Skip to main content
  • Platform
  • Company
  • Book a demo
    Book a demo
  • Platform
  • Company
  • Book a demo
    Book a demo
Button Text
Book a demo

Privacy Policy

Version 0.2 · Published 15 July 2026
Data controller: Dimply Limited (and Dimply Inc. for US-facing processing)

1. About this policy

Dimply Limited (company registration number 678661), with its registered office at The Old Schoolhouse, Enniskerry Road, Kilternan, Dublin, D18 X658, Ireland (“Dimply”, “we”, “us” or “our”), is committed to protecting your privacy. This policy explains how we collect, use, share and protect personal data when you: visit our website at www.dimply.ai (the “Website”); contact us or book a demo; receive marketing from us; or register for and use our self-service platform products.

For the personal data described in sections 3 and 5 to 18 of this policy, Dimply is the data controller. Dimply Inc. is a subsidiary of Dimply Limited and may support our US commercial operations. Where personal data is shared with Dimply Inc., this is handled in accordance with applicable data protection and transfer requirements. Unless expressly stated otherwise, Dimply Limited determines the purposes and means of the processing described in this Privacy Policy.

This policy also explains, in section 4, how personal data is processed through the Dimply platform when we provide it to our business and enterprise customers. In that context, our role is different: we act as a data processor on our customer’s documented instructions, and the customer is the controller. We have set that out in full, so that our customers — and the individuals who use experiences built on our platform — can clearly see what the platform does, while remaining transparent about who is responsible for it.

If you apply for a role at Dimply, your personal data is handled under our separate Candidate Privacy Notice, not this policy.

2. Who this policy is for

We process personal data as a controller in relation to three main groups of people:

  • Website visitors — people who browse www.dimply.ai, complete a form, or contact us.
  • Marketing and sales contacts — individuals at customer, prospective-customer and partner organisations with whom we communicate about our products and services.
  • Platform users — individuals at our business customers and self-service users who register for and use the Dimply platform to build and manage financial experiences.

Separately, section 4 describes the personal data processed through the platform for our customers’ end-users (for example, customers of a bank or members of a pension scheme). For that data, we act as a processor, not a controller.

3. The personal data we collect as a controller, and why

3.1 Website visitors

When you visit the Website or get in touch, we collect:

  • Contact details you provide — for example, your business email address when you book a demo, ask a question, or make a partnership or press enquiry.
  • Free-text information you choose to give us — anything you include in a “how can we help” or contact field, which may include your name, contact details and the content of your message.
  • Technical and usage data collected automatically — for example, the date and time of your visit or submission, your IP address, and browser and device information, which we use to keep the Website secure and operating correctly.
  • Cookie and analytics data — see section 5 and our separate Cookie Policy.

We use this data to respond to you, to operate and secure the Website, and to understand and improve how the Website is used.

3.2 Marketing and sales contacts

Where you have expressed an interest in our products, engaged with us commercially, or where we identify your organisation as a potential customer or partner, we process your business contact details and details of our interactions with you (for example, records of meetings, demos and correspondence). We use this to manage our relationship with your organisation, conduct business-to-business marketing, and plan and improve our sales activities. You can opt out of marketing at any time (see section 8).

3.3 Platform users

When you register for or use the Dimply platform — including the self-service Starter Edition or Builder products, or as a named user provisioned by your organisation — we process, as controller:

  • Registration data — your name, email address, organisation name and organisation role.
  • Usage data — information generated as you use the platform, such as IP address, browser type, session and activity data, system and performance information, and security-related signals.
  • Build content you create — including the descriptions you type when you use our natural-language build tools (for example, “Build using AI mode”, the Experience Builder, and “Ask Dimply”) to design and configure experiences.

We use this data to provide, secure, and support the platform and your account; to operate the build tools you choose; to monitor and improve platform performance and our products; and to meet our legal and contractual obligations.

Please note: the experiences you build may themselves connect to, or process, personal data about other individuals (for example, your own customers). Where that happens, you are the controller of that data, and we act as your processor. That is the processing described in section 4, and it is governed by the data processing agreement between your organisation and us, not by this policy.

4. How the Dimply platform processes personal data on behalf of our customers

4.1 Our role, and our customer’s role

The Dimply platform lets our business and enterprise customers (for example, financial institutions) build, personalise and deploy digital financial experiences for their own end-users. When personal data about end users is processed through the platform, we act as a data processor: we process that data only in accordance with our customer’s documented instructions to deliver the experiences the customer has configured.

Our customer is the data controller. It decides what data is used, for what purposes and on what basis, and it is responsible for providing its own privacy notice to its end-users. We do not use that end-user personal data for our own purposes, nor do we use it to train or improve any AI model. The subsections below describe how the platform uses that data to ensure the position is transparent. The obligations that apply to us in this role are set out in the data processing agreement between the relevant customer and us.

