Digicust
Privacy Policy
Information about the processing of personal data by Digicust FlexCo.
1. Controller and privacy contact
Controller
Digicust FlexCo
Commercial Register Number: FN 538643y
Am Felde 2, Haus 3, Top 2
2431 Enzersdorf an der Fischa, Austria
Managing Directors
Thomas Übellacker, MSc; Matthias Pfeiler, BA
Privacy contact
Please send privacy requests to privacy@digicust.com.
2. Scope and roles
This notice describes Digicust's processing as a controller, particularly when you visit our website, communicate with us, or when we administer business relationships, accounts and billing.
Where Digicust processes Customer Content and Customer-related usage, permission or log data on documented instructions to provide the Platform or agreed support, Digicust acts as a processor or subprocessor. The relevant Customer Agreement and Data Processing Agreement (DPA) govern that processing.
Customer Content processed on instructions is not used for Digicust's own advertising, general model training or independent product development. This notice does not grant Digicust additional rights over Customer Content.
3. Processing by Digicust as controller
Website delivery and security
When you access the website, we process technically necessary connection and log data, including IP address, time, requested resource, referrer, browser and device information. We use it to deliver the website, maintain stability, diagnose errors and detect or defend against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the website. Recipients may include hosting, CDN and security providers, particularly Cloudflare.
Enquiries, demos, trials and business relationships
For contact, demo, trial, partner or event requests, we process the contact, company, communication and, where applicable, test data you provide to respond, take pre-contractual steps and conduct business communications. The legal bases are Article 6(1)(b) GDPR for contractual or pre-contractual steps and Article 6(1)(f) GDPR for B2B communications and legitimate business relationships. Data may come from you, your organisation, business partners or professionally relevant public sources. Recipients may include our CRM, form and communications providers.
User accounts, authentication and permissions
For Platform accounts, we process names, business contact details, account and organisation assignments, roles, permissions, and authentication and security events. Purposes are account administration, access control, contract performance and information security. The legal bases are Article 6(1)(b) and (f) GDPR. Our legitimate interest is protecting the Platform, its Customers and users against unauthorised access and misuse.
Contracts, billing and legal obligations
We process Agreement, contact, usage, invoice and payment information for contract administration, billing, accounting and compliance with tax and company-law obligations. The legal bases are Article 6(1)(b) and (c) GDPR. Accounting records actually covered by section 132 BAO or section 212 UGB are generally retained for seven years from the applicable statutory trigger and longer where relevant to pending proceedings.
Support, security and abuse prevention
To provide support, we process contact and communication data, tickets, attachments and necessary diagnostic data. For information security, fraud and abuse prevention and incident investigation, we may process technical identifiers, logs, account and event data. The legal bases are Article 6(1)(b) and (f) GDPR; our legitimate interests are supporting Customers, securing our services and preventing unlawful use.
Newsletter and direct marketing
When you subscribe to a newsletter, we process your email address and evidence of consent under Article 6(1)(a) GDPR. Where permitted for B2B communications, direct marketing may also rely on Article 6(1)(f) GDPR; our interest is promoting relevant services to professional contacts. You may withdraw consent and object to direct marketing at any time.
Legal claims and compliance
Where necessary, we process relevant Agreement, communication, security and transaction data to comply with legal obligations and to establish, exercise or defend legal claims. The legal bases are Article 6(1)(c) and (f) GDPR. Our legitimate interest is protecting our rights and documenting lawful conduct.
4. Website, cookies, analytics and marketing
5. Customer Content and processing on instructions
Customer Content and Customer-related usage, permission and log data are processed on documented instructions to provide, secure, integrate and support the Platform. The Customer Agreement and DPA determine the nature, purposes, data categories, recipients, return and deletion.
At the end of processing, data is returned or deleted at the Customer's choice; backups are protected from productive use until deletion or overwrite unless mandatory law requires retention. Contractual transition, retrieval and deletion rules apply where a provider switch is relevant.
Data subjects should normally exercise rights regarding Customer-controlled content with the relevant Digicust Customer. Digicust assists that Customer under the DPA.
6. Recipients and international transfers
Depending on the activity, hosting, infrastructure, security, analytics, advertising, CRM, form, newsletter, communications, payment and professional advisory providers receive only necessary data. For Customer Content, the Digicust Trust Portal provides the current subprocessor register; the DPA and Appendix 2-C govern the contractually approved initial set and change process.
Cloudflare operates a globally distributed edge network and may process data, particularly in the United States. Where applicable, transfers rely on the EU-US Data Privacy Framework and, additionally, EU Standard Contractual Clauses. Other providers may permit limited third-country or remote access under their agreements. Such transfers rely on an adequacy decision or appropriate safeguards under Chapter V GDPR.
7. Retention
Personal data is deleted or anonymised when its purpose and applicable statutory or contractual evidence, security and limitation periods cease to apply. In the event of litigation, an authority investigation or a statutory retention duty, deletion may be suspended until the matter closes and the relevant period expires.
The seven-year period described in section 3 generally applies to relevant accounting and tax records. The provider periods or retention criteria stated in section 4 apply to LinkedIn Insight Tag and Apollo data. Section 5 and the relevant Agreement/DPA govern Customer Content retention.
8. Your rights
Subject to the GDPR, you have rights including:
- access and a copy of your data;
- rectification of inaccurate and completion of incomplete data;
- erasure or restriction;
- data portability where applicable;
- objection under Article 21 GDPR, particularly to direct marketing;
- withdrawal of consent for the future without affecting prior lawfulness;
- protection against solely automated decisions producing legal or similarly significant effects, where applicable; and
- a complaint to a supervisory authority.
Austrian authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at. To exercise your rights, contact privacy@digicust.com.
9. Changes, version and effective date
Version 1.2 · Effective 2 September 2026.
We update this notice following material changes to our processing or the law. Where required, we communicate material changes through appropriate channels.
This English version is provided for information only. The German version is the governing and authoritative version.