HEINEKEN EXPERIENCE PRIVACY POLICY
1 General
This Privacy Policy applies to the processing of all personal data collected through (i) visiting the Heineken Experience website and use of the services offered thereon (the “HEX Website”), and (ii) visiting the Heineken Experience premises (the “HEX”). The HEX is an interactive, museum-like attraction located in the original Heineken brewery in the heart of Amsterdam, and the ‘Heineken Experience’ is a tradename of HEINEKEN International B.V. (“HEINEKEN” or “we” or “us”).
HEINEKEN, located at Tweede Weteringplantsoen 21, 1017 ZD Amsterdam, the Netherlands is the controller of the processing of all personal data collected through the HEX Website and the HEX. HEINEKEN respects your privacy and is committed to keeping your Personal Data secure and managing it in accordance with our legal responsibilities under applicable data protection laws.
Please read this Privacy Policy carefully as it contains important information to help you understand our practices regarding any personal information that you share with us, or that we collect otherwise when you visit or use the HEX Website or HEX (“Personal Data”).
2 What Personal Data We Collect and How We Use your Personal Data
For certain services or activities on or relating to the HEX Website and HEX, you will need to share Personal Data with us to enable us to provide you the requested service or product, or for you to participate in the activity. Requested Personal Data on the HEX Website marked with an asterisk is mandatory. In addition to Personal Data, you are required to share with us, we collect certain information (that may include Personal Data) when you visit our HEX Website.
We have specified the Personal Data we collect, the purposes for which we use the Personal Data, the legal bases we use to collect this Personal Data, and how long we will retain your Personal Data:
1 Participation in Promotional Activity
If you participate in contests or events, and depending on the campaign, prize draw, or contest (a “Promotional Activity”), you will be asked for your name, email address, home address, telephone number, and answers to open questions in order to ‘win’. If we need to send you a prize per regular mail, we will ask you to share a postal address and any other specific details we required to send you your prize. We need this Personal Data to process your participation and to be able to communicate with you about your prize, and to send the prize to you. The Personal Data relating to your participation in a Promotional Activity is collected for the performance of a contract with you and will be retained by us for a maximum period of 6 months after the end of the Promotional Activity.
2 Processing the purchase and delivery of a HEX Ticket
In order for us to process your payment, and to deliver the ticket(s) you have ordered, both for visits and tours (“HEX Ticket”)we, will ask you to share your age group (optional), visit or tour date and timeslot, first and last name e-mail address, country of residence, if you require wheelchair assistance (optional), and your payment information. The Personal Data relating to your HEX Ticket order is based on the performance of a contract with you, and for us to comply with legal (e.g., tax and accounting) obligations, and will be retained by us for a maximum period of 7 years after the date of purchase.
3 Processing a meeting or event booking (request) at the HEX
When you make a meeting or event booking request, we will require your company name, your first and last name, phone number and e-mail address. Once the Heineken Experience has confirmed your booking request, we additionally require you to share the address of your company, how many people will join the meeting/event, dietary wishes, and invoice and payment information. The Personal Data relating to your meeting or event booking (request) is collected based on the performance of a contract with you, and for us to comply with legal (e.g., tax and accounting) obligations, and will be retained by us for a period of two years after the date of the meeting or event.
4 Customer Service
If you visit our HEX Website and have a question or other remark, you can either email or call us (“Customer Service”). If you do, you will be asked to provide your name and email address . We will only use this Personal Data to contact you and respond to your question or remark. The Personal Data relating to your question or remark, including the content of your question or remark, is collected based on the performance of a contract with you, and will be retained by us for a period of one year after your question or complaint has been solved, or the inquiry was closed.
6 Information about your visit and use of the HEX Website
When you visit the HEX Website we collect certain information, such as your IP address, which web pages you visit, device category, browser, and type of internet browser, clicks and views. This information is collected via cookies and similar technologies and enables us to build so-called segments, which are groups of website visitors or customers with a number of common characteristics such as age group, gender, or region. Some of this information is considered Personal Data and requires your prior consent. If you consent to us collecting this Personal Data, we will add you to one of our segments.
