Privacy Statement

This statement explains what personal data we process, why we process it, who receives it, and how you can exercise your legal rights.

In this Privacy Statement, “personal data” means any information which directly or indirectly identifies you as a person (like the combination of your full name and address). Similarly, “processing” means any operation performed on your personal data, for example the collection, storage, use, disclosure, or destruction.

1. Who are we and how can you reach us? 1

2. What categories of personal data do we process? 2

3. What do we do with your personal data? 2

4. Who will receive your data and under what circumstances? 13

5. How do we transfer your personal data to other countries? 14

6. What are your legal rights? 15

7. How long do we keep your data? 17

8. How do we use algorithmic decision making? 17

9. How do we use artificial intelligence? 17

10. How can I delete my account? 18

11. Changes to this privacy statement 18

1. Who are we and how can you reach us?

We are Delivery Hero Czech Republic s.r.o., located at Smrčkova 2485/4, Libeň, 180 00 Praha, Czech Republic.

As regards your privacy, it is us who decides how and for what purposes your personal data is processed. In data protection language that makes us the “data controller”.

If you have any questions related to how your personal data is processed, you can contact us at dpo@foodora.cz. If you would like to reach our data protection officer, please contact dpo@deliveryhero.com.

2. What categories of personal data do we process?

We process personal data provided by you, collected from your device when you interact with us or obtained from third parties. Broadly speaking we will process the following categories:

Account data

including your name, email address, password, telephone number, country, communication and other profile settings.

Order and delivery data

including delivery details, order history, product names and quantities.

Location data

including address, postcode, city, country, longitude and latitude.

Device data

including IP address, session information, device configuration settings, platform interactions such as items added to the cart, and other data obtained through web-trackers (e.g. cookies, SDKs, pixels).

Payment data

including payment method data, payment amount, payment recipient details, payment instrument details such as expiration date, payment confirmation, refund details, and bank receipts.

Customer support data

including content of your customer support requests, response from our customer care teams and images attached.

You can find all details about how we process your personal data below.

3. What do we do with your personal data?

A. When you create an account

• Account Creation

When creating an account we process your account data such as your name, email address, password, telephone number, country, and date of birth. This information is necessary to take the first step in establishing a customer relationship and providing you with our services.

For account security, we verify your phone number using a one-time code sent via SMS, or via WhatsApp if you actively select that option.

The legal basis for this processing is therefore “entering into or performance of a contract” under Art. 6(1)(b) GDPR.

• Single-Sign-On (“SSO”) Options

You can register using your Facebook, Google, or Apple accounts to make the sign-up and log-in process easier. If you choose this option, we may receive SSO data such as your name, email address, telephone number, country, and your date of birth. This information is necessary for initiating our customer relationship and entering into a contract with you. We never receive or store the password you use for these systems.

Information on third-party SSO providers can be found here:

Facebook https://www.facebook.com/privacy/explanation

Google https://support.google.com/accounts/answer/112802

Apple https://support.apple.com/en-us/HT204053

The legal basis for this processing is “entering into or performance of a contract” under Art. 6(1)(b) GDPR.

We process this personal data as long as you remain our customer, or until you delete your account with the SSO provider.

• Managing Your Account and Subscriptions (foodora PRO)

You can access your profile to update your details, view past orders, or manage subscription plans. To deliver these core service features, we process your account data, order and delivery data, payment data, and device data. The legal basis for managing your account and active subscriptions is ‘performance of a contract’ under Art. 6(1)(b) GDPR.

To offer customized subscription offers and plans, we may analyze your account data, location data, and order and delivery data to segment promotional campaigns. The legal basis for tailoring these subscription options is our ‘legitimate interest’ under Art. 6(1)(f) GDPR.

We store this personal data as long as you remain our customer and in the ordinary course of things we delete it after 3 years of inactivity, or when you close your account.

• Foodora Business

Through our Business service, companies can provide their employees or other individuals with vouchers, gift cards, or allowances (“Benefits”). To set this up, we receive your name, email address, and allowance rules directly from the business granting the Benefit. We use these details to ensure you can access your Benefits and to send you necessary updates.

