Privacy Policy
Privileged & Confidential Hogan Lovells DRAFT
Attorney-Client Communication February 19, 2024
Privacy Notice
Table of Contents
- Our Commitment To Privacy
- Important Information:
- What Information Do We Collect and How Do We Collect It?
- How Do We Use Your Personal Data?
- Opting Out:
- Data Security:
- Data Retention:
- We May Share Your Personal Data:
- Transferring Personal Data Globally
- Use of Cookies and Other Tracking Technologies
- Your Rights in Relation to Your Personal Data:
- Changes to This Privacy Notice
- Contact Information
California residents: See “10.3 Additional State Disclosures” for additional information about your personal information and privacy rights under California law.
Welcome to the SodaStream USA, Inc. ("SodaStream,” “us,” and/or “we”) website. Below you will find our Privacy Notice regarding the personal information we collect about users of our Services.
You may download a printable copy of this Privacy Notice (PDF): here.
1. Our Commitment To Privacy
1.1 We provide this notice (“Privacy Notice”) to explain our information practices and the choices you can make about the way your information is collected and used in connection with our digital properties that link to this Privacy Notice, including our websites (the “Site”, “our website” or “this website”) and our other products and services (collectively with our websites, the “Services”). The purpose of this Privacy Notice is to describe the types of personal information we collect, when, why and how we collect, use and disclose your personal information, and your rights under applicable law. This Privacy Notice is not intended to override the terms of any contract you have with us, nor any rights you might have under applicable data privacy laws.
1.2 We strongly urge you read this Privacy Notice and make sure you fully understand our practices in relation to personal information, before you access or use our Services. If you read and fully understand this Privacy Notice, but remain opposed to our practices, you must immediately leave our website, and avoid or discontinue all use of our Services. Where you have read this Privacy Notice but would like further clarification, please contact us at privacy@sodastream.com.
1.3 By accessing our Services, you acknowledge and agree that your personal information will be handled as described in this Privacy Notice. Your use of the Services, and any dispute over privacy is subject to this Privacy Notice and our Terms and Conditions, including its applicable limitations of liability and the resolution of disputes.
2. General Information:
2.1 Children. We do not knowingly collect or maintain information from those under the age of 16, and no part of our Services is designed for users under the age of 16. Parents and guardians should supervise their children’s activities at all times. If we learn we have collected or received personal information from a person under the age of 16, we will delete that information. If you believe we might have any information from or about a person under the age of 16, please contact us at privacy@sodastream.com.
2.2 Third-Party Links. Note that our website contains links to third party websites which we are not responsible for. These links are not an endorsement of, or representation that we are affiliated with, any third party. In addition, our content may be included on web pages or in mobile applications or other online services that are not associated with us. We do not control websites, mobile applications or online services operated by third parties, and we are not responsible for their information practices. Please review the privacy policies of such third party websites should you visit these websites. This Privacy Notice does not address the privacy or information practices of any third parties.
3. What Categories of Personal Information Do We Collect and How Do We Collect It?
3.1 Depending on your interaction with us, we may collect the following categories of personal information about you directly from you, automatically through your use of our Services, and from third parties:
- Identifiers, such as your name, email address, telephone number, mailing and billing address, date of birth, login credentials and passwords, IP address, device ID, unique online identifiers, or similar identifiers.
- Commercial information, such as your purchase, registration, log-in and Service usage history or other consuming histories or tendencies.
- Financial information, such as your financial account information, credit card number, debit card number, or other payment card information.
- Professional information, such as your occupation, employment history, professional contact information, or other information provided by you in connection with the Services.
- Internet or other electronic network activity, such as your browser type and operating system; browsing history, clickstream data, search history on the Services, and information regarding your interaction with an internet website, application, email, newsletter, or advertisement, including access logs and other activity information related to your use of our Services; the length of time you visit our Services; and the referring URL, or the website or application that led you to our Services.
- Audio, electronic, visual, or similar information, such as voice and video recordings of customer care calls.
