Online Card Payment Processing Fees
At Beneat we take data protection seriously. Privacy and information security are at the heart of Beneat. This Privacy Policy Statement describes the key principles and practices we abide by in order to ensure your privacy is respected while using our services.
Beneat s. r. o. (“Beneat”, “we”) process personal data of users of Beneat beauty, wellness and well-being services ordered through Beneat application (“Beneat App”) and users of other Beneat products and services and the visitors of the website thebeneat.com (“Website”).
In this Privacy Statement, the word “Beneat Services” refers jointly to the Website and the Beneat App and other services provided by Beneat to users. In this Privacy Statement, the word “User” or “you” refers jointly to our and our group companies’ customers, users of Beneat delivery services and representatives potential customers and the users of the Beneat Services. Our Privacy Statement explains, for example, the types of personal data we process, how we process the personal data and how you may exercise your rights as a data subject (for example, right to object, right of access).
Some of our services might be subject to a separate privacy policy. If a separate privacy policy applies to a particular service, we will post it in connection with the service in question.
This Privacy Statement may be updated from time to time in order to reflect the changes in data processing practices or otherwise. You can find the current version on the Website. We will not make substantial changes to this Privacy Statement or reduce the rights of the Users under this Privacy Statement without providing a notice thereof.
1. DATA CONTROLLERS
This Privacy Statement applies to processing of personal data carried out by Beneat - TBD
2. BENEAT’S CONTACT DETAILS
Beneat s. r. o.
Business ID: TBD
Correspondence address: TBD
E-mail address: support@thebeneat.com
Data Protection Officer: Beneat has appointed a data protection officer who you can reach through the above contact details or by sending e-mail to privacy@thebeneat.com.
3. PERSONAL DATA PROCESSED AND SOURCES OF DATA
We process personal data only to the extent necessary and appropriate for the specific processing purpose. The personal data collected and processed by us can be divided into two general data categories: User Data and Usage Data.
User Data
User Data is personal data collected directly from you on behalf of which you are using the Beneat Services, as the case may be. We may collect User Data from our Users in a variety of ways, including, after conclusion of a service agreement with the Users when register to the Beneat Services, subscribe to a newsletter or fill out a form. Further, please note that we also collect details of any transactions and payments you carry out through the Beneat Services.
User Data that is necessary in order to use the Beneat Services
The following personal data collected and processed by us is necessary in order for a proper performance of the contract between you and us for the compliance with our legal obligations.
When you register to the Beneat Services and create a user account, you need to provide us with the following information:
- full name
- telephone number
- email address
User Data you give us voluntarily and while using Beneat Services
Your user or customer experience may be enhanced by providing us with the following information:
Additional Account Information:
- a picture,
- address where services are provided,
- location data (if you consent to the processing of your location data),
- partner-specific bonus card or participation in other loyalty programme if applicable in your country,
- when ordering age-restricted goods or services: age, and
- other information you provide either when creating a user account or later when modifying your account profile.
Other Information. We may also process other information provided by you voluntarily such as:
- information related to your orders from Beneat or through Beneat Services (for example, services or items purchased, special instructions, date and time of order, total amount of order and other order history),
- information you provide when submitting ratings, comments or responding to surveys,
- favorite partner locations or merchants and other preferences,
- marketing opt-ins and opt-outs, and
- information you provide by phone or in email or chat correspondence with us, including call recordings of your calls with our customer service.
In addition to User Data collected from you, we process certain personal data third party service providers provide about you. For example, for corporate customers, we may process company contact person information to enable communication and marketing with the company as well as managing the customer relationship. Such data is primarily obtained from public sources such as local trade registers, companies providing this type of information services, or the companies themselves.
If your order contains products or services which may imply a health condition or other sensitive (special category) personal data, Beneat needs to process this data in order to provide the Beneat Services to you. In addition to the contents of the order, this may also include, for example, medical prescription data in the case of prescription medicine. Beneat adheres to any additional safeguards that may apply to processing such personal data under applicable laws and regulations. If required under applicable laws, Beneat will ask for separate consent for processing such personal data and you may withdraw such consent anytime through your profile settings or by contacting Beneat support at support@thebeneat.com.
