Privacy Policy

Version 1.2 Effective date: 27 June 2026 Last updated: 13 August 2026
Summary. We collect the minimum data needed to provide the TEL TSI Compliance Companion: your email address for authentication, your assessment answers to save your progress, and standard billing information processed by our payment provider. All data is stored in the EU. You can request deletion at any time.

1. Data Controller

The data controller responsible for your personal data is:

TSI Solution GmbH
Pfalzgasse 7/1/61, 1220 Wien, Austria
UID: ATU82721002  ·  FN: 666498 w
Email: privacy (at) tel-tsi.eu

For all data protection queries, please use the email address above.

2. Scope of This Policy

This Privacy Policy applies to the TEL TSI Compliance Companion SaaS platform accessible at tel-tsi.eu (the "Service"). It describes what personal data we collect, why we collect it, how long we retain it, and your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Austrian Data Protection Act (DSG 2018).

3. Data We Collect and Why

3.1 Account Data

Data Purpose Legal Basis
Email address Authentication, account management, transactional emails (e.g. password reset) Performance of contract (Art. 6(1)(b) GDPR)
Organisation name Workspace identification; shown on compliance reports Performance of contract (Art. 6(1)(b) GDPR)
User role (admin / contributor / viewer) Access control within your organisation workspace Performance of contract (Art. 6(1)(b) GDPR)

3.2 Assessment Data

Data Purpose Legal Basis
Assessment answers and progress (state_json) Save and restore your TEL TSI compliance self-assessment across devices; generate PDF compliance reports Performance of contract (Art. 6(1)(b) GDPR)
Assessment name and timestamps Dashboard display; audit trail for your organisation Performance of contract (Art. 6(1)(b) GDPR)

3.3 Billing Data

Data Purpose Legal Basis
Payment-processor customer ID Link your organisation to its subscription record with our payment processor Performance of contract (Art. 6(1)(b) GDPR)
Subscription status, plan, and renewal date Enforce access control; send renewal and subscription expiry notices Performance of contract (Art. 6(1)(b) GDPR)
Payment card details and invoices Processed and stored exclusively by our payment processor - we do not store card numbers or CVVs Performance of contract; legal obligation (Art. 6(1)(b)(c) GDPR)

3.4 Technical Data

We do not set advertising or cross-site tracking cookies. Our authentication provider sets a short-lived HTTP-only session cookie to maintain your login. For aggregate usage statistics we use two privacy-preserving, cookieless analytics tools. The first is a product analytics tool (PostHog, EU region). The second is the web analytics function of our hosting provider. Neither tool stores cookies or other identifiers on your device. Neither tool tracks you across websites. The web analytics function records the page URL, the referring page, the browser, the device type and an approximate location to city level (for example, "AT, Vienna"). We replace the values of sensitive query parameters before the page URL is sent. Examples of such parameters are an organisation identifier and an invitation code. The replacement text is "[redacted]". See Section 9 for details.

4. Sub-processors and Third-Party Services

To provide the Service we engage a small number of sub-processors. Each is bound by a data processing agreement and processes your data only on our documented instructions. They fall into the following categories:

Category Role Location
Cloud database & authentication Stores account and assessment records and manages sign-in (email/password and third-party single sign-on). Assessment data and account records are stored in the EU (Frankfurt, Germany) region. EU (Frankfurt)
Product analytics Aggregate, cookieless usage measurement (page views and feature usage). Records the page URL, the referring page, the browser, the device type and an approximate location to city level. Unless you accept the optional analytics consent described in section 9, it stores no cookies and no identifiers on your device: the provider derives a visitor identifier from the request itself, using a privacy-preserving hash that changes every day. No cross-site tracking, and no session recording. Analytics data is processed in the EU region. EU
Web analytics (hosting provider) Aggregate, cookieless page-view measurement. Records the page URL, the referring page, the browser, the device type and an approximate location to city level. Stores no cookies and no identifiers on your device. The provider derives a visitor identifier from the request itself and discards it after 24 hours. This function runs on the same provider as our hosting and inherits its location. EU edge / US (SCCs apply)
Application & API hosting Serves the front-end and serverless API functions, including PDF generation. EU edge / US (SCCs apply)
Payment processing Subscription billing and invoicing. Acts as an independent data controller for payment card data under PCI-DSS; we share only the minimum data required (email, customer ID). US / EU (SCCs apply)
Email delivery Sends transactional and notification emails; receives only the recipient email address and the message content necessary to deliver them. US (SCCs apply)

The current list of named sub-processors, including their corporate identity and location, is available on request to privacy (at) tel-tsi.eu. We do not sell personal data to any third party.

