Privacy Policy
British American Tobacco HELLAS S.A., with registered office in Maroussi, Attica, 27 Agiou Thoma Street (hereinafter “ΒΑΤ” or “Company”), as Data Controller, wishes to inform its customers, whether current or future, as well as the retailers with whom it cooperates, regarding the purposes and the way of processing of their personal data.
The Company manages certain operations of the website via electronic platforms of cooperating third party companies, where data are entered and kept of customers who place orders and complete their purchases online and provide their consent where required by the applicable legal framework for the purpose of receiving informative & promotional material and invitations to events and competitions.
The cooperating third party companies, for the purposes of the General Data Protection Regulation (GDPR), as regards the specific operations they have undertaken in each case, act as data processors. For these operations, the Company remains responsible for the processing of your personal data and specifies the details of the processing, and has signed data processing agreements with the companies to which it has assigned the performance of processing activities, in order to ensure that the processing is carried out in accordance with the applicable legal framework and that any data subject can freely and without obstruction exercise his/her rights under the legal framework. The Company has legally ensured that the parties performing the processing on its behalf meet the requirements and provide sufficient assurances for the implementation of the appropriate technical and organizational measures, in order to protect your personal data.
CATEGORIES OF PERSONAL DATA COLLECTED FROM YOU
Depending on the circumstances we may collect some or all of the information listed below:
- Full name.
- Telephone number.
- Invoice details (name of sole proprietorship company, professional activity, Tax Reg. No.), of our suppliers or customers in case of purchase of products from our physical stores network or from our website.
- Mail Address (which in case of an electronic transaction can be distinguished between shipping address and billing address).
- Characteristics of device which is the product of purchase, such as its code or its warranty (in combination with your other personal data).
- Date of birth.
- Gender (in combination with your other personal data)
- Coupon / discount code (in combination with your other personal data that identifies you as a beneficiary and if you enter it)
- Smoking habits as potential health data
- Additional information which the customer or visitor of our website chooses to give us (e.g. by contacting us).
- Name, registered office, business address and contact details such as telephone number and email address (regarding each retailer with whom the Company cooperates, if it is a sole trader)
- Contact details (name, telephone number, email) of the legal representative of each retailer or of the person who has been appointed to communicate with the Company on behalf of the retailer.
- Order history that appears in your account when you choose to create it
- Data related to the reviews that you provide us with, if you wish, regarding the products and the services of our Company (e.g. name, email, details of the product purchased, content of your review)
- Your image data and/or identification document information that you provide us with as part of the adulthood/age verification process implemented by our Company in compliance with the prohibition provided by the Law on the sale of tobacco/nicotine products to minors
- Technical data, such as IP address, network connection information, approximate geographic location (as displayed via IP address) and aggregate statistics of website usage, which may be processed when you use certain features of our website that improve your experience while browsing it.
We inform in particular our customers that the credit/debit card details potentially required for the completion of the online purchase are not stored in any database of our Company during the transaction but are entered directly in a secure environment of the cooperating bank which is responsible for the confirmation and the general management of the financial transaction.
WAYS OF COLLECTING YOUR PERSONAL DATA
We collect the personal information you provide us whenever:
- You place an order and make an online purchase, through our e-shop that is available on our website;
- You purchase our products or repair your device in our partners’ physical stores;
- You register your device on our website;
- You subscribe to our newsletter;
- You create an account on our website;
- You contact us via the live chat available on our website or by sending us an email or calling us on the contact details available on our website
- You participate in the competitions we organize, through the participation form available on our website or through any way described in the terms and conditions of each one of our competitions.
- You evaluate the products you have purchased by responding to the relevant request sent to you by our Company, via email, if you wish.
