Legal

Privacy Policy

Last updated August 3, 2026 · Effective August 3, 2026

This Privacy Policy explains how DiMi (“DiMi”, “we”, “us”) collects, uses, discloses, and protects personal data, and the rights and choices available to you. It is written to meet international data-protection standards, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Canada's PIPEDA, and comparable laws. We designed the product so that the business content you connect is used only to answer your users' questions — never to train foundation models.

01Who we are and the scope of this policy

DiMi provides a multi-tenant platform for building AI assistants grounded in your own documents, knowledge, databases, and APIs. This policy applies to our website at askdimi.com, our web application, and related services (together, the “Service”).

This policy does not cover third-party websites, products, or services we do not control, or the independent privacy practices of customers who build assistants using the Service.

02Our roles: controller and processor

Data-protection law distinguishes the party that decides why and how personal data is processed (the “controller”) from the party that processes it on the controller's behalf (the “processor”). Our role depends on the data:

  • Controller: for personal data about our account holders and website visitors — for example account registration details, billing information, support requests, and marketing preferences — we act as the controller.
  • Processor: for the content you ingest and connect, and for the questions and answers exchanged between your end users and your assistants, we act as a processor on your behalf. You (our customer) are the controller of that data and are responsible for having a lawful basis and providing any required notices to your end users.

Where we act as a processor, our processing is governed by our Data Processing Addendum (DPA), which is available on request and forms part of our agreement with you.

03Personal data we collect

Information you provide

  • Account and profile data: your name, work email, organization name, role, and authentication credentials. Passwords are stored only as salted, hashed values — never in plain text.
  • Customer content: documents, URLs, files, database connection metadata, saved queries, API configurations, and the prompts and instructions you configure for your assistants.
  • Communications: messages you send us through the contact form, support channels, or email, including the contents of those messages.
  • Payment data: billing contact and, for paid plans, information needed to process payments. Card details are collected and stored by our payment processor — we do not store full card numbers on our systems.

Information collected automatically

  • Usage data: message counts, feature usage, analytics events, and plan-limit metering.
  • Audit logs: records of the read-only SQL queries and API calls your assistants trigger — inputs, timing, success, and a result summary.
  • Technical data: IP address, browser and device type, approximate location derived from IP, and standard server logs. IP addresses are also used for security and rate limiting.
  • Cookies: a small number of strictly necessary cookies (see “Cookies and similar technologies”). We do not use advertising or cross-site tracking cookies.

End-user (visitor) data

When members of the public interact with an assistant built by one of our customers, we process the questions asked and answers returned on that customer's behalf. Customers should not configure assistants to collect special-category or unnecessary personal data, and are responsible for informing their end users.

05Cookies and similar technologies

We keep our use of cookies minimal. We use strictly necessary cookies to keep you signed in, secure your session, and remember essential preferences. These are required for the Service to function and cannot be switched off through the product.

We do not use advertising, profiling, or cross-site tracking cookies. Our contact form is protected by a self-hosted proof-of-work check that performs no tracking. Where consent is legally required for any non-essential technology we introduce in future, we will ask for it first.

06AI model providers and subprocessors

Inference and embeddings are processed by our model provider (Together AI) under contractual terms that prohibit training on your data. We run open-weight models under our control, and your content is used solely to answer your users' questions.

We rely on a limited set of subprocessors to deliver the Service, in the following categories:

  • Cloud hosting and application infrastructure
  • Managed database and vector storage
  • AI inference and embeddings
  • Email delivery and customer communications
  • Payment processing
  • Error monitoring and product analytics

We enter into data-processing terms with each subprocessor requiring appropriate safeguards. A current, itemized list of subprocessors is available on request, and enterprise customers can request advance notice of changes. Enterprise plans also offer a path to VPC or self-hosted inference.

07International data transfers

We and our subprocessors may process personal data in countries other than your own, including the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards.

