1. Utangulizi
Foodfy ("Kampuni", "sisi", "yetu", "sisi") imejitolea kulinda faragha na usalama wa maelezo yako ya kibinafsi. Sera hii ya Faragha inafafanua jinsi tunavyokusanya, kutumia, kufichua, kuhifadhi na kulinda data yako unapotumia mfumo wa Foodfy, ikijumuisha tovuti yetu katika foodfy.ai, programu za simu, API, dashibodi za wauzaji, huduma za AI, mtandao wa uwasilishaji wa ndege zisizo na rubani, na huduma na vipengele vyote vinavyohusiana (kwa pamoja, "Mfumo").
This Privacy Policy applies to all users of the Platform worldwide, including Customers, Business Partners, Delivery Partners, Territory Partners, Corporate Account administrators and employees, Investors, Influencers, NutriLife users, and visitors. By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
Foodfy inafanya kazi katika nchi 250+. Sheria mahususi za ulinzi wa data zinazotumika kwako zinaweza kutofautiana kulingana na eneo lako. Ambapo sheria ya eneo hutoa ulinzi mkubwa zaidi kuliko Sera hii ya Faragha, sheria ya eneo hutumika. Masharti ya ziada ya kikanda yamefafanuliwa kwa kina katika Sehemu ya 16.
2. Kidhibiti Data
Foodfy ndiye mdhibiti wa data anayewajibika kwa data yako ya kibinafsi iliyochakatwa kupitia Jukwaa, isipokuwa ikiwa imeelezwa vinginevyo. Kwa Foodfy for Work (Akaunti za Biashara), shirika linalojiandikisha hufanya kama kidhibiti data cha data ya kibinafsi ya mfanyakazi, na Foodfy hufanya kazi kama kichakataji data kwa niaba yao.
Kwa maswali kuhusu ulinzi wa data, unaweza kuwasiliana na Afisa wetu wa Ulinzi wa Data kwa:
- Barua pepe: [email protected]
- Postal Address: Foodfy, Afisa wa Ulinzi wa Data, anapatikana kwa ombi kupitia [email protected]
3. Taarifa Tunazokusanya
We collect different categories of personal data depending on how you interact with the Platform and which services you use.
3.1 Watumiaji wote
- Taarifa za Akaunti: Jina kamili, anwani ya barua pepe, nambari ya simu, tarehe ya kuzaliwa, picha ya wasifu na nenosiri lililosimbwa.
- Data ya Uthibitishaji: Vitambulisho vya kuingia, siri za uthibitishaji wa vipengele viwili na misimbo ya urejeshaji, tokeni za API na vitambulishi vya kipindi.
- Data ya Kifaa na Kiufundi: Aina ya kifaa, mfumo wa uendeshaji na toleo, aina na toleo la kivinjari, ubora wa skrini, vitambulishi vya kipekee vya kifaa, maelezo ya mtandao wa simu, anwani ya IP na tokeni za arifa zinazotumwa na programu hata wakati huitumii (Tokeni za Maonyesho).
- Usage Data: Kurasa zilizotembelewa, vipengele vilivyotumika, hoja za utafutaji, ruwaza za kubofya, njia za kusogeza, muda wa kipindi, mihuri ya muda, URL zinazorejelea, na matukio ya mwingiliano.
- Data ya Mahali: Takriban eneo linalotokana na anwani ya IP. Kwa kibali chako cha moja kwa moja, eneo sahihi la GPS kwa uwasilishaji, ugunduzi wa biashara ulio karibu na vipengele vinavyotegemea eneo.
- Data ya Mawasiliano: Ujumbe unaotumwa kupitia Mfumo, mwingiliano wa usaidizi kwa wateja, maoni na majibu ya utafiti.
3.2 Wateja
- Data ya Agizo: Bidhaa zilizoagizwa, historia ya kuagiza, anwani za kuwasilisha (ikiwa ni pamoja na jina la jengo, mtaa, ghorofa, ghorofa, nambari ya kuingia na maagizo ya kuwasilisha), mapendeleo ya agizo, mahitaji maalum ya chakula na chanzo cha agizo (wavuti, programu, kioski, QR, WhatsApp, mpango wa chakula).
- Data ya Malipo: Aina ya njia ya malipo, anwani ya kutuma bili, kiasi cha miamala na historia ya miamala. Nambari kamili za kadi za malipo huchakatwa na kichakataji chetu cha malipo kinachotii PCI DSS (Stripe) na kamwe hazihifadhiwi kwenye seva za Foodfy.
- Kitabu cha Anwani: Saved delivery addresses including structured address components, GPS coordinates, Google Place IDs, and formatted addresses.
- Mapendeleo: Biashara unazopenda, vitu vilivyohifadhiwa, mapendeleo ya lishe, mipangilio ya lugha na sarafu.
- Reviews and Ratings: Product reviews, business ratings, delivery ratings, photos, and comments.
3.3 Washirika wa Biashara
- Taarifa za Biashara: Jina halali la biashara, jina la biashara, kikoa kidogo, kitambulisho cha duka la umma, aina ya biashara (mgahawa, mboga, duka la dawa, maua, rejareja, mtoa huduma, chapa), anwani halisi, nambari ya simu, barua pepe na URL ya tovuti.
