1. Introduction
This document describes the technical and organisational security measures and controls that Dimmi ApS applies to protect personal data processed on behalf of its clients, and to ensure the confidentiality, integrity and availability of the Dimmi platform.
It forms part of the Data Processing Agreement and is referred to in Annex C.2 of that agreement. Dimmi may revise these measures without notice, provided the level of protection is not reduced.
2. Platform overview
Dimmi aOS is a case management platform for global mobility. It is accessed through a web browser, and comprises a Client Portal used by the client's own staff, an Employee Portal used by the individuals concerned by a case, Dimmi Counsel, and an API where separately agreed.
The platform handles residence and work permits, social security determinations and certificates, posted worker notifications, tax support, business travel thresholds, relocation and destination services, and the compliance monitoring and reporting built on top of them.
The platform is hosted entirely within the EU.
3. Sub-processors
Dimmi engages a small number of carefully vetted sub-processors. The authoritative list is published and continuously updated at dimmi.dk/en/subprocessors, stating for each sub-processor the purpose, the categories of data, the location, the transfer mechanism and a link to the relevant data processing agreement.
Additions and replacements are announced on that page with 30 days' notice, and clients may object within the notice period.
4. Business continuity management
Encrypted database backups are taken every 6 hours and written to a separate EU storage bucket, retained for 35 days with an additional 12 monthly copies.
Backup decryption keys are held offline and separately from the backup system itself, so that compromise of the storage layer does not yield readable backups.
Backup freshness is monitored automatically, and recovery procedures are documented.
Dimmi operates as a distributed team. Access to the systems needed to operate the platform is federated through the identity provider and does not depend on physical presence at any location.
5. Supplier relationship management
Information security requirements are addressed as part of supplier selection. Contracts with suppliers that process personal data on Dimmi's behalf impose data protection obligations equivalent to those Dimmi owes its own clients, including the EU Standard Contractual Clauses where the supplier sits outside the EU/EEA.
Suppliers are reviewed on an ongoing basis, and transfer impact assessments for third-country suppliers are reviewed at least annually and whenever a transfer changes materially.
Delivery partners — the immigration, tax, relocation and moving firms that deliver services in a given jurisdiction — are bound by Dimmi's Network Partner Agreement, whose data processing appendix mirrors Dimmi's own obligations, and complete an onboarding declaration before they receive any case data.
6. Information security management
Dimmi maintains documented information security policies and procedures covering access control, incident response, backup and recovery, secure development and supplier management.
ISO 27001 implementation is underway, with certification expected in 2026. Until certification is complete, Dimmi does not hold ISO 27001 or SOC 2 attestation in its own right. Hosting is delivered from Hetzner's ISO 27001-certified EU data centres, and Dimmi's core sub-processors maintain their own certifications, which are listed against each entry at dimmi.dk/en/subprocessors.
Clients may satisfy their own audit obligations under Annex C.7 of the DPA by exercising their audit right directly until third-party attestation is available.
7. System access control
Access to systems that process personal data is granted on a need-to-know, least-privilege basis and is tied to a named individual. No shared or generic accounts are used for access to production data.
Multi-factor authentication is available for all accounts and is enforced for access to production systems.
Single sign-on against the client's own identity provider is available, so that a client's joiner-mover-leaver process governs access to Dimmi without a separate administrative step.
Production administration interfaces are restricted to private networks and are not exposed to the public internet.
Access rights are reviewed on an ongoing basis and withdrawn when no longer necessary.
8. Physical access control
Dimmi operates no server room and holds no client data on local infrastructure.
All production infrastructure is hosted in Hetzner's data centres in Germany and Finland. Those facilities are ISO 27001 certified and operate continuous surveillance, access control, redundant power, networking and cooling.
Data is replicated across EU locations, with backups written to storage physically separate from the primary infrastructure.
Dimmi works as a distributed team and keeps no client data on local devices. The platform is reached through the browser over an encrypted connection, and case documents are held in private storage reachable only through short-lived signed links. Team devices use full-disk encryption and an automatic screen lock.
9. Data access control
Authentication is delegated to WorkOS, which provides credential storage, session management and enterprise identity federation. Dimmi does not store client passwords. Credential handling, including hashing, is performed by WorkOS in line with its own published security practices and its data processing agreement with Dimmi.
