GDPR Compliance Notice

Last updated: May 6, 2025

 

TIE S.r.l. (“we,” “our,” or “us”) is committed to protecting your privacy and ensuring the security of your personal data. This document explains how we collect, use, store, and protect information within our industrial telemetry service, in compliance with the General Data Protection Regulation (GDPR – EU 2016/679).

 

 

1.     Who We Are

TIE S.r.l. is an industrial telemetry service provider based in Italy. We offer a data acquisition and analysis platform for industrial machinery, sensors and IoT devices. Our services include data collection, visualization, alarm management, and reporting functionalities. If you receive this information notice on the processing of personal data as representing a company, you undertake to make this document available to all the natural persons whose personal data may be processed by TIE S.r.l. for providing its services.

Company data

📍Address: TIE srl, Via Milano 178, 21042 Caronno Pertusella (VA), Italy

📍VAT: IT 01582010128

 

 

2.     Data Collection and Processing Roles

To ensure transparency, this section clarifies the roles and responsibilities within our telemetry service in compliance with the General Data Protection Regulation (GDPR – EU 2016/679).

  • Contact information:

            Name

            Surname

            Email address

            Company name

            Payment data (to the extent necessary to the invoicing process)

            Other information that may be provided in the context of a request for assistance.

Contact information relates to an identified or identifiable natural person and/or company. In the context of our telemetry service, contact information is limited to user identification and does not include operational data from industrial machines.

  • Access data:

            Email address (used as a unique identifier)

            Password (encrypted and securely stored)

            IP address

            Usage logs (timestamps, login attempts, access to specific platform features)

Access data relates to an identified or identifiable user account. In the context of our telemetry service, access data is limited to user account identification and management and does not include operational data from industrial machines.

  • Telemetry data:

            Measurements and samples from PLCs, sensors, devices, and shields

            System performance metrics and error logs

            Data necessary for alerting, reporting, and analytics

Telemetry data refers strictly to industrial machine parameters and does not include personal user data, except where necessary for authentication or service operation.

  • Data Controller: The entity that determines the purposes and means of processing personal data. In this case, TIE S.r.l. clients (companies using our telemetry service) are the Data Controllers, as they decide which data to collect and how to use it. It remains understood that TIE S.r.l. and its clients remain, each, the sole data controllers of the personal data exchanged between the parties for the purposes of entering into an agreement between them.
  • Data Processor: The entity that processes personal data on behalf of the Data Controller. TIE S.r.l. acts as a Data Processor, as it collects, processes, and stores industrial and access data on behalf of its clients.
  • Sub-processors: Third-party service providers that process data on behalf of the Data Processor. TIE S.r.l. relies on cloud service providers, such as AWS, for data storage and security.

📌 GDPR Compliance Impact: As a Data Processor, TIE S.r.l. ensures that all collected data is processed in accordance with agreements made with clients, adopting appropriate security measures and respecting the rights of data subjects.

 

 

3.     Data Management

 

How We Use Your Data

We process your data for the following purposes:

  • Service Provisioning: To provide access to our telemetry platform and its functionalities.
  • Security & Fraud Prevention: To detect unauthorized access, prevent cyber threats, and ensure compliance with security protocols.
  • Customer Support: To respond to inquiries, troubleshoot issues, and provide technical assistance.
  • Performance Monitoring: To analyse system performance and improve our platform.

         Legal Compliance: To meet regulatory requirements and contractual obligations.

 

Legal Basis for Processing

Under the GDPR, we process personal data based on the following legal grounds:

  • Contractual Necessity: Processing is required to fulfil our service agreement with you.
  • Legal Obligations: Compliance with laws, including data retention and security regulations.
  • Legitimate Interest: Enhancing platform security, improving service quality, and analysing performance data.

If we process your data for any other purposes (such as marketing communications), we will request your explicit consent.

 

Data Retention

We retain your data for the period necessary to provide our services and comply with legal obligations.