- Takwimu za Kisheria na Fedha: Tax identification name and number, legal entity type, banking details for payouts, and business registration documents.
- Data ya Uendeshaji: Vipengee vya menyu, orodha ya bidhaa, bei, viwango vya orodha, saa za kazi, nyakati za maandalizi, maeneo ya kuwasilisha bidhaa na usanidi wa huduma.
- Data ya Uhusiano wa Wateja: Wasifu wa CRM ikiwa ni pamoja na marudio ya agizo la mteja, jumla ya matumizi, alama za RFM (Recency, Frequency, Pesa), hatua ya mzunguko wa maisha, kiwango cha uaminifu, hali ya kujijumuisha katika uuzaji, lugha inayopendekezwa, lebo na madokezo.
- Takwimu za Wafanyikazi: Staff member names, roles, employee codes, departments, designations, employment type, contact information, emergency contacts, banking details, identity documents, and HR records when using the People and HR feature.
- Third-Party Integrations: Kitambulisho cha Mahali pa Google, ukadiriaji wa Google, wasifu kwenye mitandao ya kijamii (WhatsApp, Facebook), na data inayobadilishwa na huduma zilizojumuishwa (programu ya uhasibu, majukwaa ya uwasilishaji).
- Data ya Franchise: Muungano wa chapa ya Franchise, misimbo ya soko, usanidi wa maeneo mengi, na uchanganuzi wa kiwango cha chapa.
3.4 Washirika wa Uwasilishaji
- Uthibitishaji wa Utambulisho: Kitambulisho kilichotolewa na serikali, leseni ya udereva, usajili wa gari na uthibitisho wa bima.
- Real-Time Location: Viwianishi vya GPS vinasasishwa wakati wa uwasilishaji amilifu kwa ufuatiliaji wa agizo, uboreshaji wa njia na madhumuni ya usalama.
- Performance Data: Idadi ya maagizo yaliyokamilishwa, maagizo yaliyokataliwa, nyakati za uwasilishaji, ukadiriaji uliopokelewa na historia ya mapato.
- Data ya Utoaji wa Drone: Kwa washirika wa uwasilishaji wenye uwezo wa ndege zisizo na rubani: hali ya uwezo wa ndege zisizo na rubani, aina ya kikimbiaji, takwimu za uwasilishaji, ugawaji wa DronePort, na kumbukumbu za uendeshaji za drone.
3.5 Washirika wa Wilaya
- Maeneo Yanayosimamiwa: Kiwango cha eneo kilichokabidhiwa (Eneo, Nchi, Jimbo, Jiji, Eneo), vitambulishi vya eneo na upeo wa kijiografia.
- Vipimo vya Utendaji: Viwango vya kuabiri biashara, mapato yanayotokana, alama za kuridhika na washirika na vipimo vya ukuaji wa eneo.
- Data ya Maombi: Territory applicant profile information submitted during the application and onboarding process.
3.6 Watumiaji wa Akaunti ya Biashara (Foodfy for Work)
- Data ya Shirika: Jina halali la kampuni, aina ya huluki ya kisheria, nambari ya leseni ya biashara, nambari ya ushuru, anwani iliyosajiliwa, maelezo ya mawasiliano ya bili na nembo.
- Takwimu za Wafanyikazi: Jina la mfanyakazi, barua pepe, jukumu (msimamizi/msimamizi/mfanyakazi), idara, kituo cha gharama, nambari ya kumbukumbu ya mfanyakazi, salio la pochi, historia ya miamala ya pochi na hali ya ajira.
3.7 Wawekezaji
- Wasifu wa Mwekezaji: Hali ya idhini, mapendeleo ya uwekezaji, hati za uthibitishaji wa utambulisho, na historia ya mawasiliano.
- Shughuli ya Uwekezaji: Maslahi ya uwekezaji, ushiriki wa mikataba, kiasi cha uwekezaji na mawasiliano yanayohusiana.
3.8 Watumiaji wa NutriLife
NutriLife hukusanya data nyeti ya afya na biometriska. Tazama Sehemu ya 9 kwa maelezo ya kina.
3.9 Taarifa kutoka kwa Washirika wa Tatu
- Social media platforms when you sign in using social login (Google, Facebook, Apple).
- Wachakataji malipo na taasisi za fedha kwa ajili ya uthibitishaji wa miamala na kuzuia ulaghai.
- Public business directories and government registries for business verification and directory building.
- Fungua Ukweli wa Chakula na hifadhidata zingine za lishe kwa data ya lishe ya bidhaa.
- Third-party delivery platforms (Uber Eats, Deliveroo, Talabat, Keeta, Careem) for integrated order management.
- API ya Ramani za Google na Maeneo ya eneo, ramani na data ya anwani.
- Washirika wa uchanganuzi na wa utangazaji kwa uchanganuzi wa trafiki ya tovuti na kipimo cha kampeni.
4. Msingi wa Kisheria wa Usindikaji
We process your personal data on the following legal bases, as applicable under the General Data Protection Regulation (GDPR) and similar frameworks:
- Performance of Contract: Processing necessary to fulfill our contractual obligations to you, including account creation, order processing, payment handling, delivery coordination, and provision of Platform features you have subscribed to or requested.
