Legal
Privacy Policy
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
1. Controller
DigitAI Solutions LLC
7901 4TH ST N STE 300
ST. PETERSBURG, FL 33702, USA
Email: chris@digit-aisolutions.com
2. Hosting and server log files
This website is hosted by ALL-INKL.COM — Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. The servers are located in Germany. When you access our pages, the host automatically collects access data in server log files: the page requested, date and time, volume of data transferred, browser type and operating system, referrer URL and IP address. This data serves the secure and stable operation of the website and is not evaluated for marketing in this context. According to the host, log files are deleted after no more than seven days; longer retention may be necessary in an individual security incident. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, technically stable operation). A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider.
3. Contacting us
We process data that you share with us (e.g. by email or WhatsApp) to answer your enquiry, clarify questions and, where relevant, prepare a proposal or contract. The service providers used for hosting, email, communication and our own CRM may receive the data technically required for those purposes; we do not use it for unsolicited marketing. The legal basis is Art. 6(1)(b) GDPR for pre-contractual or contractual enquiries, otherwise Art. 6(1)(f) GDPR (legitimate interest in appropriate communication and documentation).
Applications: If you apply for an advertised role, we process the information you voluntarily provide solely to assess your application, communicate with you and decide on a possible collaboration. Please do not initially send identity documents, bank details, health information or other particularly sensitive data. We only request such information if it becomes necessary after a specific agreement. If no collaboration results, we generally delete application data no later than six months after the process ends, unless a legal obligation, the establishment or defence of legal claims, or your explicit consent to longer consideration requires otherwise.
Our pages contain references to WhatsApp. These are plain links — a connection to WhatsApp is only established once you click them. The operator is WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland. We have no influence over how WhatsApp processes your data; their privacy terms apply. If you prefer not to use it, please contact us by email.
4. Cookies & analytics
This website may use cookies and analytics tools to make our services more user-friendly, effective and secure. Cookies do not harm your computer and do not contain viruses.
We use Google Analytics 4, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses cookies and similar technologies to evaluate how this website is used — for example pages viewed, time on site, approximate location and device used. This information is generally transmitted to and stored on a Google server, which may involve a transfer to the USA. According to Google, the IP address is used at collection time to derive approximate location information and is discarded before it is logged or stored in Analytics. The purpose of this processing is to design and continuously improve our services in line with actual demand.
Google Analytics is only loaded after your explicit consent. As long as you have not consented, no Google script is loaded and no data is transmitted to Google. The legal basis is your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw this consent at any time with effect for the future: change cookie settings.
We have disabled advertising signals and personalised advertising functions in our integration and limit the lifetime of the analytics identifier we set to no more than 90 days. Event and report data stored by Google is additionally governed by the service configuration and retention rules.
In addition, you can prevent collection by Google Analytics by installing the browser add-on provided by Google: tools.google.com/dlpage/gaoptout, or by blocking and deleting cookies in your browser settings. For more information on how Google handles user data, see Google's privacy policy.
5. AI project scoper and growth scan
On the scoper page you can describe your project. This input is transmitted to OpenRouter (OpenRouter, Inc., USA) and an available model provider for the selected model to generate a non-binding estimate. Our API request technically requires an endpoint marked “Zero Data Retention” and excludes providers that collect inputs for training; if no suitable endpoint is available, the request fails. Provider information can change. Please therefore do not enter special-category personal data, secrets or third-party data. More information: OpenRouter privacy. The legal basis is Art. 6(1)(b) GDPR (pre-contractual action at your request).
In the results of the scoper and growth scan you may optionally provide your email address and phone number to have the evaluation sent to you. These fields are voluntary — you can see the evaluation without them. If you provide them, we send you the result and store your details with the evaluation in our password-protected CRM to handle your enquiry. The CRM, hosting and infrastructure providers used for this purpose receive the data technically required; this processing is separate from the public-website hosting described above. AI may prioritise the item internally against fixed criteria and prepare a draft response. This does not produce a solely automated decision with legal or similarly significant effect; a person reviews the item and decides on further communication. The legal basis for sending the result is your consent under Art. 6(1)(a) GDPR and, for further handling where applicable, Art. 6(1)(b) GDPR.
6. Payment processing
For payments we use Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; for payments to us as a US company, Stripe, Inc., USA may apply). After a proposal has been accepted, our CRM may provide you with an external payment link operated by Stripe. You enter full card details exclusively with Stripe; for contract administration and accounting we receive necessary customer, invoice, payment-status and transaction data, but not the full card number. The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR for records subject to retention duties. Stripe's privacy terms apply in addition.
7. Personality test (personality profile)
On a separate page — reachable from our careers pages, but not part of the navigation and not released to search engines — we offer a free, science-based personality test (four parts — interests, work values, personality, character strengths — with 272 self-description statements in total and up to 16 follow-up questions on individual strengths). Your answers are evaluated on our server exclusively in a rule-based, deterministic way — without the use of AI — and sent to the email address you provide as a personal evaluation.
