SONY

PRIVACY POLICY FOR “Sony | Auto Play” APPLICATION

Effective Date: This Privacy Policy was revised and is effective as of October 24, 2023.

This Privacy Policy applies to the “Sony | Auto Play” application (“Auto Play”). This Privacy Poli-cy explains our collection, use, sharing and other practices regarding your data when you use Auto Play.

Auto Play is a mobile application dedicated to wireless headphones from SONY, which can ac-cess the schedule and other notices on your mobile device and start playing music from a linked application in a timely manner.

In this Privacy Policy, we use “SONY,” "we," "us," and "our" to refer to Sony Corporation. “SONY Affiliates” shall mean Sony Group Corporation, which is the ultimate parent company of SONY and any legal entities controlled by Sony Group Corporation. The term “control” in this context means the direct or indirect ownership of at least fifty percent (50%) of the voting interest in such corporation or the power in fact to control the management decisions of such entity.

For the purposes of the GDPR and other applicable data protection laws and regulations where the concepts of "controller" and “processor” are defined, SONY is the "controller" of the Col-lected Data described in this Privacy Policy.

This Privacy Policy only applies to Auto Play and is in addition to any other privacy policy that may apply to your interactions with SONY and SONY Affiliates or any third party, regarding their product, software or service.

1. SUMMARY OF KEY POINTS

2. What information does SONY collect?

SONY collects and uses information or data as described below. Some of this information may be considered personal information under applicable law in your jurisdiction, and it is collected when you choose to provide information to us or automatically when you use Auto Play (collectively, the “Collected Data”).

(i) Information about your device on which Auto Play is installed (the “Installed Device”) and component parts thereof:

  • Device ID which is to be allocated automatically and specifications/features (e.g. product type, manufacturer name, and model name);
  • OS and OS version
  • Language code, country or region, time zone;
  • Operational status of your Installed Device and component parts thereof (e.g. sensors, display); and
  • IP address used by such Installed Device’s internet connection.

(ii) Information about Auto Play:

  • Application ID (assigned to Auto Play by us; it is not a unique identifier which would allow us to identify a specific user);
  • Application version;
  • Time stamp related to the usage of Auto Play on the Installed Device;
  • Information regarding your operation and usage of Auto Play on the Installed Device, including total time for your operation and usage, signals that trigger the start of playing music, and execution history of other support functions such as switching playlist, audio notifications and textto speech feature, while SONY will not collect or access the contents of the music you listen to, your playlist, notifications or the text-to speech. Call starting time and ending time logs relating to your usage of Related Device may be used to generate signals, while SONY will not collect or access information about call destination or the content of calls. Your linked application calendar settings (i.e availability) will be also used as such signals, while SONY will not collect or access the content of your schedule or calendar. Auto Play will access location data in your Installed Device. Such location data is used to generate signals for when you start or stop moving, which will trigger the start of music playing at appropriate times. SONY will not collect or access location data.
  • Information regarding settings and usage of your linked audio applications (Endel, Spotify, Apple Music etc. ), while SONY will not collect or access the contents of your music you listen to); and
  • Information about your environment collected in questionnaires.

(iii) Information about your headphone product(s) connected to the Installed Device and detected, or registered to Auto Play (“Related Device”):

  • Device IDs (such as, Bluetooth address and the identifier which is to be automatically allocated at the time of registration) and specifications/features (e.g. product type, device name, manufacturer name, and model name).
  • The Related Device will also be detected if it is connected to an Installed Device while Auto Play is not running. If a detected related device is not one registered with Auto Play, no further processing will occur.

3. How does SONY use the Collected Data?

SONY uses the Collected Data to provide you the features and functions of Auto Play and the related services, to answer your inquiries and to provide requested service. In addition, SONY uses your Collected Data for the following purposes:

(i) Improving/developing SONY´s products and services

SONY uses the Collected Data to improve and develop SONY’s current and future products and services, and it will be linked and analyzed in conjunction with the data we collect through other SONY audio applications if you use one of those. For the collected data through those applications, please refer to the privacy policies for those applications or services.

Product improvement and/or development includes those activities relating to either an improvement of the technical functions of Auto Play and/or the Related Device or the usability of such product(s) for the user´s convenience.

Please note that your consent forms the legal basis for SONY processing Collected Data for improving/developing SONY’s products and services under European data protection law . Where you select “Agree” on “Product and service improvement” section of the privacy setting, then we process the Collected Data because you have given us your consent.

(ii) Marketing strategies and forecasting

SONY uses the Collected Data for marketing strategies and forecasting, but not for marketing communications. The Collected Data will be linked and analyzed in conjunction with the data we collect through other SONY audio applications if you use one of those. For the collected data through those applications, please refer to the privacy policies for those applications or services.

Please note that the legal basis under European data protection law for SONY processing Collected Data for the purpose of marketing strategies for forecasting is SONY’S legitimate interest in learning what advertising and marketing strategies are effective.