- Idhini: Processing based on your freely given, specific, informed, and unambiguous consent. This applies to: precise GPS location tracking, NutriLife health and biometric data collection (special category data), marketing communications and promotional emails, non-essential cookies and tracking technologies, and AI-powered photo analysis of meals.
- Maslahi halali: Processing necessary for our legitimate business interests, provided these interests are not overridden by your fundamental rights and freedoms. This includes: Platform security and fraud prevention, analytics and service improvement, personalized search results and recommendations (non-AI profiling), customer support and communication, and enforcement of our Terms of Service.
- Wajibu wa Kisheria: Processing necessary to comply with applicable legal requirements, including tax and accounting regulations, anti-money laundering (AML) and know-your-customer (KYC) requirements, food safety and public health regulations, data retention mandated by law, and responses to lawful government or regulatory requests.
- Vital Interest: Katika hali ya kipekee, usindikaji muhimu ili kulinda maslahi muhimu ya mtu, kama vile hali za dharura zinazohusisha mizio ya chakula, matukio ya usalama, au dharura za afya ya umma.
5. Jinsi Tunavyotumia Taarifa Zako
We use the personal data we collect for the following purposes:
5.1 Uendeshaji wa Jukwaa la Msingi
- Provide, maintain, operate, and improve the Platform and all its features and services.
- Process and fulfill orders, payments, refunds, and deliveries.
- Unda, thibitisha na udhibiti akaunti za watumiaji katika aina zote za watumiaji.
- Washa ufuatiliaji wa agizo la wakati halisi, uratibu wa uwasilishaji, na utumaji wa dereva/drone.
- Process Business Partner payouts and financial reconciliation.
- Dhibiti usajili, manufaa na malipo ya Foodfy Gold.
- Operesheni Foodfy for Work pochi za kampuni, mgao, na ufuatiliaji wa gharama.
5.2 Mawasiliano
- Send transactional communications including order confirmations, delivery updates, payment receipts, and account notifications.
- Provide customer support and respond to inquiries through all channels (email, in-app, WhatsApp, SMS).
- With your consent, send promotional communications, marketing offers, and personalized recommendations.
5.3 Ubinafsishaji na AI
- Personalize your experience through AI-powered search results, business recommendations, and product suggestions.
- Provide Business Partners with AI-powered tools including menu optimization, demand forecasting, automated marketing content generation, and customer analytics.
- Power NutriLife features including AI meal photo analysis, nutritional calculation, and personalized dietary guidance.
- Washa chatbots za AI na usaidizi wa kiotomatiki kwa wateja.
5.4 Usalama, Usalama na Uzingatiaji
- Gundua, chunguza na uzuie ulaghai, matumizi mabaya, ufikiaji usioidhinishwa na shughuli zingine haramu au hatari.
- Verify the identity of Business Partners, Delivery Partners, Territory Partners, and Investors.
- Kutii majukumu ya kisheria yanayotumika, mahitaji ya kodi na mamlaka ya udhibiti.
- Tekeleza Sheria na Masharti yetu na makubaliano mengine.
5.5 Uchanganuzi na Uboreshaji
- Fanya uchanganuzi uliojumlishwa na usiojulikana ili kuelewa mifumo ya matumizi na kuboresha vipengele vya Mfumo.
- Perform A/B testing and user experience research.
- Train and improve AI and machine learning models using anonymized and aggregated data.
- Tengeneza ripoti za akili za biashara na maarifa ya soko.
6. Jinsi Tunavyoshiriki Taarifa Zako
We share your personal data only as necessary to operate the Platform and provide our services. We do not sell your personal data to third parties.
6.1 Pamoja na Watumiaji Wengine wa Majukwaa
- Washirika wa Biashara: When you place an order, we share your name, delivery address, phone number, and order details with the relevant Business Partner to fulfill your order. Business Partners on Foodfy retain full ownership of their customer data and can export it at any time.
- Washirika wa Uwasilishaji: We share your delivery address, order pickup location, and necessary contact information with Delivery Partners to complete deliveries. Delivery Partner access to your data is limited to what is necessary for the current delivery.
- Wateja: Maelezo ya Washirika wa Biashara (jina, anwani, ukadiriaji, menyu, saa za kazi) huonyeshwa hadharani kwenye Mfumo ili kuwezesha ugunduzi na kuagiza.
6.2 Pamoja na Watoa Huduma
We engage trusted third-party service providers who process data on our behalf under strict data processing agreements:
- Stripe: Uchakataji wa malipo, bili ya usajili na utambuzi wa ulaghai.
- Cloudflare: Uwasilishaji wa yaliyomo, ulinzi wa DDoS, na ngome ya programu ya wavuti.
- Anthropic na OpenAI: AI na makisio ya modeli ya kujifunza kwa mashine kwa vipengele vya Platform AI. Data inayotumwa kwa watoa huduma wa AI huchakatwa chini ya masharti yao ya usindikaji wa data ya biashara na haitumiwi kutoa mafunzo kwa miundo yao ya jumla.
- Deepgram: Speech-to-text processing for voice-enabled features.
- Twilio: SMS delivery and voice communication services.
- Google: API ya Ramani, Maeneo, uchanganuzi na huduma za utangazaji.
