Standard Page

Privacy policy

We believe in creating something better.  We understand you are trusting us with information that is important to you, and we want to repay your trust by being transparent about how we use and protect your information.  

 

This Privacy Notice explains the privacy practices for our WEST  website, the software and APIs we use, and any offline interactions we have with you (our “Services”).  Specifically, we’ll tell you about:

The information this Privacy Notice covers

This Privacy Notice covers personal information that we collect and process through both offline interactions with you through our representatives at various touchpoints and online when you provide us with your personal information directly. Personal information is any information that tells us something about you.

This could include information such as your name and contact details. Some personal information is categorised as "special" under data protection legislation. This includes information relating to health, racial or ethnic origin, and religious or philosophical beliefs. The only special category of personal information that we collect about you is your smoker status, when you create or update your account with us and we only do this where you have provided your explicit consent. This information is used for analytical purposes in order for us to understand who is using our website so that we can develop our marketing strategy [and it will also be used to provide you with Information on our activities and products relevant to you, where you have provided your consent for us to do so].

We do not intentionally collect or process any other special categories of personal information about you and nor do we collect any information about criminal convictions and offences. If you include any other special categories of personal information when you contact us or provide us with data through your use of the website, it is your responsibility to make sure you are happy for us to use that personal information in accordance with this Privacy Notice. You should be aware that this personal information is more sensitive and is more heavily protected by data protection legislation, so you should avoid including this kind of data if possible.

In the event we do need to process other special categories of personal information in very limited circumstances (such as where additional information is required to verify your age), we will only do so with your explicit consent, unless we have a legal reason to do so without your consent. Where we ask for your consent, we will explain at the time the purpose for which the personal information will be used.

How we collect personal information

We collect your personal information to provide you with our Services, so that we can stay in touch with you, to improve and personalise our Services for you, to handle any questions or complaints you may have, and to comply with our regulatory obligations. This involves:

Information you provide to us:

We collect information from you when you register an account with us, sign up to or attend an event hosted by or on our behalf, subscribe to our Services, enter a competition, request information from us, or when you interact with us by any other means related to our Services. This includes the information we need to identify you to comply with our regulatory obligations. See the Age-verification and identification section for more.

We collect information you voluntarily provide to us, such as your name and contact details, when you make an enquiry or complaint, sign up to our Services, and when you participate in our surveys or events.

Information we collect automatically or that is generated when you use our Services

We collect some information about you automatically, such as information collected by cookies, web beacons and similar technologies when you use, access or interact with us via our website. Please see our Cookies section below for further details.

Information we collect from third-parties

Some of the information we collect about you comes from third-parties such as analytics service providers. We also use some public sources to verify your personal information but only for the purposes of age verification.

What personal information we collect

Identity Data is information that specifically identifies you.  It includes your first name, last name, username or similar identifier, date of birth and gender.  We use this information to register and create your account, and to ensure we are dealing with the correct person.  In some cases, we may need your national ID details. We need to conduct age-verification so that we can comply with applicable local laws and regulations that restrict who we offer our Services to.

Contact Data includes address, email address and telephone numbers.  We use these details to deliver our Services to you.

Transaction Data is generated as a record of your interactions with us through our website. It is a record of your engagement with us through your feedback, survey responses, competitions entered and requests for information you have made from us. 

Account Profile Data is the personal information contained in your account.  It includes your username and password details as well as your Identity Data, Contact Data and Communications Data.

Image Data is the personal information contained in photographs and/or videos that may be taken at certain events we host or are hosted on our behalf. We will only collect this personal information if you are within the designated area that we are operating from and this area will be clearly sign posted to confirm that photographs and/or video footage may be taken in the area. If you do not want your image to appear in the photographs or video footage that we are collecting, please do not enter the area.

Communications Data includes your preferences in receiving information from us and your communication preferences to ensure we engage with you as you wish.

Smoker Status Data includes whether or not you smoke tobacco. This information is only collected when you create or update your account and you can change your status at any time by updating your preferences.  If you change your smoking status to ‘I’m an ex-smoker’ at any time, we are obliged by law to restrict your access to the site. In which case, we will terminate your account.  You may, of course re-join should you become a smoker again in the future.

Technical Data is the information behind the technology that we use on our website.  It tells us how our Services are performing and we use this data to make our Services operate better. Technical data includes your internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website.

