ABCDEFG

Informationsblatt nach EU Data Act (VO (EU) 2023/2854)

For connected products and linked services

Publisher: OASE GmbH

Version: 2.2

Stand: 07/2026


1. Introduction 

The following information is intended to provide you, as a ‘data subject’, with an overview of how we process your personal data and of your rights under data protection legislation. In principle, it is possible to use our website without providing any personal data. However, if you wish to make use of specific services offered by our company via our website, the processing of personal data may be necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we will generally seek your consent. 

The processing of personal data, such as your name, address or email address, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to “OASE GmbH”. Through this privacy policy, we wish to inform you about the scope and purpose of the personal data we collect, use and process. 

As the data controller, we have implemented numerous technical and organisational measures to ensure the most comprehensive possible protection of the personal data processed via this website. Nevertheless, internet-based data transmissions may, in principle, be subject to security vulnerabilities, meaning that absolute protection cannot be guaranteed. For this reason, you are free to provide us with personal data via alternative channels, such as by telephone or post. 

You too can take simple and easy-to-implement measures to protect yourself against unauthorised access to your data by third parties. We would therefore like to provide you with some advice on how to handle your data securely:  

  • Protect your account (login, user or customer account) and your IT system (computer, laptop, tablet or mobile device) with secure passwords. 

  • Only you should have access to these passwords. 

  • Ensure that you only ever use your passwords for a single account (login, user or customer account). 

  • Do not use the same password for different websites, applications or online services. 

  • This is particularly important when using IT systems that are publicly accessible or shared with others: you must always log out after each session on a website, application or online service. 

Passwords should consist of at least 12 characters and be chosen so that they cannot be easily guessed. They should therefore not contain common everyday words, your own name or the names of relatives, but should include a mix of upper- and lower-case letters, numbers and special characters. 


2. Data Controller 

The data controller within the meaning of the GDPR is: 

OASE GmbH

Tecklenburger Str. 161, 48477 Hörstel, Germany 

Telephone: 05454-80-0 

Email: info@oase.com 

Representatives of the controller: Cornelius Everke and Michael Koch 


3. Data Protection Officer 

You can contact the Data Protection Officer as follows: 

Thomas Otten 

You may contact our Data Protection Officer directly at any time with any questions or suggestions regarding data protection. 


4. Definitions 

This privacy policy is based on the terminology used by the European legislators and regulators when enacting the General Data Protection Regulation (GDPR). Our privacy policy is intended to be easy to read and understand for the general public as well as for our customers and business partners. To ensure this, we would like to explain the terminology used in advance. 

In this privacy policy, we use the following terms, amongst others: 

1. Personal data 

Personal data is any information relating to an identified or identifiable natural person. A natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. 

2. Data subject 

A data subject is any identified or identifiable natural person whose personal data is processed by the data controller (our company). 

3. Processing 

Processing means any operation or set of operations which is carried out on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of disclosure, the alignment or combination, the restriction, erasure or destruction. 

4. Restriction of processing 

Restriction of processing means the marking of stored personal data with the aim of restricting its future processing. 

5. Profiling 

Profiling is any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. 

6. Pseudonymisation 

Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person. 

7. Data processor 

A data processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller. 

8. Recipients 

A recipient is a natural or legal person, public authority, agency or other body to whom personal data are disclosed, regardless of whether or not they are a third party. However, public authorities which may receive personal data in the course of a specific investigation mandate under Union law or the law of the Member States are not considered to be recipients. 

9. Third party 

A third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons authorised to process the personal data under the direct responsibility of the controller or the processor. 

10. Consent 

Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, by a statement or by a clear affirmative action, by which the data subject signifies their agreement to the processing of personal data relating to them.


5. Legal basis for processing 

Article 6(1)(a) of the GDPR (in conjunction with Section 25(1) of the TTDSG) serves as the legal basis for our company’s processing operations where we obtain consent for a specific processing purpose. 

Where the processing of personal data is necessary for the performance of a contract to which you are a party – as is the case, for example, with processing operations required for the delivery of goods or the provision of other services or consideration – the processing is based on Article 6(1)(b) of the GDPR. The same applies to processing operations necessary for the implementation of pre-contractual measures, such as in cases of enquiries regarding our products or services. 

Where our company is subject to a legal obligation which requires the processing of personal data, such as to fulfil tax obligations, the processing is based on Article 6(1)(c) of the GDPR. 

In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were to be injured on our premises and their name, age, health insurance details or other vital information subsequently had to be disclosed to a doctor, a hospital or other third parties. In such cases, the processing would be based on Article 6(1)(d) of the GDPR. 

Finally, processing operations may be based on Article 6(1)(f) of the GDPR. This legal basis applies to processing operations not covered by any of the aforementioned legal bases, where the processing is necessary to safeguard a legitimate interest of our company or a third party, provided that the interests, fundamental rights and freedoms of the data subject do not override those interests. We are permitted to carry out such processing operations in particular because they have been specifically mentioned by the European legislator. In this regard, the legislator took the view that a legitimate interest could be assumed if you are a customer of our company (Recital 47, second sentence, of the GDPR). 

