Privacy policy.
Information pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR) on the processing of personal data when visiting digihap.tech.
The essentials in brief. This website sets no cookies, uses no analytics or tracking services, embeds no third-party content and loads fonts exclusively from its own server. We process personal data only to the extent necessary for the secure operation of the website and to answer your enquiries. The servers are located in Frankfurt am Main, Germany. IP addresses are stored in truncated form in log files and deleted after seven days at the latest.
This English version is provided for your convenience; in case of discrepancies the German Datenschutzerklärung prevails.
Contents
- 1. Controller
- 2. Principles and definitions
- 3. Hosting and server logs
- 4. Encryption
- 5. Contact form
- 6. Contact by e-mail and post
- 7. Local storage: language, appearance, notice
- 8. What we do not do
- 9. Recipients and processors
- 10. Transfers to third countries
- 11. Retention periods
- 12. Your rights
- 13. Right to object
- 14. Right to lodge a complaint
- 15. Obligation to provide data, automated decisions
- 16. Data security
- 17. Changes to this policy
1. Controller
The controller within the meaning of Article 4 (7) GDPR is:
DigiHap EWIV (European Economic Interest Grouping)
Friedrich-List-Platz 1
04103 Leipzig, Germany
E-mail: kontakt@digihap.tech
Telephone: +421 904 577 873
Represented by the manager: Alexander Löbner
No data protection officer has been appointed, as the statutory requirements for a mandatory appointment (Article 37 GDPR, Section 38 of the German Federal Data Protection Act, BDSG) are not met. For all questions regarding data protection you can reach us at the e-mail address above or by post, marked «Datenschutz».
2. Principles and definitions
We process personal data in accordance with the principles of lawfulness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality (Article 5 GDPR). This website is designed so that a plain visit generates as little data as technically possible (data protection by design and by default, Article 25 GDPR).
«Personal data» means any information relating to an identified or identifiable natural person (Article 4 (1) GDPR), such as a name, an e-mail address or an IP address. «Processing» means any operation performed on such data, such as collection, storage, transmission or erasure (Article 4 (2) GDPR).
The legal bases for our processing follow from Article 6 (1) GDPR: point (b) (contract or pre-contractual measures), point (c) (legal obligation) and point (f) (legitimate interests). We do not rely on consent (point (a)) to operate this website; in the contact form we merely ask you to confirm that you have read this privacy policy.
3. Hosting and server logs
Hosting provider
This website is operated on a server (virtual machine) managed by us and located in the Frankfurt am Main data centre (region FRA1) of the following provider:
DigitalOcean, LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA.
We have concluded a data processing agreement with DigitalOcean pursuant to Article 28 GDPR. According to the provider’s assurances, all data we store on the server remains in the selected Frankfurt region. For the particularities of a provider based in the USA, see section 10.
Server log files
Each time a page or file is requested, the web server automatically processes information transmitted by your browser and stores it in log files:
- IP address of the requesting device — truncated before storage (IPv4: last octet set to 0; IPv6: shortened to the first 48 bits), so that it can no longer be attributed to your connection
- date and time of the request
- requested address (URL) and amount of data transferred
- HTTP status code
- browser identifier (user agent) and referrer URL, where transmitted by your browser
Purpose: ensuring the trouble-free and secure operation of the website, detecting and defending against attacks, and error analysis. The logs are not merged with other data sources and are not used to create usage profiles.
Legal basis: Article 6 (1) (f) GDPR. Our legitimate interest lies in the technical security and functionality of our website.
Retention: the log files are automatically deleted after seven days at the latest. Longer storage occurs only if a specific security incident requires further analysis; in that case the entries concerned are kept separately until the matter is resolved.
To fend off automated mass requests, the web server limits the number of requests per IP address (rate limiting). The counters required for this are kept only briefly in the server’s memory and are not stored permanently.
4. Encryption
This website is delivered exclusively over an encrypted connection (HTTPS with TLS). Requests over an unencrypted connection are redirected automatically; the «Strict-Transport-Security» header instructs the browser to use encrypted connections only in future. You can recognise the encrypted connection by the padlock symbol in your browser’s address bar. Data you send to us via the contact form is thereby protected against interception by third parties during transmission.
5. Contact form
Data processed
When you send us a message via the contact form, we process the details you enter: name, e-mail address and the content of your message, together with the time of submission. No further details are required; please include in the message field only what is necessary for your request.