7 Receiving emails from the HEX
If you have booked a ticket, meeting or event via the HEX Website, we will send you service emails to inform you about your upcoming visit at the Heineken Experience (“Service Emails”).
If you have consented to receiving commercial e-mails about our Heineken Experience products or services, we will send you direct marketing e-mails (“DM Emails”). We collect your email-address for the purposes of (i) Service Emails based on the performance of a contract with you, and (ii) DM Emails based on your explicit consent. For Service Emails, your email-address will be retained by us for a period of [x months] after your visit, meeting or event. For DM Emails your email-address will be retained by us for a maximum period of 2 years after your last interaction (e.g., visit, meeting/event booking, purchase) with the Heineken Experience. You can unsubscribe from DM Emails at any time by using the unsubscribe function in each DM Email, or you can contact us at phone number +31 (0)202050593 and/or email address service.experience@heineken.com.
8 Personalized online marketing
We collect and combine information about your online navigation via the use of cookies and similar technologies. We collect information about online clicks and views on the HEX Website, your interactions with us, your online purchases and ticket purchases, your settings on the HEX Website, your browser settings, your location. In addition, we build a profile or your interests and match this with your other online information (for example by using Facebook or Google Custom audience services) to use different channels for relationship management and marketing of our products and services. These include personalised email, direct mail, social media or online advertising.
Some of the aforementioned information is considered Personal Data. We collect this Personal Data based on our legitimate interest, or (where legally required) based on your prior explicit consent. The Personal Data shall generally be deleted or anonymised 2 years maximum period of 2 years after your last interaction (e.g., visit, meeting/event booking, purchase) with the Heineken Experience. For more information please also see our Cookie Policy.
You can always opt-out of receiving personalized online marketing and you can always object to our use of your Personal Data for direct marketing purposes.
9 Sharing Personal Data within the HEINEKEN group
As a member of a global business, we share Personal Data and cookie data with HEINEKEN group affiliates and subsidiaries in your country of residence for (i) aggregated analytical and operational purposes (ii) personalized online marketing purposes, including direct marketing, creating of consumer audiences or look-a-like audiences (to the extent permitted by local law) and enrichment of existing customer profiles (as described in the paragraphs 2.7 and 2.8).
We share your Personal Data based on our legitimate interest, or (where legally required) based on your prior explicit consent.
10 maintenance and optimisation of our Website;
Your Personal Data will also be used for maintenance and analysis of our Website to solve performance issues, to improve the availability and user experience. We log all use of our Website.
Our use of your Personal Data for these purposes is necessary in our legitimate interests and the information will be retained for a maximum period of 14 months. The logs of the use of our Website will be deleted within 14 months after creation.
**3 How We Share Your Personal Data **
We share Personal Data with third parties to help us provide our services and products to you and to run our HEX Website. These third parties are:
HEINEKEN group companies for the purpose of storing Personal Data processed via the HEX Website, due to shared IT systems;
The HEINEKEN organization in your country of residence in case you have provided your country of residency and your consent to sharing your Personal Data with your local HEINEKEN organization;
Service providers where this is needed to provide us with a service and to provide data analytics services;
Prize fulfilment agencies;
CM.com provides our online ticketing platform;
Service providers that help us organize campaigns and promotions;
First and Third party advertising companies;
Media agencies for marketing purposes and research purposes;
Service providers such as solicitors and accountants;
Adyen as our Payment service providers;
Courts, parties to litigation and their professional advisers where we deem it necessary in connection with the establishment, exercise, or defence of legal claims;
Independent debt recovery agencies, solicitors, or other agents for the purpose of collecting monies due or outstanding on your account; and
In the event HEINEKEN sells all or some of the assets or shares of a HEINEKEN group company to which Personal Data was transferred to a third party, your Personal Data may be provided to this third party.
