Last updated: 23 March 2022
IAG loyalty is a trading name of Avios Group (AGL) Limited, Waterside PO Box 365, Harmondsworth, UB7 0GB, England (“IAG Loyalty”) an operating company of International Consolidated Airlines group (“IAG”).
An airline partner programme is a loyalty programme operated by one of IAG's airlines, i.e. British Airways Executive Club, Iberia Plus, AerClub, or Vueling club.
IAG Loyalty is responsible for your personal data and is committed to respecting your privacy.
- We will be transparent about the information we are collecting and what we will do with it.
- We will also use the information to help us understand you better and so that we can give you relevant offers.
- If you tell us you don’t want to receive marketing messages, we will stop sending them. We will, of course, continue to send important information relating to a product or service you have purchased to keep you informed about your purchase.
- We will put in place measures to protect your information and keep it secure.
- We will respect your data protection rights and aim to give you control over your own information.
Controller of personal information.
IAG loyalty is part of the IAG and its role as a data controller in the airline partner programmes relates primarily to the awarding and redemption of Avios. IAG Loyalty receive, store and process airline partner programme member data to administer parts of the programmes. IAG Loyalty and the airlines partners are independent data controllers each with separate responsibilities for the processing of personal information of programme members.
If you are a member of an airline partner programme that partner is a separate data controller of your personal information, links to their privacy policies are provided below:
If you have made a booking, then the party fulfilling that booking is a data controller under European Union and UK data protection law.
Personal information means details which identify you or could be used to identify you, such as your name and contact details or purchase history. It may also include information about how you use our websites.
Where we reference that others are data controllers in the section “controller of personal information“ or “who do we share your personal information with?” You should consult their privacy policies for further information.
We take great care to protect the personal information you provide to us. Here are some things you can do to keep your information secure.
To make sure your access to our websites and other online services is secure, you should not share your log in details with anyone else. When you finish using the website or online services you should log out if others may be able to access your computer or device. This is especially important if you are using a publicly accessible computer.
There is an internet fraud practice known as "phishing" which is the illegal gathering of personal information by deception. Unsolicited emails are sent to individuals from lists illegally gathered by a third party, and recipients are asked to enter or reconfirm bank or password details into a 'cloned' or illegal copy website.
We collect personal information about you whenever you use our services (whether these services are provided by us or by other companies or agents acting on our behalf), including when you enquire about or use IAG Loyalty products or services, when you use our website, or interact with us via email or via the phone.
In addition, we may receive personal information about you from third parties, such as:
- Companies contracted by us to provide services to you.
- Companies that participate in loyalty programmes that are managed (entirely or partially) by IAG Loyalty.
- Companies who provide details to us under privacy polices providing information to be shared with IAG Loyalty.
- IAG airline partners who we work with to run their loyalty programmes.
When you visit iagloyalty.com and use our services, you may provide and we may collect information, such as when you register for an account. Below is a brief, general description of the types of information we collect through iagloyalty.com:
- Information you provide for IAG Loyalty to register, complete and manage a product or service you use with us.
Your name, company, position, email, office/mobile telephone number, city and country
We will know if you have contracted an iagloyalty.com service, e.g., get active with avios, or used another sales channel such as an account manager
- Information about the services we have provided to you in the past
Details of your previous transactions, such as products purchased and your customer feedback.
- Information about other online interactions
We will retain your information if you have entered a competition, registered for a promotion or interacted with us via social media such as Facebook, YouTube or LinkedIn.
- information about your use of our websites, contact centres and social media
To help us to personalise your information and improve our website we collect information about your searches and the content you have viewed on our website using cookies and similar technologies, such as the website you come from, online display advertisements and links which appear on our marketing partner’ websites.
We will use previous web usage data stored within the cookie to personalise and understand you as a customer.
We would be able understand from your data usage that you have visited iagloyalty.com. We may use this information to contact you to offer more information about our products and services.
- Information about your device if you have been browsing on iagloyalty.com for example your IP address or unique device id. An IP address (i.e., internet protocol address) is a numeric and/or alpha-numeric code (with regard to ipv6) that can act as a unique identifier for your computer or other device – this can be turned off from your device.
Identifying the county from which you are accessing the relevant website which will enable us to provide more relevant content and use an appropriate language.
If we have your permission, we may use the functionality on your device (such as Bluetooth, wi-fi and GPS) to determine your location to provide a personalised service (you can access or change this option by amending the location settings on your device).
- Information about your or your device, collected from social media or an interaction with IAG Loyalty in another way.
- Information relating to applications for employment through IAG Loyalty’s career site.
