At a glance
Foodfe uses personal data to manage accounts, workplace meal eligibility, orders, payments and customer support.
Employers may see individual orders and prices, but they do not receive allergy or dietary information.
Kitchens receive the information needed to prepare and fulfil meals, including allergy instructions when provided.
Foodfe does not use behavioural advertising, advertising cookies or optional analytics technologies.
1. Scope of this Privacy Policy
This Privacy Policy describes how Foodfe AS collects, uses, shares, stores and protects personal data when you use the Foodfe Services.
The Foodfe Services covered by this policy include:
This policy does not replace a separate privacy notice from your employer, a meal provider, Dintero or another organisation that independently decides how it uses your personal data.
Back to top ↑2. Who is responsible for your personal data?
Foodfe AS is generally the data controller for user accounts, authentication, meal orders, Foodfe payment administration, platform security, technical operation, customer support and the development of the Foodfe Services.
Data Protection Officer
Anika
anika@dcx.no
You may contact the DPO confidentially about Foodfe's processing of personal data.
3. Roles of employers and meal providers
Your employer or workplace organisation
Your employer or workplace organisation may give Foodfe your name, contact details, workplace, programme eligibility and subsidy or allowance information. The employer is responsible for its own use of employee information and for explaining the legal basis for that use.
Depending on the customer agreement, Foodfe may process some workplace administration data on the employer's documented instructions as a data processor, while acting as an independent controller for the core Foodfe account, ordering, payment, security and support functions described in this policy.
Kitchens, caterers and other meal providers
A meal provider acts as Foodfe's data processor when it uses order information solely to prepare and fulfil meals on Foodfe's instructions. A provider may also act as an independent data controller for its own legal duties or independently determined purposes, such as accounting, food-safety obligations, handling a complaint or defending a legal claim. When acting independently, the provider is responsible for its own privacy information and legal basis.
Back to top ↑4. Personal data we process
The categories of personal data depend on how you use Foodfe.
- Account and contact data
- Name, email address, telephone number, employer or workplace, language, account identifier and account status.
- Authentication data
- Login identifier, encrypted or securely managed credentials, one-time-code status, authentication tokens, login time and failed-login information. Authentication is provided through Amazon Cognito.
- Workplace programme data
- Workplace, programme eligibility, subsidy or allowance level, price category and programme start or end information.
- Order data
- Meal selection, portion size, scheduled date, workplace or pickup location, order number, status, price and order history.
- Dietary data
- Dietary preferences, allergy and intolerance information, ingredient exclusions and free-text meal instructions that you choose to provide.
- Payment data
- Dintero payment token or reference, card brand, last four card digits, payment and refund status, transaction amount and billing address. Foodfe does not store your full card number or card security code.
- Technical data
- Essential session information and operational logs, such as timestamps, request or error identifiers, app or browser version and network metadata that may include an IP address when generated by the hosting infrastructure.
- Support data
- Emails, requests, complaints, feedback and information needed to investigate and answer your enquiry. Support emails are stored in Microsoft 365/Outlook.
- Business contact data
- Name, role, organisation, business contact details and correspondence for employer administrators, kitchens, caterers, suppliers and other business contacts.
5. Where personal data comes from
Foodfe may receive personal data:
- directly from you when you register, update your profile, place an order, provide dietary information, make a payment or contact support;
- from your employer or workplace administrator when they enrol you or manage programme eligibility and subsidies;
- from a kitchen or meal provider when it updates fulfilment or order information;
- from Amazon Cognito when it authenticates your login;
- from Dintero and participating financial institutions when they process a payment or refund; and
- automatically from essential technical systems when you use the Foodfe Services.
6. Why we process personal data
Foodfe only processes personal data for identified purposes and where a legal basis under applicable data-protection law applies.
| Purpose | Data commonly used | Legal basis |
|---|---|---|
| Create and manage your account | Account, contact and authentication data | Necessary to perform the agreement with you (GDPR Article 6(1)(b)) |
| Authenticate users and protect accounts | Authentication and essential technical data | Performance of the agreement and Foodfe's legitimate interest in service security (Articles 6(1)(b) and 6(1)(f)) |
| Administer workplace eligibility, pricing and subsidies | Workplace and programme data | Performance of the agreement, legitimate interests in administering the programme, or processing on the employer's documented instructions |
| Process, prepare and fulfil meal orders | Account, order, workplace, delivery and ordinary dietary preference data | Necessary to perform the agreement with you (Article 6(1)(b)) |
| Process allergies, intolerances or other sensitive dietary information | Allergy, health-related, religious or similarly sensitive dietary data | Your explicit consent (Articles 6(1)(a) and 9(2)(a)), subject to the additional safeguards for young users described below |
| Process payments, refunds and billing | Order, payment, billing and subsidy data | Performance of the agreement and compliance with accounting or tax duties (Articles 6(1)(b) and 6(1)(c)) |
| Provide customer support and handle complaints | Contact, order, payment and support data | Performance of the agreement and legitimate interests in support and dispute handling (Articles 6(1)(b) and 6(1)(f)) |
| Maintain, troubleshoot and secure the Services | Essential technical logs, error information and security events | Foodfe's legitimate interests in reliable and secure service operation (Article 6(1)(f)) |
| Meet legal obligations and establish or defend legal claims | Relevant account, order, payment, technical and communication data | Legal obligation and legitimate interests (Articles 6(1)(c) and 6(1)(f)); Article 9(2)(f) may apply to special-category data used for legal claims |
When Foodfe relies on legitimate interests, it assesses whether the processing is necessary and balances Foodfe's interests against your rights and reasonable expectations.
