IDH Privacy Statement for suppliers and business partners

Version: 08 Jun 2020

This privacy notice works via a so-called ‘collapsing model’.  The headings can be displayed as an FAQ.  The text underneath the headings with the “>” symbol will expand when you click the heading.

1. Introduction

This is the IDH Privacy Statement for supplier and business partner data.  This Privacy Statement provides information on the processing of personal data by IDH and its global representative offices and subsidiaries (The term ‘IDH subsidiaries’ is used here to refer to IDH entities set up outside of the Netherlands, irrespective if this IDH entity is indeed a subsidiary of IDH’s headquarters in the Netherlands in formal governance terms), hereafter IDH, we or us.

The primary purpose of this Privacy Statement is to be a dynamic resource and business tool so that we can offer our services to you in the best possible way.  We want you to feel secure when visiting our website and are committed to maintaining your privacy when doing so.

This Privacy Statement may be changed over time.  The most up-to-date Privacy Statement is published on our website: www.idhsustainabletrade.com (“Website”). This Privacy Statement was last changed on 08 Jun 2020.

This Privacy Statement is applicable to the processing by IDH of all personal data of its customers, suppliers and business partners and other individuals.  This Privacy Statement does not address the processing of personal data of employees in the context of their employment relationship with IDH.

IDH and/or its global representative offices are the controllers of the processing of all personal data that fall within the scope of this Privacy Statement.  This Privacy Statement indicates what personal data are processed by IDH and for what purpose, and to which persons or entities the data will or may be provided. IDH may share your personal data with third parties.  To read more about that, see heading 6.3.

4. For which purposes do we process your personal data?

(a) For answering your questions 

(i) What does this purpose entail?

If you get in touch with us at office@idhtrade.org or any other IDH e-mail address, we will use your personal data in order to reply to and answer your question.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data on the basis of IDH’s legitimate interest of engaging with persons who get in touch with us via e-mail.

(iii) Which personal data do we process for this purpose?

For this purpose, we process your name, contact details, your correspondence with IDH about your question and all other personal data which are necessary to answer your question.

(iv) For what period do we retain your personal data for this purpose?

If you have contacted us via office@idhtrade.org or any other IDH e-mail address then your data will be retained for six months.

 

 

(b) For the development and improvement of products and/or services 

(i) What does this purpose entail?

We process your personal data in order to assess, analyse and improve our products and (customer) services.  We use aggregated personal data to analyse customer behaviour and to adjust our products and services accordingly.  When you use a Website, enter or search data through this Website; we also process your personal data to compile analytics reports.  We use aggregated personal data to analyse customer behaviour and to adjust our products and services accordingly, to ensure that it is relevant to our customers.  This means that we analyse how often you read our newsletters, how often you visit our Website and which pages you click on.

Based on the information above, we can make adjustments to our newsletters or our Website.  We may also perform research into market trends through statistical analysis to evaluate and adapt our products and marketing to new developments, but research results are only reported on an aggregated basis.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for IDH’s legitimate interest of diagnostic analytics to assess the number of visitors, posts, page views, reviews and followers for business intelligence and in order to optimise IDH’s future marketing campaigns.

(iii) Which personal data do we process for this purpose?

For this purpose, we may process your contact details such as your name, email address and correspondence with us.  In addition, we process the personal data you entered into a Website or that were generated by the functionalities you used in a Website and the technical data from your device such as its IP-address, server domain, the pages you visited on our Websites, your click- and surf behaviour and the length of your session.

(iv) For what period do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for one year.  After this term, your personal data will be deleted from our systems.

 

 

(c) To protect safety, security and to ensure integrity

(i) What does this purpose entail?

At IDH, we value your health, safety, security and integrity highly.  We process your personal data in order to safeguard our employees, suppliers and business partners.  As such, we authenticate your access rights to our premises and may screen your personal data against publicly available government and/or law enforcement agency sanctions lists.  We also process your personal data to protect IDH and employee assets.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for IDH’s legitimate interest of general business operations and due diligence.