Our services are generally aimed at adults. Persons under the age of 16 may not provide us with any personal data without the consent of their parents or legal guardians. We do not request, collect or pass on any personal data from children and young people to third parties. 


6. Technology 

6.1 SSL/TLS encryption 

This website uses SSL or TLS encryption to ensure the security of data processing and to protect the transmission of confidential content, such as orders, login details or contact enquiries, which you send to us as the operator. You can recognise an encrypted connection by the fact that the browser’s address bar displays “https://” instead of “http://”, and by the padlock icon in your browser’s address bar. 

We use this technology to protect the data you send to us. 

6.2 Data collection when visiting the website 

When you use our website purely for information purposes – that is, if you do not register or otherwise provide us with information – we only collect the data that your browser transmits to our server (in so-called “server log files”). Every time you or an automated system accesses a page on our website, our website records a range of general data and information. This general data and information is stored in the server’s log files. The following may be recorded: 

  1. browser types and versions used, 

  2. the operating system used by the accessing system, 

  3. the website from which an accessing system reaches our website (known as a ‘referrer’), 

  4. the subpages on our website accessed via an accessing system, 

  5. the date and time of access to the website, 

  6. a truncated Internet Protocol address (anonymised IP address) and 

  7. the internet service provider of the accessing system.

We do not draw any conclusions about your identity from the use of this general data and information. Rather, this information is required in order to 

  1. deliver the content of our website correctly, 

  2. optimise the content of our website and the advertising on it, 

  3. ensure the long-term functionality of our IT systems and the technology underpinning our website, and 

  4. to provide law enforcement agencies with the information necessary for criminal prosecution in the event of a cyberattack. 

We therefore analyse this collected data and information both for statistical purposes and with the aim of enhancing data protection and data security within our company, ultimately to ensure an optimal level of protection for the personal data we process. The anonymous data from the server log files is stored separately from any personal data provided by a data subject. 

The legal basis for data processing is Article 6(1)(f) of the GDPR. Our legitimate interest arises from the purposes of data collection listed above. 

6.3 Encrypted payment transactions 

If, following the conclusion of a contract involving a fee, there is an obligation to provide us with your payment details (e.g. your account number when granting a direct debit authorisation), these details are required for payment processing. 

Payment transactions using standard payment methods (Visa/MasterCard or direct debit) are carried out exclusively via an encrypted SSL or TLS connection. You can recognise an encrypted connection by the fact that the address bar of your browser changes from “http://” to “https://” and by the padlock symbol in your browser’s address bar. 

We use this technology to protect the data you submit.


7. Cookies 

7.1 General information about cookies 

Cookies are small files that your browser creates automatically and which are stored on your IT system (laptop, tablet, smartphone, etc.) when you visit our website. 

Information is stored in the cookie that relates to the specific device you are using. However, this does not mean that we thereby gain direct knowledge of your identity. 

The use of cookies serves to make your experience of our website more convenient. For example, we use so-called session cookies to recognise that you have already visited individual pages on our website. These are automatically deleted when you leave our website. 

In addition, to optimise user-friendliness, we also use temporary cookies which are stored on your device for a specific, predetermined period. If you visit our site again to use our services, the system will automatically recognise that you have previously visited us and recall the entries and settings you have made, so that you do not have to re-enter them. 

We also use cookies to collect statistical data on the use of our website and to analyse our offering for the purpose of optimisation. These cookies enable us to automatically recognise that you have previously visited our website when you return. The cookies set in this way are automatically deleted after a defined period. The respective storage periods for the cookies can be found in the settings of the consent tool used.


8. Content on our website 

8.1 Data processing when opening a customer account and for contract fulfilment 

In accordance with Article 6(1)(b) of the GDPR, personal data is collected and processed when you provide it to us for the purpose of performing a contract or when opening a customer account. The data collected is specified in the relevant input forms. You may delete your customer account at any time; this can be done, amongst other ways, by sending a message to the above-mentioned address of the data controller. We store and use the data you provide for the purpose of contract fulfilment. Once the contract has been fully fulfilled or your customer account has been deleted, your data will be blocked in accordance with retention periods under tax and commercial law and deleted once these periods have expired, unless you have expressly consented to the further use of your data or we have reserved the right to further use your data as permitted by law, in which case we will inform you accordingly below. 

8.2 Data processing for order fulfilment 

The personal data we collect is passed on to the transport company commissioned to carry out the delivery as part of the contract fulfilment process, insofar as this is necessary for the delivery of the goods. We pass on your payment details to the commissioned bank as part of the payment processing, insofar as this is necessary for the payment to be processed. Where payment service providers are used, we provide explicit information on this below. The legal basis for the transfer of data in this context is Article 6(1)(b) of the GDPR. 

