PRIVACY POLICY

Preamble

With this Privacy Policy, we inform you about the nature, scope, and purpose of the processing of personal data within our website, online shop, our mobile application "Oberheim Connect", the operation of our connected speakers, and our social media profiles (collectively referred to as "Online Services").

The terms used are not gender-specific.

Controller

Oberheim Speakers GmbH
Brunnenstraße 10
40223 Düsseldorf
Germany

Email: info@oberheim-speakers.de
Managing Director: Nils Felix Oberheim
Commercial Register: Local Court Düsseldorf, HRB 113832
Imprint: https://oberheim-speakers.de/de/pages/imprint

Overview of Processing Activities

Categories of Processed Data

Master data (e.g., name, address, customer number); Contact data (e.g., email address, phone number); Contract and payment data; Content data (e.g., messages in forms); Usage data (e.g., pages visited, duration of visit, device types); Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers); Log data; Device data of our speakers (e.g., serial number, firmware version, device name assigned in the local network).

Categories of Data Subjects

Customers and prospective customers; Users of our website, our app, and our products; Communication partners; Business and contractual partners.

Purposes of Processing

Performance of contractual services; Communication and responding to inquiries; Provision of website, shop, app, and product features; Security and operation of the information technology infrastructure; Provision of software and firmware updates; Audience measurement and marketing (where consented to); Fulfillment of legal obligations.

Relevant Legal Bases

Consent (Art. 6(1)(a) GDPR) — e.g., for non-essential cookies, audience measurement, and embedded map displays.
Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR) — e.g., order processing, provision of app and product functions.
Legal obligation (Art. 6(1)(c) GDPR) — e.g., commercial and tax law retention requirements, product safety, and cybersecurity duties.
Legitimate interests (Art. 6(1)(f) GDPR) — e.g., secure and stable operation of our systems, fraud prevention.

In addition, national regulations apply, in particular the German Federal Data Protection Act (BDSG) and § 25 TDDDG for the use of cookies and comparable technologies.

Security Measures

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to data, input, disclosure, and availability, as well as procedures for exercising data subject rights, deleting data, and responding to data protection incidents. We already take data protection into account during the selection and development of hardware, software, and procedures (data protection by design and data protection-friendly default settings).

The transmission of data via our website, our app, and the communication of our products with our servers is encrypted (TLS/HTTPS). Firmware updates for our speakers are cryptographically signed; the devices only install updates whose signature has been successfully verified.

Transmission of Personal Data

In the context of our processing, it may happen that data is transmitted to or disclosed to other entities, such as service providers for IT operations, shop platforms, payment processing, or shipping. If such entities process data on our behalf, we enter into data processing agreements pursuant to Art. 28 GDPR. Otherwise, data is only passed on if this is necessary for contract performance, if you have consented, or if a legal obligation exists.

International Data Transfers

If data is processed in a third country, this is done strictly in compliance with legal requirements. The primary basis is an adequacy decision by the EU Commission (Art. 45 GDPR), otherwise standard contractual clauses (Art. 46(2)(c) GDPR), explicit consent, or one of the exceptions under Art. 49 GDPR. For providers from the USA, the EU-US Data Privacy Framework may be applicable; the list of certified companies is available athttps://www.dataprivacyframework.gov/. For individual services below, we state the respective basis.

Storage and Deletion

We delete personal data as soon as the purpose of processing ceases to exist, consent is revoked, and no other legal basis exists. Exceptions exist insofar as statutory retention obligations or legitimate interests require further storage; such data will then be processed exclusively for these purposes.

Statutory regular retention periods under German law: 10 years — Books and records, annual financial statements, inventories, accounting documents, and invoices (§ 147(3) in conjunction with (1) Nos. 1, 4, 4a AO; § 14b(1) UStG; § 257(1) Nos. 1 & 4, (4) HGB). 8 years — Received and sent commercial and business letters, as well as other documents relevant for taxation (§ 147(3) in conjunction with (1) Nos. 2, 3, 5 AO; § 257(1) Nos. 2 & 3, (4) HGB). 3 years — Data for considering possible warranty and damage claims for the duration of the regular limitation period (§§ 195, 199 BGB).

