Privacy policy
Version: 18 July 2026
1. Controller
The controller responsible for the processing of personal data in connection with this website and the related business activities is:
Ceratec Audio Design GmbH
Registered office: Straubingerstrasse 5, 28219 Bremen, Germany
Business premises: Walter-Bertelsmann-Weg 2, 27726 Worpswede, Germany
Managing Director: Ulrich Ranke
Commercial Register: Local Court of Bremen, HRB 19153
VAT Identification Number: DE 203341909
Telephone: +49 (0) 4792 9557080
Email: info@cerasonar.de
“Ceratec”, “cerasonar”, “we”, “us” and “our” refer to Ceratec Audio Design GmbH.
Data-protection enquiries may be sent to info@cerasonar.de.
2. Scope of this Privacy Policy
This Privacy Policy explains how we process personal data when you:
a. visit cerasonar.de;
b. create or use a dealer account;
c. request access to dealer or media resources;
d. submit an enquiry or project request;
e. place or manage an order;
f. apply to become a sales partner;
g. schedule a meeting;
h. subscribe to a newsletter; or
i. otherwise communicate or do business with us.
Our products are sold exclusively to business customers. Nevertheless, business contact details such as an employee’s name, business email address, direct telephone number and online identifier can constitute personal data.
This Privacy Policy does not govern independent third-party websites or services that you access through an external link.
3. Applicable law and legal bases
We process personal data in accordance with the General Data Protection Regulation (“GDPR”), the German Federal Data Protection Act (“BDSG”) and the German Telecommunications Digital Services Data Protection Act (“TDDDG”).
Depending on the processing activity, we rely on one or more of the following legal bases:
a. Article 6(1)(a) GDPR: consent;
b. Article 6(1)(b) GDPR: steps requested before entering into a contract or performance of a contract with the data subject;
c. Article 6(1)(c) GDPR: compliance with a legal obligation; and
d. Article 6(1)(f) GDPR: our legitimate interests or those of a third party, provided that the interests or fundamental rights and freedoms of the data subject do not override those interests.
Where an employee, representative or contact person acts on behalf of a corporate customer, distributor, dealer, supplier or other organisation, processing is normally based on our legitimate interest in establishing and managing the relevant business relationship under Article 6(1)(f) GDPR.
Where information is stored on or accessed from a user’s terminal device, we additionally apply section 25 TDDDG. Non-essential storage or access takes place only with consent unless another statutory exception applies.
4. Categories of personal data
Depending on your interaction with us, we may process:
a. name, title and position;
b. employer, business name and department;
c. business address, delivery address and billing address;
d. email address and telephone number;
e. commercial-register, business-registration and VAT details;
f. dealer, distributor and account credentials;
g. quotation, order, invoice, delivery and payment information;
h. project information, drawings, room plans and technical requirements;
i. correspondence and customer-service records;
j. newsletter and communication preferences;
k. IP address, device, browser and log information;
l. cookie identifiers and consent records; and
m. information necessary for fraud prevention, export-control screening and legal compliance.
We generally do not request special categories of personal data within the meaning of Article 9 GDPR. Please do not send such data unless it is necessary and has been expressly requested.
5. Sources of personal data
We obtain personal data:
a. directly from you;
b. from the business or organisation you represent;
c. from authorised distributors, dealers and project partners;
d. from public business registers and professional sources;
e. from payment, logistics and fraud-prevention providers; and
f. automatically when you use our website.
Where we receive your business contact details from your employer, a project partner or a public professional source, we process them for the purpose of establishing or managing a relevant business relationship.
6. Website access and server logs
When you access our website, technical information may automatically be processed, including:
a. IP address;
b. date and time of access;
c. requested page or file;
d. referrer URL;
e. browser type and version;
f. operating system and device information;
g. transferred data volume; and
h. access status or error information.
This processing is necessary to deliver the website, maintain stability and security, prevent abuse and investigate technical or security incidents.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of the website and the protection of our systems.
Log data is deleted or anonymised when it is no longer required for these purposes, unless continued retention is necessary to investigate a security incident, establish or defend legal claims or comply with a legal obligation.
7. Shopify platform and hosting
Our website and online dealer facilities are operated using the Shopify platform.
The principal European Shopify service provider is:
Shopify International Limited
2nd Floor, Victoria Buildings
1–2 Haddington Road
Dublin 4, D04 XN32
Ireland
Shopify processes technical website data, account information, order data, checkout data, security information and other data required to provide the platform.
Depending on the function used, Shopify may process data on our behalf as a processor or process certain data under its own responsibility, for example in connection with payment, fraud-prevention or platform-security services.
Processing required to provide the website and dealer functions is based on Article 6(1)(b) or Article 6(1)(f) GDPR, depending on whether the data subject is personally party to the contract.
