Introduction

22nd Century Group, Inc. (“22nd Century,” “we,” “us” or “our”) understands that when you use our services, you are entrusting us with your personal information. As a result, we have crafted this Privacy Policy (“Privacy Policy”) with you in mind, so that we can protect your personal information and inform you of your privacy rights. In this Privacy Policy, we explain our policies and procedures for data collection, use, maintenance, protection, and disclosure when you visit our website or use any of our services, including any applications provided by us (collectively, the “Services”). This policy is effective as of December 2, 2020.

We will update this policy as we adjust our procedures to protect your information. Before these changes go into effect, we will post the updated policies and procedures here, along with an effective date for the amended Privacy Policy. Once we alter the policy, continued use of the Services on or after the effective date is considered consent to the amended Privacy Policy.

About Your Use of the Services

Automatically Collected Information

Automatic Information Collection

As is customary, the Services will collect information, including technical and routing information about your computer, without you being prompted. This may include geolocation data and internet or other electronic network activity such as device identifiers and advertising identifiers. We use this information to optimize our Services for our users’ use.

Cookies & Web Analytics

Some information, including but not limited to IP addresses, operating systems, browsers, and browsing patterns, is either tracked or collected using “cookies” (which are small data files that a website places on your hard drive for record-keeping purposes) or “web beacons” (which are transparent pixel images that are used in collecting information about website usage). We use these to ensure our content improves and meets your, and other visitors’, needs. While most of the cookies we use will “disappear” when you finish browsing, we also use persistent cookies. Persistent cookies stay on your device simply to ensure we recognize your device when you revisit the Services.

Please note that there are options on most browsers (like Google Chrome, Mozilla Firefox, Safari, and Internet Explorer) to disable cookies. You can choose to use such features to disable cookies, but it may impact your use of certain functions included in the Services. To learn more about your ability to manage cookies and web beacons, please consult the privacy features in your browser.

Google Analytics

We may use Google Analytics to collect information about your use of the Services. Google Analytics collects certain information, such as how often you use the Services, the pages you visit, and the websites you used prior to using the Services. We may use the information received from Google Analytics to improve the Services. Google Analytics collects only the IP address assigned to you on the date you visit the website, rather than your name or other identifying information. We do not combine the information collected through the use of Google Analytics with any other information collected from you. Although Google Analytics stores a permanent cookie on your machine to identify you as a unique user the next time you use the Services, the cookie cannot be used by anyone but Google. Google’s ability to use and share information collected by Google Analytics is governed by the Google Analytics Terms of Use available at http://www.google.com/analytics/tos.html and the Google Privacy Policy available at http://www.google.com/intl/en/analytics/privacyoverview.html. You can prevent Google Analytics from recognizing you by disabling cookies on your browser.

Other Information We Collect

When you use the Services, we may request personal information, including your name, email, age, and other identifiers. When you view any content using the Services, we may also collect information related to such content. This information is only collected when you present it to us, and we may use it for a variety of reasons, as explained in more detail below.

Tracking Disclosure

We do not respond to web browser “do not track” signals or other similar mechanisms.

Children Under the Age of 16

The Services are not designed for children under the age of sixteen and we do not collect information about children knowingly. If you believe that we have inadvertently collected information from a child of that age, please contact us. Our policy is to delete any information collected from or concerning a child under the age of 16 as quickly as possible.

Our Use of the Data We Collect

Use of Personally Identifiable Information

We may use your personal information for the following purposes:

Providing Services

We may use personal information to provide you with services that you have ordered or requested.

Communication

When you contact us, we may use personal information (like your e-mail address) to reply and provide you with the services or information you requested. We also may use your personal information to collect feedback on our Services and policies.

Services Improvement

We reserve the right to use your personal information and browsing behavior to personalize the Services and improve the overall user experience. We also may use personal information to evaluate response rates or gauge the usability of the Services.

Protect Content

In order to stop malicious, deceptive, fraudulent or illegal activity from occurring on the Services, we may use identifying information to monitor users’ behavior. Our attempts to prevent malicious, deceptive, fraudulent, or illegal Internet activity may cause some users to be suspended from the Services.

Subscriptions

If you choose to subscribe to our email updates, we collect personal information including your name and email address so that we can reach you. This information is not distributed to third parties, except for our third party storage system.

Should you wish to unsubscribe from our email updates, you may do so at any time by clicking on the unsubscribe link in the footer of any 22nd Century email sent to you. If, however, your request to unsubscribe appears to be unsuccessful, please contact us at [email].

Data Rights

Subject to applicable law, you may have the right to request and obtain information about, or copies of, your personal information that we process, where we obtained your information, the business or commercial purpose for collecting your information, the third parties with whom your information is shared. Lastly, you may ask us to delete personal information that we have collected from you, depending on the situation and applicable laws.