4.2 Holi (conversational assistant)

Holi is a customer-facing conversational assistant that customers can configure to help their end-users understand their financial position, drawing on the customer’s own data, calculations, and journeys. Where a customer deploys Holi:

  • End-users can type free-text messages to Holi, and those conversations are stored in our system.
  • Conversation logs are retained in line with the customer’s configuration. If an end user deletes their account, they are removed from the system.
  • Holi draws on verified information the customer has made available (for example, a person’s actual products, balances and entitlements) through controlled requests to the platform’s data layer; it does not query underlying databases directly.

4.3 Customer-configured profiling and scoring

The platform can generate profiles, insights, or scores about an individual end user — for example, a financial health score. These are produced using a formula or logic that the customer configures; the platform does not generate them automatically. What is produced, how it is calculated, and how it is used are determined by the customer as the controller.

4.4 AI journey building, decision and processing components

Beyond Holi, the platform includes AI components that operate on the current end user’s context to deliver the experience the customer has built — for example, a decision component that makes real-time branching decisions within a journey, and a processing component that fetches or derives a data point for use later in the experience. These components run within the boundaries the customer has configured and the constraints we, as the platform provider, set.

4.5 Sensitive or special-category information volunteered in conversation

Holi does not automatically seek out sensitive information (such as a person’s mood or emotional state). If an end-user volunteers such information during a conversation, Holi is designed to take it into account for the remainder of that conversation; it is not carried into or referenced in that person’s later conversations. Whether such information is processed and on what basis are determined by the customer’s configuration and instructions as the controller.

4.6 Guardrails and human oversight

The platform is designed so that AI surfaces and personalises information rather than giving regulated financial advice or recommending financial products. Controls include instructions built into the assistant’s configuration and automated testing across a range of prompts and scenarios to detect and correct any drift towards regulated advice. Experiences generated with our build tools are reviewed and published by a person before they go live — the AI proposes, and people approve. End-users can respond to Holi and can give feedback on individual messages (for example, a thumbs-up or thumbs-down), which helps identify unexpected responses.

4.7 AI model providers and model training

The platform’s AI features use third-party models accessed through a private instance within our own cloud environment, so that data is processed inside the platform’s existing security boundary. Data sent to these models is not used to train or improve them. The relevant providers act as our sub-processors; our customers are informed of our sub-processors and can obtain the current list (see section 10).

4.8 Why this policy does not state a lawful basis or retention period for end-user data

For the end-user personal data described in this section, we do not state the lawful basis for processing or the retention period, because we do not determine them. As the processor, we act on our customer’s instructions: the customer, as the controller, is responsible for establishing the lawful basis for processing and setting the applicable retention periods, which the platform then applies through the customer’s configuration. The lawful bases (section 6) and retention periods (section 12) set out in the rest of this policy relate only to the personal data for which Dimply is the controller.

5. Cookies and similar technologies

Cookies and similar technologies are small files or identifiers placed on your device when you visit the Website. We use two kinds:

  • Strictly necessary cookies — required for the Website to function and to keep it secure. These are always active and do not require your consent.
  • Analytics and marketing cookies — We do not currently use analytics, advertising or other tracking cookies, so no consent is required for the cookies we use. If we introduce analytics or other non-essential cookies in the future, we will ask for your consent via a cookie banner before those cookies are set and update this policy accordingly.

6. The lawful bases we rely on (EEA and UK)

Where the EU GDPR or UK GDPR applies, we rely on the following lawful bases for the personal data we process as a controller:

  • Performance of a contract — to provide, administer and support your platform account and the self-service products, and to take steps at your request before entering into a contract.
  • Legitimate interests — to operate, secure and improve the Website and our products, to manage our business relationships, to carry out business-to-business marketing, and to protect against fraud and misuse. Where we rely on legitimate interests, we balance those interests against your rights.
  • Consent — where required, for example, for certain cookies and analytics and for some marketing. You can withdraw consent at any time.
  • Legal obligation — where we must process personal data to comply with a legal or regulatory requirement.

Where we ask you to provide personal data to meet a legal or contractual requirement, we will make this clear at the time and tell you whether provision is mandatory and what the consequences of not providing it are.

7. Special-category (sensitive) data

We do not intentionally collect special-category personal data (such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, or biometric data) about website visitors, marketing contacts or platform users. Please do not include sensitive information in free-text fields or in messages to us. If you choose to provide it, you do so voluntarily and, where required, we rely on your explicit consent. The handling of any sensitive information that an end-user volunteers within a deployed experience is addressed separately in section 4.5.

8. Marketing communications

We may send you information about our products and services, and those of our partners, where you have asked for it or where we are otherwise permitted to do so. You can opt out at any time — by using the unsubscribe link in any marketing message, or by emailing privacy@dimply.ai. We do not sell your personal data, and we do not share it with third parties for their own direct marketing.