(iii) Compliance with Law

SONY Processes the Collected Data in order to comply with applicable law and regulations including a) responding to requests from government or public authorities, law enforcement officials, courts or regulators conducting an investigation and b) to enforce compliance with our terms of use and other policies and to help other organizations (such as copyright owners) to enforce their rights in accordance with our legal and regulatory obligations under applicable laws.

Please note that the legal basis under European data protection law for SONY processing Collected Data for the purpose of complying with applicable law and regulations is SONY’S legitimate interest to comply with a legal obligation.

4. Who else has access to the Collected Data?

We do not share personal information with unaffiliated third parties for their own marketing purposes but we will share aggregate data and de-identified data with third parties. In addition, SONY will share Collected Data with SONY Affiliates and third parties as follows:

SONY Affiliates

The Collected Data will be shared at aggregate level with and used by SONY Affiliates for internal business purposes such as marketing strategies and forecasting and for product and service improvement and development, and it may be linked and analyzed in conjunction with the data we collect through other Sony audio applications if you use one of those.

SONY will otherwise share Collected Data with SONY Affiliates for other purposes set out in this Privacy Policy.

If you contact your local SONY Affiliate in relation to queries about Auto Play, or for repair or return requests of Related Devices we will also need to share Collected Data with that SONY Affiliate in connection with that request.

Service Providers

SONY and SONY Affiliates will use third party service providers to process the Collected Data on their behalf for the purposes set out in this Privacy Policy(these are IT service providers and data hosting providers). Our hosting provider is Amazon Web Services in the US, acting as our processor.

Business transfer

In the event that SONY or a SONY Affiliate sells or transfers a portion or all of its business, the Collected Data will be transferred by SONY or such SONY Affiliate to the purchasing or acquiring entity as part of the transaction, including any due diligence process connected to the sale or transfer.

Government Authorities/ Law Enforcement Officials/Regulators or courts

Collected Data will be disclosed to government authorities, law enforcement officials, regulators or courts for the purposes outlined in Section 3 above.

Other Unaffiliated Third Parties

We will disclose Collected Data to auditors or similar external consultants like lawyers or tax advisors, to defend and exercise our legal rights (e.g. enforcing compliance with the terms of use) and as we believe necessary to comply with our legal obligations.

Google services

Firebase crashlytics: Auto Play uses Firebase Crashlytics, a service provided by Google Inc. (“Google”) .Collected Data is shared with Google to analyze the crash reports and fix Auto Play’s stability issues. For further information on Firebase Crashlytics, visit: Firebase Crashlytics | A powerful Android and iOS crash reporting solution (google.com)

To better understand how Google uses the information it receives, visit: https://policies.google.com/privacy.

Google Maps SDK: Auto Play accesses location data in your Installed Device. It uses Google Maps SDK to generate signals for when you start or stop moving, which will trigger the start of music playing at appropriate times. For clarity, SONY will not collect or access location data. To better understand how Google uses the information it receives, visit: https://policies.google.com/privacy. Please also see terms of service for the details on Google Maps SDK : https://maps.google.com/help/terms_maps.html

5. Data Retention

SONY will keep the Collected Data for as long as it is necessary for the relationship with you and the purposes detailed in Section 3 or otherwise permitted or required under applicable law.

SONY will retain Collected Data for an appropriate period to protect ourselves from legal claims, to administer our business, or to the extent permitted by applicable law, which may re-quire us to hold the relevant Collected Data for specific periods.

With regard to Collected Data which is processed based on your consent declaration, SONY will apply a maximum of twenty-seven (27) months retention period from the date of the collection of the Collected Data.

If you have any questions about SONY’s data retention practices please contact SONY at www.sony.net/SonyInfo/Support/.

6. Transfer of the Collected Data internationally and Consent to processing

The Collected Data will be processed, stored and transferred for the purposes outlined in Sec-tion 3 to countries/regions outside the European Economic Area (EEA) and the UK and/or your country/region of residence, including in particular Japan and the United States.

Where information is transferred out of the European Economic Area (EEA) and the UK, to us or a third party in connection with the purposes set out in this Privacy Policy, we will, to the extent that no statutory level of security comparable to the European data protection laws exists in such countries/regions, and where this is to a stakeholder or vendor in a country that is not subject to an adequacy decision by the European Commission or the UK Government, adopt appropriate measures to ensure that your personal data will be adequately protected in these countries/regions. In particular, we may apply the standard contractual clauses approved by the European Commission, which can be accessed here the addendum to the EU Commission’s standard contractual clauses or standalone international data transfer agreement approved under the UK data protection law (as applicable) or a stake-holder’s/vendor’s Processor Binding Corporate Rules. Where the Collected Data is transferred to Japan, the adequate level of data protection is confirmed by the European Commission´s ad-equacy decision.