If a period of at least one year does not explicitly start on a specific date, it runs from the end of the calendar year in which the triggering event occurred. If several retention periods apply, the longest period shall apply.

Rights of Data Subjects

Under Art. 15 to 21 GDPR, you have the following rights in particular:

Right to Object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If your data is processed for direct marketing purposes, you can object at any time and without giving reasons. Withdrawal of Consent: You can revoke any consent granted at any time. The lawfulness of the processing carried out up to the time of revocation remains unaffected. Right of Access: You can request confirmation as to whether data concerning you is being processed, as well as access to and a copy of this data. Right to Rectification: You can request the completion or correction of inaccurate data concerning you. Right to Erasure and Restriction of Processing. Right to Data Portability: Delivery of the data provided by you in a structured, commonly used, and machine-readable format. Right to Lodge a Complaint with a Supervisory Authority.

To exercise your rights, a message to the contact details mentioned above is sufficient.

Competent Supervisory Authority

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen Kavalleriestraße 2–4 40213 Düsseldorf Phone: 0211 38424-0 Email: poststelle@ldi.nrw.de www.ldi.nrw.de

Website and Online Shop

Provision of the Online Offer and Hosting

To provide our online offer, we process the IP address of users; it is technically necessary to deliver content to the browser or end device.

Shop Platform and Hosting: Our online shop is operated via the Shopify platform. User and customer data are processed and stored on the provider's infrastructure, including order, customer, and usage data. Service provider: Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. Legal bases: Contract performance (Art. 6(1)(b) GDPR), legitimate interests (lit. f). Privacy policy: https://www.shopify.com/legal/privacy. Basis for third-country transfers: Adequacy decision (Canada) as well as standard contractual clauses for other group companies and sub-processors.

Server Log Files: Accesses are logged in server log files. The requested URL, date and time, volume of data transferred, notification of successful retrieval, browser type and version, operating system, referrer URL, and usually the IP address and requesting provider can be collected. The purpose is to ensure the stability and security of our systems, in particular to prevent abusive access. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Deletion: Usually after 30 days, unless longer retention is required for evidentiary purposes.

Email Shipping and Hosting: Our hosting services include the sending, receiving, and storage of emails. Sender and recipient addresses, further shipping information, and the content of emails are processed, also to detect unsolicited messages. Please note that emails on the Internet are regularly not transmitted with end-to-end encryption. Service provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Privacy policy: https://www.ionos.de/terms-gtc/terms-privacy.

Cookies and Comparable Technologies

Cookies are small text files or other storage notices that store and read information on end devices — for example, regarding shopping cart contents, login status, or visitor stream analysis.

Consent: We use cookies in accordance with § 25 TDDDG. We obtain consent insofar as it is required. It is not required if storage and reading are strictly necessary to provide an explicitly requested service. You can adjust or revoke your selection at any time via a consent management system.

Storage Duration: Temporary cookies (session cookies) are deleted at the latest when you leave our online offer and close your end device or browser. Permanent cookies remain stored beyond that; unless we state otherwise, the storage duration can be up to two years.

Consent Management: To collect, log, manage, and revoke consent, we use the privacy and consent function integrated into our shop platform ("Customer Privacy" by Shopify), including the associated consent banner. A pseudonymous identifier, the timestamp and scope of consent, as well as details about the browser, system, and end device are stored to prove consent and avoid re-prompting. An additional external provider is not used. Service provider: Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. Legal basis: Consent (Art. 6(1)(a) GDPR), legal obligation for logging (lit. c), and legitimate interests (lit. f).

Order Processing, Delivery, and Customer Account

We process customer data to enable the selection, purchase, payment, and delivery of selected products and associated services. The required details are marked as such in the ordering process and include data required for delivery and billing as well as contact details for inquiries. For execution, we use service providers, in particular postal, freight, and shipping companies, as well as banks and payment service providers.

If you create a customer account, we process the data stored there to give you access to your orders and addresses. You can have your customer account deleted at any time; statutory retention obligations remain unaffected.