  • The European Commission's Standard Contractual Clauses (SCCs) for transfers from the EEA;
  • The UK International Data Transfer Agreement or the UK Addendum to the SCCs for transfers from the UK;
  • Equivalent safeguards for transfers from Switzerland and other jurisdictions,

together with supplementary technical and organizational measures where needed. You may request a copy of the relevant transfer mechanism using the contact details below.

08How long we keep data

  • Customer content is retained for as long as your workspace is active. You can delete individual sources, conversations, or your entire workspace at any time.
  • Account and billing records are retained for the life of your account and afterwards only as long as needed to meet legal, tax, and accounting obligations.
  • Audit and security logs are retained for a limited period appropriate to their security and troubleshooting purpose.
  • Backups are kept on a rolling basis and overwritten in the ordinary course; deleted data is purged from backups within our standard backup cycle.

When data is no longer needed, we delete or irreversibly anonymize it.

09How we protect data

We apply technical and organizational measures appropriate to the risk. Database and API credentials are encrypted at rest with AES-256-GCM and decrypted only in memory at query time. Database connections are read-only, parameterized, and audit-logged. Every record is scoped to your organization and enforced on each query, and data is encrypted in transit.

No method of transmission or storage is completely secure, but we work to protect your data and to promptly investigate and, where required, notify you and the relevant authorities of any personal-data breach. You can read more on our Security page.

10Your privacy rights

Depending on where you live, you may have some or all of the following rights over your personal data. We honor these rights regardless of location where practicable.

Under the GDPR / UK GDPR and similar laws

  • Access — obtain confirmation of and a copy of your personal data;
  • Rectification — correct inaccurate or incomplete data;
  • Erasure — ask us to delete your data (the “right to be forgotten”);
  • Restriction — limit how we process your data in certain circumstances;
  • Portability — receive your data in a structured, machine-readable format;
  • Objection — object to processing based on legitimate interests or to direct marketing;
  • Withdraw consent — where processing is based on consent, at any time, without affecting prior processing;
  • Lodge a complaint — with your local supervisory authority (see below).

Under the CCPA / CPRA (California residents)

  • Know and access the categories and specific pieces of personal information we collect;
  • Delete personal information we have collected, subject to exceptions;
  • Correct inaccurate personal information;
  • Opt out of the “sale” or “sharing” of personal information — note that we do not sell or share personal information as those terms are defined;
  • Limit the use of sensitive personal information — we do not use sensitive personal information for purposes that trigger this right;
  • Be free from discrimination for exercising your rights.

How to exercise your rights

To make a request, email privacy@askdimi.com. We will verify your identity before acting and respond within the timeframe required by applicable law (generally one month under the GDPR, or 45 days under the CCPA, each extendable where permitted). You may use an authorized agent where the law allows. We will not charge a fee unless a request is manifestly unfounded or excessive.

11If you are an end user of a customer's assistant

When you interact with an assistant built by one of our customers, that customer is the controller of your personal data and their own privacy notice governs how it is used. We process such data on their behalf as a processor.

Please direct requests to access, correct, or delete your data to the relevant customer. If you contact us directly, we will refer your request to the appropriate customer and assist them in responding.

12Children's privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children under 16 (or the minimum age in your jurisdiction, and under 13 for purposes of the U.S. Children's Online Privacy Protection Act). If you believe a child has provided us personal data, contact us and we will delete it.

13Automated decision-making

Our assistants generate answers using AI and always disclose that they are AI. We do not use your personal data to make decisions that produce legal or similarly significant effects about you without human involvement. Assistant output may be inaccurate and should not be relied on as a substitute for professional advice.

14Changes to this policy

We may update this policy from time to time. If we make material changes, we will provide notice through the Service or by email and update the “Last updated” date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

15How to contact us

For any privacy question or to exercise your rights, contact us at privacy@askdimi.com.

If you are in the EEA, the UK, or Switzerland and are not satisfied with our response, you have the right to lodge a complaint with your local data-protection supervisory authority. Enterprise customers may request details of our EU/UK representative and Data Protection Officer where one is appointed.

This document is provided for general information only and does not constitute legal advice. Please have qualified counsel review and adapt it to your specific circumstances and the jurisdictions in which you operate before relying on it.