SILEXA Cloud Privacy Policy
Effective date: 29 September 2026
1. Who we are and what this policy covers
SILEXA Cloud is a business-to-business service provided by Redl Technologies GmbH for managing connected devices that we develop and supply. This policy explains how personal data is handled when you visit the service, use a business account, manage devices or contact us. It covers our SILEXA Cloud instances, including use by business customers in the United States.
For processing where we decide the purposes and means, the controller is:
Redl Technologies GmbH
Gewerbering 8
2020 Hollabrunn, Austria
Privacy contact: info@redl.net (please mark your request “SILEXA privacy”)
Telephone: +43 2952 2218-0
Data protection officer: Martina Gabler-Redl, at the postal address above or info@redl.net (please mark your message “Attn. data protection officer”).
Our processing is subject to the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and, where applicable, the Austrian Telecommunications Act 2021 (TKG 2021). This policy does not restrict rights provided by other applicable laws.
2. Business accounts and customer-controlled data
The service is intended for businesses and their authorised personnel. Business contact details and data linked to an employee, device operator or other identifiable person remain personal data.
We act as controller for our business relationships, administration of the platform, platform security, our own billing and handling enquiries addressed to us. Where a customer determines how personal data is used through its devices or organisation, we process that data on the customer's documented instructions as a processor. Examples may include identifiable transaction records, RFID or QR authorisations and records concerning the customer's personnel or end users.
That processing must be governed by the applicable data processing agreement. The customer is responsible for its lawful basis, notices and instructions. Its own privacy notice explains its processing. Contact the relevant business for requests concerning data it controls; we assist it with those requests. This policy is not a substitute for a data processing agreement or the customer's notice.
3. Data we process and where it comes from
The data involved depends on your permissions, the devices connected and the features your organisation enables:
- Business and account data: name, work email, telephone number, company and business address, business/customer identifiers, assigned organisation and locations, roles and permissions, language and display preferences.
- Authentication and security data: password hashes, authentication and recovery information, sessions and tokens, multi-factor and trusted-device records, login history, IP addresses, browser information and audit records, including recorded acknowledgements of legal documents.
- Device and operational data: serial numbers and device identifiers, assigned business locations, network details, configuration and configuration history, firmware/software versions, status, faults, measurements, usage and diagnostic logs. These records are personal data where they can be linked to a person.
- Transactions and authorisations: transaction identifiers and timestamps, products and quantities, RFID/card or QR identifiers, balances or redemption records and external customer references where the relevant features are used. A pseudonymous card or token identifier may still be personal data.
- Support and communications: messages, contact details, notification destinations and delivery records, service feedback and files supplied for troubleshooting. Requested device logs or display screenshots may contain personal data. A display screenshot is not a camera recording.
- Commercial records: contracts, orders, billing contacts, invoices, payment status and payment-provider references where applicable.
We receive data from you, your employer or account administrator, authorised partners and support personnel, connected devices and integrations configured for your organisation. Technical access data is generated when the platform is used. Please avoid putting unnecessary personal data, sensitive personal data or secrets into names, comments, support attachments and device content.
4. Purposes and legal bases
For data for which we are controller, the following purposes and legal bases apply:
- Accounts, business relationships and requested services: our legitimate interests in communicating with business contacts and providing and administering the service, including device support and maintenance (Article 6(1)(f) GDPR). Where you personally are the contracting party, processing necessary for that contract or requested pre-contractual steps relies on Article 6(1)(b).
- Security and reliability: our legitimate interests in preventing unauthorised access, investigating faults and misuse, maintaining availability and protecting the platform, connected devices and users (Article 6(1)(f)).
- Support and service notifications: responding to requests and sending operational communications on the same contract or legitimate-interest bases, as applicable. Optional communication channels are used according to their configuration and any required consent.
- Accounting and legal requirements: compliance with applicable Austrian accounting, tax and other legal duties (Article 6(1)(c)); establishing, exercising or defending legal claims where necessary (Article 6(1)(f)).
- Optional analytics, marketing or other consent-based functions: only where introduced and separately explained and consent is required, Article 6(1)(a). Consent may be withdrawn at any time for future processing.
Processing of customer-controlled data follows the customer's instructions and legal basis. Acknowledging this policy does not constitute blanket consent to processing and does not replace a separate consent where one is required.
Business contact and account information required to establish and secure your access must be provided for the requested service. Without it, we may be unable to create your account, provide support or fulfil the contract. Optional profile details and optional communication channels are not generally required.
5. Who can receive data
Access is limited according to the purpose and assigned permissions. Recipients may include:
- Authorised Redl personnel responsible for operations, support, administration and security.
- Your organisation's authorised administrators, users and appointed partners or technicians, within their assigned scope.
- Providers of hosting, storage, backups, IT operations and email delivery acting under appropriate contractual arrangements.
- Providers of enabled messaging, authentication, remote support, integration or payment services. Depending on the service, a provider may act as our processor or as an independent controller.
