Terms of Use
Data Privacy Policy
Introduction & General Terms
PepsiCo Singapore (‘PepsiCo’, ‘we’ or ‘us’, 'our'), cares about your privacy and is committed to protecting your personal data to the best of our ability.
This PepsiCo Singapore privacy policy (the ‘Privacy Policy’) provides information on what personal data PepsiCo may collect from you, the basis on which PepsiCo may process your personal data and for what purpose, when PepsiCo may disclose or transfer collected your personal data about you, the international transfer of your personal data, when PepsiCo may notify you of the purpose of our collection of your personal data, the sources of your personal data, how long your personal data may be retained for, how your personal data may be protected, how you may contact us, and your rights under the Personal Data Protection Act 2012 (the ‘PDPA’).
For the purposes of this Privacy Policy, “personal data” is defined in accordance with s 2 of the PDPA as data, whether true or not, about an individual who can be identified –
a) from that data; or
b) from that data and other information to which the organization has or is likely to have access.
Please carefully read our Privacy Policy to understand your rights to your collected personal data.
PepsiCo’s website may contain hyperlinks to websites owned and operated by third parties. These third party websites are subject to their own privacy policies and are also likely to use cookies. PepsiCo recommend that you review these policies which will govern the use of your personal data which be collected when visiting these websites, including but not limited to cookies, personal data that you may provide, and IP addresses. PepsiCo does not accept any liability arising from your use of such third party websites.
1. What personal data PepsiCo may collect from you?
When you engage in any business or transaction with PepsiCo or participate in, access, sign up to, or participate in any of PepsiCo’s services, activities or online contents (including those posted on social media and/or accessed via messaging applications), such as newsletters, promotions, live chats, message boards, website and mobile notifications or votes, PepsiCo may collect or receive personal data relating to you. This may include but is not necessarily limited to your name and surname, email address, postal address, telephone or mobile number, gender, nationality, date of birth, educational background, occupation, marital status, photo, bank account detail, as well as information collected about your use of PepsiCo’s services, such as what you read, watched or did on our website, app or when using our other services.
Some of our services enable you to sign-in via third party service providers, such as Facebook, Twitter and Instagram. If you choose to sign-in via a third party service provider, you will be presented with a dialog box which will ask your permission to allow PepsiCo to access your personal data (e.g. your name and surname, date of birth, email address) or any other information that you have made publicly accessible on the third party.
PepsiCo also collects information about how you use the PepsiCo mobile app, PepsiCo website or other PepsiCo content online, and the device(s) you use to access the services as well as unique online identifiers such as IP addresses, which are numbers that can uniquely identify a specific computer or other network device on the internet.
2. What is the basis on which PepsiCo process your collected personal data, and for what purpose?
PepsiCo will collect, use or disclose personal data in accordance with this Privacy Policy and with your consent or deemed consent. If PepsiCo cannot provide a service or product without your consent to process your personal data, PepsiCo will make this clear when PepsiCo asks for your consent or before collecting your personal data.
We may also collect, use or disclose personal data without your consent if this is required or authorised under the applicable laws, including but not limited to the following:
-
the collection, use or disclosure (as the case may be) of personal data is solely for archival or historical purposes, or solely for artistic or literary purposes;
-
the collection, use or disclosure (as the case may be) of your personal data is necessary to protect your or another person’s vital interests, e.g. responding to emergency, incidents affecting health or safety, contacting next-of-kin or friend of any injured, ill or deceased individual;
-
the collection, use or disclosure (as the case may be) of your personal data is in the national interest;
-
the collection, use or disclosure (as the case may be) of your personal data is necessary for PepsiCo to obtain legal services;
-
when PepsiCo has assessed that the collection, use or disclosure (as the case may be) of your personal data is in the legitimate interests of the organisation or another person and the organisation’s legitimate interests outweigh any adverse effect on you; and
-
the collection, use or disclosure of your personal data is necessary for any investigation or proceedings.
PepsiCo may collect, use or disclose your personal data for a number of purposes including the following:
2.1 Our contract with you
PepsiCo will collect, use and disclose your personal data in accordance with the contract between you and us, and for the following reasons:
-
Delivering products and/or services to you or procuring them from you;
-
Administering, implementing, maintaining, managing and operating our products and/or services;
-
Processing, assessing and determining any applications or requests made by you in connection with our products and/or services;
-
Issuing or executing contracts and maintaining your account with us;
-
Exercising rights or performing obligations under executed contracts; or
-
Participating in activities such as consumer promotions organized by or on behalf of us.