- Meta: Udhibiti wa kampeni ya utangazaji na ufuatiliaji wa walioshawishika.
- Watoa Miundombinu ya Wingu: Server hosting, data storage, and computing services.
6.3 Na Majukwaa ya Uwasilishaji ya Wengine
When Business Partners use delivery platform integrations (Uber Eats, Deliveroo, Talabat, Keeta, Careem, and others), order data and necessary operational information is exchanged between the Platform and these third-party services to enable cross-platform order management. This sharing is initiated by the Business Partner and governed by the terms of each delivery platform.
6.4 Pamoja na Muunganisho wa Uhasibu
When Business Partners connect accounting software (Xero, QuickBooks), financial transaction data, invoices, and business records are synchronized as configured by the Business Partner.
6.5 Kwa Madhumuni ya Kisheria na Udhibiti
- When required by applicable law, regulation, legal process, subpoena, court order, or enforceable governmental request.
- To enforce our Terms of Service and other agreements.
- To protect the rights, property, safety, or security of Foodfy, our Users, or the public.
- To detect, prevent, or address fraud, security, or technical issues.
6.6 Uhamisho wa Biashara
Kuhusiana na muunganisho, upataji, kupanga upya, kufilisika, uuzaji wa mali, au shughuli kama hiyo ya shirika, data yako ya kibinafsi inaweza kuhamishiwa kwa huluki inayopata. Tutatoa ilani kabla ya data yako ya kibinafsi kuwa chini ya sera tofauti ya faragha.
6.7 Kwa Idhini Yako
We may share your information for purposes not described in this Privacy Policy with your explicit consent.
7. Uhifadhi wa Data
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, provide our services, and comply with legal obligations. Specific retention periods include:
- Data ya Akaunti Inayotumika: Retained for the duration of your account plus 30 days after account deletion request to allow for recovery.
- Rekodi za Agizo na Muamala: Retained for a minimum of 7 years to comply with tax, accounting, and financial regulations in applicable jurisdictions.
- Rekodi za Malipo: Retained as required by PCI DSS standards and financial regulations, typically 7 years.
- Data ya Washirika wa Biashara: Retained for the duration of the business relationship plus the legally required retention period for business records.
- Data ya Afya ya NutriLife: Retained while your NutriLife profile is active. Upon deletion request, health data is permanently deleted within 30 days, except where retention is required by law.
- Data ya Usajili wa Foodfy Gold: Retained for the duration of the subscription plus 3 years for billing dispute resolution.
- Data ya Mfanyakazi wa Akaunti ya Biashara: Retained for the duration of the employee enrollment plus 1 year after removal from the Corporate Account.
- Kumbukumbu za Mawasiliano: Miingiliano ya usaidizi kwa wateja iliyobaki kwa miaka 3 kwa uhakikisho wa ubora na utatuzi wa migogoro.
- Data ya Uchambuzi: Data ya uchanganuzi iliyojumlishwa na isiyojulikana inaweza kuhifadhiwa kwa muda usiojulikana kwani haitambui watu binafsi.
When personal data is no longer needed and no legal obligation requires its retention, we securely delete or irreversibly anonymize it using industry-standard methods.
8. AI na Uamuzi wa Kiotomatiki
Foodfy hutumia akili ya bandia na usindikaji wa kiotomatiki katika vipengele vingi vya Mfumo. Tumejitolea kuweka uwazi kuhusu jinsi teknolojia hizi zinavyochakata data yako.
8.1 Jinsi AI Huchakata Data Yako
- Personalized Recommendations: Miundo ya AI huchanganua historia ya agizo lako, tabia ya kuvinjari, eneo, na mapendeleo ili kupendekeza biashara, bidhaa na matoleo. Uchakataji huu unatokana na maslahi halali.
- Search Ranking: Search results are ranked using algorithms that consider relevance, distance, popularity, ratings, and personalization signals.
- Utabiri wa Mahitaji: Kwa Washirika wa Biashara, AI huchanganua data ya kihistoria ya mpangilio, mifumo ya misimu, matukio ya karibu nawe na data ya hali ya hewa ili kutabiri mahitaji. Hii hutumia data iliyojumlishwa ya biashara.
- Uboreshaji wa Menyu: AI inapendekeza marekebisho ya bei na marekebisho ya menyu kulingana na data ya mauzo, uchanganuzi wa mshindani, na matakwa ya wateja. Maamuzi ya mwisho daima hufanywa na Mshirika wa Biashara.
- Utambuzi wa Udanganyifu: Mifumo otomatiki huchanganua mifumo ya muamala, maelezo ya kifaa na ishara za tabia ili kutambua shughuli zinazoweza kuwa za ulaghai. Miamala iliyoalamishwa inaweza kukaguliwa na wachanganuzi wa kibinadamu.
- NutriLife AI: AI huchanganua picha za milo ili kukadiria maudhui ya lishe na kutoa mapendekezo ya lishe ya kibinafsi kulingana na wasifu wako wa afya. Tazama Sehemu ya 9 kwa maelezo zaidi.
- Uuzaji wa Kiotomatiki: AI hutengeneza maudhui ya uuzaji, kampeni za barua pepe, na ofa za matangazo kwa Washirika wa Biashara kulingana na mgawanyo wa wateja na data ya tabia.