Legal bases: Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legal obligation (lit. c); Legitimate interests (lit. f).

Payment Procedures

We offer secure payment options and use banks and payment service providers for this purpose. The data processed by payment service providers includes master data, bank details or card data, security features, as well as contract, amount, and recipient-related information. This information is required to perform transactions. We do not receive account or card details ourselves, but only a confirmation or rejection of payment. Payment service providers may transmit data to credit agencies for identity and credit checks. The terms and privacy notices of the respective providers additionally apply to payment transactions.

Legal basis: Contract performance (Art. 6(1)(b) GDPR).

We offer the following payment methods: Credit Card (Shopify Payments): Service provider: Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. Privacy policy: https://www.shopify.com/legal/privacyPayPal: Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Privacy policy: https://www.paypal.com/de/legalhub/privacy-fullKlarna: Service provider: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. Privacy policy: https://www.klarna.com/de/datenschutzerklarung/.

Contact and Inquiry Management

When contacting us (e.g., via contact form, email, phone, or via social media) as well as within the framework of existing business relationships, we process the details of inquiring persons insofar as this is necessary to answer and process the request. We use this data exclusively for the respective purpose of communication.

Legal bases: Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legitimate interests (lit. f).

Audience Measurement and Web Analytics

Audience measurement serves to evaluate the visitor flows of our online offer. This allows us to recognize, for example, which content and functions are used and which areas we should improve. For this purpose, profiles — i.e., data summarized into a single usage process — can be created, and information can be stored and read in your browser. Collected data includes in particular visited pages, used elements, as well as technical information about the browser, system, and usage times. No clear data such as names or email addresses are stored for analysis purposes, but rather pseudonyms.

Google Analytics: Measurement and analysis of the use of our online offer based on a pseudonymous user identification number that contains no clear data. For users from the EU, individual IP addresses are not logged or stored; IP data is used exclusively to derive rough location details (city, region, country, continent) and is subsequently deleted. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: Consent (Art. 6(1)(a) GDPR). Privacy policy: https://policies.google.com/privacy. Third-country transfer basis: EU-US Data Privacy Framework. Opt-out: Browser add-on at https://tools.google.com/dlpage/gaoptout.

Google Tag Manager: Technical management and integration of scripts and services. Tag Manager itself does not collect personal data for its own purposes, but enables the integration of other services about which we inform separately here. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: Consent (Art. 6(1)(a) GDPR). Privacy policy: https://policies.google.com/privacy.

Online Marketing and Conversion Measurement

We process personal data in order to display advertising based on potential interests and measure its effectiveness. For this purpose, user profiles may be stored in cookies or comparable storage notices. As a rule, we only receive aggregated information about the success of our ads. As part of conversion measurement, we can track which measures led to an interaction or contract conclusion.

Google Ads and Conversion Measurement: Placement of advertisements in the provider's advertising network and measurement of conversion. We do not receive personal information about individual users. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: Consent (Art. 6(1)(a) GDPR). Privacy policy: https://policies.google.com/privacy. Third-country transfer basis: EU-US Data Privacy Framework.

Meta Conversions API: To measure the effectiveness of our advertisements on Meta services, we transmit event data on interactions with our online offer — such as page views, shopping cart actions, and orders — server-side to Meta. Pseudonymized information may be transmitted to assign the event to a Meta user account. For the collection and transmission of this event data, we are jointly responsible with Meta Platforms Ireland Limited; we have concluded the "Controller Addendum" for this purpose. Further processing of the data is the sole responsibility of Meta. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Legal basis: Consent (Art. 6(1)(a) GDPR). Privacy policy: https://www.facebook.com/privacy/policy. Third-country transfer basis: EU-US Data Privacy Framework.

The transmission takes place exclusively server-side via the Conversions API; a Meta Pixel in the browser is not used.

No third-party advertising is served on our website; we do not market advertising space to third parties.

Embedded Third-Party Content

We integrate functional and content elements that are obtained from servers of the respective providers. This requires that these providers process the IP address of users, as the content could not otherwise be transmitted to the browser. Providers may also use web beacons for statistical or marketing purposes.

