Privacy Policy
How we collect, use and protect your personal data under EU Regulation 2016/679 (GDPR).
Last updated: August 2026 — Version 2.3This policy explains how we collect, use and protect your personal data when you use SiltaTek services: the web panel, the Android app SiltaFlow, the Windows application Label Creator and the Chrome extension Odoo Label Printer. Processing is carried out under Regulation (EU) 2016/679 (GDPR) and applicable Italian privacy law.
1. Data Controller
Martone Fabio, individual person
Via del Carrara 43, 55010 Capannori (LU), Italy
Italian tax code: MRTFBA93P01G491B
Email: info@siltatek.com
2. Personal Data Collected
2.1 Data provided through Google Sign-In
- Email address
- First and last name
- Profile photo
We do not collect passwords: authentication is handled entirely through Google OAuth 2.0.
2.2 Data automatically collected by the web panel
- Access data: login date and time.
- Usage data: license tier, license and subscription status, trial, available and consumed credits, generated, revoked or hashed API keys/licenses, and technical device-validation data.
- Preferences: language and email-notification preferences.
- GDPR consents: date of acceptance of privacy policy and terms, and accepted version.
- Audit logs: records of actions, timestamps and details.
2.3 Data collected by the applications
Android app SiltaFlow
- Device identifier: device code or irreversible SHA-256 hash used for activation, license, trial and credit checks.
- Device information: commercial name, manufacturer, model, platform and Android version.
- Camera data: barcode and basic OCR images are processed on device through Google ML Kit and are not sent to SiltaTek servers. If AI/LLM or document-analysis features are enabled, text, images or extracted data may be sent to the provider configured by the User.
- Voice data: voice recognition is handled by the device recognition service; Siltatek does not receive the audio.
- Communication with Odoo: the app communicates directly with the User-configured Odoo server through JSON-RPC. Endpoints, credentials and Odoo data remain under User control and do not pass through SiltaTek servers.
- License, trial and credits: the app may send device code/hash, app identifier, API key/license or related hashes, license/trial status and credit usage to Firebase and SiltaTek services for activation, validation and accounting.
Windows app Label Creator
- Device identifier: a unique code generated through an irreversible cryptographic hash of computer hardware characteristics.
- License validation: periodic checks with Firebase and SiltaTek services through device code/hash and API key/hash; license, trial, tier, device-limit and credit status may be processed.
Chrome extension Odoo Label Printer
- Device identifier: a unique code generated through an irreversible hash of browser characteristics.
- Interaction: the extension works only on *.odoo.com pages and captures visible Odoo record data to print labels. This data is stored locally in the browser and is not sent to SiltaTek servers unless the User activates remote or AI services configured by the User.
- License and activation: the extension may verify enablement through device code/hash and API key/hash with Firebase and SiltaTek services.
2.4 Payment data
Payments are handled by Lemon Squeezy and Stripe. SiltaTek does not store full payment-card data. We may receive customer IDs, subscription IDs, invoice references, payment status and tax information needed for billing and license management.
3. Purposes and Legal Bases
- Service delivery: account management, licenses, trials, API keys and credits.
- Contract management: plans, subscriptions, invoices, refunds and support contracts.
- Security: fraud prevention, abuse detection, audit logs and credential protection.
- Legal obligations: tax, accounting and regulatory compliance.
- User requests: contact form, support tickets and operational communications.
4. Processors and Sub-Processors
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Google Firebase | Authentication, database, functions and storage | Account data, license data, logs, device hashes | EU/Global |
| Lemon Squeezy | Merchant of Record, payments and invoices | Billing data, subscriptions, invoices | USA/EU with safeguards |
| Stripe | Payment processing | Customer IDs, subscription IDs, payment events | USA/EU with safeguards |
| Twilio SendGrid | Transactional emails | Recipient email, name and notification content | USA with safeguards |
| Aruba S.p.A. | Web and email hosting | Contact-form email data | Italy (EU) |
Data is not sold to third parties and is not used for advertising profiling.
5. AI Features and External Providers
Some application features may use third-party AI services for product descriptions, invoice OCR, field suggestions, data alignment or document analysis. No AI provider is imposed by SiltaTek. The User chooses and configures the provider, such as OpenAI, Google Gemini, Anthropic, OpenRouter, DeepSeek, Ollama or a local/remote server, and enters their own API keys.