2.2 Provision of Services
PepsiCo will collect, use and disclose your personal data for the purposes of providing our services, activities or online contents. This would include, for example:
-
communicating information about our services, activities or online contents (e.g. relating to upcoming promotions or new product launches) or dealing with your requests and enquiries;
-
service administration, which means that PepsiCo may contact you for reasons related to the business, transaction, service, activity or online content you have executed or signed up for (e.g. notifying you about the administration of a promotion that you have participated in, or notifying you that a particular service, activity or online content has been suspended for maintenance or updating our Privacy Policy);
-
customising the content that you see on our website and app, and the advertising that you see on our website, app, or other sites and services;
-
working with third parties to show you relevant advertising on that third party websites;
-
contacting you about any submission you have made;
-
using IP addresses and device identifiers to identify the location of users, blocking disruptive use, establishing the number of visits from different countries, tailoring the content of our website, app or other services based on browsing behaviours, and determining which country you are accessing the services from;
-
analysis and research so that PepsiCo may improve the services offered by PepsiCo;
-
investigating suspected misconduct activities reported by or against you or third party via PepsiCo Speak Up Hotline including enquiring those who witnessed the misconduct activities; or
-
conducting a third-party due diligence (TPDD) against you to find out any corruption and for our Global Anti-Bribery Compliance Policy including investigation via public sources.
2.3 Legal obligations
PepsiCo may process your personal data when it is necessary for compliance with any legal obligations to which PepsiCo is subject.
2.4 Legal claims
PepsiCo may process your personal data when it is necessary to establish, comply, exercise or defend legal claims against you or initiate litigation action to protect our interests.
3. When will PepsiCo disclose or transfer collected personal data about you?
PepsiCo may from time to time disclose or transfer your collected personal data to other entities in the PepsiCo group or to third parties for any of the purposes listed in item 2. Examples of relevant third parties to whom PepsiCo may disclose or transfer your collected personal data include governmental agencies and private sectors or third parties who perform services on our behalf, such as web hosting providers, payment providers, customer relationship management providers, marketing partners, media and fulfilment partners, and website analytics providers.
When PepsiCo discloses or transfers your collected personal data to third parties who perform services on our behalf or in connection with the goods and services that PepsiCo provides, PepsiCo ensures that such service providers use your collected personal data only in accordance with our instructions, and PepsiCo does not authorise them to use, disclose or transfer your collected personal data except as necessary to perform services on our behalf or to comply with any applicable legal obligations. In this regard, PepsiCo will ensure that the third parties are held to at least a reasonable standard with regard to their data protection obligations, such as reasonable safeguards of the personal data in their possession.
PepsiCo may also disclose or transfer your collected personal data to third parties in the circumstances as follows:
-
where the disclosure or transfer is required by any applicable law or to comply with a specific order from any competent authority;
-
where the disclosure or transfer is required for the purposes of, or in connection with, any legal proceedings, or otherwise for the purpose of establishing, exercising or defending our legal rights;
-
where the disclosure is required by law enforcement authorities or other government agencies who have issued a lawful disclosure request for the personal data;
-
where PepsiCo believe the disclosure is necessary to prevent harm or financial loss, or in connection with an investigation of suspected or actual criminal activity; or
-
where PepsiCo sell or transfer all or a portion of our business or assets (including through a merger, reorganisation, spin-off, dissolution or liquidation).
4. International transfer of personal data
Due to the global nature of our operations, PepsiCo deals with many international organisations and uses global information systems; as a result, PepsiCo may disclose or transfer your collected personal data to group companies located in countries or territories outside Singapore whose data protection laws may not be the same or as extensive as those in Singapore.
PepsiCo will only disclose or transfer your collected personal data to a recipient in a country or territory outside Singapore which is bound by legally enforceable obligations to provide the personal data transferred a standard of protection that is comparable to that under the PDPA.
Where such data security standards are deemed inadequate, PepsiCo will nevertheless provide appropriate safeguards to protect your interest and will only disclose or transfer the personal data if:
-
you have explicitly consented to the transfer after having been informed of the possible risks of such transfer to that recipient in that country or territory;
-
you are deemed to have consented to the disclosure by PepsiCo to the recipient under the applicable laws relating to deemed consent;
-
the transfer is necessary for the performance of a contract between you and PepsiCo, or to do anything at your request with a view to you entering into a contract with PepsiCo;
-
the transfer is necessary for the conclusion or performance of a contract between PepsiCo and a third party which is entered into at your request, or which a reasonable person would consider to be in your interest;
-
the transfer is necessary for a use or disclosure in certain situations where your consent is not required under the PDPA, such as those as set out in Section 2 of this Privacy Policy above, e.g. when use or disclosure is necessary to respond to an emergency that threatens your or another person’s life, health or safety; in such cases we will take reasonable steps to ensure that the personal data will not be used or disclosed by the recipient for any other purposes;
-
the personal data is data in transit; or
-
the personal data is publicly available in Singapore.
