Privacy Policy for HOLDX Manager
Last updated: 21 September 2026
1. Controller
The controller responsible for the processing of personal data in connection with HOLDX Manager is:
SSP Safety System Products GmbH & Co. KG
Zeppelinweg 4
78549 Spaichingen
Germany
Email: [email protected]
Contact: Johann Aulila, Dipl.-Ing. (FH)
HoldX Product Manager and contact for account data and customer-submitted support information:
Rico Czernig Email: [email protected] Telephone: +49 7424 9804981
HOLDX Manager is an application for commissioning, configuring, monitoring, diagnosing and updating compatible HOLDX safety locking devices.
This Privacy Policy describes how personal data is processed when using HOLDX Manager.
2. Data processed when creating and using an account
Certain functions of HOLDX Manager require a user account. In particular, an authenticated account may be required for functions that modify device configuration, perform administrative operations, or provide authorized SSP technicians with extended access to device functions.
When an account is created or maintained, we may process:
- name;
- email address;
- company name;
- company address;
- postal code and country;
- optional salutation / preferred form of address;
- an optional profile picture;
- an internal user identifier; and
- assigned and effective role information, including whether multi-factor authentication is required and satisfied.
The company address must be a business address, not a private home address. Providing a salutation / preferred form of address and a profile picture is optional. The salutation is used only to address the user appropriately when SSP responds to support or product inquiries; selecting Mx. is the neutral option for users who prefer not to state Mr. or Ms. The profile picture is used only to personalize the user's profile. A user can remove it at any time in Settings > Profile, which deletes the stored profile picture without affecting account functionality.
Account data is processed to provide authenticated application functions and to protect accounts, devices and backend systems against unauthorized access. The legal basis for the optional profile picture is consent under Article 6(1)(a) GDPR. The legal basis for name, company and business contact information, and for the optional preferred form of address, is SSP's legitimate interest under Article 6(1)(f) GDPR in identifying and responding to business users.
Without an account, functions requiring authenticated write or administrative access to HOLDX devices may not be available.
2.1. Product access and administration
Users may request a higher product role. Such a request contains the Firebase UID, email address, name, company, current and requested roles, the requested capability, an optional message, status and timestamps. Authorized SSP administrators may review the request, add an administrative note, approve or deny it, and update the assigned role.
Administrative audit records can contain the acting administrator's UID and email address, the affected user's UID, the event type, timestamp and technical details about the action. Authorized administrators can also disable accounts and revoke sessions. The legal basis is SSP's legitimate interest under Article 6(1)(f) GDPR in controlling and securing access to HOLDX Manager functions and supporting users.
3. Authentication with Firebase
HOLDX Manager uses Firebase Authentication, provided by Google, for user authentication.
Users may currently sign in using:
- email address and password;
- Google Sign-In; or
- Sign in with Apple on supported Apple platforms.
When Google Sign-In is selected, information associated with the Google identity used for authentication may be provided to Firebase, including basic account information such as the user's identifier, email address, display name and, where available, profile image. HOLDX Manager does not automatically copy the identity-provider profile image into the HOLDX profile; a profile picture is stored only after the user chooses one in the application.
When Sign in with Apple is selected, Apple provides Firebase with the account identifier and the information the user elects to share. Depending on the user's Apple settings, this can include a private relay email address.
Firebase Authentication may also process technical information required to provide and secure the authentication service, such as IP address and user-agent information.
Google may process personal data in countries outside the European Economic Area. Where required by applicable data-protection law, appropriate safeguards for international data transfers are used.
4. Backend processing and storage through Cloudflare
HOLDX Manager uses Cloudflare Workers for backend processing and Cloudflare R2 for storage of application data, including user-related data required to provide the account and application services.
Depending on the operation performed, this may include:
- account and profile information;
- optional profile images;
- account authorization information;
- data submitted voluntarily through support or diagnostic functions;
- technical information necessary to process and secure a backend request.
When communicating with an online service, technical connection information such as IP addresses may necessarily be processed by the network and infrastructure providers involved.
Backend processing supports account functions, access administration, support, product inquiries and service security. The applicable legal bases for those purposes are described in the corresponding sections of this Privacy Policy.
5. Bluetooth and HOLDX device information
HOLDX Manager communicates with compatible HOLDX devices using Bluetooth Low Energy (BLE).
The application may locally read and process information such as:
- device identification and serial number;
- installed firmware version;
- device configuration;
- operating status;
- diagnostic information and error codes;
- counters and operating information; and
- other information required to commission, configure, diagnose or update the device.
