This site contains information about products containing nicotine, intended for people over 18 years of age. For visits and purchases on the website you must be 18 years or older.
Swedish Match North Europe AB (“Swedish Match”, “we”) applies the prevailing regulatory framework pertaining to the processing of personal data and continuously strives to provide you with optimal integrity protection. This Privacy Notice is intended to help you understand how we use the personal data you submit to us when you, for example, create an account or purchase products from www.zyn.com (the “Website”) (except for the subdomain us.zyn.com).
Swedish Match North Europe AB, corp. reg. no. 556571-6924, SE-118 85 Stockholm, Sweden, tel: +46 (0)200 113 114, is the controller for processing the personal data you submit to us. If you have questions about Swedish Match’s processing of your personal data, please contact us, at firstname.lastname@example.org.
We mainly process your personal data to fulfill our obligations to you – for example, administrating your user account, managing your product orders, sending newsletters and providing service and support. More information about each purpose, and also the legal grounds for our processing, follows below.
When you order products from the Website, we ask you to provide, for example, your personal identity number or information about your age and contact information so we can process your order. Your personal identity number or age information is used to verify that you are of legal age. The legal basis for processing your personal identity number or age information is our legitimate interest in ensuring that we only sell nicotine containing products to persons over the age of 18. Other personal data, such as contact details, is required to administrate and deliver the order and to provide service. The legal grounds are that the processing is necessary to allow Swedish Match to fulfil the agreement with you. If you do not submit the information we request when ordering, you cannot carry out the order.
Swedish Match also stores your order history, meaning information about products you have ordered, the quantity, date and price. We store such documentation in order to offer you qualified service after placing your order, and to manage any complaints and meet the current regulatory requirements. The legal basis for this processing is our legitimate interest in providing good service, thereby enabling the safe use of our products, and to allow us to make the requisite assessments, fulfil our obligations and protect our rights in conjunction with complaints. Swedish Match also processes your contact information and your order history for the purpose of market research. The legal basis for this processing is our legitimate interest in conducting such research in order to evaluate and improve our products.
Your personal data may also be processed so we can fulfil our legal obligations, for example, in accordance with the Swedish Accounting Act.
We also process your e-mail address and order history for marketing purposes. The marketing consists of distributing newsletters and special offers on items in our product range via e-mail. You are entitled to oppose the marketing, and you can also at any time, choose to unsubscribe from our newsletters and other marketing by e-mail. To unsubscribe, please contact us on email@example.com or use the unsubscribe link included in each newsletter/e-mail. The legal basis for our processing of your e-mail address is our legitimate interest in marketing our products to existing customers.
How long do we save personal data?
Your personal data is processed for as long as necessary to administrate your order and to provide you with service, as well as managing any complaints and current regulatory requirements, but not longer than one year after you placed the order if we do not have a legal obligation to store the data longer. On the condition that you have not opposed receiving newsletters and other marketing by e-mail, we will also use your e-mail address for the marketing of similar products for up to one year after your latest order.
When you create a user account on the Website, we ask you to submit certain information about yourself, for example, your name and e-mail address. We process this personal data to create and administrate your account. The legal basis for this processing is our legitimate interest in providing and administrating your user account. When you place an order and are signed into your account, the purposes and legal grounds described above under “For customers” also apply. If you do not submit the information we request when creating an account, you cannot create the account. However, you are not for this reason prevented from ordering products on the Website. You may at any time sign into “My pages” and update most of the personal data you have submitted.
We delete your account if you have not signed into the account or placed an order for one year or notified us that you wish to keep your user account.
When you notify us that you wish to receive our newsletter, you submit your e-mail address, which is then processed for marketing purposes. The legal basis for this processing is our, and your, legitimate interest in administrating the distribution of newsletters. You may contact us at any time to unsubscribe from our newsletter, most easily at firstname.lastname@example.org. You can also unsubscribe via the link in the newsletter.
We will delete your e-mail address the moment you cancel your subscription for our newsletter or in any other way object to receiving marketing from us.
When you contact customer service, we process the personal data you submit, if any, to administrate your customer service case. The legal basis for this processing is our, and your, legitimate interest in managing your case. Your personal data may also be processed so we can fulfil our legal obligations, such as those under applicable consumer protection legislation. The legal basis for this processing is our legitimate interest in providing good service.
We store your personal data as long as the case remains open and erase the data as soon as the case is concluded.
When you visit the Website, we collect information about your IP address (see also Swedish Match’s Information about cookies). Note that certain companies other than Swedish Match also collect your IP address when you visit the Website, in connection with the use of third-party cookies. How this occurs, and how you can go about limiting or turning off cookies in your web browser, is described in Swedish Match’s Information about cookies.
