such personal information with us and that you have made the information in this Privacy Policy available to the third party.
When you (as a sole trader or as a partner in a partnership) apply for a Five Guys Franchise, we use an automated system known as the Online Franchise Form to determine your eligibility to operate a Five Guys Franchise. This is a method of assessing potential franchise opportunities. This system enables us to make fair and informed decisions on whether you are assessed as an appropriate candidate to apply for a Five Guys Franchise.
Some of these decisions do not involve human input and the systems apply pre-defined logic programming and criteria to make a decision. For example, we use information about your capital availability, and capital source (such as your cash reserves, bank funding, private equity or other funding available to you). This information is analysed by automated means which uses statistical models and rule based systems to evaluate your credit worthiness, affordability and overall financial health.
We use your personal information for a variety of different purposes. In particular, your personal information may be used by us, our employees, service providers, and disclosed to third parties for the purposes set out in the table below. For each of these purposes, we have set out the legal basis upon which we rely in order to use your personal information.
Under data protection law, we can only use your personal information if we have a legal basis to do so. Examples of where we have a legal basis to process your personal information, includes when:
We must tell you which legal basis we are relying on when we use your personal information. The legal basis we rely on is set out below together with the purposes that we use your personal information for.
Purpose |
Legal Basis |
To communicate with you in relation to our dealings with you. |
Legitimate interests: We require your personal information in order to enable us to assess any application to operate a Five Guys Franchise with us, during the operation of the Five Guys Franchise, to operate our business and for the purposes of furthering our business. Performance of a contract we have with you. This will only be applicable if you are personally entering into a franchise agreement as a sole trader or as a partner in a partnership. |
To assess any application for a Five Guys Franchise and decide whether the application is successful. |
Legitimate interests: We require your personal information in order to process and assess an application to operate a Five Guys Franchise and to enable us to manage and carry out our operations as a business. Necessary to enter into or perform a contract we have with you. This will only be applicable if you are a sole trade or a partner in a partnership |
To carry out our obligations arising from the relevant franchise agreement. |
Legitimate interests: It is in our legitimate interest to comply with the terms of the franchise agreement we have in place. Performance of a contract we have with you. This will only be applicable if you are a sole trader or a partner in a partnership. |
To receive payments from you. |
Performance of a contract we have with you. This will only be applicable if you are a sole trader or a partner in a partnership. Legitimate interests: It is in our legitimate interest to comply with the terms of the franchise agreement we have in place. |
To manage any service or quality related issues, complaints, feedback and queries in relation to the operation of the Five Guys Franchise. |
Legitimate interests: We require your personal information in order to ensure the Five Guys Franchise operated to the high standards required by us and to enable us to manage and carry out our operations as a business. Performance of a contract we have with you. This will only be applicable if you are a sole trader or as a partner in a partnership. |
To comply with any legal or regulatory obligations (including in connection with a court order). |
Necessary for compliance with a legal obligation to which we are subject. |
CCTV recordings to prevent and detect crime. |
Legitimate interests: We require your personal information in order to protect your business against unlawful activity. |
To inspect and electronically monitor all information generated by you in the operation of the Franchise as may be contained or stored in the central Five Guys IT systems. |
Legitimate interests: We require your personal information in order to ensure that the highest degree of quality and service is maintained in the Five Guys restaurant that you are operating under the terms of the Franchise Agreement, and to ensure the restaurant is operated in strict conformity with such methods and standards as are required by Five Guys. |
We may be required to obtain your personal information to comply with our legal requirements, to enable us to fulfil the terms of any franchise agreement or in preparation of us entering into a franchise agreement. If you do not provide the relevant personal information to us, we may not be able to perform our obligations pursuant to your contract with us or process any application to operate a Five Guys Franchise.
