Version 0.2 · Published 15 July 2026
Data controller: Dimply Limited (and Dimply Inc. for US-facing processing)
Dimply Limited (company registration number 678661), with its registered office at The Old Schoolhouse, Enniskerry Road, Kilternan, Dublin, D18 X658, Ireland (“Dimply”, “we”, “us” or “our”), is committed to protecting your privacy. This policy explains how we collect, use, share and protect personal data when you: visit our website at www.dimply.ai (the “Website”); contact us or book a demo; receive marketing from us; or register for and use our self-service platform products.
For the personal data described in sections 3 and 5 to 18 of this policy, Dimply is the data controller. Dimply Inc. is a subsidiary of Dimply Limited and may support our US commercial operations. Where personal data is shared with Dimply Inc., this is handled in accordance with applicable data protection and transfer requirements. Unless expressly stated otherwise, Dimply Limited determines the purposes and means of the processing described in this Privacy Policy.
This policy also explains, in section 4, how personal data is processed through the Dimply platform when we provide it to our business and enterprise customers. In that context, our role is different: we act as a data processor on our customer’s documented instructions, and the customer is the controller. We have set that out in full, so that our customers — and the individuals who use experiences built on our platform — can clearly see what the platform does, while remaining transparent about who is responsible for it.
If you apply for a role at Dimply, your personal data is handled under our separate Candidate Privacy Notice, not this policy.
We process personal data as a controller in relation to three main groups of people:
Separately, section 4 describes the personal data processed through the platform for our customers’ end-users (for example, customers of a bank or members of a pension scheme). For that data, we act as a processor, not a controller.
When you visit the Website or get in touch, we collect:
We use this data to respond to you, to operate and secure the Website, and to understand and improve how the Website is used.
Where you have expressed an interest in our products, engaged with us commercially, or where we identify your organisation as a potential customer or partner, we process your business contact details and details of our interactions with you (for example, records of meetings, demos and correspondence). We use this to manage our relationship with your organisation, conduct business-to-business marketing, and plan and improve our sales activities. You can opt out of marketing at any time (see section 8).
When you register for or use the Dimply platform — including the self-service Starter Edition or Builder products, or as a named user provisioned by your organisation — we process, as controller:
We use this data to provide, secure, and support the platform and your account; to operate the build tools you choose; to monitor and improve platform performance and our products; and to meet our legal and contractual obligations.
Please note: the experiences you build may themselves connect to, or process, personal data about other individuals (for example, your own customers). Where that happens, you are the controller of that data, and we act as your processor. That is the processing described in section 4, and it is governed by the data processing agreement between your organisation and us, not by this policy.
The Dimply platform lets our business and enterprise customers (for example, financial institutions) build, personalise and deploy digital financial experiences for their own end-users. When personal data about end users is processed through the platform, we act as a data processor: we process that data only in accordance with our customer’s documented instructions to deliver the experiences the customer has configured.
Our customer is the data controller. It decides what data is used, for what purposes and on what basis, and it is responsible for providing its own privacy notice to its end-users. We do not use that end-user personal data for our own purposes, nor do we use it to train or improve any AI model. The subsections below describe how the platform uses that data to ensure the position is transparent. The obligations that apply to us in this role are set out in the data processing agreement between the relevant customer and us.
Holi is a customer-facing conversational assistant that customers can configure to help their end-users understand their financial position, drawing on the customer’s own data, calculations, and journeys. Where a customer deploys Holi:
The platform can generate profiles, insights, or scores about an individual end user — for example, a financial health score. These are produced using a formula or logic that the customer configures; the platform does not generate them automatically. What is produced, how it is calculated, and how it is used are determined by the customer as the controller.
Beyond Holi, the platform includes AI components that operate on the current end user’s context to deliver the experience the customer has built — for example, a decision component that makes real-time branching decisions within a journey, and a processing component that fetches or derives a data point for use later in the experience. These components run within the boundaries the customer has configured and the constraints we, as the platform provider, set.
Holi does not automatically seek out sensitive information (such as a person’s mood or emotional state). If an end-user volunteers such information during a conversation, Holi is designed to take it into account for the remainder of that conversation; it is not carried into or referenced in that person’s later conversations. Whether such information is processed and on what basis are determined by the customer’s configuration and instructions as the controller.
The platform is designed so that AI surfaces and personalises information rather than giving regulated financial advice or recommending financial products. Controls include instructions built into the assistant’s configuration and automated testing across a range of prompts and scenarios to detect and correct any drift towards regulated advice. Experiences generated with our build tools are reviewed and published by a person before they go live — the AI proposes, and people approve. End-users can respond to Holi and can give feedback on individual messages (for example, a thumbs-up or thumbs-down), which helps identify unexpected responses.
