Consumer Contact Center Data Protection Notice (U.S.)

We, at Ferrero, wish to provide you with the best possible consumer experience and are committed to protecting your privacy. In line with this commitment, we would like to inform you about how we will be processing your personal data in the context of the activities of our Consumer Contact Centers, as detailed in this information notice (the “Notice”).

1. Who are we?
Ferrero U.S.A., Inc. with its headquarters at 7 Sylvan Way, Parsippany NJ 07054 (hereafter, “Ferrero” or “we”). When collecting and processing personal data for consumer care purposes, Ferrero acts as a data controller.

If you have any questions on the processing of your personal data or if you wish to exercise any of your data protection rights, feel free to contact Ferrero at its corresponding privacy email address: privacy.us@ferrero.com.

2. What personal data do we collect?

(a) Information we collect directly from you
We process the personal data that you directly provide to us when you get in contact with our Consumer Contact Center. This includes:
• your first and last name
• the country where you are located
• your email address
• whether you are above 18 years of age
• the details of your question, comment or the issue which you are reporting to us.

You may also provide your telephone number, postal address or any other information that you find relevant on a voluntary basis.

Some personal data is essential for our Consumer Contact Center to be able to handle your request. If you contact us by telephone, the operator will specify what personal data is required from you at the time of first contact (most likely, your name and contact details). If you contact us in writing, mandatory fields may be marked as such in a corresponding online form.

When you ask a question, formulate a comment or report an issue to our Consumer Contact Center, we kindly ask you to refrain from sharing any information relating to other individuals, unless you are lawfully entitled to do so, for example in your capacity as a parent or legal guardian of a child, or when you have obtained the express consent of the concerned individual(s).

(a) Information we collect from other sources

Ferrero may obtain information on consumer satisfaction, comments, concerns or issues from other sources, as well. In particular, in the context of our consumer care activities, we may collect information from social media (e.g., if you post a question on the social media fan page of Nutella or another Ferrero product) and e-commerce platforms (e.g., if you post a public review on an e-commerce platform).

In addition, Ferrero may collect information relating to consumer care from other persons. In particular, we may receive information from:
• our trade partners (e.g., a supermarket where you bought a Ferrero product may inform us about a comment, concern or issue raised by you)
• our consumer care partners (e.g., a consumer care agent may forward us a complaint or comment which you posted on social media)
• other companies or departments from the Ferrero Group (e.g., you may have by mistake contacted the Consumer Contact Center of Ferrero in another country, or the wrong department, in which case our colleague will forward us your communication).
Protecting the privacy of consumers is a key aspect of our relationship with our trade partners and service providers. This is why we only collect and process information from them when necessary to achieve a legitimate purpose (e.g., consumer protection), in compliance with all data protection and privacy rules.

3. What about sensitive personal data?
In general, we kindly ask you to refrain from sharing any sensitive personal data with our Consumer Contact Center when this is not necessary for answering your request or concern.

Sensitive personal data include information relating to your health and financial data, ethnic and racial origins, political opinions, genetic and biometric data, sexual orientation, and religious or philosophical beliefs.

In some instances, we understand that you may voluntarily or inadvertently share sensitive personal data with us when asking a question, formulating a comment or reporting an issue (for example, question on allergens). If processing sensitive personal data is necessary for answering your request or properly addressing the issue reported to us, we will make sure to obtain your explicit consent before doing so.

Similarly, when we collect sensitive personal data from other sources, such as from our trade partners (e.g., a supermarket selling Ferrero products), we will make sure that such collection is lawful (e.g., you have explicitly consented to it).

Be assured that we will treat any sensitive personal data with the highest level of confidentiality and in accordance with all applicable laws.

4. What are the purposes and legal bases of the processing?
In the context of the activities of our Consumer Contact Center, we will process your personal data only for specific and legitimate purposes. Each purpose and its legal basis are described in the table below:
Purpose Legal basis

For personal data in general

1. for acknowledging receipt and/or providing an answer to your question(s) or comment(s) the performance of the services provided by the Consumer Contact Center at your request
2. for handling, mitigating the risk of, or solving the issue(s) that you are reporting to Ferrero the legitimate interests pursued by Ferrero to appropriately address any issue relating to the activities of Ferrero or of any company of the Ferrero Group
3. for complying with Ferrero’s internal policies and procedures and/or for improving our procedures, products or services (including in relation to safety, quality, group reporting, audit or certification) the legitimate interests pursued by Ferrero to prevent further incident and to improve the procedures, products and services of Ferrero or of any company of the Ferrero Group
4. for defending the general interests of Ferrero or any entity of the Ferrero Group, including protecting their reputation or defending their position in the context of a claim or dispute The legitimate interests pursued by Ferrero to defend the financial, reputational or other general interests of Ferrero or of any entity of the Ferrero Group
5. for compliance with all applicable laws and regulations, including product liability, health and safety regulations processing is necessary for compliance with a legal obligation to which the controller is subject
6. for liaising or cooperating with the competent public health authorities or food safety authorities processing is necessary for compliance with a legal obligation, or with the performance of a task carried out in the public interest
7. for training purpose or for improving the quality of our services when you have contacted us by telephone (recording of phone calls) your consent and the legitimate interest of Ferrero to improve the quality of our consumer care services

