1. PERSONAL INFORMATION
1.1 Personal Information We May Collect
Two types of information are collected in connection with the Properties: Personal Information and Other Information. “Personal Information” is information that identifies you or makes you identifiable as an individual. “Other Information” is any information that does not reveal your specific identity. If we are required to treat Other Information as Personal Information under applicable law, then we may use and disclose it for the purposes for which we use and disclose Personal Information as detailed in this Policy. Other Information is addressed separately below, under the heading “OTHER INFORMATION”.
We and our third-party service providers may collect the following Personal Information from you such as:
- Postal address (including billing and shipping addresses)
- Telephone number
- Email address
- Date of birth
- Credit and debit card number
- Purchase details
- Size, weight - if you use a size advisor
1.2 Collection of Personal Information
We and our third-party service providers collect Personal Information through the Properties in a variety of ways, including:
1.2.1 Through the Properties
We may collect Personal Information through the Properties, for example, when you register for newsletters or other communications through the Properties, register a customer account, make a purchase or make a request.
We may collect Personal Information from you offline, e.g., if you provide information to us at an E.M.P. store or at a concert venue.
1.2.3 From Other Sources
We may receive your Personal Information from other sources, for example:
- address databases; or
- marketing partners when they share information with us in the context of marketing and promotional campaigns related to our business.
If you use your social media or other third party account to enter our sweepstakes, contest, or promotions or via an initiation to sign into such account on our Properties, you will share certain Personal Information from your third party account with us which may include, for example, your name, email address, photo, list of social media contacts, listening history, favorite tracks and any other information that you make or which is otherwise accessible to us when you connect through such third party account.
You are not required by statute or contract to provide any Personal Information to us. For example, when you participate in various opportunities provided through the Prop-erties, we collect Personal Information from you in order to enable you (or us) to complete your experience on the Properties.
1.3 How We Use Personal Information
We and our third-party service providers use Personal Information for the following business purposes including:
Providing the functionality of the Properties and fulfilling your requests.
- To provide the Properties' functionality to you, such as arranging access to your registered account, and providing you with related customer service.
- To respond to your inquiries and fulfill your requests, when you contact us via one of our online contact forms or otherwise, for example, when you send us questions, suggestions, compliments or complaints, or when you request information about our Properties.
- To send to you administrative information, including information regarding the Properties and changes to our terms, conditions and policies.
- To complete and fulfill your purchase, for example, to process your payments, have your order delivered to you, communicate with you regarding your purchase and provide you with related customer service.
- To provide you with the international customer service of all EMP companies.
We will engage in these activities to manage our contractual relationship with you and/or to comply with a legal obligation.
Providing you with our newsletter and/or other marketing materials and facilitating social sharing
- To send you newsletters with information about our products and services and newsletters with information from our affiliates within Warner Music Group at regular intervals. You may also choose to provide additional information when you subscribe to the newsletter. If you have subscribed to our newsletter, you will receive an email from us. [To complete your subscription to our newsletter, you will have to click on the activation link in that email.
- To send you other marketing communications, that we believe may be of interest to you if you have indicated that you would like to receive them (including, without limitation, by our third-party service providers that send direct mail, and other types of advertising).
- To send you SMS text messages using your telephone number, e.g., if you participated in a sweepstake with this number and you have indicated you would like to receive them. Please keep in mind that message and data rates may apply. You should check with your mobile service provider for applicable data rates.
We will engage in this activity with your consent or because we have a legitimate interest.
Analysis of Personal Information for business reporting and providing personalized services.
- To analyze or predict our users' preferences in order to prepare aggregated trend reports on how our digital content is used, so we can improve our Properties.
- To personalize your experience on the Properties using your IP address, by presenting content, products, and offers tailored to you.
We will engage in this activity with your consent or because we have a legitimate interest.
Allowing you to participate in sweepstakes, contests or other promotions.
- • To notify you of the outcome of a contest, EMP will send you an email. If you win a contest, EMP may publish your name.
We use this information to manage our contractual relationship with you.
Aggregating and/or anonymizing Personal Information.
- We may aggregate and/or anonymize Personal Information so that it will no longer be considered Personal Information. We do so to generate other data for our use, which we may use and disclose for any purpose.
We will engage in this activity because we have a legitimate interest.
Accomplishing our business purposes.
- Data analysis, for example, to improve the efficiency of our Properties;
- Audits, to verify that our internal processes function as intended and are compliant with legal, regulatory or contractual requirements;
- For fraud and security monitoring purposes, for example, to detect and prevent cyberattacks or attempts to commit identity theft;
- For developing new products and services;
- For enhancing, improving, or modifying our current products and services;
- For identifying usage trends, for example, understanding which parts of our Properties are of most interest to users;
- For determining the effectiveness of promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users; and
- For operating and expanding our business activities, for example, understanding which parts of our Properties are of most interest to our users so we can focus our energies on meeting our users' interests.
