We have compiled this Data Protection Statement to inform you about the collection of personal data when using our website. Personal data means all data that can be used to identify you, such as your name, address, email addresses and your use of our website. We have put comprehensive technical and operational safeguards in place to protect your data against coincidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security procedures are regularly reviewed and upgraded to reflect the latest technological developments.
1 Data Controller (the person who has control over your data)
The data controller pursuant to Article 4 para. 7 of the EU General Data Protection Regulation (GDPR) is Yamaha Music Europe GmbH, Siemensstrasse 22-34, 25462 Rellingen, Germany, Phone: +49 (0) 4101/ 303-0, Fax: +49 (0) 4101/ 303-333 (also refer to our legal notice).
2 How to contact the Data Protection Officer
You can contact our Data Protection Officer by sending an email to Dataprotection@contact.europe.yamaha.com.
3 Your rights
You have the following rights in relation to your personal data:
3.1 General rights
You have a right to information, rectification, erasure, restriction of data processing, to object against the data processing and to data portability. To the extent a data processing is based on your declaration of consent, you have the right to revoke such consent with effect for the future.
3.2 Rights concerning data processing conducted on the basis of a legitimate interest
Article 21 para. 1 GDPR gives you the right to object against the processing of your personal data on the basis of Article 6 para. 1e GDPR (data processing in the public interest) or Article 6 para. 1f GDPR (data processing to safeguard a legitimate interest) for reasons resulting from your personal circumstances at any time, including against a profiling based on the same provision. We will cease to process your personal data if you object against it, unless we demonstrate compelling legitimate reasons for the data processing that prevail over your interests, rights and freedoms, or if the data processing serves the purpose of asserting, exercising or defending legal interests.
3.3 Rights concerning direct advertising
In as far as we process your personal data for direct advertising purposes, Article 21 para. 2 GDPR gives you the right to object against the processing of your personal data for the purpose of such advertising, including profiling to the extent it is related to direct advertising.
We will cease processing your personal data for direct advertising purposes if you object against such use of your personal data.
3.4 Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint about the processing of your personal data by us with the relevant data protection supervisory authority.
4 Personal data collected when visiting our website
Where our website is only used for the purpose of gathering information, meaning without you registering or transmitting information to us otherwise, we will only collect the personal data transmitted by your browser to our server. When you surf our website, we will collect the following data required by us to display our website to you and ensure its stability and security. The legal basis for this collection of data is Article 6 para. 1f GDPR:
–IP address, date and time of the request, time zone difference to Greenwich Mean Time (GMT), content of the request (specific page), access status/HTTP status code, data transferred, referring website, browser, operating system and surface, browser language and version.
5 Contacting us by email or using the contact form
When you contact us by email or via one of the contact forms, we will store the data submitted by you (your email address, your name and telephone number, if provided) for the purpose of responding to your inquiries. In as far as our contact form requests information that is not necessary to get in contact with you, the respective fields are always marked as optional. This data allows us to substantiate your inquiry and to improve our handling of your request. This data is explicitly disclosed on a voluntary basis and on the basis of your consent pursuant to Article 6 para. 1a GDPR. In as far as the data concern communication channels (e.g. email address, telephone number), you also consent to us contacting you via such communication channels for the purpose of responding to your inquiry. You are free to revoke your declaration of consent at any time with effect for the future.
We will delete the relevant data subject to a revocation of consent as soon as their storage is no longer necessary, or alternatively restrict the data processing in cases where statutory retention obligations apply.
6.1 General information
You can subscribe to our newsletter offering information on our current deals and promotions by granting your consent pursuant to Article 6 para. 1a GDPR. The subscription to our newsletter uses the so-called double opt-out procedure. After you have registered on our website, we will send an email to the address specified by you. The email will ask you to confirm your subscription to our newsletter. Your data will be blocked and automatically deleted after 1 month if your subscription is not confirmed within 72 hours.
The IP addresses, as well as the time and date of your subscription and confirmation will be stored for longer periods. This serves the purpose of being able to evidence your subscription and investigate any potential misuse of your personal data.
Your email address, language and country are the only mandatory information required for receiving our newsletter. The disclosure of other data marked as optional is voluntary and will only be used for personalized communication with you. After you have confirmed your subscription, your email address will be stored by us for the purpose of sending you our newsletter. The legal basis for this collection of data is Article 6 para. 1a GDPR:
You may revoke your consent to receive the newsletter and cancel your subscription at any time. You can declare your revocation of consent by clicking on the link included in each newsletter email, or by contacting the Data Protection Officer at the address specified above.
6.2 Newsletter tracking
Please note that we analyse your user behaviour when sending out the newsletter. The data for this analysis is gathered by so-called tracking pixels, which are embedded in the emails. The data is analysed by linking the data specified above and the tracking pixels with your email address and an individual ID. This ID is also part of the links contained in the newsletter.
All data is collected in pseudonymised format only. This means that the IDs are not linked to any other personal data, which effectively precludes any direct references to persons. We will store the data for as long as you remain subscribed to the newsletter.
