Data protection notices for the Lidl website and the Lidl app
1. Contact details of the controller and the data protection officer
Unless otherwise stated in the following clauses, Lidl Cyprus, 2 Pigasou Str., Aradippou, CY-7100 Larnaca, Cyprus ("Lidl Cyprus") and Lidl Stiftung & Co. KG, Stiftsbergstraße 1, 74172 Neckarsulm ("Lidl Stiftung", and together with Lidl Cyprus "we", "us") are joint controllers of the processing of your data on the website https://www.lidl.com.cy/c/en-CY/ and in the Lidl app ("Services").
The data protection officers of Lidl Cyprus and Lidl Stiftung can be contacted at the above postal addresses or at dataprotection@lidl.com.cy.
2. Involvement of third parties as data processors
Unless otherwise stated, the recipients or categories of recipients named below act as data processors. They are carefully selected and contractually bound in accordance with Article 28 GDPR. This means that they may only process personal data on the basis of our instructions and not for purposes other than those stated.
3. Transfers to recipients in third countries
Under certain circumstances, it may be necessary for us to transfer your personal data to recipients in a third country or several third countries outside the European Union (EU)/the European Economic Area (EEA).
The EU Commission has certified some third countries as having a level of data protection comparable to the GDPR by means of an adequacy decision. You can find an overview of third countries with an adequacy decision here. For service providers based in the USA, this only applies if they are certified in accordance with the EU-US Data Privacy Framework.
If there is no adequacy decision, we secure the transfer by other measures. These can be, for example, binding company regulations, standard contractual clauses of the European Commission, certificates or recognised codes of conduct.
Unless otherwise stated below, the transfer to a third country takes place either on the basis of an adequacy decision or one of the measures listed above. If you have any questions, please contact our data protection officer.
4. Accessing our Services
Purposes of data processing/legal basis
When you access our Services automatically and without your intervention, your browser sends the
IP address of the end device used,
Date and time of access,
Name and URL of the retrieved file,
Website/application from which access is made (referrer URL),
Browser and, if applicable, operating system of your end device,
Name of your access provider
to our server and temporarily stores them in a log file for the following purposes:
To ensure a smooth connection set-up,
To ensure convenient/appropriate use of our website/application,
To evaluate system security and stability.
If you agree to geolocalisation on your end device, we process your real-time location data when you use certain functions of our Services (e.g. displaying the location of the nearest Lidl store in the store finder).
The legal basis for data processing is Article 6(1)(1)(f) GDPR. Our legitimate interest lies in the correct presentation of our Services, the protection of our systems and the prevention of unauthorised access to our website. If the presentation serves to prepare a contract, the legal basis for data processing is Article 6(1)(b) GDPR.
Storage period/criteria for determining the storage period
The log files are stored for a period of seven days and then automatically deleted.
5. Contact form, email contact, telephone calls, social media and customer surveys
Purposes of data processing/legal basis
Personal data that you provide to us when filling out contact forms, by telephone, by email or via social media will only be used for the purpose of processing your enquiry.
If you take part in one of our customer surveys, you do so voluntarily. In these anonymous surveys, no information is stored that allows conclusions to be drawn about the participants. Only the date and time of your participation will be saved. You can specify your details using free-text fields or by creating screenshots. You can also voluntarily agree to be invited to participate in user studies on a regular basis. These are conducted by telephone interviews, written surveys or tests on the user-friendliness of our applications. For this purpose, we store your first name, surname and email address. Any additional personal information you provide in surveys or user studies will be considered to have been provided voluntarily and will be stored in accordance with the GDPR. When using free-text fields and screenshots, please refrain from submitting personal data about yourself or another individual.
The legal basis for data processing is Article 6(1)(f) or Article 6(1)(b) GDPR. Our and your concurrent (legitimate) interest in this data processing arises from the aim of answering your enquiries, solving any problems you may have and thus maintaining and increasing your satisfaction as a customer or user of our website. If you give your consent as part of a customer survey or user study, Article 6(1)(a) GDPR is the legal basis for data processing based on consent. You can withdraw this consent at any time with effect for the future. Further details on this are set out in the data protection notices of the customer surveys and user studies. The legal basis for the processing of data protection requests is Article 6(1)(c) GDPR, as this is necessary to comply with legal obligations.