If you connect or login to your account with Facebook, Facebook shares with us personal information about you such as your profile picture, a sample of your Facebook friends and your Facebook ID. While Beneat maintains its page on Facebook both Beneat and Facebook are joint controllers for your personal data. More information on processing of personal data on Facebook is available at Meta Privacy Policy.
Usage Data
Usage Data arises from User interactions with the Beneat Services. Although we do not normally use Usage Data to identify you as an individual, you can in certain circumstances be identified from it, either alone or when combined or linked with User Data. In such situations, Usage Data can also be considered personal data under applicable laws and we will treat such data as personal data.
We may automatically collect the following Usage Data when you visit or interact with the Beneat Services:
Information that describes your device or browser and Beneat’s application, their versions, features, capabilities, and settings
Information about your operator, Internet service provider and network connection type, including your IP address
Identifiers provided by your device or third parties for application vendors or advertisers, or identifiers we create ourselves
Country, locale, time zone and geo-IP level location information
Where you followed a link to Beneat Services, and links you followed from Beneat Services
Details of your interactions with, and usage of, Beneat Services. This includes, for example, usage patterns, which features you use, advertisement, participating into a specific campaign and offer impressions and interactions, and information on orders
Data for tracking and reporting transactions initiated by our advertising partners, including timestamps, and identifiers mentioned above
For details on how to control advertising and analytics identifiers on your device, see below under the section “Cookies and other technologies”.
Cookies and other technologies
We use various technologies to collect and store Usage Data and other information when the Users visit the Beneat Services, including cookies, storing website data, and using web and application telemetry.
Cookies and other website data saved on your device allow us to identify visitors of the Beneat Services and facilitate the use of the Beneat Services and to create aggregate information of our visitors. This helps us to improve the Beneat Services and better serve our Users. The cookies and other website data will not harm your device or files. We use cookies and other website data to tailor the Beneat Services and the information we provide in accordance with the individual interests of our Users. Please note that the retention time of different cookies is limited and varies from less than a minute till indefinitely and when a specific cookie is deleted.
You can manage the cookie preferences you have submitted earlier by clicking thebeneat.com/cz/privacy/#manage-gdpr-consents. TBD → manage GDPR consent page required
The Users may choose to set their web browser to refuse cookies. For example, the following links provide information on how to adjust the cookie and other web data settings on some popular browsers:
Please note that some parts of the Beneat Services may not function properly if use of cookies is refused.
The Beneat Services use pseudonymized identifiers to track and predict your app and service usage and preferences. Beneat also uses session-only 3rd-party tracking technologies to verify and report transactions initiated by our advertising partners.
You can manage your cookie preferences through the cookie banner on our websites.
You can also manage your communication and other privacy settings via Beneat App.
Beneat visitor identifiers can be disabled on iOS and Android mobile devices by changing your settings (for iOS: Settings → Beneat → Beneat settings → Limit Tracking, and for Android: Beneat application → Profile tab → Settings icon in the top-right corner).
Generally, advertising identifiers can be disabled on iOS mobile devices by turning on the Limit Ad Tracking tab (Settings → Privacy → Advertising → Limit Ad Tracking). For an overview and more information on the advertising identifier, please see Apple Advertising and Privacy site.
