Digicust

Privacy Policy

Information about the processing of personal data by Digicust FlexCo.

Version 1.2 · 2 September 2026Authoritative German version

1. Controller and privacy contact

Controller

Digicust FlexCo
Commercial Register Number: FN 538643y
Am Felde 2, Haus 3, Top 2
2431 Enzersdorf an der Fischa, Austria

Managing Directors

Thomas Übellacker, MSc; Matthias Pfeiler, BA

Privacy contact

Please send privacy requests to privacy@digicust.com.

2. Scope and roles

This notice describes Digicust's processing as a controller, particularly when you visit our website, communicate with us, or when we administer business relationships, accounts and billing.

Where Digicust processes Customer Content and Customer-related usage, permission or log data on documented instructions to provide the Platform or agreed support, Digicust acts as a processor or subprocessor. The relevant Customer Agreement and Data Processing Agreement (DPA) govern that processing.

Customer Content processed on instructions is not used for Digicust's own advertising, general model training or independent product development. This notice does not grant Digicust additional rights over Customer Content.

3. Processing by Digicust as controller

Website delivery and security

When you access the website, we process technically necessary connection and log data, including IP address, time, requested resource, referrer, browser and device information. We use it to deliver the website, maintain stability, diagnose errors and detect or defend against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the website. Recipients may include hosting, CDN and security providers, particularly Cloudflare.

Enquiries, demos, trials and business relationships

For contact, demo, trial, partner or event requests, we process the contact, company, communication and, where applicable, test data you provide to respond, take pre-contractual steps and conduct business communications. The legal bases are Article 6(1)(b) GDPR for contractual or pre-contractual steps and Article 6(1)(f) GDPR for B2B communications and legitimate business relationships. Data may come from you, your organisation, business partners or professionally relevant public sources. Recipients may include our CRM, form and communications providers.

User accounts, authentication and permissions

For Platform accounts, we process names, business contact details, account and organisation assignments, roles, permissions, and authentication and security events. Purposes are account administration, access control, contract performance and information security. The legal bases are Article 6(1)(b) and (f) GDPR. Our legitimate interest is protecting the Platform, its Customers and users against unauthorised access and misuse.

Contracts, billing and legal obligations

We process Agreement, contact, usage, invoice and payment information for contract administration, billing, accounting and compliance with tax and company-law obligations. The legal bases are Article 6(1)(b) and (c) GDPR. Accounting records actually covered by section 132 BAO or section 212 UGB are generally retained for seven years from the applicable statutory trigger and longer where relevant to pending proceedings.

Support, security and abuse prevention

To provide support, we process contact and communication data, tickets, attachments and necessary diagnostic data. For information security, fraud and abuse prevention and incident investigation, we may process technical identifiers, logs, account and event data. The legal bases are Article 6(1)(b) and (f) GDPR; our legitimate interests are supporting Customers, securing our services and preventing unlawful use.

Newsletter and direct marketing

When you subscribe to a newsletter, we process your email address and evidence of consent under Article 6(1)(a) GDPR. Where permitted for B2B communications, direct marketing may also rely on Article 6(1)(f) GDPR; our interest is promoting relevant services to professional contacts. You may withdraw consent and object to direct marketing at any time.

Legal claims and compliance

Where necessary, we process relevant Agreement, communication, security and transaction data to comply with legal obligations and to establish, exercise or defend legal claims. The legal bases are Article 6(1)(c) and (f) GDPR. Our legitimate interest is protecting our rights and documenting lawful conduct.

4. Website, cookies, analytics and marketing

Technically necessary storage and access are used to operate the website. We use optional analytics, marketing and design services only in accordance with your Cookie Manager choice, which you may change at any time for the future. Technical identifiers and IP addresses may constitute personal data.

PostHog

We use PostHog through its EU endpoint for website and product analytics. Depending on consent, this may include event data, technical identifiers and session replay. Strict masking is configured before marketing consent; password fields remain masked after consent. The legal basis for optional personal analytics is Article 6(1)(a) GDPR. See the PostHog Privacy Notice.