- You participate in the verification process of your adulthood/ age implemented by our Company, through a special mechanism provided by an external partner ("Yoti Age Verification"). In particular, in order for our Company to ensure that it does not promote / sell tobacco / nicotine products to minors, in accordance with the applicable legislation, it will ask you to verify your adulthood / age, through a specific procedure consisting of an initial "face scan" stage, during which the user activates the camera of his/her device and takes a photo of his/her face (selfie) and then an estimation of his/her age is made through the Yoti Age Verification mechanism. If this initial stage fails (e.g. due to a technical problem or an error), the user will be asked to repeat it or, alternatively, to proceed to the second stage of "identity scan" in order to verify his/her age through the information of the identification document provided by the same, at his/her choice (e.g. ID card, passport or driving license).
- You use certain features of our website when browsing it, such as when using the search box to quickly and easily find any information that interests you and that is available on our website.
We may obtain data from other third-party sources, for example when our partners collect your data when you express your interest in our products, or as mentioned above, when you purchase products through our authorized partners, in the context of social or other promotional events or in the context of their own commercial activities (ex. retailers of our products), or when active customers recommend to us that we contact you, to resolve problems related to the operation of the device or for information you wish to receive about our products. Regarding the retailers, we collect their personal data from the network of our distributors, following orders they receive from retailers for our company’ s products.
The personal data we collect from you is necessary to allow us to fulfil our duties towards you or others. For example, when you make an online purchase you will be asked for information that is necessary for the conclusion and performance of the contract, while you may also be asked for information to facilitate the delivery of your order (e.g. shipping address). Also, when you subscribe to our Newsletter in order to receive email notifications, we must enter your email address and name in order to be able to process your request. In addition, other information may be required to ensure the commencement and smooth development of our contractual relationship, as well as our Company’ s compliance with the legal framework, such as your date of birth or other data necessary for the verification of your adulthood / age, in order to determine if you meet the legal requirements for the use of tobacco/nicotine products.
In the event that you refuse to disclose certain personal data to us, which are deemed necessary for meeting the purpose of the processing, we may not be able to provide the services you desire or we may not be able to satisfy a request you may have. We therefore inform you that the data relating to your identification, as well as your contact details are absolutely necessary and required for any transaction or contractual relationship with the Company.
For details on the legal basis on which we rely to be able to use and process your personal data, please refer to the following section titled "Legal basis for processing".
LEGAL BASES FOR PROCESSING
In accordance with European Regulation 679/2016 for the protection of personal data, there are specific reasons for which we may legally process your personal data. These reasons are:
When the processing of your data is done in the context of the provision of our services (sale, device warranty) and for the proper fulfilment of our contractual obligations.
For the purchase of our products through our e-shop that is available on our website or with physical presence, from stores of our authorized partners, for the management of your order and its delivery to the address you wish, for the registration of your device in the Glo network of our Company, for the resolution of any problem you have encountered with your device, including the support of your device’s warranty, for responding to questions, requests and complaints you address to us in relation to our products and services and for the management of your participation in the competitions we organize, according to the terms and conditions of each one of them, it is necessary to process your personal data, so that we can fulfil our contractual obligations to you and to provide you with the services you wish. In the cases where you choose physical transactions, we can provide the above services to you through the network of our authorized partners’ physical stores.
Furthermore, it is necessary to process your personal data in order to create and manage your account on our website, offering you the opportunity to use the services and privileges offered through the website's user account. Please note that if you already have an account with one of the widely used social media platforms, such as Facebook and Google, you can register and log in to your account using your user data with that provider. When you log in this way, we may gain access to your email address, provided that you have shared this information with that provider.
You may find information about the processing of your personal data by Google here: Privacy Policy – Privacy & Terms – Google.
You may find information about the processing of your personal data by Facebook here: Meta Privacy Policy - How Meta collects and uses user data | Privacy Center | Manage your privacy on Facebook, Instagram and Messenger | Facebook Privacy.
The processing of our retailers’ personal data is carried out in the context of the execution of our broader commercial cooperation for the promotion and distribution of our Company's products to consumers through our retailers.
When your data is processed for reasons of support and assurance of our legal interests
We can use your personal data when it is in our legal interest to do so, and such an action is not counterbalanced against any potential damage for you.
