Terra Flow Systems
PlatformThe CubeFeaturesSoftware advisorAbout usContact
DEEN
LoginPackages & prices
Terra Flow Systems
PlatformThe CubeFeaturesBefore & afterERP for biogas plantsSoftware advisorAbout usContact
Packages & pricesFind the right packageLogin
DEEN
Rotenturmstraße 16–18, 1010 Wien
office@tfs.co.at

Privacy Policy

This is a translation of our German privacy policy. It is provided for convenience only. In case of any discrepancy or dispute, the German version is the binding one.

1. GENERAL

The controller for the data processing is:
Terra Flow Systems GmbH
Rotenturmstraße 16-18
1010 Wien
Phone: +43 720 880722
Email: office@tfs.co.at

With the following privacy information we, Terra Flow Systems GmbH, explain which personal data is collected when you use the Terra Flow Systems system and when you visit the website tfs.co.at (including all sub-sites, for example app.terra-flow.systems), why we use this data and how.

The collection, administration and use of personal data by Terra Flow Systems complies with the applicable data protection law, in particular the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) in their respective valid versions.

One essential benefit of Terra Flow Systems is the automatic documentation of your operational activities, based on the evaluation of sensor data from your plant and of selected information from your smartphone (for example GPS position, speed and acceleration).

This data is used exclusively for documentation relevant to operations. While an activity is running, the location is also recorded when the app is in the background.

The data is used within the scope of our General Terms and Conditions.

All collected data is protected against unauthorised access by technical and organisational measures according to the current state of the art. Data is never evaluated or passed on without your express consent.

2. WHICH DATA WE COLLECT AND HOW WE USE IT

When Terra Flow Systems is used, personal data and operational data is collected, stored and processed to the extent required for the proper provision of our services. The processing is based on Art. 6 (1) (b) GDPR for the performance of the contract and, where necessary, on legitimate interests under Art. 6 (1) (f) GDPR.

Storage & evaluation: Terra Flow Systems stores and uses personal data in particular in order to give the user a secure, efficient and personal use of the system, and in order to develop new applications, improve existing ones and adapt them to the needs of the users. We use personal data exclusively for the performance of the contract. Without your express consent there will be no further use beyond the statutory provisions.

Other technologies: Terra Flow Systems websites and Terra Flow Systems use “cookies”, that is small text files stored on the computer and in the browser. Terra Flow Systems uses these in order to offer a more user-friendly, more effective and more secure service. You can refuse the use of cookies in the settings of your browser. Please note, however, that switching off cookies can reduce the scope of the services or have a negative effect on the use of the services of Terra Flow Systems.

3. ACCESS LOGS (SERVER LOG FILES)

When tfs.co.at is called up, the upstream web server logs every request. Recorded are the time of the request, the IP address of the requesting device, in full, that is not shortened, together with the port number, the protocol used, the request method, the host called up, the address requested including the query parameters passed, the headers “Referer” (the page visited before), “User-Agent” (browser and system identification) and “Accept”, as well as the response status, the size of the response and the duration of processing. Cookies and authorisation data transmitted are automatically replaced by the note “REDACTED” and are therefore not logged.

Our own application does not log any visitor data in normal operation. Additional entries only arise in the event of an error: if a message from one of our forms could not be delivered, its subject line is recorded, and that subject line contains the company or farm or the surname and the package concerned. For events from the payment processing, identifiers and invoice numbers are logged, but no email addresses.

Purpose and legal basis: The logs serve exclusively the secure and undisturbed operation of the website and the isolation of errors. The legal basis is our legitimate interest under Art. 6 (1) (f) GDPR. This data is not merged with other data sets, nor is it evaluated for statistical purposes. We do not use any web analytics.

Storage period: The size of the logs is technically limited. Once the intended volume is reached, the oldest entries are continuously overwritten. There is therefore no fixed retention period measured in days.

4. ENQUIRIES VIA OUR FORMS (CONTACT AND SOFTWARE ADVISOR)

On tfs.co.at we provide two forms: the contact form and the software advisor. We use the details given there exclusively to answer your enquiry and to advise you.

Contact form: Processed are first name, surname, company, telephone number, email address, the package you selected as being of interest and your message.

Software advisor: Processed are farm, first name, surname, address, email address, telephone number, the way you prefer to be answered (telephone or email) and your message, as well as the answers you gave in the questionnaire (for example details on plant type and locations) together with the package recommendation calculated from them and its reasoning. We need these details so that the following consultation does not have to start from scratch.

In both cases we additionally record the time of receipt. The subject line of the message contains the origin of the enquiry (contact enquiry or software advisor), the company or farm or the surname, and the package concerned, so that we can assign the enquiry immediately. Your email address is set as the reply address so that we can answer you directly.

Details from the software advisor with the contact form: If you have filled in the software advisor, even only in part, and then send the contact form, your answers from the questionnaire are sent along with this enquiry and are marked in it as belonging together. This means you do not have to explain everything a second time during the call back. Until you send the form, your answers are held in the session storage of your browser (sessionStorage). As soon as you close the tab, they are deleted there. They only leave your device when you send a form.