Usage Data is the information generated, including using cookies, as you use our Services.  We use third-party analytics providers to analyse how you are using those Services.  This data, especially when we use it as Aggregated Data, tells us how the experience could be improved and what we can do to enhance the services we offer. We use a third-party service, Google Analytics, to collect standard internet log information and details of your behaviour patterns as you navigate around our website.  It does this using information from cookies.  This helps us to find out the number of users to the various parts of our website and how they interact with the content on the site.  We also use this information to maintain and monitor the performance of our website, and to look for ways of improving our website and the services it offers you.  This information does not identify any individuals.  You can see our Cookies Policy here.

Aggregated Data is derived from your personal information but is not considered “personal data” in law as it is anonymous and the data does not directly or indirectly reveal your identity.  This data is used for statistical research and to inform business strategy. We collect, use and share Aggregated Data, such as statistical or demographic data. Aggregated Data may be derived from personal information (for example, we may aggregate all our website visitors’ website usage to calculate the percentage of them accessing a specific website feature) but it does not identify individuals. However, if we combine or connect this Aggregated Data with your personal information in a way that directly or indirectly identifies you, we treat the combined data as “personal data” which will be used in line with this Privacy Notice.

Age-verification and identification

You must be at least 18 years of age to use our website and our Services. This is to ensure that we meet our legal obligations.  Before you enter our website you will be asked to verify your age.  When you register an account via the website, you will need to provide Identity Data so that, with your consent where necessary, we can authenticate your age. Your Identity Data is used to verify your age.  If for some reason we are not able to verify your age from the information provided, you will be asked to consent to a full identity check by submitting evidence in the form of National ID, such as your passport. Your Identity Data will be kept only for the period we need to hold it for legal reasons after that.  After your identity check is completed your National ID document is not kept by us or by any of our service providers.

Not participating in the age-verification or identification process will obstruct your interactions with us. If you have any questions about the age-verification or identification process, please contact our Customer Service here or via [To be inserted] and an advisor will be happy to help you.  Our website and our Services are not intended for children and we do not knowingly collect data relating to children.

Cookies

We collect website Usage Data and Technical Data automatically from your mobile or other device using cookies, web beacons and similar technologies. A cookie is a small file of numbers and letters that we put on your mobile or other device if you agree.  These cookies allow us to distinguish you from other visitors to our website and tells us how you are using our website.  Some cookies are necessary to provide you with a good experience as you browse; others help us to gather information that informs how we can improve our website for you. You can block cookies at any time by activating the setting on your browser that allows you to refuse some or all cookies. If you do block cookies there may be parts of our website that you will be unable to access or that will not function properly.

Our cookies help to:

  • make our website work as you would expect;
  • remember your settings during and between visits;
  • improve your and other users' experiences; 
  • allow you to sign up to receiving additional information and updates; and
  • improve the speed/security of our website.

We use the following cookies on our website:

[To be inserted]

How we use your personal information

Your personal information is used for the following purposes:

Account creation and age-verification.  If you sign up for an account with us via the website or at one of our events, we will use your personal information to register your account and carry out age-verification.  

Account management. We use your personal information to administer your account and to manage our relationship with you, which will include notifying you about any changes to our terms or privacy notice, enabling you to use promotional codes or discounts, and responding to your queries. This also includes using your personal information to communicate with you about events, competitions, games, and surveys, which you have requested information about or shown an interest in. 

Providing customer service. If you contact us, we will save your contact details to respond to your query. The information you provide is saved in our system to ensure you receive the correct support from our Customer Service team and to inform our understanding of your experience.

Personalising your experience. We use information about your behaviour on our website to personalise your experience by tailoring our communications to your preferences. If you are registered to receive communications, we use information about your online activity to inform the email updates you receive from us with news and related information. You can opt out of receiving these communications in the preference centre in your account. You can also unsubscribe through a link in every communication we send out. We use information about your online activity to personalise your online browsing experience on our website to ensure you will see content that is relevant for you.]

Providing reviews, surveys and feedback. If you leave a review about our Services on our website or at one of the events you attend, or if we invite you to fill out a questionnaire, you can choose what information you provide. The information is collected to give readers of the review a better understanding of our Services and to help us better understand your preferences and to serve you better. We analyse this feedback - and feedback on other review sites - to learn how we can make improvements to our Services.

Events. We use your personal information when we invite you to events hosted by us or on our behalf. If you participate in an event, we collect information about you to better understand your preferences. Offline data collection may be part of a promotional initiative, such as a prize draw or competition and at some events we take photographs of attendees. Where photographs or videos are taken at the events, the areas will be clearly sign posted and if you do not want your image to be captured, you should avoid these areas. 