IAG Loyalty may collect personal information relating to applications for employment with the company through our careers page (https://apply.iagloyalty.com/jobs/) such as your résumé, and other information relevant to specific jobs advertised. Such personal information will be subject to the terms hereof. You will be required to opt-in for the submission of any such personal information submitted through our careers page.
What do we use your personal information for?
The main purposes for which we use your personal information are:
- To deliver the services you have asked for
We will use the data you provide so we can process purchases and take payments
- To send status updates and service communications to you
We may send a communication informing you of any operational updates about IAG Loyalty services you are using.
- To provide services tailored to your requirements and to treat you in a more personal way
We may update and share non-personal information with our media agency, in order to serve tailored and relevant advertising from our partners and third parties on our websites and social channels.
- To carry out advertising, analysis and market research
We will analyse the way in which our sales channels, products and services are being used by customers so that we can understand how to improve the service we offer and encourage customers to use the full range of our products and services.
- To carry out marketing and keep you informed of IAG Loyalty's products and services
We may send you information about our products and services by email, tailor the content of our websites, emails and other communications to ensure they are as relevant to you as possible
We may combine / match anonymised customer relationship marketing data with a third party (e.g., Google, Facebook) so both companies can understand behavioural activities such as knowing other sites visited
- To send you status updates and service communications
Even if you have opted-out of receiving marketing information from us, we may still send you communications about the services you are signed up to use. These communications will help you get the most from the services we provide
We may also send you communications about the services you have previously used, for example, where you experienced some form of issue or problem, and we wish to contact you about it proactively in order to resolve it successfully
- To improve our websites, products and services
We may monitor the way that you and other customers use our website so that we can identify ways to improve the website experience
- For management and administrative purposes
We may use and retain your personal information, including your purchase history, for administrative purposes, which may include for example, accounting and billing, auditing, credit verification, anti-fraud screening (including the use of credit reference agency searches) and systems testing, maintenance and development.
When we have your permission, we will send you marketing communications from IAG Loyalty. We will only allow third parties or other members of our group to send marketing communications to you when we have agreed marketing permissions from third parties.
We will respect your choice as to what communications you wish to receive and how these are sent.
If you decide you would no longer like to be sent marketing communications, you can change your mind at any time. The ways to stop being sent marketing communications are described below:
Email your request to our data protection team: firstname.lastname@example.org
Each marketing communication we send by email will also have an “unsubscribe” option which will allow you to stop you receiving further marketing emails. We aim to action requests to stop being sent marketing communications within 10 working days of receiving those requests, but it is possible you will receive some marketing in the period prior to that change being made.
Please note that if you tell us that you do not wish to be sent further marketing communications, you will still receive service communications (as described above) which don’t contain marketing content and are necessary, for example, operational updates. If you ask us to stop sending marketing communications, please note we will retain your personal information for the purposes of indicating that you do not want to receive marketing communications.
IAG Loyalty will only process your personal information where we have a legal basis to do so. The legal basis will depend on the reason or reasons IAG Loyalty collected and needs to use your information. Under EU and UK data protection laws in almost all cases the legal basis will be:
- Because we need to use your information so that we can fulfil the contract we have with you
- Because it is in IAG Loyalty’s legitimate interests as a loyalty company to use your personal information to operate and improve our business and operations. For example, during the proposal process or request for proposal (RFP) process
- Because IAG Loyalty needs to use your personal information to comply with its legal obligation
- To protect the vital interests of you or another person
- Because you have consented to IAG Loyalty using your information for a particular purpose
More information on each legal basis is provided below.
If processing of your data is subject to any other laws, then the basis of processing your data may be different to that set out above and may in those circumstances be based on your consent in all cases.
It will be necessary for IAG Loyalty to use your personal information to fulfil the service arrangements we have with you.
As a loyalty company IAG Loyalty has a legitimate business interest to use the personal information we collect to offer an effective service and carry out our business.
There are situations where IAG Loyalty is subject to a legal obligation and needs to use your personal information to comply with those obligations.
There are situations where we may need to use your personal information to protect the vital interests of you or another person.
Alternatively, we may collect and use your personal information where you have given your specific consent to us doing so.
If you have provided your consent to the collection, processing and transfer of your personal data, you have the right to fully or partly withdraw your consent as described above, or by contacting email@example.com. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there is another legal ground for the processing.
However, if you withdraw this consent, in some circumstances, it may mean we will not be able to provide all or parts of the service you have requested from us.
We will keep your information for as long as we need it for the purpose it is being processed for. For example, where you buy a product or service with us, we will keep the information related to your booking, so we can fulfil the specific arrangements you have made and after that, we will keep the information for a period which enables us to handle or respond to any complaints, queries or concerns relating to the booking. The information may also be retained so that we can continue to improve your IAG Loyalty experience.