During normal operation, HOLDX device information exchanged through Bluetooth remains between the computer or mobile device running HOLDX Manager and the connected HOLDX device. It is not automatically transmitted to SSP's backend.
HOLDX project files (.holdx) and BLE traces that a user exports are stored in locations selected or controlled by that user. They are not uploaded automatically. A user-submitted diagnostic report does not automatically include an exported BLE trace. The user is responsible for deleting these locally stored or exported files when they are no longer needed.
Exceptions are described below, in particular when a user enables crash reporting or explicitly sends a diagnostic report.
6. Firmware updates
HOLDX Manager downloads firmware packages and catalogue metadata from the configured firmware service. During an interrupted update, it stores local recovery information containing the target version, update phase, update time and progress for the affected device identity. The recovery record is removed after the update completes successfully.
HOLDX Manager does not upload firmware-update history to the profile backend. Firmware packages and catalogue data are hosted in Cloudflare R2 with the EU jurisdiction restriction. Cloudflare may process ordinary request and connection metadata when those files are downloaded.
7. Voluntary crash and diagnostic reports
Automatic crash reporting is disabled by default.
Users may voluntarily choose to provide diagnostic information to assist SSP in identifying and correcting software or device problems.
7.1. Automatic crash diagnostics
On Android, iOS and macOS, users may opt in to Firebase Crashlytics, provided by Google, for automatic crash reporting.
Crashlytics may process crash stack traces, technical identifiers and technical/device information required to diagnose the failure.
Crashlytics collection remains disabled unless the user selects Allow crash reports. The choice can be changed later in Settings and applies to future reports. When reporting is disabled, HOLDX Manager disables SDK collection and requests deletion of reports that the SDK identifies as unsent. This does not delete reports already transmitted to Google or SSP.
The legal basis is the user's consent under Article 6(1)(a) GDPR.
7.2. User-submitted diagnostic reports
On every supported platform, a signed-in user can review and explicitly send a diagnostic report to SSP. The report contains structured application events, timestamps, technical errors, and potentially system, device, serial-number or firmware identifiers. Passwords, authentication tokens, enrollment codes and email addresses inside the event log are redacted. The backend associates an uploaded report with the authenticated account UID and email address.
Sending a diagnostic report is a separate, user-initiated support action and is not controlled by the Crashlytics preference. The legal basis is SSP's legitimate interest under Article 6(1)(f) GDPR in investigating support requested by the user.
8. Product inquiries and quotation requests
When a signed-in user explicitly requests product information or a quotation, HOLDX Manager sends the optional salutation / preferred form of address, first and last names, email address, company, postal code, country, language, requested product and quantity, optional street and city, and message through SSP's backend to Microsoft Dynamics. This information is used to process the inquiry and allow SSP to respond using the supplied contact details. The legal basis is Article 6(1)(b) GDPR because SSP processes the request in order to take pre-contractual steps requested by the user. HOLDX Manager does not use the submitted inquiry data for advertising or behavioral profiling.
9. Usage reports and analytics
HoldX Manager does not include general-purpose usage analytics. Crash diagnostics and explicitly submitted support reports are described separately above.
10. No advertising or automated profiling
HOLDX Manager does not use the information described in this Privacy Policy for advertising or behavioral advertising.
HOLDX Manager does not use personal data for automated decision-making that produces legal effects or similarly significant effects on users.
11. Recipients of personal data
Personal data is disclosed only where necessary for the purposes described in this Privacy Policy.
Within SSP, access is restricted to authorized personnel who require the data for account or role administration, customer support, product inquiries, cybersecurity, service operation or product support.
Service providers currently relevant to HOLDX Manager include:
11.1. Google / Firebase
- Firebase Authentication for account authentication; and
- Firebase Crashlytics for optional Android, iOS and macOS crash reporting.
11.2. Cloudflare
- Cloudflare Workers for backend processing; and
- Cloudflare R2 for application and user-data storage.
These service providers may use subprocessors as part of providing their services and are subject to their respective contractual and data-protection arrangements.
11.3. Microsoft Dynamics
- Microsoft Dynamics receives contact, company, location, requested-product and message information when a signed-in user explicitly submits a quotation request.
Personal data may also be disclosed where this is required by applicable law or a binding order from a competent authority.
12. International transfers
Some of our service providers operate internationally. Consequently, personal data may be processed outside Germany or the European Economic Area.