OpenStreetMap: To display our location, we embed map material from OpenStreetMap. When loading the map sections, your IP address is transmitted to the operator of the map servers, as the map cannot otherwise be delivered to your browser. We do not request location data from your end device. Map display via Google Maps does not take place. Service provider: OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. Legal basis: Consent (Art. 6(1)(a) GDPR). Privacy policy: https://osmfoundation.org/wiki/Privacy_Policy. Third-country transfer basis: Adequacy decision of the European Commission for the United Kingdom (renewed on December 19, 2025, valid until December 27, 2031).

Fonts: The fonts we use are served from the infrastructure of our shop platform under our own domain. External font services such as Google Fonts are not integrated; no data is transmitted to third parties.

Social Media Presence

We maintain profiles in social networks to communicate with users and inform them about us. User data may be processed outside the European Union, which may make the enforcement of rights more difficult. Networks regularly process user data for market research and advertising purposes and create usage profiles, in which data can also be stored across devices — especially if users are members of the respective network and logged in there.

For details of processing and opt-out options, we refer to the privacy notices of the network operators. Access and deletion claims can be asserted most effectively directly against the providers, as only they have access to the data. However, you can also contact us.

Instagram: Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Privacy policy: https://privacycenter.instagram.com/policy. Third-country transfer basis: EU-US Data Privacy Framework.

Facebook Pages: For the collection and transmission of data from visitors to our Facebook page for Page Insights purposes, we are jointly responsible with Meta Platforms Ireland Limited. We have entered into the "Page Insights Controller Addendum" with Meta, which regulates security measures and the fulfillment of data subject rights; users can address access and deletion requests directly to Meta. Joint responsibility is limited to collection and transmission to Meta Platforms Ireland Limited; further processing is the sole responsibility of Meta. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Privacy policy: https://www.facebook.com/privacy/policy. Third-country transfer basis: EU-US Data Privacy Framework.

LinkedIn: For the collection of data from visitors to our LinkedIn page for page statistics ("Page Insights"), we are jointly responsible with LinkedIn Ireland Unlimited Company; the "Page Insights Joint Controller Addendum" was concluded for this purpose. Further processing is the sole responsibility of LinkedIn. Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Privacy policy: https://www.linkedin.com/legal/privacy-policy. Third-country transfer basis: EU-US Data Privacy Framework.

TikTok: Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, D02 T380, Ireland. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Privacy policy: https://www.tiktok.com/legal/privacy-policy-eea. Third-country transfer basis: Standard contractual clauses.

Mobile Application "Oberheim Connect"

This section describes the processing of personal data in our app for iOS and Android.

Function and Basic Principle

Oberheim Connect serves to set up, control, and configure our connected speakers. The app finds speakers in the local network and communicates with them directly via your home network. Control does not take place via our servers. We receive no information about your use of the app or your speakers.

No user account: No user account is required to use the app. We do not create user profiles and do not store personal usage data on our servers. Registration or login does not take place.

Data Stored on Your End Device

The app stores settings locally on your end device, in particular recognized speakers and their names, groupings, as well as sound and room correction settings. This data does not leave your end device and local network and is not transmitted to us. You can delete it by resetting app data or uninstalling the app.

Device Discovery in Local Network

To find speakers, the app uses network service discovery (mDNS/Bonjour) in your local network. Details published in the network, in particular device names, local IP addresses, and service information of the speakers, are processed. This processing takes place exclusively on your end device and within your network.

Legal basis: Contract performance (Art. 6(1)(b) GDPR) — discovery is necessary to provide the contractually promised functions.

Notes on Operating Systems: iOS/iPadOS: Upon first start, the operating system asks for your permission to access devices on the local network. Without this permission, we cannot automatically find your speakers; you can revoke permission at any time in system settings. In this case, manual connection via IP address remains possible. Android: To discover devices on Wi-Fi, the app uses the permission for nearby devices ("Nearby Wi-Fi devices"). This permission is explicitly not used to determine your location and is labeled accordingly. The app does not request location permission.