(iii) Which personal data do we process for this purpose?

For this purpose, we process your contact details such as your email address, personal details such as your name and company you work for, your license plate number if you use one of our parking spaces and your visiting history to IDH premises.

(iv) For what period do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for one year.  After this term, your personal data will be deleted from our systems.

 

 

(d) To comply with the law

(i) What does this purpose entail?

In some cases, IDH processes your personal data to comply with laws and regulations.  This could, for example, be the case where tax or business conduct related obligations apply.

In order to comply with relevant laws and regulations, we may need to disclose your personal data to government institutions or supervisory authorities.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data to comply with legal obligations that IDH is subject to.

(iii) Which personal data do we process for this purpose?

For this, we process your contact details such as your address and email address, personal details such as your name and date of birth, payment information and your chamber of commerce and VAT details and tax details.

(iv) For what period do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for seven years.  After this term, your personal data will be deleted from our systems.

(a) To deliver you our Website’s functionalities and for their technical and functional management 

(i) What does this purpose entail?

If you use our Website, we process technical data to offer you our Website functionalities and to allow our Website’s administrators to manage and improve our Website’s performance.  We process your personal data to allow you to share pages with others using the sharing options you have configured on your device. IDH also uses cookies to ensure you can retrieve information from our Websites quickly and easily, read more about cookies under header 5.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for IDH’s legitimate interest of marketing and diagnostic analytics to assess the number of visitors, posts, page views, reviews and followers in order to optimise IDH’s future marketing campaigns.

(iii) Which personal data do we process for this purpose?

For this purpose, we process the personal data you have entered into our Websites or that is generated by the functionalities you have used in our Websites and the technical data from your device such as its IP address, server domain, the internet browser you use, the pages you have visited on our Websites, your click- and surf behaviour and the length of your session.

(iv) How long do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for one year.  After this term, your personal data will be deleted from our systems.

 

 

(b) To allow you to connect with us (e.g. via social media)

(i) What does this purpose entail?

IDH is active on social media platforms like Facebook, Twitter, LinkedIn and YouTube.  When you contact IDH via social media, we process your personal data in order to answer your questions and to respond to your messages.

In addition, when you visit a ‘Connect with us’ screen on one of our Websites, you can contact us through a variety of communication channels.  We provide you with our email address, for you to send us your feedback and suggested improvements, as well as our Website, Twitter, Facebook and YouTube details.  When you click one of the corresponding icons we will refer you to the website or app of the applicable third party, whether this is your email provider or a social media platform.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for IDH’s legitimate interest of direct marketing and diagnostic analytics to assess the number of visitors, posts, page views, reviews and followers for business intelligence and in order to optimise IDH’s future marketing campaigns.

(iii) Which personal data do we process for this purpose?

For this, we process the communication channel you have chosen to use to connect with us and the personal data you supply to IDH.  This includes your (user) name, address, email address and the personal data you have included in your message.  In addition, when you click one of the buttons displayed, the relevant third party might place cookies on your device.  To read more about cookies, see heading 5.

(iv) How long do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for one year. After this term, your personal data will be deleted from our systems.

 

(a) For the assessment and acceptance of a supplier, consultant or business partner

(i) What does this purpose entail?

When you get in contact with IDH, we will process your personal data for assessment and acceptance purposes, for example in order to confirm and verify your identity. IDH will further process your personal data for other administrative purposes such as due diligence and screening against publicly available government and/or law enforcement agency sanctions lists.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for IDH’s legitimate interest of administrative purposes, fraud detection and prevention, general business operations and due diligence.

(iii) Which personal data do we process for this purpose?

For this purpose, we process your contact details such as your address and email address, personal details such as your name and date of birth, passport number, bank details and details of your correspondence with us.

(iv) For what period do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for seven years after the termination of the business relationship.  After this term, your personal data will be deleted from our systems.