When using group orders, we process and display the host’s first name and delivery address, along with each participant’s first name and selected items, to manage the shared basket.

The legal basis for this processing is ‘performance of a contract’ under Art. 6(1)(b) GDPR.

We retain this data for as long as you remain a customer. We typically delete this information when you close your account or after three years of inactivity, unless legal obligations require a longer retention period.

Please note that the business providing your Benefit handles your data independently; you should refer to their privacy statement for details on their practices.

B. When you browse our platform

• Cookies and Web Tracking Technologies

When you browse our platform, we use web tracking technologies (e.g., cookies, SDKs, measuring pixels) to provide our services and ensure our platform remains secure and functional. They also help us understand how you interact with us, improve our performance, and show you customized content or targeted advertising to our users.

Cookies and web tracking technologies may be used to collect data that we classify as device data, including preferences such as language settings, platform interactions such as items added to the cart, platform performance analytics, and crash reporting.

You can find more information on these technologies (including on retention periods and the applicable legal basis) in our Cookies, SDKs and Web-Tracking Policy and in our consent management banner. The consent management banner appears the first time you visit our platform, and you can always adjust your preference via our platform settings.

• Personalized Content and Suggestions

To make your experience more relevant, we may customize our platform to show you vendors nearby, past favorites, or products we believe you’ll enjoy. To make this feature available, we process your account data, location data, order and delivery data, and device data.

We also use customer segmentation, and demographic inferences (like age and gender) to highlight specific products or cuisines, such as Italian restaurants, or vegan products. These suggestions are designed to help you discover vendors and products that match your interests and they do not have any legal or similarly significant effect on you. We would like to highlight that personalized content is separate from the marketing initiatives on our platform.

The legal basis for processing your data for the purpose of customer segmentation, suggesting products and vendors is ‘legitimate interest’ under Art. 6(1)(f) GDPR.

We will retain this information for the same duration as your general account data.

C. When you place an order

• Shopping Cart and Order Processing

Once you select items, we save them in your cart so you can pick up your order right where you left off, even if you close the app. When you are ready to checkout, we process your information to ensure your delivery is successful. To receive and fulfill your order, we use your account data, device data, as well as your order and delivery data including your address, longitude and latitude, product names and quantities.

For specific products such as medicines or adult products, we may also process special categories of personal data if you have given us your prior consent. In this case, we will ensure that we clearly inform you, obtain your prior consent or otherwise comply with the requirements of Art. 9 GDPR.

The legal basis for this processing is ‘performance of a contract’ under Art. 6(1)(b) GDPR, and ‘consent’ under Art. 9(2)(a) GDPR for health related data.

We will retain this information for the same duration as your general account data.

• Invoicing

When you place an order and select a payment provider, your information will be shared with them to initiate the payment process. As a customer of these payment providers, you can find information on their privacy practices in their separate privacy statements.

After your payment, we are legally required to provide you with an invoice. To fulfill this requirement and to facilitate your payment, we need to process your account data, order details, and payment data including payment amount, recipient details, and bank receipts.

In some cases, the vendor you ordered from (like a restaurant or shop) is responsible for issuing the invoice. When this happens, we share only the specific information they need to fulfill their legal duties.

The legal basis for this processing is ‘legal obligation’ under Art. 6(1)(c) GDPR.

We store this personal data for 10 years after the invoice date.

• Saving Payment Methods

You can save your preferred payment method to make your checkout process more convenient. This way you won’t have to re-enter your payment details the next time you place an order. To enable this feature, we process your account data, order details and payment data.

The legal basis for this processing is ‘consent’ under Art. 6(1)(a) GDPR.

We will keep this personal information for as long as you choose to share it with us.

When you subscribe for foodora PRO, we will request to store your payment data to enable regular billing in accordance with your subscription. As maintaining a regular payment process for your subscription plan is a fundamental part of this service, the legal basis for this processing is "performance of a contract" under Art. 6(1)(b) GDPR.