8.2 Haki Zako Kuhusu Maamuzi ya Kiotomatiki
Under applicable law (including GDPR Article 22), you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where such automated decisions are made:
- You have the right to obtain human intervention and review of the decision.
- You have the right to express your point of view and contest the decision.
- You may request an explanation of the logic involved in the automated decision.
To exercise these rights, contact us at [email protected].
8.3 Ulinzi wa Data wa AI
- Data iliyotumwa kwa watoa huduma wengine wa AI (Anthropic, OpenAI) inachakatwa chini ya makubaliano ya usindikaji wa data ya biashara. Data yako haitumiwi kufunza miundo yao ya madhumuni ya jumla ya AI.
- Mafunzo ya muundo wa AI na Foodfy hutumia data isiyojulikana na iliyojumlishwa ambayo haitambui watumiaji mahususi.
- Matokeo ya AI ni ya uwezekano na yanawasilishwa kama mapendekezo au makadirio, sio maamuzi mahususi.
9. Data ya Afya na Biometriska (NutriLife)
NutriLife huchakata data nyeti inayohusiana na afya na biometriska ambayo inahitaji ulinzi maalum chini ya sheria zinazotumika za faragha. Sehemu hii inatoa maelezo ya kina kuhusu jinsi tunavyoshughulikia data hii.
9.1 Kategoria za Takwimu za Afya Zilizokusanywa
With your explicit consent, NutriLife may collect and process the following categories of health data:
- Physical Measurements: Uzito wa mwili, urefu, asilimia ya mafuta ya mwili, mduara wa kiuno, mduara wa nyonga, na index ya uzito wa mwili (BMI).
- Vital Signs: Viwango vya sukari ya damu, usomaji wa shinikizo la damu, na kiwango cha moyo.
- Viashiria vya Mtindo wa Maisha: Sleep duration, hydration levels, daily step count, energy levels, stress levels, mood, and digestive health indicators.
- Taarifa za Chakula: Maandishi ya shajara ya chakula, picha za milo, ulaji wa kalori na virutubishi (protini, wanga, mafuta, nyuzinyuzi, sukari, sodiamu), ulaji wa virutubishi (vitamini A hadi B12, kalsiamu, chuma, potasiamu, na wengine), aina ya lishe na mizio ya chakula.
- Wasifu wa Afya: Tarehe ya kuzaliwa, jinsia, kiwango cha shughuli, malengo ya afya (kupunguza uzito, kuongezeka, matengenezo), uzito unaolengwa, hali ya kiafya, matumizi ya virutubishi, ujauzito au hali ya kunyonyesha.
- Data ya Uchambuzi wa AI: Picha za mlo zilizochambuliwa na AI, alama za kujiamini, na makadirio ya lishe yanayotokana na AI.
9.2 Msingi wa Kisheria na Idhini
Data ya afya na kibayometriki imeainishwa kama data ya kategoria maalum chini ya GDPR (Kifungu cha 9) na sheria sawa duniani kote. Tunachakata data hii kwa msingi wa idhini yako ya wazi, ambayo unatoa wakati wa kuabiri NutriLife. Unaweza kuondoa idhini yako wakati wowote kwa kuzima NutriLife katika mipangilio ya akaunti yako, jambo ambalo litasababisha kufutwa kwa data yako ya afya ndani ya siku 30.
9.3 Ukomo wa Madhumuni
Your NutriLife health data is used strictly for the following purposes:
- Kukokotoa kiwango chako cha kimsingi cha kimetaboliki (BMR), jumla ya matumizi ya kila siku ya nishati (TDEE), na malengo ya kalori na virutubishi mahususi.
- Tracking your food diary entries and nutritional intake over time.
- Providing AI-powered dietary suggestions and meal plan recommendations.
- Inaonyesha mienendo ya afya na maendeleo kuelekea malengo yako uliyotaja.
9.4 Ulinzi Mkali wa Data
- Data ya afya ya NutriLife imesimbwa kwa njia fiche wakati wa mapumziko na inasafirishwa kwa kutumia usimbaji fiche wa AES-256 na TLS 1.3.
- Data ya afya huhifadhiwa kando na data ya jumla ya Mfumo na vidhibiti vya ziada vya ufikiaji.
- Data ya afya ya NutriLife KAMWE haishirikiwi na makampuni ya bima, waajiri, watangazaji au wahusika wengine kwa madhumuni ambayo hayahusiani na kutoa huduma ya NutriLife.
- Data ya afya KAMWE haitumiki kwa ulengaji wa matangazo au kuuzwa kwa washirika wengine.
- Ufikiaji wa data za afya ndani ya Foodfy unazuiliwa kwa wafanyikazi muhimu na mifumo kwa msingi wa uhitaji wa kujua.
10. Data ya Usajili wa Foodfy Gold
When you subscribe to Foodfy Gold, we process additional data related to your membership:
- Subscription Data: Plan type, subscription status (active, trial, paused, cancelled, expired), start and end dates, trial period dates, and renewal dates.
- Data ya Malipo: Stripe customer ID, Stripe subscription ID, payment method (last four digits and card type only), and billing history. Full card details are stored exclusively by Stripe.