Indicatively, we process your personal data:
- So that you can help us get an insight into your level of satisfaction with the products we offer you, so that we can objectively evaluate and improve them. That's why we use your data (e.g. name, phone or email) to conduct customer satisfaction surveys or market surveys for the customers of glo.
- So that you can help us better understand the needs of the visitors of our website and offer them information that is useful to them and the appropriate services.
- To ensure the prompt and proper response to the questions, complaints and in general any issues you bring to our attention, when you contact us.
- To ensure that the content of our website is presented as effectively as possible to its users, e.g. by improving the results of the search engine included on our website, thus helping you to search easily and quickly for any information you wish and that is available on our website (e.g. regarding our products, the terms of use of the website, the product return policy, etc.).
- To ensure that our website works smoothly.
- So that you can help us keep our systems secure and prevent any unauthorized access or cyber attacks.
When you give us your consent to use your personal data
In specific cases, the processing of your personal data is carried out only after you have given your explicit consent, for example to subscribe to our newsletter and to receive information about special offers and promotions.
When you register on our website we ask for your consent so that we can process your data for specific purposes which are listed below indicatively. For any other activity of our company, which may emerge in the future and which relies on your consent, we will provide you with sufficient information before the start of the processing, so that you can decide whether or not you want us to process your data.
Specific cases where we will ask for your consent before using your data are indicatively: for sending invitations to events, newsletters, updates about our existing or new products and special in general as well as for profiling on the basis of which you will receive personalized updates on offers and products and for other promotions based on your needs, interests, preferences, purchases and transactions in general, which actions we will communicate to you using, either your e-mail or your mobile phone number (in case of sending SMS, Viber or by phone) according to the communication channels of your choice.
You have the right to withdraw your consent at any time either by selecting the unsubscribe link you will find in each communication, or by sending an e-mail to dpo@bat.com. However, the withdrawal of the consent shall not affect the lawfulness of the processing based on the consent in the period prior to its withdrawal.
When the processing of your personal data is necessary in order to comply with the obligations imposed by law.
We are required to use your personal data when this is expressly mandated by a provision of the law or in the framework of regulatory compliance, for example when we process your data for tax purposes or to ensure, through the age/ adulthood verification mechanism we use according to the aforementioned, that the use and the purchase of tobacco products is held according to the law, only by adults.
The reason justifying processing of data that may be considered as falling within the special categories of data (ie. Smoking habits as potential health data) is that this kind of data is manifestly made public by the data subject upon expression of the latter’s interest in our products.
PURPOSES OF PERSONAL DATA PROCESSING
Your personal data will be used in accordance with the principles of necessity, proportionality, lawfulness and transparency.
Your personal data is processed mainly electronically, for the following indicative purposes:
- a) Provision of services by physical transaction, or execution of online orders for the purchase of products and the support of your requests: In order to help you complete your purchases through our e-shop, to deliver your order, to provide you with ongoing support with any problem you encounter regarding your device or to implement your requests to participate in the competitions we organize, in accordance with their terms and conditions, we must process the personal data that you disclose to us, such indicatively as your name, your address, your date of birth, your contact details, etc.
- b) Newsletter: when you agree to receive by email, telephone, SMS or WhatsApp / Viber updates and news about BAT’s marketing initiatives, contests and other advertising and promotional materials either general or personalized to your needs, interests, preferences, purchases and in general based on your transactions, and where you have provided us with your consent in this regard. In addition, we will use your contact details to inform you about our promotional initiatives, invitation to events we organize, etc. for the development of our company's business activity.
- c) Creation of your consumer profile: with your prior consent, we process your personal data in order to collect consumer habits and to send you personalized information.
- d) To know, through your reviews, your level of satisfaction with the products we offer you, helping us to objectively evaluate and improve them.
- e) Compliance with the legal framework: To ensure that we promote and sell tobacco products to adults only, to inform you of any product safety or recall issues, etc.
- f) Ensuring the best and most efficient operation of the website.
- g) Ensuring the prompt and proper response to the questions, complaints and in general any issue you bring to our attention, when you contact us.