D. When we deliver your order

• Preparing and Delivering Your Order

Once you place an order, we share your order details with the vendor (e.g. restaurants, shops) to start preparation. Your delivery details are then shared with couriers (also called “riders”) to bring your order to your door. We share only the information strictly necessary for them to fulfill your request, and we process your order and delivery data to make this possible. Occasionally, a vendor or rider might contact you via our platform’s chat feature or phone if an item is out of stock or if they need help finding your address.

As the preparation and delivery of your order is a fundamental part of the services provided on our platform, the legal basis for this processing is ‘performance of a contract’ under Art. 6(1)(b) GDPR.

In some cases, riders are asked to provide proof of delivery. This may include the time and date of delivery, your name, and in some cases, a signature or photo as evidence. This information helps us resolve any disputes, providing you with a higher level of customer satisfaction. The legal basis for proof of delivery is ‘legitimate interest’ under Art. 6(1)(f) GDPR.

If you receive a gift (like flowers or a meal) from someone else or order through a partner platform that uses our delivery services, we receive name, address, and phone number. We use these details to fulfill the delivery and rely on the sender to ensure they have the right to share this information. If we are the data controller of recipient data, we will rely on ‘legitimate interest’ under Art. 6(1)(f) GDPR as the legal basis to fulfill the delivery services.

We will retain this information for the same duration as your general account data.

• Customer Care

If you have questions or encounter an issue, our support team is here to help. To provide accurate assistance, we use your account data, order and delivery data, delivery related data, payment data, along with any details you share in your request. This information enables us to provide you with relevant and accurate assistance.

To give you faster resolutions, we use automation for routine tasks such as canceling your order or changing delivery instructions. Our support agents may also utilize algorithmic decision making processes for the purpose of calculating compensation for any issues you may experience, and for issuing a refund or voucher.

We may also use artificial intelligence powered chatbots for instant answers. We will always inform you when you are communicating with an AI. To maintain high service standards, AI supported tools may also assist our teams for internal quality assurance purposes. Rest assured, we remain the "controller" of your data; we do not allow third parties to train their AI models. If your concern is complex, you can always ask for help from a human agent.

As resolving your issues is an essential part of the complete fulfillment of the service we provide to you, the legal basis for processing your data for this purpose is ‘performance of a contract’ under Art. 6(1)(b) GDPR. The legal basis for conducting quality assurance reviews to improve our customer service is our ‘legitimate interest’ under Art. 6(1)(f) GDPR.

We will keep the data we process within the customer care for the duration of the statutory limitation periods for legal claims in your jurisdiction (which might range from 3 up to 6 years).

• User Reviews

Once your order has been delivered, you can rate and review the vendor you have ordered from. In this case, your name will be displayed on our platform next to the content of your review. For this purpose, your account data; and the content of your review will be processed.

The legal basis for this processing is ‘consent’ under Art. 6(1)(a) GDPR.

We will keep your reviews for as long as you choose to share it with us.

E. When we promote our platform or vendor services

• App/SMS Notifications and Email Newsletters

We share updates about new restaurants and promotions through the app, email, or SMS. To make sure the content we provide is similar to what you’ve ordered before, we use your account, location, and order and delivery data. This helps us to promote specific cuisines, restaurants, or products you might enjoy, such as Italian restaurants or vegan options. You are always free to opt-out from such communications.

The legal basis for this processing of your data for the purpose of sending app notifications and email/sms newsletters is ‘legitimate interest’ under Art. 6(1)(f) GDPR in conjunction with the exception under EU ePrivacy laws for promoting similar goods and services to the one you have already ordered from our platform.

We will process the data we process within this purpose for the duration of your account with us. The information if you have opted in to or out of receiving such communications we will store for the duration of the statutory limitation periods for legal claims in your jurisdiction (which might range from 3 up to 6 years).

• Incentives

We use a variety of incentives to make our platform more attractive to you and to ensure that you enjoy all the advantages that our platform has to offer. These incentives include vouchers, customer referral programs (“Refer a Friend”), competitions, and bonus programs.