8.3 Concluding contracts via the online shop, retailers and goods dispatch 

We only transfer personal data to third parties where this is necessary for the performance of the contract, for example to companies responsible for delivering the goods or to the bank commissioned to process payments. No further transfer of data takes place, or only if you have expressly consented to such transfer. Your data will not be passed on to third parties without your express consent, for example for advertising purposes. 

The legal basis for data processing is Article 6(1)(b) of the GDPR, which permits the processing of data for the performance of a contract or for pre-contractual measures. 

8.4 Contacting us / Contact form 

Personal data is collected when you contact us (e.g. via the contact form or by email). The data collected when using a contact form is specified on the relevant contact form. This data is stored and used exclusively for the purpose of responding to your enquiry or for establishing contact and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your enquiry in accordance with Article 6(1)(f) of the GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Article 6(1)(b) of the GDPR. Your data will be deleted once your enquiry has been fully processed; this is the case when it is clear from the circumstances that the matter in question has been conclusively resolved and there are no statutory retention obligations preventing its deletion. 

8.5 Application Management / Job Board 

We collect and process the personal data of applicants for the purpose of handling the application process. Processing may also take place electronically. This is particularly the case where an applicant submits the relevant application documents to us electronically, for example by email or via a web form on our website. If we enter into an employment or service contract with an applicant, the data provided will be stored for the purpose of managing the employment relationship in accordance with statutory provisions. If we do not enter into a contract with the applicant, the application documents will be automatically deleted two months after notification of the rejection decision, provided that no other legitimate interests on our part preclude such deletion. An example of such a legitimate interest in this context is the burden of proof in proceedings under the General Equal Treatment Act (AGG). 

The legal basis for the processing of your data is Article 88 of the GDPR in conjunction with Section 26(1) of the BDSG. 

8.6 Handling of data relating to customers and suppliers 

We process your data, some of which is personal, for the purpose of initiating, implementing and fulfilling contractual relationships, preparing quotations and issuing invoices, as well as for contacting you and providing information as part of our customer service. 

1. Legal basis for the processing activity 

The processing is necessary for the performance of a contract or a pre-contractual measure in accordance with Article 6(1)(b) of the GDPR, or is necessary to safeguard our legitimate interest in accordance with Article 6(1)(f) of the GDPR, and no interests or fundamental rights and freedoms of the data subject override this. 

2. Categories of recipients 

Internal recipients include the consultancy, contract management, accounts, controlling and back-office departments. Furthermore, we engage service providers (data processors) to carry out our tasks, such as IT service providers and hosting providers, and transfer data to public authorities or courts in accordance with our legal obligations. 

8.7. Handling of visitors’ data 

We process your data, some of which is personal, to verify access authorisation. In doing so, we store the following data: 

Visitor contact details (title, surname, first name, email address) 

Data relating to the visit (location, building, date, time) 

1. Legal basis for the processing 

The processing is necessary for regulated access control and serves our legitimate interest in accordance with Article 6(1)(f) of the GDPR; no interests or fundamental rights and freedoms of the data subject override this. 

2. Duration of storage 

Your personal data will be stored for a period of 1 year from your last visit.


9. Sending out newsletters 

9.1 Sending newsletters to existing customers 

If you have provided us with your email address when purchasing goods or services, we reserve the right to send you regular offers by email for goods or services from our range that are similar to those you have already purchased. In accordance with Section 7(3) of the German Unfair Competition Act (UWG), we are not required to obtain your separate consent for this. Data processing in this regard is carried out solely on the basis of our legitimate interest in personalised direct marketing in accordance with Article 6(1)(f) of the GDPR. If you initially objected to the use of your email address for this purpose, we will not send you any emails. You are entitled to object to the use of your email address for the aforementioned marketing purposes at any time, with effect for the future, by notifying the data controller named at the beginning of this notice. You will only incur transmission costs in accordance with the standard rates set out in the German Telecommunications Act ( ). Upon receipt of your objection, the use of your email address for marketing purposes will be discontinued immediately. 

9.2 Promotional newsletter 

On our website, you are given the opportunity to subscribe to our company’s newsletter. The personal data provided to us when you subscribe to the newsletter is determined by the form used for this purpose. 

We inform our customers and business partners about our offers at regular intervals via a newsletter. In principle, you can only receive our company’s newsletter if 

  1. you have a valid email address and 

  2. you have registered to receive the newsletter.

For legal reasons, a confirmation email will be sent to the email address you first provided when registering for the newsletter, using the double opt-in procedure. This confirmation email serves to verify that you, as the owner of the email address, have authorised the receipt of the newsletter. 

When you subscribe to the newsletter, we also store the IP address of the IT system you were using at the time of registration, as assigned by your Internet Service Provider (ISP), as well as the date and time of registration. The collection of this data is necessary to enable us to trace any (potential) misuse of your email address at a later date and therefore serves to protect us legally. 

