This Privacy Notice shall serve as information how Sika processes your personal data when using Sika Digital Applications.

Sika is committed to ensuring the security and protection of your personal information and adheres to applicable data privacy regulations. Please be aware that depending on your country of origin, different privacy requirements may be applicable to you. For more information about your local data privacy requirements, please consult your local Sika legal entity via the following link Sika Data Privacy Portal.

Purposes of the Sika Supplier Relationship Management Application (SRM Application)

The SRM Application is used for managing supplier relationships, fulfilling contractual obligations, conducting due diligence processes, evaluating and monitoring suppliers, managing documents such as NDAs, self-assessments, audit documentation, and meeting regulatory and compliance requirements.

Data Capture

Sika Digital Applications can process different categories of personal data depending on the implemented scope of the respective application. The processed personal data of Sika employees and external users may include:

  • First and last names, business email addresses, business landline and mobile phone numbers; 
  • User data (e.g. usernames and passwords).

Legal Basis

If you are a direct contracting party of Sika, the legal basis for the processing of your personal data is the implementation of pre-contractual measures or the performance of a contract entered into at your request. If you are a contact person for a Sika customer or business partner, the legal basis for processing your personal data is Sika’s legitimate interest in establishing and maintaining business relationships.

Furthermore, personal data is processed in order to comply with legal obligations, particularly with regard to compliance, auditing, taxation, regulatory reporting and the defence of and enforcement of legal claims.

The legal basis for this data processing is Sika’s legitimate interest in establishing and developing stable customer relationships. Sika's overarching legitimate interests are the management of supplier relationships and the fulfilment of legal and regulatory obligations. Failure to provide the data means it is not possible to use the SRM tool or collaborate with Sika.

Furthermore, user-related data is used within the SRM tool for access security, access control, traceability of system actions, user administration, and personalisation purposes. There is no exclusively automated decision-making. The legal basis for processing this data is Sika’s legitimate interest in ensuring the SRM Application operates securely.
 

Data disclosure

The recipients of the personal data are organisational units within companies in the Sika Group. These include the Procurement, Supplier Risk Management, Corporate Compliance, Corporate Legal, Sustainability and Quality departments. Where applicable, the Finance department is also included, insofar as this is necessary for the creation of a creditor master record.

Sika uses external service providers to make the SRM Application available, including web servers, storage space, database services, security services and maintenance services. The recipient of the SRM Application is Procurence Sp. z o.o., Cosmopolitan Tower, ul. Twarda 4/171, 00-105 Warsaw, Poland. Other recipients may include technical service providers involved in system provision, authentication or integration. In this context, Sika or the relevant service providers process the personal data of SRM Application users on the basis of Sika’s legitimate interest in efficiently and securely providing this online service.

Where personal data is transferred internationally, Sika ensures an adequate level of protection in accordance with applicable data protection laws. Depending on the jurisdiction, this may include the use of standard contractual clauses, intra‑group agreements, or other legally recognized safeguards.

Furthermore, Sika will not disclose your personal data to third parties unless you have expressly consented to such disclosure, unless Sika is legally obliged or entitled to disclose data due to local legal regulations and/or official court orders, or unless Sika has an overriding legitimate interest in disclosure. Technical security measures are in place to ensure that data is transmitted securely in such cases (e.g. encryption).

Retention period

Unless specified otherwise in individual cases, personal data will be deleted when it is no longer necessary for the purposes of collection or processing, provided there are no statutory retention obligations preventing its deletion. Sika will also delete personal data upon request if the conditions set out therein are met. If personal data is required for other legally permissible purposes, it will not be deleted, but its processing will be restricted. In this case, the data will not be processed for other purposes.

Any personal data received by Sika in connection with the performance of a contract will be retained for the duration of the contractual relationship and, where necessary, for a period beyond this. Sika stores tax-related documents for the periods prescribed by commercial or tax law.

User data is subject to soft deletion after two years of inactivity. The data subject is informed in advance by email and given the opportunity to confirm further storage. For companies in the EU and EEA, data is permanently deleted after five years of inactivity. Furthermore, certain data may be stored for longer if required by legal obligations, for example in relation to tax, compliance and regulatory reporting, or for the assertion or defence of legal claims.

Contact information and responsible legal entity

For more information on the responsible legal entity in your country of origin and how to contact us, please visit our Sika Data Privacy Portal.

Your rights

Please be aware that the privacy rights listed below are in line with the EU-GDPR and might apply in countries outside of the EU as well. However, these rights are not absolute in all countries where Sika operates. To exercise your rights, please note that your eligibility may depend on your country of origin, some or all of these rights may not apply to you, or you may be entitled to different rights. For more information about your local data privacy requirements or to exercise your rights, please consult your local via the following link: Sika Data Privacy Portal.

(a) Right to access

You have the right to request confirmation from Sika as to whether personal data concerning you is being processed, and if so, to request access to that data. This includes details of the purposes of the processing, the categories of personal data concerned and the recipients or categories of recipients to whom the personal data has been or will be disclosed. However, this is not an absolute right and may be limited by the rights of other individuals. You have the right to receive a copy of the personal data being processed. Your requests are generally free of charge. However, if your requests are manifestly unfounded or excessive, Sika may require you to contribute to the costs on a reasonable basis.

(b) Right to rectification

You have the right to request that Sika corrects any inaccurate personal data relating to you. Depending on the purpose of the processing, you may also have the right to complete any incomplete personal data by providing a supplementary statement.

(c) Right to erasure

You have the right to request that Sika erases your personal data, and Sika may be obliged to erase this personal data.

(d) Right to restriction of processing

You have the right to request that the processing of your personal data be restricted. In this case, your personal data will be marked and can only be processed by Sika for specific purposes.

(e) Right to data portability

You have the right to receive any personal data that you have provided to Sika in a commonly used electronic format. You may also request that Sika transfers this data to another organisation of your choice.

(f) Right to object

Under certain circumstances, you may have the right to object, on grounds relating to your particular situation, to the processing of your personal data by us and we can be required to no longer process your personal data.

Moreover, if your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. In this case your personal data will no longer be processed for such purposes by us.

(g) Right to withdraw consent

You may withdraw your consent to data processing at any time by notifying Sika. As a result, Sika will no longer be able to process your personal data on this basis.

(h) Right to lodge a complaint with a supervisory authority

Depending on your place of residence, you may lodge a complaint with the competent data protection authority in your jurisdiction.