Beneat uses different third party analytics and telemetry providers, marketing or affiliate partners, and other services integrated into our client software listed below:
TBD → list must be upgraded after we normalize cookies and other 3rd party vendors
| Name | Vendor | Purpose | Vendor privacy statement | | --- | --- | --- | --- | | Google Analytics | Google | Visitor and usage analytics | Link | | Google AdSense | Google | Ad Targeting | Link | | Google Tag Manager | Google | Analytics and reporting | Link | | Upwave | Upwave | Analytics, marketing and reporting on Beneat app | Link | | AppsFlyer | AppsFlyer | Analytics, marketing and reporting on Beneat app. | Link | | hCaptcha | Intuition Machines, Inc. | Bot detection and avoidance and reporting | Link | | Bugsnag | SmartBear Software Inc. | Error event and performance tracking on websites and apps | Link | | Facebook Graph API | Meta | Ads management | Link | | Facebook Pixel | Meta | Advertising/ conversion tracking | Link | | Firebase | Firebase | Mobile and web application development platform | Link | | Intercom | Intercom | Chat with customer support | Link | | Ravelin | Ravelin | Anti-fraud | Link | | Riskified | Riskified | Payment fraud preventiont | Link | | Adform | Adform | Managing and delivering online ads | Link | | Floodlight | Floodlight | Advertising/conversion tracking | Link | | Microsoft Clarity | Microsoft | User heatmaps analysis | Link | | Interspace | Interspace (Accesstrade) | Affiliate marketing platform | Link | | Microsoft Bing | Microsoft | Search engine | Link | | Iterable | Iterable | Marketing automation | Link | | LinkedIn InsightTag | LinkedIn Marketing Solutions | Advertising/conversion tracking | Link | | Taboola Pixel | Taboola | Advertising/conversion tracking | Link | | TradeDoubler | TradeDoubler | Advertising/conversion tracking | Link | | Twitter Universal Website Tag | Twitter Ads | Advertising/conversion tracking | Link | | Yahoo | Yahoo | Advertising/conversion tracking | Link | | Reddit Pixel | Reddit Ads | Advertising/conversion tracking | Link | | Sentry | Sentry.io | Functional software | Link |
Please note that not all of the above vendors are necessarily being used at any given time, or on all market areas.
4. THE PURPOSES AND GROUNDS FOR THE PROCESSING
We process personal data only to the extent necessary and appropriate for the specific processing purposes. Please note that one or more of the following purposes and legal grounds may apply simultaneously.
Firstly, Beneat processes your personal data to perform our contractual obligations towards you, for example, to the extent necessary to:
- offer the Beneat Services to you under the contract between you and Beneat
- perform the contract between you and Beneat and for purposes of managing and delivering your Order as well as communicating with you about changes to terms and conditions, privacy policies, or other important changes related to the contract;
- handle your payments or any refunds (where applicable) and to provide our partners (the restaurants, retailers and our courier partners hereinafter collectively also as “Partner”)) with the information necessary for the delivery of your order; and
- to answer your questions or solve your support cases if you contact us.
Secondly, we may process your personal data if there is an appropriate and justifiable interest (that is, a legitimate interest) to run, maintain and develop our business or to create and maintain customer relationships. When choosing to use your data on the basis of our legitimate interests, we weigh our own interests against your right to privacy and, for example, provide you with easy to use opt-out from our marketing communications and use pseudonymized or non-personally identifiable data when possible. You have the right to object processing of your data on the basis of legitimate interest. However, Beneat can refuse such an objection in accordance with applicable legislation, for example, if the processing is necessary for preparing, exercising or defending legal claims.
We process your personal data to the extent necessary and based on legitimate interest, for example, to:
- claims handling, debt collection and legal processes. We may also process data for the prevention of fraud, misuse of our services and for information, system and network security and safety.
- contact you regarding the Beneat Services and to inform you of changes relating to them or asking your review or feedback on Beneat Services.
- market the Beneat Services to you or show you targeted or personalized advertisements through Beneat Services or send you otherwise targeted marketing of services or products that may be of your interest. In order to form such a target group we may process information listed above in the section on Usage Data. Please note that if required by applicable law processing of personal data for marketing purposes will be based on your consent (see also section “Direct Marketing” below).
- improve the quality of the Beneat Services and develop our business, for example, by analyzing any trends in the use of the Beneat Services by processing data related to your use of Beneat Services.
- ensure that our services are in line with your needs, personal data can be used for things like customer satisfaction surveys. When possible, we will do this using only aggregated, non-personally identifiable data.
- process your data within the Beneat in accordance with this Privacy Statement.
While processing your personal data for the purposes of providing Beneat Services to you as well as other purposes stated above we may use automated means in processing that may also include automated decision-making.
Further, we may process your personal data to administer and fulfill our legal obligations. This includes data processed for complying with our bookkeeping obligations and providing information to relevant authorities such as tax authorities or law enforcement authorities in accordance with mandatory legal provisions.
