Please click the following link to see details of each privacy policy.
YOKOWO Group GDPR Privacy Policy
YOKOWO CO., LTD. ("YCL"), together with YOKOWO EUROPE LTD., YOKOWO EUROPE GmbH ("YEG") and other YCL affiliates (collectively, "we" or "Our Company") endeavor to protect the personal data of those who are in the European Economic Area (the "EEA"). This privacy policy (this "Privacy Policy") therefore intends to inform you about how we, acting as independent data controllers, collect and process your personal data that you - our employees and officers, employees and officers of our customers, employees and officers of our business partners and visitors to our website ("Website") - submit or disclose to us, whether directly or indirectly. We process this personal data in accordance with applicable European Union and Member State regulations on data protection and in particular, with the General Data Protection Regulation No 2016/679 (the "GDPR").
Please carefully review this Privacy Policy in advance of using our Website and our services. If you do not wish your personal data to be used by us as set out in this Privacy Policy, please do not provide us with your personal data. Please note that in such a case, we may not be able to provide you with our services, you may not have access to and/or be able to use some features of our Website, and your customer experience may be impacted.
If you have any queries or comments relating to this Privacy Policy, please contact our Public Relations & Equity Department at the following email address: sp@jp.yokowo.com
Additional contact details are located in the final section of this Privacy Policy.
1. Objectives and legal bases for the processing of personal data
We only process personal data for the following purposes and legal bases, in accordance with Article 6 of the GDPR.
Legitimate interests: Our Company collects and processes your personal data for the specific purposes set forth below, which are required for us to pursue our legitimate interests and perform our services, pursuant to Article 6(1)(f) GDPR:
Purpose | Categories of Personal data | Legitimate Interest |
---|---|---|
Hiring employees CV acquisition (via human resources company) |
Name, Career (academic and professional background), Email address, Telephone number | Recruitment of Job applicants |
Personnel evaluation of employees, management, and officers | Name, Address, Telephone number, Email address, Comments on evaluation and performance, Financial data (salary data) | Analyzing performance valuations of employees |
Employment Agreement | Name, Address, Employment conditions, including salary | Retaining and assessing employees |
Payroll and pay slip issuance | ID card copy, Insurance number, Tax ID, Bank account details | Management of payroll for employees |
Contact information for emergencies | Emergency contact information: Name, Relationship, Phone number of primary contact | Employee safety |
Ship the product directly to the customer | Name, Address, Email address, Telephone number | Shipping products to customers |
Project management to support product development of customers | Company name, Company address, Name of person, Department, Title, Telephone number, Email address, Fax | Management of customers and customer data |
Analysis on interest of customers who visit website | Company name, Company address, Name of person, Department, Title Telephone number, Email address, Fax, Cookies | Contacting customers about products they may be interested in |
Direct marketing by phone calls to promote products | Company name, Company address, Name of person, Department, Title, Telephone number, Email address | Conducting marketing activities |
Support for response to inquiries and communicate with customers to learn their interests and propose products | Company name, Company address, Name of person, Department, Title, Telephone number, Email address, Fax | Conducting marketing activities |
Processing and storing resumes | Name, Address, Phone number, Email address, Evaluation and performance comments, Financial data related to the Company (EEA subsidiary or department that they manage) | Recruitment of Job applicants |
Processing documents for sales performance of employees. Confirm and assess sales performance documents from employees and keep the documents | Name, Address, Phone number, Email address, Evaluation and performance comments, Financial data related to the Company (EEA subsidiary or department that they manage) | Analyzing performance valuations of employees |
Product quotation, Shipping and sales records | Name and surnames, Address, Phone number, Email address | Providing product quotation to customers and maintaining shipping/sales records |
Introduce products to customers, confirm requirements for custom-made products | Name and surname, Company address, Company name, Department name, Email address, Telephone number, Customer code | Managing customer data to handle business negotiations, manage order history, and place orders |
Obtain approval for design drawings | Name and surname, Company address, Company name, Department name, Email address, Telephone number, Customer code | Managing customer data to handle business negotiations, manage order history, and place orders |
Identify billing and delivery addresses for customs clearance and shipping | Name and surname, Company address, Company name, Department name, Email address, Telephone number, Customer code | Managing customer data to handle business negotiations, manage order history, and place orders |
Business activities: in order to contact customers and employees, discuss, decide, check, etc., daily tasks relating to business matters | Name and surnames, Company name, Company location, Phone number, Email address | Contacting customers and employees with respect to daily business matters |
Input and manage customer data in Sansan | Name and surnames, Company Address, Company Phone number, Email Address | Contacting business contacts with respect to business activities |
Input and manage customer inquiries, purchases, and claim records on QuickBase | Name and surname, Company name and address for billing and delivery, Contacts (phone, email), Purchase record of company | Providing customer service and order handling |
