Skip to main content
Privacy policy

Your data, protected and transparent.

Data protection is a particularly high priority for the management of Digetiers GmbH. This statement informs you about which data we collect, how we process it and which rights you have under the GDPR.

01General

When we process data.

We are delighted by your interest in our company. Data protection is a top priority for the management of Digetiers GmbH, and the protection of your personal data is especially important to us.

You can generally use our website without providing personal data. However, if you wish to use certain services, it may be necessary for us to process your data. In such cases, we only do so where there is a legal basis for it or where you have given your consent.

We process your personal data (e.g. name, address, email, telephone number) only within the framework of applicable data protection law, in particular the General Data Protection Regulation (GDPR). The terms used in this privacy statement correspond to the definitions of the GDPR, in particular Art. 4 GDPR. With this statement we inform you which data we collect, how we use and process it, and which rights you have.

Data processing is permitted in particular in three cases

a

ConsentArt. 6(1)(a) & 7 GDPR

Where you have consented to the processing of your data by us. We inform you in advance — in this privacy statement and at the time of obtaining consent, in accordance with Art. 4 No. 11 GDPR — precisely for what purpose and under what circumstances your data is processed by us.

b

ContractArt. 6(1)(b) GDPR

Where the processing of your personal data is necessary for the initiation, conclusion or performance of a contractual relationship.

c

Legitimate interestArt. 6(1)(f) GDPR

Where, following a balancing of interests, the processing is necessary to safeguard our legitimate interests and your interests or fundamental rights do not override them. Our legitimate interests lie in particular in the technically flawless, secure and trouble-free operation of our website, the prevention of attacks and misuse, the storage of access data in server log files, a privacy-friendly, cookieless reach measurement, and the use of service providers required for this. Web analytics using cookies, marketing services and the creation of usage-based profiles for advertising purposes, by contrast, are not based on our legitimate interest but exclusively on your prior consent via our cookie banner (see the “Cookies” section).

02Controller

Who is responsible for your data.

The controller within the meaning of the GDPR, other data protection laws applicable in the member states of the European Union and other provisions of a data protection nature is:

Digetiers GmbHThe Knowledge Layer Company
Address
Lautenschlagerstraße 16
70173 Stuttgart, Germany
Email
Managing Director
Julius Hollmann
Register court
Stuttgart Local Court (Amtsgericht Stuttgart)
Register number
HRB 722816
VAT ID
DE328242554
External Data Protection OfficerDataGAP GmbH
Bessemerstr. 51, 1. OG
12103 Berlin, Germany
Contact:

We have appointed DataGAP GmbH to advise on data protection matters and to support us as our company data protection officer. Please send all data protection enquiries to the contact address above; we will forward them to our data protection officer where necessary.

03Contacting us

When you contact us.

If you contact us by email or via our contact form, we process your first and last name, your email address and the content of your message in order to handle your enquiry. Enquiries are stored and processed in HubSpot. The legal basis is Art. 6(1)(b) GDPR (performance or initiation of a contract) or Art. 6(1)(f) GDPR; our legitimate interest lies in the proper and prompt handling of your contact enquiry and the associated communication. We delete the data as soon as it is no longer required for processing and no statutory retention obligations apply. As described above, we use HubSpot, provided by HubSpot Ireland Limited, 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland, as a processor pursuant to Art. 28 GDPR. We have concluded a data processing agreement (DPA) with HubSpot. According to their information, the data we use is processed and stored in Frankfurt am Main. As the parent company HubSpot, Inc. is based in the USA, a transfer of personal data to the USA cannot be ruled out. HubSpot, Inc. is certified under the EU-US Data Privacy Framework (DPF); the transfer therefore takes place on the basis of the European Commission’s adequacy decision on the DPF (Art. 45 GDPR) and, additionally, on the basis of the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).

If you would like to apply for a position with us, please use exclusively our applicant management tool Personio for this purpose, and not this contact option or an email address. Application documents that reach us by email are handled in accordance with the requirements set out in the “Applications” section.

04Hosting & security

Technical operation & encryption.