 

 

(b) For the conclusion and execution of agreements

(i) What does this purpose entail?

When you work together with us as a supplier, consultant or business partner, we process your personal data for administrative purposes such as sending invoices and making payments.  We also use your personal data in order to deliver or receive and administer our or your services. IDH will process your personal data in order to further execute our agreement.

When you require access to IDH’s premises, we process your personal data for screening purposes.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for the performance of the agreement to which you are party or in order to take the necessary steps prior the entering into an agreement.

(iii) Which personal data do we process for this purpose?

For this purpose, we process your contact details such as your address and email address, personal details such as your name and date of birth, bank details, payment information and other data stored in our supplier, consultant and business partner database.

(iv) For what period do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for seven years after the termination of the business relationship.  After this term, your personal data will be deleted from our systems.

 

 

(c) For relationship management and marketing 

(i) What does this purpose entail?

IDH uses the information stored in its customer database to contact you about events organized by IDH, as well as to provide customer services and perform account management.

(ii) On what legal basis do we process personal data for this purpose?

We process your personal data for IDH’s legitimate interest of general business operations, such as relationship management, and marketing.

(iii) Which personal data do we process for this purpose?

For this purpose, we process your contact details such as your name, work address, email address, telephone number, work title and company you work for.

(iv) For what period do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for five years.  After this term, we will assess whether this personal data is still required for this purpose. If not, your personal data will be deleted from our systems.

 

 

(d) For business process execution and internal management

(i) What does this purpose entail?

We process your personal data in the performance and organisation of our business. This includes general management and management of IDH assets. IDH also processes your personal data for its internal management. We provide central processing facilities in order to work more efficiently. We conduct audits and investigations, implement business controls, and manage and use supplier and business partner directories. Also, we process your personal data for finance and accounting, archiving and insurance purposes, legal and business consulting and in the context of dispute resolution.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for the purposes of IDH’s legitimate interests of general business operations, internal mangement and compliance with legal and financial obligations.

(iii) Which personal data do we process for this purpose?

For this purpose, we process your contact details such as your address and email address, personal details such as your name and date of birth, payment and credit information, payment and order history, correspondence with IDH, meeting history with IDH employees, and data generated during the performance of the agreement between you and IDH.

(iv) For what period do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for seven years.  After this term, your personal data will be deleted from our systems.

 

 

(e) For organisational analysis, development and management 

(i) What does this purpose entail?

At IDH, we may process your personal data in the preparation and performance of management reporting and analysis.  We use aggregated personal data to create management reports and to analyse IDH’s business.  We conduct customer, supplier and business partner surveys to learn more about your views and opinions in preparation of our management reporting.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for the purposes of IDH’s legitimate interests of general business operations, such as management reporting.

(iii) Which personal data do we process for this purpose?

For this purpose, we process your contact details such as your email address, personal details such as your name, position in the organisation you work for, correspondence with IDH and the information you provide when responding to our surveys.

(iv) For what period do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for five years. After this term, your personal data will be deleted from our systems.

 

 

(f) To monitor and investigate compliance within IDH 

(i) What does the purpose entail?

IDH monitors its IT systems to check compliance with IDH policies and regulations, such as the Code of Conduct and the IT Policy.  During monitoring activities, your personal data may be accessed and viewed.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for the purpose of IDH’s legitimate interest of monitoring compliance with our internal policies and regulations,

(iii) Which personal data do we process for this purpose?

For this purpose, any personal data that is stored on IDH’s IT systems may be accessed and viewed for compliance purposes.  The personal data that are accessed and viewed will not be stored for compliance purposes, unless we need them to further investigate potential non-compliant behaviour.

(iv) For what period do we retain your personal data for this purpose?

We do not retain your personal data for this purpose, unless they are linked to non-compliant behaviour.  We will then retain the relevant personal data until the investigation or proceedings have been concluded.

(i) What does this purpose entail?