We may share your personal information with:
Type of third party |
Examples |
General |
|
Our group companies. |
Other companies and entities that are part of the Five Guys Group. |
Our service providers. |
Our business partners, suppliers and sub-contractors in relation to the assessment of an application for a Five Guys Franchise, for example:
A current list of these third party service providers with whom we share your personal information can be provided to you on application to the Legal Department at legal@fiveguys.nl. |
Our professional advisers. |
Including accountants, lawyers and other professional advisers that assist us in carrying out our business activities, a current list of these third parties can be provided to you on application to the Legal Department at legal@fiveguys.nl. |
Reference checking agencies who undertake certain checks on our behalf about you. |
This may include credit reference checks and details of any judgements entered against you, for the purpose of assessing an application to operate a Five Guys Franchise. We share your name and current address with such reference checking agencies, who will then contact you directly to undertake such checks. |
Government authorities and third parties involved in court action. |
External agencies and organisations (including the police, the relevant local authority depending on where you are resident, relevant EEA Visas and Immigration departments, the Dutch State Secretary for Justice and Security and other law enforcement agencies) for the purpose of complying with applicable legal and regulatory obligations. For a full list of third parties with whom your particular personal information may be shared, please contact the Legal Department at legal@fiveguys.nl. |
We may also disclose your personal information to other third parties, for example:
We will process your personal information both within and outside the European Economic Area (EEA) (inter alia in the United Arab Emirates, Hong Kong and the United States of America, as amended from time to time).
When we transfer personal information outside the (EEA), we will implement appropriate and suitable safeguards to ensure that such data will be protected as required by applicable data protection law, for example we will seek to anonymise it. If we can't anonymise your personal information, we will take reasonable steps to ensure that your personal information is protected. To do this we may use a set of standard data protection clauses which have been approved by the European Commission in accordance with Article 46 of the General Data Protection Regulation. For further information as to the safeguards we implement and to obtain a copy please contact the Legal Department at legal@fiveguys.nl.
We will retain your personal information for no longer than is necessary for the purposes for which the personal information are processed. The length of time we hold on to your personal information will vary according to what that information is and the reason for which it is being processed.
To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements which may specify how long we should retain your personal information for.
We will keep your personal information for the duration of our contract with our franchise agreement and for a period of six years after that contract is terminated.
If an application to operate a Five Guys Franchise is submitted and is unsuccessful, we will only retain your personal information for a period of two years from the date that you or the applicant are notified that the application was unsuccessful.
For further information on our policy and how long we will keep your information for, please contact the Legal Department at legal@fiveguys.nl or by one of the other means of communication set out in the How to Contact Us section below.
We have put in place appropriate security measures to seek to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality. Details of these measures may be obtained from the Legal Department at legal@fiveguys.nl.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
The rights below are rights that apply under the EU General Data Protection Regulation and so will predominantly apply if your personal data is used by an entity established in the EEA. Therefore, the rights may not apply to everyone who receives this policy. The rights may only apply in certain circumstances and are subject to certain exemptions. Please see the table below for a summary of your rights. You can exercise these rights using the contact details below.
Your rights |
Summary of your rights |
Right of access to your personal information |
You have the right to receive a copy of your personal information that we hold about you, subject to certain exemptions. We may require further information in order to respond to your request (for instance, evidence of your identity and information to enable us to locate the specific personal information you require). |
Right to rectify your personal information |
You have the right to ask us to correct your personal information that we hold where it is incorrect or incomplete. |
Right to erasure of your personal information |
You have the right to ask that your personal information be deleted in certain circumstances. For example:
|
Right to restrict the use of your personal information |
You have the right to suspend our use of your personal information in certain circumstances. For example:
|
Right to data portability |
You have the right to obtain your personal information in a structured, commonly used and machine-readable format and for it to be transferred to another organisation, where it is technically feasible. The right only applies:
|
Right to object to the use of your personal information (including to object to direct marketing, automated decision making and profiling) |
You have the right to object to the use of your personal information in certain circumstances and subject to certain exemptions. Examples of this right include;
|
Right to withdraw consent |
You have the right to withdraw your consent at any time where we rely on consent to use your personal information. |
Right to complain to the relevant data protection authority |
You have the right to complain to the relevant Data Protection Authority where you think we have not used your personal information in accordance with data protection law. This will depend on factors such as which Five Guys entity you are dealing with and where they are located, where the Five Guys Franchise is located, where you reside, or where the infringement occurred. Please see the list of Data Protection Authorities set out in the Annex to this Notice for details of the Data Protection Authorities which may be relevant in the event that you have a complaint. |
If you think there is a problem with how your personal information is being handled, please contact us by using the details set out in the How to Contact Us section below.