Quizzes, competitions and games. Occasionally we will invite you take part in a quiz, competition or play an online game in order to win prizes through the website. The information you provide via the games and quizzes will be used to record your scores and post the results on our leader board. We will also use personal information to send coupons or vouchers to the winners.  

Information about our activities.  If you have requested information from us about any of our activities, we may contact you by email / SMS / telephone / post (depending on your preferences) about activities which we carry out, unless you have told us you do not want to hear from us. Otherwise we will only contact you if you have agreed we can.

Where appropriate and with your consent (by setting your preferences in the preferences centre during or at any time after the registration process), we may pass your information to our affiliate Imperial companies where you are located so that you receive further personalised information and services that might interest you. You may ask us at any time not to use your information by contacting us using the contact details below. In order to provide you with a personalised experience, we will send you information based on your preferences. These preferences can be based on your online behaviour and/or surveys that you have participated in. Personalised emails will be sent out (if you are subscribed) based on your online behaviour and preferences. In certain cases, your personal information will be matched to personal information received from third-parties to build up a profile. This profile will give us insight on how we can personalise your experience with us. 

You can ask us to stop sending you product information messages at any time by logging into the website and unchecking relevant boxes to adjust your preferences or by following the opt-out links on any product information message sent to you. You can also opt-out by contacting us at any time.  Where you opt-out of receiving these product information messages, this will not apply to personal information provided to us as a result of other transactions. Therefore, if you opt-out of product information messages, we will still need to send you service communications from time to time, such as information about changes to our services or product recalls.

Research and analysis. We use all the data we collect (largely as Aggregated Data), including your feedback, your responses to questionnaires and your online behaviour to conduct research and analysis to improve and develop our business. We carry out research and analyse the data we have (usually in aggregated form, to improve our Services, our marketing strategy and our customer relationships and experiences.  We also use and share our statistical data and the results of our research and analysis to improve our business and develop new services.

Administering and protecting our business.  We use all the data we collect to administer and protect our business, our website and our information and systems.  This includes carrying out activities like trouble-shooting, data analysis, testing, system maintenance, system security, support, reporting and hosting data.

Lawful basis that allows us to use your personal information

We need to tell you the lawful basis that permits us to use your personal information. We may use your personal information under more than one lawful basis depending on the specific reasons for using it. Please contact us if you need more details about the specific lawful basis we are relying on to process your personal information.

If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we will only process your personal information without your knowledge or consent where this is required or permitted by law.]

Our use of your personal information is allowed:

  • with your permission (for example, where you subscribe to updates from us);
  • where we need your personal information to enter into a contract with you (for example, when you enter a competition via our website);
  • where we need to comply with a legal or regulatory obligation (for example, where we need verify your age or your identity); and/or
  • where it is necessary for our legitimate interests (or those of a third-party) and your interests and fundamental rights do not override those interests (for example, when we use your information to help us improve and develop our Services)

The table below provides more detail about the personal information we use and the legal basis that we rely on in each case.

Purpose

Personal information used

Lawful basis including basis for legitimate interest

Account creation and Age-verification.

Identity Data, Contact Data, Account Profile Data, Communications Data, Smoker Status Data

(a) Performance of a contract with you

(b) Necessary to comply with legal obligation

(c) Consent

Account management

Identity Data, Contact Data, Transaction Data, Account Profile Data, Communications Data

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to develop our relationship with you to progress our business)

Providing customer service

Identity Data, Contact Data, Transaction Data, Communications Data

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to develop our relationship with you to progress our business)

Personalising your experience

Identity Data, Contact Data, Transaction Data, Account Profile Data, Communications Data, Technical Data, Usage Data, Third-Party Data, Smoker Status Data

(a) Consent

(b) Necessary for our legitimate interests (to develop our products/services and grow our business)

Providing surveys, reviews and feedback

Identity Data, Contact Data

(a) Consent

(b) Necessary for our legitimate interests (to study how our products/services are used, to develop them and grow our business)

Events 

Identity Data, Contact Data, Image Data

(a) Consent;

(b) Necessary for our legitimate interests (to develop and grow our business understanding of customers and to inform our marketing strategy).

