Email: Ordinary mail:
4. Data Subjects
IITR Datenschutz GmbH Dr. Sebastian Kraska Marienplatz 2
Privacy Notice - Purchase
This Privacy Notice applies to the purchasing of goods on the website www.pizzahut.de as well as via the order platform “TicTuk”.
The responsible data controller for any personal data collected and processed in connection with the purchasing of goods on the website www.pizzahut.de is ISH Germany GmbH, Friedrichstraße 68, 10117 Berlin, ) or the franchisee who is next to the delivery address provided by you ("Restaurant", "we" or "us"). Here you can find a list with names, addresses and email-addresses of our franchisees. If an order is placed via the "TicTuk" order portal, ISH Germany GmbH and the respective franchisee, who is closest to the delivery address you have specified, are each separate controllers.
Data Protection Officer
If you have any questions etc. about or in connection with this Privacy Notice - Purchase or would like to complain about our handling of your personal data or exercise any of your rights (see 9. below), please contact us by using the above contact details or contact our data protection officer by using the following contact details:
This Privacy Notice - Purchase applies to the collection and processing of personal data of users that purchase on the website www.pizzahut.de as well as via the order platform “TicTuk”.
5. Categories of Data, Purposes of the Processing and Legal Basis
We collect and process the following categories of personal data about you: first name, surname, telephone number, email address, invoice address, delivery address, payment information. We receive this personal data either directly from you (if you purchase without a user account) or from ISH Germany GmbH, the operator of the website www.pizzahut.de (if you purchase through your user account).
We collect and process your personal data in order to provide you with the ordered goods and to handle the purchase and delivery contract with you. The legal basis is contract performance pursuant to Art. 6 (1) (b) GDPR.
The provision of the personal data is necessary to enter into a contract with the Restaurant. If you do not provide your personal data, you cannot purchase goods on the website www.pizzahut.de and have them delivered.
Please note that we process your personal data for other purposes only if we are obligated to do so on the basis of legal requirements (e.g., transfer to courts or criminal prosecution authorities), if you have consented to the respective processing or if the processing is otherwise lawful under applicable law. If processing for another purpose takes place we may provide you with additional information.
6. Recipients and Categories of Recipients
Any access to your personal data at the Restaurant is restricted to those individuals that have a need to know in order to fulfill their job responsibilities.
The Restaurant may transfer your personal data for the respective purposes to the recipients and categories of recipients listed below.
6.1 Private third parties – Affiliated or unaffiliated private bodies other than us.
In the case of an order via the "TicTuk" order portal, the restaurant that is closest to the delivery address you specified, receives your specified personal data and processes them as an independent controller for the purpose of executing the order.
6.2 Data processors – Certain third parties, whether affiliated or unaffiliated, may receive your personal data to process such data on behalf of the Restaurant under appropriate instructions as necessary for the respective processing purposes. The data processors will be subject to contractual obligations to implement appropriate technical and organizational security measures to safeguard the personal data, and to process the personal data only as instructed.
TicTuk Technologies Ltd. processes your personal data as a processor for the purpose of processing an order via the order platform “TicTuk”.
6.3 Governmental authorities, courts, external advisors, and similar third parties that are public bodies as required or permitted by applicable law.
If we become involved with a merger or another situation involving the transfer of some or all of our business assets, we may share your information with business entities or people involved in the negotiation or transfer.
In addition, we may share information about you with other companies if you give us permission or direct us to share the information.
7. Storage Period
Your personal data is stored by the Restaurant and/or our service providers, to the extent necessary for the performance of our obligations and for the time necessary to achieve the purposes for which the personal data is collected, in accordance with applicable data protection laws. When the Restaurant no longer needs to process your personal data, we will erase it from our systems and/or records and/or take steps to properly anonymize it so that you can no longer be identified from it (unless we need to keep your information to comply with legal or regulatory obligations to which the Restaurant is subject. E.g., personal data contained in contracts, communications, and business letters may be subject to statutory retention requirements, which may require retention of up to 10 years. If applicable, any other personal data will in principle be deleted 5 years after the termination of the respective related contractual relationship between you and the Restaurant, if applicable).
If you have declared your consent for any personal data processing activities, you can withdraw this consent at any time with future effect. Such a withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal.
Pursuant to applicable data protection law you may have the right to: request access to your personal data, request rectification of your personal data; request erasure of your personal data, request restriction of processing of your personal data; request data portability, and object to the processing of your personal data. Please note that these aforementioned rights might be limited under the applicable national data protection law. For further information on these rights please refer to the Appendix Your Rights.
You also have the right to lodge a complaint with the competent data protection supervisory authority. To exercise your rights please contact us as stated in Section 2 above.
Changes to the Privacy Notice - Purchase
This Privacy Notice may require an update from time to time – e.g. due to the introduction of new services. We reserve the right to change or supplement this Privacy Notice - Purchase at any time. We will publish the changes on the website www.pizzahut.de and/or inform you accordingly (e.g., via email).
Appendix Your Rights
(a) Right of access: You may have the right to obtain from us confirmation as to whether or not personal data concerning you is processed, and, where that is the case, to request access to the personal data. The access information includes – inter alia – the purposes of the processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data have been or will be disclosed. However, this is not an absolute right and the interests of other individuals may restrict your right of access. The right of access is limited pursuant to the Federal Data Protection Act, e.g. it does not apply if the data (a) were recorded only because they may not be erased due to legal or statutory provisions on retention, or (b) only serve the purposes of monitoring data protection or safeguarding data, and providing information would require a disproportionate effort, and appropriate technical and organizational measures make processing for other purposes impossible.
You may have the right to obtain a copy of the personal data undergoing processing. For further copies requested by you, we may charge a reasonable fee based on administrative costs.
(b) Right to rectification: You may have the right to obtain from us the rectification of inaccurate personal data concerning you. Depending on the purposes of the processing, you may have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
(c) Right to erasure ("right to be forgotten"): Under certain circumstances, you may have the right to obtain from us the erasure of personal data concerning you and we may be obliged to erase such personal data. Such right to erasure does not apply pursuant to the Federal Data Protection Act e.g. if in the case of a non-automated processing erasure would be impossible or would involve disproportionate effort due to the specific mode of storage and if your interest in erasure can be regarded as minimal. In such case, you may have the right to restriction of processing.
(d) Right to restriction of processing: Under certain circumstances, you may have the right to obtain from us restriction of processing your personal data. In this case, the respective data will be marked and may only be processed by us for certain purposes.
(e) Right to data portability: Under certain circumstances, you may have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and you may have the right to transmit those data to another entity without hindrance from us.
(f) Right to object: Under certain circumstances, you may have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data by us and we can be required to no longer process your personal data.
Moreover, if your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. In this case your personal data will no longer be processed for such purposes by us.