Scan Rewards Privacy Notice

This privacy notice informs you how NIQ collects and processes your personal data in connection with your participation in the ScanRewards friends and family test. Other privacy notices apply to you, for example if you participate in one of our other panels or special market research studies or use our other apps. In this case, we have informed you accordingly in the respective context.  
NIQ consists of the companies listed here, which together form the "NIQ Group". NIQ, "we", "us", "our" means the NIQ company identified in this privacy notice as the controller for processing your personal data.
Where we refer to personal data below, we mean any information relating to an identified or identifiable living person. Personal data that has been anonymized in such a way that the data subject cannot be identified or can no longer be identified (anonymous data) is no longer considered personal data.
We may need to amend or update this privacy notice from time to time. Therefore, please read this privacy notice at regular intervals.

Controller, data protection officer

For the purposes of this privacy notice, the controller is:

Foxintelligence SAS, 1 rue de Metz 75010 Paris, France | contact@foxintelligence.io, registered 820 039 311 in Paris RCS.  
The Data protection Officer can be contacted by email to Privacy@foxintelligence.io or postal letter to the above address, Attn: Data Protection Officer.

Content

In this privacy notice, we inform you about the following: 
- which personal data we process in the context of your participation in the Consumer Panel; 
- the purposes and legal basis of the processing;  
- to whom we transfer your personal data to; 
- whether the provision of your personal data is mandatory and the consequences of not providing it; 
- your rights regarding your personal data and how you can exercise these; 
- the duration of the processing;  
- our security measures;
- and cookies and similar technologies we use  

Personal data categories, processing purposes, legal bases of processing and data storage periods or rules

Personal data categories
Processing
purposes
Legal basis of the processing
Storage period of rules
Category
Master data (or: contact information): Your name and postal address, email address, phone number(s), City, Country


Types
For us to effectively manage the panel of users and deduplicate participants upon registration, To communicate with user during the panel Login and getting feedback about the app
Source
Panel management: Our legitimate interest as a market research company Communication: Your consent


Storage
For us to effectively manage the panel of users and deduplicate participants upon registration, To communicate with user during the panel Login and getting feedback about the app
Category
Sociodemographic data (or: profile data): DOB, gender, # people of people on Household




Types
Statistical analysis of your purchase data Ensure an even distribution of users with the same sociodemographic data.  Specifically we want to have people from different age group and household size in the tester sample
Source
Your consent







Storage
3 years without any activity (login, open email of app interaction) Or When the user deletes the account through the app
Category
Purchase data collected through the ScanRewards app: Information regarding your purchases of groceries and other goods for your household based on scanning of barcodes, photo image of receipts from physical stores, and entry of non-barcoded items using codebook
Types
Test internal processes and monitor the performance of our internal tools in capturing the data






Source
Your consent









Storage
3 years without any activity (login, open email of app interaction) Or When the user deletes the account through the app
Category
Internet log data: IP address, sign-in /-out timestamps, information regarding the type of device, operating system and browser, device unique id
Types
Information security purposes, the detection and prevention of fraud and cyber attacks


Source
Our legitimate interests as an app publisher




Storage
3 years without any activity (login, open email of app interaction) Or When the user deletes the account through the app

Recipients

We may share your personal data with other companies in the NIQ Group. Within the NIQ Group, only employees and departments with a “need to know” have access to your personal data and only to the extent necessary. Regarding the transfer of your personal data within the NIQ Group, the companies of the NIQ Group are either independent controllers, joint controllers or processors, depending on the processing activity.
We may transfer your personal data to recipients, who are usually processors, outside the NIQ Group. These third parties belong to the following categories of recipients:  
- service providers for the operation of our website and the processing of personal data stored or transmitted by the systems (e.g. hosting or service providers for data centre services, web and app analytics,  payment processing or IT (Information Technology) security);
- consultants and service providers as independent controllers or joint controllers (e.g. insurance companies or accounting service providers);
- persons who are subject to professional secrecy or are obliged to maintain confidentiality, for example lawyers, tax consultants and auditors;
- government agencies/authorities, to the extent deemed necessary to comply with legal obligations;
- persons involved in carrying out our business operations (e.g. auditors, banks, insurance companies, legal advisors, regulatory authorities, parties involved in company acquisitions or the establishment of joint ventures);
- recipients in the course of any reorganisations, mergers, disposals or other transfers of assets. We will then ensure that the recipient of your personal data agrees to handle it in a manner that complies with applicable data protection law and is compatible with the original purposes of the processing. We continue to ensure the confidentiality of your personal data and inform you about the transfer to another controller.
Where we use third party service providers (including processors), these third parties are subject to contractual obligations (e.g. a data processing agreement). These processors will only process your personal data in accordance with our prior written instructions and must take measures to protect the confidentiality and security of your personal data.