Data sent to such services may include prompts, product data, Odoo data, extracted document text, images or attachments needed for the requested feature. These transfers depend on User configuration and remain under User responsibility, including evaluation of the chosen provider's terms and privacy policy.
6. Cookies and Tracking
The web panel uses only technical cookies necessary for Firebase Authentication and login-session management. We do not use profiling cookies, third-party tracking cookies, advertising pixels, analytics services, remarketing or advertising services. The Android app does not use advertising IDs or advertising services.
7. Data Retention
| Data category | Retention period |
|---|---|
| Account data | For the duration of the active account |
| Audit logs | 730 days, then automatic deletion |
| Notifications | 90 days, then automatic deletion |
| Demo licenses | 14 days, then automatic expiry |
| Post-deletion account data | 30-day grace period, then definitive deletion |
| Billing data | Kept by Lemon Squeezy/Stripe under tax obligations |
| Contact-form data | Only as long as needed to handle the request, maximum 12 months |
8. Transfers Outside the EU
Main service data is stored on Firebase services in the europe-west1 region where applicable. Some transfers outside the EU may occur through Firebase Authentication, Lemon Squeezy, Stripe, SendGrid, and through AI/LLM providers or Odoo servers chosen by the User. Transfers rely on applicable safeguards such as the EU-U.S. Data Privacy Framework, Standard Contractual Clauses and Data Processing Agreements.
9. Data Subject Rights
Under Articles 15-22 GDPR you may exercise the rights of access, rectification, erasure, restriction, portability and objection. Requests can be made from the web panel where available or by writing to info@siltatek.com. We respond within 30 days; in complex cases the period may be extended by 60 days with a reasoned notice.
10. Data Security
- HTTPS/TLS encryption in transit.
- Encryption at rest on Firebase services.
- API keys stored as irreversible SHA-256 hashes.
- Client credentials encrypted with AES-GCM and bound to the device where applicable.
- Webhook signature verification for payment events.
- Rate limits for sensitive operations.
- Audit logging of relevant operations.
- Firestore security rules based on least privilege.
11. Minors
The Service is not intended for persons under 16 years of age. We do not knowingly collect personal data from children under 16. Access occurs through Google Account, which applies its own age checks according to applicable law.
12. Communications
We do not send marketing emails, newsletters or promotional communications. We send only transactional emails, such as license expiry and renewal reminders, support ticket notifications, support-contract notifications and upgrade-related communications. Notification preferences can be managed in the panel settings.
13. Support Providers
The Service allows Users to purchase technical support from registered third-party Providers. When a support contract is entered into, the selected Provider may access the User's name, email address, contract details and support-ticket messages related to that contract. Data is shared only with the selected Provider and only for support purposes.
14. Changes to this Policy
We may update this policy. In case of substantial changes, we will inform Users through the web panel or by email. Continued use of the Service after publication of the changes constitutes acceptance of the updated policy.
15. Contacts and Supervisory Authority
For questions, to exercise your rights or to report privacy issues:
Email: info@siltatek.com
Website: www.siltatek.com
You also have the right to lodge a complaint with the competent supervisory authority: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it, email protocollo@gpdp.it.
16. Support, notices and surveys in SiltaFlow
Trial and licensed users can open tickets, exchange messages with SiltaTek, receive notices and answer surveys. The limit is three new tickets per calendar day (Europe/Rome); replies do not use the limit.
Data processed
- a pseudonymous identifier through Firebase anonymous authentication, device code only as a SHA-256 hash, language, app and Android versions, trial/licence status, plan and FCM token;
- ticket category, priority, subject, description, messages, status and dates, plus name and email if supplied;
- delivery, view, skip, dismissal and open-text or closed-choice survey responses.
Notices and surveys may be mass-delivered or targeted by installation identifier, trial/licence status, plan, language or app version. Push notifications contain generic text only; content is downloaded after authentication. A communication may be skippable, dismissible or require a response where needed for the service.
Purposes, legal basis and retention
Processing provides support and contractual features, operational information, feedback collection, delivery and response measurement, and abuse prevention. Legal bases are contract or pre-contractual steps and legitimate interests in operation, security and improvement. Surveys are not used for behavioural advertising, profiling or automated decisions and must not contain special-category data.
Closed tickets and messages: 24 months; delivery and interaction states: 90 days; survey responses: 12 months from submission; installations and tokens not updated: 180 days. Invalid FCM tokens are removed sooner.
Questions about privacy?
We are available to clarify any questions about your data processing