Through developing innovative, sustainable, and inclusive business models and crowding in value chain actors and the financial sector, IDH, through its data collection programs, aims to support smallholder farmers to invest and grow their businesses to improve their livelihoods.

IDH has developed and owns the intellectual property rights in a several data collection survey methodologies, including but not limited to a service delivery model (“SDM”) to analyse the performance of services delivered to smallholder farmers by service providers (e.g. value chain players, financial service providers or specialized service providers).

The programs and surveys in which smallholder farmers may participate, serve to provide IDH and where applicable its business partners with strategic information regarding such smallholder farmers.

The applicable survey for the SDM generally aims to provide insight into the business case for smallholder farmers and provides suggestions on i.e. how to innovate services offered to the smallholder farmers, how to make the services delivered to smallholder farmers by service providers investable and how to scale these services.

Additionally, IDH uses surveys to measure its impact and learn and improve its programs.

The surveys serve to provide evidence and information on the impact created by IDH’s interventions

The applicable survey for the general impact measurement and learnings of IDH aims to provide IDH with valuable insights on the progress of its interventions and input further improve its programs

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for IDH’s and your legitimate interest of providing respectively receiving business optimization services, impact measurement or monitoring services and evaluation of our programmes. Depending on the type of personal data processed by IDH, we can also process your personal data on the basis of your consent.

(iii) Which personal data do we process for this purpose?

For this purpose, we process:

  • Your name;
  • Your location;
  • Your address;
  • Your gender;
  • Your financial data;
  • Your household data;
  • Answers provided by you in relation to the survey that is conducted; and/or

Other personal data of which you will be informed prior to commencement of the relevant program or study.

(iv) How long do we retain your personal data for this purpose?

We will retain your personal data for a period of 10 years after completion of the relevant program or survey you took part in, unless a follow-up program or survey is conducted within such period of 10 years. In the latter event, your personal data will be deleted after completion of a follow-up program or survey.

(a) Only if you have consented to this by registering to our newsletter, for sending you relevant information about IDH.

(i) What does this purpose entail?

When you register for the newsletter on our Website, we ask you for your consent to receive newsletters from IDH. We will contact you through email.

If you want to opt out of receiving our newsletter, just follow the steps in that particular communication.

(ii) On what legal ground do we process personal data for this purpose?

We process your personal data for IDH’s legitimate interest of direct marketing.

(iii) Which personal data do we process for this purpose?

For this purpose, we process:

  • your email address;
  • your server domain;
  • whether you opened the newsletter;
  • the links you click on in our emails.

(iv) How long do we retain your personal data for this purpose?

For this purpose, your personal data will be retained for as long as you wish to receive information from IDH. In case you wish to cease receiving information, you can unsubscribe at any time by contacting us or by using the unsubscribe option included in each e-mail.  After doing so, your personal data will be deleted from our systems.

 

We also collect information through the use of cookies.  Cookies are small files of information which save and retrieve information about your visit to this website – for example, how you entered our site, how you navigated through the site, and what information was of interest to you. When you use the Website, the cookies send data to IDH.

IDH does not retain a cookie longer than necessary. We use session cookies and permanent cookies:

  • A session cookie can track usage such as the webpages you visit and what options you use. When you close the internet browser, the session is ended and the cookie is deleted.
  • A permanent cookie enables the Website to recognize you at a subsequent visit.

IDH stores cookies that are essential in providing the functionalities of the Website.

If you do not wish to receive any cookies at all, you may set your browser to refuse cookies all together. Please note that in that case you may no longer be able to use all the functionalities of the Website.

Only if you have given prior consent, IDH places cookies that are not strictly necessary for providing the functionalities of the Website. Through such non-strictly necessary cookies we collect information about your use of the Website and remember your preferences. Examples of collected information are which pages are visited and the length of a user session. Through these cookies we aim to improve your user experience of our Website. If you do not consent to cookie being placed, these cookies will be blocked.