- Geolocation data, such as the general physical location of your device.
- Protected classifications, such as your age or gender.
- Inferences, such as inferences drawn to create a profile reflecting your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes.
- Sensitive personal information, as defined under applicable local law, such as account login credentials and passwords, and financial account information, credit card number, debit card number, or other financial information.
3.2 Information We Collect Automatically. We, our service providers, and our business partners may automatically collect certain data about you, your computer or mobile device, your interactions over time with the Services, communications channels (including your interactions with chatbots on our Site), and other online services through cookies, pixel tags, clear GIFs, and similar technologies. This may include information such as your browser type, operating system, IP address, domain name, number of times you visited the website, dates you visited the website, date and time of an online request, the time required to download information you requested, error codes generated while your browser is in contact with our website, the amount of time you spent viewing the website and other session recordings and activity logs, and any other information described above as “Internet or other electronic network activity.” We explain more about our use of cookies and similar technologies in our section below regarding “Our Use of Cookies and Other Tracking Technologies” and our Cookie Notice.
3.3 Information We Collect Directly From You. We collect personal information directly from you when you use our Services. For example, if you register for an account, make a purchase, or contact us as an individual, we may collect information such as your name, date of birth, email address, telephone number, address information; gender, age, and information about your household or lifestyle information and your zip code, the consumption habits of you and members of your household, payment and credit card information, information to set up and access your SodaStream account, correspondence with us, any feedback on our products and services which you provide, and your customer support records and preferences, which may include any recordings and transcripts of your calls, recording of video calls, emails, form submissions, and chats with us for different purposes such as providing customer support, feedback, understanding our customer needs or training purposes, information that you voluntarily provide to us in response to market surveys we invite you to participate in, and other information that you choose to provide. If you register for an account, make a purchase, or contact us on behalf of a company, we will collect information such as company identification data, identification data from the company representative, company composition and consumption data, device data, payment data, login data, and other information that you choose to provide. If you create user generated content, we will collect information such as your posts, messages, ratings of our products, feedback, and other content that you can choose to upload to our forums or otherwise make available on the Services, as well as associated metadata.
3.4 Information We Collect Through Social Networks. If you engage with us through social media (e.g. Instagram, Facebook, Pinterest, YouTube, Twitter, Tik-Tok) we collect your affiliation with social media related to us and any personal information you voluntarily provide, such as opinions in blog or recipe entries or messages you post on our social media pages. If you upload content, including your personal information, to a social network and then tag our website, your submission will be subject to that social network's terms of use and privacy notice, even where you post on an official SodaStream page on the social network.
3.5 Information We Collect From Other Users. If you invite others to use the Services, for example by sending an invitation email from the Site to the recipient’s external email address, you will be providing us with personal information about the recipient, such as their email address or online account username. We will process such personal information to provide this interactive Service. You are responsible for ensuring that the recipient’s information is accurate, and you should only provide the information of a recipient with their consent.
3.6 Information We Collect From Other Sources. We may collect personal information about you from other sources, such as our service providers and business partners. We (and our service providers and third party business partners) may also combine personal information we receive from you with personal information we obtain from other sources, such as data enrichment providers, information services and data licensors.
4. How Do We Use Your Personal Information?
We may use the categories of your personal information described above for the following business and commercial purposes:
4.1 Service delivery:
We may use your personal information to:
- offer, operate and improve our products and/or Services and our business (e.g., validate your order or subscription);
- process your payment and complete transactions with you (e.g., of a monthly fee in the case of a subscription);
- provide the products and Services that you requested or ordered or to which you subscribed. We will also use your personal information for the handling and fulfilment of your orders;
- provide support for the Services, and respond to your requests, questions and feedback as well as to provide customer support;
- provide our customer management services, to maintain our relationship with you;
- verify your identity, establish and set up your account, verify or re-issue a password, log your activity or authenticate your access and use of the Services;
- communicate with you about the Services, including by sending announcements, updates, security alerts, and support and service messages.
