Privacy Policy
Digidely Sàrl — Website, Business Relations, and Digital Services
Last updated: September 27, 2026
1 Who is responsible for your data?
Digidely Sàrl, Rue du Pont 26, 1820 Montreux, Switzerland, IDE CHE-421.516.949, is responsible for the data processing described in this policy. You can contact us at contact@digidely.com or at our mailing address, with the subject line “Data Protection.”
This policy applies to visitors to digidely.com, individuals who contact us, and representatives of our clients, prospects, suppliers and partners. It also applies to individuals whose data is included in the supporting documents required to verify our remuneration, as described below. It explains what data we process, for what purpose, to whom it may be disclosed, and how to exercise your rights.
Where we process data on behalf of a client, including in that client’s campaigns, content, website, software or automations, that client remains responsible for the processing for which it determines the purposes and essential means. We act on its instructions and under the applicable data processing agreement. Its own privacy information therefore supplements this policy. Where we determine an independent purpose, for example when calculating variable remuneration owed to us, we are responsible for the relevant processing to that extent. Access granted for a technical assignment does not automatically permit reuse of the data for that separate purpose.
2 What data do we process?
When you visit the site, our servers may record the information required to provide and secure it: IP address, date and time, requested pages, browser and device information, errors and security events.
If you use our contact form, we receive your first name, last name, email address, the subject and content of your message. During our exchanges, we may also receive your telephone number, company, role, availability and the documents you send us for your project.
To prepare a proposal, deliver services or manage a payment, we process professional and billing contact details, project information, communications, contracts, amounts, due dates and payment statuses.
To conclude, manage and sign contracts, we process the relevant documents, the signatories’ names, roles and contact details, their authority to represent the parties and evidence of acceptance. The process may generate transaction identifiers, dates and times, authentication information and technical logs. Depending on the signature level selected, the identity-verification provider may collect an identity document directly, together with the information needed to verify it. Such documents are not requested through our general form and are not systematically provided to Digidely.
Where remuneration depends on results or payments received, we use the records and supporting documents required to calculate it: periods, amounts, currencies, refunds and reconciliation references. This data comes from the client or from tools to which the client gives us authorized access. We favor aggregated data and read-only access; individual data is reviewed only where necessary for verification. Full payment-card numbers are not required for this calculation.
This data comes primarily from you or from the people who manage your company’s relationship with us. Professional information may also come from a referral or public registers, in particular to verify a company’s identity and the authority of its representatives. Where required by law, we will inform you of this indirect collection within the applicable time limit.
Fields marked as required are necessary to process the relevant request; other information is optional. Without certain information, we may be unable to respond to you or provide the requested service. Avoid sending passwords, identity documents or sensitive data through the general contact form. An appropriate channel will be agreed where such data is needed.
3 Why do we use this data?
We use the data required to respond to your requests, arrange our communications and meetings, prepare proposals, deliver and monitor services, provide support and manage our professional relationship.
Remuneration records are used for calculation, verification, invoicing and the handling of discrepancies. They are not reused to solicit our clients’ customers. Where individuals are identifiable, the required privacy information is provided in accordance with the law, including where the data was obtained indirectly.
We also process the information needed for invoicing, accounting, compliance with legal obligations, preservation of evidence of agreements, and the establishment, exercise or defense of legal claims. Technical data is used to operate the site, resolve errors and prevent unauthorized access and abuse.
We do not sell your personal data. A contact request does not automatically subscribe you to a newsletter. If we send you marketing communications, we comply with the applicable legal requirements and provide a simple, free way to object. Messages needed to manage a contract remain distinct from marketing.
We apply the principles of the Swiss Federal Act on Data Protection, including transparency, proportionality, purpose limitation and security. We obtain consent where it is required; this policy provides information and does not, by itself, constitute your consent.
Where the GDPR applies, pre-contractual steps requested by you and the performance of a contract with you are based on Article 6(1)(b). Site security, the management of relationships with company representatives, proportionate verification of remuneration owed to us and the defense of legal claims are based on our legitimate interests, balanced against your rights, under Article 6(1)(f). Article 6(1)(c) applies to legal obligations within the GDPR framework, and Article 6(1)(a) to processing requiring your consent. An obligation arising solely under Swiss law is not automatically treated as an obligation under Article 6(1)(c).
