Privacy policy

 

1.      General information

The following notices provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified.

This Privacy Policy explains how we collect, use, and protect personal data when youvisit our website or if you close a contract with us.

 

2.      Who is responsible for datacollection on this website?

The controller responsible for the data processing on this website is:

digid GmbH

Robert-Koch-Straße 30a

55129 Mainz

Germany

Email: info@digid.com

3.      What data we collect and for which purposes

Website Access and Log Files

When you visit our website, certain technical information is automatically collected toensure the secure and stable operation of the website.

This may include IP address, browser type and version, operating system, date and time of access, referrer URL, accessed pages and files. The processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.

We host our website with Webflow. The provider is Webflow, Inc., 398 11th St., Floor 2, SanFrancisco, CA 94103  (hereinafter:Webflow). When you visit our website, Webflow collects various log files including your IP addresses. For details, please refer to the Webflow privacypolicy: https://webflow.com/legal/privacy.

The use of Webflow is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the most reliable presentation of our website. Insofar as a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR; the consent can be revoked at any time.

Webflow is acting as our data processor under Art. 28 GDPR. A data processing agreement including Standard Contractual Clauses is in place. Webflow is certified under the EU-US Data Privacy Framework which covers the legal basis for the datatransfer to the US under GDPR.

Contact Requests

If you contact us via contact form, email, telephone, or postal mail, we process the information provided to handle your request and communicate with you.

This may include the data categories you provide to us, especially your name, company name, business contact details (email address, phone number), company address and communication content.

The processing is based on Art. 6(1)(b) GDPR where the request relates to contractual matters or Art. 6(1)(f) GDPR for general communication and inquiries. We only process data necessary for the respective purpose.

4.      Storage period

We retain personal data only for as long as necessary for the respective purpose or asrequired by statutory retention obligations.

In particular:

  • server log data is generally     retained for a limited period for security purposes,
  • contact requests are retained     until the request has been fully processed,
  • contractual and invoicing data     may be retained longer due to legal obligations.

Once retention is no longer required, the data will be deleted or anonymized if no legal storage obligations apply.

 

5.      Privacy information for job applicants

We are committed to ensuring the highest level of protection for your personal data inthe context of applications. You can submit applications to us online at https://www.digid.com/careers, by postal mail or by e-mail. All personal data you submit to us as part of an application (in particular your CV, cover letter, attachments such as certificates and references) are protected against unauthorised access and manipulation by technical and organisational measures.

We process your personal data for the purpose of the application procedure (selection process). The legal basis for data processing is the initiation of a contractual relationship and our legitimate interest (Art. 6(1)(f) GDPR andArt. 6(1)(b) GDPR). Furthermore, we may process your personal data if this is necessary for the fulfilment of legal obligations or for the defence of asserted legal claims against us (Art. 6(1)(c) GDPR). Only authorised employees from the HR department or employees involved in the application process have access to your data. If we are unable to consider your application, your data will be deleted six months after rejection. This does not apply to data that is subject to legal retention periods. If necessary, we would like to store your data longer in order to be able to contact you in the future. In this case, we will obtain separate consent from you in accordance with Art. 6(1)(a) GDPR. The consent is voluntary and can be revoked at any time.

 

6.      Cookies and third-party tools

Our website uses cookies and comparable technologies to ensure functionality, improve user experience, and analyze website usage.

Technically necessary cookies (category “strictly necessary”) are processed based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.

Allnon-essential cookies and third-party services (categories “analytics”,“marketing”, “personalization”) are only activated based on your consentpursuant to Art. 6(1)(a) GDPR.

You may withdraw or modify your consent at any time through the cookie settings on our website.

Depending on the services used, personal data may be transferred to countries outside the European Union or European Economic Area. In such cases, appropriate safeguardsare implemented in accordance with applicable data protection laws.

Third-party services on our website:

·        Webflow: CMSand website hosting, legal basis: legitimate interest, Webflow, Inc., 398 11thSt., Floor 2, San Francisco, CA 94103, https://webflow.com/legal/privacy

·        Finsweet Cookie Consent Manager: legal basis: legitimate interest, strictlynecessary, loaded via jsDelivr CDN, JSD Limited, Suite 2a1, Northside House,Mount Pleasant, Barnet, England, EN4 9EB, https://www.jsdelivr.com/terms/privacy-policy

·        Cloudflare: CDNand security, _cfuvid cookie (strictly necessary), Cloudflare Inc., 101Townsend St., San Francisco, CA 94107, https://www.cloudflare.com/privacypolicy/

·        Google Services: Google Ireland Limited, Google Building Gordon House, 4 Barrow St,Dublin, D04 E5W5, Ireland, https://business.safety.google/privacy/?hl=de

o  Google Tag Manager: Tag Management System, legal basis: consent, ,

o  Google Analytics: analytics, performance measurement, legal basis: consent, categoryanalytics

o  YouTube: videoplayer, sets cookies when video is watched, legal basis: consent

o  Google Fonts and Google Maps: link only, no embed on homepage. No connection to Google servers is established when visiting the website. No personal data is transferred.

 

7.      Security, SSL and TLS encryption

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or manipulation.

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as thesite operator. You can recognize an encrypted connection by the fact that theaddress line of the browser changes from “http://” to “https://” and by thelock symbol in your browser line.

If SSL orTLS encryption is activated, the data you transmit to us cannot be read bythird parties.

 

8.      Data subject rights

Under applicable data protection laws, you have the following rights regarding your personal data:

  • right of access,
  • right to rectification,
  • right to erasure,
  • right     to restriction of processing,
  • right to data portability,
  • right     to object to processing,
  • right to withdraw consent at     any time with future effect.

You also have the right to lodge a complaint with a competent supervisory authority if you believe that the processing of your personal data violates applicable data protection law.

You can contact us at any time with regard to this and other questions on the subject of data protection.

‍‍

Status: May 2026