Google Tag and Google Ads

Google tags initialise with Consent Mode and advertising and analytics consent denied by default. After consent, Google Ads and configured Google destinations may be used for reach and conversion measurement. Online identifiers, cookie, device, browser and interaction data may be processed. The legal basis is Article 6(1)(a) GDPR. Under Google's provider defaults, Google Analytics cookies generally last up to two years unless the specific setting or browser applies a shorter period. See the Google Privacy Policy.

Meta Pixel and Conversions API

After marketing consent, we use the Meta Pixel for reach, audience and conversion measurement. Certain conversion events may also be sent to Meta through a Conversions API executed by Cloudflare. Page views, event data, technical identifiers and hashed contact data may be processed. The legal basis is Article 6(1)(a) GDPR. Digicust and Meta Platforms Ireland Limited may be joint controllers for the collection and transmission of certain event data; Meta's terms govern its subsequent processing. See the Meta Privacy Policy.

OpenAI Ads Measurement Pixel and Conversions API

After marketing consent, and only for a visit carrying an OpenAI-provided advertising click identifier (oppref), we use the OpenAI Ads Measurement Pixel to measure and optimise our ChatGPT advertising campaigns. Before consent, this value may be held transiently in page memory so it is not lost during internal navigation; it is neither persistently stored nor transmitted at that stage. The Pixel may then store the identifier in the first-party __oppref cookie and set a browser reference named __obref so a later lead event can be considered within the applicable attribution window. We also send the lead_created event with the same event ID through a Conversions API executed by Cloudflare, allowing OpenAI to deduplicate browser and server signals. We process the event ID and time, a query-free page path, the opaque OpenAI identifiers and, on the server side, the IP address and user agent. Our Conversions API payload contains no form content or contact data. If Automatic Advanced Matching is enabled in Ads Manager in the future, the Pixel may detect supported contact data on the website, normalise it and hash it with SHA-256 in the browser; according to OpenAI, raw data is not sent through this feature. The legal basis is Article 6(1)(a) GDPR. The integration is not activated without consent or an OpenAI ad click. See the OpenAI Ads Measurement Pixel documentation and OpenAI Privacy Policy.

LinkedIn Insight Tag

After marketing consent, we use the LinkedIn Insight Tag for conversion measurement, audience creation and aggregate campaign reporting. LinkedIn may receive the URL, referrer, IP address, device and browser characteristics and timestamp. LinkedIn states that it removes direct identifiers within seven days and deletes the remaining pseudonymised data within 180 days. The legal basis is Article 6(1)(a) GDPR. See the LinkedIn Insight Tag FAQ.

Apollo company-level website visitor identification

Only after your separate website-visitor-identification consent do we load the website tracker provided by ZenLeads, Inc. d/b/a Apollo.io, 440 N Barranca Ave #4750, Covina, CA 91723-1722, USA. It is used to associate website visits with companies worldwide, assess visit and interest signals, and prioritise our B2B sales activity. The legal basis is your consent under Article 6(1)(a) GDPR and section 165(3) Austrian Telecommunications Act 2021.

Through the network request, Apollo may receive the IP address together with a pseudonymous visitor ID, timestamps, minimised public page categories, limited UTM campaign data, the origin of an external referrer, and matched company information. Apollo's automatic URL and SPA tracking is disabled in our integration: only the origin and a canonical category path such as /en/blog/ are sent, never the literal dynamic page path, query string, or fragment. We fully exclude unknown page categories, unknown parameters, suspicious UTM values, and sensitive functional pages such as account, activation, certificate, signature, vCard, business-card and administration pages.

The tracker version reviewed on 31 August 2026 uses, in particular, apolloAnonId and an event queue in local storage without a fixed browser expiry, plus a 24-hour record for Apollo's tracking eligibility. When the file is requested, Apollo or its security provider Cloudflare may additionally set the third-party security cookie __cf_bm on the Apollo domain for about 30 minutes; it is not readable by us. The external file is cryptographically pinned to the reviewed version; the browser blocks any change until it has been reviewed again. Our integration also stops processing if the reviewed runtime interfaces change. Apollo does not publish a fixed product-specific server retention period. The purpose, contract, risk and legal criteria in Apollo's privacy policy and the applicable DPA therefore apply; data must be deleted or anonymised when its purpose and applicable obligations end.