If you identify yourself as a Lidl Plus customer, the responsible Lidl company will receive your contact details, which are required for the customer service department to process an enquiry or for a product-specific enquiry with suppliers. The legal basis for this is Article 6(1)(b) GDPR.
Recipients/categories of recipients
When answering your enquiries and analysing customer surveys, your data will also be processed on our behalf by data processors from the customer service department and customer survey department.
Mysta Section title
If necessary to process your complaint, the data you provide may be passed on to companies within the Lidl Group. If your customer service enquiry leads to a further request, we will use your previously collected data for this request so that you do not have to enter your data again.
In order to process your complaint, it may also be necessary to pass on your contact details to our service partners, who will contact you regarding the next steps (e.g. arranging a collection or repair appointment). We will inform you of the name of the specific service partner as part of our communication. The transfer of data is necessary to fulfil warranty claims and thus to perform the contractual relationship with you in accordance with Article 6(1)(b) GDPR.
Storage period/criteria for determining the storage period
We will delete or anonymise all personal data that you provide to us in response to enquiries (suggestions, praise or criticism) no later than 95 days after the final response. Experience has shown that there are usually no more queries after 95 days. If you assert your rights as a data subject under data protection law, your personal data will be processed for the following purposes for three years after the final response to prove that we have complied with legal requirements. The storage period for personal data collected as part of customer surveys is communicated in advance as part of the specific customer survey.
6. Competitions
Controller
The controller for data processing in connection with the organisation of competitions is Lidl Cyprus, 2 Pigasou Str., Aradippou, CY-7100 Larnaca, Cyprus.
Purposes of data processing/legal basis
You have the opportunity to take part in various competitions on our website, from our newsletter or via the Lidl app. Unless otherwise specified in the respective competition, the personal data you provide to us when participating in the competition will be used exclusively for the purposes of organising the competition (e.g. determining the winner, notifying the winner, sending the prize).
The legal basis for data processing in the context of competitions is Article 6(1)(b) GDPR.
Storage period/criteria for determining the storage period
After the competition ends and the winners are announced, the participants’ personal data will be deleted. In the case of non-cash prizes, the winners’ data will be retained for the duration of the statutory warranty claims in order to arrange for rectification or replacement in the event of a defect.
7. Sending of advertising
Purposes of data processing/legal basis
You can sign up for our marketing communications on our website, in our mobile applications, the websites or mobile applications of partner companies and via embedded content on our social media presences. If you have expressly consented to receiving our Lidl marketing communications (email, SMS, WhatsApp, push notifications), we will use your email address or mobile phone number and, if applicable, your name to send you information (see Section "Advertising content"), taking into account your user profile (see Section "Personalised user profile").
In order to ensure that no errors have been made when entering the email address, we use the double opt-in procedure. After you have entered your email address in the registration field, we will send you a confirmation link. Only when you click on this confirmation link will your email address be added to our mailing list. We will do the same with your mobile phone number if you have provided it to us as part of the Lidl Plus registration process.
You can withdraw your consent to receiving marketing communications, including the creation of personalised user profiles, at any time with effect for the future, e.g. at the end of each newsletter, in your Lidl Plus account or via our customer service department at info@lidl.com.cy. When you unsubscribe, we consider your consent to the creation of this personalised user profile and the receipt of newsletters based on it to be withdrawn.
The legal basis for the aforementioned processing is Article 6(1)(f) GDPR or, if consent has been given, Article 6(1)(a) GDPR. The processing of existing customer data for our own advertising purposes or for the advertising purposes of third parties is a legitimate interest within the meaning of the first-mentioned provision.
Recipients/categories of recipients
The recipients include the operators of social networks, advertising partners and specialised service providers who process personal data on our behalf in accordance with our instructions.
If external data processors are used to carry out marketing communications, they are contractually obliged in accordance with Article 28 GDPR.
Storage period/criteria for determining the storage period
If you withdraw your consent to individual advertising measures or object to certain advertising measures, your data will be deleted from the corresponding (email) distribution lists within 48 hours for technical reasons.