1. Data Controller
The data controller for the personal data collected through dijit.app is:
- Controller: DIJIT LABS OÜ
- Privacy contact email: legal@dijit.app
1.1. Data Protection Officer (DPO)
You may contact the DPO at legal@dijit.app, indicating "Data Protection Officer" in the subject line.
2. Scope and dual role (Controller / Processor)
Dijit.app processes personal data in two different capacities, which should be distinguished:
With respect to the data that Dijit.app collects and decides to process on its own, such as the Client's and its Users' account, contact, billing, and usage data (sign-up, contract management, support, billing, security). These processing activities are governed by this Policy.
With respect to the personal data contained in the documents that the Client uploads and manages through the platform (invoices, delivery notes, accounting documents, and any third-party data they contain). Here, the Client is the Controller and Dijit.app processes such data solely in accordance with its instructions, pursuant to the Data Processing Agreement (DPA).
3. Categories of data and data subjects
Data subjects: representatives and contact persons of the Client, platform Users, and website visitors.
Categories of data processed as Controller
- Identification and contact data: first name, last name, email address, phone number, company, and job title.
- Account and authentication data: credentials, session identifiers, and access logs.
- Tax and billing data: company name, tax ID/VAT number/tax identification, address, and data required for invoicing. Payment processing is carried out by the payment provider; Dijit.app does not store full card details (see section 6).
- Usage data: technical data on Service usage (consumption, logs, metrics) for security, support, and improvement purposes.
The processing of special categories of data (Art. 9 GDPR) is not requested. The Client shall refrain from including such data unless strictly necessary and based on a valid legal basis for which it is responsible.
4. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Sign-up, management, development, and control of the contract and the Service | Performance of a contract (Art. 6(1)(b)) |
| Billing and collection; management of non-payment | Performance of a contract and legal obligation (Art. 6(1)(b) and 6(1)(c)) |
| Compliance with legal obligations (tax, accounting) | Legal obligation (Art. 6(1)(c)) |
| Technical support and Customer service | Performance of a contract (Art. 6(1)(b)) |
| Platform security, fraud prevention, and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Service communications (notices, essential updates) | Performance of a contract (Art. 6(1)(b)) |
| Commercial/promotional communications about our own products | Legitimate interest or consent, as applicable (Art. 6(1)(f) / 6(1)(a)) |
| Handling and evidence of rights requests and claims | Legal obligation and legitimate interest (Art. 6(1)(c) and 6(1)(f)) |
5. Data retention
Data will be retained for as long as necessary for the purpose for which it was collected and, in particular:
- Contract and billing data will be retained for the duration of the relationship and, once it ends, for the applicable statutory tax and commercial limitation periods.
- Once the license ends, the data will be blocked and retained only at the disposal of the competent authorities to address any potential liabilities, and deleted once those periods have elapsed.
- Client Content (for which Dijit.app acts as Processor) is retained and deleted as provided in section 15 of the Terms and in the DPA.
6. Recipients and sub-processors
Dijit.app does not sell or transfer personal data to third parties for commercial purposes. Data is only disclosed:
- To the Public Administration or authorities where there is a legal obligation.
- To service providers (processors/sub-processors) that provide services to Dijit.app under contract and with data protection safeguards:
| Provider | Service | Location |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Ltd.) | Cloud infrastructure, storage, and AI services (Azure AI Foundry) | EU |
The updated list of sub-processors is maintained in Annex II of the Terms.
7. International transfers
Data is stored and processed on servers located in the European Union / European Economic Area, within Dijit.app's Microsoft Azure infrastructure perimeter. The Client authorizes the hosting and processing of its data in that data center for the provision of the Service.
As a general rule, no international transfers outside the EEA are carried out. If, exceptionally, any provider involves processing outside the EEA, the safeguards of Chapter V of the GDPR will apply (adequacy decision or Standard Contractual Clauses).
8. Artificial Intelligence, OCR and automated decisions
- The Service uses OCR and artificial intelligence technologies to read, extract, and classify information from documents. All such processing is carried out using models hosted in Dijit.app's own Azure tenant (Azure AI Foundry), with the data remaining within the Azure perimeter.
- The Client's data is not used to train, retrain, or improve third-party AI models, nor is it shared with external AI providers.
- Dijit.app does not make automated individual decisions that produce legal effects or similarly significantly affect the data subject within the meaning of Art. 22 GDPR, except for those strictly necessary for contract performance. Automatic data extraction is a support tool subject to review by the Client (see section 14 of the Terms).
9. Security measures and breach notification
Dijit.app applies appropriate technical and organizational measures (Art. 32 GDPR) to ensure the confidentiality, integrity, availability, and resilience of systems, including access controls, encryption in transit and at rest, activity logging, and backups.
In the event of a security breach affecting personal data, Dijit.app will act in accordance with Arts. 33 and 34 GDPR, notifying the supervisory authority and, where applicable, the affected individuals or the Client (where the Client is the Controller), without undue delay.
10. Data subject rights
Data subjects may exercise the following rights:
- Access to their personal data.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten").
- Objection to processing.
- Restriction of processing.
- Data portability.
- Withdraw consent given, where applicable, without retroactive effect.
To exercise these rights, simply send a request to legal@dijit.app indicating the right you wish to exercise. Dijit.app will respond within one (1) month, extendable in accordance with the GDPR. Supporting identity documentation will only be requested where there are reasonable doubts about the applicant's identity, and in a proportionate manner (a copy of an identity document is not required by default).
When the request relates to data contained in the Client's documents (for which Dijit.app acts as Processor), Dijit.app will forward the request to the Client as Controller and provide the assistance предусмотрed in the DPA.
11. Complaint to the supervisory authority
If the data subject considers that the processing does not comply with the applicable regulations, they may lodge a complaint with the competent supervisory authority:
- Supervisory authority of the controller (Estonia): Estonian Data Protection Inspectorate — Andmekaitse Inspektsioon (www.aki.ee).
- Local authority of the data subject: additionally, the data subject may lodge a complaint with the authority in their country of residence (e.g., in Spain, the Spanish Data Protection Agency — AEPD, www.aepd.es).
12. Software communications
Dijit.app will keep the Client informed about updates, new features, and essential notices regarding the Service, communications necessary for contract performance. Some communications may be of a commercial or promotional nature regarding our own products; the Client may object to these latter communications at any time, without affecting essential service communications, and in any case after the contract ends.
14. Client responsibility for its data
The Client is responsible for the personal data it enters into and stores in the software, as well as for having a valid legal basis for its processing and for informing the relevant data subjects. Dijit.app accesses such data solely for the performance of the Service and under strict security measures, in accordance with the DPA.
15. Changes to this Policy
Dijit.app may update this Policy to reflect legal, technical, or organizational changes. Material changes will be communicated to the Client by reasonable means (registered email or notice on the platform) within a reasonable period before they take effect. The "last updated" date indicates the current version.
16. Contact
- Controller: DIJIT LABS OÜ
- Privacy and rights requests: legal@dijit.app
- Contracting and billing: central@dijit.app
- Support: soporte@dijit.app
For the Client, communications will be sent to the address provided during contracting.
17. Governing law and jurisdiction
The processing of personal data is governed by Regulation (EU) 2016/679 (GDPR) and other applicable data protection laws, as well as the laws of the Republic of Estonia. For any dispute, the parties submit to the provisions of section 23 of the Terms and Conditions of Use.
Do you have questions about privacy?
For any inquiry related to your personal data or the exercise of your rights, write to our data protection contact.
legal@dijit.app