4.2 Research and development:
We and our service providers may use your personal information for research and development purposes, including to improve our products, understand your interests, and to analyze and improve the Services and our business.
4.3 De-Identified data:
We may create aggregated, de-identified or other anonymous data from personal information we collect. We de-identify or anonymize your data in such a way that you may not reasonably be re-identified by us or another party by removing information that makes the data personally identifiable to you. We may use this anonymous data and disclose it to third parties for our lawful business purposes, including to analyze and improve the Services and promote our business.. To the extent we de-identify or anonymize any data originally based on personal information, we will maintain and use such data in de-identified form and will not attempt to reidentify the data.
4.4 Compliance and protection:
We may use your personal information where we believe necessary to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from law enforcement or government authorities;
- protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims);
- audit our internal processes for compliance with legal and contractual requirements or our internal policies; and
- enforce the terms and conditions that govern the Services and prevent, identify and investigate fraudulent, harmful, unauthorized activities, including cyberattacks and identity theft, and other inappropriate activities and monitor content integrity on our website.
4.5 Carrying out Marketing and Advertising:
We and our third-party advertising partners may use your personal information for direct marketing and advertising purposes:
- Direct marketing. We may for example send you emails to inform you of news and updates about our products and services. This may be in the form of email, post, SMS, or telephone. Where required by law, we will obtain your consent prior to sending you such marketing information.
- Interest-based advertising. We may engage third-party advertising and social media companies to display ads on the Services and on other online services. These companies may use cookies and similar technologies to collect information about you over time across the Services, our communications and other online services, and use that information to serve ads that they think will interest you and measure and improve the performance of the advertising campaigns. This is called interest-based advertising. We may also disclose information about our users with these companies to facilitate interest-based advertising to those or similar users on other online platforms. This may include tracking and storing interactions on websites, e.g., after you have clicked on an advertisement; tracking usage of the Services; storing and tracking audience reach and conversions; connecting information from the service provider’s advertising network with actions performed on the website; storing your preferences; building a profile of your interests to show you relevant and personalized advertisements; or listing advertisement on search engine websites based on recent searches.
5. Opting Out:
Marketing Communications. We may send periodic promotional communications to you. We will give you the opportunity to "opt out" of direct marketing when you contact us in relation to a product or service or you receive any email, text or other direct marketing communication.
You have a right to prevent direct marketing of any form at any time - this can be exercised by following the opt-out link attached to each communication, or by sending your request to privacy@sodastream.com. If you want to review or update the information you have provided us, you can click "my profile" at our website's home page and edit the information. If you have not been asked already to provide your email address and a password, we will ask you to do it before changes are made, so as to help prevent others from accessing and altering your personal information.
Push Notifications. We may send push notifications to your device. You can opt-out of push notifications at any time by adjusting your device settings. 5.2 You have a right to prevent direct marketing of any form at any time - this can be exercised by following the opt-out link attached to each communication, by changing privacy settings within your SodaStream account or by sending an email to privacy@sodastream.com. If you want to review or update the information you have provided us, you can click "my profile" at our website's home page and edit the information. If you have not been asked already to provide your email address and a password, we will ask you to do it before changes are made, so as to prevent others from accessing and altering your personal data.
6. Data Security:
6.1 We implement physical, technical, and organizational measures designed to safeguard personal information. These measures are aimed to protect the personal information we collect from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Please be aware that despite our efforts, no data security measures can guarantee security
7. Data Retention:
7.1 We may retain your data as long as necessary to provide our Services, and beyond such time to the extent legally permitted and based on our legal obligations (e.g. in relation to invoice retention) or legitimate interests (e.g. in retaining data for the purposes of responding to possible disputes or complaints or for possible reactivation of subscriptions).
7.2 In addition, we maintain a data retention policy which we apply to information in our care. Where your data is no longer required, we will ensure it is securely deleted or anonymized.
8. We May Disclose Your Personal Information:
SodaStream may disclose the categories of your personal information described above for our business and commercial purposes as follows:
- with our corporate parent, or other SodaStream affiliates and subsidiaries for the purposes mentioned in this Privacy Notice.
