Swedish Match North Europe AB (“Swedish Match”) applies the prevailing regulatory framework pertaining to the processing of personal data and continuously strives to provide you with optimal integrity protection. This Privacy Notice is intended to help you understand how we and others use your personal data in connection with your use of, and purchase of products from, www.zyn.com (the “Website”) (except for the subdomain zyn.com/us/en).
WHO IS THE CONTROLLER OF YOUR PERSONAL DATA?
Swedish Match North Europe AB, corp. reg. no. 556571-6924, SE-118 85 Stockholm, Sweden, tel: +46 (0)200 113 114, is the controller for processing the personal data as described in this Privacy Notice.
In addition, Swedish Match has partnered with The Hut.com Limited (“THG”) who are the authorized reseller and merchant of products that are sold via the Website. THG are a company registered in England and Wales (reg. no. 05016010) with its registered office at 5th Floor, Voyager House Chicago Avenue, Manchester Airport, Manchester, England, M90 3DQ.
THG are also a controller of your personal data where it is processed in connection with the sale of products via the Website (but not for other purposes described in this Privacy Notice) and will process your personal data in accordance with this Privacy Notice.
Where we refer to “we”, “us” or “our” in this Privacy Notice, we usually mean Swedish Match although, in connection with the sale of products via the Website, it refers to Swedish Match and/or THG (as applicable).
If you have questions about Swedish Match and/or THG’s processing of your personal data, please contact firstname.lastname@example.org.
FOR WHAT PURPOSES ARE YOUR PERSONAL DATA PROCESSED?
We mainly process your personal data to fulfill our obligations to you – for example, administrating your user account, managing your product orders, sending newsletters and providing service and support. More information about each purpose, and also the legal grounds for our processing, follows below.
For customers on the Website
When you order products from the Website, we ask you to provide, for example, your personal identity number or information about your age and contact information so we can process your order. Your personal identity number or age information is used to verify that you are of legal age. The legal basis for processing your personal identity number or age information is our legitimate interest in ensuring that we only sell nicotine containing products to persons over the age of 18. Other personal data, such as contact details, is required to administrate and deliver the order and to provide service. The legal grounds are that the processing is necessary to allow us to fulfil the agreement that we have with you. If you do not submit the information we request when ordering, you cannot carry out the order.
We also store your order history, meaning information about products you have ordered, the quantity, date and price. We store such documentation in order to offer you qualified service after placing your order, and to manage any complaints and meet the current regulatory requirements. The legal basis for this processing is our legitimate interest in providing good service, thereby enabling the safe use of our products, and to allow us to make the requisite assessments, fulfil our obligations and protect our rights in conjunction with complaints.
Swedish Match also processes your contact information and your order history for the purpose of market research. The legal basis for this processing is our legitimate interest in conducting such research in order to evaluate and improve our products.
Your personal data may also be processed so we can fulfil our legal obligations, for example, in accordance with Swedish and/or UK accounting laws and regulations.
Swedish Match process your e-mail address and order history for marketing purposes. The marketing consists of distributing newsletters and special offers on items in Swedish Match’s product range via e-mail. You are entitled to oppose the marketing, and you can also at any time, choose to unsubscribe from our newsletters and other marketing by e-mail. To unsubscribe, please contact us on email@example.com or use the unsubscribe link included in each newsletter/e-mail. The legal basis for our processing of your e-mail address is consent or it is otherwise in Swedish Match’s legitimate interest in marketing its products to existing customers.
For individuals with user accounts
When you create a user account on the Website, Swedish Match ask you to submit certain information about yourself, for example, your name and e-mail address. We process this personal data to create and administrate your account. The legal basis for this processing is our legitimate interest in providing and administrating your user account. When you place an order and are signed into your account, the purposes and legal grounds described above under “For customers on the Website” also apply. If you do not submit the information we request when creating an account, you cannot create the account. However, you are not for this reason prevented from ordering products on the Website. You may at any time sign into “My pages” and update most of the personal data you have submitted.
We delete your account if you have not signed into the account or placed an order for one year or notified us that you wish to keep your user account.
For individuals who contact customer service
When you contact customer service, Swedish Match and/or THG will process the personal data you submit, if any, to administrate your customer service case. The legal basis for this processing is our, and your, legitimate interest in managing your case. Your personal data may also be processed so we can fulfil our legal obligations, such as those under applicable consumer protection legislation. The legal basis for this processing is our legitimate interest in providing good service.
We store your personal data as long as the case remains open and erase the data as soon as the case is concluded.
For visitors to the Website
When you visit the Website, we collect information about your IP address (see also Swedish Match’s Information about cookies). Note that certain companies other than Swedish Match also collect your IP address when you visit the Website, in connection with the use of third-party cookies. How this occurs, and how you can go about limiting or turning off cookies in your web browser, is described in Swedish Match’s Cookie Notice.
We use your IP address to prevent infringements, incidents and other misuse of our services on the Website, to run statistics on visitors to the Website, to update and improve the Website and marketing our products. The legal basis for this processing is our legitimate interest in preventing misuse and in having a properly functioning Website and to market our products.