Web hosting

Our website is operated on Amazon Web Services (AWS); the provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. Operation takes place via the AWS Amplify service with a server location in the European Union (AWS region Ireland); the website is delivered via the Amazon CloudFront content delivery network with edge locations distributed worldwide. The legal basis is our legitimate interest in a technically flawless, secure and economically efficient online offering (Art. 6(1)(f) GDPR).

With every access, usage data is automatically collected in so-called server log files: browser type and version, the operating system used, the referrer URL, the time of the server request and the IP address. This data is necessary to deliver the website correctly, to ensure its stability and security, to prevent attacks and, in the event of cyberattacks, to provide investigating authorities with the necessary information. We do not use this information to draw conclusions about you as an individual. Server log files are stored separately from other personal data and deleted after 15 months at the latest.

AWS processes personal data exclusively in accordance with our instructions within the framework of a data processing agreement (Art. 28 GDPR, AWS Data Processing Addendum). Where data is processed outside the EU or EEA (in particular in the USA) as part of the CDN operation, this takes place on the basis of the EU-US Data Privacy Framework — Amazon Web Services, Inc. is certified under it — and, additionally, the standard contractual clauses approved by the European Commission. Further information can be found in the AWS privacy notice at aws.amazon.com/privacy.

Our domain is managed by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany (domain and DNS services). A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS SE. When resolving the name for a website request, IONOS technically processes the IP addresses of the requesting DNS resolvers; no further processing of personal data by IONOS takes place for the operation of this website. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the reliable technical provision and availability of our website.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential content — such as enquiries you send to us as the site operator — this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser changes from “http://” to “https://” and by the lock symbol in your browser bar. When SSL/TLS encryption is active, the data you transmit to us cannot be read by third parties.

Cookieless reach measurement

In addition to consent-based web analytics (see the Google Analytics section), we record page views using our own cookieless method directly on our server. No cookies are set and no information is stored on or read from your device; consent under Sec. 25 TDDDG is therefore not required. We record exclusively: the page accessed (without URL parameters), the language version, the domain of the referring website on entry, a rough device class and the country of origin.

To determine the number of unique visitors, a daily-rotating, non-reversible check value (hash) is calculated from the IP address and browser identifier. The IP address itself is only processed transiently and not stored; the check value can neither be traced back to you nor linked across multiple days. The legal basis is our legitimate interest in privacy-friendly reach measurement (Art. 6(1)(f) GDPR). The aggregated statistics are stored as part of our hosting provider’s server logging.

05Cookies

Only with your consent.

Our website uses cookies and comparable technologies. Technically necessary cookies — such as those used to store your cookie decision — are set on the basis of our legitimate interest (Art. 6(1)(f) GDPR or Sec. 25(2) TDDDG); they do not require consent. Our legitimate interest in this respect lies in the trouble-free and secure operation of the website, in providing the functions you have expressly requested, and in storing and implementing your cookie decision. All other cookies and services — for web analytics (statistics) and marketing — are only set or loaded once you have actively consented via our cookie banner (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG).

In the cookie banner you can activate or reject each category and each individual service separately. Without your consent, no analytics or marketing cookies are set and the corresponding services are not loaded. Your selection is valid for 180 days and can be revoked or changed at any time with effect for the future via the “Cookies” link in the footer.

You can find out which services we use specifically, which cookies they use, for what purpose and on what legal basis in the following overview.