- with any service providers to whom the relevant SodaStream entity subcontracts all or part of this processing. The purpose of this transfer will be to help manage our business and deliver services. For instance, we may transfer your personal information to a service provider to the extent necessary to complete an order and deliver your product, and to process the payment of your order. Other instances may include transfers to e-marketing service providers, hosting providers and any other relevant roles.
- we may sometimes disclose your personal information with third-party business partners, including data enrichment providers, or enable third-party business partners, including vendors that provide chat functionalities on our Site, to collect information directly via our Services.
- with third party advertising companies that collect information about your activity on the Services, and other online services to help us advertise our Services, and/or use customer lists that we disclose to them to deliver ads on their platforms on our behalf to those customers and similar users.
- we may disclose or otherwise allow others access to your personal information pursuant to a legal request, such as a subpoena, legal proceedings, search warrant or court order, or in compliance with applicable laws, if we have a reasonable belief that the law requires us to do so, with or without notice to you. We may also allow access to this information in special emergencies where physical safety is at risk.
- we disclose your personal information where we believe it is appropriate to do so to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our Terms and Conditions or this Privacy Notice, or as evidence in litigation in which we are involved.
- we may disclose any personal information or other information obtained from or about you, to third parties in connection with a merger, acquisition, bankruptcy or sale of all, or substantially all, of our or our affiliates’ assets.
- we may disclose your personal information with professional advisors, such as lawyers, auditors, bankers and insurers.
- certain personal information and any content that you make publicly available on or via the Services, is visible to other users of the Services and the public. Where your personal information can be seen, collected, and used by others, including being cached, copied, screen captured or stored elsewhere by others (e.g., search engines), we are not responsible for any such use of data. We therefore encourage you only to post information that you are sure you want to be publicly accessible.
9. Use of Cookies and Other Tracking Technologies
SodaStream, and our third party advertising and analytics partners, uses certain monitoring and tracking technologies (such as cookies, beacons, pixels, tags and scripts) to track information about your use of our Services. These technologies are used in order to maintain, provide and improve our Services on an ongoing basis, and in order to provide our customers with a better experience, as well as for advertising and analytics purposes. For example, through these technologies, we are able to maintain and keep track of our customers' preferences and authenticated sessions, to better secure our Services, to identify technical issues, user trends and effectiveness of campaigns, and to monitor and improve the overall performance of our Services. We may combine this information with other personal information we collect about you (and our third party business partners may do so on our behalf).
Cookies. Cookies are small text files containing small amounts of information which are downloaded and may be stored on any of your devices that enable internet usage e.g. your computer, smartphone or tablet - like a memory for a web page. Please review your browser’s “Help” file to learn the proper way to modify your cookie settings. Please note that if you delete or choose not to accept cookies from the Site, you may not be able to utilize the features of the site to their fullest potential. To learn more about cookies, visit http://www.allaboutcookies.org.
Clear GIFs, pixel tags, and other technologies. Clear GIFs (also known as web beacons, web bugs, or pixel tags) are tiny graphics with a unique identifier, similar in function to cookies. In contrast to cookies, which are stored on your computer’s hard drive, clear GIFs are embedded on web and app pages. We may use clear GIFs to among other things, track the activities of Site visitors, help us manage content, and compile statistics about Site usage. A clear GIF can collect information such as: the IP address of the computer that downloaded the page on which the tag appears; search terms and other interactions with the Site; the URL of the page on which the pixel tag appears; the time the page containing the pixel tag was viewed; the browser type and language; the device type; geographic location; and, the identification number of any cookie on the computer previously placed by that server. We and our third party business partners may also use clear GIFs in HTML emails to our customers, to help us track email response rates, identify when our emails are viewed, and track whether our emails are forwarded.
Please note that third party services placing cookies or utilizing other tracking technologies through our Services may have their own policies regarding how they collect and store information. Such practices are not covered by our Privacy Notice and we do not have any control over them.