Transfer of data outside of EU/EEA

Due to the international nature of our business, it may be necessary for us to transfer your personal data to other companies within the NIQ Group and to third parties outside the European Union (EU) and/or the European Economic Area (EEA) (“Third Countries”). For this reason, we may transfer your personal data to Third Countries that have different laws and data protection compliance requirements than the country in which you are located. The third countries concerned, e.g. the USA, may not have the level of data protection that you enjoy under the GDPR. This can mean disadvantages such as an impeded enforcement of data subjects’ rights, a lack of control over further processing and access by state authorities. You may only have limited legal remedies against this.
Within the NIQ Group, we have concluded an intra-group data transfer agreement with the relevant transfer mechanisms (standard contractual clauses of the European Commission) to ensure an adequate level of protection for your personal data when it is transferred from the EU/EEA to third countries.
Insofar as we transfer your personal data from the EU/EEA to recipients in third countries that are not covered by an adequacy decision of the EU Commission, we achieve an adequate level of data protection by concluding standard contractual clauses of the European Commission or by means of binding corporate rules of our business partners and supplement these transfer mechanisms with further contractual, technical and organisational measures if necessary. Please contact Privacy@foxintelligence.io to obtain a copy of transfer mechanisms.

Are you obliged to provide your personal data ?

In principle, you are not obliged to provide your personal data. However, if you do not provide your personal data, we may only be able to provide you with limited services or not answer your enquiries. If the processing of your personal data is necessary for the fulfilment of a contract between you and us and you do not provide the required information, we may discontinue our contractual services. In this case, we will notify you in advance.

Your data subject rights

You have the following rights in relation to your personal data:
...
We do not make decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you (Art. 22 GDPR).
Processing Time: We will comply with your request without undue delay and in any event within one month of receipt of the request. This period may be extended by a further two months if necessary, considering the complexity and number of requests. NIQ will inform you of any such extension, together with the reasons for the delay, within one month of receipt of the request. This does not apply to right to withdraw consent, which we implement without delay within our statutory obligation.

Duration of the processing

We will only process your personal data for as long as is necessary to achieve the above purposes. For details, please see column “data storage periods or rules” in sec. 2. Third parties engaged by us will store your personal data on their systems for as long as is necessary in connection with the provision of services to us in accordance with the relevant contract. We will delete or anonymise your personal data as soon as it is no longer required for the purposes described in this privacy notice and if we have no legal basis to further store your personal data.
In addition, the retention period may be extended if we are subject to statutory retention and documentation obligations (for Germany these are up to ten years). The retention period may also be based on the statutory limitation periods (for Germany this is up to thirty years, with the regular limitation period being three years). In certain circumstances, we may also need to store your personal data for longer, e.g. in connection with authority or legal proceedings.
Regarding the use and retention period of cookies, please note section Cookies and other technologies.

Security

We protect your personal data from loss, misuse, disclosure, alteration, unavailability, unauthorised access and destruction and maintain the confidentiality of your personal data. This is also ensured using appropriate technical and organisational measures. We choose our security measures considering the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons and continuously improve them. Technical measures include, for example, the use of encryption (e.g. TSL encryption for personal data in transit), access control to our systems, monitoring of system resources and system messages, ensuring the availability and resilience of systems and services.
Organizational measures include, for example, defining roles and responsibilities, ensuring the correct and secure operation of information processing systems, regular training and awareness-raising of employees, as well as evaluating and assessing the effectiveness of the aforementioned measures. Access to your personal data is only granted to employees, service providers or NIQ Group companies who require such access for the fulfilment of a business purpose or for the performance of their duties.

