PMI CONSUMER PRIVACY NOTICE

We take privacy seriously. This notice tells you who we are, what information we collect about you, and what we do with it. We will use information about you only in accordance with applicable data protection laws.

Please also read our terms of use for the service you are interested in. They contain more details about the way we do business and any restrictions that may apply.

Who are we?

We are a member of Philip Morris International. Our details (name, address, etc.) will have been given to you separately at the time of (or to confirm) the collection of information about you, for example, in a notice on an app or a website, or in an e-mail, containing a link to this notice.

Find out more…
•   PMI: Philip Morris International, a leading international tobacco group. It is made up of a number of companies or “affiliates”.
•   PMI affiliates: Each member of the Philip Morris International group of companies is a “PMI affiliate”. “We” (or “us” or “our”) refers to the PMI affiliate that first collected information about you and who, in accordance with data protection law, are the associated controllers and/or operators of personal data, depending on the purposes for which the data is processed.
•   PMI product: means a product of ours or of another PMI affiliate.

How do we collect information about you?

We may collect information about you in various ways.
•   You may provide us with information directly (e.g. filling in a form, or making a call to us).
•   We may collect information automatically, electronically (e.g. when you use a PMI app or website).
•   We may acquire information from third parties (e.g. publicly-available information on social media platforms such as Facebook and Twitter).

In this notice, we refer to all the methods by which you are in contact with us as “PMI touchpoints”. PMI touchpoints include both physical (for example, retail outlets and events), and digital (for example, apps and websites).

Find out more…
We may collect information that you provide directly. Typically, this will happen when you:
•   sign up to be a member of our databases (this could be, for example, in person, via app, or online);
•   purchase PMI products or services at a retail outlet;
•   download, or use, a digital touchpoint (e.g. an app or a website);
•   contact us through a touchpoint, or by e-mail, social media or telephone;
•   register a device with us;
•   subscribe to a PMI panel portal;
•   register to receive PMI press releases, e-mail alerts, or marketing communications;
•   participate in PMI surveys or (where permitted by law) PMI competitions or promotions; or
•   attend an event that a PMI affiliate has organized.

We may collect information about you automatically. Typically, this will happen when you:
•   visit an outlet that sells PMI products (e.g. by collecting your data at check-out, or through sensors at the outlet that connect with mobile technology);
•   attend an event that a PMI affiliate has organized (e.g. through purchases at the event or through sensors at the event that connect with mobile technology);
•   communicate with us (for example, through a touchpoint; or social media platforms);
•   use PMI touchpoints (e.g. through tracking mechanisms in an app or a website); or
•   make public posts on social media platforms that we follow (for example, so that we can understand public opinion, or respond to requests concerning PMI products).

We may also collect information about you automatically through the use of cookies and similar tracking technologies on digital PMI touchpoints. The specific cookies and technologies used will depend on the PMI touchpoint in question. To learn about the cookies (including Google analytics cookies) and similar technologies used on a touchpoint, including how you can accept or refuse cookies, please see the cookie notice made available on or through that touchpoint. For example, to learn about cookies and similar technologies used on www.pmi.com, visit the pmi.com cookie notice link at the bottom of every page on the site. The pmi.com cookie notice is also available here.

We may also collect information in other contexts made apparent to you at the time.

What information about you do we collect?

We may collect various types of information about you:
•   information needed to fulfill your product reservation request at md.iqos.com;
•   information necessary to provide warranty services;
•   information you give us in forms or surveys;
•   information about your visits to our outlets and events;
•   information you give us in calls you make to call center;
•   information about your preferences and interests;
•   information necessary to verify your age

Find out more…
Information that we collect from you directly will be apparent from the context in which you provide it. For example:
•   when reserving products from us through a touchpoint, you provide your name, contact, and the products you have chosen so that we can handle your request;
•   you may provide information on your product preferences and interests so that we can offer you products and services that will interest you;
•   if you make an appointment to see us (or someone supporting our products or services), we may collect your name and contact details;
•   we may collect information that enables us to verify your age, for example presentation of an identity document.

Information that we collect automatically will generally concern:
•   details of your visit or call (such as time and duration);
•   in a sales outlet, how frequently you visit, and for how long, and which purchases you make;
•   your use of digital PMI touchpoints (such as the pages you visit, the page from which you came, and the page to which you went when you left, search terms entered, or links clicked within the touchpoint); and
•   your device (such as your IP address or unique device identifier, location data, details of any cookies that we may have stored on your device).

