Skip to content
Header
You are on the main content

Privacy Policy

Nestle Korea Co., Ltd., including Nespresso affiliates, Nespresso Business Unit (hereinafter referred to as “Nespresso”) is doing its best to ensure that personal information provided by users is protected when operating Nespresso's brand homepage. Nespresso complies with the personal information protection regulations which are required by information and communication service providers such as PERSONAL INFORMATION PROTECTION ACT, PROTECTION OF COMMUNICATIONS SECRETS ACT, TELECOMMUNICATIONS BUSINESS ACT, ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION, ETC and personal information protection guidelines established by the Korean government such as the Korea Communications Commission, the Ministry of Science and Technology Information and Communication, and the Ministry of Public Administration and Security, and through its Privacy Policy, informs you of the purposes and methods of using the personal information provided by users, and what measures are being taken to protect personal information. Nespresso's privacy policy is disclosed on the first screen of the homepage and can be viewed easily by users at any time.

Nespresso's Privacy Policy is subject to change due to changes in laws and guidelines, changes in Nespresso's internal policies, etc. and when the Privacy Policy changes, we immediately publish the change and the date of change through the brand's homepage so that users can easily recognize the revised content.

    Nespresso’s Privacy Policy contains the following information:

  1. Items of personal information collected and method of collection
  2. Purpose of collecting and using personal information
  3. Period of retention and use of personal information
  4. Procedure of destruction of personal information
  5. Consignment of personal information processing
  6. Rights of users and legal representatives and how to exercise them
  7. Technical / Administrative Measures for Personal Information Protection
  8. Matters concerning the installation, operation and refusal of cookies
  9. Matters concerning provision of personal information to third parties
  10. Transfer of personal information to overseas
  11. Privacy Officer and related departments
  12. Notification obligations due to policy changes

1. Items of personal information collected and method of collection

Nespresso collects the following personal information for membership registration, consultation, and provision of various services:
  • Name
  • Nespresso Professional Club Membership Number
  • Email Address
  • Telephone Number
  • Mailing Address (Delivery Address / Billing Address
  • Zipcode
In addition, in the process of using services and business processing, user name and password, web browser and OS type, access log, IP address, advertising ID, cookie, visit date, service use record, member information processed by the business operator for marketing purposes, etc. may be generated and collected.

Also, during the purchase process of Nespresso's product, payment method, card name, card number, cardholder name, expiration date, first two digits of password, 8 digits of birth date, or business registration number may be collected when paying by credit/debit card and bank name and account number when using account transfer. The name, phone number, address, postal code, etc. of the recipient of the item may be collected when the item is delivered.

2. Purpose of collecting and using personal information

Most brand homepage services can be used without a separate user registration. However, for brand member service, product purchase, and participation in various events, we are collecting personal information necessary from users, through consumer survey, to provide better quality services to users including customized service. The collected personal information is used for the following purposes.
2.1. Fulfillment of contracts for service provision and settlement of fees according to service provision
Provision of contents, provision of specific customized services, delivery of goods or sending invoices, identification, purchase and payment, collection of fees
2.2. Member Management
Membership service use and identification according to the limited identification system, personal identification, prevention of illegal use and unauthorized use of bad members, confirmation of intention to join, restriction on the number of subscriptions, confirmation of consent from legal representative when collecting personal information of children under 14, Identification of the legal representative later, preservation of records for dispute settlement, handling complaints , and delivery of notices.
2.3. Use for Marketing, Advertising
Development of new services and provision of customized services, provision of services and advertisements according to statistical characteristics, checking the validity of the service, providing event and advertising information and providing opportunities to participate, identifying the frequency of access, and statistics on service use by members.

3. Period of retention and use of personal information

Nespresso retains users' personal information and uses it according to regulations while a user is a member of Nespresso's brand homepage and uses the member service of the brand homepage provided by Nespresso. After a member requests termination of membership or the purpose of collecting and using personal information is achieved, the information will be destroyed without delay. However, the following information is retained for the specified period for the reasons below.

[Retention of information according to related laws]
Retention of member information for a certain period of time specified by related laws if it is necessary to preserve it in accordance with the provisions of related laws such as Commercial Law, ACT ON THE CONSUMER PROTECTION IN ELECTRONIC COMMERCE, ETC.
  1. Items to be retained: Records on contract or withdrawal of subscription, etc.
    - Laws for grounds and policies: ACT ON THE CONSUMER PROTECTION IN ELECTRONIC COMMERCE, ETC
    - Retention period: 5 years
  2. Items to be retained: Records on payment and supply of goods, etc.
    - Laws for grounds and policies: ACT ON THE CONSUMER PROTECTION IN ELECTRONIC COMMERCE, ETC
    - Retention period: 5 years
  3. Items to be retained: Records on consumer complaints or dispute settlement
    - Laws for grounds and policies: ACT ON THE CONSUMER PROTECTION IN ELECTRONIC COMMERCE, ETC
    - Retention period: 3 years
  4. Items to be retained: Records on display/advertising
    - Laws for grounds and policies: ACT ON THE CONSUMER PROTECTION IN ELECTRONIC COMMERCE, ETC
    - Retention period: 6 months
  5. Items to be retained: Books and supporting documents for all transactions prescribed by the tax law
    - Laws for grounds and policies: FRAMEWORK ACT ON NATIONAL TAXES
    Retention period: 5 years
  6. Items to be retained: Records on electronic financial transactions
    - Laws for grounds and policies: ELECTRONIC FINANCIAL TRANSACTIONS ACT.
    Retention period: 5 years
  7. Items to be retained: Service visit history
    - Laws for grounds and policies: PROTECTION OF COMMUNICATIONS SECRETS ACT, Act on Information and Communication Network
    Retention period: 1 years
  8. Items to be retained: Illegal use record
    - Laws for grounds and policies: Company internal policy
    - Retention period: 1 years

