This policy explains how Dimmi ApS processes personal data when Dimmi is the controller — that is, when Dimmi decides why and how the data is processed.
Controller Dimmi ApS · CVR no. 46 63 85 73 Karen Blixens Plads 16, 2300 København S, Denmark info@dimmi.dk
Data Protection Officer Massimo Hansen — massimo@dimmi.dk
What this policy does not cover
Most of the personal data that passes through the Dimmi platform is not covered by this policy.
When a client uses Dimmi to handle a residence permit, an A1 certificate, a tax question, a posting notification or a relocation, the client is the controller of that case data and Dimmi is its processor. Dimmi processes it on the client's documented instructions and not for its own purposes. That processing is governed by the Data Processing Agreement, described in the Specification of Data Processing, and — for the individual concerned — explained in the Employee Portal privacy notice.
If you are an employee, candidate or family member whose case is being handled in Dimmi, the Employee Portal privacy notice is the document you want. Your employer, not Dimmi, is the controller of your case data.
1. Scope
This policy applies where Dimmi is the controller, which covers:
- visitors to dimmi.dk and users of its forms;
- prospective clients and their contact persons;
- users of the Client Portal, in respect of their own account and how they use it;
- individuals who contact Dimmi by email, phone or through the platform;
- newsletter subscribers, and attendees at Dimmi events and webinars;
- contacts at partners, delivery partners, suppliers and funders; and
- applicants for positions at Dimmi.
2. Personal data Dimmi collects
2.1 Information you give us
Account data. Name, work email, phone number, position and role, language preference, and user settings for people with a Client Portal account.
Communication data. Contact details and the content of enquiries, support messages and correspondence. Meetings and demonstrations may be recorded where the participants are told in advance and agree.
Marketing data. Information given when subscribing to the newsletter, registering for an event, or requesting material such as a whitepaper or the transfer impact assessment package.
Testimonials. Quotes, reviews and endorsements, where the individual has agreed to their use.
Recruitment data. Applications, CVs, references and interview notes, where you apply for a position.
2.2 Information collected automatically
Log data. IP address, browser type, timestamps of requests, and pages and features accessed.
Device data. Device type, operating system, browser, referring page and clickstream.
Usage data. Features used, actions taken, time zone, session length and volume of queries.
Cookies and similar technologies. Described in the Cookie Policy.
Website analytics. Aggregate statistics about how dimmi.dk is used, collected with open-source software Dimmi runs on its own EU servers. It sets no cookies, stores nothing on your device and does not identify you. No analytics of any kind runs inside the platform at app.dimmi.dk.
2.3 Information from other sources
Contact details of prospective clients and partners collected from public sources, professional networks and business databases; information from event organisers where you attended a joint event; and information from a client where that client names you as its contact person.
2.4 Aggregated data
Dimmi produces aggregated and anonymised statistics about how the platform and website are used. Once aggregated so that no individual can be identified, this data is no longer personal data and may be used and shared freely — for example in benchmarks or product research.
3. Purposes, legal bases and retention
| Purpose | Data categories | Legal basis | Retention |
|---|---|---|---|
| Providing and administering Client Portal accounts | Account data, log and usage data | Contract performance, Art. 6(1)(b) | Account lifetime + 30 days |
| Invoicing and accounting | Account data, billing details, payment metadata | Contract performance, Art. 6(1)(b); legal obligation, Art. 6(1)(c) | 5 years from the end of the financial year (Danish Bookkeeping Act) |
| Responding to enquiries and providing support | Communication data, account data | Contract performance, Art. 6(1)(b); legitimate interest, Art. 6(1)(f) | 24 months from last contact |
| Network and information security, fraud prevention | Account data, log and device data, audit log | Legitimate interest, Art. 6(1)(f); legal obligation, Art. 6(1)(c) | Audit log 730 days; error and access logs 90 days |
| Maintaining and improving the platform | Log and usage data, aggregated data | Legitimate interest, Art. 6(1)(f) | Duration of active use |
| Understanding how the website is used | Page visited, referrer or campaign, coarse technical data, country; IP processed momentarily to derive country and a daily-rotating hash, and not stored | Legitimate interest, Art. 6(1)(f) | Raw visit records 12 months; aggregate statistics thereafter |
| Sales and business development, including outreach to prospective clients | Contact data, communication data, data from public sources | Legitimate interest, Art. 6(1)(f) | 24 months from last engagement, or until objection |
| Newsletters and event invitations | Contact data, marketing data | Consent, Art. 6(1)(a), and the Danish Marketing Practices Act s. 10 | Until consent is withdrawn |
| Events, webinars and demonstrations | Contact data, attendance and recording where agreed | Consent, Art. 6(1)(a); legitimate interest, Art. 6(1)(f) | 24 months after the event |
| Testimonials and case references | Name, position, employer, quote | Consent, Art. 6(1)(a) | Until consent is withdrawn |
| Managing partner, delivery partner and supplier relationships | Contact data, communication data | Contract performance, Art. 6(1)(b); legitimate interest, Art. 6(1)(f) | Duration of the relationship + 5 years |
| Recruitment | Recruitment data | Steps prior to a contract, Art. 6(1)(b); consent for retention in a talent pool, Art. 6(1)(a) | 6 months after the process ends, or 12 months with consent |
| Establishing, exercising or defending legal claims | Any of the above, as required | Legitimate interest, Art. 6(1)(f) | Until the claim is resolved and the limitation period has expired |
| Complying with legal obligations | As required by the obligation | Legal obligation, Art. 6(1)(c) | As required by the obligation |
Where Dimmi relies on legitimate interest, it has assessed that interest against the rights and freedoms of the individuals concerned. You may ask for an explanation of that assessment at info@dimmi.dk.