No Advertising, No Tracking

The app contains no advertising. We do not use advertising identifiers (no Identifier for Advertisers on iOS, no Advertising ID on Android), do not conduct cross-device or cross-provider tracking, and do not pass data to third parties for advertising purposes. Tracking within the meaning of Apple's App Tracking Transparency does not take place.

Error Diagnosis and Usage Analysis

The app contains no analytics or crash reporting features. No usage or diagnostic data is transmitted to us.

Microphone and Room Calibration

To calibrate your listening room, the app uses your end device's microphone. The speaker outputs a measurement signal, which is recorded via the microphone to determine the frequency response in the room and calculate filter settings for the speaker.

Recording takes place exclusively for this purpose and only during a measurement started by you. Evaluation takes place entirely on your end device. The audio recording is discarded after completion of the measurement and is not stored. Only the measurement result remains in the form of the frequency response, i.e., sound pressure levels over frequency; an audio signal is no longer contained therein. From this measurement result, filter settings for the speaker are calculated.

Audio recordings and measurement results are not transmitted to us and do not leave your end device and local network.

Microphone access requires your permission, which the operating system prompts for and which you can revoke in system settings at any time. Without microphone access, the calibration function is not available; all other functions of the app remain usable.

Legal basis: Contract performance (Art. 6(1)(b) GDPR) — the measurement is triggered by you and is necessary to provide the calibration feature.

Update Notifications

If you allow push notifications, we inform you exclusively about available firmware updates for your speakers. The content of such a notification consists of a notice text and the version number; personal data is not included.

Procedure: Notifications are sent as broadcast messages based on topics. The app subscribes to a topic with the delivery service of the respective operating system. We do not store device identifiers (push tokens) ourselves and do not maintain recipient lists. We therefore cannot track which or how many end devices received a notification, and cannot direct notifications to individual persons.

Not Processed: Push tokens, recipient lists, open or interaction rates, location data, or other details about your end device.

Transport: Technical delivery takes place OS-dependently via Apple Push Notification service (iOS) or Firebase Cloud Messaging (Android) and is not possible without these services. Service providers: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland; Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Objection and Deactivation: You can deactivate notifications at any time in your end device's system settings or in the app. Since we store no recipient data, no notice to us is necessary and no data needs to be deleted on our end.

Legal basis: Consent (Art. 6(1)(a) GDPR). Delivery requires that you allow notifications in your operating system.

App Acquisition via App Stores

The app is provided via the Apple App Store and Google Play. When downloading and updating, the respective store operators process data such as your identifier, payment information, and usage/download statistics under their own responsibility. We have no influence on this. We only receive summarized, non-personal statistics from store operators.

Apple: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Privacy policy: https://www.apple.com/legal/privacy/ Google: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://policies.google.com/privacy

Children

The app and our products are not directed at children. We do not knowingly collect personal data from children.

Connected Speakers

This section describes processing in connection with the operation of our connected speakers.

Local Operation

Our speakers are designed for operation in your local network. Playback, control, and configuration take place within your network. The speaker does not transmit usage, playback, or audio data to us. Settings and configurations are stored on the device and can be erased by resetting to factory settings.

Firmware Updates

To keep your speaker secure and functional, it checks whether updates to the operating software are available and downloads them from our delivery infrastructure. Technically required, the IP address of your Internet access is processed; furthermore, details about the device model and installed firmware version may be transmitted to deliver the appropriate update. We do not use this data to identify users or build usage profiles.

Legal bases: Contract performance including update obligations (Art. 6(1)(b) GDPR); Legal obligation to provide security updates (lit. c); Legitimate interests in secure product operation (lit. f).

Streaming via Third-Party Services

When you stream audio content to the speaker via third-party services — such as via AirPlay or music service applications —, the processing of your usage, account, and playback data is carried out by the respective provider under its own responsibility and according to its privacy policy. We receive no account or playback data in this context.

No Remote Access Without Your Consent

We have no remote access to your speaker. The device has no feature that allows us remote access or reading of data.