For what purposes do we use information about you, and on what legal basis?


Subject to the above, we use information about you for the following purposes:
•   To comply with regulatory obligations, such as verifying your age and status as a user of our products;
•   To process your product reservation request through the md.iqos.com website directly;
•   To sell products, including fulfilling your requests and processing payments in a physical store that sells PMI products;
•   To provide sales-related services to you, including dealing with your inquiries and requests, and providing warranty services;
•   To market our products (where permitted by law), including administering loyalty programs, product improvement, market research, developing marketing strategies, administering marketing campaigns, and customizing your experiences at outlets that sell PMI products;
•   To support all the above, including administering your accounts, enabling you to use PMI touchpoints, corresponding with you, managing your appointments with us or with someone supporting our products or services (for example, regarding a new product, or after-sales service), customizing your experiences of PMI touchpoints, and administration and troubleshooting;
•   For business analytics and improvements, including improving PMI products, outlets and events, and the information that we (or our affiliates) provide to our customers;
•   For other purposes that we notify you of, or will be clear from the context, at the point information about you is first collected.

The legal basis for our use of information about you is one of the following (which we explain in more detail in the “find out more” section):
•   compliance with a legal obligation to which we are subject;
•   the performance of a contract to which you are a party;
•   a legitimate business interest that is not overridden by interests you have to protect the information;
•   where none of the above applies, or where law requires it, your consent (which we will ask for before we process the information).

Find out more…
The purposes for which we use information about you, with corresponding methods of collection and legal basis for use, are:


Purpose Method of collection and legal basis for Processing
Comply with regulatory obligations
•   verify your age and status as a user of our products
This information is generally provided to us by you directly.

We use it because it is necessary for us to comply with a legal obligation to sell products only to adults, or, in countries where there is no such legal obligation, because we have a legitimate business interest to sell our products only to adults that is not overridden by your interests, rights and freedoms to protect information about you.
Provision of services related to reservations
•   deal with your inquiries and requests;
•   correspond with you;
•   general administration and troubleshooting;
This information is generally provided to us by you directly.

We use it because we have a legitimate business interest in providing sales-related services to our customers that is not overridden by your interests, rights and freedoms to protect information about you.
Market our products (in a physical store)
•   understand your preferences (such as what products or events may interest you or may be better tailored to your needs) and, where permitted by law, market to you personally;
•   invite you to participate in, and administer, surveys or market research campaigns;
•   for market research;
•   develop marketing strategies;
•   administer marketing campaigns;
•   customize your experience of PMI touchpoints (for example, to personalize your visit, such as with greetings or suggestions that might interest you).
This will typically be a combination of information that you provide to us (for example, your name and contact and social media details); information that we collect automatically (for example, using technology to monitor use of PMI touchpoints) and (where permitted by law) information that we acquire from third parties (such as public social media posts).

We use it on the grounds that we have a legitimate business interest to market our products, to operate PMI touchpoints, and to customize your experiences, in these ways that is not overridden by your interests, rights and freedoms to protect information about you.
Market our products (where permitted by law)
•   provide you with information about, and to manage, PMI affiliates, their promotions, products and services, outlets, events and the regulation of our products; and to develop and improve tools to pursue these purposes.
This will typically be a combination of information that you provide to us (for example, your name and contact details, your social media handles); information that we collect automatically (for example, using cookies and similar technologies) and (where permitted by law) information that we acquire from third parties (such as public social media posts).

We use it on the grounds that we have a legitimate business interest to market these things that is not overridden by your interests, rights and freedoms to protect information about you.

In certain countries, where required by law, we will send you these materials in electronic format only with your consent.
Support for all the above purposes
•   administering your accounts;
•   enabling you to use PMI touchpoints (for example, allowing you to remain logged in to sections of a touchpoint that are reserved for authorized users only, administering your language preference, associating your shopping cart with you);
•   corresponding with you;
•   managing your appointments with us or with someone supporting our products or services (for example, regarding a new product, or after-sales service);
•   enhancing your experiences;
•   administration and troubleshooting.
This will typically be a combination of information that you provide to us (typically, name, password (or equivalent)) and information that we collect automatically (for example, information about your device, and cookies and similar tracking technologies).