Google's Firebase Data Processing and Security Terms incorporate the EU Standard Contractual Clauses and provide for the EU-US Data Privacy Framework where applicable. Cloudflare's Data Processing Addendum likewise incorporates the EU Standard Contractual Clauses and the EU-US Data Privacy Framework for applicable restricted transfers. HOLDX Manager's R2 object storage is additionally configured with Cloudflare's EU jurisdiction restriction.
For Dynamics 365, Microsoft states that transfers outside the EEA are subject to appropriate safeguards under Article 46 GDPR, including its commitments under the EU Standard Contractual Clauses. Microsoft also participates in the EU-US Data Privacy Framework.
13. Retention and deletion
We retain personal data according to SSP's approved retention schedule and any applicable legal obligations. Approved HoldX Manager retention periods are stated below. Data controlled by external providers is additionally subject to their applicable retention and deletion processes.
13.1. Account and profile information
Account and profile information is generally retained while the HOLDX Manager account remains active. If the user deletes the account, associated account and profile data under SSP's control will be deleted unless continued retention is required for a legal obligation or another legitimate purpose permitted by law.
13.2. Authentication information
Authentication information processed by Firebase is additionally subject to Google's provider-controlled retention and deletion processes. When a user deletes a HOLDX Manager account, the backend requests deletion of the Firebase Authentication account immediately. Residual provider-controlled data, if any, is handled according to Google's applicable retention and deletion terms.
13.3. Local diagnostic events
Structured diagnostic events stored by HoldX Manager on the user's device are retained for up to 14 days and are also limited by event count and storage size.
13.4. Submitted support reports and access requests
Submitted support-report metadata and payloads are retained for up to one year from submission. Resolved product-access requests are retained for up to one year from the decision date. Administrative audit records are retained for up to one year from the recorded event. A daily backend cleanup removes records that exceed these periods.
13.5. Cloudflare infrastructure logs
HOLDX Manager uses Cloudflare's native Workers Logs for backend diagnostics. Cloudflare retains these native logs for no more than seven days. HOLDX Manager does not export these logs through Logpush or another external log export to R2 or any other long-term log store.
13.6. Firebase Crashlytics information
Firebase Crashlytics information already transmitted is subject to Google's provider-controlled retention and deletion processes.
13.7. Local firmware recovery information
Interrupted-update recovery information remains on the user's device until a successful update clears it or the application's local data is removed. It is not uploaded to the profile backend.
14. Account deletion
Users can delete their HOLDX Manager account using the account-deletion functionality provided by the application.
Deletion removes the active HOLDX Manager account and initiates deletion of account data under SSP's control, subject to the retention exceptions described above.
Deletion of the HOLDX Manager account does not delete a user's separate Google or Apple account.
15. Security
We use appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss or destruction.
Access to authenticated HOLDX Manager functionality is controlled through user authentication and authorization.
However, no electronic transmission or storage system can guarantee absolute security.
Suspected cybersecurity vulnerabilities or security-related issues in an SSP product can be reported to the SSP Security Team at [email protected]. Where possible, include the product name, product ID number, a description of the issue, steps to reproduce it, and contact details. SSP aims to acknowledge received reports within five working days.
16. Your rights
Where the GDPR applies, users may have the right to:
- obtain information about and access to their personal data under Article 15 GDPR;
- correct inaccurate personal data under Article 16 GDPR;
- request deletion of personal data under Article 17 GDPR;
- request restriction of processing under Article 18 GDPR;
- receive certain personal data in a portable format under Article 20 GDPR;
- object to processing based on legitimate interests under Article 21 GDPR; and
- withdraw consent at any time for processing based on consent under Article 7(3) GDPR.
Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.
Requests concerning these rights may be sent to:
Users also have the right to lodge a complaint with a competent data-protection supervisory authority pursuant to Article 77 GDPR.
17. Changes to this Privacy Policy
HOLDX Manager is under active development. Functions and associated data processing may change as the application develops.
We may update this Privacy Policy where features, service providers, legal requirements or data-processing activities change.
The current version will be made available through the application and/or the SSP website.
Material changes affecting optional processing based on consent will not retroactively replace consent previously given.
18. Contact and Data Protection Officer
Questions concerning privacy or the processing of personal data in HOLDX Manager can be addressed to:
SSP Safety System Products GmbH & Co. KG
Zeppelinweg 4
78549 Spaichingen
Germany
Email: [email protected]
Data Protection Officer:
Michael Rohloff
Email: [email protected]
Telephone: +49 160 1536807