Last updated on February 28, 2019
TOYOTA PRIVACY NOTICE
Toyota (“we”, “our”, or “us”) is committed to protecting your privacy. Whether you deal with Toyota as a customer, consumer or as a member of the general public, you are entitled to the protection of your Personal Data. This Toyota Privacy Notice (“Notice”) describes the categories of Personal Data we process in connection with your use of any of the websites available at global.toyota, www.toyota.co.jp, www.toyota-global.com, www.lexus.jp, www.discoverlexus.com, www.toyotagazooracing.com, www.toyota-dreamcarart.com, www.toyota-insidedreams.com, www.mobilityforall.com (“Websites”) and the services, features or content we offer (“Services”), the purposes for which Personal Data is collected, the parties with whom we share it, the security measures we take to protect your data, in particular in the event of international data transfers. It also informs you about your rights and choices with respect to your Personal Data, and how you can contact us to inquire about our data protection practices. Please read this Notice carefully. In the event you disagree with any provision in this Notice, please do not use our Websites or provide any Personal Data. This notice may change from time to time, for more information about Notice amendments see Section 11 below.
For the purpose of this Notice
Toyota Motor Corporation (“Toyota”)
1 Toyota-cho, Toyota city
Aichi, 471-8571, JAPAN
is responsible for the processing of your Personal Data as Data Controller.
We have set up a Data Protection Contact Point that will handle any questions or requests you may have concerning this Notice, your Personal Data, and its processing.
For any questions, requests or complaints concerning the application of this Notice or for exercising your rights, as described in this Notice, you can contact us at the Data Protection Contact Point:
Data Protection Contact Point
Information Security Management Department
Toyota Motor Corporation
1 Toyota-cho, Toyota city,
Aichi, 471-8571, JAPAN
“Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
When visiting our Websites you have the option to provide us with Personal Data relating to you. Additionally, when you use our Services we automatically collect certain information about you and your internet usage. The specific categories of Personal Data concerned and the sources from which we obtain them are linked to the way you interact with our Websites and Services. More information about the categories of Personal Data and the ways in which we collect it are described below.
(1) Personal Data You Give to Us Our Websites offer you the possibility to (i) participate in our offers and programs, including a request for filling out our valuation and forms, (ii) make and amend your booking for our services, including for Toyota Kaikan and Plant tour, Toyota Rent-a-Car, and others offered in Japan, (iii) contact us via phone call or email, or otherwise provide information directly to us, and/or (iv) interact with us in social media. The Personal Data thereby collected includes:
(2) Personal Data We Automatically Collect As you navigate through our Websites, we use automatic data collection technologies to collect certain Personal Data about your device, browsing activity, and patterns, including:
Our Websites use single-session (temporary) and multi-session (persistent) cookies. Temporary cookies last only as long as your web browser is open, and are used for technical purposes such as enabling better navigation on our Websites. Once you close your browser, the cookie disappears. Persistent cookies are stored on your computer for longer periods and are used for purposes which include tracking the number of unique visitors to our Websites and Personal Data such as the number of views a page gets, how much time a user spends on a page, and other pertinent web statistics. This Personal Data identifies your browser to our servers when you visit the Websites.
(4) Social Media Plugins When using our Websites we allow you to share information with social media sites and to access our social media profiles through so-called plugins. Social networks are able to retrieve Personal Data through those plugins, even if you don’t interact with them. Moreover, if you are logged onto a social network while visiting our Websites with social plugins imbedded in them, the network can collect and store information about such visit and link it to your social network user account. As we have no control over the data collected by social media networks through their plugins, we encourage you to read their applicable data privacy policies to learn more about them.
Once you choose to share information of our Websites on social media or when you connect with our social media profiles through the plugins, those social media sites allow us to automatically access Personal Data retained by them about you consisting of content viewed by you, content liked by you and information about the advertisements you have been shown or have clicked on. You can restrict our access to your Personal Data by changing your privacy setting on the respective social media site.
Lastly, you can access our Websites via a third-party service, e.g. from our profiles on social networks. In those cases, we collect Personal Data from your social media user account consisting of your first and last name, email address and phone number and any other information you have made public.
We will only process your Personal Data for specific, explicit and legitimate purposes. We will not process your Personal Data for any further purposes than the ones the data was originally intended for, unless the new purpose is compatible with the original one. In the absence of compatibility, the processing of Personal Data for further purposes is subject to your prior explicit consent.
The following table lists the purposes for which we your Personal Data and the legal basis we rely on:
We will not retain your Personal Data for longer than is allowed under the applicable data protection laws or for longer that is necessary in relation to the purposes for which it was originally collected or otherwise processed. As a general rule, we will delete your Personal Data after 3 years, unless statutory retention periods apply.
In the absence of statutory retention periods, alternatively after completion of those periods, we will erase your Personal Data. Further, we will erase your Personal Data where one of the following applies: (i) when you withdraw your consent (where lawfulness of processing was based on your consent) and there is no other legal ground for the processing; (ii) when you object to the processing and there are no overriding legitimate grounds for the processing; (iii) when your Personal Data has been unlawfully processed; and (iv) when it is necessary to comply with legal obligations.
We have taken into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, and implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
For the purposes for which we collect your Personal Data, we may disclose it to the following categories of recipients:
If you purchase a car or another product or service from one of our Authorised Retailers or Authorised Repairers or if you give them your Personal Data, you will have a separate relationship with this Authorised Retailer or Authorised Repairer. In this case, they are the data controller of your Personal Data. For all questions or requests about the collection and use of your Personal Data by one of the Authorised Retailers or Authorised Repairers, please contact them directly.
International data transfers refer to transfers of Personal Data outside of the European Economic Area (“EEA”). We are a company with operations around the world. Accordingly, our business requires the transfer of Personal Data to and from other group companies or third parties, which may be located outside the EEA, including Japan. We will only transfer Personal Data to countries that provide for an adequate data protection standard meeting the requirements as set out by the European Commission. Data transfers to countries not meeting that threshold will only occur in accordance with international data transfer agreements based on EU Standard Contractual Clauses.
We want to be as transparent as possible with you, so that you can make meaningful choices about how you want us to use your Personal Data.
We remind you that you can at any time exercise certain data protection rights:
Any requests related to the above rights can be made by sending an email to the Data Protection Contact Point listed above.
Your choices on how you want to be contacted
In this context, you can make a variety of choices about how you want to be contacted by us, through which channel (for example, email, mail, social media, phone, etc.), for which purpose and how frequently, by adjusting the privacy settings on the relevant device or updating your user or account profile or by following the "unsubscribe” instructions included in the communication.
We reserve the right to amend this Notice from time to time consistent with applicable data protection laws and regulations. Any changes to this Notice will be posted on this page. If we make material changes to how we treat your Personal Data, we will notify you through a new version of this Notice on the website home page. The date this Notice was last revised is identified at the top of the page.