This kind of tracking can be prevented by disabling the automatic display of images in your email program settings. This may cause the newsletter to be displayed incompletely and you may not be able to use all functions. The tracking mentioned above will be activated when you click on "show image".
7 Registration and use of the portal
You have the option of registering with us and creating a customer account. When registering, we will collect and store the following personal data:
- First name
- Last name
- Email (user name)
- Address (optional)
- Date of birth(optional)
- Product interests (optional)
- Registration of products (optional)
- Interests (optional)
Our registration process uses the so-called double opt-in procedure, i.e. your registration is only complete once you have confirmed it by clicking on the link contained in the confirmation email sent to you. We will automatically delete your data from our database if your registration is not confirmed within 72 hours. The data specified above is mandatory. Any additional information may be entered on a voluntary basis when you are logged into our portal.
Once the registration process has been completed, you will receive your personal, password-protected access and may review and manage your data. Registration is voluntary, but may be a necessary condition for using our services.
When you use our portal, we will store your data required for the performance of the contract and information on your payment method until you permanently delete your account. We will store the data provided by you on a voluntary basis for the duration of your use of the portal, unless you delete them at an earlier point in time. You can manage and change all information in the password-protected customer area. The legal basis for this collection of data is Article 6 para. 1a, b and f GDPR:
8 Enrolment in prize competitions
If you enrol in prize competitions, we will collect the data required for conducting the price competition. This information usually consists of your individual contribution to the prize competition (e.g. a comment or a photo), as well as your name and contact details. We may in certain cases disclose your data to our prize competition partners, i.e. to deliver a prize to you. The processing and disclosure of data may vary from prize competition to prize competition and is therefore set out in the respective prize competition's conditions of participation. Enrolment in the prize raffle and the associated collection of data are voluntary. The legal basis for the data processing is your declaration of consent pursuant to Article 6 para. 1a GDPR. Your data will be deleted after the prize competition has ended.
You can submit your application to our company electronically, i.e. by email or via one of our internet forms. We will only use the information submitted to us for the purpose of processing your application, the data will not be disclosed to third parties. Please note that unencrypted emails are not protected against third-party access during transmission.
You may also submit your application to our company via our online career portal. Your online application will be transmitted directly to our Human Resources Department via an encrypted connection and will of course be treated as strictly confidential by us. We will only use the information submitted to us for the purpose of processing your application, the data will not be disclosed to third parties. Further information on the processing of data from job applicants can be found in the data protection statement of our career portal.
If you have applied for a specific position that has already been filled, or if we believe there is another opportunity for which you would be suited equally or even better, we would like to be able to make your application available within our company. Please advise us if you object against us making your application available internally.
Your personal data will be deleted immediately after conclusion of the application process or within a maximum period of 6 months, unless you have granted your consent to a longer period of storage, or if we have entered into an employment agreement with you. The legal basis for this collection of data is Article 6 para. 1a, b and f GDPR:
10 Use of social plug-ins
This website uses social plug-ins from the following companies
- Facebook (Operator: Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA)
- Twitter (Operator: Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA)
- Pinterest (Operator: Pinterest Inc., 635 High Street, Palo Alto,CA, 94301, USA)
- Instagram (Operator: Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA)
- Linkedin (Operator: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland)
- Youtube (Operator: YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA)
These plugins will usually collect your data automatically and transmit the data to the respective operator's server. To guarantee your privacy is protected, we have taken technical measures that guarantee your data cannot be collected by the provider of the respective plug-in without your consent. When accessing a site with embedded plug-ins, these are initially deactivated. The plus-ins are only activated by clicking the relevant symbol, and in doing so you grant your consent to the transmission of your data to the respective operator. The legal basis for the use of plug-ins is Article 6 para. 1a and f GDPR.
Following activation, the plug-ins also collect personal data such as your IP address, and transmit these to the server of the respective provider, where they will be stored. Activated social plug-ins also create a cookie with a unique identifier when the website in question is accessed. Providers are thus also able to create profiles about your usage behaviour. This also happens if you are not a member of the social network of the respective provider. If you are a member of the provider's social network and you are logged in to the social network while you visit this website, your data and information about visiting this website can be combined with your profile on the social network. We have no influence on the exact scope of the data collected about you by the respective provider. More detailed information on the scope, nature and purpose of data processing and on rights and settings options to protect your privacy can be found on the data protection notices of the respective social network provider. These can be found at the following addresses:
We are offering you the chance to register and sign up through your Facebook account.
By registering/signing up through Facebook, you are consenting to data being shared between us and Facebook, as described below. The legal basis for data processing is therefore your freely granted consent, which you can withdraw at any time (Article 6 (1) (a) GDPR).
If you sign up through Facebook, Facebook will ask for your permission to share certain information in your Facebook account with us. This may include your first name, surname, and your email address to verify your identity and gender, as well as the general location, a link to your Facebook profile, your time zone, your date of birth, your profile picture, information about your "Likes" and your friend list. These data are used to set up, prepare and personalize your account.These data are collected by Facebook and sent to us in compliance with the provisions in Facebook's Data Policy (https://en-gb.facebook.com/policy.php). You can manage which information we receive from Facebook through the privacy settings in your Facebook account. When you sign up with us via Facebook, your account will automatically be linked to your Facebook account, and information about your activity on our websites may be shared with Facebook and posted in your timeline and news feed for your friends.
