Privacy policy
Embodme attaches great importance to the protection of your personal data.
This privacy policy describes how we collect and process your personal data.
The personal data contains all the information concerning an identified or identifiable physical individual.
This privacy policy explains how Embodme collects and processes your personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, or GDPR) and applicable French data protection law.
data controller
The controller responsible for processing your personal data is EMBODME SAS, 81 rue des poissonniers, 75018 Paris, France (RCS Paris 843 725 714). For any question about your personal data or to exercise your rights, you can contact us at [email protected].
article 1: collection
Embodme , by collecting and processing your personal data, is responsible for the processing of personal data as required by national legislation concerning the protection of personal data. The personal data that is collected contains the information that you provide us with when you fill out a form to open an account on our site, whenever you purchase products on our website or whenever you contact us. This information is in particular contact information, such as your name, your address, your telephone number, your email address. Also collected as part of this process are details about orders, purchases, deliveries, invoices etc. Personal data may also be collected automatically when you visit our website or open an account. This data may be obtained through the use of cookies that you have accepted when you enter our site and cookies which come from third-party sites. The connection data, such as your IP address or your browsing history may also be collected. The data which is collected is sent to the Sales Department at Embodme.
article 2: purpose / use
2.1) purpose of the collection and the processing of personal data
The reason that we collect and process your personal data is to allow us to improve our products, to provide you with a customer service, to make your visit to the site a more personal experience, to allow you to save your shopping cart, manage your orders, and with your consent, to send you promotional messages and other information about us.
2.2) sales canvassing
In the absence of your agreement, we undertake not use your personal data for sales canvassing purposes. You can unsubscribe and opt out of receiving promotional messages by changing the settings on your account.
2.3) legal basis for processing
We process your personal data on the following legal bases: the performance of our contract with you (creating your account and managing your orders, deliveries and after-sales service); your consent (analytics and advertising cookies, and marketing emails), which you may withdraw at any time; our legitimate interest in improving our products and keeping our site secure; and compliance with our legal obligations, in particular accounting and tax record-keeping.
article 3: cookies
A cookie is a small file stored on your device that records information about your browsing. When you first visit our site, a consent banner lets you accept or refuse non-essential cookies. Essential cookies (needed for the shopping cart, security and remembering your language choice) are always active, because the site cannot work without them. Analytics and advertising cookies (Google Analytics, Google Ads, Google Tag Manager and the Meta/Facebook pixel) are placed only after you have given your consent, and never before. You can change or withdraw your choice at any time using the 'Cookie settings' link in the footer of the site. Your consent choice is stored for six (6) months, after which you will be asked again.
article 4: duration of conservation of data
We keep your personal data only for as long as necessary for the purposes for which it was collected: account and contact data are kept for three (3) years after your last activity; order and invoicing data are kept for ten (10) years to meet our legal accounting and tax obligations; and your cookie consent choice is kept for six (6) months. At the end of these periods your data is deleted or anonymised.
article 5: right of access and rectification, modification
In accordance with the GDPR, you have the right to access your personal data and to obtain its rectification, erasure or portability, as well as the right to restrict or object to its processing and to withdraw your consent at any time (without affecting processing carried out before withdrawal). You may exercise these rights by logging into your account or by emailing [email protected]; we may take appropriate steps to verify your identity first. You also have the right to lodge a complaint with the French supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL, www.cnil.fr), or with the supervisory authority of your country of residence.
article 6: disclosure
Your data will not be sent to third parties, and in particular to our commercial partners, without your express consent. In certain cases, we may be forced to release your data in accordance with mandatory legal provisions. Data may in particular need to be sent to public authorities, as part of a police investigation, or to financial organisations in particular with regard to payments.
article 7: security
We guarantee that we take every appropriate precaution to preserve data security so as to prevent the data from being damaged or tampered with or unauthorized third parties from gaining access and misusing the data. As part of our security measures we use data encryption using SSL (Secure-Socket- Layer) software, and firewalls. If you think that your account may have been pirated, please contact us at the following [email protected]
article 8 - third-party services
We hand over information that we receive to third parties solely for the purposes described in the following:
a. In certain circumstances, under force of law, Embodme must disclose information to third parties. This occurs notably when law enforcement authorities oblige Embodme to disclose information relating to a suspected crime or abuse. Cases regarding companies who are inquiring about credit card abuse are included.
b. Google Analytics
Google Analytics is a web analytics service provided by Google, Inc. that Embodme uses to help analyze how the site is used; this service uses cookies that generate information about your use of the website, which is then transmitted to and stored by Google on servers in the United States. This information will be used by Google to evaluate your use of the website, compiling reports on website activity for Embodme and providing other services relating to website activity and internet usage. To opt out of this so that your activity on this website is not tracked, follow this link: https://support.google.com/ads/answer/2662922?hl=en
c. Google - Remarketing
Re-marketing is Google’s program for “interest-based advertising”, which Embodme uses within the scope of its marketing operations. A special browser cookies is stored on the user’s computer in order to complete this process. This allows Embodme, Google or third-party services to serve users special ads when visiting other websites.
d. Facebook
Our site uses the Meta (Facebook) pixel to measure the performance of our advertising and to show you relevant ads on Meta platforms. The pixel loads only after you have given your consent, and may set cookies and transmit data to Meta Platforms Ireland Ltd and to Meta in the United States. You can withdraw your consent at any time using the 'Cookie settings' link in the footer, and you can manage your advertising preferences in your Facebook account settings.
e. PayPal and BNP
Financial transactions are handled by our payment service providers: BNP and PayPal. We will only share transaction data with them for the purposes of processing your payments and refunds.