- Matumizi ya Faida: Total orders placed with Gold benefits, delivery savings, discount savings, total calculated savings, and benefit redemption logs.
This data is processed to manage your subscription, apply benefits to eligible orders, calculate your savings, and provide you with subscription management features. Legal basis: performance of contract.
11. Akaunti ya Biashara na Data ya Wafanyakazi
Kwa Foodfy for Work (Akaunti za Biashara), majukumu ya usindikaji wa data yanashirikiwa:
11.1 Uhusiano wa Kidhibiti Data
The enrolling organization (employer) acts as the data controller for employee personal data provided through the Corporate Account. Foodfy acts as a data processor, processing employee data solely as instructed by the employer and in accordance with the Foodfy for Work Data Processing Agreement.
11.2 Data Zilizokusanywa
- Jina la mfanyakazi, anwani ya barua pepe na jukumu ndani ya Akaunti ya Biashara (msimamizi, meneja, mfanyakazi).
- Idara, kituo cha gharama, na nambari ya kumbukumbu ya mfanyakazi kama inavyotolewa na mwajiri.
- Wallet balance, credit history, spending history, and refund records.
- Historia ya agizo lililotengenezwa kwa kutumia pochi ya shirika, ikijumuisha vitu vilivyoagizwa na kiasi.
11.3 Majukumu ya Mwajiri
Waajiri wanawajibika kwa: (a) kuwa na msingi halali wa kushiriki data ya mfanyakazi na Foodfy; (b) kuwafahamisha wafanyakazi kuhusu uchakataji wa data kupitia Jukwaa; (c) kujibu maombi ya haki za data ya mfanyakazi kuhusiana na data inayodhibitiwa na mwajiri; na (d) kuhakikisha utiifu wa sheria zinazotumika za uajiri na ulinzi wa data.
12. Data ya Uendeshaji ya Utoaji wa Drone
When drone delivery services are used, the following additional data is processed:
- Route and GPS Data: Njia za ndege zisizo na rubani, vituo vya relay kupitia maeneo ya DronePort, viwianishi vya GPS vya uwasilishaji, na makadirio ya nyakati za kuwasili.
- Data ya Washirika wa Uwasilishaji: Kwa washirika wa uwasilishaji wenye uwezo wa kutumia ndege zisizo na rubani: eneo la wakati halisi wakati wa usafirishaji unaoendelea, takwimu za uwasilishaji na kumbukumbu za uendeshaji.
- Data ya DronePort: Vipimo vya matumizi ya DronePort, ratiba za matengenezo, na hali ya uendeshaji.
- Data ya Utoaji wa Wateja: Precise delivery coordinates required for safe and accurate drone landing, which may be more precise than standard address-based delivery.
Data ya uwasilishaji wa ndege zisizo na rubani huchakatwa kwa misingi ya kisheria ya utendakazi wa mkataba na, inapohitajika, nia halali katika kudumisha utendakazi wa uwasilishaji salama na bora. Data ya mahali pa wakati halisi ya Washirika wa Utumaji huchakatwa tu wakati wa uwasilishaji unaoendelea.
13. Usalama wa Data
Foodfy hutekeleza hatua za kina, zinazoongoza katika sekta ya kiufundi na shirika ili kulinda data yako ya kibinafsi:
13.1 Ulinzi wa Kiufundi
- Usimbaji fiche wa data yote katika usafiri wa umma kwa kutumia TLS 1.2+ (HTTPS inatekelezwa kwenye sehemu zote za mwisho za Mfumo).
- Usimbaji fiche wa data nyeti ukiwa umepumzika kwa kutumia usimbaji fiche wa AES-256.
- Web application firewall (WAF) and DDoS protection powered by Cloudflare.
- Mtandao wa uwasilishaji wa maudhui (CDN) ulio na akiba ya utendakazi na usalama.
- Uchakataji wa malipo unaotii PCI DSS kupitia Stripe, bila hifadhi ya nambari za kadi kamili kwenye seva za Foodfy.
- Two-factor authentication (2FA) available for all accounts and mandatory for privileged accounts.
- Uthibitishaji wa API kwa kutumia tokeni salama zenye kikomo cha viwango na utambuzi wa matumizi mabaya.
- Regular automated vulnerability scanning and penetration testing.
13.2 Ulinzi wa Shirika
- Role-based access controls ensuring employees can only access data necessary for their function.
- Usanifu wa data wa wapangaji wengi na ugawaji hifadhidata wa nchi mahususi, kuhakikisha data kutoka maeneo tofauti ya mamlaka imetenganishwa kimantiki.
- Mikataba ya usindikaji wa data na watoa huduma wengine wote.
- Regular security awareness training for all personnel with access to personal data.
- Taratibu za majibu ya matukio na timu ya usalama iliyojitolea.
- Mbinu za kupunguza data: tunakusanya tu data muhimu kwa madhumuni maalum.
While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security and encourage all users to take steps to protect their own accounts, including using strong, unique passwords and enabling two-factor authentication.