Cookies and other technologies

Our website contains cookies and other technologies (e.g. pixels, scripts) (together “Cookies”). Cookies are used to make our website user-friendly, effective and secure. Cookies are, for example, small text files that are stored on your terminal device and contain personal data such as personal settings and login information.
We use the following categories of Cookies:
Cookie category 
Cookie
name 
First / third party 
Cookie
domain 
Cookie lifetime 
performance
_gcl_au
Third party 
.foxintelligence.io 
2 days 
performance
_jsuid
Third party 
.foxintelligence.io 
7 month 
performance
_ska_id
Third party 
.foxintelligence.io 
11 month 
performance
_hjSessionUser_ 
Third party 
.foxintelligence.io 
9 month 
performance
Google analytics 
Third party 
.foxintelligence.io 
1 year 
performance
Intercom
Third party 
.foxintelligence.io 
8 month 
Strictly necessary 
PHP Session 
Third party 
cps.foxintelligence.io 
14 month 
We use first- and third-party Cookies. First party Cookies come from our platform and send information only to us; third party Cookies are placed on our website by third parties and send information about your device to other companies that recognise the Cookie. We use session Cookies, which are only stored for individual online sessions and are deleted when you close your browser; and persistent Cookies, which are deleted when they reach their expiry date or are deleted by the user.
We place Strictly Necessary Cookies to provide you with a tele media service or other equivalent information society service expressly requested by you. The subsequent processing of Strictly Necessary Cookies is based on our legitimate interest to provide you with a technically optimized, user-friendly and appropriate website or your consent (as applicable). We use other Cookies only with your consent. Where we rely on consent, you can withdraw your consent at any time with effect for the future, e.g. by managing your Cookie settings or by sending an e-mail to Privacy@foxintelligence.io.
A list of Cookies used by our website can be found in the following:
...
We also use third-party technologies with your consent. You can find a list below:
3rd party tool
Google Analytics
Description
We use Google Analytics of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland  (“Google”).  

The Cookies used by Google generate information about how you use our website. This information is usually transferred to a Google server in the USA and stored there, where it is also processed by Google for its own purposes.  

IP anonymisation We have activated the IP anonymisation function on our website.

This means that your IP address is shortened by Google within states of the EU/EEA before being transmitted to the USA. Google will transfer the full IP only in exceptional cases to a Google server in the USA and shorten it there. On behalf of the responsible party, Google will use this information for the purpose of evaluating your use of our website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. For more information, please visit https://policies.google.com/privacy.

Google also provides further information on its data processing here. Appropriate safeguard for the personal transfer to the United States: Commission implementing Decision of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework in conjunction with Google’s self-certification under the EU-US Data Privacy Framework.
3rd party tool
Google Adsense
Description
We utilize Google AdSense, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) under a data processing agreement with the provider, to display advertisements on our website.

Google AdSense uses cookies to serve ads based on a user's previous visits to our website or other websites.
These cookies enable Google and its partners to serve ads to our users based on their visit to our sites and/or other sites on the Internet.

Cookie Information
The cookies utilized by Google AdSense collect information about how users interact with our website and the ads displayed. This information is generally transmitted to and stored on a Google server in the USA, where it is also processed by Google for its own purposes.

IP Anonymization
To protect your privacy, we have implemented IP anonymization for Google AdSense on our website. This means that Google shortens your IP address within the states of the European Union (EU) or the European Economic Area (EEA) before it is sent to the USA. Only in exceptional cases is the full IP address sent to a Google server in the USA and shortened there. Google uses this information on behalf of the website operator to evaluate your interaction with the ads, compiling reports on ad activity and providing other services relating to ad activity and internet usage.

Based on your consent given when registering your account in the app we process personal data about you through Google AdSense in the manner and for the purposes set out above.
Appropriate safeguard for the personal transfer to the United States: Commission implementing Decision of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework in conjunction with Google’s self-certification under the EU-US Data Privacy Framework.
3rd party tool
Clicky
Description
We employ Clicky Web Analytics, a service provided by Roxr Software Ltd. under a data processing agreement with the provider, to monitor usage and conversions on our website. Clicky uses cookies to collect data about how visitors use our site. This information helps us understand user interactions on our website, enabling us to improve user experience and optimize our content and services.

Cookie Information
The cookies set by Clicky track information such as how visitors arrive at our website, how often they visit, and which parts of the site they frequent most. This data is collected anonymously and is used to improve the functionality and user-friendliness of our site.

IP Anonymization
In our commitment to protect your privacy, we ensure that IP addresses are anonymized before data is sent to Clicky. This means your IP address is masked, thereby safeguarding your personal information. Clicky processes this information to provide us with insights into website traffic and user behavior, without personally identifying individual visitors.