  • Access Data & Contact Information: Retained as long as your account is active.
  • Telemetry Data: Retained based on contractual agreements with clients.
  • Logs & Security Records: Stored for security auditing and fraud prevention, typically for up to 12 months.

You may request data deletion at any time (see Section 7 for details).

 

How We Share Your Data

We do not sell, rent, or trade your personal data. However, we may share data under specific conditions:

  • Service Providers: Third-party partners providing cloud hosting, analytics, and security services, as well as external consultants (including legal and/or tax consultants) where necessary for the business activities of TIE S.r.l.
  • Legal Authorities: If required by law enforcement, regulatory bodies, or in response to legal proceedings.
  • Business Transactions: In the event of a merger, acquisition, or business restructuring, data may be transferred to the relevant entity.

All data-sharing activities are conducted under strict confidentiality agreements and in compliance with GDPR guidelines.

 

International Data Transfer

We primarily store and process data within the European Economic Area (EEA). However, if any data transfer outside the EEA is necessary, we ensure it complies with GDPR through:

  • Adequacy Decisions: Countries with equivalent data protection laws.
  • Standard Contractual Clauses (SCCs): Legal agreements with non-EEA service providers.
  • Privacy Shield Alternatives: Compliant mechanisms for US-based services.

We ensure that all third parties handling your data adhere to high privacy and security standards.

 

 

4.     Data Security

 

Data Security and Certifications

TIE S.r.l. implements advanced security measures to protect data processed within our telemetry service, including:

  • Encryption: Data is encrypted both in transit (TLS) and at rest.
  • Access Controls: Secure authentication and role-based access control (RBAC) mechanisms are in place.
  • Monitoring and Logging: All access and usage activities are monitored to detect anomalies or unauthorized access attempts.
  • Backup and Disaster Recovery: Backup and recovery procedures ensure data availability in case of failure or unexpected events.

 

 

Data Breach Management

TIE S.r.l. is committed to handling any potential data breaches in compliance with GDPR requirements.

Incident Response Procedure

In the event of a data breach involving personal data, the company ensures that:

  • Incidents will be addressed as quickly as possible to minimize potential impacts on clients and data subjects.
  • All necessary measures will be taken to identify the root cause and implement corrective actions.
  • If required by GDPR, affected users and regulatory authorities will be notified within the required timeframe (72 hours after detection).

 

Record of Processing Activities (RAT)

In compliance with Article 30 of the GDPR, TIE S.r.l. is committed to implementing a Record of Processing Activities (RAT) documenting the processing of personal data within the TIELEMETRY service.

 

Sub-processors and Supply Chain Management

TIE S.r.l. uses third-party service providers (sub-processors) to ensure the availability, security, and functionality of the TIELEMETRY service.

List of Main Sub-processors

  • Amazon Web Services (AWS) – Cloud computing and secure data storage.
 

 

5.     Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data.
  • Right to Rectification: Correct inaccuracies in your personal information.
  • Right to Erasure (“Right to be Forgotten”): Request the deletion of your data.
  • Right to Restrict Processing: Limit how we use your data.
  • Right to Data Portability: Obtain your data in a structured format for transfer.
  • Right to Object: Withdraw consent or object to processing.
  • Right to Lodge a Complaint: File a complaint with the Data Protection Authority if you believe your rights have been violated.

📩 To exercise these rights, please contact us at: telemetry@tiesrl.it

Important: Modifying or deleting your consent may impact the availability of our telemetry services, making it impossible to continue using certain features.

 

6.     Changes to This GDPR Compliance Notice

We may update this notice periodically to reflect legal or operational changes. If significant updates are made, we will notify users through our platform or email. The most current version will always be available on our website.

 

7.     Contact Us

If you have any questions regarding this GDPR Compliance Notice or your personal data, you can reach us by:

📧 E-mail: tielemetry@tiesrl.it
📞 Phone: 02 965 9484
📍 Address: Via Milano 178, 21042 Caronno Pertusella (VA), Italy