9. Automated decision-making and profiling

As a controller, we do not make decisions about you based solely on automated processing that produces legal effects concerning you or that significantly affect you. Any profiling or scoring of end-users within a deployed experience is configured and controlled by our customer as the controller — see section 4.3.

10. Who we share your personal data with

We share personal data only where necessary, and we do not sell it. We may share it with:

  • Service providers who process personal data on our behalf under contract and only on our instructions. Google Cloud provides our cloud hosting and infrastructure.
  • Sub-processors used to deliver the platform — our customers are given access to, and notice of changes to, the current list of sub-processors under their agreement with us.
  • Professional advisers, auditors and authorities where we are required or permitted to disclose data by law.

11. International data transfers

The platform and its data are hosted within the European Economic Area (in Google Cloud regions in Belgium and Frankfurt). Where we transfer personal data outside the EEA or the UK — for example, to our US subsidiary or to a service provider — we put in place a lawful transfer mechanism. Depending on the recipient, this may be the European Commission’s and the UK’s Standard Contractual Clauses (with the UK Addendum), reliance on an adequacy decision, or the EU–US / UK Data Privacy Framework, where applicable, together with any additional safeguards required.

12. How long do we keep your personal data

We keep personal data only for as long as necessary for the purposes for which we collected it, taking into account applicable legal and regulatory requirements. In summary, for personal data we hold as controller:

Category of personal data Indicative retention period
Enquiry and contact data For as long as needed to deal with your enquiry, and a short period afterwards
Marketing-contact data Until you opt out, and then only as needed to honour your preferences
Platform account data For the duration of your account, and a limited period afterwards
Usage and security log data Typically between 180 days and one year
Contract, financial and certain marketing records Up to six years, to meet legal and commercial requirements

We review what we hold and securely delete personal data when it is no longer required.

13. How we keep your personal data secure

We maintain appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access on a least-privilege, need-to-know basis, network and application security controls, logging and auditing, and backup and recovery. Dimply is certified to ISO/IEC 27001:2022. We select our service providers carefully and require them to maintain appropriate security.

14. Your data protection rights (EEA and UK)

Where the EU or UK GDPR applies, you have the right to: access your personal data; have inaccurate data corrected; have your data erased in certain circumstances; restrict or object to certain processing; data portability; and, where processing is based on consent, to withdraw that consent at any time. You also have the right to complain to a supervisory authority (see section 18).

To exercise any of these rights, email privacy@dimply.ai. We will respond within one month and may need to verify your identity first.

If you are an end-user of an experience built by one of our customers, please direct your request to that organisation, which is the controller of your data; we will support them in responding to your request.

15. United States

If you are in the United States, including California, the following applies in addition to the rest of this policy. We collect the personal data described in this policy — such as your name, business email address and website usage data — for the business purposes set out here. We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

Depending on where you live, you may have the right to access, delete or correct your personal data, and to opt out of any sale or sharing of it. We will not treat you differently for exercising these rights. To make a request, email privacy@dimply.ai.

16. Children’s privacy

Our Website and platform products are intended for business users and are not directed to children. We do not knowingly collect personal data from children.

17. Changes to this policy

We keep this policy under review and will post any updates on the Website, updating the date shown below. This policy was last updated on 15 July 2026.

18. How to contact us, and how to complain

Data controller: Dimply Limited, The Old Schoolhouse, Enniskerry Road, Kilternan, Dublin, D18 X658, Ireland.

Privacy contact: privacy@dimply.ai. Our Privacy Officer is the primary point of contact for privacy matters and for data subject rights requests.

Complaints (EEA): if you are in the EEA and are unhappy with how we have handled your personal data, you can complain to the Irish Data Protection Commission — www.dataprotection.ie; 6 Pembroke Row, Dublin 2, D02 X963.

Complaints (UK): if you are in the UK, you can complain to the Information Commissioner’s Office — www.ico.org.uk.

Contents
  1. 1. About this policy
  2. 2. Who this policy is for
  3. 3. The personal data we collect as a controller, and why
  4. 4. How the Dimply platform processes personal data on behalf of our customers
  5. 5. Cookies and similar technologies
  6. 6. The lawful bases we rely on (EEA and UK)
  7. 7. Special-category (sensitive) data
  8. 8. Marketing communications
  9. 9. Automated decision-making and profiling
  10. 10. Who we share your personal data with
  11. 11. International data transfers
  12. 12. How long do we keep your personal data
  13. 13. How we keep your personal data secure
  14. 14. Your data protection rights (EEA and UK)
  15. 15. United States
  16. 16. Children’s privacy
  17. 17. Changes to this policy
  18. 18. How to contact us, and how to complain

Footer

Product

Meet the Platform
Experience Builder
Micro-apps
Holi

Company

About

Get Started

Book a Demo
© {{year}} Dimply. All Rights Reserved.
Privacy Policy
Terms of Service