How transmission works
The form is processed without third-party services. Your details are transmitted in encrypted form to our own server in Frankfurt, checked there for completeness and plausibility and then forwarded as an e-mail over an encrypted connection (TLS) to our mailbox kontakt@digihap.tech. Your details are not stored permanently on the web server; they are removed from memory once the e-mail has been sent.
To protect against automated spam submissions we use only technical means without third parties: a form field invisible to humans that only programs fill in, a check of the time elapsed between opening the form and submitting it, and a limit on the number of submissions. For that limit, a non-reversible, daily-changing check value derived from your IP address is held in memory for a maximum of 60 minutes. Your IP address itself is neither stored by the form service nor transmitted to us in the e-mail. We do not use CAPTCHAs or bot detection by external providers.
Purpose and legal basis
We process your details solely to handle and answer your enquiry and for the resulting correspondence. The legal basis is Article 6 (1) (b) GDPR where your enquiry is aimed at concluding or performing a contract or membership, and otherwise Article 6 (1) (f) GDPR on the basis of our legitimate interest in answering enquiries addressed to us properly.
Your confirmation that you have read this privacy policy serves transparency and is not consent within the meaning of Article 6 (1) (a) GDPR; it does not give rise to any additional processing.
Retention
Your enquiry and our reply are stored in our e-mail mailbox and deleted once the matter has been dealt with conclusively and no further correspondence is to be expected, at the latest six months after the last exchange. If the enquiry leads to membership or a contract, the documents required for this are retained in accordance with statutory retention periods (see section 11).
6. Contact by e-mail and post
If you contact us directly by e-mail at kontakt@digihap.tech or by post, we process the details you provide (sender address, name, content of your message, attachments) in order to handle your request. The legal basis is Article 6 (1) (b) or (f) GDPR as described in section 5.
Please note that the confidentiality of an e-mail cannot be guaranteed along the entire transmission path. Our mailboxes are accessible via encrypted connections (TLS); whether the connection between the mail servers involved is encrypted also depends on your provider. For particularly confidential documents we recommend the postal route or handing them over in person.
Our e-mail mailbox is provided by: united-domains GmbH, Gautinger Straße 10, 82319 Starnberg, Germany; the servers are located in Germany. A data processing agreement pursuant to Article 28 GDPR is in place with this provider.
7. Local storage: language, appearance, notice
This website sets no cookies. It stores three settings exclusively in your own browser (web storage) — and only if you make them yourself:
| Key | Content | When stored |
|---|---|---|
| digihap-theme | «light» or «dark» — your choice of appearance | when you use the light/dark switch |
| digihap-lang | «de» or «en» — your choice of language, so that you arrive in your language on your next visit | when you switch the language |
| digihap-consent | time of acknowledgement of the privacy notice, so that it is not shown again | when you confirm the notice with «Got it» or «Close» |
These values contain no identifier, are not transmitted to our server and do not allow recognition. Storing them is strictly necessary to provide the service you have explicitly requested — the chosen appearance, the chosen language, hiding the notice — (Section 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG); no consent is required for this. Without your choice, the appearance follows your device’s system setting and the language follows the address you open, and nothing is stored.
Under «Privacy settings» (in the menu and in the footer) you can see at any time what is stored and delete all values with one click. You can also remove them via your browser settings («clear site data»).
Notice bar on your first visit
On your first visit we show a short notice bar. It is not a «cookie banner» in the legal sense — there is nothing for which we would need your consent — but information that this website works without cookies and tracking and about what it stores in your browser. Should we use services requiring consent in future (such as audience measurement), we would list them in the privacy settings as a separate category with a genuine choice and update this policy.
8. What we do not do
- We set no cookies — neither technically necessary ones nor any for analytics or advertising. The notice bar on your first visit merely informs you of this (see section 7).
- We use no web analytics, no tracking, no pixels, no fingerprinting and no audience measurement.
- We embed no third-party content: no external fonts (Google Fonts or similar), no map services, no videos, no social media plug-ins, no content delivery networks. The map illustrations on this website are our own static vector graphics.
- We send no newsletter and no advertising e-mails.
- We do not pass on your data for advertising purposes and do not sell it.
- We make no automated decisions and carry out no profiling (Article 22 GDPR).
9. Recipients and processors
Within DigiHap EWIV, only those persons who deal with your request have access to your data. Data is passed on to third parties only where necessary to fulfil the respective purpose, where we are legally obliged to do so or where you ask us to.