Services & cookies in use

Google Tag ManagerAnalytics
Provider
Google Ireland Ltd., Ireland (group USA, DPF-certified)
Cookies
No cookies of its own (loads tags only)
Purpose
Managing measurement and marketing tags
Retention
Legal basis
Art. 6(1)(a) GDPR · Sec. 25(1) TDDDG (consent)
Google Analytics 4Analytics
Provider
Google Ireland Ltd., Ireland (group USA, DPF-certified)
Cookies
_ga, _ga_<ID>
Purpose
Anonymised reach and usage analytics (IP anonymisation on)
Retention
up to 2 years
Legal basis
Art. 6(1)(a) GDPR · Sec. 25(1) TDDDG (consent)
HubSpotAnalytics
Provider
HubSpot, Inc., USA (DPF-certified)
Cookies
__hstc, hubspotutk, __hssc, __hssrc
Purpose
Visitor analytics and request attribution
Retention
approx. 6 months · __hssc 30 min · __hssrc session
Legal basis
Art. 6(1)(a) GDPR · Sec. 25(1) TDDDG (consent)
SalesViewerMarketing
Provider
SalesViewer GmbH, Bochum, Germany (no third country)
Cookies
No cookies of its own; identification takes place via a client-side script that reads technical information from your device (including browser/device details) and behavioural data and matches it against a company database.
Purpose
Identifying company visitors
Retention
Legal basis
Art. 6(1)(a) GDPR · Sec. 25(1) TDDDG (consent)
LinkedIn InsightMarketing
Provider
LinkedIn Ireland Unlimited Company, Ireland (group USA, DPF-certified)
Cookies
bcookie, lidc, li_gc, UserMatchHistory
Purpose
Campaign and conversion measurement
Retention
1 day to 1 year
Legal basis
Art. 6(1)(a) GDPR · Sec. 25(1) TDDDG (consent)

Cookie names and retention periods reflect the current state of the providers’ documentation and may change.

06Content management

Content via Storyblok.

For our website we use the content management system Storyblok, provided by Storyblok GmbH, Peter-Behrens-Platz 2, 4020 Linz, Austria, to manage and deliver content efficiently. When you visit our website, requests are sent to Storyblok’s servers in order to load content dynamically. The following personal data is processed:

— your IP address
— information about the browser and operating system you use
— the date and time of access
— the page you access

This data is processed to safeguard our legitimate interest in a functional and performant website pursuant to Art. 6(1)(f) GDPR. Further information can be found at storyblok.com/privacy-policy.

07Purposes & legal bases

What we use data for.

a

Website use

We process your data in order to provide the website, prevent attacks and optimise our offering. The legal basis is Art. 6(1)(f) GDPR (legitimate interest).

b

Contacting us

When you contact us (e.g. by email or contact form), we process your data to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR (performance/initiation of a contract) or Art. 6(1)(f) GDPR (legitimate interest in handling your contact enquiry).

c

Applications

If you would like to apply to us, please use exclusively our applicant management tool Personio on our website. Applications via other channels (e.g. by email) are not considered and are deleted without delay.

We process your data to conduct the application procedure via Personio, operated by Personio SE & Co. KG, Munich, with whom we have concluded a data processing agreement. The legal basis is Art. 6(1)(b) GDPR in conjunction with Sec. 26 BDSG. If you are hired, we continue to store your data within the scope of the employment relationship. If your application is rejected, we delete your data after 6 months unless legitimate interests exist (e.g. obligations to provide evidence under the AGG). Further information can be found in our privacy statement for applicants.

d

Newsletter & email communication

If you subscribe to one of our newsletters or consent to promotional email contact (e.g. “The Knowledge Layer” or general product and company updates), we process your email address and the registration data in order to send you the selected content by email. The legal basis is your consent (Art. 6(1)(a) GDPR). Registration takes place via the double opt-in procedure: you first receive a confirmation email and are only added to the distribution list after clicking the confirmation link. To demonstrate consent, we log the time of registration and confirmation as well as the IP address used. You can revoke your consent at any time with effect for the future, e.g. via the unsubscribe link in every email. We use HubSpot for dispatch and management (see the sections on processing and third-country transfer).

e

Whitepaper & document downloads

If you request a whitepaper or another document, we process the data you provide (e.g. name, company, email address) in order to make the document available or send it to you. The legal basis is Art. 6(1)(b) GDPR (performance of pre-contractual measures at your request) or Art. 6(1)(f) GDPR (legitimate interest in provision). Optionally, you can additionally consent to receiving further emails; this consent is voluntary and not a precondition for the download (Art. 6(1)(a) GDPR, double opt-in as under d). Without this consent, we use your data exclusively to deliver the requested document.

f

Events & webinars

For the registration and running of events/webinars, we process your details for organisation, for providing the access link and for event-related information. The legal basis is Art. 6(1)(b) GDPR. An optional subscription to further emails after the event takes place only on the basis of your voluntary consent (Art. 6(1)(a) GDPR, double opt-in); participation is independent of this.