Quizzes, competitions  and games

Identity Data, Contact Data

(a) Consent

(b) Performance of a contract with you

(c) Necessary for our legitimate interests (to study how our products/services are used, to develop them and grow our business)

[Information on our products and activities 

Identity Data, Contact Data, Transaction Data, Account Profile Data, Communications Data, Technical Data, Usage Data, Third-Party Data, Smoker Status Data

(a) Consent

(b) Necessary for our legitimate interests (to develop and grow our business, understanding customers and to inform our marketing strategy)]

Research and analysis

Identity Data, Contact Data, Transaction Data, Account Profile Data, Technical Data, Third-Party Data, Smoker Status Data

(a) Necessary for our legitimate interests (to define types of customers for our products/services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

(b) Consent (only where you have provided it in relation to Smoker Status Data)

Administering and protecting our business  

Identity Data, Contact Data, Transaction Data, Account Profile Data, Communications Data, Technical Data, Usage Data, Third-Party Data

Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

If you do not provide personal information

Where we need to collect personal information by law and you fail to provide that data when requested, we may not be able to provide our Services to you. In this case, we may not be able to fulfil our obligations to you, but we will notify you if this is the case at the time.

Who we share your personal information with

We will treat all your personal information as confidential and in accordance with data protection laws. We will, however, share your personal information with our affiliates that are part of the Imperial Brands group and with third parties who provide us with services. We limit the amount of third parties that have access to your personal information to only what is needed to provide the Services. 

To do so, there are certain categories of processors (i.e. those third parties who process your personal information on our behalf) that have access to your personal information, which include: 

  • System administration providers;
  • Website host providers;
  • Cloud storage providers;
  • Venues that host events for or on our behalf;
  • Analytics providers;
  • Age-verification solutions;
  • Marketing agencies and similar service providers.

Where we use third parties to process your personal information on our behalf, we will always carry out checks to ensure that there are appropriate protections for the safeguarding your personal information. We will also monitor the performance of these third parties (and their approved subcontractors) to ensure that your personal information remains secure.

We require all third parties to respect the security of your personal information and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal information for their own purposes and only permit them to process your personal information for specified purposes and in accordance with our instructions.

We share your personal information with our Imperial Brands affiliate in the country where you sign up to our Services from, which provides us with sales, marketing and customer care services in that country.  This is so that we can engage with you in your own language, and can provide you with local customer support.

We also share information (usually Aggregated Data) with our relevant affiliates for business administration and reporting purposes, and for product and services development purposes.  For instance, we share statistical customer feedback and survey data with our affiliate responsible for product innovations.

We will not usually disclose your personal information other than as set out above. However, there are certain circumstances where we need to share personal information, for instance:

  • where we are legally required to disclose the information, for example because a court orders us to do so;
  • where the disclosure of the personal information is required for the purposes of the prevention and detection of crime. This includes sharing the personal information with tax authorities and law enforcement agencies;
  • where we need to disclose the personal information for or in connection with any legal proceedings, or for obtaining legal advice, or the disclosure is otherwise necessary for the purposes of establishing, exercising or defending legal rights;
  • where disclosure is necessary to protect your vital interests (for example if you are unwell at one of our events, we may need to seek medical assistance); and 
  • where we share your personal information with third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets if we reorganise our business. Alternatively, we may seek to acquire other businesses or merge with them.

Cross-border transfers 

Your personal information will only be transferred to countries in the European Economic Area (the “EEA”) or where the recipient has confirmed an adequate level of protection for it, for instance, by contractual agreement. You can ask us about the arrangements we have in place. In some cases, we work with third parties, including our Imperial Brands affiliates, based outside of the European Economic Area (EEA) who store, host or transfer your personal information outside the EEA.  

If we transfer your personal information out of the EEA, we will ensure that a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented: 

  • we will ensure the countries that we transfer your personal information to have been deemed to provide an adequate level of protection for personal information by the European Commission;
  • we will use data processing agreements or specific contracts approved by the European Commission which give personal information the same protection it has in Europe; or
  • where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal information shared between the Europe and the US.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal information out of the EEA.

How we look after your personal information

Information sent via the internet is not always secure. We cannot guarantee the security of the information while it is being transmitted to our website as you register your account; any transmission is at your own risk.  However, once we’ve received it, we take appropriate security measures to keep it safe. We limit access to your personal information to those who have a business need to know. Where we use service providers, we require them to take appropriate security measures to protect your personal information from accidental or unlawful destruction, loss, or alteration and unauthorised access or disclosure.  They will only process your personal information on our instructions; and they are subject to a duty of confidentiality.  

We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are required to do so.

How long we keep your information for

We keep your personal information for as long as is necessary to fulfil the purposes for which it was collected. After that we will delete or de-identify your personal information unless we hold it to comply with our legal obligations, resolve disputes and enforce our agreements.  We will keep any personal information in your account for as long as you have an account with us and generally for a period of 3 years following when you last accessed your account, provided that you are not subscribed to our newsletter or other services. 