f. Happyfox
Embodme uses Happyfox for processing submitted requests to our customer service. The services are offered by the company Happyfox Inc., Irvine, California. Further information can be found in Happyfox's privacy policy: https://www.happyfox.com/privacy-policy/
g. MailChimp
Embodme uses Intuit Mailchimp to send newsletters and targeted emails. This service is provided by The Rocket Science Group LLC (an Intuit company), 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA. Where your personal data is transferred to the United States, the transfer is governed by the EU-U.S. Data Privacy Framework and/or the European Commission's standard contractual clauses. Further information can be found in Mailchimp's privacy policy: https://mailchimp.com/legal/privacy/
international data transfers
Some of our service providers (in particular Google, Meta, Mailchimp and Happyfox) are located in the United States. When your personal data is transferred outside the European Union / European Economic Area, we ensure an adequate level of protection by relying on a European Commission adequacy decision (including the EU-U.S. Data Privacy Framework) or on the European Commission's standard contractual clauses.
community forum and imported discussions
Our community forum includes discussions that were originally posted on our previous support forum and migrated to this platform so that this shared knowledge remains available to Erae users. To protect the people who wrote them, these historical posts are displayed under a neutral label ('Erae community member') instead of the original author's name. If you are the author of such a post, you can create an account on this site using the same email address you used on the previous forum to claim your posts and have them shown under your account. We retain the email address linked to a migrated post solely to make this matching possible, and only for a limited period, after which it is deleted. The legal basis for this processing is our legitimate interest in maintaining a continuous community knowledge base. You can ask us to remove your migrated posts or the associated email address at any time by writing to [email protected].
crash and diagnostic reports
Erae Lab and Erae Sound can send us a report when something goes wrong, so that we can find the cause. What is sent depends on the Diagnostics setting in the software. Without identifiers, the default, is a snapshot of the application's memory taken when it closes unexpectedly, from which file names under your home folder, your user name and your environment variables have been removed, together with the list of loaded software modules, your Erae settings and a short timeline of the last events. It carries no log text, no preset or project name and no machine identifier, and the address of the connection is not stored with it. Full is that same snapshot plus the recent application log, the state of the host application, preset and project names, and the machine identifier (the same one used for licence activation, shown in Erae Lab as 'Machine id'), so that our support team can match the report to your messages; it is also sent when the software detects a device or sync problem. Off sends nothing automatically. Reports can include file names and the names of the other audio plugins loaded next to our software.
Reports sent under 'Without identifiers' are processed on the basis of our legitimate interest (Article 6(1)(f) GDPR) in keeping our software stable and safe to use. You can object at any time by setting Diagnostics to 'Off' in Erae Lab or Erae Sound. Full reports are sent only with your consent (Article 6(1)(a) GDPR), given by answering Yes to the prompt shown once when you first use the software, and you can withdraw that consent at any time in the same setting.
Crash reports are stored in a private location, are never made public and are deleted after 180 days. Because a report without identifiers holds nothing that points to a person, we are not able to link it to you, to retrieve it for an access request or to remove it in answer to an erasure request (Article 11 GDPR). Full crash reports can be found and deleted on request. For anything concerning crash reports, write to [email protected].
update checks and usage statistics in Erae Lab and Erae Sound
When Erae Lab checks for updates, which it does whatever the Diagnostics setting, it sends us the application version, its release channel (release or nightly), your operating system version, the current Diagnostics setting and, when an Erae is connected, its model (Erae Touch or Erae 2) and firmware version, so that we can offer you the right updates. We count these checks per day to know which versions of Erae Lab and which Erae models and firmware versions are in use, so that we can prioritise fixes and support. What else happens depends on the Diagnostics setting. With 'Off', update checks still happen but are only included in anonymous daily totals of update checks; they are not counted as users. With 'Without identifiers', and also with 'Full', each update check is counted towards a daily number of unique users: our server computes a pseudonymous code from the IP address and technical details of the request (application, platform and operating system), using a key that changes every day and is destroyed afterwards. The code is deleted within 48 hours and only daily totals are kept. We never store your IP address. With 'Full', Erae Lab also sends a usage message at most once a day when it starts, and once a day for each Erae model you connect, containing the same information together with your machine identifier: the same identifier used for licence activation and crash reports, so these records are linked to your licence and to your crash reports when you have them. With 'Full', this message also lists the names of the MIDI controllers you use with Erae Lab, as your system reports them (maker and model where available); network, virtual and personally named ports are left out. Also with 'Full', Erae Sound sends its own usage message naming the DAW it runs in and its plugin format, never your project, track or file names. Neither update checks nor usage messages contain your Erae serial number, your name, your email address, your user name or any file path.
Usage messages carrying your machine identifier are sent only with your consent (Article 6(1)(a) GDPR), given by choosing 'Full' in the Diagnostics setting. You can withdraw that consent at any time by choosing another setting, after which the machine identifier is no longer sent; records already received are kept until they are deleted after 13 months, unless you ask us to delete them sooner. Update checks, their daily totals and the daily count of unique users are processed on the basis of our legitimate interest (Article 6(1)(f) GDPR) in offering you the right updates and knowing how many people use which versions and Erae models. You can object to being counted as a user at any time by setting Diagnostics to 'Off'.
Records linked to a machine identifier are deleted after 13 months. The pseudonymous codes used to count unique users are deleted within 48 hours, and because the daily key is destroyed, we cannot link them to you (Article 11 GDPR). Daily totals of update checks and of unique users hold no identifier and are kept for at most 25 months. To access or delete the usage records linked to your computer, send us at [email protected] either the identifier shown in Erae Lab under 'Settings', in the 'DIAGNOSTICS' section, next to 'Machine id' (use its 'Copy' button), or the email address of your licence.