The legal basis for administering our promotions and fulfilling reward terms is ‘performance of a contract’ under Art. 6(1)(b) GDPR. If you participate in promotional programs or competitions operated by third parties, any resulting data transfer to those third parties is based on your ‘consent’ under Art. 6(1)(a) GDPR.

We retain incentive data for as long as your account remains active and delete it upon account closure or after 3 years of inactivity, unless statutory retention rules apply. However, to prevent fraud and stop the re-use of one-time discounts across multiple accounts, we retain promotional usage records following account deletion under our ‘legitimate interest’ under Art. 6(1)(f) GDPR.

• Online Marketing

To reach new customers and keep you updated, we show targeted ads on our platform and on third-party media properties (e.g, websites, social platforms). To make our marketing processes relevant, we process account data, location data, order and delivery data, and device data such as session information, your configuration settings, platform interactions such as items added to the cart, and data obtained through web-trackers (e.g. cookies, SDKs, pixels).

We also use customer segmentation, and inferences about your consumption preferences and demographics (like age and gender) to highlight specific products or cuisines. These insights are typically aggregated and pseudonymized, which means that we cannot identify you individually. This process is designed to show you products you’ll enjoy and it doesn’t have any legal or similarly significant effect on you.

Your prior explicit ‘consent’ under Art. 6(1)(a) GDPR is requested to show you our online targeted advertisements. If you do not consent to personalized online advertisements, please note that you may still receive ads related to our service and products. However, these ads will be generic and not result from specific targeting processes.

We will keep this personal information for as long as you choose to share it with us but in any case we will delete the data we process within this purpose after deletion of your account.

• Partner Promotions and Advertisements

To help you discover new restaurants and products, we display advertisements on our platform, such as "featured restaurants" at the top of your search or special limited-time deals. To make sure these ads are relevant to you, we process account data, location data, order and delivery data, and device data.

We also use customer segmentation, and inferences about your consumption preferences and demographics (like age and gender) to highlight specific products or cuisines. These insights are typically aggregated and pseudonymized, which means that we cannot identify you individually. This process is designed to show you products you’ll enjoy and it doesn’t have any legal or similarly significant effect on you.

We do not share your personal data with third parties who promote their products on our platform. However, in some cases, we can share advertising performance insights (like the number of clicks, engagement metrics) to help them understand how their ads are performing.

We ask your ‘consent’ under Art. 6(1)(a) GDPR in order to show you personalized advertisements. If you do not consent to personalized advertisements, please note that you will still receive ads, however, they will not be tailored to your personal interests.

We will keep this personal information for as long as you choose to share it with us but in any case we will delete the data we process within this purpose after deletion of your account.

• Social Media Pages

When you visit our pages on social media platforms such as Facebook and Instagram, the operators (such as Meta Ireland Ltd.) process your personal data, as explained in their own privacy statements. Meta provides us with aggregated statistics and insights about our social media pages, allowing us to understand the user interactions. It’s important to know that we cannot see which individual person visited our page or link these stats back to your profile.

For the data collected on our social media pages and analyzing the user interactions, both we and the social media platforms (such as Meta) act as joint controllers. We’ve established joint controller agreements with these operators.

You can learn more about how Meta handles your data and how to exercise your rights here:

Meta Privacy Policy

Meta Controller Addendum

The legal basis for processing of your data for the purpose of engaging with users and utilizing user insights is ‘legitimate interest’ under Art. 6(1)(f) GDPR.

F. When we ensure the security of our platform

• IT Infrastructure, Multi-Factor Authentication, and Systems Security

We use secure servers, cloud infrastructure, and advanced monitoring tools to keep our platform safe and ensure uninterrupted service. To keep our infrastructure safe at all times, we deploy measures including endpoint security detection, traffic monitoring, backup systems, and data loss prevention solutions. As part of our access security, we also utilize two-factor authentication to verify your phone number. By default, this verification code is sent via standard SMS. If you prefer, you can actively choose to receive your code via WhatsApp instead.