The personal data collected as part of a newsletter subscription is used exclusively for sending our newsletter. Furthermore, newsletter subscribers may be informed by email where this is necessary for the operation of the newsletter service or for registration purposes, as might be the case with changes to the newsletter content or alterations to the technical conditions. No personal data collected as part of the newsletter service will be passed on to third parties. You may cancel your subscription to our newsletter at at any time. The consent you have given us to store personal data for the purpose of sending the newsletter may be withdrawn at any time. A link for withdrawing consent is included in every newsletter. Furthermore, you may unsubscribe from the newsletter directly on our website at any time or notify us of your wish to do so by other means. 

The legal basis for data processing for the purpose of sending the newsletter is Article 6(1)(a) of the GDPR. 

9.3 Episerver 

We use Episerver to send out newsletters. The provider is Episerver GmbH, Wallstraße 16, 10179 Berlin. Episerver is a service that enables the organisation and analysis of newsletter distribution. The data entered to subscribe to the newsletter (e.g. email address) is stored on Episerver’s servers. 

The newsletters we send via Episerver enable us to analyse the behaviour of newsletter recipients. Among other things, this allows us to analyse how many recipients opened the newsletter and how often each link in the newsletter was clicked. With the help of what is known as conversion tracking, we can also analyse whether a predefined action (e.g. the purchase of a product on our website) took place after a link in the newsletter was clicked. 

Where our newsletter is sent to our existing customers, this analysis is carried out on the basis of our legitimate interest in determining the success of our newsletter and optimising its content (Article 6(1)(f) of the GDPR). If you subscribe to our newsletter, the analysis is carried out on the basis of the consent you provided during the registration process, including consent given in this regard (Article 6(1)(a) of the GDPR). 

If you do not wish your data to be analysed via Episerver, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. You can also unsubscribe from the newsletter directly on the website. 

The data you have provided to us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and, following unsubscription, will be blocked on both our servers and Episerver’s servers to prevent further newsletters from being sent. Should you also wish to have your data stored for newsletter purposes deleted, please let us know. Data stored by us for other purposes (e.g. email addresses for the members’ area) remains unaffected by this. 

Further information on Episerver’s privacy policy can be found at: https://www.episerver.com/de/legal/datenschutz


10. Our activities on social media 

To enable us to communicate with you on social media and keep you informed about our services, we maintain our own pages on these platforms. When you visit one of our social media pages, we are jointly responsible with the provider of the relevant social media platform for the processing operations triggered thereby, within the meaning of Article 26 of the GDPR. 

We are not the original provider of these pages, but merely use them within the scope of the options offered to us by the respective providers. 

We therefore wish to point out, as a precaution, that your data may also be processed outside the European Union or the European Economic Area. Using these platforms may therefore entail data protection risks for you, as it may be more difficult to exercise your rights – such as the right to access, erasure, objection, etc. – and processing on social networks is often carried out directly by the providers for advertising purposes or to analyse user behaviour, without us being able to influence this. Where the provider creates user profiles, cookies are often used, or your usage behaviour is linked to the member profile you have created on the social media platforms. 

The processing of personal data described above is carried out in accordance with Article 6(1)(f) of the GDPR on the basis of our legitimate interest and the legitimate interest of the respective provider, in order to be able to communicate with you in a modern manner and to inform you about our services. If you are required to give your consent to data processing as a user of with the respective providers, the legal basis is Article 6(1)(a) of the GDPR in conjunction with Article 7 of the GDPR. 

As we do not have access to the providers’ data records, we would like to point out that the best way to exercise your rights (e.g. the right to access, rectification, erasure, etc.) is to contact the relevant provider directly. We have provided further information on the processing of your data on social media platforms below, for each social media provider we use: 

10.1 Facebook 

(Joint) data controller in Europe: 

Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland 

Privacy Policy (Data Policy): 

10.2 Instagram 

(Joint) data controller in Germany: 

Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland 

Privacy Policy (Data Policy): 

10.3 LinkedIn 

(Joint) data controller in Europe: 

LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland 

Privacy policy: 

10.4 YouTube 

(Joint) data controller in Europe: 

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland 

Privacy policy: 


11. Web analytics 

11.1 Google Analytics Universal 

On our websites, we use Google Analytics, a web analytics service provided by Google Ireland Limited (https://www.google.de/intl/de/about/), Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). In this context, pseudonymised user profiles are created and cookies (see the section on “Cookies”) are used. The information generated by the cookie about your use of this website, such as 

  1. the browser type and version, 

  2. the operating system used 

  3. the referrer URL (the previously visited page) 

  4. the host name of the accessing computer (IP address) 

  5. the time of the server request

are transmitted to a Google server in the USA and stored there. The information is used to analyse the use of the website, to compile reports on website activity and to provide other services relating to website and internet usage for the purposes of market research and the user-centred design of these web pages. This information may also be transferred to third parties where required by law or where third parties process this data on Google’s behalf. Under no circumstances will your IP address be linked to other data held by Google. IP addresses are anonymised so that they cannot be linked to you (IP masking). 