Processing POS, SAP order entries, and shipping for YEG | Name and surname, Company name and address for billing and delivery, Contacts (phone, email), Purchase record of company | Providing POS, invoice, and shipment handling |
Provide services to deliver customer ordered items | Delivery information and billing information as follows: Company name and address, Name and surnames, Telephone number, Shipping Records | Delivering items to customers |
Process personal data submitted by its EEA subsidiary in order to evaluate performance of FC staff | Name, Address, Phone number, Email address, Evaluation and performance comments. | Analyzing performance valuations of employees |
Process personal data submitted by its EEA subsidiary in order to check their performance and skills | Name and surnames, Address, Phone number, Email address | Evaluating candidates to hire as employees |
Analysis of interest of visitor to the website by using Google Analytics and Salesforce system | Name, Address, Phone number, Email address, Company name, Title, IP address, Cookie | Conducting marketing activities |
Management of customer's information | Name and surnames, Company address, Company phone number, E-mail Address | Conducting marketing activities |
Business communication in normal business activities such as business communications with partners (and not, e.g., sending emails to those who have never contacted the division before) | Name and surnames, Company address, Company phone number, Email address | Using business card information for normal business activities |
Business communication in normal business activities | Name and surnames, Company address, Company phone number, Email address | Using business card information for normal business activities |
Identify customers to negotiate with to: (i) introduce products which meet customer requirements, (ii) confirm requirements and specifications for custom-made products, and (iii) obtain approval of design drawings | Name and surname, Address, Company name, Department name, Telephone number, Email address | Identifying customers to introduce products that meet customer requirements, confirm requirements and specs, and obtain approval for design drawings |
Identify the billing addresses and delivery addresses on the invoices required for customs clearance | Name and surname, Mailing address, Department name, Telephone number, Email address | Identifying billing and delivery addresses for invoices |
Management of the placement of all seconded employees | Name and surnames, Address, Phone number, Email address, Evaluation and performance comments, Passport number, Social security number, Health data (results of general health diagnosis and blood type diagnosis within the range required by Japanese law) | Management of seconded employees |
In order to review accounting process and tax computation of subsidiaries, Japan HQ requires them. | Name and surname, Payroll data: employee name, details of pay (basic, pay, deduction items, e.g. amount of social insurance, withholding tax) | Reviewing accounting processes and tax computations of subsidiaries |
Invoicing and sending inquiries to customers/vendors. | Name and surname, Phone number, Email address, Address | Facilitating communication for invoicing and sending inquiries |
Input and manage customer/vendor data in Sansan | Name and surnames, Company address, Company phone number, Email address. | Using business card information for normal business activities |
For Internet access from company PCs
|
Information used in Exchange such as name, e-mail address, workplace, etc., Name, Email address, Department, Information about where someone accessed using what IP address: Access Web page, Source IP address, Access person | Implementing security measures to protect assets and information and prevent unrestricted access |
Process customer information for sales operation purposes; Some sites include person in charge for reference purposes. | Customer contact person and department information as reference only, German-based employee name | Using the system of ERP |
Used as groupware as a collaboration tool such as SharePoint and Teams in addition to the E-mail service | Employee profile data (name, email address, employee number, title, work address, phone number) | Using collaborative tools such as groupware |
Employee information used for queries to IT and to report problems; used for PC asset management purpose. | Employee profile data (name, email address, employee number, title, work address, phone number) | Implementing IT inquiry ticket system for smooth business operations |
Process personal data stored in this service in order to reset passwords; system management | Employee profile data (name, email address) | Implementing a password reset tool for smooth business operations |
Process personal data stored in this service in order to login to this service; system management | Employee profile data (name, email address), Login ID using email address | Implementing an attachment sending service for smooth business operations and improved security; implementing a password reset remote desktop service for increased efficiency and operating ability |
Stored Office365 data, Stored Azure AD (Active Directory), Mobile management (Intune); system management | Any data stored by employees (personal backup data, account information, email) | Implementing cloud storage for smooth HQ business operations and efficiency |
Used as groupware as a collaboration tool including E-mail service. | Any data stored by employees (personal backup data, account information, email) | Implementing cloud storage for smooth HQ business operations and efficiency |
Identify and share (within group): (i) customers name, location and contact person(s), and (ii) customers' requirements to YOKOWO including project milestones, etc. | Name and surname, Department, Title | Share meeting minutes and promote transparency with respect to customer requirements |
Consent: Our Company collects and processes your personal data for the purposes set forth below, based on your consent according to Article 6(1)(a) GDPR, Article 9(2)(a) GDPR or the EU e-Privacy Directive. You are free to give or refuse your consent, and may change your decision at any time by contacting us by email. If you choose to withdraw your previously given consent, it will not affect the lawfulness of processing conducted prior to such withdrawal.