The recipient is Apollo. Depending on the processing stage, Apollo may act on instructions or as an independent controller. Apollo states in its privacy policy that customer-provided data may be used to expand, enrich, and verify its Contributor Database and made available to other Apollo customers. Its public materials do not conclusively assign Website Visitors data to that independent purpose; to the extent this use applies, it is included as potential Apollo processing under your separate consent. The precise contractual allocation must be confirmed with Apollo before production use. Data is transferred to the United States; Apollo identifies EU Standard Contractual Clauses and its EU-US Data Privacy Framework certification as transfer mechanisms. For more information and privacy requests, see the Apollo Privacy Policy and Apollo Privacy Center. You may withdraw consent at any time in the Cookie Manager. We then immediately block the runtime interfaces, delete accessible first-party identifiers and reload the page to terminate already executed third-party code and its listeners.

Apollo's person-level identification for US-based business contacts and the LiveIntent IdentityGraph technology included for that purpose in the currently reviewed tracker are technically disabled in our integration. Consequently, this integration does not load LiveIntent scripts, resolve email hashes through LiveIntent, or set LiveIntent identifiers. Any later activation first requires written clarification of roles, independent purposes and the applicable international-transfer safeguard, an updated privacy notice, and fresh consent; it must not be enabled through an Apollo dashboard change alone.

Adobe Fonts and YouTube

Adobe Fonts load only on pages using the relevant font assets and after consent. Adobe may receive technically necessary request data. YouTube content is loaded subject to consent and, where used, embedded in privacy-enhanced mode; Google or YouTube receives technical and usage data when a video is played. The legal basis is Article 6(1)(a) GDPR. See Adobe Fonts privacy information and the Google/YouTube Privacy Policy.

5. Customer Content and processing on instructions

Customer Content and Customer-related usage, permission and log data are processed on documented instructions to provide, secure, integrate and support the Platform. The Customer Agreement and DPA determine the nature, purposes, data categories, recipients, return and deletion.

At the end of processing, data is returned or deleted at the Customer's choice; backups are protected from productive use until deletion or overwrite unless mandatory law requires retention. Contractual transition, retrieval and deletion rules apply where a provider switch is relevant.

Data subjects should normally exercise rights regarding Customer-controlled content with the relevant Digicust Customer. Digicust assists that Customer under the DPA.

6. Recipients and international transfers

Depending on the activity, hosting, infrastructure, security, analytics, advertising, CRM, form, newsletter, communications, payment and professional advisory providers receive only necessary data. For Customer Content, the Digicust Trust Portal provides the current subprocessor register; the DPA and Appendix 2-C govern the contractually approved initial set and change process.

Cloudflare operates a globally distributed edge network and may process data, particularly in the United States. Where applicable, transfers rely on the EU-US Data Privacy Framework and, additionally, EU Standard Contractual Clauses. Other providers may permit limited third-country or remote access under their agreements. Such transfers rely on an adequacy decision or appropriate safeguards under Chapter V GDPR.

7. Retention

Personal data is deleted or anonymised when its purpose and applicable statutory or contractual evidence, security and limitation periods cease to apply. In the event of litigation, an authority investigation or a statutory retention duty, deletion may be suspended until the matter closes and the relevant period expires.

The seven-year period described in section 3 generally applies to relevant accounting and tax records. The provider periods or retention criteria stated in section 4 apply to LinkedIn Insight Tag and Apollo data. Section 5 and the relevant Agreement/DPA govern Customer Content retention.

8. Your rights

Subject to the GDPR, you have rights including:

  • access and a copy of your data;
  • rectification of inaccurate and completion of incomplete data;
  • erasure or restriction;
  • data portability where applicable;
  • objection under Article 21 GDPR, particularly to direct marketing;
  • withdrawal of consent for the future without affecting prior lawfulness;
  • protection against solely automated decisions producing legal or similarly significant effects, where applicable; and
  • a complaint to a supervisory authority.

Austrian authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at. To exercise your rights, contact privacy@digicust.com.

9. Changes, version and effective date

Version 1.2 · Effective 2 September 2026.

We update this notice following material changes to our processing or the law. Where required, we communicate material changes through appropriate channels.

This English version is provided for information only. The German version is the governing and authoritative version.