Didit Privacy Policy
Effective Date: January 11, 2026
1. Data Controller
The Data Controller for the processing of data collected through this Website is:
- Didit Identity Spain SL – CIF B22929327, Calle Napoles 227, P. 1, 08013 Barcelona, Spain
- Didit Identity, Inc. – EIN 39-2860573, 1111B S Governors Ave STE 34855, Dover, DE 19904, USA
Email: [email protected]
2. Purposes
The personal data of the user of this Website will be processed for the following purposes:
-
To enable the maintenance, development, and management of the business relationship formalized with DIDIT BUSINESS users who request to receive products and/or services from Didit. The data processed for this purpose will be stored for as long as the relationship is maintained and, once it is terminated, for the legally stipulated periods of conservation and prescription of responsibilities. The legal basis for the processing is:
a) In relation to the self-employed DIDIT BUSINESS users, the execution of a contract to which the data subject is a party.
b) In relation to the professional location data (contact data and data related to the function or position held) of the natural persons who, providing their services to the DIDIT BUSINESS customer (legal entity), come into contact with Didit to enable the maintenance of the business relationship formalized through this Website ("Contact Persons"), the legitimate interest of Didit in maintaining the business relationship with the DIDIT BUSINESS customer through them. - To enable the maintenance, development, and management of the services provided to the DIDIT PERSONAL users. The data processed for this purpose will be stored until the revocation of the consent given for the receipt of such services and, thereafter, during the periods of conservation and prescription of responsibilities provided by law. The legal basis for the processing is the consent of the user expressed through the channels made available to them. In relation to the processing of biometric data intended to unequivocally identify an individual, the legal basis is the explicit consent for the processing of such data.
-
To attend to requests for information and/or queries made by the user. The data processed for this purpose will be stored until the request for information and/or query has been answered and, after that, for the legally stipulated periods of conservation and prescription of responsibilities. The legal basis for the processing is:
a) the consent of the user in the event that they use the contact form on this Website; or
b) the legitimate interest of Didit in responding to the user in the event that they do not use the said form (sending spontaneous e-mails, telephone calls, sending written requests by post). - To keep the user informed, including by electronic means, about Didit's products, services, and news. The data processed for this purpose will be stored until the revocation of the consent given for the receipt of such communications and, thereafter, during the periods of conservation and prescription of responsibilities provided by law. The legal basis for the processing is the consent of the user expressed through the channels made available to them on this Website.
- To manage the applications received from candidates who apply for the job offers published on this website. The data received will be processed exclusively for the purpose of considering and managing the application. Once the selection process has been completed, in the event that the candidate is not selected, their data will be kept blocked for the legally stipulated periods of conservation and prescription of responsibilities. The legal basis for this data processing is the implementation of pre-contractual measures at the candidate's request.
- If at the end of the selection process the candidate is not selected but wishes Didit to keep their CV for future job opportunities, they must expressly consent to this. In this case, the legal basis for this data processing is the candidate's consent. The CV will be stored for 90 days and, after that, during the legally established periods of conservation and prescription of responsibilities.
3. Recipients
Didit may communicate the data to Public Administrations for the fulfillment of legal obligations; to State Security Forces and Bodies and/or the Courts and Tribunals that require them in the framework of an investigation, instruction, or procedure; to banking entities for the management of collections and payments; and to organizations to which the DIDIT PERSONAL user identifies themselves using the service. It may also communicate the data to the following categories of data processors: Providers of electronic communications, office automation, hosting, housing, computer maintenance, management, accounting, auditing, consulting, and legal representation. Some of these data processors may be located outside the European Economic Area, in which case Didit will have adopted appropriate data protection safeguards in advance.
4. Rights
The data subjects may exercise their rights of access, rectification, erasure, restriction of processing, data portability, right to object, and the right not to be subject to a decision based solely on automated processing - including profiling - which produces legal effects concerning them or similarly significantly affects them, as well as withdraw their consent at any time without affecting the lawfulness of the processing prior to its withdrawal, by sending their request to the e-mail address [email protected]. In any case, the data subjects have the right to lodge a complaint with the corresponding supervisory authority if they deem it appropriate.
Didit has appointed a Data Protection Officer who can be contacted through the e-mail address [email protected].
5. Governing Law
This Privacy Policy is governed by the laws of Spain, including the General Data Protection Regulation (GDPR) and the Spanish Organic Law on Data Protection and Guarantee of Digital Rights.
© 2026 Didit Identity. All rights reserved.