You also have a right to complain to the Data Protection Authority in either the place you work, the place you live or the place the infringement occurred. The Annex attached to this Notice contains a list of all the Data Protection Authorities in the jurisdictions where Five Guys has its operations as at the date of this Policy. However, there may be other Data Protection Authorities that are relevant to you. Please refer to this Annex for further details of the Data Protection Authorities that are relevant to you. Please get in touch using the How to Contact us section below if you require further information.
We will review this Privacy Policy regularly and we reserve the right to make any changes at any time to take account of changes in our business activities and legal requirements and the manner in which we process personal information.
Any changes we make to this Privacy Policy in the future will be posted on the "Five Guys Patty Press" and, where appropriate, we will give reasonable advance notice of any changes to you by e-mail.
For all queries or issues relating to the collection or processing of your personal information by us If you have any questions regarding this Privacy Policy or the way we use your personal information (outside of the USA and Canada), you can contact us by e-mail or telephone to the Legal Department at legal@fiveguys.nl, or by mail to:
Attention: Legal
Piet Heinkade 55
1019GM Amsterdam, the Netherlands.
This Privacy Policy was last updated in August 2018.
Annex 1
(Data Protection Authorities (DPA))
Country |
DPA |
Belgium |
Commision de la protection de la vie privée Commissie voor de bescherming van de persoonlijke levenssfeer Rue de la Presse 35 / Drukpersstraat 35 |
France |
Commission Nationale de I'Informatique et deds Libertés – CNIL 8 Rue Vivienne, CS 30223 |
Germany |
Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit Husarenstraße 30 |
Ireland |
Data Protection Commissioner Canal House |
Italy |
Garante per la protezione del dati personali Piazza du Monste Citorio, 121 |
Luxembourg |
Commission Nationale pour la Protection des Données 1, avenue du Rock 'n' Troll |
Netherlands |
Autoriteit Persoonsgegevens Prins Clauslaan 60 |
Portugal |
Comissão Nacional de Protecção de Dados – CNPD R. de São, Bento, 148-3° |
Spain |
Agencia de Protección de Datos C/Jorge Juan, 6 |
Switzerland |
Data Protection and Information Commissioner of Switzerland |
UK |
The Information Commissioner's Office Water Land, Wycliffe House |
In this Supplier Privacy Policy (Privacy Policy):
This Privacy Policy (together with your terms of engagement or contract with us, and any other documents referred to in your terms of engagement or contract with us), sets out the basis on which we collect and use personal information about you when you or a Supplier supply us with goods or services.
This Privacy Policy describes:
This is to make sure you have a full picture of how we collect and use your personal information.
In this Privacy Policy where we use the words personal information we use these words to describe information that is about you and is information which identifies you.
You have the right to object to our use of your personal information in certain circumstances. A summary of your right to object (along with your other rights under data protection law) and details of who to contact if you want to exercise this right can be found at the How to Contact us section below. For further information on your rights see the Your rights section below.
For the purpose of data protection law, we are the data controller in respect of your personal information collected and used in connection with the provision by you or the Supplier of goods or services. This is because we dictate the purpose for which your personal information is used and how we use your personal information.
In the course of the receipt by us of goods and services from you or the Supplier we collect and use personal information about you.
Information that we hold about you
The information that we hold about you may include the following:
Type of Personal Information |
Examples |
General |
|
Contact information. |
Name, address, email address, telephone number and job title. |
Communications between you and Five Guys. |
Communications between you and Five Guys in relation to the goods or services supplied to us and the respective obligations of the parties to the contract. |
Details of your expertise. |
Details relating to your skills and expertise, previous work experience and qualifications and details included in any pitch or tender response that you or the Supplier submit to us. |
Telephone recordings. |
Recordings of telephone calls with our representatives and call centres. |
Photographs and video recordings. |
Images (including photographs and pictures) or video recordings created in connection with our activities, as well as CCTV recordings captured by equipment on our premises. |
Financial |
|
Financial information and account details |
Bank account number, or other financial account number and account details in order that we can make payments to you pursuant to the terms of the contract between you and Five Guys. |
We also collect information from other third party and publicly available sources such as Facebook, Instagram, LinkedIn, Snapchat or Twitter (or any other equivalent sources).
We may also collect certain sensitive personal information from you (including any special categories of personal data). Where we do so we will rely on your explicit consent or we will notify you if we can rely on a different legal basis for processing this type of information.
In the course of the provision of goods or services to us you may provide us with personal information relating to third parties such as your subcontractors.