You can prevent the installation of cookies by adjusting your browser settings accordingly; however, please note that in this case, you may not be able to make full use of all the functions of this website. 

These processing operations take place exclusively upon the granting of express consent in accordance with Article 6(1)(a) of the GDPR. 

You can also prevent the collection of data generated by the cookie and relating to your use of the website (including your IP address), as well as the processing of this data by Google, by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=de). 

The parent company, Google LLC, is a US company certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Article 45 of the GDPR is in place, meaning that personal data may be transferred without the need for further safeguards or additional measures. 

You can view the Google Analytics privacy policy at: https://support.google.com/analytics/answer/6004245?hl=de


12. Plugins and other services 

12.1 Google Maps 

We use Google Maps (API) on our website. Google Maps is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google group of companies, headquartered at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Maps is a web service for displaying interactive (land) maps to present geographical information visually. By using this service, you can, for example, view our location and find it easier to plan your journey to us. 

As soon as you access any subpages on which the Google Maps map is embedded, information about your use of our website (such as your IP address) is transmitted to Google’s servers in the USA and stored there, provided you have given your consent within the meaning of Article 6(1)(a) of the GDPR. In addition, Google Maps loads Google Web Fonts, Google Photos and Google Stats. These services are also provided by Google Ireland Limited. When you visit a page that embeds Google Maps, your browser loads the web fonts and images required to display Google Maps into your browser cache. For this purpose, too, the browser you are using establishes a connection to Google’s servers. As a result, Google becomes aware that our website has been accessed via your IP address. This occurs regardless of whether Google provides a user account through which you are logged in, or whether no user account exists. If you are logged in to Google, your data will be directly associated with your account. If you do not wish your data to be associated with your Google profile, you must log out of your Google user account. Google stores your data (even for users who are not logged in) as usage profiles and analyses them. You have the right to object to the creation of these user profiles; to exercise this right, you must contact Google. 

If you do not consent to your data being transmitted to Google in future when using Google Maps, you also have the option of completely disabling the Google Maps web service by disabling JavaScript in your browser. Google Maps, and therefore the map display on this website, will then no longer be available for use. 

These processing operations take place exclusively upon the granting of explicit consent in accordance with Article 6(1)(a) of the GDPR. 

You can view Google’s Terms of Service at https://www.google.de/intl/de/policies/terms/regional.html; the additional Terms of Service for Google Maps can be found at https://www.google.com/intl/de_US/help/terms_maps.html

The parent company, Google LLC, is a US company certified under the EU-US Data Privacy Framework. An adequacy decision in accordance with Article 45 of the GDPR is in place, meaning that personal data may be transferred even without further safeguards or additional measures. 

You can view the Google Maps privacy policy at: (“Google Privacy Policy”): https://www.google.de/intl/de/policies/privacy/

12.2 Google Photos 

We use the Google Photos service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, to store images embedded on our website. 

Embedding refers to the integration of specific third-party content (text, video or image data) provided by another website (Google Photos) and subsequently displayed on our own website. An ‘embed code’ is used for embedding. If we have integrated an embed code, the external content from Google Photos is displayed by default as soon as one of our web pages is visited. 

Through the technical implementation of the embed code, which enables the display of images from Google Photos, your IP address is transmitted to Google Photos. Furthermore, Google Photos records our website, the browser type used, the browser language, the time and duration of the visit. In addition, Google Photos may collect information about which of our subpages you have visited and which links you have clicked on, as well as other interactions you have carried out whilst visiting our site. This data may be stored and analysed by Google Photos. 

These processing operations take place exclusively upon the granting of explicit consent in accordance with Article 6(1)(a) of the GDPR. 

This US company is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Article 45 of the GDPR is therefore in place, meaning that personal data may be transferred even without further safeguards or additional measures. 

You can view Google’s privacy policy at: https://www.google.com/policies/privacy/

12.3 Google Tag Manager 

We use the Google Tag Manager service on this website. The operator of Google Tag Manager is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google group of companies, headquartered at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. 

This tool allows ‘website tags’ (i.e. keywords embedded in HTML elements) to be implemented and managed via a user interface. By using Google Tag Manager, we can automatically track which button, link or personalised image you have actively clicked on and can then record which content on our website is of particular interest to you. 

The tool also triggers other tags, which may in turn collect data. Google Tag Manager does not access this data. If you have disabled tracking at domain or cookie level, this setting will apply to all tracking tags implemented using Google Tag Manager. 

These processing operations take place exclusively upon the granting of explicit consent in accordance with Article 6(1)(a) of the GDPR. 

The parent company, Google LLC, is a US company certified under the EU-US Data Privacy Framework. An adequacy decision has therefore been issued in accordance with Article 45 of the GDPR, meaning that personal data may be transferred without the need for further safeguards or additional measures. 

Further information on Google Tag Manager and Google’s privacy policy can be found at: https://www.google.com/intl/de/policies/privacy/

12.4 Google Web Fonts 

Our website uses so-called web fonts to ensure a consistent display of typefaces. Google WebFonts are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google group of companies, headquartered at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. 

