Security · Data Protection

    Rigorous data protection.

    Emailing passport copies and sharing personal data in unencrypted channels is where GDPR risk lives. Dimmi replaces all of it with a secure, purpose-built data infrastructure – hosted in the EU.

    Modern stone civic building with frosted security tiles and birds in motion

    How Dimmi implements GDPR

    Immigration cases involve some of the most sensitive personal data a company handles: passport numbers, salary details, educational records, family information. GDPR doesn't just require that this data is stored securely — it requires that every aspect of how it's collected, processed, shared, and retained is lawful, proportionate, and transparent. Dimmi's architecture is designed around these obligations from the ground up.

    Data minimisation

    Dimmi collects only the data required for the specific permit type being applied for. No blanket intake forms, no unnecessary data fields.

    Purpose limitation

    Case data is used exclusively for the immigration case it belongs to. The multi-tenant database architecture ensures each case is isolated — data from one case is never accessible from another.

    Role-based access control

    Each user sees only what their role requires. The HR manager sees the full case. The applicant sees their own documents and status. An external reviewer sees only what has been explicitly shared with them. Access is scoped per case and per user.

    Secure document handling

    Applicants upload sensitive documents — passports, diplomas, salary slips — directly into Dimmi's secure environment. Document extraction and processing runs on isolated infrastructure using private models, ensuring that personal data is never exposed to general-purpose cloud AI services.

    Data subject rights

    Dimmi supports the exercise of data subject rights under GDPR, including access, rectification, erasure, and data portability. Applicants can request deletion of their personal data, and case data can be exported in standard formats.

    Dimmi as data processor

    Dimmi operates as a data processor under GDPR. Data processing agreements are available for every customer relationship, clearly defining roles, responsibilities, and safeguards.

    How Dimmi meets the EU AI Act

    The EU AI Act introduces binding requirements for AI systems that operate in contexts affecting people's legal rights and access to public services. Immigration case handling falls squarely within this scope. Dimmi is designed to meet the Act's requirements for transparency, human oversight, and traceability — not as an afterthought, but as a core part of how the platform works.

    Transparency

    Every AI-generated recommendation clearly identifies itself as AI-generated and shows the legal sources it draws from. Users always know when they're reading AI-assisted guidance versus human-reviewed content.

    Human oversight

    AI does not make final decisions in Dimmi. Every case includes human expert review before submission to the authorities. The platform supports professionals — it does not replace them.

    Traceability

    Every AI output is logged together with the legal sources consulted, the query that triggered it, and the reasoning chain that produced it. This creates a complete, auditable record of how each recommendation was generated.

    Source-linked outputs

    Dimmi's legal intelligence is built on a Retrieval Augmented Generation (RAG) architecture grounded in a validated dataset of Danish immigration law, administrative practice, and procedural requirements. Outputs are anchored in specific legal sources — not generated from general training data.

    System documentation

    Dimmi maintains documentation of its AI system's purpose, capabilities, limitations, and intended use context — as required by the AI Act's transparency and documentation obligations.

    An infrastructure built for rigorous data protection — hosted in EU.

    Hosted in Europe

    All data encrypted in transit and at rest, hosted entirely within the EU. Built with privacy-by-design architecture from day one.

    ISO 27001

    We are implementing ISO 27001, the international standard for information security management, and expect certification as our controls complete formal audit.

    Data Protection

    Our platform is designed from the ground up to meet GDPR and AI Act requirements for transparency, traceability, and oversight — taking data protection off your shoulders.

    Anchored. Always

    Every answer is cited and anchored in our Dimmi Corpus; our validated legal dataset, continuously updated.

    Infrastructure & Operations

    • End-To-End Encryption

      All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are managed through industry-standard key management infrastructure, ensuring sensitive immigration data remains protected at every stage.

    • EU-Based Infrastructure

      Our entire infrastructure is hosted within the European Union, ensuring data sovereignty and full compliance with EU data residency requirements. No data leaves the EU at any point in the workflow.

    • Audit Logging & Traceability

      Every action within the platform is logged with full traceability — who accessed what, when, and why. This supports internal compliance reviews, external audits, and regulatory reporting requirements.

    • Isolated Document Processing

      Sensitive documents are processed through a dedicated pipeline that separates personal data from AI processing. Extraction and redaction run on private, isolated models — passport scans, salary data, and diplomas are never sent to third-party AI services.

    Questions about how we handle your data?

    Request our Data Processing Agreement, or contact us for a walkthrough of our architecture and the specific compliance requirements applicable to your organisation.