Necessary storage of or access to information on a terminal device is based on section 25(2) TDDDG. Optional analytics, advertising or personalisation functions are activated only on the basis of consent under section 25(1) TDDDG and Article 6(1)(a) GDPR.
Shopify and its subcontractors may process data outside the European Economic Area. The safeguards described in section 20 of this Privacy Policy apply.
8. Dealer accounts and restricted resources
When you apply for or create a dealer account, we process the information entered in the registration form, together with verification and account-usage information.
We use this information to:
a. verify business status;
b. decide whether to approve dealer access;
c. provide price lists, technical documents and restricted resources;
d. administer the account;
e. process quotations and orders;
f. prevent unauthorised access and misuse; and
g. manage the business relationship.
For sole traders and other individuals who are personally party to the contract, the legal basis is Article 6(1)(b) GDPR.
For employees and representatives of corporate customers, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the efficient administration and security of our dealer network.
Account data is retained for the duration of the active business relationship. After closure, data may be retained where required for contractual documentation, fraud prevention, statutory retention obligations or legal claims.
9. Enquiries, project support and customer service
If you contact us by email, telephone, contact form or another communication channel, we process the information you provide in order to:
a. respond to the enquiry;
b. provide technical or project assistance;
c. prepare a quotation or system recommendation;
d. manage an existing order or business relationship; and
e. document the communication.
Where the enquiry concerns a contract with the data subject, the legal basis is Article 6(1)(b) GDPR.
In other business-contact cases, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is responding to legitimate business enquiries and managing commercial relationships.
If you submit plans, drawings, photographs or project documents, you are responsible for ensuring that you are authorised to provide any personal data contained in those documents.
10. Quotations, orders and contractual processing
We process customer, contact, delivery, billing, product, payment and transaction information in order to:
a. prepare quotations;
b. accept and process orders;
c. arrange payment and delivery;
d. provide product and project support;
e. manage returns, complaints and warranty cases;
f. perform accounting and tax obligations; and
g. establish, exercise or defend legal claims.
For individual contracting parties, processing is based on Article 6(1)(b) GDPR.
For contact persons acting on behalf of a business, processing is based on Article 6(1)(f) GDPR.
Processing required by commercial, accounting, customs, export-control or tax law is based on Article 6(1)(c) GDPR.
11. Order-management providers
We may use specialist order-management, inventory, invoicing and fulfilment providers, including Billbee GmbH, to process orders and coordinate fulfilment.
The data may include:
a. customer and contact details;
b. order and product details;
c. delivery and billing addresses;
d. invoice and payment status; and
e. shipment information.
The legal basis is Article 6(1)(b), Article 6(1)(c) or Article 6(1)(f) GDPR, depending on the processing context.
Where the provider acts as our processor, it is contractually required to process personal data only in accordance with our documented instructions.
12. Shipping and logistics
We disclose the information required for delivery to the selected carrier or logistics provider, which may include UPS and other domestic or international carriers.
The disclosed information may include:
a. recipient name;
b. company name;
c. delivery address;
d. telephone number;
e. email address;
f. order or shipment reference; and
g. customs and export information.
The legal basis is Article 6(1)(b) GDPR where the data subject is personally party to the contract and Article 6(1)(f) GDPR where the recipient is a contact person acting for a corporate customer.
Where contact details are used solely to provide optional shipment notifications, we will rely on consent where required.
International deliveries may require disclosure to carriers, customs authorities, customs brokers and other recipients in the destination or transit countries.
13. Payments
Depending on the selected payment method, payment and transaction data may be processed by banks, Shopify payment services and independent payment providers such as PayPal, PAYONE or the provider of the payment method selected at checkout.
The relevant provider may receive:
a. name and business details;
b. billing information;
c. transaction amount and currency;
d. order reference;
e. payment-account or payment-token information;
f. device and fraud-prevention information; and
g. payment status.
Payment providers may process certain information as independent controllers under their own privacy policies, particularly for payment execution, fraud prevention, regulatory compliance and credit assessment.
We do not normally receive complete credit-card details. Such details are processed by the relevant certified payment provider.
The legal basis for payment processing is Article 6(1)(b) GDPR. Fraud-prevention and security processing may additionally be based on Article 6(1)(f) GDPR or a legal obligation under Article 6(1)(c) GDPR.
14. Newsletter
You may subscribe to our email newsletter.
We normally use a double-opt-in procedure. After registration, you receive an email asking you to confirm the subscription.
We process:
a. email address;
b. name, where voluntarily provided;
c. language and market information, where provided;
d. date and time of registration and confirmation;
e. IP address used for registration and confirmation; and
f. newsletter interaction data where you have consented to such measurement.
The legal basis for sending consent-based newsletters is Article 6(1)(a) GDPR.