These processing operations take place exclusively upon the granting of explicit consent in accordance with Article 6(1)(a) of the GDPR. 

The parent company, Google LLC, is a US company certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Article 45 of the GDPR is therefore in place, meaning that personal data may be transferred even without further safeguards or additional measures. 

Further information on Google WebFonts and Google’s privacy policy can be found at: https://developers.google.com/fonts/faq ; https://www.google.com/policies/privacy/

12.5 YouTube videos in enhanced privacy mode (YouTube NoCookies) 

Some subpages of our website contain links to YouTube’s services. As a general rule, we are not responsible for the content of websites to which links are provided. However, should you follow a link to YouTube, please note that YouTube stores its users’ data (e.g. personal information, IP address) in accordance with its own data usage policies and uses it for commercial purposes. 

YouTube is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. 

We also embed videos stored on YouTube directly on some subpages of our website. When this is done, content from the YouTube website is displayed in sections of a browser window. When you visit a (sub)page of our website that contains embedded YouTube videos, a connection is established with the YouTube servers and the content is displayed on the website via a request sent to your browser. 

YouTube content is embedded only in ‘enhanced privacy mode’. YouTube provides this mode itself and thereby ensures that YouTube does not initially store any cookies on your device. However, when you visit the relevant pages, your IP address and, where applicable, other data are transmitted, thereby indicating, in particular, which of our web pages you have visited. This information cannot, however, be linked to you unless you have logged in to YouTube or another Google service before visiting the page, or are permanently logged in. As soon as you start playing an embedded video by clicking on it, YouTube will, via the enhanced privacy mode, only store cookies on your device that do not contain any personally identifiable data, unless you are currently logged in to a Google service. These cookies can be prevented by adjusting your browser settings and using browser extensions. 

Requesting the video also constitutes your consent to the placement of the relevant cookie (Article 6(1), first sentence, point (a) of the GDPR). 

This US company is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Article 45 of the GDPR is therefore in place, meaning that the transfer of personal data may take place even without further safeguards or additional measures. 

You can view YouTube’s privacy policy at: https://www.google.de/intl/de/policies/privacy/

12.6. ThingLink 

ThingLink processes data visually (videos, panoramas, etc.) for our website. When using an embedded ThingLink display, the following data is collected: IP address, browser, statistics (views, hovers, clicks per image); this data is stored for 30 days. The provider is ThingLink Oy, Bulevardi 7, 00120 Helsinki, Finland. Privacy policy: https://www.thinglink.com/privacy. 

The legal basis for processing is your consent: Processing based on consent: Article 6(1)(a) of the GDPR. 

12.7 Sklik / imedia.cz 

We use the Seznam Sklik conversion tracking technology and the retargeting function on our website. This is a service provided by seznam.cz, a.s., Prague 5 – Smíchov, Radlická 3294/10, 15000, Czech Republic (hereinafter: Sklik). 

This technology enables personalised adverts to be displayed to visitors to our website within the Sklik partner network. 

Furthermore, Sklik provides further information on its data protection practices at https://o.seznam.cz/ochrana-udaju/ 

12.8 Fastly 

We use the CDN service “Fastly” provided by Fastly, Inc., Attention: General Counsel, 475 Brannan St., Suite 300, San Francisco, CA 94107. This is a Content Delivery Network (CDN). A CDN is a network of high-performance servers that cache content at various locations around the world. The legal basis for the use of Fastly and the transfer of your data to it is Article 6(1)(f) of the GDPR (legitimate interest in data processing), unless otherwise stated for the respective service. This legitimate interest arises from our need to ensure the technically flawless and rapid display of our website and to reduce the load on our IT infrastructure. 

Further information on the handling of user data can be found in Fastly’s privacy policy: https://www.fastly.com/privacy/


13. Privacy Notice for the OASE Control App and the OASE Switch App 

We are delighted that you are interested in our mobile applications. The following information explains which personal data we process in connection with the use of the OASE Control App and the OASE Switch App, the purposes for which this is done, the legal basis for the processing, to whom data may be disclosed, how long data is stored and what rights you have. This information is provided in a precise, transparent, comprehensible and easily accessible form. 

13.1 Scope 

This privacy notice applies to the use of the OASE Control App, the OASE Switch App and the associated functions, in particular user accounts, device integration, cloud functions, fault and service communications, optional voice assistants, support tickets, multi-user/sharing functions, error reports and – where actually used – statistical and BI-based analyses. The privacy policies of the respective app store operators also apply to the mere use of app stores.   

13.2 App download via the Apple App Store / Google Play 

When downloading the app, technically necessary information is transmitted to the respective app store operator. We have only limited influence over this processing. Insofar as we arrange for the app to be made available in the stores, the associated processing is based on our legitimate interest in the distribution of the app or – insofar as a user agreement is already established through the download – on the initiation or performance of the contract. Information regarding any transfers to third countries is also governed by the terms and conditions of the respective store operator.  