These parties may be in the European Union or other countries in the European Economic Area or elsewhere in the world. When Personal Data is stored by us outside the EEA we will ensure an adequate level of protection of the transferred Personal Data. We require service providers to use appropriate measures to protect the confidentiality and security of the Personal Data.
**4 Security of Personal Data **
We will take appropriate technical, physical and organizational measures to protect the Personal Data collected through the HEX Website from misuse or accidental, unlawful or unauthorized destruction, loss, alteration, disclosure, acquisition or access, that are consistent with applicable privacy and data security laws and regulations. However, no internet-based site can be 100% secure and we cannot be held responsible for unauthorised or unintended access that is beyond our control. The HEX Website may contain links to other websites. We are not responsible for the privacy practices, content or security used by such other websites, which shall not be governed by this Privacy Policy. We advise you to always carefully read the privacy policies on these other websites.
**5 Retention of Your Personal Data **
We will retain your Personal Data for as long as legally required or for as long as necessary to provide you with any requested services or for any of the other purposes listed in this Privacy Policy. The specific retention terms are listed in this Privacy Policy for each of the relevant purposes. We will take reasonable steps to destroy or de-identify Personal Data we hold if it is no longer needed for the purposes set out above or after the expiration of the defined retention term.
**6 Cookies **
A major part of the information referred to in this Privacy Policy is collected via our use of cookies and similar techniques. Cookies are small text files containing small amounts of information which are downloaded and may be stored on your user device, e.g. your computer, smartphone, or tablet. Techniques we use that are like cookies are tracking pixels, Java scripts, tags, and web beacons. These cookies and similar techniques are sometimes necessary to remember your account settings, language, and country, but also enable us to measure and analyse your behaviour on the HEX Website and for showing you personalised advertisements on the HEX Website or on third party websites. Where required, you will be asked for consent to our use of cookies. To view more information on what cookies we use and how we use them please review our separate Cookie Policy in the footer of the HEX Website.
**7 Children's Privacy **
The Heineken Experience, the HEX Website and the HEX premises are not intended for use or visit by individuals under the age of 18 (or the applicable legal age for consuming the products in question). We do not knowingly collect Personal Data from individuals under the age of 18.
8 Your Rights to Access, Rectification, Deletion, Restriction and Data Portability
You have the right to request an overview of your Personal Data processed by or on behalf of us. You have the right to have your Personal Data rectified, deleted, or restricted (as appropriate). You can exercise this right by contacting this webform with a data privacy request. Please note that requests that do not meet the requirements set out by applicable law or HEINEKEN guidelines may be requested to be re-issued or denied and that certain Personal Data may be exempt from such access, rectification, and deletion requests pursuant to applicable data protection laws or other laws and regulations. Please note that you can also delete Personal Data by de-activating your user, however we will retain Personal Data where it is legally required for us to do so, which applies e.g. to sales administration.
You have the right to receive the Personal Data that you have provided to us in a structured, commonly used, and machine-readable format, and in certain circumstances we will, at your request, transmit your Personal Data to another controller where this is technically feasible.
**9 Your Right to Object **
You also have a right, in certain circumstances, to require us to stop processing your Personal Data, but where we have compelling legitimate grounds, we will continue processing your Personal Data. However, you have the right to object to our use of your Personal Data for direct marketing purposes, including profiling, and when you do so, we will accommodate your request. Where you have provided consent to our use of your Personal Data, you have the right to withdraw your consent without this effecting the lawfulness of our use of this Personal Data before your withdrawal by sending an email to service.experience@heineken.com.
**10 Updates **
We will keep this Privacy Policy under review and make updates when necessary. Any changes to this Privacy Policy will be posted on the HEX Website page and to the extent possible, will be communicated to you.
**11 Contact **
If you have any other question, objection to our use of your Personal Data or a complaint about this Privacy Policy or about our handling of your Personal Data, please contact us via this e-mail: service.experience@heineken.com With a data privacy request. You also have the right to file a complaint with your local data protection authority.
This version was last updated in April 2026.