We use it on the grounds that correspond to the purpose for using the information that we are supporting. For example, where we administer your account to support a purchase or to provide after-sales service, we use the information to discharge our contractual obligations to you as a buyer of our products; where we administer your account to show you our products, we are supporting marketing and so we use it on the grounds that we have a legitimate business interest to market our products that is not overridden by your interests, rights and freedoms to protect information about you, and so on.
Business analytics and improvements
•   allowing us or our business partners to inform you of potential opportunities to get involved in promoting PMI products;
•   for business analytics and improvements (including for PMI products, outlets that sell PMI products, events, digital PMI touchpoints and the information that we (or our affiliates) provide to our customers).
This will typically be a combination of information that you provide to us; information that we collect automatically; and (where permitted by law) information that we acquire from third parties.

We use it on the grounds that we have a legitimate business interest to analyse and to improve our business performance, our products, PMI touchpoints, outlets and events, and to invite others to get involved in promoting PMI products, that is not overridden by interests, rights and freedoms to protect information about you.
Where we do not base our use of information about you on one of the above legal bases, or where law requires it, we will ask for your consent before we process the information (these cases will be clear from the context).

In some instances, we may use information about you in ways that are not described above. Where this is the case, we will provide a supplemental privacy notice that explains such use. You should read any supplemental notice in conjunction with this notice.

Who do we share your information with, and for what purposes?

We may share information about you with:
•   PMI affiliates;
•   third parties who provide PMI affiliates or you with products or services;
•   PMI affiliates’ carefully selected business partners and advertisers (in areas connected with our products, or consistent with their style and image) so that they can contact you with offers that they think may interest you, in accordance with your preferences; and
•   other third parties, where required or permitted by law.
We share information about you with others only in accordance with applicable laws. Thus, where law requires your consent, we will first ask for it.

Find out more…

Sharing data with other PMI affiliates

•   Information about you will be shared with Philip Morris Products S.A. (based in Neuchâtel, Switzerland - The country that provides an adequate level of protection of personal data in accordance with Article 32 of Law № 133/2011 on the protection of personal data), which is the place of central administration of personal data processing for PMI affiliates. Philip Morris Products S.A. processes the information about you for all the purposes described in this notice

•   Information about you may be shared with the PMI affiliate that is responsible for the country in which you live (if it wasn’t the PMI affiliate that first collected the information) for all the purposes described in this notice.

•   Information about you may be shared with any other PMI affiliate that you contact (for example, if you travel and you want to know where to buy PMI products in a new country, or where to find service or support for PMI products) in order to enhance our service to you.

Details of PMI affiliates and the countries in which they are established are available here.

Sharing data with Third Parties
•   To the extent permitted by applicable law, we may share information about you with third parties who provide PMI affiliates or you with products or services (such as advisers, payment service providers, delivery providers, retailers, product coaches, information services providers and age verification providers).
•   To the extent permitted by applicable law, we may share information about you with PMI affiliates’ carefully-selected third party business partners and advertisers (in line with the kind of thing you might associate with our products, for example because they have similar or complementary image, style, or functionality) so that they can contact you with products, services that they think may interest you, in accordance with your preferences.
•   We may share information about you with other third parties, where required or permitted by law, for example: regulatory authorities; government departments; in response to a request from law enforcement authorities or other government officials; when we consider disclosure to be necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual illegal activity; and in the context of organizational restructuring.

Where might information about you be sent?

As with any multinational organization, PMI affiliates transfer information globally. Accordingly, information about you may be transferred globally (for example, if you are in the European Economic Area (“EEA”), your information may be transferred outside the EEA, in accordance with the requirements of the current legislation of the Republic of Moldova.

Find out more…
If information about you is used as described in this notice, it may be transferred both within the country or territory where it was collected and outside of it, including to a country or territory where the relevant data protection standards may not apply, provided that the requirements of applicable Moldovan law are met. When using information as described in this notice, information about you may be transferred either within or outside the country or territory where it was collected, including to a country or territory that may not have equivalent data protection standards.

For example, PMI affiliates within the EEA may transfer personal information to PMI affiliates outside the EEA. In all such cases, the transfer will be:
•   a European Commission adequacy decision or to the National Center for Personal Data Protection;
•   subject to appropriate safeguards, for example the EU Model Contracts or contracts approved by the National Center for Personal Data Protection;
•   necessary to discharge obligations under a contract between you and us (or the implementation of pre-contractual measures taken at your request) or for the conclusion or performance of a contract concluded in your interest between us and a third party, such as in relation to travel arrangements.