You may withdraw your consent at any time by using the unsubscribe link in a newsletter or contacting info@cerasonar.de. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We may use MailerLite or another contracted email-delivery provider to send and manage newsletters.
Where newsletter-opening or link-click measurement is used, it is activated only where the required consent has been obtained.
After unsubscribing, your address may be retained on a suppression list to ensure that no further newsletter is sent. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is compliance with the withdrawal request.
Evidence of consent may be retained for the period required to demonstrate compliance and defend legal claims.
15. Cookies and similar technologies
Our website uses cookies and comparable technologies.
15.1 Strictly necessary technologies
Strictly necessary technologies may be used to:
a. provide the website and checkout;
b. maintain a secure session;
c. remember the contents of a shopping cart;
d. authenticate dealer accounts;
e. prevent fraud and abuse;
f. store privacy and consent preferences; and
g. balance website traffic and ensure technical stability.
Where information is stored on or accessed from a terminal device solely because this is strictly necessary to provide a service expressly requested by the user, section 25(2) TDDDG applies.
Any subsequent processing of personal data is based on Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the function.
15.2 Optional technologies
Analytics, advertising, personalisation and other non-essential technologies are used only after the user has given the required consent.
The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR.
You can give, refuse or withdraw consent through the consent-management tool available on the website. Withdrawal applies to the future and does not affect processing already carried out lawfully.
Refusing optional technologies does not prevent access to the core website, although individual optional features may not be available.
15.3 Cookie details
The consent-management tool provides current information about:
a. the technology or cookie name;
b. the provider;
c. the purpose;
d. the storage duration; and
e. the applicable category.
Because website technologies may change, the cookie list maintained in the consent tool forms the current detailed cookie inventory.
16. Website analytics
Where enabled and consented to, we may use website-analytics services to understand how the website is used and to improve content, navigation and technical performance.
Analytics data may include:
a. pages viewed;
b. interactions and events;
c. approximate location;
d. browser and device information;
e. referrer information;
f. truncated or otherwise protected IP information; and
g. pseudonymous identifiers.
Optional analytics are used only on the basis of section 25(1) TDDDG and Article 6(1)(a) GDPR.
Google Analytics
Where Google Analytics 4 is enabled, the provider for users in the European Economic Area is generally Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google may also process data in the United States and other countries.
Google Analytics is not activated before the required consent has been given. Consent can be withdrawn at any time through the website’s consent-management tool.
We configure analytics settings with the objective of data minimisation and use the shortest retention periods reasonably suitable for our analytics purposes.
No Google Universal Analytics disclosure should be interpreted as authorising the use of the discontinued Universal Analytics service. Only the analytics technology actually implemented on the website is covered by this section.
17. Scheduling through Calendly
Our website may contain a link to Calendly for scheduling meetings.
If Calendly is opened as an external website, data is transmitted to Calendly only when you follow the link and use its service.
Calendly may process:
a. name and contact details;
b. selected appointment information;
c. time zone;
d. answers entered into the booking form;
e. technical and device data; and
f. communication and reminder information.
Where we receive appointment information from Calendly, we process it to schedule and conduct the requested meeting.
The legal basis is Article 6(1)(b) GDPR where the meeting concerns a potential or existing contract with the data subject. In other business cases, the legal basis is Article 6(1)(f) GDPR.
Calendly may process information in the United States. The safeguards described in section 20 apply.
18. Partner applications through Typeform
We may use Typeform for distributor, dealer or partner applications.
If you use the relevant form, Typeform and we process the information requested in the form, which may include:
a. name and contact details;
b. company and market information;
c. business experience;
d. territory and customer information; and
e. information voluntarily included in the application.
The purpose is to assess and respond to the proposed business relationship.
For individual applicants, the legal basis is Article 6(1)(b) GDPR. For representatives of corporate applicants, the legal basis is Article 6(1)(f) GDPR.
Typeform is operated by a provider established in Spain and may use subcontractors in other countries.
19. YouTube and other external content
Our website may link to videos or other content hosted by YouTube or other third parties.
Where content is provided only as an external link, data is normally transferred to the third party when you click the link.
Where a third-party video or other external resource is embedded directly on our website, it will be loaded before consent only if it can be operated without non-essential storage, access or personal-data transmission. Otherwise it will be blocked until the required consent has been given.
When YouTube content is activated, Google may process IP address, device information, video interactions, account information and cookie or identifier data.
The legal bases for non-essential embedded content are section 25(1) TDDDG and Article 6(1)(a) GDPR.
20. International data transfers
Some service providers, carriers, distributors, customers or subcontractors may be located outside the European Economic Area.
Where personal data is transferred to a country outside the European Economic Area, we use an appropriate transfer mechanism where required, including:
a. an adequacy decision of the European Commission;
b. the EU–US Data Privacy Framework for recipients validly participating in that framework;
c. standard contractual clauses approved by the European Commission; or
d. another transfer mechanism permitted under Articles 44 to 49 GDPR.
