Privacy Policy

At DigMedix, we protect your personal privacy and always strive to ensure a high level of data protection. This privacy policy explains how we collect and use your personal data. It also describes your rights and how you can act on them.

It is important that you understand the privacy policy and feel secure with our processing of your personal data. You are always welcome to contact us if you have any questions

What is personal data and what is processing of personal data?

Personal data is all kinds of information that can be directly or indirectly associated to a physical living person. For example, images and sound recordings that are processed in a computer can be personal data even if no names are mentioned. Encrypted data and different types of electronic identities (such as IP numbers) are personal data if they can be linked to physical people.

Processing of personal data is everything that occurs in terms of handling personal data. Any action performed with personal data counts as a form of processing, regardless of whether it is automated or not. Examples of common processing are collection, registration, organising, structuring, storing, revising, transfer and deletion.

What personal data do we collect about you as a customer and for what purpose (why)?

Purpose: In order to process service issues, in order to implement and manage participation in competitions and/or events, in order to evaluate, develop and improve our services, products and systems for customers and users, in order to prevent abuse of a service or to prevent, avoid and investigate crimes against the company.

Processing performed by retailers using the data: Communication and answering any questions via phone or via digital channels, including social media. Identification. Investigating any complaints and support cases (including technical support). Communication before and after participation in a contest or event (e.g. confirmation of notifications, questions or evaluations). Identification and age check. The choice of winner and award of any prize(s) (e.g. payouts or travel vouchers).Adaptation of services to be more user-friendly (e.g. change the user interface to simplify the flow of information or to highlight features commonly used by customers in our digital channels). Analyses of data in order to improve features and tools. Analyses of data to develop, broaden and change product categories and product data to make the service more relevant to users and customers. Analyses of data in order to develop and improve our resource efficiency from an environmental and sustainability perspective (e.g. by informing about efficient resource utilisation per category, environmentally-friendly products and more efficient deliveries). Analyses of data in order to prioritise and plan the choice of retailers on the site. Analyses of data to enable our users and customers to influence the appearance and contents of our services. Analyses of data to improve IT systems in order to improve performance or enhance security for DigMedix, its users and customers. Based on the data we collect (e.g. clicks to retailers, age and gender) you can be sorted into a user group, upon which analyses are then performed on an aggregate level using non-identifiable or pseudonymised data without any link to you as an individual. The insights from the analyses form the basis for which products, product categories, and the design of tools for which users and customers have access to. Prevention and investigation of possible fraud or other crimes (e.g. clicks to retailer manipulation). Prevention of spam, phishing, unauthorised retrieval of price or product data from our services, harassment, unauthorised login to user accounts, or other actions prohibited by law or by our membership, service or customer agreement. Protecting and improving our IT environment against attacks and intrusions.

Categories of personal data: Name. Contact details (e.g. address, e-mail and phone number). Age. Gender. City. Correspondence and feedback regarding our services and products. Purchase and user-generated data (e.g. clicks and visit history). Technical data pertaining to devices used and their settings (e.g. language setting, IP address, browser settings, time zone, operating system, screen resolution and platform). Information about how you interacted with us, in other words how you used the service, login method, where and how long different pages were visited, response times, download errors, how you access and leave the service, etc.

Legal basis: Legitimate interest. The processing is necessary to meet our and your legitimate interest in processing your participation in competitions and/or events.

Storage period: From the time of collection and for a period of 36 months thereafter.

Where do we process your personal data?

We always strive to ensure that your personal data is processed within the EU/EEA and that all of our own IT systems are located within the EU/EEA. However, upon systematic support and maintenance, we may have to transfer the data to a country outside the EU/EEA. If we share your personal data with a personal data counsel who - either on their own or through a subcontractor - is established or stores data in a country outside the EU/EEA, in these cases the counsel may only share the data relevant to the purpose (e.g. log files).

Regardless of the country in which your personal data is processed, we take all reasonable legal, technical and organisational measures to ensure that the level of protection is the same as within the EU/EEA. In cases where personal data is processed outside of the EU/EEA, the level of protection is guaranteed either by a decision by the EU Commission that the country concerned ensures an adequate level of protection or by the use of so-called appropriate safeguards. Examples of appropriate safeguards are approved codes of conduct in the recipient country, standard contract clauses, binding company internal rules or Privacy Shield.

If you want a copy of the safeguards that have been taken or information about where these have been made available, please contact us at

What rights do you have as someone who is a registered member?

  • We are always open and transparent about how we process your personal data and if you want to gain a deeper insight into the personal data we are processing, you may request access to the data (the data is provided in the form of a register extract indicating purpose, categories of personal data, categories of recipients, storage periods, information about where the information has been collected and the existence of any automated decision-making). Please note that if we receive a request for access, we may ask for additional information to ensure the effective handling of your request and that the information is provided to the correct person.
  • You may request that your personal information be corrected if the information is incorrect. Within the framework of the stated purpose, you also have the right to supplement any incomplete personal data. Keep in mind that you as a member of DigMedix can edit a great deal of submitted data when logged in on DigMedix's website.
  • You may request the deletion of personal data we process about you if: (i)The data is no longer necessary for the purposes for which they have been collected or processed (ii)You oppose a weighing of interests we have performed based on legitimate interest and your objection weighs more than our legitimate interest (iii)You oppose processing for direct marketing purposes. (iv)Personal data is processed illegally. (v)Personal data must be erased to comply with a legal obligation we are subject to. (vi)Personal data which has been collected for a child (under the age of 13) for which you have parental responsibility and collection has been made in connection with an offering via information society services (e.g. social media).
  • Keep in mind that we may have the right to deny your request if there are legal obligations that prevent us from immediately deleting certain personal data. These obligations derive from accounting and tax legislation, banking and money laundering legislation, yet also from consumer law.