In all cases, appropriate security measures for the protection of personal information will be applied to protect personal information in accordance with the current legislation of the Republic of Moldova on the protection of personal data.

How do we protect information about you?

We implement appropriate technical and organisational measures to protect personal information that we hold from unauthorised disclosure, use, alteration or destruction. Where appropriate, we use encryption and other technologies that can assist in securing the information you provide. We also require our service providers to comply with strict data privacy and security requirements.

How long will information about you be kept?

We will retain information about you for the period necessary to fulfil the purposes for which the information was collected. After that, we will delete it. The period will vary depending on the purposes for which the information was collected. Note that in some circumstances, you have the right to request us to delete the information. Also, we are sometimes legally obliged to retain the information, for example, for tax and accounting purposes.

Find out more…
Typically, we retain data based on the criteria described in the table below:


Type Explanation/typical retention criteria
•   marketing to you (including marketing communications) (if you use digital touchpoints and are contactable) Most of the information in your marketing profile is kept for the duration of our marketing relationship with you; for example, while you continue to use digital touchpoints, or respond to our communications. However, some elements of your marketing profile, such as records of how we interact with you, naturally go out of date after a period of time, so we delete them automatically after defined periods (typically 3 years) as appropriate for the purpose for which we collected them.
•   marketing to you (including marketing communications) (if you are no longer in contact with us); This scenario is the same as the above, but if we don’t have any contact with you for a long period (typically 2 years), we will stop sending you marketing communications and delete your history of responses to them. This will happen, for example, if you never log on to a digital touchpoint, or contact customer care, during that time. The reason is that in these circumstances, we assume you would prefer not to receive the communications.
•   marketing to you (including marketing communications) (if you are not contactable); If you have registered to receive marketing communications, but the information you give us to contact you doesn’t work, we will retain your details for a period of typically only 6 months to allow you to return and correct it.
•   marketing to you (including marketing communications) (incomplete registrations); If you commence registering yourself in a database, but do not complete the process (for example, if you don’t complete the age verification process, or you don’t accept the touchpoint’s terms of use), we will retain your details for only 6 months to allow you to return and complete the process.
•   market research; If you are not registered with us for other purposes (e.g. marketing communications, warranty, customer care), and we use publicly available information about you in order to understand the market or your preferences, we will retain the information about you for a short period in order to perform the particular item of market research.
•   purchases and warranty; If you purchase goods, we will retain details of this for so long as required to complete the sale, and to comply with any legal obligations (for example, for tax and accounting record-keeping purposes). If you also register for a warranty for a device, we will retain details of this for so long as relevant to the warranty.
•   customer care; If you contact customer care, we will make a record of the matter (including details of your enquiry and our response) and retain it while it remains relevant to our relationship, for example if you need us to replace a device under warranty, or if your recent enquiries are relevant. Temporary records (for example, an automated recording of a telephone call in which you ask us to direct you to a retail outlet) may be relevant only until more permanent records are made, and will be retained only temporarily.
•   system audit logs; System audit logs are retained typically for a period of only a few months.
•   business analytics; Business analytics data is typically collected automatically when you use PMI touchpoints and anonymised/aggregated shortly afterwards.

What rights and options do you have?

You may have some or all of the following rights in respect of information about you that we hold:
•   request us to give you access to it;
•   request us to rectify it, update it, or erase it;
•   request us to restrict our using it, in certain circumstances;
•   object to our using it, in certain circumstances;
•   withdraw your consent to our using it;
•   data portability, in certain circumstances;
•   opt out from our using it for direct marketing; and
•   to request information and explanations on the processing and protection of personal data provided by the data controller, contacting the person responsible for personal data protection, the company ,,Law, Privacy & Data Protection Services" SRL, IDNO 1018600008466, which can be contacted at office@gdpr.md
•   opt out from our using it for direct marketing; and •   lodge a complaint with the supervisory authority to the National Center for Personal Data Protection MD-2004, Republic of Moldova, mun. Chisinau, 48 Sergia Lazo Str., Tel: +373-22-820801, fax: +373-22-820807, e-mail: centru@datepersonale.md

We offer you easy ways to exercise these rights, such as “unsubscribe” links, or giving you a contact address, in messages you receive.

