Privacy Policy for the use of ShowCode SoundBase Services
Table of Contents:
1. Introduction and scope of this Privacy Policy
1.1 Data Controller
1.2 Representative in the European Union (Art. 27 GDPR)
2.1 General information on data processing
2.2 Visiting our website
2.3 Data processing during registration for an account and access to Soundbase
2.4 Data processing during the use of Soundbase
2.5 Data processing when contacting us
2.6 Data processing for marketing purposes
2.7 Tracking to analyze and optimize our services and their use, as well as to measure the success of advertising campaigns and to optimize the display of advertising
2.8 Cookies and other information stored on your device
3. Rights of the data subjects
3.1 Right to object
3.2 Right of access
3.3 Right of correction
3.4 Right to erasure („Right to be forgotten”)
3.5 Right to restriction of processing
3.6 Right to Data Portability
3.7 Right to withdraw consent
3.8 Right to lodge a complaint
1. Introduction and scope of this Privacy Policy
We appreciate your interest in SoundBase. Protecting your personal data is important to us. ShowCode Corp. (“ShowCode”) offers various audio-centric applications and tools under the brand name SoundBase (“Soundbase”), which can be accessed via the website www.soundbase.app (“Website”) or via the Soundbase Application (“App”).
In this privacy policy, we inform you about the nature, scope, and purpose of the collection and use of personal data when registering, accessing and using Soundbase.
1.1 Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) – i.e. the party who decides on the purposes and means of processing personal data – in connection with the processing is
ShowCode Corp.
2 Enterprise Dr.
Old Lyme, CT 06371
USA
Email: support@showcode.com
1.2 Representative in the European Union (Art. 27 GDPR)
As we are a company based in the United States of America (“USA”), we are obliged to name a representative within the European Union (“EU”).
Our representative in the EU is:
Sennheiser electronic SE & Co. KG
Am Labor 1
30900 Wedemark
Germany
Email: datenschutz@sennheiser.com
2. Data processing in detail
In this section of the privacy policy, we provide detailed information about the processing of personal data. For clarity, we have organized this information according to specific functions.
2.1 General information on data processing
Unless otherwise specified, the following applies to all processing operations described below:
2.1.1 No obligation to provide personal data
Unless there is a contractual or legal obligation to provide personal data, you are not obliged to provide data.
2.1.2 Consequences of non-provision
If data is required (e.g., data that is marked as mandatory), failure to provide same will result in the service in question not being provided. Otherwise, failure to provide same may result in our services not being provided in the same form and quality.
2.1.3 Transferring personal data to government authorities
We only transfer personal data to government authorities (including law enforcement agencies) if this is necessary to fulfill a legal obligation to which we are subject or if it is necessary to assert, exercise, or defend legal claims.
2.1.4 Retention of personal data
We do not store your data for longer than we need it for the respective processing purposes. If the data is no longer required, it is regularly deleted, unless its temporary storage is still necessary. Reasons for this may include, for example:
• Compliance with legal retention obligations
• Obtaining evidence for legal disputes within the framework of the statutory limitation provisions
2.1.5 Categories of personal data processed by us
- account data: username and password
- personal master data: title, name, date of birth
- address data: Street, house number, additional address information if applicable, postal code, city, state/province, country
- contact data: phone number, E-Mail
- registration data: information about the service you signed up for; times and technical information about registration, confirmation, and cancellation; data you provided during registration
- payment data: bank account data, credit card data, data relating to payment providers (please see below for details)
- log file data: date and time of your visit to our service; the website from which the accessing system reached our site; websites accessed during use; session identification data (session ID); and the following information about the accessing computer system: Internet Protocol address (IP address) used, browser type and version, device type, operating system, and similar technical information.
2.2 Visiting our website
This section describes how we process your personal data when you visit our website.
2.2.1 Information regarding the processing
- categories of personal data: log file data
- purpose of processing: establishing connections, displaying service content, detecting attacks on our site based on unusual activity, troubleshooting
- legal basis: legitimate interests (Art. 6(1)(f) GDPR)
- our legitimate interests: Proper functioning of services, security of data and business processes, prevention of misuse, prevention of damage caused by interference with information systems
- retention period: Logs are immediately accessible for 3 days. After this time, they are archived into one-month chunks and deleted after 1 month.