13.3 Processing in connection with the OASE Control app 

When you use the OASE Control app, we process, in particular, account data, login details, device and controller assignments, configurations, usage events, operational and sensor data, fault and status messages, synchronisation events, support details and – where you have enabled them – data relating to voice assistants and error reports. This processing is generally necessary in order to provide  you with the app, your user account, cloud synchronisation, remote control, history, alarm notifications and the management of multiple devices or multiple users. The legal basis for this is generally Article 6(1)(b) of the GDPR.   

13.4 Cloud synchronisation, history and remote access 

Where you use cloud functions, operational, status, measurement and sensor data are transmitted to our cloud infrastructure to enable device history, cross-device synchronisation of your account and control outside your local network. If you disable cloud interactions in the settings, certain data and control functions will only be available to you locally. This cloud data is processed for the purpose of fulfilling the contract. Categories, frequencies and technical details of the synchronisation are also set out in the Data Act information for the relevant products.   

13.5 Local operation without the cloud 

Depending on your device configuration, certain functions of the OASE Control app can be used purely locally within your network. In this case, operational, status and sensor data are processed only locally, provided that no other function you have activated triggers a transmission to OASE or a third-party provider. Insofar as data remains exclusively on your device or within your local network and is not accessible to us, our role is limited to providing the software functionality.   

13.6 Account sharing and invitation function 

If you invite other people to a device, household or system network, we process the authorisation and assignment data required for this. Depending on the technical setup, invitation links, QR codes, email addresses, names or other identifying characteristics of the users involved may be processed. The legal basis is the performance of the contract, insofar as you consciously use this function. Where invitation emails are sent, we use an email service provider for this purpose. Before granting access, you should be aware that, depending on the role and access model, invited persons may receive information about the system and about the user sending the invitation. 

13.7 Transaction emails and service communications 

We send emails that are necessary for the set-up, security and use of your user account or your devices. These include, in particular: 

  • Registration and verification emails, 

  • Password reset emails, 

  • Emails regarding changes to account details, 

  • Invitations relating to account-sharing and authorisation features, 

  • Alerts and error messages from devices, 

  • Safety and service information, 

  • Other technically necessary notifications relating to the use of our apps and services. 

To send these emails, we use the Twilio SendGrid service, a service provided by Twilio Inc., 101 Spear Street, 5th Floor, San Francisco, CA 94105, USA. 

In particular, the following data is processed in connection with the sending of emails: 

  • The recipient’s email address, 

  • Time of dispatch, 

  • Delivery status, 

  • Technical dispatch and delivery information, 

  • Where applicable, the content of the message sent. 

Processing is carried out for the purpose of providing and performing the services you use, as well as to ensure secure and reliable email delivery. 

The legal basis for sending contract-related and technically necessary messages is Article 6(1)(b) of the GDPR. 

Where dispatch and delivery logs are processed to ensure deliverability, for error analysis or to prevent misuse, this is done on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR. 

According to Twilio, so-called ‘Email Activity Data’ is stored in the United States. Sending and delivery logs are generally stored for a period of 30 days and then deleted. 

Further information on data protection at Twilio SendGrid can be found at: 

13.8 Support tickets and fault handling 

If you use in-app support or other support channels, we process the information you provide, e.g. contact details, a description of the problem, affected devices, error messages and the processing history in the ticketing system. Where access to cloud data or system logs is necessary to process your enquiry, this is done for the purpose of handling your support request and is therefore generally based on Article 6(1)(b) of the GDPR. Access by our support staff should only be role-based, limited to the specific purpose and logged. 

13.9 Optional voice assistants 

If you connect to Amazon Alexa or Google Assistant, we process the mapping and integration data required for this purpose. Activating this feature is optional and not required for the core functionality of the app. The legal basis is therefore, in principle, your consent in accordance with Article 6(1)(a) of the GDPR. You may withdraw your consent at any time with future effect. Depending on the technical setup, deactivation and unpairing can be carried out in the OASE app, in the voice assistant’s app, or in both systems; the key requirement is that the actual data flow can be terminated and the user is clearly informed of this.   

13.10 Error reports and app diagnostics 

Where we process error or crash reports, this is done solely for the purposes of ensuring the stability, analysing errors and improving the technical performance of the app. Where such processing is not necessary for the direct performance of the contract, it should only take place on the basis of separate consent. Your consent must be voluntary, specific to the purpose and revocable; revocation must be as easy as giving consent. 

13.11 Statistical Analysis and BI/Reporting 

We may analyse usage, operational and service data in a manner compliant with data protection regulations for the purposes of internal statistics, product improvement, capacity planning, error analysis and service quality. 