4 Website, cookies and external links
The website uses WordPress together with presentation and form components. Data entered in the form is sent to us so that we can respond to your request. Browsing the website does not require the creation of an account.
Cookies and similar technologies may be used for the website’s technical functions, security and the storage of your preferences. Login or administration cookies concern people who use those functions. A session cookie ends when the session is closed; a preference stored in the browser remains until it expires or is deleted. Details of the technologies actually used and their retention periods are set out in our Cookie Policy.
In this version of the website, we do not enable external analytics or advertising tracking. If such features are added, we will update this information and obtain the necessary choices before they are activated. You may also manage or delete data stored on your device through your browser settings; doing so may affect certain preferences or technical functions.
Appointments are arranged by contacting us. Links to social networks, maps or other websites lead to services operated by third parties. When you open these links, the relevant services process data under their own rules. Their processing is not covered solely by this policy.
5 Who may receive your data?
Access is limited to authorized persons at Digidely and to service providers who need it for their assignment. We use hosting, email and business-management services. Their obligations are defined according to their role, particularly where they process data on our behalf.
Infomaniak Network SA, Switzerland, provides our hosting, email and storage services. Website data, messages and files entrusted to these services are hosted in Switzerland. The provider’s information is available in its Privacy Policy.
AbaNinja, provided by DeepCloud SA, Switzerland, is used for business management and invoicing. We record the contact details needed for the relationship, proposals, invoices and payment monitoring. Application data is hosted in Switzerland. This statement concerns hosting; it does not mean that every additional feature of a provider involves processing exclusively in Switzerland. AbaNinja’s terms and information are available on its official website.
We may disclose strictly necessary information to our professional advisers, institutions involved in payments you make, and authorities or courts where justified by a legal obligation or the defense of a legal claim. Payment data depends on the method used and the relevant institution; we do not ask for payment-card data through our general form.
Swisscom Sign, provided by Swisscom (Switzerland) Ltd in Switzerland, is our electronic-signature provider. When we initiate a process, we send it the documents to be signed and the contact details needed for invitations, authentication and evidence of signatures. The parties responsible for identification, certification and timestamping are presented in the signing process; they may act under their own responsibility for the legal obligations attached to those services. Processing of our contract file and processing needed for the signatory’s account or personal identification must be distinguished. Service information is available on the official Swisscom Sign page and in the privacy notices presented before identification and signing.
Providers and tools specific to an assignment are identified in the relevant file and the privacy information for the service concerned before they are used. Their involvement in a client assignment does not mean that they collect data on digidely.com. Where a provider is involved in processing for which we are responsible, we provide the necessary information about its role and the countries concerned.
6 International data processing
The hosting described in Section 5 is located in Switzerland. If a service, additional feature or support access involves communicating your data abroad, we will specify in advance, in the relevant information, the destination countries and, where necessary, the applicable safeguards or exceptions. That information supplements this policy for the relevant processing.
A transfer to a country that does not benefit from a level of protection recognized as adequate by Switzerland requires a mechanism permitted by the FADP, such as recognized standard contractual clauses adapted to Swiss law and supplemented by the necessary measures. A legal exception may be used only where its conditions are met. For recipients in the United States, an adequacy decision linked to the Swiss–U.S. framework may be relied on only where the recipient and processing are actually covered.
You may ask us for information about transfers concerning you and the applicable safeguards, as well as a copy of those safeguards where possible, while protecting confidential information and third-party data.
7 How long do we keep data?
Requests that do not lead to a contractual relationship are kept for the time needed to respond and conclude the exchanges directly related to the request. Additional retention requires a specific reason, for example follow-up requested by you or evidence needed for a dispute; data is not kept indefinitely merely because you might become a client.