4. Destruction procedure of personal information

In principle, personal information of users is destroyed without delay when the purpose of collecting and using personal information is achieved. The information entered by the user for membership registration, etc. is transferred to a separate DB after the purpose is achieved (in case of paper, a separate filing box) and is stored for a certain period of time in accordance with the internal policy and other related laws (refer to the retention and use period) and then destroyed.

5. Consignment of personal information processing

Nespresso is consigning the processing of personal information necessary to provide services as follows. Nespresso stipulates necessary matters to ensure that personal information can be safely processed during consignment contracts in accordance with relevant laws and regulations.
Consignment Company Scope of Work for Consignment
Gaeasoft Corp Digital marketing work
ValuePoint Corp. Sending direct mail to online and offline members
Jconcompany Co., Ltd. Sending SMS/E-Mail to on-offline members, etc.
NHN KCP Corp. Credit card, mobile phone payment, real-time account transfer payment
Taeeun Inc. Product packing and Order delivery processing
Ubase, Inc. Customer services & Coffee Machine After service agency
Valex Document storage for offline members
Joohee Logis Co., Ltd. Order delivery service agency
CJ Logistics Order delivery service agency
Ilyang Logistics Order delivery service agency
Fermi Co., Ltd. Video consultation solution for customer service
Hummingn IMC Sending DM, SMS/E-Mail to on-offline members, etc.
EMBRAIN Service of DM, SMS, Email communication and customer satisfaction survey
OHJIN CORPORATION Machine installation and A/S service agency.
Cybersource Operation of e-commerce platform and prevention of fraudulent transactions
Adyen B.V. Credit card payment agency when saving credit card information
HiQ System Co.,Ltd Coffee Machine After service agency
Microsoft Azure Store invoices in electronic document

The company can consign the processing of personal information to a third party in order to provide useful information such as new product introductions and event information to users, and in such cases, a separate consent procedure shall be taken. You may not agree to the consignment of personal information processing, but if you do not agree, we will not be able to provide services that requires consignment such as identity verification, authentication, customer information analysis, product shipping service, etc.

6. Rights of users and legal representatives and how to exercise them

Users and legal representatives can view or modify their registered personal information or the personal information of children under the age of 14 at any time using the brand homepage, and may request termination of subscription.

To view or modify personal information of users or children under the age of 14, you can request 'change personal information' (or 'modify member information') or cancellation of subscription (withdrawal of consent) and deletion through Nespresso Club (080-734-111). After going through the identity verification process, you can directly view, correct or withdraw.

If a user requests correction of errors in personal information, the personal information will not be used or provided until the correction is completed. In addition, if incorrect personal information has already been provided to a third party, the result of the correction will be notified to the third party without delay so that correction can be made.

The Company handles personal information canceled or deleted at the request of a user or legal representative as specified in "3. Period of retention and use of personal information" and processes it so that it cannot be viewed or used for any other purpose.

7. Technical and Administrative Measures for Personal Information Protection

Nespresso works for or on behalf of Nespresso and takes all reasonable steps to ensure that your data cannot be obtained by any entity other than third parties who have agreed to keep your data confidential and secure.

A. Administrative Measures
Nespresso strives to protect your personal information by establishing an internal management plan and providing regular training to employees. Access to your data will be conducted only when necessary and limited to a subset of Nespresso employees who are trained to adhere to strict standards for confidentiality in handling your data.
B. Technical Measures
Nespresso uses a data network protected by industry standard firewall and password security in order to maintain the security and confidentiality of the data Nespresso collects. However, despite Nespresso's efforts to build a secure and reliable website for visits, the Internet is generally not considered a completely secure environment, therefore, please be aware that Nespresso cannot guarantee the confidentiality of the data you provide or the material you transmit through the Nespresso website or via email. Therefore Nespresso cannot be responsible for the security of your data as it is transferred to Nespresso over the internet.
C. Physical Measures
Nespresso takes safeguards to prevent physical access to your personal information through access controls such as physical locks on your personal information processing system, computer rooms, and document storage locations.