WHO DO WE SHARE YOUR PERSONAL DATA WITH?
Swedish Match may share your personal data with other companies within the Swedish Match Group, as well as with collaborating partners that provide services to us, including for example, our website hosting and ecommerce partner THG and other partners that provide IT and subscription services. These recipients may process your personal data on our behalf and in accordance with our instructions as a data processor (including THG, except for the limited purposes described in this Privacy Notice where THG is also a controller). Swedish Match takes all appropriate legal, technical and organizational measures to ensure that your personal data is processed securely, and with an adequate level of security when transferring to or sharing with selected recipients of this kind.
Swedish Match and/or THG may also share your personal data with third party controllers who process your personal data independently, such as companies that manage the transportation of goods or provide payment solutions. We only share your information with these companies in order to fulfill our respective commitments toward you. When your personal data is shared with these third party controllers, your personal data is processed in accordance with their privacy notices.
Swedish Match may also share your personal data with government agencies if we are obligated under the law to do so, or on suspicion of criminal activity.
WHERE DO WE PROCESS YOUR PERSONAL DATA?
Your personal data will primarily be processed within the EU/EEA and other countries that the EU consider to be ‘adequate’ (including the UK), but it may also be transferred to other countries that do not have data protection laws that offer equivalent protection to EU/EEA data protection laws, such as the United States.
Your personal data will only be transferred to such a country if there are legal grounds to do so and sufficient guarantees that your personal data will be handled in a lawful manner. In such cases, all appropriate legal, technical and organizational measures will be taken to ensure that your personal data is processed securely, and with an adequate level of security comparable to the level of protection offered by EU/EEA data protection law (or UK data protection law if you are in the UK).
HOW LONG DO WE SAVE YOUR PERSONAL DATA?
We save your personal data only as long as is necessary for the purpose for which you submitted your data. See more information under each purpose above.
In respect of personal data that we process in connection with the supply of products to you (including in connection with any liability that we may have to you in respect of the supply of such products), your personal data may generally be retained for up to seven years from the date of the supply of the relevant products. We may then destroy such files without further notice or liability.
In respect of personal data that we process in connection with the other purposes described in this Privacy Notice, generally we retain it for up to one year after the date of our last interaction with you.
We may also save your personal data for a longer time if it is necessary to fulfill a legal obligation that requires processing in accordance with applicable laws, or so that we can establish, enforce or defend legal claims.
WHAT ARE YOUR RIGHTS?
You have certain specific legal rights that you can enforce against us. A summary of these rights follows below.
Right to access/extracts from the register. You have the right to know what personal data about you we are processing. Upon request from you, we will provide you with information in writing about our processing of your personal data, free of charge.
Right to data portability. You have the right to request a copy of the personal data you have provided to us in a structured, generally used and machine-readable format. Provided that it is technically possible – which is determined by Swedish Match – you also have the right to request that we transfer this personal data to another controller. The right to data portability applies to personal data that is processed via automated means, and is based on an agreement with you.
Right to correction of erroneous information. You have the right to request that we correct erroneous or incomplete information about you. If you have a user account, you may also sign into your account and rectify certain inaccurate personal data.
Right to deletion of certain data. You have the right to request that we delete your personal data under certain conditions, for example, if your personal data is no longer necessary for the purpose for which we collected the data, if you object to a weighing of legitimate interests we have carried out and support for our legitimate interest is lacking, if you object to direct marketing purposes, if your personal data was processed in an unlawful manner or if your personal data has to be deleted in order to fulfill a legal obligation.
In certain cases, we must save your personal data despite your request owing to legal requirements such as accounting and tax legislation, or, for example, if we need to retain certain data in order to establish, enforce or defend a legal claim.
Right to restrict processing of your personal data. You have the right to demand a restriction on our processing of your personal data in certain cases. If, for example, you have contested the fact that your personal data is correct, you can request a restriction on processing for a period of time that will give us the opportunity to check if your personal data is correct.
Right to object to our processing of personal data. You have the right, under certain conditions, to object to our processing of your personal data.
You have the right to object to processing that is based on the legal grounds of our legitimate interest. However, we may continue processing your data despite your objection to the processing if we have compelling legitimate reasons for the processing that outweigh your privacy interests.
You have the right at any time to object to our processing of your personal data for direct marketing. If you object to such processing, we will without undue delay cease all direct marketing to you.
To exercise any of the above rights, please contact us at firstname.lastname@example.org.
COMPLAINTS TO SUPERVISORY AUTHORITY
If you have a complaint regarding the processing of your personal data, you have the right to submit such complaints to a data protection authority. For more information, please contact your national data protection authority. Contact details for data protection authorities in the EU (and the UK) are available here.
HOW DO WE PROTECT YOUR PERSONAL DATA?
We take the security measures needed to protect your personal data seriously. For example, we use Secure Socket Layer (SSL), a protocol for the secure transfer of data.
LINKS TO OTHER WEBSITES
CHANGES TO THIS PRIVACY NOTICE
Swedish Match reserves the right to make changes to this Privacy Notice. Any such changes are to be published on the Website.
Latest update to this Privacy Notice: 21 June 2021 (Version 1.5)