- recipients: Better Stack, Inc. 651 N Broad Street, Suite 206 Middletown, Delaware 19709 United States +1 628-900-3830, DigitalOcean LLC 105 Edgeview Drive, Suite 425 Broomfield, CO, 80021
2.3 Data processing during registration for an account and access to Soundbase
When registering for an account and accessing SoundBase, we process the following personal data:
2.3.1 Information regarding the processing
- categories of personal data: account data, registration data
- purpose of processing: to generate an account and to provide you with access to SoundBase
- legal basis: performance of a contract (Art. 6(1)(b) GDPR in connection with the SoundBase Terms of Use)
- retention period: The data collected during registration will be stored as long as you have a SoundBase account. If you delete your SoundBase account, your data will be deleted unless statutory retention periods require longer storage.
- recipients: We use MongoDB Atlas, a cloud-based database service provided by MongoDB Inc., 1633 Broadway, 38th Floor, New York, NY 10019, USA. MongoDB Inc. processes data in the USA.
- Other recipients: DigitalOcean LLC, 105 Edgeview Drive, Suite 425 Broomfield, CO, 80021
2.4 Data processing during the use of Soundbase
When using SoundBase, we process the following personal data:
2.4.1 Information regarding the processing
- categories of personal data: personal master data, contact data, payment data
- purpose of processing: to enable you to use the features of Soundbase, for example use of any interactive or collaboration features, such as sending a message through SoundBase, fill out a form, publish statements of the platform, sharing contents with other users
- legal basis: performance of a contract (Art. 6(1)(b) GDPR in connection with the SoundBase Terms of Use)
- retention period: The data will be stored for as long as necessary to fulfill the contractual obligations and for the duration of your use of SoundBase. If you delete the Soundbase account, your data will be deleted unless statutory retention periods require longer storage.
- recipients: MongoDB, Inc. (as detailed in the previous section) and the online payment service provider Stripe (Stripe Inc., 510 Townsend St., San Francisco, CA 94103, USA) on our website. For customers within the EU, Stripe Payments Europe, (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Irland), is responsible. When you choose Stripe as your payment method, personal data such as payment method (e.g., credit card, debit card), bank code, currency, amount, and transaction date are transferred to Stripe. We offer Stripe as a payment service provider, in addition to traditional banks/credit institutions, to fulfill contractual relationships. Stripe Inc. may process data in the USA, among other locations. As mentioned in 2.2.1 Better Stack Inc. , 651 N Broad Street, Suite 206, Middletown, Delaware 19709, United States. In order to comply with internal accounting obligations within the Sennheiser Group, financial data (which may contain personal user information) is transferred to the Sennheiser group entity Sennheiser Global Services Sp. z o.o., Pl. Władysława Andersa 3, Poznan Wielkopolskie 61-894, Poland and Sennheiser Electronic Corporation, 1 Enterprise Dr., Old Lyme CT 06371 USA.
2.5 Data processing when contacting us
If you contact us through SoundBase, we process the following personal data:
2.5.1 Information regarding the processing
- categories of personal data: personal master data, contact data, contents of your message
- purpose of processing: to handle any request you may have to our consumer services such as resolving your problem or question, manage any complaints or deal with any feedback you may provide to us
- legal basis: performance of a contract (Art. 6(1)(b) GDPR in connection with the SoundBase Terms of Use)
- retention period: The data will be stored for the duration necessary to process your request and any subsequent queries. After the request has been fully processed, the data will be deleted unless statutory retention periods require longer storage.
- recipients: Zendesk, Inc., 181 Fremont Street, San Francisco, CA 94105, United States (support ticket handling)
2.6 Data processing for marketing purposes
When we engage in marketing activities (e. g. by means of contests or promotions) towards you, we process the following personal data. We only contact you for marketing purposes if you consent in advance:
2.6.1 Information regarding the processing
- categories of personal data: personal master data, contact data
- purpose of processing: marketing activities such as contests or promotions
- legal basis: consent (Art. 6(1)(a) GDPR
- retention period: the data will be stored and used for the abovementioned purposes for as long as you do not revoke your consent.
- recipients: Sennheiser electronic SE &Co. KG, Am Labor 1, 30900 Wedemark, Germany
2.7 Tracking to analyze and optimize our services and their use, as well as to measure the success of advertising campaigns and to optimize the display of advertising
Below, we describe how your personal data is processed using tracking technologies for the analysis and optimization of our Website and App. The description of the tracking procedures also includes information on how you can prevent or object to data processing. Please note that the so-called “opt-out,” i.e., the rejection of processing, is usually stored via cookies. If you use our services on a new device or in a different browser, or if you have deleted the cookies set by your browser, you must declare your rejection again.
