ABCDEFG

Information Sheet Pursuant to the EU Data Act (Regulation (EU) 2023/2854)

For Networked Products and Connected Services

1. Purpose and Scope

This information sheet serves to fulfill the transparency obligations pursuant to Art. 3 et seq. of the Data Act. In particular, it describes the nature, scope, and purpose of the data generated by IoT devices, as well as the rights of access and disclosure regarding such data.

Scope: OASE Control App, OASE WiFi Controller, and connected IoT devices and cloud services.


2. Categories of Data Generated 

The following categories of data are generated during use:

  • Usage data (e.g., account data, interactions, configurations)

  • Operational and status data (e.g., runtime, error codes)

  • Measurement and sensor data (e.g., temperature, consumption values)

  • Diagnostic data (e.g., crash reports, if enabled)

The data is generated automatically through the use of the product within the meaning of Article 2(1) of the Data Act. If you do not wish to have any interactions between the OASE controller and the OASE Cloud, you can disable this feature in the settings.

The exchange of general usage data between the OASE app and the OASE Cloud is necessary to ensure the system functions properly. This applies, among other things, when using multiple control devices to synchronize the account.

Security-related access information (e.g., cryptographic keys or device passwords) is provided only to the extent permitted by the EU Data Act and in accordance with IT security requirements.


3. Data Ownership and Access Rights

The user is considered the authorized data owner within the meaning of the Data Act. OASE ensures:

  • Access to data via the app or export function

  • Provision upon request in a structured format

  • Review of third-party access requests on a case-by-case basis

Entitlement exists only to the extent provided by law.

Access credentials for external networks (e.g., the user’s Wi-Fi login credentials) are generally not subject to data access as described in this information sheet.

Device-internal authentication information is used exclusively for secure communication between the app and the device.


4. Technical Provision and Interfaces 

Provision is primarily via:

  • In-app access

  • Export functions (e.g., JSON/ZIP). The format provided depends on technical capabilities and the legal requirements of the EU Data Act.

  • Support-assisted provision

API-based provision is provided only to the extent that it is technically and legally necessary.

If devices within a user account are shared with other authorized individuals, the data required for access management will be processed for this purpose.


5. Storage and Processing

Primary processing takes place in Microsoft Azure (EU region). Transfers to third countries, such as the U.S., may occur within the framework of subcontracting arrangements and are based on standard contractual clauses.

Retention periods:

  • Cloud: For the duration of the contractual relationship. Device-specific statistical data from the sensors can be deleted individually for each device.

  • Local: Until uninstallation or logout

Deletion occurs immediately upon request, no later than within 7 days.

To the extent that the Terms of Use provide for the deletion of inactive user accounts, the time limits described therein apply in addition.


6. Disclosure to Third Parties

Disclosure will occur exclusively:

  • at the user’s request

  • to fulfill the contract (data processor)

  • when required by law

Oase does not disclose data for its own commercial purposes.


7. Related Services and Third-Party Providers

Services used include, in particular:

  • Microsoft Azure (hosting) (Cosmos DB)

  • Google Firebase Crashlytics (Usage occurs only after activation by the user)

  • Twilio SendGrid (sending transactional, verification, invitation, and system emails)

Optional integrations (e.g., Alexa, Google Home) are only enabled after the user actively connects them.


8. Use of Data by Oase 

Oase uses data exclusively for:

  • Operating and providing the services

  • IT security

  • Error analysis

  • Product improvement (aggregated/anonymized): Aggregated or pseudonymized product and usage data may be used for statistical analysis and the further development of our products.

No use for any other purposes.


9. Restrictions on Data Access 

Access rights may be restricted if necessary to protect:

  • Trade secrets

  • IT security

  • regulatory requirements

This is done in accordance with Article 4 of the Data Act.


10. Relationship to the GDPR

The Data Act supplements the GDPR. Personal data is processed exclusively in accordance with the GDPR. Data subjects’ rights remain unaffected.


11. Identity of the Data Controller

Oase GmbH
Tecklenburger Str. 161
48477 Hörstel
Germany


12. Contact Information and Rights 

If you have any questions about the EU Data Act or about accessing your device data, please contact:

Contact

Depending on country

Web

Data subjects’ rights under the GDPR remain fully in effect.

Right to lodge a complaint with supervisory authorities pursuant to Art. 77 of the GDPR.


13. Final Provisions

This document serves to fulfill regulatory requirements and does not replace any contractual agreements or privacy policies. Further information on the processing of personal data, in particular regarding legal bases, recipients, and data subject rights, can be found in the privacy notice.

For clarity, this document has been simplified. The exact legal wording can be found in the EU Data Act.

Appendix 1: Connected OASE Products

Standalone

Data Type

Time Interval
A User Action
(Event-based)
C State change

Garden Controller

No

Settings and statuses of connected devices, connection status, device configuration

1 MB / year

Operational and status data

Within 2 minutes

Alarms/error statuses

A, usually within 15 seconds

Temporarily stored locally on the controller every 5 minutes; transmitted to the cloud every 60 minutes;
If any of the aforementioned events (alarms/error statuses, voice assistant) occur within the periodic interval, the measurement and sensor data are transmitted along with the aforementioned data.

Configuration changes

A; no later than 5 minutes. Actual intervals may vary depending on device type, network quality, operating mode, and user settings.

Control

A; within 5 minutes at the latest. The actual intervals may vary depending on device type, network quality, operating mode, and user settings.

Outlet

No

On/Off

A, usually within 15 seconds

Pump

Yes

A, usually within 15 seconds

Filter

Yes

A, usually within 15 seconds

Lights

Yes

A, usually within 15 seconds

Aquarium controller

No

Aquarium LED

Yes


Data Security (Data Act) | Oase