We will use this personal information in accordance with this Privacy Policy. If you are providing personal information to us relating to a third party, you confirm that you have the consent of the third party to share such personal information with us and that you have made the information in this Privacy Policy available to the third party.
We use your personal information for a variety of different purposes during the course of your provision of goods or services to us. In particular, your personal information may be used by us, our employees, service providers, and disclosed to third parties for the purposes set out in the table below. For each of these purposes, we have set out the legal basis upon which we rely in order to use your personal information. This is because, under data protection law, we can only use your personal information if we have a legal basis to do so.
Examples of where we have a legal basis to process your personal information, includes when:
We must tell you which legal basis we are relying on when we use your personal information. The legal basis we rely on is set out below together with the purposes that we use your personal information for.
Purpose |
Legal Basis |
To communicate with you in relation to our dealings with you. |
Legitimate interests: We require your personal information in order to enable us to purchase the goods or services we need for the purposes of furthering our business. Performance of a contract we have with you. This will only be applicable if you are a sole trader who is providing us with goods or services. |
To make payments to you. |
Legitimate interests: It is in our legitimate interest to comply with the terms of a contract we have in place with you or a Supplier. Performance of a contract we have with you. This will only be applicable if you are a sole trader who is providing us with goods or services. Necessary for compliance with a legal obligation to which we are subject. |
To assess any tender response and decide whether your response is sufficient. |
Legitimate interests: We require your personal information in order to process and assess your tender response to provide services to us and to enable us to manage and carry out our operations as a business. Necessary to enter into or perform a contract we have with you. This will only be applicable if you are a sole trader. |
To carry out our obligations arising from our contract with you or the Supplier. |
Legitimate interests: It is in our legitimate interest to comply with the terms of a contract we have in place with you or a Supplier. Performance of a contract we have with you. This will only be applicable if you are a sole trader. |
To manage any service or quality related issues, complaints, feedback and queries in relation to the supply of goods or services in accordance with the terms of the supply contract. |
Legitimate interests: We require your personal information in order to ensure the goods or services we receive are fit for purpose and meet the needs of our organisation. Performance of a contract we have with you. This will only be applicable if you are a sole trader. |
To comply with any legal or regulatory obligations (including in connection with a court order). |
Necessary for compliance with a legal obligation to which we are subject. |
CCTV recordings captured by equipment on our premises to manage any complaints that you may have or that we may have in relation to your performance of the supplier contract. |
Legitimate interests: We require your personal information in order to manage your work activities. |
To maintain internal compliance and audit records. |
Legitimate interests. We require your personal information in order to ensure we manage and carry out our business operations in the best interests of our shareholders and customers. |
You agree that we may share your personal information with:
Type of third party |
Examples |
General |
|
Our group companies |
Other companies and entities that are part of the Five Guys Group. |
Our service providers |
Our business partners, suppliers and sub-contractors for the performance of any contract we enter into with you for example:
A current list of these third party service providers with whom we share your personal information can be provided to you on application to the Legal Department at legal@fiveguys.nl. |
Our professional advisers |
Including accountants, lawyers and other professional advisers that assist us in carrying out our business activities, a current list of these third parties can be provided to you on application to the Legal Department at legal@fiveguys.nl. |
Government authorities and third parties involved in court action |
External agencies and organisations (including the police and other law enforcement agencies) for the purpose of complying with applicable legal and regulatory obligations. For a full list of third parties with whom your particular personal information may be shared, please contact the Legal Department at legal@fiveguys.nl. |
Our franchisees |
These are individuals or organisations who enter into an agreement with us to operate a restaurant under the Five Guys brand in various jurisdictions worldwide. Your personal information will not be shared with all of our franchisees but only those that are relevant to you. |
We may also disclose your personal information to other third parties, for example:
We will process your personal information both within and outside the European Economic Area (EEA) (this includes Bahrain, Kuwait, Oman, Qatar, the United Arab Emirates, Hong Kong and the United States of America, as amended from time to time).
When we transfer personal information outside the EEA, we will implement appropriate and suitable safeguards to ensure that such data will be protected as required by applicable data protection law, for example we will seek to anonymise it. If we can't anonymise your personal information, we will take reasonable steps to ensure that your personal information is protected. To do this we may use a set of standard data protection clauses which have been approved by the European Commission in accordance with Article 46 of the GDPR. For further information as to the safeguards we implement and to obtain a copy please contact the Legal Department at legal@fiveguys.nl.