Purpose | Categories of Personal data |
---|---|
Processing certain cookies on our website, such as through Google Analytics to analyze your interest | Company name, Company address, Name of person, Department, Title, Telephone number, Email, Fax, Cookies |
Direct marketing by email or phone calls | Company name, Company address, Name, Department, Title, Telephone number, Email address, IP Address |
Health maintenance of expats | Health data (results of general health diagnosis and blood type diagnosis within the range required by Japanese law) |
Performance of a contract: Our Company collects and processes your personal data for the purposes set forth below, based on the execution of our contractual relationship with you or in order to enter into a new contractual relationship with you at your instruction, pursuant to Article 6(1)(b) GDPR:
Purpose | Categories of Personal data |
---|---|
Payroll and pay slip issuance | ID card copy, Insurance number, Tax ID, Bank account details (information used within YEG to transfer salary; other information will be used as information for payroll calculation by contacting the tax accountant) |
Legal obligation: Our Company collects and processes your personal data for the following purposes, based on the legal obligations to which we are subject, pursuant to Article 6(1)(C) GDPR:
Purpose | Categories of Personal data |
---|---|
Payroll and pay slip issuance | ID card copy, Insurance number, Tax ID, Bank account details (information used within YEG to transfer salary; other information will be used as information for payroll calculation by contacting the tax accountant) |
For shipping destination survey based on security export regulations | Name, Position, Career (academic and professional background); Email address, Telephone number |
We will process your data for these above-specified purposes and legal bases, and will not further process the data in a way that is incompatible therewith. If we intend to process personal data originally collected for one purpose in order to attain other objectives or purposes, we will ensure that you are informed of this and will solicit your consent where required.
2. Sources and types of personal data
We collect your personal data from the following sources:
- Directly from you: In order to fulfil the above purposes, our Company primarily collects and processes personal data directly from you including your name, shipping address, billing address, telephone number, fax number, e-mail address, bank account or other payment details, title, company name and department, company address, emergency contact, job application information, health data, social security number, passport number, payroll data, etc., which we may obtain when you contact us via webform, phone or email, conduct a questionnaire, purchase our products, give us your business card, meet in-person, etc. If you apply for a job with us, we will also process your resume, employment referrals/recommendations, and other employment related information.
- Indirectly from you: We also collect and process your personal data indirectly, such as when you interact with our Website and/or email us, for our legitimate interests including data analysis, website optimization, marketing, and customer support. In such cases, we may collect and process your personal data including IP address, domain name, browser version, operating system, name, company address, company and department name, email address, telephone number, purchase records, delivery and billing information.
- Third parties: We also process your personal information including name, academic and professional background, resume information, email address, mailing address, customer code, telephone number, company name and department, employee access and account credentials, IP address, cookies, employee evaluation and performance data, purchase records, etc., which we have acquired from third parties including HR companies (Adeni, JAC Recruitment, Fischer HRM, and Centre People), DUNS reports from Dun & Bradstreet, and our YOKOWO Group companies. We process such personal data for our legitimate interests, including those listed under Section 1 above.
