Privacy Policy
1. Data Controller
The data controller responsible for your personal data is:
TSI Solution GmbH
Pfalzgasse 7/1/61, 1220 Wien, Austria
UID: ATU82721002 · FN: 666498 w
Email: privacy (at) tel-tsi.eu
For all data protection queries, please use the email address above.
2. Scope of This Policy
This Privacy Policy applies to the TEL TSI Compliance Companion SaaS platform accessible at tel-tsi.eu (the "Service"). It describes what personal data we collect, why we collect it, how long we retain it, and your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Austrian Data Protection Act (DSG 2018).
3. Data We Collect and Why
3.1 Account Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Authentication, account management, transactional emails (e.g. password reset) | Performance of contract (Art. 6(1)(b) GDPR) |
| Organisation name | Workspace identification; shown on compliance reports | Performance of contract (Art. 6(1)(b) GDPR) |
| User role (admin / contributor / viewer) | Access control within your organisation workspace | Performance of contract (Art. 6(1)(b) GDPR) |
3.2 Assessment Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Assessment answers and progress (state_json) | Save and restore your TEL TSI compliance self-assessment across devices; generate PDF compliance reports | Performance of contract (Art. 6(1)(b) GDPR) |
| Assessment name and timestamps | Dashboard display; audit trail for your organisation | Performance of contract (Art. 6(1)(b) GDPR) |
3.3 Billing Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Payment-processor customer ID | Link your organisation to its subscription record with our payment processor | Performance of contract (Art. 6(1)(b) GDPR) |
| Subscription status, plan, and renewal date | Enforce access control; send renewal and subscription expiry notices | Performance of contract (Art. 6(1)(b) GDPR) |
| Payment card details and invoices | Processed and stored exclusively by our payment processor - we do not store card numbers or CVVs | Performance of contract; legal obligation (Art. 6(1)(b)(c) GDPR) |
3.4 Technical Data
We do not set advertising or cross-site tracking cookies. Our authentication provider sets a short-lived HTTP-only session cookie to maintain your login. For aggregate usage statistics we use two privacy-preserving, cookieless analytics tools. The first is a product analytics tool (PostHog, EU region). The second is the web analytics function of our hosting provider. Neither tool stores cookies or other identifiers on your device. Neither tool tracks you across websites. The web analytics function records the page URL, the referring page, the browser, the device type and an approximate location to city level (for example, "AT, Vienna"). We replace the values of sensitive query parameters before the page URL is sent. Examples of such parameters are an organisation identifier and an invitation code. The replacement text is "[redacted]". See Section 9 for details.
4. Sub-processors and Third-Party Services
To provide the Service we engage a small number of sub-processors. Each is bound by a data processing agreement and processes your data only on our documented instructions. They fall into the following categories:
| Category | Role | Location |
|---|---|---|
| Cloud database & authentication | Stores account and assessment records and manages sign-in (email/password and third-party single sign-on). Assessment data and account records are stored in the EU (Frankfurt, Germany) region. | EU (Frankfurt) |
| Product analytics | Aggregate, cookieless usage measurement (page views and feature usage). Records the page URL, the referring page, the browser, the device type and an approximate location to city level. Unless you accept the optional analytics consent described in section 9, it stores no cookies and no identifiers on your device: the provider derives a visitor identifier from the request itself, using a privacy-preserving hash that changes every day. No cross-site tracking, and no session recording. Analytics data is processed in the EU region. | EU |
| Web analytics (hosting provider) | Aggregate, cookieless page-view measurement. Records the page URL, the referring page, the browser, the device type and an approximate location to city level. Stores no cookies and no identifiers on your device. The provider derives a visitor identifier from the request itself and discards it after 24 hours. This function runs on the same provider as our hosting and inherits its location. | EU edge / US (SCCs apply) |
| Application & API hosting | Serves the front-end and serverless API functions, including PDF generation. | EU edge / US (SCCs apply) |
| Payment processing | Subscription billing and invoicing. Acts as an independent data controller for payment card data under PCI-DSS; we share only the minimum data required (email, customer ID). | US / EU (SCCs apply) |
| Email delivery | Sends transactional and notification emails; receives only the recipient email address and the message content necessary to deliver them. | US (SCCs apply) |
The current list of named sub-processors, including their corporate identity and location, is available on request to privacy (at) tel-tsi.eu. We do not sell personal data to any third party.
