BUSINESS CUSTOMER, BUSINESS PARTNER, VENDOR AND SUPPLIER PRIVACY NOTICE
YOUR PRIVACY IS IMPORTANT TO US!! Please read the following Privacy Notice to learn about how Binzagr Unilever Distribution Company Limited & Binzagr Unilever Limited collects and processes the personal data/information of individuals associated with organizations working and partnering with Us. This Privacy notice will not only inform you of the Personal Data we collect, but also the purpose for which it is collected, your corresponding rights with respect to the same.
BACKGROUND
Hindustan Unilever Limited (“HUL” or “Unilever” or “We” or “Us”) has always been at the forefront to support and work collaboratively with our distributive trade/customers (retailers, wholesalers, sales partners, etc.), vendors, suppliers, and business partners towards administrative and operational efficiency to improve our and their products/services, and effectively compete in the market.
In furtherance of the same, while working with us, organizations, and individuals such as your employees, contractors, personnel, etc. associated with them, are required to share information, including personal d. When we use personal data, we do so with integrity and transparency, upholding the rights of the individual in accordance with our values and the law. This helps us to build and maintain trust, which enables us to create meaningful, closer, and long-lasting relationships, with our customers, partners, and suppliers.
RESPONSIBILITIES OF ORGANIZATIONS WORKING WITH US
As you would be providing the Personal Data of individuals associated with you (such as employees, contractors, agents, partners, consultants, personnel, etc.) for a commercial/business engagement with Us, you shall ensure that such data is accurate and updated. You are also responsible for compliance with applicable laws, including PDPL and should inform the individuals sufficiently about the processing, including this Privacy Notice and obtain their clear, explicit and free consent, prior to sharing such information on their behalf.
COMPLIANCE WITH PDPL:
We expect that you will take all necessary measures to comply with the PDPL.
PERSONAL DATA WE COLLECT
We collect Personal Data necessary for the purposes outlined in this notice, including but not limited to: contact details (e.g., name, phone number, email address), identification data, payment information, and any other data explicitly provided by you.
PURPOSE
We collect and process your Personal Data for specific and legitimate purposes, such as delivering services or products, managing business relationships, ensuring compliance with legal obligations, and improving user experience. Any processing beyond these purposes will be conducted only with your explicit consent or as permitted by the PDPL and/or any other applicable data protection law. DATA MINIMIZATION PRACTICES
We ensure that we collect only the minimum amount of Personal Data necessary to achieve specific purposes. Our regular reviews of collected data ensure compliance with this principle by removing redundant or outdated information. This helps safeguard your privacy and ensures compliance with PDPL.
CONSENT MANAGEMENT
We obtain your free, clear and explicit consent for processing your Personal Data where required by law, particularly for sensitive data. You may withdraw your consent at any time by contacting our DPO at [maha.alkhraijy@unilever.com]. Withdrawal will not affect the lawfulness of processing conducted prior to the withdrawal. We will confirm the withdrawal within 30 business days and implement necessary actions to cease processing your data where applicable.
EXERCISING YOUR DATA RIGHTS:
You have the right to:
- Access your personal data.
- Correct inaccuracies or update incomplete data.
- Request deletion of your data when no longer needed or when processing is unlawful.
- Object to or restrict certain processing activities.
To exercise your rights, please submit a request to our DPO using the details stated herein. We will acknowledge your request within 30 business days and provide a substantive response within 30 business days.
SHARING OF DATA OUTSIDE UNILEVER
Personal Data may be shared with third parties, such as service providers, business partners, or legal authorities, where necessary to fulfill the purposes outlined in this notice. We ensure that such disclosures are compliant with the PDPL and are limited to the minimum data required for these purposes. We conduct assessments to ensure that recipients adhere to equivalent privacy and data protection standards.
INTERNATIONAL DATA TRANSFER
When We transfer your Personal Data internationally, We ensure that such transfers comply with the regulatory requirements of the PDPL . We ensure that such jurisdictions have an adequate level of data protection. If a jurisdiction does not have adequate level of data protection, we implement appropriate safeguards, such as Standard Contractual Clauses, binding corporate rules, or obtaining necessary approvals from the competent authority to ensure the data receives equivalent protection.
PROTECTING YOUR DATA
We implement robust technical, administrative, and organizational measures to protect your Personal Data against unauthorized access, alteration, or destruction. Measures include encryption, access controls, data pseudonymization, and regular audits. We comply with cybersecurity regulatory standards, such as the standards of National Cybersecurity Authority of Saudi Arabia, to ensure the highest level of data security.
DATA ANONYMIZATION AND PSEUDONYMIZATION
Where applicable, We anonymize or pseudonymize your Personal Data to ensure privacy. Anonymization renders the data irreversible, while pseudonymization substitutes identifiers to minimize identification risks. These techniques are applied in compliance with legal standards, particularly for research, analytics, or archival purposes.
HOW LONG DO WE KEEP YOUR PERSONAL DATA
Personal Data will be retained only as long as necessary to fulfil its original purpose, comply with legal requirements, or resolve disputes. Once the purpose ceases, data will be securely deleted or anonymized, except where retention is legally mandated. Specific retention periods are documented and can be shared upon request.
YOUR RIGHTS PERTAINING TO PERSONAL DATA
Under the PDPL you have the right to access, correct, update, erase, or object to the processing of your Personal Data. You may also withdraw consent or request the transfer of your data to another entity where technically feasible. To exercise these rights, please contact us using the details provided below. We will respond within 30 days, in accordance with applicable regulations.DATA BREACH NOTIFICATION
In the event of a Personal Data breach that may pose a risk to your rights or freedoms, we will notify affected individuals and the relevant regulatory authority within 72 hours of becoming aware of the breach. Notifications will include:
- A description of the breach and its likely consequences.
- Actions taken to mitigate the breach and recommendations for protecting your data.
- Contact details for further inquiries.
CONTACT US (FOR QUERIES, GRIEVANCES AND DATA PRINCIPAL RIGHTS):
For any questions, grievances, or to exercise your data rights under “PDPL and/or any other data protection law, please contact our Data Protection Officer at:
Email: maha.alkhraijy@unilever.com
We are committed to resolving your concerns in a timely and transparent manner.
UPDATION OF NOTICE
Last Updated: Sep 2024