- Professional advisers, courts, regulators and public authorities where disclosure is necessary and legally permitted or required.
Hosting and backups: Hetzner Online GmbH, Gunzenhausen, Germany, hosts our cloud instances in its data centres in Nuremberg, Germany, and Helsinki, Finland, and creates the automatic server backups described in section 8, acting as our processor. More information is available in Hetzner's privacy information.
Other providers currently used:
- Email delivery: SMTP2GO (Sand Dune Mail Ltd, Christchurch, New Zealand) delivers account, security and notification emails as our processor. It processes recipient addresses, message content and delivery information. See SMTP2GO's privacy policy.
- SMS, WhatsApp and telephone verification: Twilio Inc., San Francisco, USA, sends the SMS and WhatsApp notifications configured by your organisation and verifies telephone numbers, acting as our processor. It processes telephone numbers, message content and delivery information. WhatsApp messages are also transmitted through the WhatsApp service operated by Meta under its own terms. See Twilio's privacy notice.
We do not currently use a payment provider, Telegram messaging or a third-party remote-access service for SILEXA Cloud. We will update this policy before introducing such a service.
Resources loaded from third-party servers: To display pages, your browser loads some fonts, program libraries and map data directly from the following providers. This discloses technical request data, in particular your IP address, browser information and the address of the page, to the provider concerned. We do not receive data about you from these providers.
- Fonts: Google Fonts (Google Ireland Limited / Google LLC), on all pages including sign-in.
- Program libraries: code.jquery.com (OpenJS Foundation), cdnjs.cloudflare.com (Cloudflare, Inc.), cdn.jsdelivr.net (jsDelivr), unpkg.com and cdn.datatables.net (SpryMedia Ltd), in the signed-in application.
- Maps: map images from OpenStreetMap (OpenStreetMap Foundation) and, in dark mode, CARTO, on location and map views.
- Address suggestions: Photon (komoot GmbH, Germany) receives the address text you type when you use address suggestions.
- Text editor: TinyMCE Cloud (Tiny Technologies Inc.), only in editing views used by Redl personnel.
The legal basis is our legitimate interest in delivering the service reliably and efficiently (Article 6(1)(f) GDPR). Some of these providers operate worldwide delivery networks; see section 6.
We do not sell personal data, share it for cross-context behavioural advertising or use it for targeted advertising. SILEXA Cloud does not use analytics, advertising or tracking scripts, and we do not permit third parties to track users across unrelated services through SILEXA Cloud.
6. Hosting and international access
Our cloud instances are hosted in the European Union, using Hetzner Cloud locations in Nuremberg, Germany, and Helsinki, Finland. Hetzner creates and stores the automatic server backups as part of this hosting service. Our pre-production (staging) instance runs on Redl's own servers in Hollabrunn, Austria. Authorised personnel and customers may access the service from the countries in which they work, including the United States.
Use by a US customer does not by itself mean that our servers are in the United States. Where a disclosure or access constitutes a transfer to a recipient outside the European Economic Area, the applicable GDPR transfer requirements must be met.
Transfers and safeguards actually used:
- Twilio Inc. (USA): Twilio is certified under the EU–US Data Privacy Framework and also maintains Binding Corporate Rules approved by European data protection authorities.
- SMTP2GO (New Zealand): the European Commission has recognised New Zealand as providing an adequate level of data protection. Where SMTP2GO uses data centres in other countries, our data processing agreement with SMTP2GO applies.
- WhatsApp: Meta processes WhatsApp messages under its own terms and transfer mechanisms.
- Resource, map and address providers (section 5): your browser contacts these providers directly. Google LLC and Cloudflare, Inc. are certified under the EU–US Data Privacy Framework. komoot GmbH is located in Germany. The OpenStreetMap Foundation is located in the United Kingdom, which the European Commission has recognised as providing an adequate level of data protection. Other resource providers may process request data through delivery networks outside the EEA.
You may contact us for information about the safeguards and a copy where applicable, with confidential information appropriately protected.
7. Cookies and similar technologies
The platform uses session and security technologies to sign users in, protect requests and maintain access. If selected, remembering a trusted device supports multi-factor authentication. Cookies or browser storage can also remember language, appearance, interface preferences and cookie choices.
Access to or storage of information on your device that is strictly necessary for a service you request can be exempt from consent under section 165(3) TKG 2021. Other storage or access requires the applicable information and consent before it occurs. Where personal data is processed, the relevant GDPR basis also applies.
Cookies and browser storage used:
silexa_session: keeps you signed in and secures your session. Strictly necessary. Expires 120 minutes after your last activity.XSRF-TOKEN: protects forms and requests against cross-site request forgery. Strictly necessary. Expires after 120 minutes.silexa_session_trusted_device: set only if you choose to trust a browser during two-factor sign-in. Expires after 30 days.locale: set only if you select a language; remembers that choice for 30 days.cookie_consent: set only where a cookie notice is displayed; records your choice for 12 months. We also store the choice with the time, IP address and browser information as a record.- Browser storage (localStorage): remembers display preferences on your device, such as dark mode, sidebar and table layout, open tabs and recent searches. It is not sent to us automatically and remains until you clear it.