We engage in these activities to manage our contractual relationship with you, to comply with a legal obligation, and/or because we have a legitimate interest.
Information text for the online data protection notice of the advertising partner (voucher offer):
- Online Data Protection Notice (of advertising partner): Voucher offers of Sovendus GmbH: In order to select a currently interesting voucher offer for you, we will transmit your pseudonymised hash value of your e-mail address and your IPaddress in encrypted form to Sovendus GmbH, Hermann-Veit-Straße 6, D-76135 Karlsruhe (Sovendus) (Art. 6 par. 1 f GDPR). The pseudonymised hash value of your e-mail address is used to consider a possibly existing objection to receive offers from Sovendus (Art. 21 par.3, Art. 6 par. 1 c GDPR). The IP-address will be exclusively used for data security purposes and as a rule the same will be anonymised after seven days (Art. 6 Abs.1 f GDPR).
- Furthermore, we will transmit order number, order value with currency, session ID, coupon code, and time stamp in pseudonymised form to Sovendus for billing purposes (Art. 6 Abs.1 f GDPR).
- If you are interested in a voucher offer of Sovendus, while there is no objection existing to receive such offers, and if you click on the voucher banner, we will transmit your salutation, your name, your postal code and country and your e-mail address in encrypted form to the form fields of your browser to prepare a voucher (Art. 6 par. 1 b, f GDPR). Only if you (the user) subsequently agree to the voucher selection process will the data be transferred to Sovendus for processing and fulfilment purposes. This corresponds to the legitimate interest.
- You will find further information about the processing of your data by Sovendus in their Online Data Protection Notice at https://www.sovendus.co.uk/privacy_policy.
1.4 Disclosure of Personal Information
We disclose Personal Information:
To Warner Music Group and its affiliates for marketing purposes. You can consult the list and location of Warner Music Group here https://wminewmedia.com/affiliates/.
To our third-party service providers (and in some cases, our affiliates), to facilitate the services they provide to us
- These can include providers of services such as hosting, data analysis, payment processing, order fulfilment, infrastructure provision, IT services, customer service, email delivery, credit card processing, auditing and other similar services to enable them to provide such services
- By selecting the payment option "payment by invoice" we may collect the Personal Information that are required for processing the purchase with payment by invoice and for running an identity and credit check and transfer such data to the provider. The provider needs such data for purposes of obtaining information about the purchaser's identity and credit score from the appropriate credit rating agencies.
To third parties, to permit them to send you marketing communications, consistent with your choices.
- Unaffiliated third parties or their vendors, to permit them to send, or cause to be sent, marketing communications to you in online and offline media.
- Our artists (including any of the artists' band members, if applicable) and their representatives, so that the artists and their representatives may use this information to send to you communications (including marketing communications) that they believe may be of interest to you, including, for example, if you (a) sign up to join the applicable artist's mailing list and/or to receive such artist's newsletters, (b) register with the applicable artist's website, or (c) have otherwise indicated that you would like to receive information and/or marketing communications from the applicable artist. We do not control, and are not responsible for, artists' and their representatives' use of Personal Information.
To a relevant artist who is no longer affiliated with us, if you indicated an interest in such artist (for example, by registering with the artist's website)To third parties that sponsor contests, sweepstakes and similar promotions so that they can facilitate and administer such contests, sweepstakes and promotions
By using the Properties, you may elect to disclose Personal Information
- On or through message boards, chat, profile pages and blogs and other services to which you are able to post information and materials. Please note that any information and materials that you post or disclose on or through a Property will become public information, and may be available to visitors to such Property and to the general public, and may be redistributed through the Internet and other media channels where they will reach an even broader audience. We urge you to be very careful when deciding to disclose your Personal Information, or any Other Information, on or through the Properties.
1.5 Other Uses and Disclosures
We also use and disclose your Personal Information as necessary or appropriate, especially when we have a legal obligation or legitimate interest to do so:
To comply with applicable law.
- This can include laws outside your country of residence.
To respond to requests from public and government authorities.
- These can include authorities outside your country of residence.
To cooperate with law enforcement.
- For example, when we respond to law enforcement requests and orders
For other legal reasons.
- To enforce our terms and conditions
- To protect our operations or those of any of our affiliates or artists;
- To protect our rights, privacy, safety or property, or that of our affiliates, our artists, you or others; or
- To allow us to pursue available remedies or limit the damages that we may sustain
In connection with a sale or business transaction.
- We have a legitimate interest in disclosing or transferring your Personal Information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings). Such third parties may include, for example, an acquiring entity and its advisors
1.6 Retention Period
We will retain your Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law.