3.Disclosure of personal data
Our Company discloses personal data to the following recipients, including third parties and group entities within Our Company, in accordance with the applicable laws:
- Our Company: i.e., YOKOWO CO., LTD.; YOKOWO EUROPE LTD.; and YOKOWO EUROPE GmbH
- Our Company Group entities, both within the EEA and overseas: YOKOWO COMMUNICATION COMPONENTS & SYSTEMS CO., LTD.; YOKOWO PRECISION CO., LTD.; YOUR CONSULTING CO., LTD.; LTCC Materials Co., Ltd.; YOKOWO AMERICA CORPORATION; YOKOWO MANUFACTURING OF AMERICA LLC; YOKOWO KOREA CO., LTD.; YOKOWO MICRO TECH CO., LTD.; YOKOWO (SINGAPORE) PTE. LTD.; YOKOWO ELECTRONICS (M) SDN. BHD.; YOKOWO (THAILAND) CO., LTD.; YOKOWO CORP. (H.K.) LTD.; YOKOWO (HONG KONG) LTD.; DONGGUAN YOKOWO CAR COMPONENTS CO., LTD.; DONGGUAN YOKOWO COMMUNICATION COMPONENTS CO., LTD.; YOKOWO VIETNAM CO., LTD; and YOKOWO MANUFACTURING OF THE PHILIPPINES, INC.
- External Third Parties: AMI Partners (tax accountant); FedEx, DHL, UPS, Pacific Inc, Nippon Express, KWE (forwarders and couriers); Salesforce (CRM software); QuickBase (low-code application development platform); Office 365 (cloud storage, messaging, emails, office tools and integration software); Microsoft Azure (system maintenance); Wadax (rental server); Sansan (business contact database); Google Analytics (analytics services); SBI Business Solutions (sales management software); Ryomo Systems (ERP system support); Citrix (system maintenance); Japan Business Systems (external contractor); Keeper AWS (cloud service); Zscaler (cloud security company); Nextset (system maintenance); Cybozu (system maintenance); Google App Engine (cloud computing platform); and Garoon (enterprise groupware).
4.Cross-border data transfers
In order to conduct our business, Our Company is at times required to transfer personal data from our offices in the EEA to our headquarters (YOKOWO CO., LTD.) and sales branches in Japan or to our overseas affiliates in the United Kingdom, the United States, the Republic of Korea, Taiwan, Singapore, Malaysia, Thailand, Hong Kong, China, Vietnam, and the Philippines. In addition, we may transfer personal data to external third-party service providers located outside the EEA in: Japan and the United States.
Adequacy Decisions pursuant to Article 45 GDPR:- The transfer of your personal data to third parties in Japan is conducted in reliance on the European Commission adequacy decision on Japan.
- Transfers of personal data to (i) Our Company and Our Company Group entities and (ii) third parties other than in Japan, the United Kingdom and the Republic of Korea are made through our conclusion of modernised standard contractual clauses under the GDPR for data transfers from controllers or processors in the EEA (or otherwise subject to the GDPR) to controllers or processors established outside the EEA (and not subject to the GDPR), which were issued by the European Commission on June 4, 2021, pursuant to Article 46.2 GDPR. The third countries to which we transfer personal data on this basis are: Japan, the United States, the United Kingdom, the Republic of Korea, Taiwan, Singapore, Malaysia, Thailand, Hong Kong, China, Vietnam, and the Philippines.
5.Retention of personal data
The retention period of your personal data shall be determined in accordance with applicable law, or as otherwise required in relation to our contractual obligations or to support our legitimate business activities. We shall retain your personal data for no longer than is necessary, after which point we shall promptly, safely and permanently remove the personal data from our records.
6.Rights of data subjects
Under the GDPR, data subjects have the rights listed below.
If you have any questions regarding these rights, please contact Our Company using this Inquiry Form. In addition, if you are dissatisfied with our response to your request or with our processing of your personal data, you have the right to file a complaint with a data protection supervisory authority, and in particular, with a supervisory authority in the Member State of your habitual residence, place of work or alleged GDPR infringement, pursuant to Article 77 GDPR.