5. Retention Periods

Data Category Retention Reason
Account and organisation data Until account deletion, plus 30 days (soft-delete buffer) Service provision; recovery period
Assessment answers and reports Until the assessment is deleted by the user, or until account deletion Service provision
Billing records (invoices, payment history) 7 years after the relevant subscription period Austrian tax law (§ 212 BAO)
Authentication session tokens 1 hour (JWT expiry); refresh tokens valid for 7 days Security
Session replays of public pages (consent-based, see Section 9) 30 days, then deleted automatically Understanding how visitors use the public site

6. Your Rights Under the GDPR

As a data subject in the EU/EEA, you have the following rights:

To exercise any of these rights, email privacy (at) tel-tsi.eu. We will respond within 30 days. You also have the right to lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at) or the supervisory authority in your EU member state.

7. International Data Transfers

Your assessment data is stored in our EU (Frankfurt) region and does not leave the EEA in normal operations. Certain providers (for example, application hosting and payment processing) may process limited metadata (IP address, request logs) outside the EEA, subject to Standard Contractual Clauses (SCCs) under Art. 46 GDPR. Copies of the applicable SCCs are available on request.

8. Data Security

We implement the following technical and organisational measures to protect your data:

9. Cookies, Tracking and Session Replay

Default (no consent): the Service uses a single, strictly necessary session cookie set by our authentication provider to maintain your authenticated session; it is deleted when you sign out. We do not use advertising cookies or tracking pixels. Both of our analytics tools run in a cookieless mode. The product analytics tool (PostHog, EU region) sends no identifier from your browser. The provider derives a visitor identifier from the request itself, using a privacy-preserving hash that changes every day, so it cannot recognise you tomorrow or on another device. The web analytics function of our hosting provider sends no identifier from your browser. The provider derives a visitor identifier from the request itself, and discards it after 24 hours. Neither tool writes to cookies or local storage, so no non-essential information is stored on or read from your device. This is how the Service behaves unless and until you opt in below. We do not use Google Analytics, Microsoft Clarity, or any advertising service.

Optional, with your consent (Art. 6(1)(a) GDPR / § 165(3) TKG 2021): on our public pages we ask - via a small, non-blocking notice - whether we may (a) store an analytics identifier in a cookie and local storage so repeat visits can be recognised, and (b) record a replay of your browsing session on the public pages to understand how visitors use the site. Session replay runs only after you accept, applies only to public marketing pages (never the logged-in application), masks all text you type, and recordings are automatically deleted after 30 days. Declining or ignoring the notice leaves the cookieless default in place, and the site works identically either way. Your choice itself is stored locally on your device, which is strictly necessary to honour it. Your choice applies to the product analytics tool only; the web analytics function stays cookieless either way.

Withdrawing consent: you can withdraw at any time - . Withdrawal stops any recording, removes the analytics cookie and local-storage identifiers from your device, and returns the Service to the cookieless default. It does not affect the lawfulness of processing before withdrawal.

10. Children's Data

The Service is intended for business professionals in the rail sector (railway undertakings, infrastructure managers, and rail freight facility operators). We do not knowingly collect personal data from individuals under 16 years of age. If you believe a minor has registered, please contact us immediately at privacy (at) tel-tsi.eu.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to registered users by email at least 14 days before taking effect. The version number and effective date at the top of this document will always reflect the current policy. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact

TSI Solution GmbH
Pfalzgasse 7/1/61, 1220 Wien, Austria
Email: privacy (at) tel-tsi.eu