- h) The processing of our retailers’ personal data is carried out for the fulfilment of the scope of our contract and of our broader commercial cooperation and in particular to enable the promotion and distribution of our Company's products to consumers, through our retailers, and the communication with the latter regarding any issue that may arise during our transactional relationship.
STORAGE PERIOD
When the processing of your personal data is based on the execution of the contract between us, your personal data are stored for as long as necessary for the execution of the contract and the provision of the services we have undertaken towards you or for as long as stipulated by law for the establishment, exercise, and/or support of legal claims under the contract.
For the purpose of product and services marketing activities, your personal data are stored until the withdrawal of your consent. You may withdraw your consent at any time. Withdrawal of consent shall not affect the lawfulness of the processing based on the consent given in the period prior to its withdrawal.
Where processing is mandatory under the applicable law, your personal data will be stored for the period provided by the relevant provisions applicable in each case. Please note that, especially in the context of the process of verifying your age/adulthood through Yoti Age Verification, the image data and/or the information of the identification document you provide us with are automatically deleted as soon as the above process is completed.
Personal information will be processed in accordance with applicable regulations and, in any case, in a way that guarantees their security and confidentiality, preventing their disclosure or unauthorized use, modification or destruction.
DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
The Company uses third parties in certain cases that require the processing of your personal data.
The third parties involved in these activities are carefully selected, are specialized, competent, reliable and provide adequate guarantees as regards their compliance with the applicable data processing laws and regulations, including the security profile of such personal information.
For some processing activities the Company has appointed such third parties as Data processors or in each case has explicitly authorized them for the processing described in this statement. In these cases, the Company remains responsible for the processing of your personal data, determines the individual elements of the processing and signs Data Processing Agreements with the third parties to whom it entrusts the performance of processing activities, in order to ensure that the processing is carried out in accordance with the applicable legal framework and that each data subject can freely and without restriction exercise his or her rights.
The Company will periodically check that third parties perform their respective duties and that they comply with the measures for the protection of personal information.
The Company cooperates with third companies, organized in a network of physical stores, in order to make its products available to the physical market and to consumers who prefer physical transactions. When purchasing products, our authorized partners, resellers, process the personal data of our customers, in order to complete the purchase of products, or to resolve any problem the customer may encounter from the use of the device, or even to service the warranty of the purchased product, as well as to register on behalf of the Company the corresponding positive statements of consumers for receiving informative material through various channels, if the latter so wish.
In the case of an electronic transaction, the Company, in order to complete an online purchase through its website and to deliver the products to the customer, cooperates with third companies that forward, organize the order and invoice the products of the transaction, as well as with cooperating courier companies. When cooperating companies resell the relevant products in respective permitted channels in accordance with the applicable terms agreed with the Company, they act as independent controllers for the purpose of the resale.
The Company may also forward your personal data to third parties – external partners that provide us with online platforms and in general services related to the conducting of product and service evaluation surveys, so that we can get insight of your level of satisfaction with our transactional relationship or conduct statistical or targeted market analysis.
The Company may also provide access to your personal data, when required, to third party contractors for the purpose of technical support and maintenance of its database (e.g., online platform providers, IT support technicians).
Access to your personal data is provided, if required, to companies with which our Company cooperates while using specific website features/functions through electronic platforms provided by these third parties in order to improve the efficiency of our website and, subsequently, the user's experience.
In the context of the age/ adulthood verification process, we use the Yoti Age Verification mechanism provided by our external partner Yoti Limited.
The Company may disclose your data, in aggregated/ anonymous form, for processing and independent use, to other companies in the British American Tobacco Group based abroad, for the conduct of market analysis and processing, statistical or targeted, in relation to the products for sale by such third parties, and to identify promotional activities or offers.
Your personal data will be forwarded outside the European Union only towards countries that guarantee adequate protection to the interested party based on a decision of the European Commission and/or in accordance with the adequate guarantees provided by EU Regulation 679/2016.