4. Who Dimmi shares data with
Service providers. Hosting and infrastructure, email and communication tools, CRM and marketing tools, website analytics, accounting and payment processing. Each acts as a processor under a data processing agreement.
Dimmi uses no third-party analytics provider. Website analytics runs on open-source software (Umami) hosted on Dimmi's own infrastructure in the EU, so no data about visits to dimmi.dk is disclosed to any analytics company. No data from the Dimmi platform is included.
Professional advisers. Lawyers, accountants and auditors, where necessary.
Authorities. Where required by law, or where necessary to establish, exercise or defend a legal claim.
In a business transaction. In connection with a merger, acquisition, financing or transfer of all or part of the business, subject to appropriate confidentiality undertakings.
Dimmi does not sell personal data, and does not share it with third parties for their own marketing purposes.
The sub-processors that handle data on the Dimmi platform are published at dimmi.dk/en/subprocessors.
5. International transfers
Dimmi's hosting and primary processing take place within the EU/EEA.
A small number of service providers process personal data outside the EU/EEA. Those transfers rest on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with the provider's own data processing agreement, or on an adequacy decision where one applies.
A documented transfer impact assessment exists for every transfer to a third country without an adequacy decision. The assessments are reviewed at least annually and on material change, and the current package is available on request at info@dimmi.dk.
The transfer mechanism for each provider is stated at dimmi.dk/en/subprocessors.
6. Your rights
Under the GDPR you have the right to:
- be informed and to obtain access — to know what Dimmi processes about you and to receive a copy;
- rectification — to have inaccurate or incomplete data corrected;
- erasure — to have data deleted where it is no longer needed, where consent is withdrawn, or where processing is unlawful, subject to Dimmi's own legal obligations;
- restriction — to have processing limited while a dispute about accuracy or lawfulness is assessed;
- object — to processing based on legitimate interest, and at any time to direct marketing;
- data portability — to receive data you have provided in a structured, commonly used, machine-readable format;
- withdraw consent — at any time, without affecting processing that took place beforehand; and
- lodge a complaint — with a supervisory authority.
To exercise a right, write to info@dimmi.dk. Dimmi responds within one month and may ask for information to verify your identity before acting. Exercising a right never results in adverse treatment.
You may complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, or to the supervisory authority in your country of residence.
7. Security
Dimmi applies technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control on a need-to-know basis, multi-factor authentication, central logging and documented incident response.
The measures are described in full in the Security Measures.
8. Retention
Retention periods are set out in the table in section 3. Where no period is stated, Dimmi keeps personal data only as long as necessary for the purpose it was collected for, and then deletes or anonymises it.
Data held in encrypted backup archives is blocked from further processing and deleted when the backup lifecycle expires.
9. Automated decision-making
Dimmi does not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
AI-assisted features on the platform — Dimmi Counsel, eligibility screening, document extraction — produce decision support that is reviewed by a person before it is acted on. Personal data is not used to train or fine-tune AI models.
10. Children
The platform is intended for business use and is not directed at children. Where a case concerns an accompanying child, that data is processed on the client's instructions under the DPA, not under this policy.
11. Changes to this policy
Dimmi may update this policy. The current version and its date are shown at the top of this page. Where a change materially affects how personal data is processed, Dimmi gives notice by email or in the platform before it takes effect.
12. Contact
General privacy enquiries and requests to exercise your rights: info@dimmi.dk Data Protection Officer: Massimo Hansen — massimo@dimmi.dk
Dimmi ApS · Karen Blixens Plads 16, 2300 København S, Denmark
Previous versions of this document are available at dimmi.dk/en/legal/archive.