The legal basis for processing your data for the purposes of hosting and ensuring the security of your personal data is ‘legitimate interest’ under Art. 6(1)(f) GDPR.

The legal basis for sending the default SMS verification code is ‘legitimate interest’ under Art. 6(1)(f) GDPR. If you explicitly choose to receive your verification code via WhatsApp, the legal basis for using that specific channel is your ‘consent’ under Art. 6(1)(a) GDPR.

• Fraud Detection and Prevention

To provide you with a secure platform and a safe ordering experience, we implement proactive measures to detect and prevent fraudulent activity. For this purpose, we process your account data, payment data, location data, device data, and order and delivery data such as successful and cancelled orders, voucher and refund history.

We analyze platform interactions and sometimes use information from third-party partners (like payment providers) to validate the legitimacy of your transactions and ensure our services and incentives are used as intended. By using machine learning and algorithmic decision making, our systems detect irregularities that may lead to protective measures such as additional authentication or temporary account restrictions to prevent financial loss or platform misuse.

For the purposes set out in this section, and in particular to improve order acceptance on our platform, we may exchange personal data with Mastercard. For details on how Mastercard handles your personal data and your data subject rights when they act as a data controller, as well as Mastercard's binding corporate rules under Art. 47 GDPR, please see the link below:

Mastercard Ekata Global Privacy Notice

If any such decision (i) results in a negative, legally binding outcome for you, (ii) similarly significantly affects, or (iii) you believe there has been an error, you can contact our customer care team. In this case, we will individually assess the circumstances of your case.

The legal basis for processing your data for the purposes of fraud detection and prevention is ‘legitimate interest’ under Art. 6(1)(f) GDPR.

We retain data processed for fraud prevention for the duration of your account. Following account closure, we keep this data only for as long as necessary to investigate potential links to fraudulent activity or to comply with statutory limitation periods (e.g., defense of legal claims).

G. When we improve our services

• User Surveys and Interviews

To improve our service, we may invite you to provide feedback through surveys or user experience interviews. For this, we process your account data, order and delivery data, device data, the content of your feedback, and your usage interactions as part of the interviews.

Participation is entirely voluntary and based on your ‘consent’ under Art. 6(1)(a) GDPR. Once you agree, we may contact you via email, SMS, or platforms like WhatsApp. You can withdraw your consent at any time by contacting us. In this case we will exclude you from participating in interviews and ensure that you don't receive any further invitations.

We keep this data as long as you grant us consent to do so. At the latest, when you delete your account, we will consider your declaration of consent to have been withdrawn.

• Data Analytics

To ensure our platform remains efficient and easy to use, we analyze how our features, pricing, and promotions perform. For instance, we use A/B testing to compare different app designs and see which provides the smoothest experience. We also study how customers respond to various pricing models to help us refine our strategies. To achieve this, we process order and delivery data, anddevice data. These insights are typically aggregated (so you cannot be identified) or pseudonymized (meaning it will be very hard to identify you as a person).

The legal basis for processing your data for this purpose is ‘legitimate interest’ under Art. 6(1)(f) GDPR.

•

• Business Intelligence, Insights & Group-level Statistics Reporting

We process aggregated customer data including account data, device data, as well as order and delivery data to create group-level reports, such as market statements and trading updates. This helps us identify broader market trends and make informed decisions about our overall business strategy.

We also provide partners (e.g., restaurants and shops) with aggregated reports on sales and engagement. These help them improve their service by showing why customers might have preferred certain menu items or vendors. These reports are strictly anonymous; partners cannot identify you personally.

The legal basis for processing your data for this purpose is ‘legitimate interest’ under Art. 6(1)(f) GDPR.

H. When we are required to comply with laws and regulations

•

• Legal Proceedings and Authority Requests

As with any organization, there are instances when we are required to share personal data with public authorities. We may also process your personal data to initiate or defend legal claims and uphold our rights and interests. In these cases, we only disclose what is strictly necessary for the specific investigation or proceeding.

The legal basis for processing your data for complying with public authority requests is ‘legal obligation’ under Art. 6(1)(c) GDPR; and for initiating and defending legal claims is ‘legitimate interest’ under Art. 6(1)(f) GDPR.