Role-based access control governs what an authenticated user can see. A client's users see only that client's cases. An individual in the Employee Portal sees only their own case, and certain information relating to private circumstances — family, housing and personal settling-in matters — is visible to the employer only where necessary for a service the employer has ordered.
Dimmi personnel access to client data is restricted to those who need it to deliver a case, is logged, and is subject to the confidentiality undertakings in section 16.
Dependency scanning and static code analysis run in the continuous integration pipeline, and the application enforces signed webhooks, SSRF protection and rate limiting.
10. Transmission access control
Data in transit is encrypted with TLS 1.2 or higher. TLS 1.0 and 1.1 are refused. HTTP Strict Transport Security is enforced with a one-year max-age across dimmi.dk and its subdomains, so a browser that has visited once will not connect over plain HTTP again.
Data at rest is encrypted at the storage layer on both compute and object storage. Database backups are additionally encrypted client-side before they leave the application, so that the storage provider holds ciphertext only.
Integration secrets and credentials are encrypted at rest with a separate key.
Live case documents are held in private storage and are reachable only through short-lived signed links, never through a public URL.
11. Entry control
Security-relevant events are logged centrally, with personal data scrubbed from application logs.
The audit log records look-ups and views of case data against a unique user identity with a timestamp, and is retained for 730 days.
Email, webhook and error logs are retained for 90 days. Error monitoring is configured to exclude personal data from stack traces.
12. Availability control
Encrypted database backups are taken every 6 hours, with point-in-time recovery for the primary database.
Backups are encrypted both in transit and at rest, and are stored with versioning, retention controls and dedicated access credentials separate from those used for production.
Patching is prioritised by threat level, with expedited patching for critical vulnerabilities.
Client environments are logically separated within the platform.
13. Separation control
Development, test, staging and production environments are separated, and production personal data is not used in development or test environments.
Client data is logically separated so that no client's users can reach another client's cases.
14. Risk management
Dimmi carries out periodic reviews of the risks to the rights and freedoms of data subjects arising from its processing, and of the security risks to the platform, and adjusts the measures in this document accordingly.
Transfer impact assessments are maintained for every transfer to a third country without an adequacy decision, approved by the Data Protection Officer, and reviewed at least annually and on material change.
Dimmi assists clients with data protection impact assessments and prior consultation under Articles 35 and 36 of the GDPR.
Findings from risk reviews and from security incidents are reported to Dimmi's management.
15. Operations security
Malicious code. Team devices run the operating system's built-in protections against malicious code, with security updates applied promptly. Email is the principal vector, and is addressed below.
Email. Inbound and outbound email is protected by the mail provider's own security and spam filtering. Messages identified as malicious are quarantined.
Incident response. Dimmi maintains a documented incident response procedure. A personal data breach affecting a client's data is notified to that client without undue delay and, where possible, within 24 hours of Dimmi becoming aware of it — ahead of the client's own 72-hour deadline to the supervisory authority under Article 33 of the GDPR.
All breaches are recorded in an internal breach register, which is available to clients on request. Incident exercises are run annually in connection with refresher training.
16. Security regarding personnel
All Dimmi employees are bound by written confidentiality undertakings that survive the end of their engagement.
Employees who handle personal data receive training in the GDPR and in data minimisation as part of onboarding, and annual refresher training in connection with incident exercises.
Access to client data requires authorisation and is granted only to personnel who need it to deliver a case.
17. Retention of personal data
During the term of the agreement, personal data is retained in accordance with the retention schedule in Annex C.5 of the Data Processing Agreement and, where the client instructs erasure earlier, in accordance with that instruction.
On termination, personal data is erased or returned at the client's choice no later than 60 days after termination, unless EU or Member State law requires storage. Where erasure is impracticable because data is held in encrypted backup archives, the data is blocked from further processing and erased on expiry of the backup lifecycle.
Contact
Questions about these measures, and requests for the transfer impact assessment package or for documentation in support of a client audit:
Massimo Hansen, Data Protection Officer — massimo@dimmi.dk General enquiries — info@dimmi.dk
Previous versions of this document are available at dimmi.dk/en/legal/archive.
Previous versions of this document are available at dimmi.dk/en/legal/archive.