    It may also be possible that processing is necessary for us to determine, enforce or defend legal claims. Should we be prevented from granting a request for deletion, we will instead block personal data from being used for purposes other than the purpose that prevents the requested deletion.

  • You have the right to request that our processing of your personal data be limited. If you disagree that the personal data we process is correct, you may request limited processing during the time which we need to check if your personal data is correct or not. If we no longer need your personal data for the stated purposes, but you need the data to determine, enforce or defend legal claims, you may request limited processing of the data by us. This means that you can request that we do not delete your data. If you have objected to a weighing of interest of legitimate interest that we have performed as a legal basis for a purpose, you may request limited processing during the time which we need in order to check if our legitimate interest outweighs your interest in having the data deleted. If the processing has been limited in accordance with any of the above situations, we may, in addition to the actual storage, process the data to determine, enforce or defend legal claims, to protect someone else's rights or if you have given your consent.
  • You always have the right to avoid direct marketing and to object to all processing of personal data based on a weighing of interest.
  • In cases where we use a weighing of interest as a legal basis for a purpose, you have the possibility to object to the processing. In order to continue processing your personal data after such objection, we need to demonstrate a compelling legitimate reason for the current processing that weighs heavier than your interests, rights or freedoms. Otherwise, we may only process the data to determine, exercise or defend legal claims.
  • You may object to your personal data being processed for direct marketing. The objection also includes the analyses of personal data (so-called profiling) performed for direct marketing purposes. Direct marketing refers to all types of targeted marketing actions (e.g. e-mail and text messaging). Marketing actions - where you as a customer have actively chosen to use one of our services or otherwise initiated contact with us to know more about our services - do not count as direct marketing (such as product recommendations or other features and offers on DigMedix's website). If you oppose direct marketing, we will discontinue the processing of your personal data for that purpose and terminate any direct marketing actions. Keep in mind that you are always able to influence which channels we will use for communicating personal offers. E.g. you can choose to receive only e-mails from us, but not text messages. In this case, you should not object to personal data processing as such but limit our communication channels (by changing the settings on ‘My pages’or by contacting customer service).
  • If our right to process your personal data is based either on your consent or implementation of an agreement with you, you are entitled to request that the data relating to you and which you have provided to us is transferred to another party which will be responsible for the personal data (so-called data portability). A prerequisite for data portability is that the transfer is technically possible and can occur in an automated manner.

What are cookies and how do we use them?

Cookies are a small texts consisting of letters and numbers sent from our web server and stored on your browser or device.

On, we use the following cookies: 1. Session cookies (a temporary cookie that terminates when you close your browser or device). 2. Sustained cookies (cookies that remain on your computer until you delete them or they expire). 3. First party cookies (cookies set by the website you visit). 4. Third party cookies (cookies set by a third party site). 5. Similar technologies (technologies that store information in your browser or device in a manner similar to cookies).

The cookies we use are intended to improve the services we offer. Some of our services need cookies to work properly, while others improve the services for you. We use cookies for overall analytical information regarding your use of our services and for saving functional settings such as language and other information. We also use cookies to provide relevant targeted marketing to you.

Can you yourself control the use of cookies?

Yes. Your browser or device allows you to change the settings for the usage and scope of cookies. Go to the settings of your browser or device to learn more about managing the settings for cookies. Examples of things you can manage are blocking all cookies, only accepting first party cookies, or deleting cookies when you close your browser.

Keep in mind that some of our services might not work if you block or delete cookies. You can read more about cookies in general on

How is your personal data protected?

We use IT systems to protect the privacy, integrity and access to personal data. We have adopted security measures to protect your personal data against unauthorised or illegal processing (such as unauthorised access, loss, destruction or damage). Only those persons who actually need to process your personal data to meet our stated purposes have access to them.

What does it mean that the Data Protection Authority is the supervisory authority?

The Data Protection Authority is responsible for monitoring the application of the law, and a person who deems that a company processes personal data in an incorrect manner is able to file a complaint through the Data Protection Authority.

How do you contact us in the easiest manner with questions about data protection?

Since we take data protection very seriously, we have designated employees who handle these issues, and you can always reach them via

We may make changes to our privacy policy. The latest version of the privacy policy is always available here on the website. Upon updates that are critical to our processing of personal data (such as a change in specified purposes or categories of personal data) or updates that are not critical to processing but which may be of crucial importance to you, you will receive information via and via e-mail (if you have stated an e-mail address) in good time before the updates start to apply.

When we provide information about updates, we will also explain what the updates involve and how they affect you.