08Third-country transfer

Transfer to third countries.

As part of our website, personal data may be transferred to recipients in so-called third countries outside the European Union (EU) or the European Economic Area (EEA), in particular to the USA. This concerns, for example, services such as Google Analytics or Google Tag Manager, whose provider Google LLC is based in the USA.

The USA is currently not generally regarded, under data protection law, as a country with a level of protection equivalent to the GDPR. In order to ensure the protection of your data nonetheless, the transfer takes place — where the respective provider is certified under the EU-US Data Privacy Framework (DPF) (e.g. Google LLC, HubSpot, Inc., Amazon Web Services, Inc.) — on the basis of the European Commission’s adequacy decision pursuant to Art. 45 GDPR. Additionally, or where no DPF certification exists, we base the transfer on the European Commission’s standard contractual clauses pursuant to Art. 46(2)(c) GDPR, which we have concluded with the respective providers. Further information on the third-party providers used can be found in the respective sections of this privacy statement.

09Google services

Analytics & Tag Manager.

Our website uses services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland (“Google”).

Google Analytics

We use Google Analytics 4 (GA4), a web analytics service provided by Google. GA4 is loaded exclusively via Google Tag Manager and only once you have consented to web analytics via our cookie banner (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG). In addition, we use Google Consent Mode v2: without your consent, Google receives the “denied” signal and no analytics data is transmitted — not even so-called cookieless pings.

GA4 collects information about your use of our website (e.g. pages accessed, time spent, clicks on buttons and downloads, browser type and version, device category, approximate region of origin) and uses cookies for this. Full IP addresses are not logged or stored by Google Analytics 4; the IP address is only used transiently for rough location determination and then discarded. The purpose of the processing is to analyse user behaviour in order to improve our website and to statistically evaluate our content and marketing measures. You can revoke your consent at any time with effect for the future via the “Cookies” link in the footer.

It cannot be ruled out that data is also processed by Google on servers in the USA. Google LLC is certified under the EU-US Data Privacy Framework; additionally, we have concluded with Google the standard contractual clauses (SCCs) approved by the European Commission.

Google Tag Manager

We also use Google Tag Manager (GTM), a tool for managing website services (“tags”). GTM is likewise only loaded after your consent via the cookie banner and does not set any cookies of its own. However, it triggers other services (such as Google Analytics) which in turn can collect data — each of these services remains bound to your respective consent: via Google Consent Mode v2 we transmit the status of your consent to Google, and services without consent are not triggered. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.

You can delete cookies that have already been set at any time in your browser settings; on your next visit you will be asked for your consent again. If you have consented to the use of Google Analytics, you can additionally prevent future data collection by installing the official browser add-on to deactivate Google Analytics — available at tools.google.com/dlpage/gaoptout. Further information can be found in Google’s privacy policy at policies.google.com/privacy.

10Social media

Linked profiles.

On our website we link to our company profiles on various social networks. These are exclusively external links. No active social plugins (such as Like or Share buttons) are used that would automatically transmit data to the platform operators as soon as the page loads.

Processing of your personal data by the respective providers (including LinkedIn, Meta Platforms, Substack and Medium) only takes place once you actively click a link and visit our presence there. We have no influence over the processing by these providers. Further information can be found in the privacy policy of the respective provider.

LinkedIn

We operate a LinkedIn page in order to communicate with prospects, applicants and customers. When you visit it, data is processed by LinkedIn Ireland Unlimited Company. We receive only aggregated, anonymous statistics from LinkedIn.

Instagram

We use Instagram, operated by Meta Platforms Ireland Limited, to present our company culture, services and projects. When you visit our Instagram page, Meta’s privacy policy applies. We do not receive any personal data from Instagram, only aggregated insights.

Substack

We use Substack, operated by Substack, Inc., to publish articles and specialist content. The link on our website leads directly to our Substack presence. When you visit the Substack page, data is processed by Substack under its own responsibility. Further information can be found in Substack’s privacy policy.