Technical details of the visit: Together with your enquiry we transmit details that your browser and our server know anyway, so that we can classify the enquiry and do not have to start from scratch when calling you back: the page you entered through, including any campaign parameters (for example utm_source) and the page you came from; the number of pages called up and the time until sending; time zone as well as the language and region setting of your device; device type, screen and window size; browser and operating system; the quality of the connection; your IP address, the host name determined from it by reverse lookup and the browser identification. Time zone, language and region setting give the country, not a place. If the reverse lookup of your IP address does not return a host name, we record that as well. We do not collect any characteristics that would allow a device to be recognised across several visits.

Information on your IP address: In order to be able to classify an enquiry, we determine for your IP address the network operator, that is the name and the number of the autonomous system the address block belongs to, as well as the country, postal code and place the block is registered to. This is not a measurement of your location: with mobile connections, in company networks and behind a VPN this registration belongs to the provider and not to you. We note this expressly in the internal message. For this purpose we transmit your IP address to IPinfo.io Inc. (USA), which acts as our processor. Processing in the USA cannot be ruled out. It is safeguarded by the standard contractual clauses of the European Commission or by the EU-US Data Privacy Framework. The result is held by us in a cache for at most seven days, so that the same address is not transmitted more than once. Further information can be found at ipinfo.io/privacy-policy. The data on the network operator comes from IPinfo.

Storage on the web server: In addition to the email, every enquiry is stored as a non-public entry in our WordPress installation. The reason is failure safety only: if an email gets stuck, your enquiry is not lost. These entries are visible only to logged-in administrators, are not published in a searchable form and are deleted automatically after twelve months.

Mail service provider: For sending these messages we use SendGrid, a service of Twilio Inc. (USA), which acts as our processor. Processing in the USA cannot be ruled out. It is safeguarded by the standard contractual clauses of the European Commission or by the EU-US Data Privacy Framework. Further information can be found at www.twilio.com/en-us/legal/privacy.

Legal basis: The processing takes place in order to carry out pre-contractual measures which are taken at your request, under Art. 6 (1) (b) GDPR, and, insofar as your enquiry is not aimed at concluding a contract, on the basis of our legitimate interest in answering enquiries under Art. 6 (1) (f) GDPR. For the technical details of the visit and for the storage on the web server we rely on Art. 6 (1) (f) GDPR: our interest in being able to classify an enquiry, in detecting misuse of the forms and in not losing an enquiry through a delivery error. Sending the form also requires your express confirmation that we may use your details and these technical details to answer the enquiry.

Storage period: We delete the entries on the web server automatically twelve months after receipt. Beyond that we keep your enquiry in our email mailboxes for as long as this is necessary for handling it and for subsequent queries, and delete it afterwards unless statutory retention obligations stand in the way.

5. ORDER AND PAYMENT PROCESSING (STRIPE)

For the purchase of a package we use Stripe Checkout. The payment takes place on a page operated by Stripe, to which you are forwarded from tfs.co.at. The provider is Stripe Payments Europe, Ltd. (Ireland); Stripe, Inc. (USA) is also involved in the processing.

Which data Stripe collects: During the order process Stripe collects your name, your email address, your billing address (mandatory), your VAT identification number and the payment details required for the payment method chosen (for example card details or your account details together with a SEPA direct debit mandate). The VAT identification number is needed in order to determine the value added tax correctly. The invoice is also created by Stripe.

What we learn of this: Your payment details are processed exclusively by Stripe; we do not receive or store them at any time. Stripe notifies us of the outcome of the order (invoice paid, renewal, failed payment, cancellation). From this notification our server generates an internal email to sales and invoicing which contains your name, your email address, your billing address, the package booked, the invoice amount, the invoice number and the link to the receipt. Here too we do not store anything in a database of our own; for sending this notification, what is said in section 4 about the mail service provider applies.

Legal basis: The processing is necessary for the performance of the contract concluded with you (Art. 6 (1) (b) GDPR). Insofar as invoice and payment data has to be kept in order to fulfil obligations under tax and company law, this takes place on the basis of Art. 6 (1) (c) GDPR for the duration of the statutory retention periods.

Third countries: Insofar as personal data is transmitted to Stripe, Inc. in the USA in this context, this is safeguarded by the standard contractual clauses of the European Commission or by the EU-US Data Privacy Framework. Further information on the data processing by Stripe can be found at stripe.com/at/privacy.

6. HOW YOU YOURSELF INFLUENCE WHICH DATA OTHERS SEE

When Terra Flow Systems is used, different users within a farm can be assigned different roles. These roles define the scope of viewing, editing and administering operational data. The assignment and administration of the roles (for example “Admin”, “User”, and so on) is the responsibility of the respective farm and can be adjusted individually. The farm can thereby determine which information is visible, editable or administrable for which users.

Personal data that users provide voluntarily (for example name, email address, device information) is processed in accordance with the applicable data protection provisions. Access to this information can be restricted or extended depending on the role assigned.

Note: Changes to user roles and to the scope of their permissions are possible at any time through the administrator of the respective farm. Terra Flow Systems accepts no responsibility for the internal assignment of roles and recommends handling it with care and reviewing it regularly.

