Join HEINEKEN and eazle
Heineken UK Limited and Star Pubs & Bars Limited are part of the Heineken Group.
If you are viewing this policy in connection with your visit to the Join Heineken or eazle by Heineken websites, Heineken UK Limited is the company responsible for processing your data and references to "we", "us" or "our" in this policy means Heineken UK Limited.
If you are viewing this policy in connection with your visit to the eazle by Star Pubs & Bars website, Star Pubs & Bars Limited is the company responsible for processing your data and references to "we", "us" or "our" in this policy means Star Pubs & Bars Limited.
If you have any questions about this privacy notice or our processing activities, we can be contacted as follows:
It is important that you read this privacy notice together with our Cookie Policy and any terms of use that apply to the services or website which are presented to you. This privacy notice supplements the other notices and is not intended to override them.
2. HOW and WHAT personal data do we collect about you?
This privacy policy describes how we look after your personal data collected when you engage with us including when (i) you visit our Join Heineken, eazle by Heineken or eazle by Star Pubs & Bars websites; (ii) you purchase products or services from us; and (iii) we communicate with each other as part of our ongoing business relationship including where you contact us via our websites, email or telephone with an enquiry or complaint and where we send email or other communications to you ("Engagement").
We collect different categories of information which we have grouped together as follows:
We also collect, use and share Anonymised Data such as statistical or demographic data which is not reasonably likely to reveal your identity (directly or indirectly). For example, we may receive aggregated usage data detailing the percentage of users accessing a specific website. If we combine or connect Anonymised Data with other data so that it can directly or indirectly identify you, the combined data is 'personal data' which will be used in accordance with this privacy policy.
We do not knowingly:
3. WHY do we collect your personal data?
We collect the above categories of personal data about you for the following purposes (more specifically described in Annex 1):
4. What is our LAWFUL BASIS for collecting your personal data?
Under data protection laws, we must have a lawful basis under which we process your personal data. We will only use your personal data for the purposes set out in section 3, unless we reasonably consider that we have another appropriate reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the lawful basis which allows us to do so.
If you provide us with your consent to processing in connection with your use of our websites, you can withdraw it at any time and we will stop the processing activities that were based on consent as a lawful basis. Please note we may still process the data if we have another lawful basis for processing (in most instances, this will be for a more limited purpose e.g. back-up storage or to record a withdrawal).
Where we need to collect personal data due to a legal or regulatory obligation, or for performance of a contract, and you do not provide that data when requested, we may not be able to continue our Engagement with you or perform the contract we have or are trying to enter into with you (for example, to provide you with products or allow you to participate in competitions). We will notify you of this at the time.
Further information on the relevant purposes and linked lawful basis are set out in Annex 1.
5. WHO do we SHARE your personal data with?
We may share your personal data with the parties set out below:
Our external third parties may be based outside the UK or the EEA. Whenever we transfer your personal data out of the UK or the EEA, we ensure that the same level of protection is afforded to it by ensuring at least one of the following safeguards are put in place:
We have put in place reasonable security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know - they are subject to a duty of confidentiality. Unfortunately, no transmission of information over the internet can be completely secure, and the security of information depends in part on the security of the computer you use to communicate with us and the security you use to protect account information and passwords. Please, take care to protect this information.
Our website and the Wi-Fi services include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third party websites, plug-ins or applications and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website you visit and third party service/application that you use.
7. How LONG will my personal data be used for?
We will only retain your personal data to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, tax, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider any legal requirements, the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means. Criteria used to determine retention periods for specific data collected are detailed further in Annex 1.
8. What are my RIGHTS?
Under data protection laws, you have various rights which are set out below. The rights available to you depend on our reason for processing your personal data. You are not required to pay any charge for exercising your rights, although we may charge a reasonable fee if your request is unfounded, repetitive or excessive. We have one month to respond to you (unless you have made a number of requests or your request is complex, in which case we may take up to an extra two months to respond). Please note that, where we ask you for proof of identification, the one-month time limit does not begin until we have received this. If we require any clarification and/or further information on the scope of the request, the one-month deadline is paused until we receive that information.
You also have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk
We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance using the details at the start of this policy.