The Company may also disclose your personal information to public authorities, if required by laws, regulations, administrative or judicial measures, etc.
RIGHTS OF DATA SUBJECTS - METHODS OF COMMUNICATION
We inform the user that the current European Data Protection Regulation and the relevant national legislation grant him special rights, including the right of access, correction, erasure, restriction, as well as opposition to the processing and portability of data in accordance with Articles 13 to 22 of Regulation 2016/679 of the EU. More specifically:
Right to object to the processing:
This right allows you to object to the processing of your personal data when it is done for one of the following reasons:
- for the purposes of the legitimate interests we pursue
- for the purposes of direct marketing and consumer profiling
- to be able to perform a duty of public interest or
- for scientific, historical, research or statistical purposes.
Right to withdraw consent
If we have obtained your consent to the processing of your personal data for certain activities, you may withdraw your consent at any time and we will stop processing your data for the purpose for which you consent, unless we consider that there is an alternative legal basis to justify the continued processing of your data for this purpose, in which case we will notify you of such processing.
For this purpose, you can send your request in writing to the E-mail: dpo@bat.com . In addition, each advertising email has a link that allows you to disable the sending of our newsletters and other promotions.
Access right
You can ask us at any time for access to the information we hold about you in order to be fully aware and verify the lawfulness of the processing. Access to your information does not incur an additional charge, unless there is a specific situation which is set out in the Regulations. Where we are legally permitted to do so, we may reject your request. If we reject your request, we will respond to you with specific justification for the reasons of the rejection.
Right to erasure
You have the right to request that we erase your personal data in certain cases. The exercise of this right is justified in particular when:
- The data is no longer needed.
- You withdraw your consent for us to use your data and there is no other valid reason to continue the processing.
- The data has been processed illegally.
- It is necessary to erase the data in order to comply with our obligations under the law or
- You object to the processing and we are unable to prove compelling legal reasons for continuing our processing.
We may refuse to comply with your request for erasure only in limited cases by always explaining the reason, such as when a contract exists and is being executed between us.
When we comply with a valid data erasure request, we will take all reasonable steps to erase the relevant data.
Right to restrict processing
You have the right to ask us to restrict the processing of your personal data in certain cases, for example if you dispute the accuracy of the personal data we keep about you or have objections to the processing of your personal data for our legitimate interests. If we have forwarded your personal data to third parties, we will inform them of your request to restrict the processing of your data, unless this is impossible or involves a disproportionate effort. In case of removal of any restrictions on the processing of your personal data, we will duly inform you in advance.
Right to correction
You have the right to request that we correct any inaccurate or incomplete personal data we keep about you. If we forward this personal information on to third parties, we will inform them of the correction, unless this is impossible or involves a disproportionate effort. In the event that we do not fulfil your request for some legal reason, we will respond to you and justify the reasons.
Right to data portability
If you so wish, you have the right to transfer your personal data between service providers. In effect, this means that you are able to transfer the information we keep about you to another third party. To be able to do this, we will provide your data in a widely used software format so that you can transfer the data. Alternatively, we can transfer the data directly on your behalf.
Right to lodge a complaint with the Supervisory Authority (DPA)
We also inform the user that according to Article 77 of the EU Regulation, if you believe that the processing concerning you breaches the aforementioned Regulation, you have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) through its web portal (https://eservices.dpa.gr/).
For any issue regarding the processing of personal data, you can directly contact the Data Protection Officer (DPO) PISTIOLIS-TRIANTAFYLLOS & ASSOCIATES LAW FIRM, ANDERSEN LEGAL, email: dpo@bat.com
You can also contact us to submit questions or exercise your rights in the following ways:
- by sending an email at gr@myglo.com or
- by post, at 27 Agiou Thoma Str., Maroussi, Attica, GR 15124 or
- By telephone, at 8005001450
CHANGES TO THE PRESENT PRIVACY POLICY
We may make changes to this Privacy Policy at any time by posting a copy of the amended Policy on the Website, so please check back regularly.