We retain this information for as long as necessary to comply with legal obligations related to ongoing proceedings and investigations. After the final closing of the respective legal proceedings we will delete your data immediately.

• Age verification when purchasing restricted goods

The sale of certain products on our platform, such as alcohol or tobacco, is subject to statutory age restrictions. In accordance with these requirements, we must verify your age to determine whether we are legally permitted to process and fulfill your order. For this purpose, we process your identity data, which includes your date of birth and images of your identification documents.

The legal basis for this processing is "legal obligation" under Art. 6(1)(c) GDPR. We retain the provided images of your identification documents for a period of 7 days following the completion of the verification process, after which they are permanently deleted.

• Responding to Data Subject Requests

We respect your legal rights under data protection laws. When you exercise these rights, we must process your information to fulfill our legal duty to respond. For example, if you request access to your data, we must gather and review the information we hold to provide a complete response.

The legal basis for processing your data for complying with data subject requests is ‘legal obligation’ under Art. 6(1)(c) GDPR.

We retain this information for as long as necessary to comply with our legal obligations.

• Regulatory Compliance in the EU

To comply with EU laws, including the Digital Services Act (DSA), financial regulations, and antitrust rules, we are required to share certain aggregated data with the parties specified in these laws (e.g., vendors on our platform, regulating bodies). While this information will originate from customer data, we generally do not share personal data to meet these requirements. The processing of personal data is based on the legal basis of ‘legal obligation’ under Art. 6(1)(c) GDPR.

4. Who will receive your data and under what circumstances?

You can trust that, within our company, only those staff members will receive access to your personal data who need them in order to fulfill their professional duties, such as providing you with a great online experience, or looking into your support request. In certain scenarios, we also need to share your personal data with recipients outside of our company. Please be assured that your data is shared with these recipients only to the extent necessary for the specified purposes and only as we are legally permitted to do so.

In addition to sharing data with the parties already specified above, we will only share your data as follows:

4.1. Delivery Hero group companies

We are part of an international group of companies with legal entities in many parts of the world, including our group’s headquarters located with Delivery Hero SE in Berlin, Germany. In order to utilize our resources efficiently and ensure that our business processes function properly, we utilize our group-wide shared technological support services that sometimes necessitate sharing personal data with our parent company, Delivery Hero SE, or with the locations of our global tech hubs. In certain situations, we might also share limited data with other group companies, for example, to assist with payment collection or to implement platform security measures.

Delivery Hero group companies are bound by strict intra-group data transfer agreements ascertaining compliance with data protection requirements whenever sharing personal data with group companies.

4.2. Data processors

We use various third-party service providers to perform our operations. Many of these providers process your personal data as so-called “data processors”. This means they are only allowed to process your personal data under our instructions and have no claims whatsoever to process your personal data for their own, independent purposes. Our processors are strictly monitored and we only engage processors who meet our high data protection standards. The main data processor for cloud technology on our platform is our group’s headquarters located with Delivery Hero SE in Berlin. Delivery Hero SE provides us with a wide range of services of technology, such as cloud hosting, platform security, marketing or customer relationship management tools.

Delivery Hero SE will also use data processors (as so-called “sub-processors”), as follows:

Our user platforms and databases run on cloud resources provided by the EU subsidiaries of Google Cloud Platform and Amazon Web Services. We use marketing and communications tools by companies such as SalesForce or Braze. Our finance and accounting platforms are provided by SAP.

4.3. Vendors and Couriers

To fulfill your orders, we share strictly necessary information with the vendors (restaurants and shops) and couriers who prepare and deliver your request. In rare cases, we may also share your email address with a vendor when strictly necessary to facilitate essential product recalls or safety notifications regarding your purchases.

4.4. Other third parties and service providers

In addition to data processors, we also work with third parties, to whom we share your personal data, but who are not bound by our instructions and instead will process your data independently. These may be our consultants, lawyers or accountants who receive your data from us under a contract and process your personal data for legal reasons, or to protect our own interests. Under no circumstances will we sell or rent your personal data to third parties without your explicit, informed consent.

