Five2lunch Privacy Policy

This Privacy Policy gives you an overview of the processing of your personal data in the context of the use of the offers and online services within the "five2lunch" website on five2lunch.com and related mobile app (in the following, when the word "Platform" is used, this refers both to the website as well as the mobile app). This Privacy Policy also informs you about your rights and the possibilities you have to control your personal data and to protect your privacy.

Who is responsible for the data processing and whom can I contact?

Responsible for the data processing is SIA Five2lunch . This company is also meant if the terms "we" or "us" are used in the following. You can contact our data protection officer at:

legal@five2lunch.com


Which personal data do we process and from which sources do these data come from?

When we provide our Platform to you for use, we process personal information from various sources. On the one hand, this is data that we automatically collect when you use the Platform. However, this may also be data that you have voluntarily provided to us or that we receive from our partners.

Data that we automatically collect when you use our Platform

As soon as you visit the website or open the app, you send technical information to our web servers. This happens regardless of whether or not you make a booking with a slot or whether or not you subsequently register with an account with us to use the Platform. In any case we will collect the following access and web-access data (that we call "Access Data"):
  • Date and time of the visit and the duration of use of the Platform
  • The IP address of your device
  • The visited subsites of the website or subsections of the app; and
  • More information about your device (type of device, browser type and version as well as settings, installed plug-ins, operating system)


We process Access Data to allow you and other users to use the Platform and to ensure the functionality of the Platform. We also process Access Data to perform analyses on the performance of the Platform, to continuously improve the Platform and correct errors; to ensure IT security and operation of our systems as well as in order to prevent or uncover abuse, particularly fraud. Further, we process Access Data to customize the Platform to your needs (personalization). For this purpose, we will also assign you a so-called "Unique User ID". This Unique User ID allows us to assign your bookings and other interactions.

To process this data, we also use cookies. Cookies are small text files that you download to your device when you visit our websites and save the above information about yourself. There, you can also find out about which data we process using not our own cookies, but the cookies and tracking tools of third parties such as Google and Facebook.

Data which you yourself transmit to us

In addition to the data we receive from all visitors, we also process other data. The exact amount of this data depends on how you use the Platform. You can use the Platform with and without creating a user account.

Account data

If you decide to create a user account and fill out the registration form, we will process your:

  • Name and surname
  • Email address
  • Your login password
  • Phone number (optional)

You can also use the social log-in functions offered on our Platform to create your user account. If you choose this function, you send us your username on the social network of your choice (i.e., Facebook or Google), the email address you use to log on to the social network and, if applicable, the mobile phone number provided to the social network.

The data entered during registration will be used for the purpose of providing the Platform and to notify you by email on any information relevant to the Platform or registration, such as modification to the scope of the Platform or to the technical circumstances.

Booking and reservation data

If you make a slot reservation, we will further process your:
  • Email address
  • Name and surname
  • Phone number (optional)
  • The restaurant you are making the booking for
  • Time of the slot
  • Special preferences


Please note that, if you fill out the text box indicating your dining/special preference, this might reveal certain sensitive personal information, e.g. food allergies or physical disabilities. If you would not like this data to be processed, please leave the respective field blank.

We process this data to secure your reservation, to inform you about the status of your reservation and also to customize the Platform to your needs based on your previous reservations and bookings.

Customer support requests

You might wish to make a request for assistance to our customer support team or submit a complaint. In this case, in order to react to your request, we will process your IP address and contact data as well as the contents of your request.

You can contact our data protection officer at:

support@five2lunch.com

For what other purposes do we process your data?

In addition, we might process your data for additional purposes. These include:
  • Disclosing your personal data to third parties if we are legally obliged to do so;
  • Asserting legal claims and to defend against legal disputes;
  • Complying with legal requirements for data retention due to tax legislation etc.


What is the legal basis of the processing?

When processing your personal data, we rely on various legal bases according to the so-called Basic Data Protection Ordinance, an EU-wide legal framework for the standardization of data protection law ("GDPR" for short). Here we refer in detail to the following legal bases:

Consent (Article 6 (1) a GDPR)

Since you have given us your consent to process personal data for the specific purposes explained above, this consent ensures the legality of the processing. By registering with your account data or making a booking, you expressly agree the data processing as described in detail in this Privacy Policy by ticking the box before sending the registration or reservation form: If we process your data, it is because you have expressly allowed and requested us to do so when you use the Platform. Thus, your consent represents the most important legal basis for the processing of your personal data by us.