5. Notification of the purpose for our collection of your personal data
Before PepsiCo collects your personal data, and at the time of obtaining consent for such collection and subsequent use and/or disclosure, we will always notify you about our purpose of doing the same. Only in some circumstances, it is not necessary for us to inform you of our purpose of processing, such as when:
-
you are deemed to have provide your consent to the collection, use and disclosure of your personal data; or
-
PepsiCo is permitted to collect, use and/or disclose your personal data without consent in accordance with the PDPA.
6. Sources of your personal data
PepsiCo will collect your personal data directly from you and sometimes may collect personal data from publicly available sources and/or from third parties In the latter case, PepsiCo will ensure that the disclosure of your personal data by the third party to PepsiCo fully complies with the PDPA.
7. Your rights
The PDPA aims to give you more control of your personal data. You have legal rights concerning your collected personal data which includes:
7.1 Right to access
You have the right to request access to your personal data that is in PepsiCo’s possession. You may also request for information about the ways in which the personal data you have requested has been or may have been used or disclosed within a year before the date of your request. This right to access is subject to the exceptions in the PDPA accordingly.
Where necessary, PepsiCo may request for the payment of a small sum to process the request for access made by an individual.
7.2 Right to data portability
You have the right to request us to transfer your collected personal data to other persons/organisations, or request to see your collected personal data that PepsiCo have transferred to other persons/organisations, unless it is impossible for us to carry out your request due to technical circumstances.
7.3 Right to correction
You have the right to request PepsiCo to correct any inaccurate personal data in order to make it accurate, up-to-date, complete and not misleading, unless there are exceptions in the PDPA. If PepsiCo rejects your request, such rejection will be based on reasonable grounds and we will record such rejection with reasons.
PepsiCo will also send the corrected personal data to every other organisation to which we had disclosed the personal data within a year before the date the correction is made, unless that other organisation does not require the corrected personal data for any legal or business purpose.
7.4 Right to lodge a complaint
You have the right to make a complaint in the case of where PepsiCo data processors such as our employees or contractors do not comply with the PDPA.
7.5 Right to withdraw consent
You may withdraw your consent at any time, unless PepsiCo have a lawful basis to deny your request.
If you change your mind about how you would like us to have or process your personal data and would like to withdraw your consent, you can tell us anytime by requesting the withdrawal of your consent via email at asia.privacy@pepsico.com . Where relevant, we will inform you of the likely consequences of your withdrawal prior to processing your request. Once your consent has been withdrawn, we will cease collecting, using or disclosing the personal data unless it is required or authorised under any applicable laws.
8. Data retention period
PepsiCo will retain your collected personal data for as long the purpose for which the personal data was collected is still being served by the retention, or if retention remains necessary for any legal or business purpose. We may also be required or permitted by applicable laws to retain the personal data for a longer period after there are no more purposes for which the personal data may serve. If PepsiCo needs to keep your collected personal data for a longer period to comply with the legal obligation, or if some existing claims or complaints will reasonably require us to keep your collected personal data or for regulatory or technical reasons, PepsiCo will continue to protect that collected personal data.
Generally, if you provide your personal data to enter into a promotion, PepsiCo will only keep your collected personal data for as long as is necessary for the administration of that promotion.
If you sign up for our email newsletters or marketing communications, PepsiCo will keep your collected personal data until such time as you request that your collected personal data be deleted (if you elect to unsubscribe at any time then PepsiCo will generally retain some of your personal data in order to ensure that you are not contacted again).
PepsiCo may need to retain images and video footages from CCTV surveillance systems installed for security and safety of persons within our premises for 60 days.
9. Data security
PepsiCo uses a range of measures to keep your collected personal data safe and secure, which may include encryption and other forms of security. PepsiCo require our employees and third parties who carry out work on our behalf to comply with the PDPA and the appropriate privacy standards including obligations to protect any leakage of information and to apply appropriate security measures for the processing of information.
10. Changes to this Privacy Policy
PepsiCo reserves the right to change, amend or update the privacy policy at any time as PepsiCo deems appropriate by notifying you of the said change, amendment or update on our website (if applicable) or you could contact us at asia.privacy@pepsico.com to check at any time.
11. How you can contact us
If you have any comments, suggestions, questions or want to make a complaint or exercise your rights regarding your collected personal data, please contact us at asia.privacy@pepsico.com .