Some of the communication channels we offer might also send you push messages, for instance about new products or services. You can disable these messages through the settings in your phone or the application.

Find out more…
The rights you have depend on the laws of your country. If you are in the European Economic Area, you will have the rights set out in the table below. If you are elsewhere, you can contact us (see the paragraph “who should you contact with questions?” at the end of this notice) to find out more.


Right in respect of the information about you that we hold Further detail (note: certain legal limits to all these rights apply)
•   to request us to give you access to it This is confirmation of:
•   whether or not we process information about you;
•   our name and contact details;
•   the purpose of the processing;
•   the categories of information concerned;
•   the categories of persons with whom we share the information and, where any person is outside the EEA and does not benefit from a European Commission adequacy decision ;
•   the appropriate safeguards for protecting the information;
•   (if we have it) the source of the information, if we did not collect it from you;
•   (to the extent we do any, which will have been brought to your attention) the existence of automated decision-making, including profiling, that produces legal effects concerning you, or significantly affects you in a similar way, and information about the logic involved, as well as the significance and the envisaged consequences of such processing for you; and
•   the criteria for determining the period for which we will store the information.

On your request we will provide you with a copy of the information about you that we use (provided this does not affect the rights and freedoms of others).
•   to request us to rectify or update it This applies if the information we hold is inaccurate or incomplete.
•   to request us to erase it This applies if:
•   the information we hold is no longer necessary in relation to the purposes for which we use it;
•   we use the information on the basis of your consent and you withdraw your consent (in this case, we will remember not to contact you again, unless you tell us you want us to delete all information about you in which case we will respect your wishes);
•   we use the information on the basis of legitimate interest and we find that, following your objection, we do not have an overriding interest in continuing to use it; •   the information was unlawfully obtained or used; or;
•   to comply with a legal obligation.
•   to request us to restrict our processing of it This right applies, only to processing operations that are subject to the General Data Protection Regulation (No. 679/2016 EU - GDPR), temporarily, while we review your case, if you:
•   contest the accuracy of the information we use; or
•   have objected to our using the information on the basis of legitimate interest (if you make use of your right in these cases, we will tell you before we use the information again).
This right applies also if:
•   our use is unlawful and you oppose the erasure of the data; or
•   we no longer need the data, but you require it to establish a legal case.
•   to object to our processing it You have two rights here:
(i)   if we use information about you for direct marketing: you can “opt out” (without the need to justify it) and we will comply with your request; and
(ii)   if we use the information about you on the basis of legitimate interest for purposes other than direct marketing, you can object to our using it for those purposes, giving an explanation of your particular situation, and we will consider your objection.
•   to withdraw your consent to our using it This applies if the legal basis on which we use the information about you is consent. These cases will be clear from the context.
•   to data portability If the processing falls under the General Data Protection Regulation (No. 679/2016 EU - GDPR):
(i)   you have provided data to us; and
(ii)   we use that data, by automated means, and on the basis either of your consent, or on the basis of discharging our contractual obligations to you, then you have the right to receive the data back from us in a commonly used format, and the right to require us to transmit the data to someone else if it is technically feasible for us to do so.
•   to lodge a complaint with the supervisory authority in your country From the Republic of Moldova
National Center for Personal Data Protection MD-2004, Republic of Moldova, mun. Chisinau, 48 Sergheia Lazo str., tel: +373-22-820801, fax: +373-22-820807, e-mail: centru@datepersonale.md

From the European Union
Each European Economic Area country must provide for one or more public authorities for this purpose.
You can find their contact details here:
http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm


Country-specific additional points

According to which country you are in, you may have some additional rights.

Who should you contact with questions?
If you have any questions or you wish to exercise any of your rights, you can find the contact details of the relevant PMI branches and contact the person in charge of personal data protection, the company ,,Law, Privacy & Data Protection Services" SRL, IDNO 1018600008466, which can be contacted at office@gdpr.md.

If your country has a data protection authority, you have a right to contact it with any questions or concerns. If the relevant PMI affiliate cannot resolve your questions or concerns, you also have the right to seek judicial remedy before a national court.

Changes to this notice

Notice published on 22 May 2018. Last modified 17 May 2022. You can find previous versions of this notice here.