Privacy Policy
for Visitors, Job Candidates, Vendors, and Business Partners
Part I - General Information
1. About this Policy
1.1. This Privacy Policy (the “Policy”) explains how Foodient Ltd. (“Foodient”, “we”, “us”, “our”, formerly “Whisk”) collects, uses, discloses, and safeguards personal data of the following categories of individuals:
- (a) visitors of our corporate and brand website at whisk.com (Section A);
- (b) candidates applying for positions with Foodient (Section B);
- (c) individuals associated with our vendors and suppliers (Section C); and
- (d) individuals associated with our business partners and prospective business partners (Section D).
1.2. Each section sets out the personal data we process, the purposes and legal bases of processing, the sources of the data, and the retention principles applicable to that category. Part III sets out provisions common to all categories, including your rights, security, international transfers, and contact details.
2. About Foodient (Controller)
2.1. Foodient Ltd. is a company incorporated in England and Wales (company no. 08001091) with its registered office at 483 Green Lanes, London, N13 4BS, United Kingdom.
2.2. For all personal data described in this Policy, Foodient acts as the data controller within the meaning of the UK General Data Protection Regulation (“UK GDPR”) and Regulation (EU) 2016/679 (“EU GDPR”).
2.3. This Policy is issued in compliance with the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (“PECR”), the EU GDPR, and, where applicable, other data-protection laws.
3. Data Protection Officer
3.1. Foodient has appointed a Data Protection Officer (“DPO”):
Larisa Sheckler
Email: [email protected]
Postal address: Foodient Ltd. - DPO, 483 Green Lanes, London, N13 4BS, United Kingdom
3.2. You may contact the DPO at any time with questions about this Policy or to exercise your rights under Part III.
Part II - Processing by Category of Data Subject
Section A. Visitors of our Website (whisk.com)
A.1 Personal data we collect
A.1.1 Visitor and device data: IP address, device identifiers, browser type, operating system, pages visited, time spent on pages, crash and error logs.
A.2 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Operating and securing the Website (hosting, traffic management, abuse prevention) | Legitimate interests - Art. 6(1)(f) UK GDPR |
| Complying with legal obligations and protecting our rights | Legal obligation - Art. 6(1)(c); legitimate interests - Art. 6(1)(f) UK GDPR |
A.3 Sources
We collect this personal data directly from you when you visit the Website. We also collect technical data automatically through your interaction with the Website.
A.4 Retention
A.4.1 Server and access logs: up to twelve (12) months.
Section B. Job Candidates
This Section applies if you apply, or are considered, for a position with Foodient (whether through a direct application, via a recruiter, or through a publicly available profile).
B.1 Personal data we collect
Depending on the applicable job position and its requirements, we may collect the following types of data from you:
B.1.1 Identification and contact data: name, postal address, email address, telephone number, nationality, work-authorisation status, and date of birth (only where strictly necessary).
B.1.2 Application data: CV/résumé, cover letter, employment history, education, qualifications, certifications, languages, and references.
B.1.3 Assessment data: notes from interviews, results of role-related assessments, technical exercises, and competency evaluations.
B.1.4 Background and verification data, where lawful and proportionate: verification of qualifications, employment history, and (where required for the role and permitted by law) criminal-record checks.
B.1.5 Equal-opportunity monitoring data, where collected on a voluntary basis: limited demographic information used solely in anonymised, aggregated form.
B.1.6 Communications: correspondence between you and our recruitment team or external recruiters.
B.2 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Assessing your suitability for the role and managing the recruitment process | Steps prior to entering a contract at your request - Art. 6(1)(b) UK GDPR; legitimate interests in identifying and selecting personnel - Art. 6(1)(f) UK GDPR |
| Verifying information you provide (qualifications, employment history, references) | Legitimate interests in ensuring the integrity of the recruitment process - Art. 6(1)(f) UK GDPR |
| Carrying out background or criminal-record checks where required for the role | Legal obligation - Art. 6(1)(c) UK GDPR; substantial public interest - Art. 9(2)(g) UK GDPR (where special-category data is involved), in accordance with applicable employment law and Schedule 1 of the UK Data Protection Act 2018 |
| Equal-opportunity monitoring (voluntary) | Substantial public interest in equality of opportunity - Art. 9(2)(g) and Schedule 1 of the UK Data Protection Act 2018; anonymised before analysis |
| Retaining your data in our talent pool for future opportunities | Your explicit consent - Art. 6(1)(a) UK GDPR, withdrawable at any time |
| Defending against, or bringing, legal claims arising from the recruitment process | Establishment, exercise, or defence of legal claims - Art. 9(2)(f) UK GDPR; legitimate interests - Art. 6(1)(f) UK GDPR |
B.3 Sources
B.3.1 We collect personal data directly from you when you apply or interact with our recruitment team.