14. Uhamisho wa Data wa Kimataifa
Foodfy inafanya kazi katika nchi 250+ kupitia miundombinu yake ya kimataifa na mtandao wa Washirika wa Wilaya. Data yako ya kibinafsi inaweza kuhamishwa hadi na kuchakatwa katika nchi zingine kando na nchi yako ya makazi. Tunapohamisha data ya kibinafsi kimataifa, tunaweka ulinzi unaofaa ili kuhakikisha kwamba data yako inaendelea kulindwa:
- Standard Contractual Clauses (SCCs): Kwa uhamisho kutoka EEA/Uingereza hadi nchi zisizo na uamuzi wa utoshelevu, tunatumia Vifungu vya Kawaida vya Mikataba vilivyoidhinishwa na Tume ya Ulaya.
- Mikataba ya Uchakataji Data: Watoa huduma wengine wote wanaochakata data ya kibinafsi kwa niaba yetu wanafungwa na makubaliano ya kina ya usindikaji wa data ambayo yanajumuisha majukumu ya ulinzi wa data, mahitaji ya usalama na ulinzi wa uhamishaji mipakani.
- Ugawaji Data Mahususi wa Nchi: Usanifu wetu wa wapangaji wengi hutumia vijisehemu vya hifadhidata mahususi vya nchi, ambayo ina maana kwamba data ya uendeshaji inahifadhiwa na kuchakatwa ndani au karibu na eneo la kijiografia la Eneo husika, na kupunguza uhamishaji wa mipaka kwa shughuli za kila siku.
- Maamuzi ya Utoshelevu: Where available, we rely on adequacy decisions issued by relevant regulatory authorities.
- Transfer Impact Assessments: We conduct transfer impact assessments for data transfers to countries without adequate data protection frameworks.
15. Haki zako za Faragha
Kulingana na eneo lako, una haki mbalimbali kuhusu data yako ya kibinafsi. Foodfy imejitolea kuheshimu haki hizi kwa watumiaji wote duniani kote:
15.1 Haki za Ulimwengu
Regardless of your location, all Foodfy users may:
- Ufikiaji: Request a copy of the personal data we hold about you in a structured, commonly used, machine-readable format.
- Marekebisho: Request correction of inaccurate, incomplete, or outdated personal data. You can update most information directly through your account settings.
- Ufutaji: Request deletion of your personal data, subject to legitimate retention requirements (legal obligations, dispute resolution, fraud prevention).
- Restriction: Request that we restrict the processing of your personal data in certain circumstances.
- Pingamizi: Pingamizi uchakataji wa data yako ya kibinafsi kwa madhumuni ya uuzaji wa moja kwa moja. Tutatii maombi yote ya kuondoka mara moja.
- Withdrawal of Consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.
- Ufutaji wa Akaunti: Request complete deletion of your account and associated personal data. Account deletion requests are processed within 30 days.
15.2 Jinsi ya Kutumia Haki Zako
You may exercise your rights by:
- Kufikia mipangilio ya akaunti yako kwa usimamizi wa data ya huduma binafsi, mabadiliko ya mapendeleo na kufuta akaunti.
- Kutuma barua pepe kwa Afisa wetu wa Ulinzi wa Data kwa [email protected] na ombi lako.
- Kutuma barua pepe kwa [email protected] kwa maswali ya faragha ya jumla.
We will verify your identity before processing requests and respond within the timeframe required by applicable law (typically 30 days, extendable by an additional 60 days for complex requests with prior notification to you).
16. Haki za Faragha za Kikanda
The following supplemental provisions apply based on your location and the applicable data protection law:
16.1 Eneo la Kiuchumi la Ulaya na Uingereza (GDPR / GDPR ya Uingereza)
Ikiwa unaishi EEA au Uingereza, una haki zifuatazo za ziada chini ya Kanuni ya Jumla ya Ulinzi wa Data:
- Kubebeka kwa Data: Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.
- Uamuzi wa Kiotomatiki: Right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects (GDPR Article 22). See Section 8.2.
- Afisa Ulinzi wa Takwimu: DPO yetu inaweza kupatikana kwa [email protected] kwa maswali yoyote yanayohusiana na GDPR.
16.2 California, Marekani (CCPA / CPRA)
Ikiwa wewe ni mkazi wa California, una haki zifuatazo chini ya Sheria ya Faragha ya Mteja ya California (kama ilivyorekebishwa na Sheria ya Haki za Faragha ya California):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources of collection, the business purpose for collecting, and the categories of third parties with whom we share it.
- Right to Delete: Request deletion of your personal information, subject to statutory exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: Foodfy haiuzi maelezo yako ya kibinafsi. Hatushiriki maelezo ya kibinafsi kwa utangazaji wa tabia ya muktadha tofauti bila idhini yako.
- Right to Limit Use of Sensitive Personal Information: Request limitation of the use and disclosure of sensitive personal information to what is necessary for the purposes specified.
- Kutokuwa na Ubaguzi: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
Katika kipindi cha miezi 12 iliyopita, hatujauza taarifa za kibinafsi kama ilivyofafanuliwa na CCPA/CPRA.
16.3 Brazili (LGPD)
Iwapo unaishi Brazili, una haki chini ya Lei Geral de Protecao de Dados (LGPD), ikijumuisha haki ya: uthibitisho wa kuchakata, kufikia, kusahihisha, kutokujulikana, kubebeka, kufuta data iliyochakatwa kwa kibali, maelezo kuhusu kushiriki, na haki ya kutuma maombi kwenye Autoridade Nacional de Protecao de Dados (ANPD).