In some parts of the Beneat Services, you may be requested to grant your consent for the processing of personal data. For example, within Beneat App you may manage your marketing and other permissions. If processing of your personal data is based on your consent, you may withdraw it at any time by contacting us or amending the respective consent setting for example within the Beneat App.
5. TRANSFER TO COUNTRIES OUTSIDE EUROPE
Beneat stores your personal data primarily within the European Economic Area. However, we have service providers, operations and group companies in several geographical locations. As such, we and our service providers may transfer your personal data to, or process it in, jurisdictions outside the European Economic Area or the User’s domicile.
We will take steps to ensure that the Users’ personal data receives an adequate level of protection in the jurisdictions in which they are processed. We provide appropriate and adequate protection for the transfers of personal data to countries outside of the European Economic Area through a series of agreements with our service providers based on the Standard Contractual Clauses or through other appropriate safeguards.
More information regarding the transfers of personal data may be obtained by contacting us on any of the addresses indicated above.
6. DATA RECIPIENTS
We only share your personal data within the organization of Beneat if and as far as reasonably necessary for the purposes of this Privacy Statement.
We do not share your personal data with third parties outside of Beneat organization unless one of the following circumstances applies:
For the purposes set out in this Privacy Statement and to authorized service providers
To the extent that third parties (such as the beauty, wellness and well-being service providers, merchants or retailers which provide your order) need access to personal data in order for us to perform the Beneat Services or for other legitimate reasons, we provide such third parties with your data. As an example, we may share your phone number with the Partner you ordered from if it's necessary, for example, for asking you whether you accept a replacement product in the order or to inform you that an item is missing from your order or for any special request clarifications.
Furthermore, we may provide your personal data to our group companies or to authorized service providers who perform services for us (including data storage, accounting, analytics, sales and marketing and payment fraud prevention) to process it for us and to payment service providers to process your payments to us.
When data is processed by third parties on behalf of Beneat, Beneat has taken the appropriate contractual and organizational measures to ensure that your data are processed exclusively for the purposes specified in this Privacy Statement and in accordance with all applicable laws and regulations and subject to our instructions and appropriate obligations of confidentiality and security measures.
Please bear in mind that if you provide personal data directly to a third party, such as through a link in the Beneat Services, the processing is typically based on their policies and standards.
With Partners for the performance of Beneat Services
To the extent that third parties, such as the Partners which prepare, sell and/or deliver your order, our partners who deliver your order need access to personal data in order for us to perform the Beneat Services, we provide such third parties with your data.
We provide the Partner and where applicable, its parent company or franchisor, with personal data necessary to fulfill your order. Depending on the Partner’s role this may include your name, delivery address and data relating to your purchase, including venue details, order number, time of order and delivery, delivery method, ordered products, comments and feedback that you've given about the order. Such data is shared for enabling the Partner to provide the order including, where applicable, picking up the products in the store, ensuring the quality of the Partner's service and product selection available at Beneat as well as complying with Partner's legal obligations. Where Partner processes such details for purposes of fulfilling its own rights and obligations, such as its legal obligations towards you, Partner is independent controller of the Personal Data and responsible for the lawfulness of its processing operations.
You may be able to add the details of your Partner-specific bonus card or loyalty program on the Beneat Service for purposes of linking any orders placed at the Partner to the relevant loyalty program, in accordance with the terms defined by Partner. Beneat will share such details to the Partner and Partner is independent controller of such details and thereby responsible for ensuring lawfulness of the processing.
We may also share your phone number and name with the Partner you ordered from if it's necessary, for example, for asking you whether you accept a replacement product in the order or to inform you that an item is missing from your order or for any special request clarifications or other necessary purposes related to completing the order. For deliveries that are performed by our merchant partners themselves we may also share your delivery address and phone number with those Partners.