We explain more about the information we collect using cookies and tracking technology in the Cookie Notice.
9.1 Additional State Disclosures
9.1.1 Scope.
You may have certain rights regarding our processing of your personal information under applicable state law. If our processing of your personal information is governed by such laws, this section provides you with additional information regarding your rights and our processing of your personal information under state law.
9.1.2 Your privacy rights. Depending on the jurisdiction in which you live, you may have the rights listed below under applicable state law. However, these rights are not absolute, and in certain cases we may decline or limit your request as required or permitted by applicable law.
- Information. You can request the following information about how we have collected and used your personal information:
- Access. You can request a copy of the personal information that we have collected about you during the past 12 months.
- Correction. You can request that we correct inaccurate personal information that we have collected about you.
- Deletion. You can ask us to delete the personal information that we have collected about you.
- Opt-out of “selling” and ”sharing”. You can opt-out of disclosures of your personal Information that constitute “selling” or “sharing” of your personal information as those terms are defined under applicable law.
- Opt-out of targeted advertising. You can opt-out of our use of your personal information for targeted advertising purposes under applicable law.
- Nondiscrimination. You are entitled to exercise the rights described above free from discrimination as prohibited by applicable law.
9.1.3 Request to information, access, correction, and deletion. You may submit requests to exercise your right to information, access, correction or deletion via email to privacy@sodastream.com.
We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.
9.1.4 Request to opt-out of our “sales” and “sharing” of your personal information. Our use of the interest-based advertising services described above may constitute a “sale” or “sharing” of your personal information under applicable state law from which you may have the right to opt-out. That is because these services use certain categories of our users’ personal information to show you ads they think may interest you on other online services. You can request to opt-out of this “sale” or “sharing” of your personal information here: Do Not Sell or Share My Personal Information. We have no actual knowledge that we have “sold” or “shared” the personal information of individuals under 16 years of age.
9.1.5 Identity verification. We will need to verify your identity to process your information, access, correction, and deletion requests and reserve the right to confirm your state of residence. To verify your identity, we may require government identification, a declaration under penalty of perjury or other information.
9.1.6 Authorized agents. Your authorized agent may make a request on your behalf upon our verification of the agent’s identity. Authorized agents must also provide a copy of the consumer’s signed permission authorizing the agent to submit requests on the consumer’s behalf. You or your authorized agent may be required to provide the information we request to verify your identity, and provide us with confirmation that you have given the authorized agent permission to submit the request.
9.1.7 We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive.
9.1.8 Appeals. You may have the right to appeal a decision we make relating to requests to exercise your rights under applicable local law. To appeal a decision, please contact us at privacy@sodastream.com.
9.1.9 Information practices.
- Sensitive Personal Information. We do not use or disclose sensitive personal information for purposes for purposes other than permitted under applicable local law.
- Retention. We retain personal information as long as necessary to provide our products and Services, and beyond such time to the extent legally permitted and based on our legal obligations (e.g. in relation to invoice retention) or legitimate interests (e.g. in retaining data for the purposes of responding to possible disputes or complaints or for possible reactivation of subscriptions).
9.1. 10 Personal Information that we collect, use and disclose. The chart below describes our business and commercial purposes for processing the categories of your personal information described above, as well as the categories of third parties to whom we may disclose, “sell,” or “share” (as those terms are defined under applicable law) each category of personal information. Information you voluntarily provide to us, such as in free-form webforms, may contain other categories of personal information not described below.