For sensitive personal data (e.g., health data)

8. for answering your request, handling your complaint or addressing an issue relating to our products, brands or services (e.g., question or issue on allergens) your explicit consent (through a separate consent request) or the fact you manifestly made these personal data public (e.g., post on social media)
9. for addressing a serious health risk to an individual (e.g., for informing emergency responses services in the event of a severe allergic reaction) processing is necessary in order to protect the vital interests of an individual
10. for addressing a significant health or sanitary risk in accordance with food safety regulations or public health policies (e.g., product recall procedure due to a (risk of) contamination) processing is necessary for reasons of public interest in the area of public health
11. for defending the legal, financial or reputational interests of Ferrero or any entity of the Ferrero Group in the context of a dispute or litigation for the establishment, exercise or defence of a legal claim by Ferrero or any other entity of the Ferrero Group

5. How long do we keep your personal data?
Your personal data are kept for no longer than necessary for achieving the above-mentioned purposes. In particular, the following retention periods generally apply:
• 3 months for the recordings of calls when you have contacted us via telephone.
• 12 months in case of general comments or inquiries linked to our activities, products or brands (e.g., availability of a certain product in a certain country), which are not related to the quality of our products or services.
• 24 months in case of comments or reports on the quality of our products or services (e.g., complaint about the freshness of a Ferrero product; information on a product shortage; report on a Ferrero website failure; etc.).
• 10 years in case of comments or reports which are considered as critical and may lead to liability (e.g., hospitalization, choking, or other critical events).

In the event the provided information leads to a claim, dispute or legal proceedings, the above-mentioned retention periods may be extended. In particular, your personal data will be kept until the issue is fully resolved (e.g., final solution, settlement, decision or judgment), and may further be archived in accordance with applicable law.

6. With whom do we share your personal data?
Ferrero is committed to ensuring the confidentiality of your personal data. Among other measures, the employees of our Consumer Contact Center are subject to an obligation of confidentiality and will only share your personal data with a limited number of relevant persons (the “Recipients”) whose involvement is necessary for achieving one of the above-mentioned purposes.

In particular, your personal data may be shared with the following Recipients:
• The employee(s) of the Consumer Contact Center receiving your question, comment or complaint, in order to be able to provide you with an answer or address the issue.
• Other department(s) of Ferrero whose involvement is necessary for answering your request, handling your complaint or addressing the issue (e.g., if your report a Product quality issue, with the Food Safety & Quality department of the concerned companies of the Ferrero Group).
• With the supplier, service provider, distributor or vendor whose involvement is necessary for answering your request or addressing the issue reported by you (e.g., if you report an issue on the freshness of a Ferrero product in a specific point of sale, we may contact the vendor).
• With the competent public authority or authorities, where required to do so by law (e.g., when Ferrero must cooperate with the competent food safety authority).
• With our auditors, legal consultants, lawyers or the competent public authorities or courts, whenever necessary for Ferrero or a company of the Ferrero Group to comply with internal policies, with the law or for establishing or defending a legal claim (including in the context of judicial proceedings).

In order to protect your privacy, your personal data will be anonymized or pseudonymized before being shared with the relevant Recipients whenever possible (i.e., whenever this would not defeat the purpose of the processing).

7. Do we transfer your personal data to another country?
As a general rule, your request will only be handled by the Consumer Contact Center to which you reached out. However, your personal data may be transferred to Recipients located in another country. Most notably, the servers of our consumer care database are located in Italy.

Ferrero will ensure that your personal data are always transferred in a secure and lawful manner. In particular, if you are located in the European Economic Area (EEA) and your personal data need to be transferred outside of the EEA, in a country that is not offering an adequate level of data protection, Ferrero undertakes to adopt an appropriate transfer tool, as well as supplementary measures where necessary (e.g., encryption).

8. What are your data protection rights?
Depending on the state in which you live, you may have several rights in relation to the processing of your personal data.

In particular, you may have the right:

• to obtain additional information or clarifications on the processing of your personal data, and to obtain a copy of your personal data.

• to request the correction of your personal data if they are inaccurate or incomplete.

• to object to the processing of your personal data on grounds relating to your particular situation whenever the processing is based on one of our legitimate interests.

• to obtain restriction of processing from us (i.e., temporary suspension of the processing) while we assess the validity of another request relating to your personal data

• to data portability whenever you have provided us with personal data (i.e., the right to receive your personal data in a commonly used and machine-readable format and transmit them to another controller).

• the right to request the erasure of your personal data.

• to withdraw your consent, whenever your personal data have been collected or are being processed based on your consent.

You may exercise these rights by contacting us in writing at privacy.us@ferrero.com. We will analyze your request and get back to you with an answer as soon as possible.

In the event you believe that Ferrero did not handle your request properly or infringed the applicable data protection law, you may file a complaint with any competent data protection authority.

9. General information
This Notice was last updated in January 2024. From time to time, Ferrero will amend this Notice. Ferrero therefore invites you to regularly visit this page in order to stay up to date.