12 Website analysis
We use the services explained in the following to analyse and optimize our webpages. These services allow us to analyse how users navigate our website, which information they are looking for and how users came across our service. The data collected by us includes information about the website that has referred the user to one of our webpages (the so called referrer), the sub-pages the user has accessed or how frequently and for how long a sub-page was viewed. This helps us in improving our services and in making them more user-friendly. The data collected is not used to identify individual users. It is anonymised or at least pseudonymised. The legal basis for this collection of data is Article 6 para. 1f GDPR:
12.1 Google Analytics
This website uses Google Analytics, a web analysis service offered by Google Inc, (1600 Amphitheatre Parkway Mountain View, CA 94043, USA). We use Googly Analytics in the universal analytics mode. This allows for the allocation of data, sessions and interactions to a pseudonymous user ID across multiple devices and therefore an analysis of the user's activities across multiple devices.
You can stop cookies being saved by amending the relevant setting in your browser software; however, we would like to point out that if you do this, you may not be able to use all of the functions of this website in full. Furthermore, you can stop the data generated by the cookie related to your usage of the website (including your IP address) being collected by Google, and stop Google processing these data by downloading and installing the browser plug-in available at http://tools.google.com/dlpage/gaoptout. _ Opt-out cookies prevent your data from being collected during future visits to our website. To prevent Google Analytics from collecting data across multiple devices, you will have to set an opt-out cookie on each device used by you. Please click here to place the opt-out cookie:Deactivate Google Analytics
12.2 Google Tag Manager
We can also use the "Google Tag Manager" to embed the Google analysis and marketing services in our website and manage these services.
More information on the use of data for marketing purposes by Google is available at: https://www.google.com/policies/technologies/ads, Google's data protection statement can be reviewed at https://www.google.com/policies/privacy.
If you would like to object against interest-targeted advertising by Google Marketing Services, you can use the settings and opt-out options offered by Google at: http://www.google.com/ads/preferences. The legal basis is our legitimate interest pursuant to Article 6 para. 1f GDPR
12.3 Creation of pseudonymized user profiles
We partner with Sizmek Inc. in order to deliver interest-based advertising and offers to you based on your interests and your usage behaviour on the Internet. Sizmek Inc. headquarters are located at 401 Park Avenue South, New York, NY 10016, USA. Sizmek Inc. relies on cookies which are written to and read from your device when it visits our website. A cookie is a small text file that contains a unique, pseudonymous identifier. A cookie is stored on your device, and associated with a specific web browser. The following information may be associated with the pseudonymous ID stored in your cookie:
- Operating system of the device
- Browser version
- IP address
- URLs visited, including time and date
- Interactions with advertisements served by Sizmek
The pseudonymized user profiles created by Sizmek that is associated with a Sizmek cookies do not contain personally identifiable information. Information is processed and stored for up to 13 months for the purposes of digital marketing, security enhancement and fraud detection and prevention. Data processing is carried out on the basis of Art. 6 para. 1 f) DSGVO. You can object to the use of Sizmek at any time by setting the opt-out cookie available under the following link: https://www.sizmek.com/privacy-policy/optedout/
14 Social Bookmarks
Our website features so-called embedded social bookmarks (e.g. from Facebook, Twitter and Xing). Social bookmarks are Internet bookmarks used by the users to collect links and news reports from these services. The social bookmarks are only embedded in our website as a link pointing to the respective services. When you click on the embedded image, you will be directed to the website of the respective service provider, i.e. user information will only then be transmitted to the respective service provider. Information concerning the handling of your personal data when using these websites can be found in the data protection statements of the respective service provider.
15 Disclosure of data
Your data is generally not disclosed to third parties, unless we are required to disclose the data under a law, the disclosure is necessary for the performance of a contract, or if you have granted your express consent to the disclosure of your data.
External service providers and partner companies, such as online payment providers or the shipping company contracted for the delivery, will only receive your data to the extent necessary for processing your order. However, in these cases, the extent of the data disclosed will be limited to the necessary minimum. In as far as our contractors come into contact with your personal data, we will ensure that the contract data processing pursuant to Article 28 GDPR also complies with the applicable data protection laws. Please take note of the data protection statements of the respective service providers. The responsibility for third-party content lies with the respective service provider of such content. We review such content on compliance with the statutory requirements, within the bounds of what is reasonable.
We take great care to ensure your data is processed within the EU / EEC. From time to time, it may be necessary for us to use contractors who will process data outside of the EU / EEC. We will in these cases ensure that an adequate level of data protection is afforded by the recipient prior to disclosing your personal data. This means that a data protection level comparable to the standards within the EU is achieved by way of entering into EU standard agreements or an adequacy decision, such as the EU Privacy Shield.
16 Data security
We have put comprehensive technical and operational safeguards in place to protect your data against coincidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security procedures are regularly reviewed and upgraded to reflect the latest technological developments.
Last modified: Oct 2018