4.5. Mergers & acquisitions, change of ownership

In the event of a merger with, or acquisition by, another company or group of undertakings, we may need to disclose limited information to that company and their advisors who are under professional obligations to maintain the confidentiality of your personal data. This may occur in circumstances such as mutual due diligence assessments and regulatory disclosures.

In any event, we will ensure that we only disclose the minimum amount of information necessary to conduct the transaction, while also carefully considering the feasibility of removing or anonymising any data that could identify individuals.

4.6. Prosecuting authorities, courts and other public authorities

From time to time we may be requested to disclose personal data to public authorities. In some circumstances, we may disclose personal data with public bodies in order to bring or defend legal claims, to protect our rights and interests, or to address security concerns.

Examples of such situations include cooperating in the detection and prevention of crime, responding to legal processes such as court orders or subpoenas, or sharing data with tax authorities for tax-related purposes. The public authorities involved in these scenarios may include law enforcement agencies, courts, tax authorities, or other government bodies.

5. How do we transfer your personal data to other countries?

We and the parties we share your personal data with may transfer personal data to countries other than the country in which you use our services. Where such transfers take place, we take appropriate measures to ensure that your data is always afforded an adequate level of protection in the countries to which it is transferred.

For example, if we transfer your personal data from a country within the European Economic Area (EEA) to a country outside of the EEA, we take appropriate safeguards to ensure that these transfers provide a level of protection that complies with data protection requirements. If there are specific further requirements of the law of the country in which you use our services, we will abide by them as well. Specifically, as far as transfers from the EEA to countries outside the EEA are concerned, we rely on a number of appropriate safeguards:

• Adequacy decisions by the EU Commission (also including the United States, to the extent recipients have certified under EU-US Privacy Framework, or other applicable mutual agreement between the EU and the US);

• Standard contractual clauses mutually agreed in our contract with the data recipient (including any supplementary measures, if required).

• Further appropriate safeguards in accordance with Art. 46 GDPR (for example binding corporate rules).

• When necessary, data transfer impact assessments.

If you would like to receive a copy of the appropriate safeguards securing the data transfer, please contact us.

6. What are your legal rights?

Under the data protection laws, you are entitled to the following rights:

Right to access

You have the right to request a copy of your personal data and obtain additional information on how we process it.

Right to rectification

If you notice that your personal data is incorrect, you can always request that we correct it.

Right to erasure

You have the right to ask us to delete your personal data. Please note that even if you exercise this right, we may be required to retain some of your information if we process it as part of our legal obligations, or in pursuit of our own (or a third party’s legitimate interests) such as the assertion of, or defense against, legal claims, preventing fraud or protecting ourselves or others against abusive behavior.

Right to restriction of processing

If you have requested the deletion of your personal data, but we are legally prevented from immediately deleting it, we will store your data in our archives and retain them for the sole purpose of meeting our legal obligations. However, you will not be able to use our services during this time, as this would require us to de-archive your personal data.

Right to data portability

You can ask us to provide you or another data controller with your personal data in a machine-readable format. However, please note that this right only applies to data that we process based on your consent.

Right to object

You have the right, for reasons arising from your particular situation, to object at any time to any processing of your personal data, which is processed on the basis of our legitimate interests. If you object, we will no longer process your personal data unless we can prove compelling grounds for the processing that outweigh your interests, rights and freedoms or the processing serves to assert, exercise, or defend against legal claims.

You also have the right to object at any time, without giving any explanations, to the processing of your personal data for the purposes of direct marketing (including any associated profiling).

Right of complaint

You can raise a complaint about our processing with the data protection authority in the country of your habitual residence, place of work, or the place where you think a violation of data protection laws has occurred. In the case of cross-border data processing, you can also lodge a complaint with our lead supervisory authority in Berlin, Germany.

Right not to be subject to a decision based solely on automated processing

You have the right to object to a fully automated decision (i.e. without any human intervention in the decision-making process) that has legal effects or significantly affects you.