B.3.2 We may also receive personal data from third parties, including recruitment agencies and head-hunters, professional networking sites (such as LinkedIn) where you have made your profile publicly available, named referees, and background-check providers.
B.4 Automated decision-making
B.4.1 We do not make hiring decisions that produce legal or similarly significant effects on you solely on the basis of automated processing within the meaning of Article 22 UK GDPR. Human reviewers are involved in all hiring decisions.
B.5 Retention
B.5.1 Unsuccessful candidates: we retain your application data for up to twelve (12) months from the conclusion of the recruitment process to allow us to defend potential claims and to consider you for other roles, unless you object to such retention.
B.5.2 Talent pool (where you consent): we retain your data for up to twelve (12) months from your last interaction, or until you withdraw consent, whichever is earlier.
B.5.3 Successful candidates: your data is transferred to your employee file and retained in accordance with our employee privacy notice and applicable employment-law retention requirements.
B.6 Data Transfers
Your data will not be transferred outside the European Economic Area (EEA) nor will it be subject to automated processing for the purpose of making a decision regarding your application.
Section C. Vendors and Suppliers
This Section applies if you act on behalf of a current or prospective vendor or supplier of goods or services to Foodient. A reference to this Policy appears in the footer of our outgoing emails to vendor contacts.
C.1 Personal data we collect
C.1.1 Business-contact data: name, job title, organisation, business email address, business telephone number, and other professional contact details.
C.1.2 Communications: correspondence between you (or your colleagues) and our procurement, finance, legal, or business teams.
C.1.3 Contract and onboarding data: information required to enter into and administer the contract between Foodient and your organisation, including signature blocks, contact persons, and points of escalation.
C.1.4 Due-diligence and compliance data: information necessary for know-your-supplier checks, anti-bribery and anti-corruption screening, sanctions screening, and (where applicable) anti-money-laundering checks.
C.1.5 Payment-administration data: bank-account details and tax-related information of contact persons where strictly necessary for the contractual relationship.
C.2 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Negotiating, entering into, and performing contracts with your organisation | Performance of a contract or steps prior to entering one with your organisation - Art. 6(1)(b) UK GDPR; our legitimate interests in maintaining vendor relationships - Art. 6(1)(f) UK GDPR |
| Day-to-day vendor-relationship management and communications | Legitimate interests - Art. 6(1)(f) UK GDPR |
| Due diligence, sanctions screening, anti-bribery and anti-corruption checks | Compliance with legal obligations - Art. 6(1)(c) UK GDPR; legitimate interests in maintaining integrity of our supply chain - Art. 6(1)(f) UK GDPR |
| Accounting, tax, and statutory recordkeeping | Compliance with legal obligations - Art. 6(1)(c) UK GDPR |
| Defending against, or bringing, legal claims | Legitimate interests - Art. 6(1)(f) UK GDPR; establishment, exercise, or defence of legal claims - Art. 9(2)(f) UK GDPR where applicable |
C.3 Sources
C.3.1 We collect personal data directly from you or your colleagues during the procurement process and over the course of the vendor relationship.
C.3.2 We may also receive personal data from public sources (company registries, sanctions lists, regulator databases), from third-party providers of due-diligence and compliance services, and from your organisation.
C.4 Retention
C.4.1 We retain vendor-contact and contract-administration data for the duration of the contractual relationship and for a period thereafter equal to the longer of (a) six (6) years following the end of the relationship (statutory limitation for contract claims in England and Wales), or (b) any longer period required by applicable tax, accounting, or sector-specific law.
C.4.2 Due-diligence and compliance records are retained for the period required by applicable anti-money-laundering, anti-bribery, and sanctions laws.
Section D. Business Partners and Prospective Business Partners
This Section applies if you act on behalf of a current or prospective business partner of Foodient (including retailer and grocer partners, technology partners, distribution partners, and other commercial counterparts). A reference to this Policy appears in the footer of our outgoing emails to partner and prospect contacts.
D.1 Personal data we collect
D.1.1 Business-contact data: name, job title, role, organisation, business email address, business telephone number, country of work, and language preferences.
D.1.2 Contract and account data, where you become an active partner: contract details, point-of-contact information, account-management data, and onboarding records (without prejudice to the separate Platform Services agreements).
D.1.3 Publicly available data: information available on public professional networks (such as LinkedIn), your organisation’s website, public regulatory filings, and conference attendee lists.