Medium

We use Medium, operated by Medium Corporation, to publish specialist articles. When you visit our Medium page, data is processed by Medium under its own responsibility. Further information can be found in Medium’s privacy policy.

11Applications

Data in the application process.

If you would like to apply to us, please use exclusively our applicant management tool Personio on our website. Applications via other channels (e.g. by email) are not considered and are deleted without delay. We process applicant data exclusively for the purpose of conducting the application procedure. The legal basis is Art. 6(1)(b) GDPR in conjunction with Sec. 26 BDSG. Additional information submitted voluntarily is processed on the basis of your consent pursuant to Art. 6(1)(a) GDPR.

If your application documents contain special categories of personal data within the meaning of Art. 9(1) GDPR — such as information on a severe disability, health or religious affiliation — we process this, insofar as it is necessary for exercising rights or fulfilling obligations under employment law and social security law, on the basis of Art. 6(1)(b) in conjunction with Art. 9(2)(b) GDPR and Sec. 26(3) BDSG; otherwise only on the basis of your explicit consent pursuant to Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR. We ask you to refrain from including unnecessary special categories of personal data in your documents.

For the application procedure we use Personio SE & Co. KG, Munich, as a processor within the meaning of Art. 28 GDPR. Only the responsible employees in the human resources (HR) department and the management have access to applicant data. Personio may also use subcontractors to provide the service; any data transfers to third countries take place on the basis of appropriate safeguards, in particular standard contractual clauses. If no employment relationship is established, we generally delete your data after six months, unless longer storage is required for the assertion, exercise or defence of legal claims or you have consented to longer storage. Earlier deletion takes place if you request it in the context of your data subject rights and no statutory retention obligations or legitimate interests preclude it. In the case of a successful application, the data is further processed for the employment relationship.

12Disclosure to third parties

When we share data.

We only disclose personal data if:

a

you have consented — Art. 6(1)(a) GDPR

b

this is necessary for the performance of a contract — Art. 6(1)(b) GDPR

c

we are legally obliged to do so — Art. 6(1)(c) GDPR

d

legitimate interests exist and your rights do not override them — Art. 6(1)(f) GDPR

13Retention

How long we store data.

Further storage is considered above all where this is still necessary for legal action by us or for our other legitimate interests. For your master data that was required to fulfil a (including free-of-charge) contractual relationship, this means that we store it until the complete fulfilment or termination of the contractual relationship, plus the limitation period (which is generally 2 or 3 years), plus a reasonable margin for a possible interruption of the limitation period.

For your usage data collected in connection with your use of the website, this means that we store it only for as long as this is still necessary for the proper functioning of our website and our legitimate interest extends. Statistical information will primarily be stored only in pseudonymised form. Beyond that, we store your data insofar as we are legally obliged to do so. These are in particular the tax retention periods, which are generally 6 or even 10 years.

14Your rights

Your rights under the GDPR.

01

AccessArt. 15 GDPR

You can find out which personal data we process about you.

02

RectificationArt. 16 GDPR

You can have inaccurate or incomplete data rectified.

03

ErasureArt. 17 GDPR

You can request the erasure of your personal data.

04

Restriction of processingArt. 18 GDPR

You can have the processing of your data restricted in certain cases.

05

Data portabilityArt. 20 GDPR

You can receive your data in a structured, commonly used format or have it transferred to another controller.

06

ObjectionArt. 21 GDPR

You can object to the processing of your personal data.

07

Withdrawal of consentArt. 7(3) GDPR

You can withdraw a consent you have given at any time with effect for the future, without affecting the lawfulness of processing carried out up to the withdrawal.

08

Complaint to a supervisory authorityArt. 77 GDPR

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, www.baden-wuerttemberg.datenschutz.de.

To exercise your rights, please contact .

15Changes

Changes to this statement.

We reserve the right to adjust this privacy statement in order to keep it in line with current legal requirements or changes to our services. We will inform you of material changes to this privacy statement as well as of changes to the purposes of processing, for example by means of a clear notice on our website or — where necessary — by direct notification.

Status of this privacy statement: July 2026.