The criteria we use to determine our retention periods include:
- The length of time we have an ongoing relationship with you and provide the Properties to you (for example, for as long as you have an account with us or keep using the Properties);
- Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them); or
- Whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).
1.7 Sensitive Information
We ask that you not send us, and you not disclose to us, any sensitive Personal Information (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, criminal background or trade union membership) on or through the Properties or otherwise.
2. OTHER INFORMATION WE MAY COLLECT
We and our third-party service providers may collect Other Information (defined above) such as:
- Browser and device information
- Mobile App usage data
- Server log files
- Geographic location information
- Demographic information and other non-personally identifiable information provided by you
- Information about how you use the Properties
- Aggregated information
2.1 How We May Collect Other Information
We and our third-party service providers may collect Other Information in a variety of ways, including:
Through your browser or your device:
Certain information is collected by most browsers, such as your Media Access Control (MAC) address, device type (Windows or Macintosh), screen resolution, operating system version, Internet browser type and version and the type and version of a Property that you are using. We and our service providers may also collect a unique device identifier assigned by us or our service providers to the device from which you are accessing a Property and other transactional information for the device that we and our service providers may use to serve content and advertisements to the device.
Through your use of Mobile Apps:
When you download and use a Mobile App, we and our service providers may track and collect Mobile App usage data, such as the date and time the Mobile App on your device accesses our servers and what information and files have been downloaded to the Mobile App based on your device number.
Through server log files:
An Internet Protocol (IP) address is a number that is automatically assigned to your device from which you are accessing a Property by your Internet Service Provider (ISP), and is identified and logged automatically in our server log files whenever you visit the Property, along with the time of the visit and the activity on the Property. We and our service providers use IP addresses for purposes such as calculating Property usage levels, helping diagnose server problems, administering the Properties and determining your approximate geographic location.
- If your device stores Flash LSOs, and if you do not want Flash LSOs stored on your device through which you access the Properties, you can adjust the settings of your Flash player to block Flash LSO storage using the tools contained using the Website Storage Settings Panel. You can also control Flash LSOs by going to the Global Storage Settings Panel and following the instructions (which may include instructions that explain, for example, how to delete existing Flash LSOs (referred to as “information” on the Macromedia site), how to prevent Flash LSOs from being placed on your device without you being asked, and (for Flash Player 8 and later) how to block Flash LSOs that are not being delivered by the operator of the page you are on at the time). Please note that setting the Flash Player to restrict or limit acceptance of Flash LSOs may reduce or impede the functionality of some Flash applications, including, potentially, Flash applications used in connection with the Properties or our content. We expect our service providers and technology suppliers to honor any decision by you to restrict or limit Flash LSOs, but we cannot guarantee that they will do so.
- Our Properties do not respond to browserbased do-not-track signals.
Geographic location information
If you use any location-enabled products or services, you may be sending us location information. When you use a location-enabled service, we may collect and process information about your precise geographical location, such as GPS signals sent by a mobile device. We and our third party service providers and partners may use your device’s physical location to provide you with personalized location-based services, content and advertisements. In some instances, you may be permitted to allow or deny such uses of your device’s location, but if you choose to deny such uses, we may not be able to provide you with the applicable personalized services and content.
We may collect demographic information, such as your zip code or gender, as well as other information, such as your preferred means of communication, when you volun-tarily provide this information to us. This information does not necessarily personally identify you or any other user of the Properties, unless further information is added to it that would allow identification to take place. In such case, the information will be treated as Personal Information.
Information about how you interact on the Properties:
We may collect information about how you interact on the Properties. For example, some Properties may utilize analytic tools to help us better serve you through improved products, services, and revisions to the Properties. This collected information may let us know which services and features you are using the most within a Property, as well as device type and hardware features, country and language of download, etc.
By aggregating information:
We may aggregate Personal Information so that the end-product does not personally identify you or any other user of the Properties, for example, by using Personal Information to calculate the percentage of our users who like a particular artist.
Our plugins are not integrated into our website without restriction, but merely by using an HTML link (so-called "shariff plugin"). This type of integration ensures that by using our website no connection to the service of the social network provider will be established yet. If you click on a button of a social network, a new window will open and access the page of the service provider. For the purpose and scope of data collection and the further processing and use of data by social network providers on their respective websites, and for your related rights and setting options to protect your privacy, please refer to the data privacy policies of the providers.
2.2 How We May Use and Disclose Other Information
Please note that we may use and disclose Other Information for any purpose, except where we are required to do otherwise under applicable law. If we are required to treat Other Information as Personal Information under applicable law, then we may use it as described in “How We May Collect Other Information” section above, as well as for all the purposes for which we use and disclose Personal Information. In some instances, we may combine Other Information with Personal Information (such as combining your name with your geographical location). If we combine any Other Information with Personal Information, the combined information will be treated by us as Personal Information as long as it is combined.