Purposes of processing
Analyzing user behavior through tracking helps us to check the effectiveness of our services, optimize them, adapt them to the needs of users, and fix errors. Tracking to measure the success of advertising campaigns serves to optimize our ads for the future.
Legal basis
Consent (Art. 6(1)(a) GDPR)
Information on the tracking methods used can be found in the consent tool and in the following section:
- tool used: Matomo
- purpose: analysis how user use SoundBase and optimization of our services
- personal data processed: region, IP address, country, user ID, system details
- technologies used: javaScript + cookie (only with consent)
- legal basis : legitimate interests - to optimize the software performance for various countries and user locations. This is necessary to assure that the software is working smoothly around the world
Recipients: Matomo by InnoCraft, 7 Waterloo Quay PO625, 6140 Wellington, New Zealand
2.8 Cookies and other information stored on your device
To make SoundBase more attractive and to enable the use of certain functions, we and certain third parties use cookies or local storage entries on our Website or on the App. These are small text files or pieces of information that are stored on your device. Some of the cookies or local storage entries we use are deleted after the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies or local storage entries remain on your device and allow us or our partner companies to recognize your browser on your next visit (so-called persistent cookies).
The following cookie categories are used:
Technically Necessary Cookies:
These cookies or local storage entries are technically necessary for the operation and functionality of the website. They make the website technically accessible, secure, and usable and provide essential and fundamental functionalities, such as navigation on the website, correct display of the website in the internet browser, or consent management. Since these are technically necessary cookies or local storage entries, we may store these on your device without your consent.
- Provider: Stripe
- Purpose: Provides transaction flow state to Stripe and customer ID information
- Cookie Function: userId
- Storage Duration: 1 year
- Provider: monti-APM
- Purpose: Links session data with backend server logs
- Cookie Function: userStatus
- Storage Duration: 1 year
- Provider: my.soundbase.app
- Purpose: Allows users to resume sessions on the same server that they were previously connected to.
- Cookie Function: cache-control
- Storage Duration: 6 months
Non-Necessary Cookies:
These cookies or local storage entries provide features or enable the use of certain tools on our Website or in our App explained above. We will require and obtain your consent before the cookies or local storage entries are stored on your device.
- Provider: Matomo
- Purpose: Track user behavior over several visits
- Cookie Function: user session
- Storage Duration: 1 year
Deactivation of Cookie Settings
Most browsers are preset to automatically accept cookies. You can object to the creation of cookies by disabling cookies in your browser's system settings. However, please note that some cookies are technically necessary for the functionality of our website, as the site cannot be accessed and displayed otherwise. By disabling cookies, you may not be able to use the website to its full extent.
Cookies that are not technically necessary for the functionality of our website are only used with your prior consent.
Furthermore, you can also control the installation of cookies yourself at any time by changing your browser settings and/or deleting all cookies
3. Rights of the data subjects
3.1 Right to object
You have the right to object, on grounds relating to your particular situation, at any time with effect for the future, to the processing of personal data concerning you which is carried out in accordance with Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions.
You can exercise your right to object free of charge.
3.2 Right of access
You have the right to know whether we process personal data relating to you, what personal data this may be, and to receive further information in accordance with Art. 15 GDPR.
3.3 Right of correction
You have the right to request that we immediately correct any inaccurate personal data concerning you (Art. 16 GDPR). Taking into account the purposes of the processing, you have the right to request the completion of incomplete personal data, including by means of a supplementary statement.
3.4 Right to erasure („Right to be forgotten”)
You have the right to request that we erase personal data concerning you without undue delay, provided that one of the reasons specified in Art. 17 (1) GDPR applies and the processing is not required for one of the purposes specified in Art. 17 (3) GDPR.
3.5 Right to restriction of processing
You have the right to request a restriction on the processing of your personal data if one of the conditions set out in Art. 18(1)(a) to (d) GDPR applies.
3.6 Right to Data Portability
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format. Furthermore, you have the right to transfer this data to another controller without hindrance from us or to have us transfer it directly, provided this is technically feasible. This right shall apply if the basis for data processing is consent or a contract and the data is processed automatically. This does not apply to data stored in paper form only.
3.7 Right to withdraw consent
You may withdraw your consent at any time; however, the processing of personal data by us remains lawful until the time you withdraw your consent.
3.8 Right to lodge a complaint
You have the right to file a complaint with a supervisory authority.