Privacy Notice
Transparent information about what personal data DigiXRAY Labs processes, for what purposes, on what legal basis, and for how long.
1. Data Controller
55122 Mainz
Germany
This privacy notice applies to the processing of personal data on the digixray-labs.com domain, its forms, customer service interfaces, and the related digital systems of DigiXRAY Labs.
2. Principles and Data Sources
DigiXRAY Labs processes personal data lawfully, fairly, transparently, for specific purposes, and in accordance with the principle of data minimization. Data may be obtained directly from the data subject, through the technical use of the website, from customer or support interactions, or—with consent—from analytics or advertising providers.
We do not sell personal data. We do not ask for special categories of data, credit card information, passwords, or other sensitive information on our general contact, support, and AI platforms.
3. Data Processing in Detail
| Data Processing | Data Processed and Purpose | Legal Basis | Preservation |
|---|---|---|---|
| Website, Server Logs, and Security | IP address, date and time, requested URL, HTTP status, referring page, browser and device information, security events. Purpose: page loading, troubleshooting, and prevention of attacks and abuse. | GDPR Article 6(1)(f): legitimate interest in a secure and functional web service; for access to end devices, TDDDG Section 25(2), if strictly necessary. | For as long as necessary for technical and security purposes; in the event of an incident, until the investigation and enforcement of legal remedies are completed. |
| Contact Us, Request a Quote, and Project Needs Assessment | Name, email address, phone number, website URL, business and project details, message, attachments, and the form’s technical metadata. Purpose: to respond to your inquiry, assess your needs, and prepare a proposal and contract. | Article 6(1)(b) of the GDPR, if a pre-contractual measure is taken at the request of the data subject; otherwise, Article 6(1)(f) of the GDPR, legitimate interest in handling inquiries. | Until the matter is resolved; in the case of a contract, until the end of the contractual and statutory retention period; in the case of a legal claim, until the statute of limitations expires. |
| Customer, Project, and CRM Records | Contact information, project ID, status, tasks, communication history, consent status, and internal notes. Purpose: project management, customer relations, quality assurance, and business administration. | Article 6(1)(b), (c), and (f) of the GDPR, depending on the specific data and purpose. | In accordance with the term of the contract and the follow-up period, as well as the applicable deadlines for accounting, tax, or claims enforcement. |
| Email and Phone | Contact information, message content, sender/recipient, date and time, technical delivery data. Purpose: communication, administrative matters, and verifiability. | Article 6(1)(b) or (f) of the GDPR; for compliance documentation, Article 6(1)(c). | Until the matter is resolved, and thereafter as required by law or to enforce claims. |
| Customer Service Portal and SupportCandy Ticket | Account and contact information, ticket subject, messages, attachments, status, priority, and agent activity. Purpose: to manage and document support requests. | Article 6(1)(b) and (f) of the GDPR. | Until the grant matter is closed, and for the period necessary to address any contractual or legal claims. |
| Newsletter and Professional Information | Name, email address, subscription and unsubscription dates, proof of consent, delivery data, and—if permitted—open/click data. Purpose: to send requested professional content. | Article 6(1)(a) of the GDPR: voluntary consent. With regard to proving consent and preventing abuse, see Article 6(1)(f) of the GDPR. | Until unsubscription; proof of consent may be retained on a limited basis until the end of the claim period. |
| AI chatbot and AI-powered processing | Text entered by the user, conversational context, technical identifiers, and data required to generate a response. Purpose: to provide a response requested by the user, pre-screening, summarization, or task support. | Article 6(1)(b), (f), or (a) of the GDPR, depending on the purpose and at the initiative of the data subject. | For the time required to perform the function and carry out administrative tasks; a quality assurance log may be maintained only if there is a documented need and an appropriate legal basis. |
| Analytics and UX Measurement | Online identifiers, IP and device data, page views, clicks, scrolling, session and usage events; for example, Microsoft Clarity or Google Analytics, if actually configured. | Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG: prior consent. | Until consent is withdrawn or until the end of the documented and configured retention period for the service in question. |
| Marketing and Conversion Tracking | Online identifiers, campaign sources, conversion events, device and browser data; for example, Google Ads, Meta Pixel, or Microsoft UET, if configured. | Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG: prior consent. | Until the consent is withdrawn or until the end of the service provider's retention period. |
| Browser Notification | Push subscription ID, browser and device data, notification interactions. Purpose: to send notifications requested by the data subject. | Article 6(1)(a) of the GDPR, as well as separate consent from the browser. | Until revoked or the subscription is terminated. |
| Translation and Display Preferences | Selected language and related technical preference. Purpose: to display the requested language version. | Article 6(1)(f) of the GDPR, or consent in the case of prolonged, unnecessary storage. | Until the end of the session or until the documented lifetime of the selection expires. |
AI and Form Security: Please do not provide passwords, credit card information, health information, government-issued identification, or other particularly sensitive information unless DigiXRAY Labs specifically requests it as part of a specific, secure, and lawful process.
