Privacy Policy
What we collect, why we collect it, how long we keep it, and what you can ask us to do with it.
Version 2.0 — in force from 11 September 2026.
This policy explains what personal data Digibitig collects, why we collect it, who sees it, how long we keep it, and what you can ask us to do with it. It forms part of the terms of use.
1. Who is responsible
1.1 The operator of digibitig.com is the controller of the personal data described here. Requests, questions and complaints about this policy go through the contact page.
1.2 Where we process data on the instructions of a Member — for example, personal data that a Member chooses to publish in a post — that Member is responsible for having a lawful basis for publishing it, and we act as the host of that publication.
2. What we collect
2.1 Data you give us
- Account details — name, username, e-mail address, and a password stored only as a cryptographic hash, never in readable form.
- Profile information — anything you choose to add: biography, work experience, education, certifications, skills, spoken languages and levels, country and city, avatar, links.
- Content — your posts, comments, images and files, ratings, bookmarks, tags, reports and support messages, including drafts held in your browser.
- Verification data — if you apply for the verified badge: the identity documents and details you submit, stored encrypted and accessible only to the staff carrying out the check.
- Correspondence — messages you send us through the contact form or support tickets, and our replies.
2.2 Data collected automatically
- Technical and security records — IP address, user-agent, browser and device characteristics, language, referring page, the pages and actions requested, and timestamps of registration, sign-in, sign-out, password change, e-mail change, posting, editing, deletion and moderation events.
- Cookies and local storage — see section 8.
- Abuse signals — rate-limit hits, failed sign-in attempts, duplicate-account indicators and similar records used to keep the Platform safe.
2.3 Data from third parties
- Payment confirmations from our payment provider. We receive the fact, amount, time and status of a payment; we never receive or store your card number.
- Delivery and security reports from our e-mail and infrastructure providers (for example, bounce and spam reports).
- Reports and legal notices about you sent by other Members, rights holders or authorities.
3. Why we process it, and on what basis
- To provide the service — creating and running your account, publishing your Content, notifications, search, language preferences. Basis: performance of the contract between you and us.
- To keep the Platform safe and lawful — preventing and investigating spam, fraud, abuse, duplicate accounts, attacks and prohibited Content; enforcing the terms of use; establishing, exercising or defending legal claims. Basis: our legitimate interest in a secure, lawful platform, and compliance with legal obligations.
- To meet legal obligations — responding to lawful requests, retaining records we are required to retain, accounting and tax records. Basis: legal obligation.
- To process verification — checking the identity documents you submit. Basis: performance of the contract you requested, and your explicit consent where the documents contain data requiring it.
- To communicate with you — service messages, security alerts, changes to terms, replies to your requests. Basis: contract and legitimate interest.
- To improve the Platform — aggregated and statistical analysis of how features are used. Basis: legitimate interest. This analysis does not identify you individually.
Technical records exist for security, abuse investigation and legal compliance. We do not build advertising profiles, we do not run advertising networks, and we do not sell personal data to anyone.
4. What is public and what is not
4.1 Public: your username, avatar, the profile fields you choose to complete, your posts and comments, the ratings you give, your badges, and the dates associated with them. Public means readable by anyone, with or without an account, indexed by search engines, and capable of being copied, quoted, cached and archived by third parties beyond our control.
4.2 Not public: your e-mail address, your password hash, your identity documents, your IP address and technical records, your reports and their contents, your support correspondence, and your payment records.
4.3 You decide what goes into your profile and your posts. Personal data that you choose to publish becomes public by your own act, and removing it later does not reach copies already made elsewhere. Please think before publishing anything you may later want back.
5. Who we share it with
5.1 Service providers who process data on our instructions and under a written data-processing agreement, limited to what their function requires: hosting and infrastructure, object storage and content delivery, database and backup services, e-mail delivery, error monitoring and logging, real-time messaging, and payment processing.
5.2 Authorities, courts and legal counsel, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims, to investigate fraud or abuse, or to prevent a risk of serious harm to a person.
5.3 A successor, in the event of a merger, acquisition, reorganisation or sale of assets — in which case this policy continues to apply to the transferred data until it is replaced by a policy giving no less protection, and you will be informed.