We will retain your personal information for no longer than is necessary for the purposes for which the personal information are processed. The length of time we hold on to your personal information will vary according to what that information is and the reason for which it is being processed.
To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means. We also consider any applicable legal, regulatory, tax, accounting or other requirements which may specify how long we should retain your personal information for.
Subject to the above, we will keep your personal information for the duration of our contract with you or the Supplier and for a period of seven years after that contract is terminated.
If you or the Supplier submits a tender response to us and this is unsuccessful we will only retain your personal information for such period as is in our reasonable business interests from the date that you or the Supplier are notified that the submission was unsuccessful. For further information on our policy and how long we will keep your personal information for, please contact the Legal Department at legal@fiveguys.nl or by one of the other means of communication set out in the How to Contact Us section below.
We have put in place appropriate security measures to seek to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality. Details of these measures may be obtained from the Legal Department at legal@fiveguys.nl.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
The rights below are rights that apply under the EU General Data Protection Regulation and so will predominantly apply if your personal data is used by an entity established in the EEA. Therefore, the rights may not apply to everyone who reads or receives this policy. The rights may only apply in certain circumstances and are subject to certain exemptions. Please see the table below for a summary of your rights. You can exercise these rights using the contact details below.
Summary of your rights |
|
Right of access to your personal information |
You have the right to receive a copy of your personal information that we hold about you, subject to certain exemptions. We may require further information in order to respond to your request (for instance, evidence of your identity and information to enable us to locate the specific personal information you require). |
Right to rectify your personal information |
You have the right to ask us to correct your personal information that we hold where it is incorrect or incomplete. |
Right to erasure of your personal information: |
You have the right to ask that your personal information be deleted in certain circumstances. For example:
|
Right to restrict the use of your personal information |
You have the right to suspend our use of your personal information in certain circumstances. For example:
|
Right to data portability |
You have the right to obtain your personal information in a structured, commonly used and machine-readable format and for it to be transferred to another organisation, where it is technically feasible. The right only applies:
|
Right to object to the use of your personal information (including to object to direct marketing, automated decision making and profiling) |
You have the right to object to the use of your personal information in certain circumstances and subject to certain exemptions. Examples of this right include;
|
Right to withdraw consent |
You have the right to withdraw your consent at any time where we rely on consent to use your personal information. |
Right to complain to the relevant data protection authority |
You have the right to complain to the relevant Data Protection Authority, where you think we have not used your personal information in accordance with data protection law. This will depend on factors such as which Five Guys entity you are dealing with and the country in which it is located, where you reside or where the infringement occurred. Please see the list of Data Protection Authorities set out in Annex 1 to this Notice for details of the .Data Protection Authorities which may be relevant in the event that you have a complaint. |
If you think there is a problem with how your personal information is being handled, please contact us by using the details set out in the How to Contact Us section below.
You also have a right to complain to the Data Protection Authority in either the place you work, the place you live or the place the infringement occurred. Annex 1 attached to this Notice contains a list of all the Data Protection Authorities in the jurisdictions where Five Guys has its operations as at the date of this Policy. However, there may be other Data Protection Authorities that are relevant to you. Please get in touch using the How to Contact us section below if you require further information.
We will review this Privacy Policy regularly and we reserve the right to make any changes at any time to take account of changes in our business activities and legal requirements and the manner in which we process personal information.
Any changes we make to this Privacy Policy in the future will be posted on the “Five Guys Patty Press” and, where appropriate, we will give you reasonable advance notice of any changes to you by email.
If you have any questions regarding this Privacy Policy or the way we use your personal information (outside of the USA and Canada), you can contact us by e-mail to the Legal Department at legal@fiveguys.nl, or by mail to:
Attention: Legal Department
Piet Heinkade 55
1019GM Amsterdam, the Netherlands.
This Privacy Policy was last updated in August 2018.