Performance of our contractual obligations towards you (Article 6 (1) b GDPR)

At the same time, the processing takes for the provision of the Platform in the context of the performance of our contract with you. Accordingly, in most cases, the processing is not only justified by your consent, but also because it is necessary to fulfil our contract with you. For example, if you make a booking with a restaurant using the Platform, it will be required to process the booking data to secure your booking.

Our legitimate interests (Article 6 (1) f GDPR)

There are also some cases in which we would be entitled to process your data even without your consent because it is necessary to protect our legitimate interests (or the interests of third parties). In this respect, the purposes described above for which we process your data also, in many cases, represent legitimate interests. This means that we are allowed to process the data necessary to guarantee the safety of our IT systems in any case, even if you have not given or withdrawn your consent to this processing. This also relates to preventing abuse of our platform or personalizing ads to your interests (so-called direct marketing).

Legal requirements (Article 6 (1) c GDPR) or in the public interest (Article 6 (1) e GDPR)

In addition, we are legally obliged to provide certain information to criminal prosecution or tax authorities in individual cases upon request.

To whom do we transmit your data?

We treat your personal data with care and confidentially and will only pass them on to third parties to the extent described below and not beyond. We transmit data to public authorities only in the case of a legal obligation based on a request for information from the respective authority.

Outside of legal obligations towards public authorities, we only transmit your data to other users of the platform, to our third-party providers who help us provide the platform or within the five2lunch group of companies:

Other users of the platform

We transmit booking and reservation data to our partner restaurants using the Platform to facilitate reservations at their restaurants.

Other Third Parties

In addition, we transmit data to external service providers that enable us to provide the Platform. These include the data and providers listed on our Cookie Policy. In this context, please note that all our server hosting and cloud services are provided by Amazon Web Services, Inc. ("AWS"). AWS processes all data on our behalf and we have subjected AWS to a strict data processing agreement to ensure the security of the processing in accordance with the requirements of the GDPR.

Within the five2lunch group of companies

We are part of a global group of affiliated companies owned by SIA Five2lunch. All business intelligence data will generally be anonymized to ensure that your right to data protection is respected. However, SIA Five2lunch might have access also to personal, non-anonymized data under certain circumstances such as an internal revision or business audit requested by public authorities.

Do we transfer your data to countries outside the EU or the EEA?

We generally do not transfer your data to countries outside the EEA (so-called "Third Countries"). We do not host your data in Third Countries and all our servers are located in the EEA (Ireland, to be exact). However, we will ensure that an adequate level of data protection is guaranteed at any time. In this regard, we will ensure that the data recipients are either certified under the so-called "Privacy Shield" (as in the case of Google and Facebook), the "Binding Corporate Rules" or that the EU Standard Contractual Clauses are entered into by any other recipient to ensure the security of the processing and an adequate level of data protection.

How long will my data be stored?

We process and store your personal data as long as it is necessary for the fulfilment of our contractual or legal obligations. All other data will be deleted immediately when you unsubscribe from the Platform. If the remaining data are no longer required for the fulfilment of such obligations, they will be regularly deleted, unless their further processing is necessary for the preservation of evidence or to prevent legal claims from becoming time-barred.

Do you create a user profile with my personal data?

We use your data to optimize your five2lunch browsing experience. This means that we use your data to provide you with a personalized Platform based on your personal preferences and interests and to make tailor-made offers based on your previous behavior. For example, the IP-address of your computer will be used in order to identify your geographical location and in order to offer a you localized content in your local language. We might make suggestions and offers for new restaurants based on the restaurants you have previously viewed and/or made a booking with using our Platform. However, we will never process and analyze your personal data in the context of profiling in such a way that this leads to an automated decision that has a legal effect on you or significantly impairs you in a similar way.

Is there an obligation for me to provide data? What happens if I do not provide my data or no longer do so?

You are not required by law to provide us with the personal data as indicated by this Privacy Notice. In particular, the contractual relationship that you have entered into with us by agreeing to our terms and conditions does not imply any obligation to provide your personal data. However, the transmission of the contract information provided by you to us is a basic prerequisite for concluding a contract with us. In addition, you cannot use the Platform or only to a limited extent if you do not provide us with certain data or object to the use of these data.

What rights do I have with regard to the processing?

You can assert the following rights against us under the GDPR:
  • Your right to information under Article 15 GDPR
  • Your right to correction under Article 16 GDPR
  • Your right to cancellation under Article 17 GDPR
  • Your right to limitation of processing under Article 18 GDPR
  • Your right to data transferability under Article 20 GDPR
  • In addition, you have a right of appeal to the responsible data protection supervisory authority (Article 77 GDPR in conjunction with § 19 BDSG).
You can revoke your consent to the processing of your personal data at any time. This also applies to the revocation of declarations of consent issued to us prior to the validity of the GDPR, i.e. before 25 May 2018. However, this revocation is only effective for the future. Processing that took place before the revocation is not affected by this.