16.4 Asia-Pasifiki (PDPA na Sheria Sawa)
Iwapo uko katika maeneo ya mamlaka yenye Sheria za Ulinzi wa Data ya Kibinafsi au sheria sawa (ikiwa ni pamoja na Singapore, Thailand, na nchi nyingine za Asia-Pasifiki), una haki za kufikia, kusahihisha, kufuta, kuwekewa vikwazo na kubebeka kwa data yako ya kibinafsi kama inavyotolewa na sheria ya eneo husika. Tunachakata data yako kwa kufuata mahitaji yanayotumika ya PDPA, ikijumuisha kupata idhini inapohitajika na kutoa notisi ya uwazi ya shughuli za kuchakata data.
16.5 Mashariki ya Kati na Afrika Kaskazini
Kwa watumiaji katika UAE, Saudi Arabia na maeneo mengine ya mamlaka ya MENA, tunatii kanuni zinazotumika za ulinzi wa data ikijumuisha Sheria ya Amri ya Shirikisho ya UAE kuhusu Ulinzi wa Data ya Kibinafsi, Sheria ya Ulinzi wa Data ya Kibinafsi ya Saudi Arabia na mifumo sawa ya kikanda. Hii inajumuisha mahitaji ya ujanibishaji wa data inapohitajika.
16.6 Mamlaka Nyingine
Foodfy imejitolea kutii sheria za ulinzi wa data katika maeneo yote ya mamlaka tunakofanyia kazi. Ikiwa eneo lako la mamlaka lina mahitaji mahususi ya ulinzi wa data ambayo hayajaorodheshwa hapo juu, tafadhali wasiliana na [email protected] kwa maelezo kuhusu jinsi tunavyolinda haki zako chini ya sheria ya eneo lako.
17. Arifa ya Uvunjaji wa Data
Katika tukio la ukiukaji wa data ya kibinafsi ambayo inahatarisha haki na uhuru wako, Foodfy atafanya:
- Iarifu mamlaka husika ya usimamizi ndani ya saa 72 baada ya kufahamu ukiukaji huo, kama inavyotakiwa na Kifungu cha 33 cha GDPR na masharti sawia katika maeneo mengine ya mamlaka.
- Waarifu watu walioathiriwa bila kuchelewa kusikostahili wakati ukiukaji huo unaweza kusababisha hatari kubwa kwa haki na uhuru wao, kama inavyotakiwa na Kifungu cha 34 cha GDPR na masharti sawa.
- Provide details of the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
- Andika ukiukaji wote wa data ya kibinafsi, ikijumuisha ukweli, athari na hatua za kurekebisha zilizochukuliwa, kwa mujibu wa rejista yetu ya ndani ya ukiukaji.
Ikiwa unaamini kuwa data yako imeingiliwa, tafadhali wasiliana mara moja na [email protected].
18. Watoto na Wadogo
The Platform is not intended for use by individuals under the age of 18, or the age of digital consent in their jurisdiction (which may be lower, such as 16 in most EEA countries or 13 in the United States under COPPA). We do not knowingly collect personal information from children below the applicable age threshold.
Tukifahamu kwamba tumekusanya data ya kibinafsi kutoka kwa mtoto chini ya umri unaoruhusiwa bila kukusudia bila ridhaa ya mzazi au mlezi, tutachukua hatua za haraka kufuta maelezo hayo kwenye mifumo yetu. Ikiwa unaamini kuwa tumekusanya taarifa kutoka kwa mtoto, tafadhali wasiliana nasi mara moja kwa [email protected].
19. Viungo na Huduma za Watu wa Tatu
The Platform may contain links to third-party websites, applications, and services. This Privacy Policy does not apply to any third-party services, and Foodfy is not responsible for the privacy practices, content, or security of any third party. This includes Business Partner websites built using the Foodfy Website Builder, which may contain additional third-party integrations selected by the Business Partner.
We encourage you to review the privacy policy of every third-party service you interact with.
20. Mabadiliko ya Sera hii ya Faragha
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes:
- We will update the "Last updated" date at the top of this page.
- We will provide prominent notice on the Platform.
- Kwa mabadiliko ya nyenzo ambayo yanaathiri pakubwa jinsi tunavyochakata data yako, tutakuarifu kwa barua pepe angalau siku 30 kabla ya mabadiliko hayo kutekelezwa.
- Where required by law, we will obtain your consent to material changes in data processing practices.
Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
21. Wasiliana Nasi
Ikiwa una maswali yoyote, wasiwasi, au maombi kuhusu Sera hii ya Faragha, data yako ya kibinafsi, au desturi zetu za ulinzi wa data, tafadhali wasiliana nasi kupitia njia zifuatazo:
- Afisa Ulinzi wa Takwimu: [email protected]
- Privacy Inquiries: [email protected]
- Security Issues: [email protected]
- Msaada wa Jumla: [email protected]
- Tovuti: foodfy.ai
We are committed to resolving any complaints about our collection or use of your personal data. If you have a complaint, please contact us first. If we are unable to resolve your concern, you have the right to lodge a complaint with your local data protection supervisory authority.