Privacy Policy
for the software "TIA Openness Manager" – EU-only backend (Netlify Pro, eu-central-1 Frankfurt)
Version 3.5.5 – Effective 27 August 2026
Privacy & Data Processing
1. Data Controller
AnyAutomation
Inh. Brzozowski
Rappenstrasse 9
8307 Effretikon
Switzerland
UID: CHE-341.595.058
Email: support@tiaopenessmanager.ch
Website: https://www.tiaopenessmanager.ch
1.1 Data Processors
To deliver the service the provider engages exclusively EU-based data processors. A Data Processing Agreement (DPA) is in place with each processor:
- Netlify, Inc. – hosting of backend functions and the account database in the EU region
eu-central-1(Frankfurt, Germany). DPA: https://www.netlify.com/pdf/netlify-dpa.pdf - Stripe Payments Europe, Ltd. (registered office Ireland) – processing of payments, subscriptions, and the Stripe Customer Portal. DPA: https://stripe.com/legal/dpa
- Sendinblue SAS (Brevo, registered office France) – delivery of transactional emails (sign-in codes, license and subscription notifications). DPA: https://www.brevo.com/legal/termsofuse/dpa/
All personal data is processed exclusively within the EU. No data is transferred to third countries (in particular, not to the United States).
2. Data Collected
The software may process the following data:
- Local project information (TIA Portal)
- User text inputs
- Technical context data from engineering environments
- Anonymized Hardware IDs for licensing
- Log data (actions, timestamps)
None of this data is automatically sent to the provider.
2.1 Account System (Backend)
When you create an account the following data is stored in the EU backend (Netlify Pro, eu-central-1 Frankfurt):
- Email address (used for login and license binding)
- No password: sign-in is passwordless via a 6-digit one-time code sent by email. The code is stored only as a salted hash and is deleted when used or after 15 minutes.
- Refresh-token family (for session management, stored as hashes only; family revocation on reuse detection)
- Hardware IDs of the devices activated so far (for license binding)
- HWID-switch counter (max. 3 hardware switches per rolling 30 days, for abuse prevention)
- Timestamp of the most recent license validation or session renewal ("last used", incl. application version)
- A coarse location region derived from it server-side (country, city, region coordinates rounded to roughly 1 km). The derivation happens on the EU server from the connection IP; the IP address itself is not stored.
The activity and region data serves license and service administration only (e.g. detecting inactive accounts, abuse prevention, support). No movement profile is created: only the most recent state is stored, no history.
Engineering data or TIA Portal project contents are NEVER transmitted to the backend.
3. Transmission to External LLMs
The user decides independently which data is transmitted to an external LLM. Transmissions occur only on explicit user action (sending a chat message or file attachment, OAuth flow against the LLM provider).
The provider has no influence on:
- The type, scope, and content of transmitted data
- Storage or further processing by the LLM provider
- The security of external systems
Principle: all data stays local except on explicitly triggered actions (LLM chat, OAuth login, license validation).
4. Online Licensing & Data Transmission
What is transmitted to the provider?
The software performs online license validation against the account system and transmits the following data:
During account login:
- Email address + 6-digit one-time sign-in code (verified in the backend; passwordless, no password exists)
- Hardware ID (automatically generated)
- Login timestamp
On every application start (license refresh):
- Session token
- Hardware ID
- Windows account identifier (see below)
- Validation timestamp
- Application version (on license validations)
Windows account identifier: the Hardware ID describes the workstation and is the same for every Windows account on that computer. Newer application versions additionally transmit a hashed identifier derived from the Windows account you are signed in with on that computer, so that licence use can be distinguished per Windows account on a shared computer. The name of the Windows account and its Windows identifier are not transmitted: both identifiers are formed on your computer, and only the resulting hash value is sent. We use them to validate the licence and to prevent misuse, not for advertising, and they are not passed on to third parties.
A record of licence binding checks is kept: one entry per activation, start-up validation and organisation seat validation, containing the two hashed identifiers named above, the masked IP address and the time; repeated identical checks within the same hour are stored once. The Windows-account-derived identifier is removed from these entries at the latest 400 days after the entry was written. The remaining machine-side history of the entry (hashed hardware identifier, masked IP address, time) is kept for as long as the account exists, as protection against licence abuse, and is deleted together with the account.
For these validations the backend records the time of last use and derives a coarse location region server-side from the connection IP (country/city level, see 2.1); the IP address itself is not stored.
Note: The software can be used offline for up to 14 days, after which a fresh online validation is required.
During subscription purchase (via Stripe):
- Email address (passed to Stripe)
- Selected license model (Pro, Pro+, Volume)
- Payment information (processed by Stripe, not stored by us)
On hardware switch:
- New Hardware ID + verification confirmation by the account owner
- Increments the HWID-switch counter (max. 3 switches per rolling 30 days)
4.2 Where is this data stored?
- Netlify (Functions & Database): Account data, Hardware IDs, Email, License status – hosted in the EU region
eu-central-1(Frankfurt, Germany) - Stripe: Payment and subscription information – Stripe Payments Europe Ltd. (Ireland, EU)
- Brevo (formerly Sendinblue): Email delivery (sign-in codes, license and subscription notifications) – Sendinblue SAS (France, EU)
All licensing and subscription data is processed exclusively within the EU. No data is transferred to third countries (in particular, not to the United States).
4.3 What is NOT transmitted?
The software does not send:
- Engineering data from TIA Portal
- Prompts or queries to LLMs
- LLM outputs
- Project contents
- PLC code
- User actions or logs
The provider conducts no analysis of engineering data and no tracking of usage behavior inside the software. From the license validations described in section 4 the backend stores the time of last use, the server-derived coarse location region (see 2.1) and the record of licence binding checks described there; beyond that, no telemetry takes place.
5. Storage at User Location
Log files and local data are stored exclusively at the user's location. Log file path: %LocalAppData%\TiaOpennessManager\Logs. These logs remain local – they are never uploaded automatically or in the background to the provider.
The user is responsible for:
- Access protection
- Data privacy
- Internal compliance
- Backup & archiving
6. Right to Delete
You can delete your account at any time through the software (Settings → Account → Delete Account) or by sending an email to support@tiaopenessmanager.ch. On deletion the following happens:
- Email + refresh-token family are immediately removed from the backend
- Hardware bindings + licenses are deactivated
- Activity and location-region data (last used, country/city/coordinates) is deleted together with the account record
- The trial email is added to a blacklist to prevent repeated trials
Stripe payment receipts are retained for 10 years for legal reasons (Swiss Code of Obligations Art. 957 et seq.).
Other data-subject rights under the GDPR and Swiss FADP (access, rectification, data portability, objection) can likewise be exercised by emailing support@tiaopenessmanager.ch.
7. Changes
The provider may update this privacy policy if technical changes require it.
Disclaimer:
The provider assumes no liability for data loss or damages arising from the use of external LLMs. The user is solely responsible for compliance with data protection regulations. See EULA and Disclaimer for details.
© 2025-2026 AnyAutomation.