This version was last updated in August 2023.
Annex 1 – PURPOSES, OUR LAWFUL BASIS, RETENTION PERIODS
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest | Retention period |
Where you create an account on one of our websites. | Identity Contact | Performance of a contract with you. | For the duration of your contract with us and for 2 years after a period of inactivity. |
To process and respond to your interest in becoming a Heineken customer or a SmartDispense Customer or your application to add an additional outlet where you are already a customer of ours through our Join Heineken website. | Identity Contact | Performance of a contract with you. | Information submitted through our Join Heineken website will be deleted 6 months after your application is made. |
Where we perform a contract we have in place with you, including managing payments, fees and charges, and delivering the requested product or service. | Identity Contact Financial and Transactional | Performance of a contract with you. To perform our legal obligations. | After the duration of your contract with us has expired, our online sales records will be retained by us for 7 years or longer if required by tax or corporate bookkeeping. This data will be removed after a period of 2 years of inactivity on your account. |
To communicate with you and improve our products and services, which includes:
| Identity Contact Profile Technical and Usage Marketing and communications | Performance of a contract with you. Necessary for our legitimate interests (for running our business, in order to offer you a good service and to protect our business). Where required by privacy laws, consent. | Customer services will retain all information for 1 year after your question or complaint has been solved, or the inquiry was closed. If you no longer wish to receive marketing communications from us, you can unsubscribe at any time. We will remove your email address once you have opted-out, unless this is also used and retained for other purposes listed in this privacy notice. Survey feedback will be retained until it has fulfilled its intended purpose (Note: please see section 8 above “How LONG my personal data will be used for?” to learn more about the things we consider when determining how long we will retain your personal data). |
To maintain and optimise our websites which includes where we need to solve performance issues, including troubleshooting, testing, system maintenance, support, reporting and hosting of data, to improve the availability and functionality of the websites. | Identity Contact Profile Technical and Usage | Necessary for our legitimate interests to maintain the relevance of our brand and reputation, run our business, operate administration and IT services, protect network security and to prevent fraud). Necessary to comply with a legal obligation. | We retain information relating to the performance of our websites for 2 years. |
To conduct data analytics to improve our marketing strategies and customer relationships, so that we can issue relevant marketing content and offers and analyse email engagement. This includes:
See Annex 2 for more information on our marketing and profiling activities. | Identity Profile Marketing and Communications Technical and Usage Location | Consent | Data will be processed until an opt-out / objection is received or consent is withdrawn as applicable. The cookie policy on the relevant website provides more information on specific cookie retention periods. |
To administer and protect our business and our websites (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data). | Identity Contact Technical and Usage | Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise); Necessary to comply with a legal obligation. | 26 months from website visit. |
To enable you to partake in promotions and for prize fulfilment purposes, including:
geo-targeted activities (including gamification and SMS). | Identity Contact Financial and Transactional | Performance of a contract with you. | 6 months following prize fulfilment (in certain cases the retention period may be longer due to the nature of the prize e.g. flight tickets – in such cases the personal data will be deleted when it is no longer required). |
Marketing
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
We will only send direct electronic marketing (e.g. via emails or SMS) where:
You can ask us to stop sending you direct marketing messages at any time by contacting us at unsubscribe@heineken.co.uk. Where you opt out of receiving these marketing messages, we will no longer conduct direct electronic marketing unless you opt-in again at a later point. Please note that where we have another lawful basis for processing, we will continue to process personal data for other purposes – for example, we may process information provided to us in connection with an Engagement on the basis of contract necessity.
Profiling
We may use your Identity Data, Contact Data, Profile Data, Technical and Usage Data, Marketing and Communications Data and Location Data, to form a view on what we think you may want or what may be of interest to you and to understand your purchasing trends. These profiling activities inform how we decide which brands, products, services and offers may be relevant to you. By building a profile on you, we can send you tailored communications and make personalised recommendations, inform you of special offers we think you will be interested in and customise promotions & special offers that are most relevant to you. In more detail:
Please note that whilst we carry out the profiling activities described here, we do not carry out any automated decision-making processes which could have a legal or significant impact on you.