Skip to content

Freshers campaign
Privacy Policy

Privacy Notice for Nando’s Freshers’ Week Promotion

Effective Date: Tuesday 20th September 2022

Who are we?

We are Nando’s Chickenland Limited, (Nando’s) registered at Companies House under number  02580031.

We are based at:

St Mary's House, 42 Vicarage Crescent, London, SW11 3LD

Any queries relating to data protection can be directed to our DPO by emailing hello@nandos.co.uk

Our Role:

For this promotion, Nando’s acts as a Controller of the data processed. Being a Controller means that Nando’s is responsible for making decisions about the data we process and protecting that data on your behalf, and in line with the law. We are happy to talk to you about how we process and protect data, just email us on hello@nandos.co.uk

What Personal Data do we process for this promotion and why?

For you to take part in the Freshers’ promotion, and send you your free green rewards, we need to be able to link you to your Nando’s account. We will therefore ask you for your name and the email address associated to your current Nando’s account.

If you don’t already have a Nando’s account, we will direct you to create one. The data processed when you open a Nando’s account and the ongoing maintenance of that account is governed by our main privacy notice, available here: https://www.nandos.co.uk/privacy-policy and https://www.nandos.ie/privacy-policy.

Since this promotion is only for students, we will need to validate that you are in fact a student. To do that, we ask you for your university email address. We will use that to send a link that you will click on to confirm that you are eligible for your free reward. As we do not need this data after that, we will delete it 24 hours after validation. If you do not validate your account within 4 weeks, then we will delete your university email address. (So don’t delay!)

We would love to keep you up to date with all our news and offers and as existing customers we give you the chance to opt out of these. We use the email address associated to your Nando’s account, not your university one for this. To add extra value, we will also ask you which university you are at, your year of birth and your start year at uni and your planned year of graduation. We will also use this data for analytics purposes, to see how successful our campaign has been, to see if we should come back to your university next year, and if those free rewards came in handy to you.

The lawful basis for processing your current Nando’s account data, your uni email address and your agreement to our T&C’s is contract; you are signing up to the promotion and we are giving you a green reward as part of that contract.

Our lawful basis for processing the data about your university, year of birth and university start date and graduation is legitimate interest; our need and use of this data benefits Nando’s but does not infringe on your rights and freedom. You can request a copy of our legitimate interest balancing test for this processing by emailing us at hello@nandos.co.uk.

You can withdraw your consent to marketing either by emailing us, or much easier, but just clicking the unsubscribe link in the emails we send.

Who else gets your data?

Like most companies, we use other companies as part of our data processing, for example cloud data storage services and email technology services. We have Data Processing Agreements in place with all the providers used. Where data is transferred outside of the EEA, we ensure that appropriate protection and mechanisms are in place, for example the UK International Data Transfer Agreement or Standard Contractual Clauses. If data is transferred from the UK to the EEA, then it is done so on the basis of those countries having a comparable data protection regime to the UK (adequacy).

We’ll share your “Personal Information” with people or departments within Nando’s but only if they have a need to access it.

We do not sell your data to anybody.

How long do we hold the data for?

Your university email address is deleted 24 hours after you validate your account, or after 2 weeks if you do not click on the validation link.

The data about your university, year of birth and start and graduation year is stored against your Nando’s profile and deleted when we need to delete your Nando’s account. Additionally, it will be aggregated to enable us to do analysis on the data. This means it will be de-identified and therefore out of scope of data protection regulations.

Your Rights

As a data subject, you have a number of rights over your personal data under the Data Protection Laws.  If you wish to exercise any of your rights, please contact us at hello@nandos.co.uk

Right of access: You can request access to a copy of the personal data which we hold about you, as well as details about why and how we use it;

Right to rectification:  You can ask us to change or complete any personal data we hold about you which is inaccurate or incomplete;

Right to be forgotten/erasure: You have a right, under certain circumstances, to ask us to delete any personal data we hold about you. Please note that there may be situations where we must retain your personal data after a request for erasure where we have a lawful basis for doing so;

Right of restriction: You can ask us to restrict (i.e., prevent) the processing of your personal data where you have objected to our use of it, and we have no lawful basis to continue processing your personal data;

Right of data portability:  In certain circumstances, you can ask us to transfer the data we hold about you to another organisation. This would be sent in a structured, commonly used, electronic form;

Right to object: You can object to us using your personal data for particular purposes, including marketing; and

Automated decision making: You have a right not to be subjected to automated decision making and profiling in certain situations.

If you have any cause to complain about our use of your personal data, please contact us by emailing hello@nandos.co.uk.

You also have the right to lodge a complaint about our processing with a supervisory authority — as we are a UK company our main supervisory authority is the ICO whose details are here: https://ico.org.uk/make-a-complaint/

Technical and Operational Security

We have implemented reasonable technical and organisational measures designed to secure your personal information from accidental loss and from unauthorised access, use, alteration, or disclosure. We’ll continue to maintain and improve these security measures in line with legal and technological developments.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Changes to Our Privacy Notice

We may change this Privacy Notice from time to time (for example, if the law changes). We recommend that you check our main website regularly to check for updates.

If we make any material changes to the way we process and use your personal data, we will contact you to let you know about the change.

Get in touch

If you have queries about our use of your data, please contact us by emailing us on hello@nandos.co.uk.