Annex 1
(Data Protection Authorities (DPA))
Country |
DPA |
Belgium |
Commision de la protection de la vie privée Commissie voor de bescherming van de persoonlijke levenssfeer Rue de la Presse 35 / Drukpersstraat 35 |
France |
Commission Nationale de I'Informatique et deds Libertés – CNIL 8 Rue Vivienne, CS 30223 |
Germany |
Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit Husarenstraße 30 |
Ireland |
Data Protection Commissioner Canal House |
Italy |
Garante per la protezione del dati personali Piazza du Monste Citorio, 121 |
Luxembourg |
Commission Nationale pour la Protection des Données 1, avenue du Rock 'n' Troll |
Netherlands |
Autoriteit Persoonsgegevens Prins Clauslaan 60 |
Portugal |
Comissão Nacional de Protecção de Dados – CNPD R. de São, Bento, 148-3° |
Spain |
Agencia de Protección de Datos C/Jorge Juan, 6 |
Switzerland |
Data Protection and Information Commissioner of Switzerland |
UK |
The Information Commissioner's Office Water Land, Wycliffe House |
Document Description |
The Five Guys Group Data Protection Policy |
||
Version |
2.0 |
||
Date Created |
May 2018 |
||
Status |
Final |
||
Document Owner |
|||
Authorisation |
Name |
Signature |
Date |
Prepared By: |
|||
Checked By |
Version number |
Date |
Author |
Reason for New Version |
1.0 |
May 2018 |
Initial draft |
|
1.1 |
July 2018 |
Revised draft |
|
1.2 |
3 August 2018 |
Revised draft |
|
1.3 |
22 August 2018 |
Final draft |
Date last reviewed: August 2018
Date of next review: August 2019
PURPOSE AND SCOPE OF THE POLICY
DEFINITIONS
In this Policy, the following words have the meanings set out below:
Data Controller – means the person or organisation that determines when, why and how to process Personal Data. It is responsible for establishing practices and policies in line with the GDPR. For example, each Five Guys Group company will be the Data Controller of the Personal Data about its employees.
Data Processors – means an organisation that processes Personal Data on behalf of a Data Controller in accordance with the Data Controller's instructions. The Five Guys Group may use a Data Processor to Process Personal Data on its behalf, for example TMF Netherlands B.V. who provide payroll and human resources services to us.
Five Guys Group means FGE International B.V., a private limited liability company, incorporated under the laws of the Netherlands, having its office address at Piet Heinkade 55, 1019 GM Amsterdam, The Netherlands and registered with the Trade Register under number 61334790, together with its subsidiaries, parent and its affiliated entities (collectively, Five Guys). More information on the Five Guys Group can be requested by contacting the Legal Department at legal@fiveguys.nl.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed. For example, sending an e-mail containing Personal Data of a Five Guys Group employee, including their remuneration details, to a third party that is not entitled to see it. Please see the Security Breach Notification and Reporting Policy for further details.
Data Subject means a living, identified or identifiable individual about whom we hold Personal Data. Data Subjects may be nationals or residents of any country and may have legal rights regarding their Personal Data.
Personal Data means any information about an individual which identifies them. A person does not need to be named in a document for the document to include Personal Data. If it is obvious from the document who the information relates to, this is enough to constitute Personal Data. Similarly, if it is obvious who the document is about when it is used in conjunction with other information held, this will also be enough to constitute Personal Data. Personal Data might include: a name; e-mail address; date of birth; an ID number; location data, an online identifier; or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or an opinion about an individual.
Process(ing) means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Special Category Personal Data means Personal Data revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data, and Personal Data relating to criminal offences and convictions.
Website means the websites found at:
DATA PROTECTION PRINCIPLES
FAIR AND LAWFUL PROCESSING
SPECIFIED PURPOSE
DATA MINIMISATION
ACCURACY
KEPT FOR NO LONGER THAN IS NECESSARY
SECURITY
PERSONAL DATA BREACHES
TRANSFER OF PERSONAL DATA OUTSIDE OF THE EEA
RIGHTS OF DATA SUBJECTS
ACCOUNTABILITY
PRIVACY BY DESIGN AND DATA PROTECTION IMPACT ASSESSMENT (DPIA)
DIRECT MARKETING
SHARING PERSONAL DATA
COMPLAINTS
CONSEQUENCES OF FAILING TO COMPLY WITH THIS POLICY
REVIEW AND CHANGES TO THE POLICY
An Information Governance Framework establishes the Five Guys Group's approach to handling and protecting the data it Processes, known as information governance. The Framework is made up of policies, procedures and guidance documents to help Personnel comply with our regulatory and legal obligations to protect Personal Data, both electronic and paper.
The documents that form part of the Five Guys Group's Information Governance Framework include: