HEINEKEN EXPERIENCE PRIVACY POLICY

1 General

Heineken International B.V., located at Tweede Weteringplantsoen 21, 1017 ZD Amsterdam, the Netherlands (“HEINEKEN” or “we” or “us”) is the controller of the processing of all personal data collected through the website dedicated to the Heineken Experience (the “Website”). HEINEKEN respects your privacy and is committed to keeping your Personal Data secure and managing it in accordance with our legal responsibilities under applicable data protection laws. The HEINEKEN Experience is a tradename of Heineken International B.V.

Please read this Privacy Policy carefully as it contains important information to help you understand our practices regarding any personal information that you give to us or that we collect otherwise in the context of the Website (“Personal Data”).

2 What Personal Data We Collect and How We Use your Personal Data

You can use the majority of our Website without being required to provide any Personal Data to us. For certain services or activities you will need to provide Personal Data for us to be able to provide you the requested service or product or for you to participate in the activity. Requested information on the Website marked with an asterisk is mandatory. If you do not provide the requested information, we will not be able to deliver the service or product to you or you cannot participate in the activity. In addition to information you are required to provide to us in order to participate in activities/campaigns, we collect certain information when you visit our Website.

2.1 participation in campaigns, prize draws, contests

If you take part in contests or events, depending on the campaign, prize draw or contest you will be asked for your name, email address, home address, telephone number and answers to open questions in order to ‘win’. If needed to send you the prizes per regular mail (e.g. as for tickets or products), we will also ask for your physical address or we may ask other specific details needed to award your prize to you. We need this information to process your participation and to be able to communicate with you about your prize or to send the prizes to you. All information about your participation in our campaigns, prize draws and contests will be retained by us for a maximum period of 6 months after the end of the contest. The information will not be used for other purposes if you have not explicitly been informed about these purposes and/or have been asked for prior consent.

2.2 processing your Heineken Experience ticket,

to be able to process your payment, and to deliver the requested product or service to you; We need your age group, ticket data and timeslot, first and last name e-mail address, country of residence (optional), if you request wheelchair assistance (optional), your agreement to our terms of service and your payment completion. This is also for our sales administration. Please note that the booking of your Heineken Experience tickets will take place on the platform of our data processor partner Global Ticket.

The use of this Personal Data is to perform our agreement with you or to comply with legal obligations, such as tax and accounting rules. Our online sales records will be retained by us for 7 years or longer if required by tax or corporate bookkeeping.


2.3 processing your request to book meetings and events at the Heineken Experience premises

We need your company name, your name, phone number and e-mail address in order to contact you about your booking request. Once the event/meeting has been confirmed by the Heineken Experience team, we also collect the address of your company, details of the contact person, how many people will join the meeting/event, dietary wishes, invoice information.

2.4 participate in research activities.

We also may request you to participate in research activities such as: surveys, pilots, panels, focus groups, and other research activities. Depending on the research activity, we will collect different sets of Personal Data. You will always be informed prior to the research activity what Personal Data we will collect and for what purpose we will collect this Personal data. We will provide research activities either with your consent or because we have a legitimate interest, depending on the type and nature of the research activity.

2.5 information when you contact us

If you visit our Website and have a question or other remark, you can submit our Contact Form. You will be asked to provide your name and email address and obviously information about your request. We will only use this information to respond to your question. We will register your requests, questions and our responses and other actions to handle your request. We will retain all information for 6 months after your question or complaint has been solved or the inquiry was closed.

2.6 information about your visit to and use of our Website;

To the extent necessary for our legitimate interests and, if provided, to the extent allowed based on your optional consent, we collect certain information when you visit our Website, such as your IP address, which web pages you visit, device category, browser, and type of internet browser, clicks and views. The information about your use of our Website and services enables us to build segments, which are groups of website visitors or customers with a number of common characteristics such as age group, gender or region. If you provide your consent, we will likely add you to one of our segments. Segments are used by us to customize the Website and to e.g. change the order of search results or where we place certain offers so you are more likely to see these. We may also use segments to show online advertisements that we think are relevant for you and to send you commercial messages.

We use Personal Data as it is necessary in our legitimate interests to promote our products and services to our consumers and website visitors, to enable us to attract more consumers, to improve the sale of our products and services. We will retain the Personal Data for a maximum of 14 months.

2.7 receiving emails from Heineken Experience.

If you have booked a ticket or meeting/event via our Website, we may send you emails to inform you about your upcoming visit at the Heineken Experience premises. Furthermore, we may send you commercial emails about our Heineken Experience products/services or other similar services/products that we think may be of interest to you. If you have subscribed for receiving our emails, we use the email address you have provided to send you our newsletter. In all cases, if you no longer wish to receive any e-mails from us, you can unsubscribe at any time by using the unsubscribe function in each e-mail message or you can Contact Us.

The use of your Personal Data is to process your subscription, so to perform our agreement with you, or as it is in our legitimate interests to send our customers information about our products. We will remove your email address once you have opted-out of receiving the newsletter, unless this is also used and retained for other purposes listed in this Privacy Policy

2.8 personalized online marketing;

We may process and combine information about your online navigation (clicks and views), your interactions with us, your online purchases, your settings on our Website, your browser settings, your location, and your contact details. In addition, we may build a profile or your interests and matching this with your other online information (for example by using Facebook or Google Custom audience services) in order for us to use different channels for relationship management and marketing of our products and services to you via e-mail, direct mail, social media or online advertising which may include personalising marketing content and offers, in particular when we use data management platforms, so these are tailored to your preferences.

Where we are legally required to ask you for your prior consent, we will ensure we have obtained such consent. In all other cases, we use this Personal Data as it is necessary in our legitimate interests to be able to promote our products and services to our customers, to enable us to attract more customers, to improve the sale of our products. The Personal Data shall generally be deleted or anonymised 2 years after your last order on our Website, except where we are legally required to retain the Personal Data or where it is kept for any of the other purposes.

You can always opt-out of receiving personalized online marketing and you can always object to our use of your Personal Data for direct marketing purposes.

2.9 sharing of Personal Data with other HEINEKEN group affiliates and subsidiaries

As a member of a global business, we share Personal Data and cookie data with HEINEKEN group affiliates and subsidiaries for reasons as aggregated analytical and operational purposes and with the HEINEKEN organization in your country of residence for personalized online marketing purposes (as described in the paragraph 2.8), such as direct marketing, creating of consumer audiences or look-a-like audiences (to the extent permitted by local law), enriching of existing customer profiles and/or sending emails (as described in paragraph 2.7). This includes information about your visit to our Website as described in paragraph 2.6.

We will only share such Personal Data when we are allowed to do so by law. This means that we will ask for prior consent, if this should be the lawful basis (for example when we share ‘direct marketing’ data). When we are allowed to rely on our legitimate interest, we will do so. This is the case when we create aggregated marketing insights or segments.

2.10 maintenance and optimisation of our Website; Your Personal Data will also be used for maintenance and analysis of our Website to solve performance issues, to improve the availability and user experience. We log all use of our Website.

Our use of your Personal Data for these purposes is necessary in our legitimate interests and the information will be retained for a maximum period of 14 months. The logs of the use of our Website will be deleted within 14 months after creation.

3 How We Share Your Personal Data

We may need to share Personal Data with third parties to help us provide services and products to you and to run our Website. These third parties are:

  • HEINEKEN group companies for the purpose of storing Personal Data processed via the Website, due to shared IT systems;
  • The HEINEKEN organization in your country of residence in case you have provided your country of residency and your consent to sharing your Personal Data with your local HEINEKEN organization;
  • Service providers where this is needed to provide us with a service and to provide data analytics services;
  • Prize fulfilment agencies;
  • Data management platform provider, Relay42, who provides marketing strategy services;
  • Global Ticket B.V. provides our online ticketing platform;
  • Service providers that help us organize campaigns and promotions;
  • First and Third party advertising companies;
  • Media agencies for marketing purposes and research purposes;
  • Third party providers of Social Media Platforms (including Facebook and Google);
  • Service providers such as solicitors and accountants;
  • Payment service providers;
  • Courts, parties to litigation and their professional advisers where we reasonably deem it necessary in connection with the establishment, exercise or defence of legal claims; and
  • A purchaser or parties interested in purchasing any part of our business.

