Customers and Suppliers
Information for individuals connected with our business customers (B2B), suppliers, business partners, stakeholders and/or investors.
What does this Privacy Notice cover?
This Privacy Notice provides information regarding the personal data which are processed by a company or companies within the Northfield Group of Companies (‘Northfield’ or ‘we’) in relation to (i) individuals who work for, or on behalf of, or who are shareholders of our business customers (‘Business Customers’), (ii) suppliers or vendors (‘Suppliers’), (iii) business partners, including within non-Northfield-operated joint ventures, as well as investors and shareholders (‘Business Partners’).
For individuals who require access to a Northfield site on behalf of a Business Customer, Supplier or Business Partner you will be asked to provide additional information to enable you to be identified for health, safety and security purposes and to manage the relationship between Northfield and the relevant Business Customer, Supplier or Business Partner. For further information please refer to the Privacy Notice – Northfield Group Employee, Contractor and Dependents’ at https://www.northfield-group.com/privacy/ex-employee-notice.html.
For individual retail customers, members of Northfield loyalty programs, visitors of Northfield websites or users of Northfield applications, please refer to the Privacy Notice – Motorists at https://www.northfield-group.com/privacy/b2c-notice.html.
For individuals who apply to work for Northfield, or who attend a recruitment event or undertake an assessment please refer to the Privacy Notice – Northfield Group Recruitment at https://www.northfield-group.com/privacy/job-applicant-notice.html.
These notices are also available from the Northfield websites in the various locations in which we operate, in local languages and to reflect local requirements as appropriate.
Bespoke notices and supplementary privacy statements may contain further information about how Northfield is processing your personal data. In those instances, such privacy notices will be communicated to you separately. These privacy notices may vary among the countries in which we operate to reflect local practices and applicable law requirements.
This Privacy Notice explains what personal data are processed about you, why we are processing your personal data and for which purposes, how long we hold your personal data for, how to access and update your personal data, as well as the options you have regarding your personal data and where to go for further information.
Special Notice – if you are under 16 years old. Processing children’s personal data
Except in those cases where Northfield organizes educational events specifically designed for children, we do not intentionally collect personal data of individuals under 16 years old. If you are under 16 years old (or a different age to reflect local legal requirements as communicated on the Northfield website in your location) please do not send us your personal data, for example, your name, address and email address. If you wish to contact Northfieldin a way that requires you to submit your personal data (such as for education or innovation events) please get your parent or guardian to do so on your behalf.
What personal data do we process about you? Collection of information
We process personal data from and in relation to individuals who are, or who work for or on behalf of or who are shareholders in our Business Customers, Suppliers, Business Partners in the following categories:
- Private contact information (such as name, postal or e-mail address, and phone number) only if necessary; or
- Business contact and other information (such as job title, department, name of the organisation and your dealings with Northfield on behalf of yourself or the relevant Business Customer, Supplier, Business Partner).
In addition, in order to comply with legal and regulatory obligations, to protect Northfield’s assets and employees/contractors and specifically to ensure that Northfield can comply with trade control, anti-money laundering and/or bribery and corruption laws and other regulatory requirements, we carry out screening (pre-contract and on a periodic basis post-contract) on owners, shareholders and directors of our Business Cutomers, Suppliers and Business Partners. This screening takes place against publicly available or government issued sanctions lists and media sources.
The screening does not involve profiling or automated decision making in relation to the counter-parties or potential counter-parties.
Who is responsible for any personal data collected?
Depending upon your location, a company from the Northfield group of companies will be responsible for processing your personal data, either solely or jointly with its affiliates within the Northfield group of companies – your local country site specifies the local company responsible for the processing of your personal data.
For what purposes do we process your personal data?
We process personal data covered by this Privacy Notice for the following purposes:
- Business execution – including providing, researching, developing and improving products or services; concluding and executing agreements with Business Customers, Suppliers and Business Partners; recording and settling services, products and materials to and from a Northfieldcompany; managing relationships and marketing such as maintaining and promoting contact with existing and prospective customers, account management, customer service, and development, execution and analysis of market surveys and marketing strategies;
- Organisation and management of the business – including financial management, asset management, mergers, demergers, acquisitions and divestitures, implementation of controls, management reporting, analysis, internal audits and investigations;
- Health, safety and security – including protection of an individual’s life or health, occupational health and safety, protection of Northfield companies and staff, authentication of individual status and access rights; or
- Legal and/or regulatory compliance – including compliance with legal or regulatory requirements.
or for a secondary purpose where it is closely related, such as:
- storing, deleting or anonymising personal data;
- fraud prevention, audits, investigations, dispute resolution or insurance purposes, litigation and defence of claims; or
- statistical, historical or scientific research.
Communication and marketing
You may receive offers on behalf of the relevant Business Customer, Supplier or Business Partner. On all occasions you will be given the opportunity to use the unsubscribe functionality through the different digital channels we use to interact with you.
Why do we process your personal data?
The personal data covered by this Privacy Notice are only processed:
- in order to take steps at the request of an individual prior to entering into a contract;
- where it is necessary to comply with a legal or regulatory obligation to which the relevant Northfield company/companies is subject to;
- where it is necessary for the purposes of the legitimate interests pursued by the relevant Northfield company/companies, except where such interests are overridden by the interests or fundamental rights and freedoms of the individual/s; or
- (only if legally required) with the explicit consent of the individual.