We may need to keep your personal information for a longer period under certain limited circumstances (for example, where we have a legal reason to keep the personal information for a longer period or in case of a legal claim or dealing with on-going queries or complaints.]

Links to third-party websites

Our website may include links to third-party websites, plug-ins and applications (such as Facebook and Twitter). Clicking on those links or enabling those connections may allow third-parties to collect or share data about you. We do not control these third-party links and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.

Your information rights

If you wish to exercise the rights set out in this section, please make your request in writing using the contact details in the Who we are and how to contact us section below.  We will respond to any requests to exercise your rights as soon as we can and in any event within one month of receiving your request and any necessary proof of identity or further information we need. No fee usually required.

You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.]

In summary, you have the right, within certain legal parameters, to ask us:

  • for details about how we use your personal information (which we do in this Privacy Notice);
  • to see what personal information we hold about you;
  • to correct your personal information;
  • to erase your personal information in certain circumstances;
  • not to use your personal information in a particular way;
  • to port your personal information in a commonly used electronic format;
  • to restrict how we use your personal information;
  • not to send you materials where we are relying on your consent to do so (i.e. withdrawal of your consent); and
  • not be subject to automated decisions about you and to request human intervention.

Sometimes you will be able to exercise your rights through your account settings. We have noted where this is possible in the further information provided below.

For details about how we use your personal information.  This Privacy Notice tells you this and in any further updates to it;

To see what personal information we hold about you.  You can access your personal information through your account settings or you can ask us to provide you with it.  

To correct your personal information.  You can ask us to correct inaccurate information that we hold about you. If we are satisfied that the new data you have provided is accurate, we will correct it on our systems as soon as possible. You can also update your own personal information at any time through your account settings via the website. 

To erase your personal information in certain circumstances.  You can ask us to delete your personal information in certain circumstances (for example, if we have processed your personal information unlawfully or if we no longer need it for the purposes set out in this Privacy Notice). If you ask us to delete your personal information but you do not want to close account, we will usually need to keep processing your data in a personally identifiable form, so you should be aware that we may not be able or obliged to anonymise your personal information. If you ask to delete your account, we will stop using your account but we will retain some details for legal or evidential purposes.

Not to use your personal information in a particular way.  You can object to us processing any personal information that we process where we are relying on legitimate interests as the legal basis of our processing. If we have compelling legitimate grounds to carry on processing your personal information, we will be able to continue to do so. Otherwise, we will stop processing your personal information.

To port your personal information in a commonly used electronic format.  You can ask us to send you a copy of the personal information that we hold about you in a commonly used electronic format.

To restrict how we use your personal information.  You can ask us to restrict processing of your personal information in some circumstances (for example, if you think the personal information is inaccurate and we need to verify its accuracy, or if we no longer need the information but you require us to keep it so that you can exercise your own legal rights).  This means that we only store your personal information and we won’t carry out any further processing on it unless you give us consent or we need to process the information to exercise a legal claim or to protect a third-party or the public. 

Not to send you product information.  You can ask us not to send you direct communications regarding product information. You can do this by opting out of what you no longer want to receive in the preferences section of your account settings. You can also opt out by using the "unsubscribe" option in any of our emails.

Not be subject to automated decisions about you and to request human intervention.  You can object to automated decisions being made about you and to request human intervention.] 

If you have given us permission to use your personal information in any particular way, you have the right to withdraw that permission at any time.  You can do this in the preference centre in your account or by contacting us.

Changes to this Privacy Notice 

We will keep this Privacy Notice up to date and you can find the date it was last updated at the bottom of the page. If there are any changes to the way in which your personal information is used, we will update this Privacy Notice and, where appropriate, notify you of the changes by email. We recommend that you check this page from time to time to ensure that you are aware of any changes.

Who we are and how to contact us

The data controller of all personal information collected from your use of the Services is Imperial Tobacco Limited of 121 Winterstoke Road, Bristol, BS3 2LL (referred to in this notice as “we” or “us”), a company in the Imperial Brands PLC group of companies (the “Imperial Brands Group” or “Imperial Brands”). 

If you have any queries about this Privacy Notice or complaints about the way we use your personal information, please contact us at [  ]and we will assist in resolving the issue.

Lodging a complaint

We are registered with the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk), with registration number ZA106554. If we cannot resolve your complaint or you are unhappy with how we have processed your personal information, you have the right to make a compliant at any time to the ICO. We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance using the contact details above.

Effective Date

This Privacy Notice is effective from 1 April 2020.  Previous versions of the Privacy Notice can be found [here].