For legal reasons and legal processes
We may share your personal data with third parties outside Beneat if we have a good-faith belief that access to and use of the personal data is reasonably necessary to: (i) meet any applicable law, regulation, and/or court order; (ii) detect, prevent, or otherwise address fraud, crime, security or technical issues; and/or (iii) protect the interests, properties or safety of Beneat, the Users or the public as far as in accordance with the law. When possible, we will inform you about such processing.
For other legitimate reasons
If Beneat is involved in a merger, acquisition or asset sale, we may transfer your personal data to the third party involved. However, we will continue to ensure the confidentiality of all personal data. We will give notice to all the Users concerned when the personal data are transferred or become subject to a different privacy statement.
With your explicit consent
We may share your personal data with third parties outside Beneat when we have your explicit consent to do so. You have the right to withdraw this consent at all times free of charge, for example, by contacting us.
7. STORAGE PERIOD
Beneat does not store your personal data longer than is legally permitted and necessary for the purposes of providing the Beneat Services or the relevant parts thereof. The storage period depends on the nature of the information and on the purposes of processing. The maximum period may therefore vary per use.
After a User has deleted their user account personal data may be stored only as long as such processing is required by law or is reasonably necessary for our legal obligations or legitimate interests such as claims handling, bookkeeping, internal reporting and reconciliation purposes.
We assess regularly the storage period for personal data to ensure the data is stored only for the necessary time period.
8. YOUR RIGHTS
Right of access
You have the right to access and be informed about your personal data processed by us. We give you the possibility to view certain data through your user account with the Beneat Services or request a copy of your personal data by contacting us.
Right to withdraw consent
In case the processing is based on a consent granted by the User, the User may withdraw the consent at any time free of charge. Withdrawing a consent may lead to fewer possibilities to use the Beneat Services. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Right to rectify
You have the right to have incorrect or incomplete personal data we have stored about you corrected or completed by contacting us. You can correct or update some of your personal data through your user account in the Beneat Services.
Right to erasure
You may also ask us to delete your personal data from our systems. We will comply with such a request unless we have a legitimate ground to not delete the data.
Right to object
You may have the right to object to certain use of your personal data if such data are processed for other purposes than necessary for the performance of the Beneat Services or for compliance with a legal obligation. If you object to the further processing of your personal data, this may lead to fewer possibilities to use the Beneat Services.
Right to restriction of processing
You may request us to restrict processing of personal data for example when your data erasure, rectification or objection requests are pending and/or when we do not have legitimate grounds to process your data. This may however lead to fewer possibilities to use the Beneat Services.
Right to data portability
You have the right to receive the personal data you have provided to us yourself in a structured and commonly used format and to independently transmit those data to a third party.
How to use your rights
The abovementioned rights may be used by contacting Beneat support or sending a letter or an e-mail to us on the addresses set out above, including the following information: the full name, address, e-mail address and a phone number. If you have Beneat account we recommend you contacting us through Beneat support as that allows us to identify you more easily. We may request the provision of additional information necessary to confirm the identity of the User. We may reject or charge requests that are unreasonably repetitive, excessive or manifestly unfounded.
9. DIRECT MARKETING
The User has the right to prohibit us from using the User’s personal data for direct marketing purposes, market research and profiling made for direct marketing purposes by contacting us on the addresses indicated above or by using the functionalities of the Beneat Services or the unsubscribe possibility offered in connection with any direct marketing messages.
10. LODGING A COMPLAINT
In case the User considers our processing of personal data to be inconsistent with the applicable data protection laws, the User may lodge a complaint with the local supervisory authority for data protection in Czech Republic, the Data Protection Ombudsman TBD → link to ombudsman. Alternatively, the User may lodge a complaint with the other local and competent supervisory authority for data protection.
11. INFORMATION SECURITY
We use administrative, organizational, technical, and physical safeguards to protect the personal data we collect and process. Measures include for example, where appropriate, encryption, pseudonymization, firewalls, secure facilities and access right systems. Our security controls are designed to maintain an appropriate level of data confidentiality, integrity, availability, resilience and ability to restore the data. We regularly test the Beneat Services, systems, and other assets for security vulnerabilities. Furthermore, access to personal data by employees of Beneat is restricted and access is subject to what is necessary for purposes of the employee’s work assignments.