We will use reasonable physical, technical and administrative measures to protect Personal Information under our control. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately in accordance with the “Contacting Us” section below.
4. YOUR RIGHTS
4.1 Your choices regarding our use and disclosure of your Personal Information
We give you many choices regarding our use and disclosure of Personal Information about you for marketing purposes.
You may opt-out from the following as set forth below:
Receiving marketing-related emails from us and our affiliates
If you do not want to receive marketing-related emails from us and our affiliates on a going-forward basis, you may opt-out from receiving such emails either by using the unsubscribe mechanism provided in the email or by emailing us at firstname.lastname@example.org .Receiving marketing-related SMS text messages from us and our affiliates:
If you do not want to receive marketing-related SMS text messages from us and our affiliates on a going-forward basis, you may opt-out from receiving such messages by texting back “STOP” or by emailing us at email@example.com.
Our sharing of your Personal Information with artists or unaffiliated third parties for their marketing purposes:
If you prefer that we not share your Personal Information on a going-forward basis with artists or unaffiliated third parties for their marketing purposes, you may opt-out from such sharing by emailing us at firstname.lastname@example.org
Please make clear in your email what you are opting-out from. We will comply with your request(s) as soon as reasonably practicable, in any case within the legally required time period. Please note that, if you do opt-out from receiving marketing-related messages from us, we may still send administrative messages to you.
4.2 How you can access, change or delete your Personal Information
If you would like to access, review, correct, update, suppress, restrict or delete Personal Information that you previously provided to us, if you would like to object to our use of your Personal Information, or if you would like to request to receive an electronic copy of your Personal Information for purposes of transmitting it to another company (to the extent this right to data portability is provided to you by applicable law), you may contact us at: email@example.com. We will respond to your request consistent with applicable law.
You may also lodge a complaint with the competent data protection regulatory authority: Data Protection authority of the state of Lower Saxony (Germany), Prinzenstraße 5, 30159 Hannover; Telefon: 0511 120 – 4500; Telefax: 0511 120 – 4599; E-Mail: firstname.lastname@example.org, Internet: htttp://www.lfd.niedersachsen.de.
In your request, please make clear what Personal Information you would like to have changed, whether you would like to have your Personal Information suppressed from our database or otherwise let us know what limitations you would like to put on our use of your Personal Information. For your protection, we may only implement requests with respect to the Personal Information associated with the particular email address that you use to send us your request, and we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.
Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion (e.g., when you make a purchase or enter a promotion, you may not be able to change or delete the Personal Information provided until after the completion of such purchase or promotion).
Where our collection and use of Personal Information is based on your consent, you may withdraw such consent at any time by emailing us at email@example.com, and such withdrawal will not affect the lawfulness of processing based on consent before your withdrawal.
5. CROSS-BORDER TRANSFER
If you are located in the EEA: Some of the non-EEA countries are recognized by the European Commission as providing an adequate level of data protection according to EEA standards (the full list of these countries is available here: https://ec.europa.eu/info/law/law-topic/data-protection_de. For transfers from the EEA to countries not considered adequate by the European Commission, we have put in place adequate measures, such as standard contractual clauses adopted by the European Commission regarding Personal Information. You may obtain a copy of these measures by contacting firstname.lastname@example.org.
7. CONTACTING US
We are located at the following address:
E.M.P. Merchandising Handelsgesellschaft mbH
Darmer Esch 70a
Data protection officer:
Darmer Esch 70a
phone: 0049 591 - 9 14 310
The data protection officer is a DEKRA certified "data protection specialist."
To be certified as a "data protection specialist", the data protection officer must demonstrate his or her subject matter knowledge in a written examination. DEKRA cer-tification is limited to a certain time period and may be renewed by taking subsequent tests at regular intervals or by furnishing proof of enrollment in continuing education events. The certification is issued by DEKRA Certification GmbH, Handwerkstr. 15, 70565 Stuttgart, GERMANY.
The required subject matter knowledge includes, inter alia, the following:
- Provisions and implementation of the European General Data Protection Regulation (EU GDPR)
- Provisions and implementation of the revised Federal Data Protection Act (BDSG, neu)
- Data security and IT security: technical and organizational measures
- Risk management
- Data protection management – organization of data protection within the company
- Principles governing the processing of personal data
- Data protection officer (internal/external)
- Rights of data subjects
- Notification obligations
- and more.
These requirements are satisfied by our data protection officer. According to the DEKRA seal, the certification is currently valid until January 2020.
Please note that email communications are not always secure, so please do not include credit card information or other sensitive information in your email messages to us.