Last updated August 3, 2026 · Effective August 3, 2026
This Privacy Policy explains how DiMi (“DiMi”, “we”, “us”) collects, uses, discloses, and protects personal data, and the rights and choices available to you. It is written to meet international data-protection standards, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Canada's PIPEDA, and comparable laws. We designed the product so that the business content you connect is used only to answer your users' questions — never to train foundation models.
DiMi provides a multi-tenant platform for building AI assistants grounded in your own documents, knowledge, databases, and APIs. This policy applies to our website at askdimi.com, our web application, and related services (together, the “Service”).
This policy does not cover third-party websites, products, or services we do not control, or the independent privacy practices of customers who build assistants using the Service.
Data-protection law distinguishes the party that decides why and how personal data is processed (the “controller”) from the party that processes it on the controller's behalf (the “processor”). Our role depends on the data:
Where we act as a processor, our processing is governed by our Data Processing Addendum (DPA), which is available on request and forms part of our agreement with you.
When members of the public interact with an assistant built by one of our customers, we process the questions asked and answers returned on that customer's behalf. Customers should not configure assistants to collect special-category or unnecessary personal data, and are responsible for informing their end users.
We use personal data for the purposes below. Where the GDPR or UK GDPR applies, the corresponding legal basis is shown in brackets.
Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object to such processing as described in “Your privacy rights”.
Inference and embeddings are processed by our model provider (Together AI) under contractual terms that prohibit training on your data. We run open-weight models under our control, and your content is used solely to answer your users' questions.
We rely on a limited set of subprocessors to deliver the Service, in the following categories:
We enter into data-processing terms with each subprocessor requiring appropriate safeguards. A current, itemized list of subprocessors is available on request, and enterprise customers can request advance notice of changes. Enterprise plans also offer a path to VPC or self-hosted inference.
We and our subprocessors may process personal data in countries other than your own, including the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards.
together with supplementary technical and organizational measures where needed. You may request a copy of the relevant transfer mechanism using the contact details below.
When data is no longer needed, we delete or irreversibly anonymize it.
We apply technical and organizational measures appropriate to the risk. Database and API credentials are encrypted at rest with AES-256-GCM and decrypted only in memory at query time. Database connections are read-only, parameterized, and audit-logged. Every record is scoped to your organization and enforced on each query, and data is encrypted in transit.
No method of transmission or storage is completely secure, but we work to protect your data and to promptly investigate and, where required, notify you and the relevant authorities of any personal-data breach. You can read more on our Security page.
Depending on where you live, you may have some or all of the following rights over your personal data. We honor these rights regardless of location where practicable.
To make a request, email privacy@askdimi.com. We will verify your identity before acting and respond within the timeframe required by applicable law (generally one month under the GDPR, or 45 days under the CCPA, each extendable where permitted). You may use an authorized agent where the law allows. We will not charge a fee unless a request is manifestly unfounded or excessive.
When you interact with an assistant built by one of our customers, that customer is the controller of your personal data and their own privacy notice governs how it is used. We process such data on their behalf as a processor.
Please direct requests to access, correct, or delete your data to the relevant customer. If you contact us directly, we will refer your request to the appropriate customer and assist them in responding.
The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children under 16 (or the minimum age in your jurisdiction, and under 13 for purposes of the U.S. Children's Online Privacy Protection Act). If you believe a child has provided us personal data, contact us and we will delete it.
Our assistants generate answers using AI and always disclose that they are AI. We do not use your personal data to make decisions that produce legal or similarly significant effects about you without human involvement. Assistant output may be inaccurate and should not be relied on as a substitute for professional advice.
We may update this policy from time to time. If we make material changes, we will provide notice through the Service or by email and update the “Last updated” date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
For any privacy question or to exercise your rights, contact us at privacy@askdimi.com.
If you are in the EEA, the UK, or Switzerland and are not satisfied with our response, you have the right to lodge a complaint with your local data-protection supervisory authority. Enterprise customers may request details of our EU/UK representative and Data Protection Officer where one is appointed.
This document is provided for general information only and does not constitute legal advice. Please have qualified counsel review and adapt it to your specific circumstances and the jurisdictions in which you operate before relying on it.