8. Matters concerning the installation, operation and refusal of cookies

In the process of using services and business processing, user name and password, web browser and OS type, access log, IP address, advertising ID, cookie, visit date, service use record, member information processed by the business operator for marketing purposes, etc. may be generated and collected.

We process anonymous data to improve the content of the Nespresso website, optimize the website for website visitors, and understand visitor status and website usage. When performing these activities, Nespresso may use tracking technology (“cookies”) to collect anonymous information such as browser type, operating system, and date and time of access. “Cookies” by themselves cannot be used to identify the user. Cookies are small pieces of information that are sent to your browser and stored on your computer's hard drive.

Users have the option of installing cookies. Therefore, the user may allow all cookies, check each time a cookie is saved, or refuse to save all cookies by setting options in the web browser. However, if you refuse to store cookies, it may be difficult to use some online shop services that require login.

9. Matters concerning provision of personal information to third parties

In principle, Nespresso does not disclose users' personal information to the outside. However, the following cases are exceptions:
  • When the user who is the subject of personal information agrees to provide in advance
  • In accordance with the provisions of the law or at the request of an investigative agency for the purpose of investigation in accordance with the procedures and methods specified in the law
  • When the information subject or its legal representative is in a state where it is not possible to express his or her intention, or when prior consent cannot be obtained due to an unknown address, etc. and it is clearly deemed necessary for the benefit of the imminent life, body or property of the information subject or a third party

10. Transfer of personal information to overseas

As a multinational brand, Nespresso maintains a database within various jurisdictions. Nespresso may transfer your data to destinations located outside of your country of residence, i.e. to one of these databases, a member of the Nespresso group, or to a partner that has agreed to keep your data confidential and secure. Nespresso guarantees that the data sent to the database in that country will be protected at the same level, and will strive to prevent data from being transferred to third parties in these countries. By providing your data, you are considered to be expressly consenting to the transfer of personal data outside the country for this purpose, which may result in data transfers to Nespresso Group affiliates/partners. Its specific details are as follows.

Items of personal information transferred Country Date of Transfer Method of Transfer Receiving corporation Privacy officer of the receiving corporation Purpose of use of receiving corporation Retention/use period of receiving corporation
Name, Email, phone number, address Switzerland At the time of Member registration Overseas transfer through electronic method Nestle Nespresso S.A Robert Lineke, Information Security Program Manager Nespresso Club member service provision contract fulfillment and service provision fee settlement, membership management and customer claims handling UUntil Nespresso Club member withdrawal and the purpose of collecting and using personal information is achieved
Card number, Card expiration date, Card holder name, First two digits of card password, 8 digits of date of birth or Business registration number Netherlands When saving credit card information Overseas transfer through electronic method ADYEN B.V. Joop Wijn Credit card payment agency business Until Nespresso Club member withdrawal and the purpose of collecting and using personal information is achieved
Card number, Card expiration date, Name of holder US and UK When settlement Overseas transfer through electronic method Cybersource Zou Nora, IT manager Fulfillment of contracts such as product supply and payment Until Nespresso Club member withdrawal and the purpose of collecting and using personal information is achieved
Name, Address, Phone number Netherlands At the time of an order confirmation Overseas transfer through electronic method Microsoft Azure Scott McLean (Privacy Officer for all EU regions) Store invoices in electronic document Until Nespresso Club member withdrawal and the purpose of collecting and using personal information is achieved

11. Privacy Officer and related departments

Nespresso appoints the following departments and Privacy Officers to protect users' personal information and handle complaints related to personal information.

[Nestle Korea Chief of Privacy Officer]
Name: Park, Keun Won

[Nespresso Business Unit Privacy Officer]
Name: Min, Jae Yong

[Nespresso Club]
Contact: 080-734-1113

If you need to report or consult about other personal information infringement, please contact the following organizations.
  • Report Center for Personal Information Breach (Korea Internet & Security Agency) (privacy.kisa.or.kr / 02-405-5118)
  • Personal Information Dispute Mediation Committee (www.kopico.go.kr / 1833-6972)
  • OPA PRIVACY (www.eprivacy.or.kr / 02-550-9531~2)
  • Korean National Police Agency Cyberbureau (www.ctrc.go.kr / 182)
  • Supreme Prosecutors' Office Advanced Crime Investigation Center (http://www.spo.go.kr / 02-3480-2000)
  • National Police Agency Cyber Terror Response Center (www.ctrc.go.kr / 02-392-0330)

12. Notification obligations due to policy changes

Nespresso Privacy Policy was enacted on September 01, 2013, and in the event of addition, deletion, or modification of the contents according to changes in laws, policies or technologies, we will notify the changed Privacy Policy through the brand homepage.
  • Privacy Policy Last updated: September 8, 2020
  • Privacy Policy Effective Date: June 1, 2014

Nestle Korea Limited Liability Company Nespresso Business Unit
Nestle Korea Nespresso S.A. All rights reserved.