We do not use cookies, browser storage or scripts for analytics, advertising or tracking.
You can remove cookies and browser storage or restrict them through your browser; this may end your session or disable requested features. The technologies listed above do not require consent. If we introduce optional cookies or scripts, we will ask for your consent before they are used and provide a way to change your choice at any time; withdrawing consent will be as easy as giving it.
8. Retention
We retain personal data only for the relevant purpose, taking account of legal duties and any necessary preservation for disputes or security incidents:
- Business and account records: for the active relationship and account administration, followed by the period necessary to conclude outstanding matters or meet documented legal requirements.
- Operational, access, audit and diagnostic records: for the period needed to monitor operations, investigate incidents and establish relevant actions. Currently: sessions end 120 minutes after the last activity; requested device log downloads and display screenshots expire after 10 minutes and are removed by an automatic cleanup that runs every five minutes; expired access tokens are removed 24 hours after expiry; trusted-browser records are removed after 30 days; detailed device measurements are kept for up to 90 days, hourly summaries for 365 days and data-usage records for 90 days. Audit records and acknowledgements of legal documents are kept while the account exists. Audit records documenting actions on the platform may be kept after an account is deleted where this is necessary for security or to establish, exercise or defend legal claims.
- Customer-controlled device and transaction data: according to the customer agreement and documented deletion/return instructions, subject to applicable legal requirements. Deactivation, soft deletion or archival does not necessarily erase the underlying records.
- Accounting records: generally seven years under Austrian accounting/tax rules, calculated from the end of the relevant calendar year, and longer where a specific legal obligation or pending proceeding requires it. This does not mean all platform data is kept for seven years.
- Backups: Hetzner creates an automatic backup of each cloud server daily and keeps the seven most recent; each new backup replaces the oldest, so backups are generally kept for about seven days. Before maintenance work we may create additional database copies, which are access-restricted and deleted automatically 7 days after they are created. If data has to be restored from a backup, we take steps to ensure that data deleted after the backup was created is not used again and is deleted again.
9. Security
We use technical and organisational measures appropriate to the processing risks. Platform controls include access permissions, protected authentication, password hashing and security logging; device interfaces support authenticated connections. These measures include encrypted HTTPS connections for browsers and devices; certificate-based authentication of connected devices, with certificates issued by our own certificate authority that can be revoked; optional two-factor authentication with an authenticator app; role- and permission-based access; bcrypt password hashing; databases and internal services that are not directly reachable from the internet; key-based administrative access restricted to authorised personnel; daily backups; and logging of security-relevant events. No system can guarantee absolute security.
10. Your rights
Subject to the applicable conditions, you can request access, correction, erasure, restriction and portability of your personal data. You may object to processing based on legitimate interests for reasons relating to your particular situation, and to direct marketing at any time. You can withdraw consent without affecting processing already lawfully carried out.
Contact us using section 1. We may request proportionate information to verify your identity. GDPR requests are normally answered within one month; if a permitted extension is needed, we explain it within that month. If we process the data for a customer, we assist that controller with your request.
You may complain to the Austrian Datenschutzbehörde or another competent supervisory authority, particularly in the EEA country where you live, work or consider an infringement occurred.
11. Automated decisions and children
We do not make decisions about individuals based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them. Automatic security measures, such as a temporary sign-in lockout after repeated failed attempts, are not such decisions; contact us if you are affected. Technical device rules and alerts are not, by themselves, a description of automated decisions about people.
SILEXA Cloud business accounts are not intended for children. Customers remain responsible for assessing their own use of devices and the data of any end users.
12. United States
Individuals in the United States may have additional rights under applicable state law, depending on their residence, the processing and whether the law applies to us. These can include access, correction, deletion, portability, an appeal of a declined request and rights concerning sale, sharing, targeted advertising or certain profiling. Contact us using section 1 to make a request or, where available, an appeal. We do not discriminate against individuals for exercising applicable privacy rights.
We do not sell personal information, share it for cross-context behavioural advertising, use it for targeted advertising or use it for profiling that produces legal or similarly significant effects. Where a US state privacy law applies to our processing, you can make a request as described in section 1. We verify requests, respond within the period required by the applicable law and explain how to appeal a decision. An authorised agent may make a request on your behalf with proof of authorisation.
Browser signals: SILEXA Cloud does not track users across third-party websites and does not permit third parties to do so for advertising. Because we do not sell or share personal information or use it for targeted advertising, Do Not Track and Global Privacy Control signals do not change how the service works. The providers listed in section 5 receive technical request data when your browser loads their resources.
13. Changes and the central policy
The current policy is available at silexa.cloud/privacy-policy. Links on our other instances lead to this central version. We update the date when the policy changes and provide additional information about material changes where required. New processing that requires consent will be subject to a separate choice.