Digraph

Privacy Policy / Datenschutzerklaerung

Last updated / Letzte Aktualisierung: 05.05.2026

Controller / Verantwortlicher: See provider details in /impressum. For privacy requests: demo-privacy@example.com

1. Scope

This policy explains how Digraph processes personal data when you use our website and SaaS platform for AI brand visibility monitoring.

2. Personal Data We Collect

2.1 Data You Provide

CategoryExamplesPurpose
Account dataName, email addressAccount creation, authentication
Payment dataBilling address, payment method (processed by Stripe)Process subscriptions
Client/campaign dataBrand names, keywords, ad copy inputsProvide the service
CommunicationsEmails, support requestsCustomer support

2.2 Data Collected Automatically

CategoryExamplesPurpose
Usage dataPages visited, features used, timestampsService improvement
Device dataIP address, browser type, OSSecurity, troubleshooting
CookiesSession, preference, analytics (with consent)Functionality, analytics

3. Legal Basis for Processing (GDPR Art. 6)

Processing ActivityLegal Basis
Account creation & service deliveryContract performance (Art. 6(1)(b))
Payment processingContract performance (Art. 6(1)(b))
Essential cookiesLegitimate interest (Art. 6(1)(f))
Analytics cookiesConsent (Art. 6(1)(a))
Marketing emailsConsent (Art. 6(1)(a))
Legal complianceLegal obligation (Art. 6(1)(c))
Fraud preventionLegitimate interest (Art. 6(1)(f))

4. How We Use Your Data

  • Provide, maintain, and improve our services
  • Process payments and manage subscriptions
  • Send transactional emails (confirmations, password resets)
  • Respond to support requests
  • Detect and prevent fraud or abuse
  • Comply with legal obligations
  • Send marketing communications (only with consent)

5. Data Sharing & Sub-processors

We share personal data only where needed to provide the service:

RecipientPurposeLocationSafeguard
SupabaseDatabase, authentication, storageEU/USA (project dependent)DPA + SCCs where required
Stripe (if billing is active)Payment processing and invoicingUSADPA + SCCs where required
ResendTransactional emails (alerts, support replies)USADPA + SCCs where required
OpenAILLM processing for analysis jobsUSADPA + SCCs where required
AnthropicLLM processing for analysis jobsUSADPA + SCCs where required
Google CloudHosting, infrastructure, observabilityEU/USA (service dependent)DPA + SCCs where required
Google (OAuth)Optional sign-in providerUSADPA + SCCs where required

We do not sell personal data.

6. International Data Transfers

Your data may be transferred to countries outside the EU/EEA, including the USA. We protect such transfers using:

  • EU Standard Contractual Clauses (SCCs)
  • Data Processing Agreements (DPAs)
  • Technical and organizational security measures

7. Data Retention

Data TypeRetention Period
Account dataDuration of account + 30 days after deletion
Payment records10 years (German tax law)
Support communications3 years
Server logs90 days
Analytics data14 months

8. Your Rights (GDPR)

You have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data ("right to be forgotten") (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability – receive your data in a structured format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time (Art. 7(3))
  • Lodge a complaint with a supervisory authority

To exercise your rights: Email demo-privacy@example.com

Supervisory Authority:
Landesbeauftragte für Datenschutz und Informationsfreiheit NRW
https://www.ldi.nrw.de

9. Cookies

We use cookies and similar technologies:

Cookie TypePurposeConsent Required
EssentialSite functionality, securityNo
PreferencesRemember your settingsNo
AnalyticsUnderstand usage patternsYes
MarketingTargeted advertisingYes

Manage preferences in our cookie banner or browser settings.

10. Security

We implement appropriate technical and organizational measures:

  • HTTPS/TLS encryption
  • Access controls and authentication
  • Regular security assessments
  • Data minimization
  • Employee confidentiality obligations

11. Children's Privacy

Our services are not directed to individuals under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact demo-privacy@example.com.

12. Data Subject Requests

To request access, correction, deletion, restriction, portability, or objection, email demo-privacy@example.com. We may need to verify identity before fulfilling requests.

13. Changes to This Policy

We may update this Privacy Policy. Material changes will be notified via email or website notice. Continued use after changes constitutes acceptance.

14. Contact

For privacy inquiries and GDPR requests:

Email: demo-privacy@example.com