5. Retention Periods
| Data Category | Retention | Reason |
|---|---|---|
| Account and organisation data | Until account deletion, plus 30 days (soft-delete buffer) | Service provision; recovery period |
| Assessment answers and reports | Until the assessment is deleted by the user, or until account deletion | Service provision |
| Billing records (invoices, payment history) | 7 years after the relevant subscription period | Austrian tax law (§ 212 BAO) |
| Authentication session tokens | 1 hour (JWT expiry); refresh tokens valid for 7 days | Security |
| Session replays of public pages (consent-based, see Section 9) | 30 days, then deleted automatically | Understanding how visitors use the public site |
6. Your Rights Under the GDPR
As a data subject in the EU/EEA, you have the following rights:
- Right of access (Art. 15) - request a copy of all personal data we hold about you.
- Right to rectification (Art. 16) - ask us to correct inaccurate data.
- Right to erasure / "right to be forgotten" (Art. 17) - request deletion of your account and all associated data, subject to legal retention obligations (e.g. billing records).
- Right to restriction of processing (Art. 18) - ask us to pause processing while a dispute is resolved.
- Right to data portability (Art. 20) - receive your assessment data in a machine-readable format (JSON).
- Right to object (Art. 21) - object to processing based on legitimate interests.
- Right to withdraw consent - where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, email privacy (at) tel-tsi.eu. We will respond within 30 days. You also have the right to lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at) or the supervisory authority in your EU member state.
7. International Data Transfers
Your assessment data is stored in our EU (Frankfurt) region and does not leave the EEA in normal operations. Certain providers (for example, application hosting and payment processing) may process limited metadata (IP address, request logs) outside the EEA, subject to Standard Contractual Clauses (SCCs) under Art. 46 GDPR. Copies of the applicable SCCs are available on request.
8. Data Security
We implement the following technical and organisational measures to protect your data:
- All data in transit is encrypted via TLS 1.2+.
- All data at rest is encrypted in our EU database (AES-256).
- Authentication uses short-lived JWT tokens with database Row-Level Security (RLS) policies that restrict each user to their own organisation's data.
- API endpoints require a valid Bearer token; unauthenticated requests are rejected.
- Our payment processor is PCI-DSS Level 1 certified - we never transmit or store raw payment card data.
- Access to production systems is limited to authorised personnel only.
9. Cookies, Tracking and Session Replay
Default (no consent): the Service uses a single, strictly necessary session cookie set by our authentication provider to maintain your authenticated session; it is deleted when you sign out. We do not use advertising cookies or tracking pixels. Both of our analytics tools run in a cookieless mode. The product analytics tool (PostHog, EU region) sends no identifier from your browser. The provider derives a visitor identifier from the request itself, using a privacy-preserving hash that changes every day, so it cannot recognise you tomorrow or on another device. The web analytics function of our hosting provider sends no identifier from your browser. The provider derives a visitor identifier from the request itself, and discards it after 24 hours. Neither tool writes to cookies or local storage, so no non-essential information is stored on or read from your device. This is how the Service behaves unless and until you opt in below. We do not use Google Analytics, Microsoft Clarity, or any advertising service.
Optional, with your consent (Art. 6(1)(a) GDPR / § 165(3) TKG 2021): on our public pages we ask - via a small, non-blocking notice - whether we may (a) store an analytics identifier in a cookie and local storage so repeat visits can be recognised, and (b) record a replay of your browsing session on the public pages to understand how visitors use the site. Session replay runs only after you accept, applies only to public marketing pages (never the logged-in application), masks all text you type, and recordings are automatically deleted after 30 days. Declining or ignoring the notice leaves the cookieless default in place, and the site works identically either way. Your choice itself is stored locally on your device, which is strictly necessary to honour it. Your choice applies to the product analytics tool only; the web analytics function stays cookieless either way.
Withdrawing consent: you can withdraw at any time - . Withdrawal stops any recording, removes the analytics cookie and local-storage identifiers from your device, and returns the Service to the cookieless default. It does not affect the lawfulness of processing before withdrawal.
10. Children's Data
The Service is intended for business professionals in the rail sector (railway undertakings, infrastructure managers, and rail freight facility operators). We do not knowingly collect personal data from individuals under 16 years of age. If you believe a minor has registered, please contact us immediately at privacy (at) tel-tsi.eu.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to registered users by email at least 14 days before taking effect. The version number and effective date at the top of this document will always reflect the current policy. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
12. Contact
TSI Solution GmbH
Pfalzgasse 7/1/61, 1220 Wien, Austria
Email: privacy (at) tel-tsi.eu