Right to withdraw consent

Where we rely on consent to process your personal data, you have the right to withdraw your consent at any time. If there is no other legitimate ground we are allowed to process your personal data, we will immediately stop processing it. Withdrawal of consent does not affect the legality of the processing carried out before the withdrawal.

To exercise your rights, we encourage you to use the functions available in your account. For example, if you would like to delete your data or receive a copy, you can do so by following the relevant steps in your profile. These self-service methods are designed to expedite your request. Alternatively, you can also reach out to our customer care team to assist you.

7. How long do we keep your data?

We retain your personal data for as long as it is necessary to achieve the purposes we described above. The duration for which we retain your personal data is determined by factors such as the scope, nature and purposes of the personal data processing, and whether we have legitimate interests or legal obligations that require us to retain your personal data.

8. How do we use algorithmic decision making?

Some of our processes use algorithmic decision making and machine learning. We consistently strive to ensure a significant level of human oversight in the decision making process, enabling us to modify or reverse decisions as needed. In many cases, the algorithmic decision making processes without human oversight will not have legal or similar significant effects on you. Where they do, we will ensure that you have the right not to be subject to the algorithmic decision making processes, unless those processes are authorized by applicable law or are necessary for the entering into or performance of a contract. In these cases, you can always oppose the decision and request for a human evaluation by contacting us.

For detailed information about the specific instances that algorithmic decision making processes are used, please visit the sections above that explain how we use your personal data.

9. How do we use artificial intelligence?

We may use artificial intelligence (“AI”) technologies across our operations. Depending on the context, such technologies may be used, for example, to support customer service interactions, chatbots, translations, assist with inbound and outbound communications, help route and prioritise requests, detect fraud or abuse, improve safety and security, and enhance our products and services.

Where AI tools are used, we may process account data, order and delivery data, device information, as well as customer support data, such as recordings, transcripts, chat content. The categories of personal data processed will be limited to what is necessary for the relevant purpose.

Depending on the relevant processing activity, we may rely on the following legal bases:

(a) the performance of a contract or steps taken to entering into a contract, where the processing is necessary to provide the requested services;
(b) Our legitimate interests, such as improving customer support, protecting the platform, preventing fraud and abuse, ensuring safety and security, maintaining service quality, and improving operational efficiency, provided that such interests do not harm your rights and freedoms
(c) consent, where this is required under applicable law.

Where we use third-party providers in AI-enabled services, those providers will be subject to appropriate contractual, confidentiality and data protection obligations, including, where applicable, data processing agreements under Art. 28 GDPR. We also do not permit third-party providers to use your personal data to train or improve their AI models, unless this is clearly disclosed to you and supported by an appropriate legal basis.

Where AI is used to assist decision-making without human oversight, we ensure these processes will not have legal or similar significant effects on you. Information on automated decision-making and profiling is provided in section 8 of this Privacy Statement (“How do we use algorithmic decision making?”)

In line with the EU AI Act, we ensure that any decision or suggestion generated by AI that may affect you is subject to human review. This means our team checks automated outputs and confirms important decisions to protect fairness, transparency, and your rights.

You may exercise your rights in relation to processing involving AI, including the rights of access, rectification, erasure, restriction, objection, and, where applicable, the right not to be subject to a decision based solely on automated processing, in accordance with applicable law.

For more information on how to exercise these rights, please see Section 6 of this Privacy Statement.

10. How can I delete my account?

You can delete your account at any time. On the mobile app, tap the menu icon in the top left corner, select Profile, and scroll to the bottom to tap Delete My Account. On our website, click your name in the top right corner, select Profile, and scroll to the bottom of the page to click Delete My Account. Alternatively, you can always request account deletion by sending an email to dpo@foodora.cz.

11. Changes to this privacy statement

We may update this Privacy Statement from time to time to reflect our new processes, new technologies, and legal obligations. We are committed to keeping you informed of any changes to our privacy practices, so we encourage you to review this privacy statement to keep updated.

Last modified: September 2026