Who is responsible
digitaplatform.com is operated by simetrix GmbH, Inseli 4, 6415 Arth, Switzerland. simetrix GmbH is responsible for the processing of personal data on this website.
Commercial register of the canton of Schwyz · UID CHE-174.454.280
Managing director: Nuh Mehmet Kartalbas
Email: hello@digitaplatform.com · Phone: +41 78 622 44 55
What this notice covers
This notice covers this website, digitaplatform.com, the contact sheet that you can open on every page, and email that you send to hello@digitaplatform.com.
Customers who sign in to their application on this host receive the sign-in cookies described below. What customers process inside their application is not covered by this notice.
This notice follows the Swiss Federal Act on Data Protection (FADP, revised, in force since 1 September 2023). For visitors in the EU and the EEA it also follows the General Data Protection Regulation (GDPR). Where we name a legal basis, it is the GDPR basis for those visitors.
What we process, why and how long
Server logs. Our servers record for each request the time, the requested page, the result and how long the answer took. We use these records for error analysis and for the operation of the site. Legal basis for visitors in the EU and the EEA: our legitimate interest in a secure and working site (Article 6(1)(f) GDPR). The records are collected in a central log store on a server of simetrix in Switzerland and deleted after 14 days.
Contact requests. When you write to us through the contact sheet or the contact page, we receive your name, email, company, topic and message, and the page and language you wrote from. Name, email and message are required; without them we cannot answer. Company is optional. We use these details to answer your request. Legal basis for visitors in the EU and the EEA: steps at your request before a contract (Article 6(1)(b) GDPR) or, for a general inquiry, our legitimate interest in answering your inquiry (Article 6(1)(f) GDPR). When you send the request, the server keeps the address of your device in its memory for up to one hour to limit the number of requests from one address; it does not store the address with your request. The request is stored in this site's own system in Germany. Where this site is connected to the platform's own mail service, we also receive your request as a notification mail at hello@digitaplatform.com, and the mail service keeps a copy of that mail. Email that you send to hello@digitaplatform.com directly, without the contact sheet, is a contact request too: same purpose, same legal basis, same deletion. The mailbox hello@digitaplatform.com runs on Microsoft 365; Microsoft acts as our processor for it and stores the mail in this mailbox in Switzerland. Microsoft may access the data in the mailbox from the United States for operation and support. This transfer rests on the Data Privacy Framework, under which Microsoft is certified, and on the standard contractual clauses of the European Commission, which are part of Microsoft's data protection addendum. You can get a copy of these clauses from us at hello@digitaplatform.com. We delete the request, the copy at the mail service and the mail in the mailbox when the conversation is over, at the latest after 24 months, unless a contract follows.
Browser storage. This site stores your language choice in a cookie named locale for one year. Legal basis for visitors in the EU and the EEA: our legitimate interest in showing you the site in your language (Article 6(1)(f) GDPR). It stores your display preference, light or dark, and the design you chose, in your browser's storage; this is not a cookie. All of this is functional. None of it is used for tracking. This site uses no analytics, no advertising and no third-party tracker. Nothing on this site needs your consent, so there is no consent banner.
Sign-in cookies for customers. Customers who sign in to their application on this host get three cookies from the sign-in service of the platform, digita-auth; their names start with digita_at, digita_rt and digita_csrf. The first two carry the session and can be read by the server only; the third protects the sign-in against forged requests. They are essential for the sign-in, live for seven days at most and are deleted at sign-out. While you are signed in, the servers record your email address with each request that carries the session, and the sign-in service records it at each sign-in; these records go to the same log store as the server logs and are deleted after 14 days. The sign-in service also keeps four kinds of records in its database. A user record holds your email address, which is also your user name, your name, your roles and access tiers, your language, whether the account is invited or active, whether your email address is verified, whether the account is disabled, a hash of your password, whether two-factor protection is on and, if it is, the time it was switched on, the encrypted secret and the hashed recovery codes, the count of failed sign-in attempts and the time of the last one, the time of your last sign-in, and the times the record was created and last changed; it is kept as long as your account exists and deleted when an administrator deletes the account. A session record holds your email address, the address of your device, the name of your browser, the time it was created, the time the session expires and its status, active or logged out. A security record is written for each sign-in, each failed or blocked sign-in attempt, each step of a two-factor sign-in, each sign-out, each reuse of a spent session token, each password change or reset, each time the two-factor protection is switched on or off, each creation, invitation and deletion of a user account, each accepted or resent invitation, each mail the service sends or fails to send, and each service credential it issues, exchanges or revokes; it holds the kind of event, the time and your email address; the record of a sign-out holds the session's identifier instead, the record of an invitation also holds the email address of the administrator who sent it, and the record of a mail holds the recipient address and the subject; the record of a sign-in, an attempt or a two-factor step also holds the address of your device and the name of your browser. A grant record is written when a service of the platform acts on your behalf, for example to run a scheduled job; it holds your email address as your user name, what was granted, to which service, when, until when, and whether the grant was revoked. The sign-in service deletes a session record when the session expires, a security record 90 days after the event, and a grant record when the grant expires, at the latest 90 days after it was written; revoking a grant does not delete it earlier. Legal basis for visitors in the EU and the EEA: our legitimate interest in running the sign-in that the customer ordered and in keeping it secure (Article 6(1)(f) GDPR); where you are our direct customer, also the contract with you (Article 6(1)(b) GDPR).
Links. This site links to simetrix.ch. Following a link carries no data from this site to the other site.
Who receives data and where it is
This site runs on servers in Germany. simetrix operates them on infrastructure of Hetzner Online GmbH, Gunzenhausen, Germany, which acts as our processor.
The log records of the servers go to a central log store on a server of simetrix in Switzerland, which simetrix operates itself.
Our mailbox hello@digitaplatform.com runs on Microsoft 365. Email that you send us lands there, and, where this site is connected to the platform's own mail service, so does the notification mail for a contact request. Microsoft acts as our processor for that mailbox.
No one else receives your data.
This site's data is stored in these places: The site's own systems, with the contact requests and the records of the sign-in service, and their backups are at Hetzner in Germany; a backup is deleted as a whole, and the oldest kept backup is up to four weeks old, so deleted data can remain in a backup for up to four weeks. The server logs are in the log store on a server of simetrix in Switzerland. The mail in our mailbox is at Microsoft 365 in Switzerland, and Microsoft may access it from the United States for operation and support (the paragraph on contact requests states the basis of the transfer). Switzerland recognizes the member states of the European Union as countries with adequate data protection. For residents of the EU and the EEA, the European Commission recognizes Switzerland as a country with adequate data protection.
Your rights and how to use them
You have the right to access your data, to have it corrected or deleted, to restrict its processing, and to receive a copy of the data you gave us in a portable format. Where processing rests on consent, you may withdraw it at any time; today we ask for no consent on this website. For visitors in the EU and the EEA these rights follow from the GDPR.
You may object to the processing of your data at any time.
To use a right, write to hello@digitaplatform.com.
You may complain to the Federal Data Protection and Information Commissioner (FDPIC) in Bern. Residents of the EU and the EEA may also complain to their own supervisory authority.
No automated decisions
We make no automated decisions about you and we do no profiling.
Children
This site addresses companies, not children.
Changes
We change this notice when the site changes. Last change: 29 September 2026.