All of our processing is in support of our business. Where we process your data based upon your consent, we recognize that you may withdraw consent if you wish to do so, and that you retain a right to your own data.

Residents of California have the following rights with respect to their personal information:

  • The right to know the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources from which the personal information was collected, and the business purpose for collecting such information;
  • The right to know whether and how we sell or disclose your personal information, to whom we sell or disclose your personal information, and the business purpose for selling or disclosing your personal information;
  • The right to request a copy of the specific pieces of personal information we have collected about you in the past 12 months;
  • The right to request that we not sell your personal information; and
  • The right to request that we delete the personal information that we have collected from you, in certain circumstances; and
  • The right not to receive discriminatory treatment for the exercise of your privacy rights.

You may exercise any of these rights by contacting us at [toll free phone number] or by emailing us at [email]. For more information on your right to opt out from the sale of your personal information to third parties, click here: [link to notice of right to opt-out].

Upon receipt of a request to exercise your rights, we may request additional information in order to verify your identity. To the extent possible, we will utilize information already in our possession to verify your identity. Any information you provide in connection with such verification will be deleted as soon as practicable following your request.

You may designate an authorized agent to make a request on your behalf. If you submit a request through an authorized agent, we may require that the authorized agent provide proof that the authorized agent has been authorized by you to act on your behalf and may still require you to verify your identity in accordance with the above.

The following provides more information about our data collection activities in the last twelve (12) months:

Category of Information Collected Source of Information Purpose for Collection Third Parties to whom Information is Disclosed

Identifiers, such as real name, email address or other similar identifiers.

You and/or your use of our Services

To contact you; provide you with Services; or to make our products and Services better

We also disclose your information to service providers, such as cloud computing providers, to allow 22nd Century to conduct its business. We may also share select information when you expressly request that we provide you with certain products and services.

Internet or other electronic network activity information, including but not limited to, browsing and search history, and information relating to your interaction with our Site or software

You and/or your use of our Services

To contact you; provide you with Services; or to make our products and Services better

We also disclose your information to service providers, such as cloud computing providers, to allow 22nd Century to conduct its business. We may also share select information when you expressly request that we provide you with certain products and services.

Inferences we may draw from the above information reflecting your preferences

You and/or your use of our Services

To contact you; provide you with Services; or to make our products and Services better

We also disclose your information to service providers, such as cloud computing providers, to allow 22nd Century to conduct its business. We may also share select information when you expressly request that we provide you with certain products and services.

Information Disclosure

We may need to disclose your personal information occasionally. Most of our disclosures are necessary to complete a transaction or provide the information or service you have requested. In addition to this, we may disclose your information if needed to comply with a court order, law, legal proceeding, or request from the government. We also reserve the right to disclose your information if we have the reasonable belief that such disclosure is fundamental to the safety of individuals associated with 22nd Century or others unaffiliated with the company, or to report or investigate fraud or a crime.

We reserve the right to transfer any information we have about you in the event we sell or transfer all or a portion of our business or assets. Should such a sale or transfer occur, we will use reasonable efforts to require that the transferee use personal information provided through this web site in a manner that is consistent with this Privacy Policy.

Data Retention

We will retain personal information for as long as required for the purpose for which we have collected such personal information. Where we collect personal information to provide a service for you, we will retain such personal information for as long as such services are provided. Where we collect personal information for our legitimate interests, we will retain such personal information for as long as needed to fulfill such interests.

External Links

The Services contain links to third-party material, including other websites, such as ecommerce platforms. This material is not affiliated with, or owned by, 22nd Century and other websites may have their own terms and conditions and privacy policies. After you choose to follow the link and leave the Services, we are not responsible for the content of those websites, or their privacy policies. We have no control over what information they collect, or how they choose to use that information.

Security

Security is important to us. We utilize standard and reasonable security methods, including administrative, technical and physical protections, to prevent the theft, access, alteration, destruction, or disclosure of your information. Our methods are frequently tested and improved. Nonetheless, no network, website, or communication using the Internet is perfectly secure. We will attempt to protect your information, but we cannot guarantee the safety of any information you send to us, and you do so at your own risk. In the unlikely case of a breach of private information, we will follow relevant laws and regulations to inform you of the breach.

Data Transfer from EU to US

We are located in the United States, and the information gathered from you will be processed there. The United States has not been given an “adequacy” finding by the European Union. Nonetheless, we will only transmit your private information to the United States if you agree to us doing so, unless there is a prevailing and compelling interest to the contrary.

Contact Us

If you have any questions or concerns about these policies, or how 22nd Century protects your personal data, please feel free to contact: [email].