4. Automated Decision-Making
We do not use any fully automated decision-making or profiling on this website that would have legal effects or similarly significant consequences for the data subject. Any AI-generated outline, summary, or preliminary screening does not constitute an independent, final business decision.
5. Data Processors and Recipients
Depending on the specific function and configuration, the following categories of service providers, in particular, may be involved in data processing:
- HOSTINGER Operations, UAB – hosting, infrastructure, and server logs;
- WordPress, Elementor, and related plugins – content management and form functionality;
- Fluent Forms, FluentCRM, and FluentSMTP – forms, contact records, project and email workflows;
- SupportCandy – customer service tickets and responses;
- Cloudflare Turnstile and Security Services – bot and abuse prevention, if active on that platform;
- Microsoft – Clarity and UET/Bing, provided that the appropriate consent and configuration requirements are met;
- Google and Meta – analytics, conversion tracking, or advertising, if actually configured and enabled;
- OpenAI or another AI provider – only to the extent necessary for the activated, specifically designated AI function;
- Gravitec – browser notifications, if the data subject subscribes;
- the email provider that is actually configured – delivery of messages.
We engage service providers as data processors or independent data controllers, depending on their specific legal role. We restrict access by data processors through contractual and technical safeguards.
6. Data Transfers to Third Countries
Some technology service providers may process data outside the European Economic Area. Transfers may only take place under the conditions set forth in Chapter V of the GDPR, such as an adequacy decision, the EU–U.S. Data Privacy Framework, general terms and conditions, supplementary measures, or other appropriate safeguards. The specific safeguard depends on the service provider used and its current legal status.
7. Retention and Deletion
We process the data for as long as necessary to achieve the purpose. After that, we delete or anonymize it, unless further limited storage is justified by a statutory retention obligation, an ongoing contract, a complaint, a security incident, or a legal claim. The main factors in determining the retention period are: the purpose of processing, the contractual relationship, mandatory accounting and tax deadlines, the statute of limitations, the status of consent, and technical security requirements.
8. The Data Subject's Rights
Subject to the applicable conditions, the data subject is entitled to:
- request access to and a copy of your personal data;
- request the correction of inaccurate data or the completion of incomplete data;
- request erasure or restriction of data processing;
- to object to data processing based on legitimate interests;
- to revoke this consent at any time in the future;
- to request data portability, if the conditions for it are met;
- file a complaint with the data protection supervisory authority.
The application was submitted by the hello@digixray-labs.com It must be sent to this address. DigiXRAY Labs will respond without undue delay, generally within one month. It will verify your identity only to the extent necessary to prevent unauthorized access.
9. Right to File a Complaint
The data subject may contact the data protection authority responsible for his or her usual place of residence, place of work, or the location of the alleged violation. The authority with jurisdiction based on the data controller’s registered office is:
The State Commissioner for Data Protection and Freedom of Information in Rhineland-Palatinate
34 Hintere Bleiche
55116 Mainz, Germany
Phone: +49 6131 8920-0
Email: poststelle@datenschutz.rlp.de
10. Data Security
DigiXRAY Labs implements technical and organizational measures commensurate with the risk, including access restrictions, logging, security safeguards, and update and incident management processes. Absolute security cannot be guaranteed for data transmitted over the Internet; therefore, confidential data should only be transmitted via a designated secure channel.
11. Cookies and Technologies
The detailed rules governing technologies related to terminal equipment are set forth in the Cookie information includes. Analytical and marketing technologies that are not strictly necessary can only be enabled with appropriate prior consent.
12. Amendment
This notice is updated whenever there are changes to our services, data streams, or applicable laws. We will clearly highlight any material changes if doing so is necessary for data subjects to reasonably exercise their rights.
Effective and last updated: August 10, 2026.