5.4 We do not sell, rent or trade personal data, and we do not share it for another party marketing purposes.
6. International transfers
Our providers may process data outside your country. Where that happens, we rely on an adequacy decision where one exists, or on standard contractual clauses together with the technical measures described in section 9. You can ask us through the contact page which safeguards apply to a given transfer.
7. How long we keep it
- Account and profile data — while your account exists, and then deleted or anonymised on closure, subject to the exceptions below.
- Content — while published. After account deletion it may remain in anonymised form, detached from your identity, so that threads other Members contributed to stay readable.
- Technical and security records — for a limited retention period fixed per record type, after which they are removed automatically, unless they are relevant to an ongoing investigation, dispute or legal obligation.
- Moderation and report records — kept as an audit trail for as long as necessary to enforce the terms, to prevent the return of banned accounts, and to defend legal claims.
- Verification data — kept only for as long as the check and any dispute about it require, then deleted.
- Payment and accounting records — kept for the period required by tax and accounting law.
- Records under legal hold — where a lawful request, investigation or claim requires it, retained until that requirement ends, including after account deletion.
8. Cookies and similar technologies
8.1 We use only what the Platform needs to function: a session cookie to keep you signed in, a cross-site request forgery token to protect forms, a cookie recording your language and interface preferences, and local storage holding unsent drafts on your own device.
8.2 We use no advertising cookies, no third-party tracking pixels and no cross-site profiling.
8.3 You can delete cookies or block them in your browser. Blocking the necessary ones will prevent sign-in and posting from working.
9. Security
9.1 Traffic is encrypted in transit. Passwords are stored as salted hashes and are never recoverable in readable form. Verification documents and other sensitive records are encrypted at rest. Access by staff is limited to what the role requires and is logged. Sessions expire, forms are protected against cross-site request forgery, and uploads are validated and re-encoded.
9.2 No system is perfectly secure. Use a strong, unique password, do not reuse it elsewhere, and sign out on shared devices. You are responsible for the security of your own credentials and devices.
9.3 If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, the affected Members, within the periods the applicable law sets.
10. Your rights
10.1 Subject to the conditions and exceptions in applicable law, you may ask us to: give you access to the personal data we hold about you; correct data that is inaccurate or incomplete; delete your data; restrict processing; provide your data in a portable format; object to processing carried out on the basis of legitimate interest; and withdraw a consent you have given, without affecting processing already carried out.
10.2 Send the request through the contact page from the e-mail address registered to the account. We may ask for further information to confirm that the request really comes from you; we will not act on a request we cannot verify, because doing so would itself be a data breach.
10.3 We answer within the period required by applicable law. Requests that are manifestly unfounded, repetitive or excessive may attract a reasonable fee or be refused, with reasons.
10.4 Some rights are limited: we may keep data that we are required to retain, that is necessary to establish, exercise or defend legal claims, or that is needed to prevent a banned Member from returning. Deleting your account does not delete Content that other Members have quoted, nor copies made by third parties.
10.5 You may lodge a complaint with the competent data protection supervisory authority in your country. We would appreciate the chance to resolve the matter first.
11. Deleting your account
11.1 You can delete your account at any time from your account settings. Deletion is permanent and cannot be undone.
11.2 Your personal data is removed rather than hidden. Content you posted may remain on the Platform in anonymised form, as explained in section 7, so that discussions other Members contributed to remain usable.
11.3 Records that we are required to keep, or that are necessary to defend legal claims or to enforce the terms of use, are retained for the applicable period and then deleted.
12. Automated processing
We use automated checks for spam, blocked keywords, rate limits and duplicate accounts. These may temporarily restrict posting or flag Content for review. They do not produce legal effects that significantly affect you without the possibility of human review — if an automated measure affects your account, you may ask for a human to look at it through the contact page.
13. Children
The Platform is not intended for children under 13. We do not knowingly collect data from them. If we learn that an account belongs to a child under 13, we close it and delete the data. A parent or guardian who believes a child has registered should contact us.
14. Changes to this policy
We may update this policy. The version in force is the one published on this page with its effective date. Material changes are announced on the Platform. Continuing to use the Platform after a change means you accept the updated policy.
15. Contact
Data requests, questions and complaints go through the contact page. Please use the e-mail address registered to your account so that we can identify you.