Back to top ↑7. What your employer can see
Depending on the workplace programme and your employer's permissions, an authorised employer or canteen administrator may see:
- your name and contact details;
- whether you are registered with Foodfe;
- your meal-programme eligibility;
- your subsidy or allowance level;
- your individual meal orders; and
- the prices associated with your individual orders.
Foodfe does not provide employers with behavioural advertising profiles. Employers must use information available through the employer portal only for legitimate workplace meal-programme administration and related billing or support.
Back to top ↑8. Allergies and dietary information
Providing dietary preferences, allergy information or intolerance information is optional. Some of this information may reveal health, religion or beliefs and may therefore be special-category personal data under the GDPR.
Before Foodfe stores special-category dietary information, the app asks for your separate and explicit consent. The consent notice explains the purpose, the relevant recipients and how you can withdraw consent.
Foodfe uses this information only to:
- help display or prepare appropriate meals;
- communicate relevant preparation instructions to the kitchen or meal provider;
- respond to questions or complaints concerning the relevant order; and
- protect or defend legal claims where legally necessary.
Foodfe does not use allergy or sensitive dietary information for advertising, marketing segmentation, employee monitoring or employment decisions.
You can edit or remove allergy and dietary information through your profile or settings. To formally withdraw consent or request deletion from systems not directly controlled through the app, email support@foodfe.app. Withdrawal does not affect processing that was lawful before withdrawal, but it stops future consent-based processing.
Back to top ↑9. Payments
User payments are processed by Dintero. Card information is entered directly into the payment provider's secure payment flow. Foodfe does not receive or store your full card number or card security code.
Foodfe may receive and retain:
- a payment token or transaction reference;
- the card brand and last four card digits;
- payment, failure and refund status;
- transaction amount; and
- billing address.
Dintero, banks and payment networks may act as independent controllers for payment authorisation, fraud prevention, anti-money-laundering duties and other regulatory purposes. Their own privacy notices apply to those activities.
Back to top ↑10. Who receives personal data
Foodfe shares personal data only when needed for the purposes described in this policy.
| Recipient | Information and purpose |
|---|---|
| Employer or workplace administrator | Name, contact details, registration, eligibility, subsidy or allowance, individual orders and individual order prices for workplace programme administration and billing. No allergy or dietary data. |
| Kitchen, caterer or meal provider | Name, order number, employer/workplace, meal selection, portion size, delivery or pickup location, telephone number, dietary preferences, allergy or intolerance information and free-text instructions needed to prepare and fulfil the order. |
| Dintero and financial institutions | Payment and transaction information needed to authorise payments, issue refunds and meet financial or regulatory duties. |
| Amazon Web Services | Cloud hosting, database infrastructure, Amazon Cognito authentication, Amazon SES email delivery, SMS delivery and Amazon CloudWatch operational logging/error monitoring. The primary hosting region is Ireland. |
| Microsoft 365/Outlook | Storage and handling of customer-support email communications. |
| Professional advisers and authorities | Relevant information may be disclosed to accountants, auditors, lawyers, insurers, courts, regulators, police or other public authorities when necessary or legally required. |
| Corporate transaction recipients | Information reasonably necessary for a genuine merger, financing, restructuring or sale may be disclosed under confidentiality and data-protection safeguards. |
Foodfe does not sell or rent personal data.
Back to top ↑11. Cookies, local storage and technical logs
Foodfe uses only technologies that are necessary to provide and secure the Services. These may include essential session cookies, secure authentication tokens and equivalent local-storage technologies.
Necessary technologies are used to:
- keep you signed in and maintain a secure session;
- complete authentication and prevent unauthorised access;
- remember essential service or privacy settings;
- process an order or payment flow; and
- detect and troubleshoot operational errors.
Foodfe does not use optional analytics cookies, advertising or retargeting cookies, advertising identifiers, behavioural advertising, precise location tracking or optional push-notification tracking.
Amazon CloudWatch is used for essential operational logging and error monitoring. Foodfe retains these records only for the operational and security purposes described in this policy, not for advertising or cross-service tracking.
Because Foodfe currently uses only strictly necessary technologies, no optional cookie-consent platform is used. Blocking necessary cookies or local storage may prevent login or other core functions from working.
Back to top ↑12. International data transfers
Foodfe's primary production environment is hosted in Ireland, within the European Economic Area (EEA). Foodfe currently configures its services so that personal data is intended to be processed in Norway or elsewhere in the EEA.