D.2 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Negotiating, entering into, and performing contracts with your organisation | Performance of a contract or steps prior to entering one with your organisation - Art. 6(1)(b) UK GDPR; legitimate interests - Art. 6(1)(f) UK GDPR |
| Day-to-day partner-relationship management and customer-success activities | Legitimate interests in maintaining and developing partner relationships - Art. 6(1)(f) UK GDPR; performance of a contract - Art. 6(1)(b) UK GDPR |
| Sending business-to-business communications about products, services and features that may be of interest to you in your professional role | Legitimate interests under Art. 6(1)(f) UK GDPR, Steps prior to entering a contract with your organization - Art. 6(1)(b) UK GDPR; |
| Maintaining customer-relationship-management (CRM) records, account-based marketing, and analytics | Legitimate interests - Art. 6(1)(f) UK GDPR, with regular review of relevance |
| Compliance with legal obligations, including screening sanctions for active partners | Legal obligation - Art. 6(1)(c) UK GDPR; legitimate interests - Art. 6(1)(f) UK GDPR |
| Defending against, or bringing, legal claims | Legitimate interests - Art. 6(1)(f) UK GDPR; establishment, exercise, or defence of legal claims - Art. 9(2)(f) UK GDPR where applicable |
D.3 Sources
D.3.1 We collect personal data directly from you, your employer/client or your colleagues during business interactions, meetings, and events.
D.3.2 We may also receive personal data from publicly available sources (such as LinkedIn, your organisation’s website, and trade publications), from lead-generation and sales-intelligence providers acting in compliance with applicable law, from referrals by mutual contacts, and from your organisation.
D.4 Retention
D.4.1 Active partner relationships: for the duration of the relationship and for the periods set out in clause C.4.1 thereafter (mutatis mutandis).
Part III - Common Provisions for Sections A - D
5. Disclosure of Personal Data
5.1 Across all categories in Part II, we disclose personal data to:
- (a) service providers acting as our processors (cloud hosting, IT, analytics, recruitment-applicant tracking, due-diligence providers, marketing email distribution, CRM, customer support, security and fraud prevention), under written instructions and contractual safeguards;
- (b) Foodient group companies, on a need-to-know basis for the purposes set out in this Policy;
- (c) professional advisers (legal, tax, audit) under duties of confidentiality;
- (d) public authorities, regulators, and law-enforcement bodies, where required by applicable law or to protect our rights or those of others;
- (e) counterparties in a corporate transaction (such as a merger, acquisition, financing, or insolvency), subject to confidentiality and data-protection obligations.
5.2 We do not sell personal data.
6. International Data Transfers
6.1 Foodient operates globally and personal data may be transferred to, and processed in, countries outside the United Kingdom and the European Economic Area, including to our service providers and group companies located in such countries.
6.2 Where we transfer personal data internationally, we rely on appropriate safeguards, including:
- (a) the UK and EU Standard Contractual Clauses, including the UK International Data Transfer Addendum;
- (b) UK adequacy regulations and EU adequacy decisions; and
- (c) other lawful transfer mechanisms recognised under the UK GDPR and EU GDPR.
6.3 Copies of the safeguards in place are available on request from the DPO.
7. Security
7.1 We implement appropriate technical and organisational measures designed to protect personal data, including encryption in transit and at rest where appropriate, access controls, segregation of duties, regular security testing, and vendor due diligence. No system can be guaranteed to be entirely secure.
8. Your Rights
8.1 Subject to applicable law, you have the right to:
- (a) access your personal data;
- (b) request rectification of inaccurate or incomplete data;
- (c) request erasure (the “right to be forgotten”);
- (d) request restriction of processing;
- (e) object to processing based on legitimate interests or for direct marketing;
- (f) data portability where the legal basis is consent or contract and processing is carried out by automated means;
- (g) withdraw consent at any time, without affecting the lawfulness of prior processing; and
- (h) lodge a complaint with a supervisory authority, including the UK Information Commissioner’s Office (ICO, https://ico.org.uk) or your local supervisory authority in the EEA.
8.2 To exercise your rights, contact our DPO using the details in clause 4. We will respond within the period required by applicable law (generally one month, extendable in complex cases by up to two further months).
9. Children
9.1 The Website and the activities described in this Policy are not directed at children. We do not knowingly process personal data of children below the applicable minimum age without verifiable parental or guardian consent. If you believe a child has provided us with personal data without such consent, please contact our DPO.
10. Changes to this Policy
10.1 We may update this Policy from time to time. The updated version will be posted on the Website with a revised effective date. Where the changes are material, we will provide reasonable notice in advance of the changes taking effect, and (where appropriate) by direct communication to affected individuals.
11. Contact
Foodient Ltd.
483 Green Lanes, London, N13 4BS, United Kingdom
Data Protection Officer: Larisa Sheckler
Email: [email protected]
Privacy and data-protection enquiries: [email protected]
Effective date: September, 1, 2026
Last updated: September, 1, 2026