The platform’s AI features use third-party models accessed through a private instance within our own cloud environment, so that data is processed inside the platform’s existing security boundary. Data sent to these models is not used to train or improve them. The relevant providers act as our sub-processors; our customers are informed of our sub-processors and can obtain the current list (see section 10).
For the end-user personal data described in this section, we do not state the lawful basis for processing or the retention period, because we do not determine them. As the processor, we act on our customer’s instructions: the customer, as the controller, is responsible for establishing the lawful basis for processing and setting the applicable retention periods, which the platform then applies through the customer’s configuration. The lawful bases (section 6) and retention periods (section 12) set out in the rest of this policy relate only to the personal data for which Dimply is the controller.
Cookies and similar technologies are small files or identifiers placed on your device when you visit the Website. We use two kinds:
Where the EU GDPR or UK GDPR applies, we rely on the following lawful bases for the personal data we process as a controller:
Where we ask you to provide personal data to meet a legal or contractual requirement, we will make this clear at the time and tell you whether provision is mandatory and what the consequences of not providing it are.
We do not intentionally collect special-category personal data (such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, or biometric data) about website visitors, marketing contacts or platform users. Please do not include sensitive information in free-text fields or in messages to us. If you choose to provide it, you do so voluntarily and, where required, we rely on your explicit consent. The handling of any sensitive information that an end-user volunteers within a deployed experience is addressed separately in section 4.5.
We may send you information about our products and services, and those of our partners, where you have asked for it or where we are otherwise permitted to do so. You can opt out at any time — by using the unsubscribe link in any marketing message, or by emailing privacy@dimply.ai. We do not sell your personal data, and we do not share it with third parties for their own direct marketing.
As a controller, we do not make decisions about you based solely on automated processing that produces legal effects concerning you or that significantly affect you. Any profiling or scoring of end-users within a deployed experience is configured and controlled by our customer as the controller — see section 4.3.
We share personal data only where necessary, and we do not sell it. We may share it with:
The platform and its data are hosted within the European Economic Area (in Google Cloud regions in Belgium and Frankfurt). Where we transfer personal data outside the EEA or the UK — for example, to our US subsidiary or to a service provider — we put in place a lawful transfer mechanism. Depending on the recipient, this may be the European Commission’s and the UK’s Standard Contractual Clauses (with the UK Addendum), reliance on an adequacy decision, or the EU–US / UK Data Privacy Framework, where applicable, together with any additional safeguards required.
We keep personal data only for as long as necessary for the purposes for which we collected it, taking into account applicable legal and regulatory requirements. In summary, for personal data we hold as controller:
| Category of personal data | Indicative retention period |
|---|---|
| Enquiry and contact data | For as long as needed to deal with your enquiry, and a short period afterwards |
| Marketing-contact data | Until you opt out, and then only as needed to honour your preferences |
| Platform account data | For the duration of your account, and a limited period afterwards |
| Usage and security log data | Typically between 180 days and one year |
| Contract, financial and certain marketing records | Up to six years, to meet legal and commercial requirements |
We review what we hold and securely delete personal data when it is no longer required.
We maintain appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access on a least-privilege, need-to-know basis, network and application security controls, logging and auditing, and backup and recovery. Dimply is certified to ISO/IEC 27001:2022. We select our service providers carefully and require them to maintain appropriate security.
Where the EU or UK GDPR applies, you have the right to: access your personal data; have inaccurate data corrected; have your data erased in certain circumstances; restrict or object to certain processing; data portability; and, where processing is based on consent, to withdraw that consent at any time. You also have the right to complain to a supervisory authority (see section 18).
To exercise any of these rights, email privacy@dimply.ai. We will respond within one month and may need to verify your identity first.
If you are an end-user of an experience built by one of our customers, please direct your request to that organisation, which is the controller of your data; we will support them in responding to your request.
If you are in the United States, including California, the following applies in addition to the rest of this policy. We collect the personal data described in this policy — such as your name, business email address and website usage data — for the business purposes set out here. We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
Depending on where you live, you may have the right to access, delete or correct your personal data, and to opt out of any sale or sharing of it. We will not treat you differently for exercising these rights. To make a request, email privacy@dimply.ai.
Our Website and platform products are intended for business users and are not directed to children. We do not knowingly collect personal data from children.
We keep this policy under review and will post any updates on the Website, updating the date shown below. This policy was last updated on 15 July 2026.
Data controller: Dimply Limited, The Old Schoolhouse, Enniskerry Road, Kilternan, Dublin, D18 X658, Ireland.
Privacy contact: privacy@dimply.ai. Our Privacy Officer is the primary point of contact for privacy matters and for data subject rights requests.
Complaints (EEA): if you are in the EEA and are unhappy with how we have handled your personal data, you can complain to the Irish Data Protection Commission — www.dataprotection.ie; 6 Pembroke Row, Dublin 2, D02 X963.
Complaints (UK): if you are in the UK, you can complain to the Information Commissioner’s Office — www.ico.org.uk.