If you have questions or concerns about SONY's data transfer arrangements, or if you require a copy of the relevant mechanism, please contact us as described in Section 11 “Contact us” below.

7. Security

SONY undertakes reasonable security measures designed to protect against the loss, misuse or alteration of the Collected Data. Although SONY strives to protect the Collected Data, SONY cannot guarantee or warrant the security of any Collected Data transmitted to SONY through Auto Play or that SONY stores on its systems or that is stored on SONY’s third party contractors' systems.

8. Children’s privacy

SONY is committed to complying with all applicable laws and regulations regarding the collection, storage and use of the Collected Data concerning children, including the Children's Online Privacy Protection Act in the United States.

Auto Play is intended for a general audience; Auto Play is not directed to and does not knowingly collect personal information from children younger than age of 16. Depending on your country/region of residence, this threshold age for a child may differ.

If you are a parent or guardian and are concerned that your child has provided SONY with personal information (as defined by applicable law), you should contact us as indicated in Section 11 “Contact us” below.

9. Changes/Policy Governs Use

SONY reserves the right to make changes to this Privacy Policy and will notify you of any changes by prominently posting notice of the amendment on or within Auto Play. We may also provide notice to you in other ways, such as through contact information you have provided. You are advised to consult the posted Privacy Policy regularly for any changes.

10. Privacy Rights

In some countries/regions, you have certain rights with respect to the Collected Data SONY holds about you. These will include the right to request a copy of the Collected Data that SONY holds about you and/or the right to request that SONY amends, deletes, blocks/restricts or corrects such Collected Data if it is inaccurate. You will also have the right to ask us to provide some types of the Collected Data to you, or another organization nominated by you, in a struc-tured and machine readable format. In addition, you can object to the processing of the Collected Data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement).

With regard to your Collected Data that we process if you are located in the EU/EEA, UK, you will have the following rights :

  • You have the right to access (including a copy of) your Collected Data ; to correct, delete or restrict processing of your Collected Data ; and to obtain the Collected Data you provide to us for a contract or with your consent in a structured, machine readable format, and to ask us to share (port) this Collected Data to another controller.
  • In addition, you can object to the processing of your Collected Data in some cir-cumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement, or where we are using the data for direct marketing ).
  • Where we have asked for your consent, you may withdraw consent at any time. If you ask to withdraw your consent to SONY processing your data, this will not affect any processing which has already taken place at that time. You can with-draw your consent above at any time by selecting three dots “…” on Auto Play and then search in “Information” > “About Apps”.
  • Finally, you may have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or other similar material effects ("Automated Decision-Making"). Please note that Automated DecisionMaking currently does not take place on the SONY’s systems with regard to Collected Data for the purposes of pursuing the activities outlined in “Section 3 (How does SONY use the Collected Data)".

These rights may be limited, for example if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping.

If you would like to exercise any of these rights, please contact SONY at www.sony.net/SonyInfo/Support/

You also have the right to lodge a complaint to a supervisory authority for data protection in the country/region where you live, where you work, or where you consider that a breach of data protection has occurredalthough we hope that we can assist with queries or concerns you may have about our use of the Collected Data.

11. Contact Us

This Privacy Policy applies to: SONY as a data controller. SONY's address is 1-7-1 Konan Minato-ku, Tokyo, 108-0075 Japan.

If you have any questions or concerns about this Privacy Policy, or if you wish to exercise any legal right you may have in respect of the Collected Data, please contact us at www.sony.net/SonyInfo/Support/

If you are in the EEA:

Sony Corporation, a Japanese company, is the controller for the Collected Data. Our repre-sentative in the EEA is Sony Europe BV, a Dutch company, whose business address is Taurusave-nue 16, 2132LS Hoofddorp, the Netherlands. If you have any concerns about how we process your data, you can contact our representative in the EEA by email-ing:privacyoffice.SEU@sony.com. You can also get in touch by writing to Sony Europe BV at the address above or at The Privacy Office c/o Sony Europe Legal Department, The Heights, Brooklands, Weybridge, Surrey KT13 0XW, The United Kingdom, or you can contact your local Sony company at https://www.sony.co.uk/locale-selector.

If you are in the United Kingdom:

Sony Corporation, a Japanese company, is the controller for the Collected Data. Our representative in the UK is Sony Europe BV, a Dutch company, whose UK branch has its business address in The Privacy Office, The Heights, Brooklands, Weybridge, Surrey KT13 0XW, The United Kingdom. If you have any concerns about how we process your data, you can contact our repre-sentative in the UK by emailing:privacyoffice.SEU@sony.com. You can also get in touch by writing to The Privacy Office c/o Sony Europe Legal Department, The Heights, Brooklands, Weybridge, Surrey KT13 0XW, The United Kingdom, or you can contact your local Sony company at https://www.sony.co.uk/locale-selector.