The following service providers process data on our behalf and on our instructions on the basis of agreements pursuant to Article 28 GDPR:
| Service provider | Service | Place of processing |
|---|---|---|
| DigitalOcean, LLC, Broomfield (USA) | Provision of the server infrastructure (hosting) | Frankfurt am Main, Germany (region FRA1) |
| united-domains GmbH, Starnberg (Germany) | Provision of the mailbox kontakt@digihap.tech and of outgoing mail for the contact form | Germany |
| C&W Code und Consulting GbR, Offenburg (Germany) | Technical support and maintenance of the website and server | Germany |
10. Transfers to third countries
Our servers are located in Germany. However, the hosting provider DigitalOcean is based in the United States of America. Even though the data is stored in Frankfurt, it cannot be ruled out that the provider’s staff access systems from the USA, for example for maintenance or support. For these cases the transfer is based on DigitalOcean’s certification under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023, Article 45 GDPR) and, in addition, on the EU standard contractual clauses agreed in the data processing agreement (Implementing Decision (EU) 2021/914, Module 2, Article 46 (2) (c) GDPR). A copy of the safeguards is available on request.
Beyond this, we do not transfer personal data to countries outside the European Union or the European Economic Area.
11. Retention periods
We store personal data only for as long as necessary for the respective purpose and delete it thereafter, unless statutory retention obligations require otherwise. In overview:
| Data | Retention period |
|---|---|
| Server logs (with truncated IP address) | 7 days at most |
| Check values for abuse prevention (form, rate limiting) | 60 minutes at most, in memory only |
| Local storage in your browser (language, appearance, notice) | until you delete the values — nothing is stored with us |
| Enquiries via form, e-mail or post | until dealt with conclusively, at most 6 months after the last exchange |
| Business correspondence with members and contractual partners | 6 years (commercial letters, Section 257 HGB, Section 147 of the German Fiscal Code, AO) |
| Accounting records and tax-relevant documents | 8 or 10 years in accordance with the applicable provisions of the HGB and AO |
12. Your rights
As a data subject you have the following rights vis-à-vis us:
- Access (Article 15 GDPR) to the personal data we process, its origin, recipients and the purpose of processing;
- Rectification (Article 16 GDPR) of inaccurate data or completion of incomplete data;
- Erasure (Article 17 GDPR), unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
- Restriction of processing (Article 18 GDPR);
- Data portability (Article 20 GDPR), i.e. receipt of the data you provided to us in a structured, commonly used and machine-readable format;
- Objection (Article 21 GDPR), see section 13;
- Withdrawal of consent given, with effect for the future (Article 7 (3) GDPR), should we exceptionally base processing on consent.
To exercise your rights, an informal message to kontakt@digihap.tech or to our postal address is sufficient. We respond to your request without undue delay and at the latest within one month (Article 12 (3) GDPR). To protect confidentiality, we may request additional information to confirm your identity where there are reasonable doubts.
13. Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Article 6 (1) (f) GDPR (legitimate interests). We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims (Article 21 (1) GDPR). We do not engage in direct marketing; an objection to direct marketing (Article 21 (2) GDPR) is therefore moot but would be honoured at any time.
14. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement (Article 77 GDPR). The supervisory authority responsible for us is:
Sächsische Datenschutz- und Transparenzbeauftragte (Saxon Data Protection and Transparency Commissioner)
Maternistraße 17, 01067 Dresden, Germany
Postfach 11 01 32, 01330 Dresden, Germany
Telephone: +49 351 85471-101
E-mail: post@sdtb.sachsen.de
Web: www.datenschutz.sachsen.de
15. Obligation to provide data and automated decisions
You are neither legally nor contractually obliged to provide us with personal data. You can visit this website without providing any personal data. Without your name and a means of contact, however, we cannot answer enquiries. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place.
16. Data security
We take technical and organisational measures pursuant to Article 32 GDPR to protect your data against loss, misuse and unauthorised access. These include in particular: end-to-end transport encryption (TLS), a restrictive content security policy and further security headers, a firewall restricted to the necessary services, server access exclusively via cryptographic keys, automatic security updates, truncated logging, regular encrypted backups and the principle of least privilege for everyone involved. The measures are reviewed regularly and adapted to the state of the art.
17. Changes to this policy
We adapt this privacy policy when the legal situation, our website or the services we use change. The version published here is the applicable one. This policy is available in German and English; in case of discrepancies the German version prevails. It applies exclusively to the website digihap.tech; for processing in the context of membership or a contractual relationship we provide separate information.
The content of this website does not constitute financial, tax or legal advice. This privacy policy, too, informs you solely about the processing of your data by DigiHap EWIV.
Last updated: September 2026