This privacy notice describes how we collect and use personal information about you in accordance with the General Data Protection Regulation (GDPR). It contains important information on how and why we collect, store, use and share personal information, your rights in relation to your personal information and on how to contact us and supervisory authorities in the event you have a complaint.
We may collect, use and are responsible for certain personal information. When we do so, we are regulated under the GDPR which applies across the European Union (including in the UK) and we are responsible as ‘controller’ of that personal information for the purposes of those laws.
What information is collected: Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). On our websites we collect and use personal information (including name, address, telephone number and email) in order to:
-
Respond to queries or requests submitted by you
-
Process orders or applications submitted by you
-
Administer or otherwise carry out our obligations in relation to any agreement you have with us
-
Anticipate and resolve problems with any services supplied to you
Information collected from other sources: We also collect cookies on our site for performance related tasks. We may collect information to analyze the performance of our websites and how different parts of our website are used with Google Analytics.
Google Analytics stores information about how users get to our sites and from which device types, how content is being used whilst on the site and how long users spend on our site. Google Analytics also provides information on interests and demographics of our visitors. The information is collected using a tag placed on our websites and does not relate to any personally identifiable information being collected.
If you want to opt out of Google Analytics collection you can install a browser add on. If you wish to opt out of data collection for demographic and interest data you can do this using Google Ad Settings.
Sharing of personal information: We may share personal information with other Vector Group businesses as appropriate in order to respond to your queries or requests. We may share personal information with law enforcement or other authorities if required by applicable law.
We will not share your personal information with any other third party and we will only provide your personal information which we consider is necessary for the performance of that reason.
Consent: We do not need your consent if we use special categories of your personal information in accordance with our written policy to carry out our legal obligations. In limited circumstances, we may approach you for your written consent to allow us to process certain particularly sensitive data. If we do so, we will provide you with full details of information that we would like and the reason we need it, so that you can carefully consider whether you wish to consent.
Length personal information is kept: We will only retain your personal information for as long as necessary to fulfill the purposes we collected it for, including the purposes of satisfying any legal, accounting, or reporting requirements. We will hold personal data for the period we are required to retain this information by applicable tax law. In some circumstances we may anonymize your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.
The Vector Group has agreed to retain the information collected in Google Analytics indefinitely in order to allow us to analyze trends in our website usage over time. This is not personally identifiable information.
Transfer of information out of the EEA: We may transfer your personal information to other Vector Group businesses which are located outside the European Economic Area (EEA) in order to respond to any queries submitted to us via our website or social channels.
Rights: Under the GDPR you have a number of important rights free of charge. Under certain circumstances, you have the right to:
-
Request access to your personal information and to certain other supplementary information that this Privacy Notice is already designed to address.
-
Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
-
Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
-
Object to processing of your personal information where we are processing your personal information for direct marketing purposes.
-
Object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you.
-
Object in certain other situations to our continued processing of your personal information.
-
Request the transfer of your personal information to another party.
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals’ rights under the General Data Protection Regulation which is accessible via https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/
If you would like to exercise any of those rights, please email: dataprotection(at)vector-risk.com
In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time.
To withdraw your consent, please contact dataprotection(at)vector-risk.com. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
Keeping personal information secure: We have appropriate security measures in place to prevent personal information from being accidentally lost or used or accessed in an unauthorized way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorized manner and are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Data Protection Officer: A Data Protection Officer (DPO) will oversee compliance with this privacy notice. If you have any questions about this privacy notice or how we handle your personal information, please contact the DPO by emailing dataprotection(at)vector-risk.com
Changes to this privacy notice: This privacy notice was published in January 2019. We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice.
How to contact us: Please contact dataprotection(at)vector-risk.com if you have any questions about this privacy notice.