These parties may be located in the European Union or other countries in the European Economic Area or elsewhere in the world. When Personal Data is stored by us outside the EEA we will ensure an adequate level of protection of the transferred Data. We require service providers to use appropriate measures to protect the confidentiality and security of the Personal Data.

4 Security of Personal Data

We will take appropriate technical, physical and organizational measures to protect the Personal Data collected through the Website from misuse or accidental, unlawful or unauthorized destruction, loss, alteration, disclosure, acquisition or access, that are consistent with applicable privacy and data security laws and regulations. However, no internet-based site can be 100% secure and we cannot be held responsible for unauthorised or unintended access that is beyond our control. Our Website may contain links to other websites. We are not responsible for the privacy practices, content or security used by such other websites, which shall not be governed by this Privacy Policy. We advise you to always carefully read the privacy policies on these other websites.

5 Retention of Your Personal Data

We will retain your Personal Data for as long as legally required or for as long as necessary to provide you with any requested services or for any of the other purposes listed in this Privacy Policy. The specific retention term are listed in this Privacy Policy for each of the relevant purposes. We will take reasonable steps to destroy or de-identify Personal Data we hold if it is no longer needed for the purposes set out above or after the expiration of the defined retention term.

6 Cookies

A major part of the information referred to in this Privacy Policy is collected via our use of cookies and similar techniques. Cookies are small text files containing small amounts of information which are downloaded and may be stored on your user device, e.g. your computer, smartphone or table. Techniques we use that may be similar to cookies are tracking pixels, Java scripts, tags and web beacons. These cookies and similar techniques are sometimes necessary to remember your account settings, language and country, but also enable us to measure and analyse your behaviour on our Website and for showing you personalised advertisements on our Website or on third party websites. Where required, you will be asked for consent to our use of cookies. To view more information on what cookies we use and how we use them please review our separate Cookie Policy in the footer of this Website.

7 Social Media

You may choose to share information on our Website via social media, such as Facebook, Instagram, Tripadvisor, Twitter, LinkedIn and YouTube. This means that the information you share, with name and preferences, shall be visible to visitors of your personal pages. We advise you to carefully read the privacy policies of the social media parties as these are applicable to the processing of your Personal Data by these parties.

8 Children's Privacy

The Website is not intended for use by individuals under the age of 18 (or the applicable legal age for consuming the products in question). We do not knowingly collect Personal Data from individuals under the age of 18.

9 Your Rights to Access, Rectification, Deletion, Restriction and Data Portability

You have the right to request an overview of your Personal Data processed by or on behalf of us. You have the right to have your Data rectified, deleted or restricted (as appropriate). You can exercise this right by contacting this webform with a data privacy request. Please note that requests that do not meet the requirements set out by applicable law or HEINEKEN guidelines may be requested to be re-issued or ultimately denied and that certain Personal Data may be exempt from such access, rectification and deletion requests pursuant to applicable data protection laws or other laws and regulations. Please note that you can also delete Personal Data by de-activating your user, however we will retain Personal Data where it is legally required for us to do so, which applies e.g. to sales administration.

You have the right to receive the Personal Data that you have provided to us in a structured, commonly used and machine-readable format, and in certain circumstances we will, at your request, transmit your Data to another controller where this is technically feasible.

10 Your Right to Object

You also have a right, in certain circumstances, to require us to stop processing your Personal Data, but where we have compelling legitimate grounds, we will continue processing your Personal Data. However, you have the right to object to our use of your Personal Data for direct marketing purposes, including profiling, and when you do so, we will accommodate your request. Where you have provided consent to our use of your Personal Data, you have the right to withdraw your consent without this effecting the lawfulness of our use of this Data before your withdrawal by sending an email to service.experience@heineken.com.

11 Updates

We will keep this Privacy Policy under review and make updates from time to time. Any changes to this Privacy Policy will be posted on our Website page and to the extent reasonably possible, will be communicated to you.

12 Contact

If you have any other question, objection to our use of your Personal Data or a complaint about this Privacy Policy or about our handling of your Personal Data, please contact us via this webformhttps://www.theheinekencompany.com/data-privacy-request-form with a data privacy request. You also have the right to file a complaint with your local data protection authority.

This version was last updated in July 2020.