Category of personal information |
Source of personal information |
Business/ |
Categories of third parties to whom we “disclose” personal information for a business purpose |
Categories of third parties to whom we “sell” or “share” personal information |
---|---|---|---|---|
Identifiers |
|
|
|
|
Commercial information |
|
|
|
|
Financial information |
|
|
|
[None] |
Professional information |
|
|
|
|
Internet or other electronic network activity |
|
|
|
|
Audio, electronic, visual, or similar information |
|
|
|
|
Geolocation data |
|
|
|
[None] |
Inferences |
N/A |
|
|
|
Protected classifications |
N/A |
N/A |
N/A |
[None] |
Sensitive personal information |
|
|
|
[None] |
9.1.11 Your California Privacy Rights under the Shine the Light Law.
Under California’s Shine the Light law (California Civil Code Section 1798.83), California residents may ask companies with whom they have formed a business relationship primarily for personal, family or household purposes to provide the names of third parties to which they have disclosed certain personal information (as defined under the Shine the Light law) during the preceding calendar year for their own direct marketing purposes, and the categories of personal information disclosed. You may send us requests for this information to privacy@sodastream.com. In your request, you must include the statement “Shine the Light Request," and provide your first and last name and mailing address and certify that you are a California resident. We reserve the right to require additional information to confirm your identity and California residency. Please note that we will not accept requests via telephone, mail, or facsimile, and we are not responsible for notices that are not labeled or sent properly, or that do not have complete information.
9.2 Notice of Financial Incentive
We offer various programs that may constitute a “financial incentive” under applicable law. The details of these programs are described in the chart below and are subject to change.
You have the right to withdraw from these programs at any time and may do so by following the instructions in the chart below.
We do not generally assign monetary or other value to consumers’ personal information, and our promotions activity changes continually. To the extent applicable law requires that a value be assigned to our research or promotional activities, we value the personal information collected and used under each program as being equal to the value of the discounts or other financial incentives provided in each such program, based upon a practical and good-faith effort to assess on an aggregate basis for all collected information, including but not limited to the following: the benefit and insights that we realize and expect to realize from your participation in our financial incentives (such as shopping preferences and habits); your time spent on our website; the quantity and quality of information that you provide to us as described below; sales directly or indirectly generated from participation in the promotional activities; your purchase history; and any increased goodwill towards us.
Program and material terms |
How to opt-in to the program |
Benefit that is offered for the user’s participation |
Personal information that we may collect (see “3. What Categories of Personal Information Do We Collect and How Do We Collect It?” above for description) |
How to withdraw from the program |
---|---|---|---|---|
Newsletter and Text Message Subscriptions. We will send you marketing and order-related communications. For more information, see the terms and conditions associated with our program. |
By signing up for our newsletters and/or text messages. |
A 10% discount code for your next purchase. |
|
By unsubscribing as described in the newsletter or text. You can also email us at privacy@sodaStream.com. |
Sweepstakes. You can enter into sweepstakes for a chance at winning certain prizes and/or other incentives. For more information, see our Official Rules associated with the sweepstakes. |
By entering into our sweepstakes. |
An entry into sweepstakes for a year’s supply of CO2 or similar prizes. |
|
By emailing us at privacy@sodaStream.com. |
Extended Product Warranty. By registering your machine with us, we’ll extend your warranty period. For more information, see the description of our program at https://sodastream.com/pages/register-your-product. |
By registering your machine at https://sodastream.com/pages/register-your-product. |
An additional warranty period for your machine. |
|
By emailing us at privacy@sodaStream.com. |
Other Financial Incentives. From time to time, we may offer other financial incentives, such as coupons or other price reductions for our products and services in exchange for your enrolling in email updates, newsletter delivery, contests, or similar services we provide to communicate with you. For more information, see the terms and conditions that accompany the respective program. |
By providing us with the personal information requested and entering into the program as described in the description of the respective program. |
We may offer incentives such as coupons or other price reductions. For more information, see the description of the respective program. |
For more information, see the description of the respective program. |
As described in the respective program’s description or by emailing us at privacy@sodaStream.com. |
10. Changes to This Privacy Notice
We may update and change this Privacy Notice from time to time. Please regularly check for the latest version of this Privacy Notice. We will post any changes to this Privacy Notice on our Site. If we make any changes to this Privacy Notice that materially affect our use of your personal information, we will provide you with notice in advance of such change.
11. Contact Information
If you have any questions about this Privacy Notice or wish to exercise any of your rights, you can contact us at:
email address: privacy@sodastream.com.