- Right to access: You have the right to obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, to seek access to, and a copy of, the personal data undergoing processing, as well as certain related information (Article 15 GDPR)
- Right to rectification: You have the right to demand from us the correction of inaccurate personal data, and the completion of incomplete personal data (Article 16 GDPR)
- Right to erasure: You have the right to demand that any personal data relating to you be erased without delay, when certain legal conditions apply (Article 17 GDPR)
- Right to restriction: You have the right to obtain from us the restriction of processing your personal data, when certain legal conditions apply. If you have obtained restriction of processing of your data pursuant to this right, we will notify you before such restriction is lifted (Article 18 GDPR)
- Right to data portability: You have the right to receive your personal data in a structured, commonly used and machine-readable format, as well as the right to have us transmit such data to another controller without hindrance, when certain conditions apply (Article 20 GDPR)
- Right to object to processing: You have the right to object at any time, on grounds relating to your particular situation, to our processing of your personal data when certain legal conditions apply (however you always have the right to object to processing for direct marketing purposes) (Article 21 GDPR)
- The right not to be subject to automated decision-making: You have the right not to be subject to a decision based solely on automated decision-making (including profiling) insofar as this produces legal or similar effects on you, when certain conditions apply (Article 22 GDPR). Please note that we do not conduct automated decision-making, including profiling.
- The right to withdraw your consent: You have the right to withdraw your previously-given consent at any time. If you choose to withdraw such consent, it will not affect the lawfulness of processing conducted prior to such withdrawal (Article 7(3) GDPR).
If you intend to exercise such rights, please refer to the contact section at the end of this Privacy Policy.
7.Security measures and data breach notifications
We protect your personal data from accidental or unlawful destruction, loss or alteration, as well as from unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed (a "breach"). We use adequate technical and organisational measures which are appropriate to the nature of the personal data being processed, in order to achieve this level of protection (Articles 25(1) and 32. GDPR).
In the event of any breach of personal data transmitted, stored or otherwise processed, Our Company has the mechanisms and policies in place in order to promptly identify, assess and remedy such breach. Depending on the outcome of our assessment, we will make the requisite notifications to the supervisory authorities and communications to the affected data subjects, which might include you (Articles 33 and 34 GDPR).
8.Our records of data processing
We maintain records of all our personal data processing activities in accordance with our obligations under Article 30 GDPR. In these records, we reflect all of the information necessary to comply with the GDPR, including where we might act as a data controller and/or as a data processor.
We will cooperate with the supervisory authorities as required pursuant to Article 31 GDPR.
9.Processing likely to result in a high risk to your rights and freedoms
We have mechanisms and policies in place in order to identify data processing activities that may result in a high risk to the rights and freedoms of our data subjects, including you (Article 35 GDPR). If any such data processing activity is identified, we will assess it internally and either cease such processing or ensure that the processing is conducted in a manner that is compliant with the GDPR and which involves appropriate technical and organizational safeguards.
In case of doubt, we will contact the competent data protection supervisory authority in order to obtain their advice and recommendations (Article 36 GDPR).
10.Cookies
We use cookies on our Website. A cookie is a text file that is stored on your device via internet browsers. Cookies can identify individual browsers and servers used by data subjects from other internet browsers including other cookies.
By using cookies, Our Company can optimize our Website content with users in mind. For example, by using cookies, our Website will remember your details such that you do not need to enter access data each time you visit our Website. Further, Our Company analyses your interest in our products based on your action on our Website for our marketing purpose.
You can prevent our Website's use of cookies at any time by modifying the settings on your internet browser. However, please note that by invalidating our cookies, you may not be able to use all of our Website features.
11.Changes to this Privacy Policy
This policy was established on March 1st, 2022. Our Company may change this policy in accordance with laws and regulations or at our discretion, which changes will become effective upon posting the revised Privacy Policy to our Website. If we make material changes and/or if we intend to process your personal data for a purpose other than as set forth herein, we will provide you with relevant information and will seek your consent where applicable.
12.Contact points for inquiries
For inquiries regarding this Privacy Policy or the handling of personal data by Our Company, please contact us at the details below:
YOKOWO CO., LTD
Our Public Relations & Equity Department in charge of data protection, available at:
Address: JR Kanda Manseibashi Bldg. 14F, 1-25, Kanda-sudacho, Chiyoda-ku,
Tokyo, 101-0041, Japan
Telephone: +81-3-3916-3111
Email: sp@jp.yokowo.com