7. TO WHOM WE MAKE DATA AVAILABLE

Users with the role “Admin” have comprehensive access to all data relevant to their farm, including master data, fields, operating supplies and documented activities, even if this information was not recorded by them. In the context of digital activity records, the route covered can be shown on a map.

To protect privacy, this display is limited (as far as technically possible) to the actual field work. In the Terra Flow Systems Pflanzenschutz licence this function may be restricted for technical reasons.

Other users in the business:

By default, users can only view and edit their own personal data. All extended rights and visibilities within the business are assigned and administered individually by the plant manager or managers or by the admin role.

Use and disclosure of data:

The processing, use and any disclosure of data is governed by the applicable data protection provisions and by the General Terms and Conditions (AGB). Please note that certain processing operations are necessary within the scope of the services offered.

Third countries:

No personal data is transmitted to countries outside the European Economic Area (EEA) unless this is expressly regulated in the General Terms and Conditions. Excepted from this are the transmissions described in sections 4 and 5 in the context of sending mail and of payment processing.

8. HOW WE PROTECT YOUR DATA

Security: The transmission of data between your devices (PC, notebook, smartphone and so on) and the Terra Flow Systems system is encrypted (SSL encryption). The Terra Flow Systems permission management controls which data can be seen or changed by the user. We take all reasonably required measures to ensure that unauthorised third parties cannot access stored data.

Availability: Terra Flow Systems ensures that your data is not lost even in an emergency (for example fire, hardware damage). To ensure this, we work with professional hardware service providers in Europe. We process and store personal data for as long as this is necessary for the fulfilment of our contractual obligations under the software contract and for the agreed support. After the end of the contractual relationship, in particular in the case of a cancellation or of a non-renewal of the contract, and the associated deletion of the user account, we also delete all associated personal data. Please note: (a) some time may pass between deletion from our servers and deletion from our backup storage, and (b) we may keep this information in order to comply with our legal obligations or to be able to enforce contracts.

9. REFERENCES (HYPERLINKS) TO EXTERNAL WEBSITES

Terra Flow Systems websites and Terra Flow Systems may contain references (hyperlinks) to external websites of third parties. If you follow them, you leave the sphere of influence of Terra Flow Systems. Terra Flow Systems accepts neither technical nor content-related responsibility for services and offerings of third parties.

10. CONSENT OF THE USERS

By using Terra Flow Systems, the user agrees to the General Terms and Conditions (AGB). This consent is requested explicitly during registration. The user is encouraged to consult the General Terms and Conditions with regard to terms of use, disclaimer, limitations of liability and so on (www.tfs.co.at/agb).

11. YOUR RIGHTS

As a data subject you have the following rights towards Terra Flow Systems:

Access (Art. 15 GDPR): You can request information on whether and which personal data we process about you, and receive a copy of this data.

Rectification (Art. 16 GDPR): If your data is incorrect or incomplete, you can request its rectification or completion.

Erasure (Art. 17 GDPR): You can request the erasure of your personal data. Section 12 describes how you exercise this right.

Restriction of processing (Art. 18 GDPR): You can request that we restrict the processing of your data, for example while it is being checked whether the data is correct.

Data portability (Art. 20 GDPR): You can receive the data you have provided to us in a structured, commonly used and machine-readable format, or request its transmission to another controller, insofar as the processing is based on consent or on a contract and is carried out by automated means.

Objection (Art. 21 GDPR): Insofar as we process data on the basis of a legitimate interest, such as the access logs described in section 3, you can object to this processing on grounds relating to your particular situation.

To exercise these rights, a message to support@tfs.co.at is sufficient. For the right to erasure, the requirements described in section 12 apply in addition.

Right to lodge a complaint: Independently of this, you have the right to lodge a complaint with a supervisory authority if you are of the opinion that the processing of your personal data infringes the GDPR (Art. 77 GDPR). In Austria the competent authority is the Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, telephone +43 1 52 152-0, email dsb@dsb.gv.at, www.dsb.gv.at.

12. DELETING YOUR ACCOUNT

You exercise the right to erasure (Art. 17 GDPR) as follows: a fully completed application for erasure in accordance with the requirements of Art. 17 GDPR is necessary. We provide the corresponding form on request at support@tfs.co.at. Incomplete applications or applications made informally cannot be considered for legal reasons.

13. CHANGES TO THIS PRIVACY INFORMATION

As a registered user you will be informed about changes to this privacy information. Changes are also published on the website of Terra Flow Systems (tfs.co.at). This privacy information was last updated on 11 August 2026.

terraflowsystems
TFS

ERP and operations platform for the biogas industry. Made in Austria · Built for Europe.

2026 digi4Wirtschaft project of the year Public vote, Province of Lower Austria and WKNÖ
Platform
OverviewFeaturesERP for biogas plantsBefore & afterPackages
Company
About usSoftware advisorLogin
Contact
Contact & support+43 720 880 722office@tfs.co.at
© 2026 Terra Flow Systems GmbH · Rotenturmstraße 16–18, 1010 Wien
ImprintPrivacyTerms
Built in Austria