Data Usage and Privacy  
Data collected from the device include:
- URL & Title of pages viewed on our website / in our app
- URL & Title of any links that are clicked on pages  of our website / appviewed
- Referrer
- User agent
- Screen resolution
- Language
- x/y coordinates of mouse events
- Anonymized IP address

With your consent given when registering your account in the app we process personal data concening you through Clicky in the manner and for the purposes outlined above. Our use of Clicky Web Analytics helps us better understand our audience and improve your website experience. Appropriate safeguard for the personal transfer to the United States:
- Commission implementing Decision of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework in conjunction with Roxr’s self-certification under the EU-US Data Privacy Framework.
- Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council .
3rd party tool
Hotjar
Description
We utilize Hotjar, a service provided by  Hotjar Ltd, Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's STJ 3141, Malta under a data processing agreement with the provider, to understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users’ experiences (e.g., how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf.

Cookie Information
The use of cookies by Hotjar enables us to collect standard internet log information and details of visitor behavior patterns, such as number of visits, average time spent and referrer (where users came from when they followed a link). We do this to track visitor use of the website and to compile statistical reports on website activity. For further information about Hotjar’s use of cookies, please visit Hotjar’s Cookie Information.

IP Anonymization
To ensure privacy, we have configured Hotjar to automatically anonymize your IP address so that you remain unidentifiable by the IP alone. This step emphasizes our commitment to protect your privacy while analyzing user interactions.

Data Usage and Privacy
For more comprehensive details on what data Hotjar collects and how it is used, please see Hotjar’s Privacy Policy at https://www.hotjar.com/legal/policies/privacy. You can also opt-out of Hotjar creating a user profile, Hotjar’s storing of data about your usage of our site, and Hotjar’s use of tracking cookies on other websites by following this opt-out link: https://www.hotjar.com/legal/compliance/opt-out. By giving your consent when registering your account in the app, you consent to the processing of your personal data by Hotjar in accordance with the purposes and methods described above. Our use of Hotjar enables us to understand our users' interactions with our website, helping us to improve our services and provide a better user experience. Personal data may be transferred outside the EU and the UK. Appropriate safeguard: Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council
3rd party tool
Intercom
Description
Intercom Communication and Support
We use Intercom, a service provided by Intercom, Inc., under a data processing agreement with the provider to facilitate customer support and communication. Intercom allows us to interact directly with our users through our website or application, providing a platform for sending messages, answering inquiries, and offering personalized support. This service helps us improve user experience by ensuring timely and effective communication.

Data Collection and Processing
Intercom uses cookies and other tracking technologies to collect data about your interaction with our website or application and our services. This may include information about your device, browsing activity, and the pages you visit. Intercom processes this data to enable us to communicate with you, understand your needs and preferences, and provide better service. The information collected may also include personal data, such as your name, email address, or any other details you provide when communicating with us.

Privacy and Security
Your privacy and the security of your data are paramount to us. We have taken measures to ensure that all data collected through Intercom is processed in accordance with applicable privacy laws and our privacy policy. Intercom, Inc. also commits to protecting your data and respecting your privacy, as detailed in their Privacy Policy.  

Your Choices and Rights
You have control over your personal information and how it is collected, used, and shared. At any time, you can request access to the personal data we hold about you, ask for corrections, or request deletion of your data. For interactions specific to Intercom, you may also manage your preferences and opt out of specific communication channels through the settings provided within the Intercom platform. For more information about our data practices, please visit our Privacy Policy [insert link to Privacy Policy here]. To learn more about Intercom's data protection practices, please refer to their Privacy Policy.
With your consent given upon registering your account in the app, you consent to the processing of your data when engaging with us through Intercom as described above and in accordance with our Privacy Policy. We believe that effective communication is key to enhancing our services, and Intercom helps us achieve this goal.
Appropriate safeguard for the personal transfer to the United States:
Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council
You can also use our website without Cookies, but you might not be able to use our website to its full extent or to use certain functionalities.  

Questions exercising your data protection rights, complaints

If you have any questions or complaints about the collection, use or retention of your personal data, or if you wish to exercise any of your rights in relation to your personal data, you can contact our data protection officer by emailing Privacy@foxintelligence.io
We will investigate and attempt to remedy any complaint or dispute regarding the processing of your personal data.