Some suppliers are international organisations. If supplier support, subprocessors or another arrangement results in personal data being accessed from or transferred to a country outside the EEA, Foodfe will ensure that a lawful transfer mechanism and appropriate safeguards are in place before the transfer, such as an adequacy decision or the European Commission's Standard Contractual Clauses.
You may contact the DPO for information about the transfer safeguards applicable to a particular service provider.
Back to top ↑13. How long we keep personal data
Foodfe keeps personal data only as long as needed for the relevant purpose, subject to legal requirements and legitimate needs relating to security, complaints, audits and legal claims.
| Category | Retention period |
|---|---|
| Account and profile information | While the account is active and for up to 12 months after closure. |
| Workplace eligibility and subsidy information | While you participate in the programme and for up to 12 months after participation ends. |
| Allergy and dietary information | Until you remove it, withdraw consent or close the account. Deleted information is removed from active systems within 30 days, unless a legal exception applies. |
| Ordinary order history | Up to 3 years after the order. Information that forms part of mandatory accounting documentation may be retained longer. |
| Accounting and payment documentation | Normally 5 years after the end of the relevant accounting year, where required under Norwegian bookkeeping rules. |
| Customer-support correspondence | Up to 2 years after the support case is closed, unless needed longer for a dispute or legal claim. |
| Authentication and security logs | Up to 90 days, unless needed to investigate a security incident or abuse. |
| Operational error and diagnostic records | Up to 90 days. |
| Consent records | For the duration of the processing and up to 3 years after the relevant processing ends, to document consent and withdrawal. |
| Backups | Deleted information is overwritten through the backup cycle within 30 days, unless a backup must be preserved for a security investigation or legal obligation. |
When a retention period expires, Foodfe deletes or anonymises the information. Data may be retained longer where required by law, necessary to resolve an outstanding dispute or needed to establish, exercise or defend a legal claim.
Back to top ↑14. How we protect personal data
Foodfe uses technical and organisational safeguards appropriate to the information and relevant risks. These may include:
- role-based access controls and least-privilege access;
- secure authentication through Amazon Cognito;
- encryption during transmission and encryption at rest where appropriate;
- logging, monitoring and incident-response procedures;
- backup, restoration and business-continuity measures;
- separation of production and development environments;
- confidentiality obligations for authorised personnel; and
- contractual and security requirements for data processors.
No internet service can guarantee absolute security. Contact Foodfe immediately if you believe your account or personal data has been compromised.
Back to top ↑15. Children and young users
Foodfe does not apply a fixed minimum age because employees and apprentices under 18 may be eligible to use Foodfe through their workplace. Foodfe handles children's and young people's information with additional care and provides information in clear language appropriate to the user.
Where Foodfe relies on consent to provide an online service directly to a child under 13 in Norway, consent must be given or authorised by the person with parental responsibility.
Allergy and health-related information receives stronger protection. Foodfe requires verifiable consent from a parent or guardian before relying on consent to process this type of information for a user under 18, unless another valid legal basis for the special-category processing clearly applies.
A parent or guardian may contact support@foodfe.app or the DPO to ask about a young user's information or to exercise applicable rights on the young user's behalf.
Back to top ↑16. Automated decisions
Foodfe does not make decisions based solely on automated processing that produce legal effects or similarly significant effects for users.
Technical systems may automatically validate a login, check order rules, process a payment response or flag unusual activity. Where a decision could materially restrict your account or access to the Services, Foodfe provides appropriate human review.
Back to top ↑17. Your data-protection rights
Subject to the conditions in applicable law, you may have the right to:
- receive confirmation of whether Foodfe processes your personal data and obtain access to it;
- correct inaccurate or incomplete information;
- request deletion of personal data;
- request restriction of processing;
- receive eligible information in a structured, commonly used and machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time for future processing; and
- complain to a data-protection authority.
You can correct profile information and edit or remove dietary information in the app. Data download, full account deletion and formal withdrawal requests are not currently available as self-service functions. Send these requests to support@foodfe.app with the subject Privacy request, or contact the DPO at anika@dcx.no.
Foodfe may request information reasonably necessary to verify your identity. Foodfe will normally respond within one month. The period may be extended where permitted by law for complex or numerous requests, and Foodfe will explain any extension.
Where Foodfe processes information solely on an employer's documented instructions, Foodfe may forward the request to the employer or assist the employer with its response.
Back to top ↑18. Complaints
Please contact Foodfe or the DPO first so the concern can be investigated. You also have the right to complain to the Norwegian Data Protection Authority:
You may also complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred.
Back to top ↑19. Changes to this Privacy Policy
Foodfe may update this policy when the Services, data-processing activities, providers, legal requirements or organisational arrangements change. The date at the top of the page shows when the policy was last updated.
Foodfe will provide an appropriate notice before a material change takes effect. When a new purpose requires consent, Foodfe will request new consent rather than treating continued use as consent.
Back to top ↑20. Contact Foodfe
Questions about this policy or Foodfe's use of personal data can be sent to:
Foodfe AS
Organisation number 923 049 738Beiteveien 6
0679 Oslo, Norway
support@foodfe.app
www.foodfe.app
Data Protection Officer
Anika
anika@dcx.no