Information about your right of objection under Article 21 GDPR

Right of objection in individual cases

In addition to the rights already mentioned, you have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data relating to you, which, on the basis of Article 6 para. 1 e GDPR (data processing in the public interest) and Article 6 para. 1 f GDPR (data processing on the basis of a balance of interests); this also applies to profiling based on this provision within the meaning of Article 4 para. 4 GDPR. If you file an objection, we will no longer process your personal data unless We can prove compelling grounds for processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. Please also note the information in Section 8 of this Privacy Policy: If we terminate the processing due to your objection, it may be that the Platform can no longer or only to a limited extent be made available to you.

The right to object to the processing of data for advertising purposes

You also have the right to object at any time to the processing of personal data concerning you for the purpose of direct marketing (including any subscription to our newsletter); this also applies to profiling, insofar as it is associated with such direct marketing. If you object, we will no longer process your personal data in the future.

The objection can be made form-free and should be addressed to:

legal@five2lunch.com

Modification of The Privacy Notice at Hand

To keep this information up to date, this Privacy Policy will be modified if the underlying data processing is modified. We will not constrain your rights under this Privacy Policy without your prior written consent. We will publish all intended modifications to the Privacy Policy at hand on the five2lunch website and in the app. In the event that such modifications should be substantial, we shall provide a clear notification (including, in the case of certain Platforms, a notification by email stating the modifications to the data privacy statement at hand). We will also archive older versions of the data privacy statement for future reference.

Third Party Cookies and other Third Party Tools on the five2lunch Platform

This information supplements the five2lunch Privacy Policy.Below we provide you with a list of all cookies and other web-tracking tools on our Platform that are provided either by us or by third parties.

  1. five2lunch's own cookies (so-called "First-Party Cookies"):

Name Duration Purpose AID Browser Session Partner allocation T 30 days from last modification Channel allocation sem_attributes Browser Session SEM Tracking quandooUserGeoData 24h Saves the user location based on the IP address used quandooUserLanguage Session Saves the language selected by the user quandooUserSearchDestination Session Saves the default search area of the user ut Session or 90 days User session token

We use these cookies to analyse web traffic, customise services, content and advertising, measure the effectiveness of advertising campaigns, and promote trust and security of the platform. We continue to use first-party cookies to be able to differentiate users from each other and, in conjunction with the log files from our web server, to determine the total number of people who visit the platform. The web usage data collected in this way helps us obtain the feedback we need to continually improve the platform and provide better service to users.

Users can prevent the acceptance of first-party cookies by adjusting their browser settings so that no cookies are accepted at all. However, if you configure this setting in this way, you may not be able to use certain current or future elements of our website.

  1. Cookies and plug-ins provided by others (so-called "Third-Party Cookies"):

In addition to first-party cookies, we also use the following third-party cookies and plug-ins provided on our website by the following parties:

Name of operator Address Data protection information Facebook, Inc. ("Facebook") 1601 South California Avenue, Palo Alto, California 94304, USA Facebook data privacy statement; Google, Inc. ("Google") 1600 Amphitheatre Parkway Mountain View, California 94043, USA https://policies.google.com/privacy Instagram, Inc. ("Instagram") 1601 Willow Road, Menlo Park, California 94025, USA Instagram data privacy statement Microsoft Corporation ("Bing") Microsoft Corporation, One Microsoft Way Redmond, WA 98052-6399 USA https://privacy.microsoft.com/en-us/privacystatement

Google Analytics and Google Tag Manager

Our Platform uses Google Analytics and Google Tag Manager. Google Analytics and Google Tag Manager use cookies. The information generated by the Cookie about your use of our Platform is generally transmitted to a Google server in the USA and stored there. However, within member states of the European Union or in other parties to the Agreement on the European Economic Area, your IP address will be previously shortened by Google on our Platform. For this purpose, we have implemented the code "gat._anonymizeIp();" in order to guarantee an anonymized collection of IP addresses (so-called IP Masking).

Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and abbreviated there. Google will use this information on behalf of us to evaluate your use of the Platform, in order to compile reports about the Platform activities and to render further services to us connected with the use of the Platform and internet use. The IP address transmitted by your browser within the framework of Google Analytics and Google Tag Manager will not be merged with other data from Google.