In those cases where processing is based on consent, and subject to applicable local law which provides otherwise, you have the right to withdraw your consent at any time. This will not affect the validity of the processing prior to the withdrawal of consent.
Security of your personal data
We have implemented technology and policies with the objective of protecting your privacy from unauthorised access and improper use. In particular, we may use encryption for some of our services, we apply authentication and verification processes for access to Northfield services and we regularly test, assess and evaluate the effectiveness of our security measures.
Who will we share your personal data with?
The personal data covered by this Privacy Notice are exclusively processed for the purposes referred to above and will only be shared on a strict need to know basis with:
- Other companies within the Northfield group of companies;
- Authorized third-party agents, service providers, external auditors and/or subcontractors of Northfield; or
- A competent public authority, government, regulatory or fiscal agency where it is necessary to comply with a legal or regulatory obligation to which the relevant Northfield company/companies is subject to or as permitted by applicable local law.
Interacting with Northfield through social media
If you choose to interact with Northfield through social media on a Northfield administered social media page (‘Northfield Social Media Page’) such as Facebook, Instagram, Twitter or LinkedIn, your personal data (such as your name, your profile picture and the fact that you are interested in Northfield) will be visible to all visitors of your personal webpage depending on your privacy settings on the relevant social media platform, and will also be visible to Northfield. You can delete any information that you share on these sites at any time through your relevant social media platform’s account. Northfield does not track your activity across the different social media sites that you use. If you send a message to Northfield via any messenger service on a social media platform, these messages are held for no longer than one month after receipt. Please contact Northfield if you wish to make a request that you are unable to act yourself and which relates to a Northfield Social Media Page – see the section below.
Additionally and to the extent Northfield is jointly responsible with a social media platform of a Northfield Social Media Page, Northfield will have access through the social media platform to aggregated data providing statistics and insights that help to understand the types of actions you take on Northfield Social Media Pages. For more information on how your personal data are processed on those social media platforms, including any targeted advertising that you may receive, please refer to your privacy settings accessible through your relevant social media platform’s account.
Transfers of your personal data to other countries
Where your personal data have been transferred to companies within the Northfield group and/or to authorized third parties located outside of your country we take organizational, contractual and legal measures to ensure that your personal data are exclusively processed for the purposes mentioned above and that adequate levels of protection have been implemented in order to safeguard your personal data. These measures include Binding Corporate Rules for transfers among the Northfield group and for Northfield companies in the EU, European Commission approved transfer mechanisms for transfers to third parties as well as any additional local legal requirements. You can find a copy of Northfield Binding Corporate Rules at https://northfield-group.com/privacy-notices-2/
What are the consequences of not providing your personal data?
Personal data gathered by Northfield for these processes either directly or indirectly are required in order to:
- Fulfil legal requirements and/or which is required for entering into a contract with a counter-party and continuing to contract with that counter-party; or
- Maintain contact with Business Customers, Suppliers and Business Partners.
Failure to provide us with the information required will negatively affect our ability to communicate with you, or our ability to enter into a contract with a counter-party or continue to contract with a counter-party.
How long do we hold your personal data for?
With some exceptions which are explained in supplementary privacy statements, any personal data that are required for the purposes of conclusion and execution of agreements with Business Customers, Suppliers and Business Partners or for considering bids or tenders, will be held during the duration of the contractual relationship and up to 15 years after. For agreements which have a term of more than five years and for the purposes set out above, these agreements will be held for 35 years with effect from the commencement of the agreement.
In all other cases for the purposes set out above, including personal data gathered as part of any unsuccessful bids to Northfield or which relates to the screening against publicly available or government issued sanctions lists and media sources, such personal data are held for no longer than 15 years after it was first gathered.
In all cases information may be held for (a) a longer period of time where there is a legal or regulatory reason to do so (in which case it will be deleted once no longer required for the legal or regulatory purpose) or (b) a shorter period where the individual objects to the processing of their personal data and there is no longer a legitimate business purpose to retain it.
We aim to keep our information as accurate as possible. You can request:
- access to your personal data;
- correction or deletion of the personal data (but only where they are no longer required for a legitimate business purpose);
- that you no longer receive marketing communications on behalf of the relevant Business Customer, Supplier or Business Partner;
- that the processing of your personal data is restricted; and/or
- that you receive personal data that you have provided to Northfield, in a structured, digital form to be transmitted to another party, if this is technically feasible.
To make any of these requests, please contact privacy-office-SI@northfield-group.com.
Who can you contact if you have a query, concern or complaint about your personal data?
If you have any issues, queries or complaints regarding the processing of your personal data please refer to the relevant Northfield privacy notice in your location or alternatively you can contact Privacy-Office-SI@northfield-group.com.
If you are unsatisfied with the handling of your personal data by Northfield, then you have the right to lodge a complaint to your local data protection authority (if there is one) or the Dutch Data Protection Authority whose address is Prins Clauslaan 60, 2595 AJ The Hague, The Netherlands. Please visit https://autoriteitpersoonsgegevens.nl/en for more information.
Cookies and similar technologies
Changes to this Privacy Notice
This Privacy Notice may be changed over time. You are advised to regularly review this Privacy Notice for possible changes. This Privacy Notice was last updated in August 2019.