We use your IP address to prevent infringements, incidents and other misuse of our services on the Website, to run statistics on visitors to the Website, to update and improve the Website and marketing our products. The legal basis for this processing is our legitimate interest in preventing misuse and in having a properly functioning Website and to market our products.
Swedish Match may share your personal data with other companies within the Swedish Match Group, as well as with collaborating partners, for example, when providing IT and subscription services. These recipients only process your personal data on our behalf and in accordance with our instructions. Swedish Match takes all appropriate legal, technical and organizational measures to ensure that your personal data is processed securely, and with an adequate level of security when transferring to or sharing with selected recipients of this kind.
Swedish Match may also share your personal data with other companies who process your personal data independently, outside of our control, such as companies that manage the transportation of goods or payment solutions. We only share your information with these companies in order to fulfill our commitments toward you. When your personal data is shared with these companies, which are independent controllers, your personal data is processed in accordance with what is outlined in these companies’ privacy notices.
Swedish Match may also share your personal data with government agencies if we are obligated under the law to do so, or on suspicion of criminal activity.
Your personal data will primarily be processed within the EU/EEA, but may also be transferred to a country outside the EU/EEA, such as the United States, for example, if we share your information with other companies in the Swedish Match Group.
Swedish Match will only transfer your personal data to a country outside the EU/EEA if there are legal grounds to do so and sufficient guarantees that your personal data will be handled in a lawful manner. In such cases, Swedish Match takes all appropriate legal, technical and organizational measures to ensure that your personal data is processed securely, and with an adequate level of security comparable to the level of protection offered within the EU/EEA.
We save your personal data only as long as is necessary for the purpose for which you submitted your data. See more information under each purpose above.
We may also save your personal data for a longer time if it is necessary to fulfill a legal obligation that requires processing in accordance with applicable laws, or so that we can establish, enforce or defend legal claims.
You have certain specific legal rights that you can enforce against us. A summary of these rights follows below.
Right to access/extracts from the register. You have the right to know what personal data about you we are processing. Upon request from you, we will provide you with information in writing about our processing of your personal data, free of charge.
Right to data portability. You have the right to request a copy of the personal data you have provided to us in a structured, generally used and machine-readable format. Provided that it is technically possible – which is determined by Swedish Match – you also have the right to request that we transfer this personal data to another controller. The right to data portability applies to personal data that is processed via automated means, and is based on an agreement with you.
Right to correction of erroneous information. You have the right to request that we correct erroneous or incomplete information about you. If you have a user account, you may also sign into your account and rectify certain inaccurate personal data.
Right to deletion of certain data. You have the right to request that we delete your personal data under certain conditions, for example, if your personal data is no longer necessary for the purpose for which we collected the data, if you object to a weighing of legitimate interests we have carried out and support for our legitimate interest is lacking, if you object to direct marketing purposes, if your personal data was processed in an unlawful manner or if your personal data has to be deleted in order to fulfill a legal obligation.
In certain cases, we must save your personal data despite your request owing to legal requirements such as accounting and tax legislation, or, for example, if we need to retain certain data in order to establish, enforce or defend a legal claim.
Right to restrict processing of your personal data. You have the right to demand a restriction on our processing of your personal data in certain cases. If, for example, you have contested the fact that your personal data is correct, you can request a restriction on processing for a period of time that will give us the opportunity to check if your personal data is correct.
Right to object to our processing of personal data. You have the right, under certain conditions, to object to our processing of your personal data.
You have the right to object to processing that is based on the legal grounds of our legitimate interest. However, we may continue processing your data despite your objection to the processing if we have compelling legitimate reasons for the processing that outweigh your privacy interests.
You have the right at any time to object to our processing of your personal data for direct marketing. If you object to such processing, we will without undue delay cease all direct marketing to you.
If you have a complaint regarding Swedish Match’s processing of your personal data, you have the right to submit such complaints to a data protection authority. For more information, please contact your national data protection authority (contact details for data protection authorities in the EU are available here).
If you would like to present a request about an excerpt from the registry, data portability, correction or deletion – or present an objection or a restriction – please contact us at email@example.com.
Swedish Match takes the security measures needed to protect your personal data. For example, we use Secure Socket Layer (SSL), a protocol for the secure transfer of data.
Swedish Match reserves the right to make changes to this Privacy Notice. Any such changes are to be published on the Website.
Latest update to this Privacy Notice: 12 December, 2018 (Version 1.2)