You can prevent the storage of cookies by configuring your browser software or mobile device OS settings accordingly; however, pleased note that in this case you may not be able to use all functions of our Platform to the full extent. Furthermore, you can prevent the collection of the data generated by the cookie related to your use of our Platform (incl. IP address) by Google as well as the processing of these data by Google, by downloading and installing the browser plugin available via the following link: http://tools.google.com/dlpage/gaoptout

For more information on terms of use and data protection, please visit https://www.google.com/analytics/terms/gb.html and https://policies.google.com/privacy.

Google Maps

We use Google Maps to display maps and show you the location of our partner restaurants. Evaluations posted by you on our Platform as well as the username stated in such context may be published on Google Maps.

You can find the terms of use for Google Maps at https://maps.google.com/help/terms_maps.html (including the applicable Google Privacy Policy).

Google AdWords & Google Remarketing

Google AdWords & Google Remarketing allow users who have already visited our platform and are interested in the offer to be addressed again through targeted advertising on the pages of the Google partner network. The insertion of the advertisement takes place via the use of cookies.

If you do not wish to receive interest-based advertising, you can disable Google's use of cookies for these purposes by visiting https://www.google.de/settings/ads. Both services are subject to the Google privacy policy which you can find at https://policies.google.com/privacy?hl=en.

Google Marketing Platform

Google Marketing Platform enables its users to place ads on their websites. Advertisers can determine how often, when, and for how long ads are displayed in a browser, and use cookies to facilitate behavioural targeting by indicating which areas of a website you are browsing. A pseudonymised identification number is assigned to your browser in order to check which advertisements are displayed in your browser and which have been accessed. The cookies do not contain any personal data.

You can deactivate the use of cookies by Google for such purposes at https://adssettings.google.com/authenticated. Both services are subject to the Google Privacy Policy available for download at http://www.google.com/intl/de/policies/privacy/.

Facebook plugins

Facebook plugins are integrated into our platform. You can recognize the Facebook plugins by the Facebook logo or the "Like button" on our page. An overview of Facebook plugins available can be found here: http://developers.facebook.com/docs/plugins/.

When you visit our platform, a direct connection is established between your device and the Facebook server. Facebook receives the information that you have visited our platform with your IP address. If you click the Facebook "Like" button while logged into your Facebook account, you can link the content of our platform to your Facebook profile. This allows Facebook to assign the visit to our platform to your user account. Please note that as the provider of the platform, we do not receive any information about the content of the transmitted data or its use by Facebook. However, if you are not a Facebook member, your IP address and information will be stored when you visit these websites and apps, including device information (operating system, hardware version, device settings, file and software names and types, battery and signal strength, device identifiers, device locations, including specific geographic locations, such as GPS, Bluetooth or WiFi signals, connection information such as the name of your mobile operator or ISP, browser type, language and time zone, mobile phone number) and information about your activity. According to Facebook, only an anonymous IP address is processed.

Further information in this regard can be found in Facebook's Privacy Policy available for download at http://de-de.facebook.com/policy.php. If you do not want Facebook to be able to assign the visit to our platform to your Facebook user account, please log out of your Facebook user account. Further settings and objections to the use of data for advertising purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads.

Facebook user-defined target groups

Facebook users should be aware that this website also uses the Facebook communication tool Website Custom Audiences.

To this end, Facebook pixels are integrated into our web pages, which make you anonymous as a visitor to our website, i.e. without identifying you as an individual. When you log on to Facebook later, a non-reversible and thus non-personal checksum (profile) derived from your usage data is transmitted to Facebook for analysis and marketing purposes. For further information about the purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as your privacy settings, please refer to Facebook's privacy policy, which you can find, e.g. at https://www.facebook.com/ads/website_custom_audiences/ and https://www.facebook.com/privacy/explanation. If you would like to opt out of using Facebook's user-defined website, you can do so at https://www.facebook.com/ads/website_custom_audiences/.

Instagram

Instagram plugins are integrated in our Platform. If you are logged into your Instagram account, you can link the contents of our Platform with your Instagram profile by clicking on the Instagram button. Thereby, Instagram can associate the visit to our Platform with your user account. We hereby point out that as provider of the Platform, we do not receive any information on the contents of the data transmitted and their use by Instagram.

You can find further information about this in Instagram's Privacy Policy: http://instagram.com/about/legal/privacy/

Affiliates

We cooperate with various affiliation networks that allow us to display various advertising materials such as banners or other promotional content on so-called publisher websites. Cookies are used to record which users came to our site via the respective advertising medium clicked on and then made a reservation. These cookies do not contain any personal data, but only a pseudonymous user and reservation ID, which makes it possible to assign them to the respective network. This information is required for the purpose of payment processing with the relevant network. If you do not agree to such processing, you have the option to prevent the storage of cookies by changing a setting in your Internet browser.