Where appropriate, we assess whether supplementary technical, contractual or organisational safeguards are required.
For worldwide deliveries and international dealer relationships, certain transfers may also be necessary for contract performance, customs clearance or the establishment, exercise or defence of legal claims.
21. Recipients of personal data
Depending on the processing activity, personal data may be disclosed to:
a. hosting and e-commerce providers;
b. IT, security and support providers;
c. order-management and accounting providers;
d. payment providers, banks and fraud-prevention services;
e. shipping companies, freight forwarders and customs brokers;
f. distributors, sales partners and project partners;
g. newsletter and communications providers;
h. professional advisers, auditors and insurers;
i. courts, authorities and regulatory bodies; and
j. prospective purchasers or successors in connection with a corporate transaction, subject to appropriate safeguards.
Service providers acting as processors are contractually bound in accordance with Article 28 GDPR.
22. Retention periods
We retain personal data only for as long as necessary for the relevant purpose or required by law.
In particular:
a. account data is normally retained for the duration of the account and any subsequent period required for contractual, security or legal purposes;
b. quotation, order and contractual data is retained for the duration of the business relationship and applicable limitation and retention periods;
c. accounting vouchers and invoices may be retained for eight years;
d. books, financial statements and certain tax records may be retained for ten years;
e. commercial and business correspondence may be retained for six years;
f. enquiry and project correspondence may be retained for up to three years after the end of the calendar year in which the matter was concluded, unless a longer period is required;
g. newsletter data is retained until consent is withdrawn or the newsletter service ends, while evidence of consent may be retained for an additional period required to demonstrate compliance; and
h. consent and objection records may be retained for the period necessary to prove compliance.
Longer retention may apply where data is required for pending proceedings, legal claims, audits, product-safety obligations, warranty cases or mandatory regulatory requirements.
When data is no longer required, it is deleted or anonymised unless continued storage is legally required.
23. Data security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures include, as appropriate:
a. encrypted transmission;
b. access controls and authentication;
c. role-based permissions;
d. backup and recovery measures;
e. security monitoring;
f. processor due diligence; and
g. internal confidentiality and data-protection requirements.
No internet transmission or storage system can be guaranteed to be completely secure.
24. Obligation to provide data
Certain information is required in order to:
a. create and secure a dealer account;
b. verify business status;
c. prepare a quotation;
d. conclude and perform a contract;
e. arrange payment and delivery; or
f. comply with legal requirements.
Without the required information, we may be unable to provide account access, process an order, make a delivery or enter into the requested business relationship.
Newsletter registration and optional marketing information are voluntary.
25. Automated decision-making
We do not normally make decisions producing legal or similarly significant effects based solely on automated processing within the meaning of Article 22 GDPR.
Payment, fraud-prevention or security providers may use automated risk indicators under their own responsibility. Where required, the relevant provider will supply additional information.
26. Rights of data subjects
Subject to the applicable statutory conditions, you have the right to:
a. obtain access to your personal data under Article 15 GDPR;
b. request correction of inaccurate data under Article 16 GDPR;
c. request deletion under Article 17 GDPR;
d. request restriction of processing under Article 18 GDPR;
e. receive information about recipients under Article 19 GDPR;
f. receive data in a portable format under Article 20 GDPR;
g. object to processing under Article 21 GDPR;
h. withdraw consent under Article 7(3) GDPR; and
i. lodge a complaint with a data-protection supervisory authority under Article 77 GDPR.
These rights may be restricted by statutory exceptions, including legal retention obligations and requirements for the establishment, exercise or defence of legal claims.
Requests may be sent to info@cerasonar.de.
We may request information reasonably necessary to verify the identity of the person making the request.
27. Right to object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to that processing.
If you object, we will no longer process the personal data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless processing is necessary for the establishment, exercise or defence of legal claims.
You may object at any time to the processing of personal data for direct-marketing purposes. Following such an objection, the personal data will no longer be processed for direct marketing.
28. Withdrawal of consent
Where processing is based on consent, you may withdraw that consent at any time with effect for the future.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Cookie and analytics consent can be changed through the website’s consent-management tool. Newsletter consent can be withdrawn through the unsubscribe link or by contacting us.
29. Complaints
You have the right to lodge a complaint with a competent data-protection supervisory authority.
You may contact the supervisory authority responsible for your habitual residence, your place of work, the place of the alleged infringement or our establishment.
We encourage you to contact us first so that we have an opportunity to address your concern.
30. Changes to this Privacy Policy
We may update this Privacy Policy where our processing activities, service providers, website functions or legal requirements change.
The version and update date displayed at the beginning of the policy identify the current version.
Material changes will be communicated through the website or another appropriate channel where required.