(Non-strictly necessary) cookies used on the Website:

(Category) Cookie(s) Name Retention period Extra information
Google Analytics tracking cookie _ga 14 months _ga is used to distinguish users. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports.

For more information, read the general Google Privacy policy.

Google Analytics tracking cookie _gid 24 hours _gid is used to distinguish users – stores and updates a unique value for each page visited.

For more information, read the general Google Privacy policy.

Google Analytics tracking cookie _gat 10 minutes _gat is used to throttle requests – limiting the collection of data on high traffic sites.

For more information, read the general Google Privacy policy.

Youtube tracking cookies VISITOR_INFO1_LIVE,

PREF,

YSC

GEUP

6 months

8 months

session

2 years

These cookies are set via embedded Youtube-videos. They register anonymous statistical data on for example how many times the video is displayed and what settings are used for playback. No sensitive data is collected unless you log in to your Google account, in that case your choices are
linked with your account, for example if you click “like” on a video. For more  information, read the general Google Privacy policy.
Hotjar tracking cookies _hjid and _hj… 52 weeks Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device’s IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf.

For further details, please see the ‘about Hotjar’ section of Hotjar’s support site.”

IDH uses Google Analytics’ cookies. Google Analytics is a web analysis service that is offered by Google Inc. (“Google”). Google Analytics uses cookies only to analyze the usage of the Website by users. Google uses aggregated statistical data to give IDH an insight in the way users use the Website. IDH has concluded a data processing agreement with Google to ensure proper protection of your personal data. IDH does not make use of any other Google services related to Google Analytics. To the extent allowed by the Google Analytics functionalities, IDH has opted out from sharing your information with Google. Google will remove the last three digits of your IP address. Google may only provide the aforementioned data to third parties if Google is required to do so by law, or to the extent third parties processing these data on behalf of Google.

You can find more information on Google Analytics here and here.

6. Who has access to your personal data?

As a global organisation, data we collect may be transferred internationally throughout IDH’s worldwide organisation.  Your personal data may be exchanged within IDH globally and with companies working under the name Stichting Life and Building Safety Initiative (LABS), Yayasan Inisiatif Dagang Hijau, IDH India Sustainable Trade Initiative Foundation and Initiative Development Hub LLP and IDH Investment Management B.V. We exchange your data for administrative purposes and so that we can have a complete overview of your contacts and contracts with IDH.

IDH employees are authorised to access personal data only to the extent necessary to serve the applicable purpose and to perform their jobs.

The following third parties have access to your personal data, where relevant, for the provisioning of their products or services to IDH:

  • Banks
  • Insurance companies.
  • IT suppliers.
  • Accountants and external legal advisors.
  • Forensic specialists.
  • Business partners.
  • Consultants.
  • Donors.

When third parties are given access to your personal data, IDH will take the required contractual, technical and organisational measures to ensure that your personal data are only processed to the extent that such processing is necessary.  The third parties will only process your personal data in accordance with applicable law.

If your personal data are transferred to a recipient in a country that does not provide an adequate level of protection for personal data IDH will take measures to ensure that your personal data are adequately protected, such as entering into EU Standard Contractual Clauses with these third parties.

In other cases, your personal data will not be supplied to third parties, except where required by law.

When a third party processes your personal data solely following IDH instructions, it acts as a data processor.  We enter into an agreement with such a data processor for the processing of personal data.  In this agreement we include obligations to ensure that your personal data are processed by the data processor solely to provide services to us.

IDH has taken adequate safeguards to ensure the confidentiality and security of your personal data. IDH has implemented appropriate technical, physical and organisational measures to protect personal data against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorised disclosure or access as well as all other forms of unlawful processing (including, but not limited to, unnecessary collection) or further processing.  Examples are IT security policies, staff training and secure servers.

 

You can request access, correction, restriction, portability or removal of the data that IDH processes about you at any time by sending a request to: office@idhtrade.org.

Should you have any questions regarding the processing of your personal data, please contact: office@idhtrade.org.