Evaluation (required consent): Because self-descriptions concerning mood and resilience may allow inferences about your well-being, we process your test answers only with your explicit consent (Art. 9(2)(a), Art. 6(1)(a) GDPR). Individual answers are processed only in server memory while the evaluation is calculated and are then discarded. They are neither stored nor shown in the candidate area or internal emails. Without the additional consent described below, we do not store your email address — it is used solely to send the evaluation. What remains permanently are the scores of your finished evaluation, as frequency counts: each score from the four test parts is assigned to one of eleven classes and merely counted there, kept apart by language, age band and gender. Alongside that we keep details about the run (month, parts completed, time taken in five-minute classes, technical quality indicators). The purpose is to build our own comparison values and to see which questions and which test parts measure usefully. Name, email address and IP address do not enter these counts, and no row holding your scores together is created. We nevertheless do not call this data anonymous: a profile made of many scores is distinctive enough that, within a small group, it could be attributed to a single person. The scores are therefore kept apart from your name and used internally only. An individual contribution, however, cannot be located and therefore cannot be deleted individually: the counts carry no identifier of any kind, so there is nothing by which we could recognise yours. That is the flip side of exactly the separation that protects you (cf. Art. 11 GDPR). We say so plainly here so that you know it before you submit — your consent to the evaluation covers this counting. Everything tied to your name we of course delete on an informal email to chris@digit-aisolutions.com. The legal basis for this internal analysis is the consent described above.
Talent scouting (voluntary, separate consent): At the end of the test you can consent, via a separate, unticked checkbox, to us additionally analysing your test results to create an internal aptitude profile (strengths/weaknesses, role fit) and contacting you by email about suitable job and project opportunities. This consent only takes effect once you confirm it via a confirmation link sent by email (double opt-in); unconfirmed data is deleted after 30 days at the latest. The aptitude profile is created in a rule-based way; any decision about contacting you or working together is always made by a human — no exclusively automated decision-making takes place. Confirmed profiles are stored for 12 months in our password-protected system on the server named above in Germany and transferred to our internal CRM. You can withdraw this consent at any time informally by email to chris@digit-aisolutions.com; we will then delete your profile without delay. Legal bases: Art. 6(1)(a), Art. 9(2)(a) GDPR; email outreach only takes place with this consent (Section 7(2) no. 2 of the German Act against Unfair Competition, UWG).
Feedback on individual questions (voluntary): Every statement carries a question mark that opens an explanation. Inside it you will find an optional text field for telling us when a question is unclear or ambiguously worded. This feedback does not replace your answer; it serves solely to improve how understandable the questions are, and it is not analysed by AI. We store only the month, the test language, the question concerned and your text — no name, no email address, no IP address, no session identifier and no more precise timestamp. The order of entries is reshuffled on every write, so that position reveals nothing about the order in which submissions arrived. Because this is a free text field, the note beside it expressly asks you not to enter anything personal there. The legal basis is your consent (Art. 6(1)(a) GDPR), given by filling in the field; an empty field is not transmitted.
Abuse protection: To fend off automated submissions, we limit the number of submissions per internet connection (short-term storage of the IP address in hashed form, Art. 6(1)(f) GDPR) and keep a technical log without plain-text email addresses.
8. Retention
Server log files are generally deleted after no more than seven days unless a security incident requires longer preservation. Technical lead-form recovery files are removed after successful hand-off; orphaned recovery files are scheduled for cleanup after seven days. If no contract results, we review enquiry and CRM data after communication ends and regularly delete it no later than 12 months after the last substantive contact, unless a legal claim, objection or evidence requirement justifies longer retention. If a contract or accounting transaction results, statutory commercial and tax retention periods apply and processing is restricted to those purposes. The frequency counts from the personality test (section 7) are kept without a fixed period: their purpose is to build our own comparison values, and a comparison value becomes more dependable over the years rather than less — a deletion period would destroy it at regular intervals. Because these counts contain no name, no email address and no IP address, and form no row in which one person’s scores stand together, the intrusion remains slight; we nevertheless do not call them anonymous (see section 7). An individual contribution cannot be located in them and therefore cannot be deleted individually (see section 7). Feedback on individual questions is likewise kept without a fixed period, for as long as the question concerned remains in the test; it carries no identifier of any kind and cannot be attributed to a person. Browser analytics identifiers are limited by us to no more than 90 days; where technically reachable, withdrawal through cookie settings deletes them earlier.
9. Your rights
You have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of processing (Art. 15 GDPR), as well as the right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may withdraw any consent given at any time with effect for the future. You also have the right to object to processing based on legitimate interests (Art. 21 GDPR). For this and any further questions about personal data, you can contact us at any time at the address given above.
Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). You may contact the authority in your place of habitual residence or place of work.
10. Encryption
This website uses SSL/TLS encryption throughout. You can recognise this by the address bar of your browser (https). Encryption protects the transport route against simple interception; the recipients and systems named in this policy still process data for their respective purposes.