13.12 Processing in connection with the OASE Switch app 

The OASE Switch App is currently designed as a locally operating application. No OASE user account is required to use it; according to your description, no control or sensor data is transmitted to an OASE cloud. The app uses Bluetooth/BLE to communicate with devices locally and may use location data locally, insofar as this is necessary  for the Sunrise Timer or similar local automations. If the location data does not leave the OASE ecosystem, this should be explicitly clarified in this privacy notice. The legal basis for locally required permissions and local processing is the provision of the app’s functionality; where operating system permissions are required, these are additionally controlled by the respective OS.   

13.13 Use of location data  

Insofar as the OASE Switch app and OASE Control app use location coordinates for sunrise/sunset functions, this processing is carried out solely to calculate the automatic timing you have requested. According to your description, the coordinates are used locally within the app or the controller and are not transmitted to OASE.   

13.14 Recipients and data processors 

Depending on the function used, we may engage service providers for cloud operations, email dispatch, voice assistant integration, fault analysis, support and reporting.  

The recipients and data processors we use include, in particular: 

  • Microsoft Azure (hosting and cloud infrastructure) 

  • Twilio SendGrid (sending transactional, verification, alert and service emails) 

  • Google Firebase Crashlytics (error analysis and app diagnostics, where enabled) 

  • Voice assistant providers such as Amazon Alexa or Google Assistant (only if integration is enabled); activation and deactivation of the link are carried out exclusively via the respective third-party application (e.g. Amazon Alexa or Google Home). 

  • Providers of support and ticketing systems (where used) 

  • Providers of reporting and business intelligence solutions (where used) 

Where these service providers process personal data on our behalf, this is done on the basis of a data processing agreement in accordance with Article 28 of the GDPR or another permissible legal basis under data protection law. 

If you invite other users to share devices, the data required for this purpose will be processed. This includes, in particular, the disclosure of the inviting user’s registered email address to the invited person, insofar as this is necessary to fulfil the invitation. 

Security-related authentication information (e.g. device passwords or cryptographic keys) is processed only to the extent necessary for the secure operation of the system. 

13.15 Transfers to third countries 

Where personal data is transferred to recipients outside the European Economic Area (EEA), this is done exclusively in accordance with the legal requirements set out in Articles 44 et seq. of the GDPR. 

This may, in particular, concern the following service providers: 

  • Google Firebase Crashlytics (USA), 

  • Twilio SendGrid (USA), 

  • Other providers of voice assistants or technical services, where applicable. 

Where data is transferred to the USA, we base this on appropriate safeguards in accordance with Article 46 of the GDPR, in particular the Standard Contractual Clauses (SCCs) adopted by the European Commission.  

Where individual recipients are additionally certified under the EU-US Data Privacy Framework, the transfer may also be based on an adequacy decision in accordance with Article 45 of the GDPR. 

Further information on the relevant safeguards is available on request. 

13.16 Retention period and erasure 

We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations. We generally store account data and associated cloud data for the duration of the active user account; following the deletion of the account, the data is deleted unless statutory obligations or legitimate grounds for temporary retention preclude this. Separate time limits apply to support tickets, dispatch logs, invitation tokens, error reports, security logs and BI pre-processes. If you do not use your account for 3 years, OASE will classify it as inactive. Once this period has expired, you will receive an email asking you to log in to your account within 3 weeks. If you do not log in to your account by the deadline specified in the email, it will be automatically deleted, including all stored data. For data stored locally in the OASE Switch app, processing generally ceases upon deletion of the app or removal of the local data from your device, provided that no server-side processing takes place.   

13.17 Overview of legal bases 

Where we process data because this is necessary for the provision of the app, the user account, cloud synchronisation, device control, the sharing function, alarm communication or for support enquiries, the processing is generally based on Article 6(1)(b) of the GDPR. Where we process data due to legal obligations, Article 6(1)(c) of the GDPR applies. Where we process data for IT security, fraud prevention, logging or stable technical operation, Article 6(1)(f) of the GDPR may apply, provided that a balancing of interests supports this. For optional features such as voice assistants or voluntary error reports, we rely – where necessary – on Article 6(1)(a) of the GDPR.  

13.18 Your rights 

The rights under the Data Act supplement your rights under section 14 insofar as data from connected products or associated services is concerned; they do not replace the GDPR.  

13.19 Security and privacy-friendly default settings 

We implement technical and organisational measures to protect personal data from unauthorised access, loss, alteration or unauthorised disclosure. These include, in particular, role-based authorisation schemes, access restrictions, logging, encryption, regular deletion routines and privacy-friendly default settings. Optional features involving a higher volume of data, in particular voice assistants and voluntary error reports, should remain disabled by default and only be activated following a conscious decision by the user.  

13.20 Changes to this Privacy Notice 

We update this privacy notice if there are significant changes to legal requirements, technical processes or the service providers we use. In the event of significant changes, we will inform users in an appropriate manner, for example within the app, by email or on our website. Where a change relates to new or amended processing operations requiring consent, we will seek consent again.  

Information about your rights regarding product and related service data under Regulation (EU) 2023/2854 (the Data Act) can be found in our separate information sheet on the Data Act. 


Data Security (Data Act) | Oase