Data relating to the client relationship is kept for its duration. At its end, we retain only what remains necessary to comply with a legal obligation or preserve evidence of legal rights for the applicable periods. Accounting books and records subject to Swiss law are retained for ten years from the end of the relevant financial year. This period does not automatically apply to all project data.
Technical logs are kept for the period useful for diagnostics, security and incident detection, then deleted or anonymized. Information needed to analyze an identified incident or dispute may be isolated and retained until its resolution and the expiry of the relevant obligations or time limits. Data that is no longer useful is not kept in logs for marketing purposes.
We retain contracts signed on paper or electronically and the necessary evidence throughout the contractual relationship, then in accordance with retention obligations and the relevant periods for asserting or defending legal rights. The temporary availability of a file with the signature provider does not replace this archiving. Identification data processed by the provider under its own responsibility follows the statutory periods and that provider’s information; it is not limited to the availability period of the signed document.
Privacy choices and evidence of consent are kept for the period needed to apply and document them. Where you object to marketing, a minimum amount of information may be kept on a suppression list to respect your choice on an ongoing basis.
Backups are deleted according to the rotation cycle of the relevant service. Access to them is limited to backup and restoration needs; after a restoration, deletion and objection requests remain applicable. Data processed for a client is returned or deleted in accordance with the data processing agreement and applicable legal obligations. For variable remuneration, verification access lasts only for the period contractually and legally necessary. After that period, access is revoked and only records needed for settlement, accounting retention or a dispute are retained; detailed subscriber data is not retained merely because invoices must be kept.
8 How do we protect your data?
We implement technical and organizational measures appropriate to the data and the risks, including access restrictions, protection of accounts and communications, system maintenance and incident management. We limit the information shared with our personnel and service providers to what is necessary and impose appropriate confidentiality and data-protection obligations.
Security cannot be guaranteed absolutely. This does not reduce our legal obligations. When a data breach occurs, we assess its consequences and make the required notifications and disclosures. If it concerns data processed for a client, we inform that client as soon as possible.
9 What are your rights?
Subject to the conditions of applicable law, you may ask whether we process your data, obtain the related information, have inaccurate data corrected, request erasure or object to processing. You may withdraw your consent for the future without affecting the lawfulness of prior processing. Rights to receive or transfer data apply where the legal conditions are met.
Where the GDPR applies, you also have the rights it provides, including restriction of processing and data portability, subject to their conditions. You may object to direct marketing at any time and without giving reasons. For processing based on legitimate interests, you may object on grounds relating to your particular situation.
Send your request to contact@digidely.com. We may ask for the proportionate information needed to verify your identity. Access is generally free of charge and normally answered within 30 days under the FADP. If additional time or a restriction is necessary, we will explain the reasons in accordance with the law. Different deadlines apply to processing subject to the GDPR.
Some rights may be limited, in particular by a legal retention obligation, the defense of a legal claim or the rights of other people. We assess each request on its circumstances. If it concerns data that we process solely for a client, we forward the request to the relevant controller and provide the necessary assistance.
You may contact the Federal Data Protection and Information Commissioner and exercise the available legal remedies. Where the GDPR applies, you may also lodge a complaint with the competent supervisory authority, including the authority in your habitual residence, place of work or place of the alleged infringement.
10 Assistance tools and automation projects
Some projects may involve artificial intelligence assistance or automations. Before any processing of personal data for that purpose, the project-specific information and documents will specify the uses, tools, data concerned, recipients, countries and applicable safeguards.
Browsing the site or sending a message does not authorize us to use your data to train a general model. We limit data used to the needs of the project and comply with the agreed instructions and restrictions. Any other reuse requires a separate framework and, where required by law, valid consent.
In connection with this website and the routine handling of your requests, we do not make decisions based solely on automated processing that produce legal effects or otherwise significantly affect you. If a separate service provides for such processing, specific information will explain how it works, its consequences and the applicable rights, including the possibility to express your view and obtain human review where required by law.
11 Updates to this policy
We update this policy when our processing activities or applicable requirements change. The published version shows its date. A new purpose or service requiring specific information is explained before it is implemented. Publishing a new policy does not replace consent where consent is required.