We will actively review the information we hold and delete it securely, or in some cases anonymise it, when there is no longer a legal, business or customer need for it to be retained.
Your personal information may be shared with the companies within IAG group, which includes IAG, British Airways, Iberia, Iberia Express, Vueling, Aer Lingus, Level, British Airways Holidays, BA CityFlyer, IAG Cargo, IAG Connect and IAG GBS. For more details about our group please visit the website of our parent company, IAG. We share information with them, so they can assist us in providing services to you and to understand more about you. For example, if you have used the services of one of the companies in the IAG group we may use this information to understand more about the sorts of products and services you are likely to be interested in.
You will only be sent marketing emails from other companies within our group where you have provided your consent to those companies.
We may also disclose your personal information to the following third parties for the purpose described here:
- Our partner airlines and franchisees, for example, to administer benefits because of cooperation between loyalty programmes.
- In response to a valid, legal request from government and law enforcement agencies.
- Third party service providers we are using to provide services that involve data processing, for example, to carry out marketing initiatives or run customer surveys on our behalf.
- Third parties, such as law firms and law courts, to enforce or apply any contract with you.
- Third parties, such as the police and regulatory authorities, to protect our rights, property, or the safety of our customers, staff and assets.
- Third party companies providing services for money laundering and terrorist financing checks, credit risk reduction and other fraud and crime prevention purposes and companies providing similar services, including financial institutions, credit reference agencies and regulatory bodies with whom such personal data is shared.
- If necessary, to comply with a legal or regulatory obligation in any jurisdiction, including where that obligation arises because of a voluntary act or decision by us (e.g., our decision to operate to a country or a related decision).
We do not sell personal information to third parties.
Your personal information may be sent to and stored by us and third parties in countries outside the country in which you are located and outside the European economic area and the UK.
The nature of our business means it is often necessary for us to send your personal information outside the European economic area or the UK. This occurs because our business and the third parties identified in “who do we share your personal information with?” Have operations in countries across the world.
In addition, we may transfer your data to parties in countries outside the country in which you are located to provide services to you.
This may involve sending your data to countries where under their local laws you may have fewer legal rights.
Where your personal information is transferred outside the European economic area or the UK, we will implement safeguards that assure the protection of your personal information, such as European commission approved standard contractual clauses. If you would like more information on these safeguards, please contact us using the details below.
Email your request to our data protection team: firstname.lastname@example.org
Under data protection laws in the European union and the UK, you have certain rights in relation to your personal information. As a rule, responses to exercise your rights will be provided within 1 month. If your request is particularly complicated, we may extend the deadline for responding to three months, but we will let you know if this is the case.
We will handle all requests in accordance with applicable law. However, depending on the right you wish to exercise, and the nature of the personal information involved, there may be legal reasons why we cannot grant your request. Further explanation of those rights and the exceptions to them are set out below.
Details of how to exercise your rights are set out in the section below “how can you exercise your legal rights in relation to your personal information?”
Your rights include the following:
- You may request us to stop sending you direct marketing. To see how to change your permission to market please refer to the section “how can you change what marketing communications you receive and how you receive them?” Above.
- You may request that we stop using, or erase, your personal information, unless it is needed for dealing with legal claims or we have other compelling legitimate reasons that override your rights.
- You may request us to erase your personal data when the personal data is no longer necessary for the purposes for which it was collected, or when your personal data have been unlawfully processed.
- You may access the personal information we hold on you. There are some limited exceptions to this right, such as information relating to others who have not consented to the disclosure of their information and information which is legally privileged.
- You may ask us to correct your personal information (the 'right of rectification’) if that information is inaccurate.
- You have the right to request that some of your personal data is provided to you, or to another data controller, in a commonly used, machine-readable format.
If you wish to exercise any of your individual rights set out under the heading 'your individual rights in relation to your personal information' please contact us at the address below.
When you are seeking access to your personal information, please include the following information with your request:
- Your name and postal address
- How you would prefer to receive the response (email, post)
- Details of your request
- Any details which may help us locate the information, which is the subject of your request, for example:
- We may ask you to provide:
- A photocopy of your passport or driving licence, so that we can verify your identity
- Signed authority from a third party if you are applying on their behalf
Please send your request to:
Data Protection Team
Avios Group (AGL) Limited,
Waterside PO Box 365
If you believe that your data protection rights may have been breached, you have the right to lodge a complaint with the applicable supervisory authority, or to seek a remedy through the courts.
We may update and change this policy in the future in order to reflect any changes to the way in which we process your personal data or changing legal requirements. Any changes we may make to our policy will be posted on this page and, where appropriate, notified to you by email. Please check back frequently to see any updates or changes to our policy.