v1.0 live! Celebrating with 50% off -limited offer

Privacy Policy

Last Updated: February 13, 2026

Welcome to the Privacy Policy of DIMA's AI Platform

If you have any questions related to this Privacy Policy, please feel free to contact us at the contact details provided below. Please consider that by accessing and using our services you give your acceptance to the processing of your Personal Data. If you do not agree with any aspect of this Privacy Policy, please discontinue the access and use of our Platform.

This Privacy Policy applies to personal information collected by DIMA AI on our platform for AI services. For more information about our website, please visit the Website Privacy Policy.

Deployment model: Each client's Organization Platform is deployed on a private server with firewall and network protections. Each deployment runs as an isolated instance with its own database—data is not shared between client deployments.

1. Who Are We

We are a Data Processor of your Personal Data and our identification details are:

  • Name: GuidefAI OÜ ("GuidefAI", "DIMA AI", "Company", "us", "we")
  • Postal address: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, Estonia
  • E-mail address: privacy@dima-ai.com

2. Your Relationship with DIMA AI and Who is the Data Controller

DIMA AI provides a SaaS AI platform that offers organizations the possibility to deploy and operate AI agents, automate business processes, manage AI-powered workflows, and leverage document processing (RAG), chat, and collaborative AI tools in a unified workspace. Each client's platform is deployed on a dedicated private server with firewall protection, isolated infrastructure, and a separate database—ensuring data isolation between organizations.

This Privacy Policy provides you, the User of the Platform, the relevant information about the processing of your Personal Data by DIMA AI as a Data Processor, on behalf of your organization as the Data Controller. To this end, if not stated otherwise in this Privacy Policy or in a separate disclosure, we process such Personal Data as a processor/service provider on behalf of organizations and their affiliates, who are the Data Controller, establishing the purposes and means for the processing of your Personal Data through our Platform.

In this sense, please take into account that the processing of your personal data is governed by the privacy policy of your organization, of which you have created an account.

As a general reference, the processing activities of DIMA AI on behalf of organizations are governed by the Data Processing Addendum available in our terms. However, please request the necessary information as there might be instances where the Data Processing Addendum has been modified as per request of the Data Controller.

3. Definition of Used Terms

Organization(s)

The entity that has signed up on the Platform as a customer of DIMA AI, who chooses to make the Platform available for their team members and employees in order to access AI services, through the DIMA AI Platform.

Organization Platform

The workspace within the Platform, created under the Organization Account, containing all AI agents, workflows, documents, organization details and any other relevant information, that will be presented to team members.

Organization User

Employees and/or individual contractors of any affiliates of the Organization, who are authorized by the Organization to use the Platform and which have an individual account under the account of the Organization (the "Organization User", "Organization Users" or "you").

AI Services

All the AI capabilities that organizations choose to make available on the Platform such as: AI model access (chat, completion), AI agent automation, document processing and RAG (retrieval-augmented generation), workflow management, image and media generation, embeddings for search, analytics (internal workspace metrics), and any other AI-powered features in connection with their business operations.

Data Controller

The organization that has provided access to the account that took you to the Platform. The organization is the entity establishing the purposes and means of processing your personal data. Please consult the privacy policy of your organization as it is directly applicable to the processing carried out by DIMA AI.

Data Processor

Us, DIMA AI, who process your personal data based on the instructions and controls established by the organizations within the Platform.

General Data Protection Regulation

(EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC ("GDPR").

DIMA AI's Services

The services offered by GuidefAI OÜ through the DIMA AI Platform, for the purpose of allowing organizations to deploy AI agents, automate workflows, manage documents and RAG, and provide AI-powered chat, image generation, and other solutions to their team members.

Licensable Software and/or Platform

The website www.dima-ai.com together with all software made available by DIMA AI and any other sub-domain assigned to an organization; the Platform is deployed per client on a private server with isolated infrastructure and database. The DIMA AI Platform is accessible from devices with internet connection (optimized for desktop, mobile, and tablets). Through it, Users access the AI services made available by their organization—including AI chat, agents, workflows, document RAG, and image generation—using the account provided by their organization.

Personal Data

Any data or information that can be used to identify a natural person, and are subject to applicable data protection laws, such as GDPR. We use the term "Personal Data" throughout this Privacy Policy to mean, as applicable, "personal data" (under the GDPR).

Privacy Policy

The legal information contained or referenced herein that governs the way we, as a Data Processor, collect, process and share Personal Data ("Policy").

T&C

The terms, conditions and legal information contained in our Terms & Conditions, that govern your use of our platform and form the legal agreement between you and us.

Users

The individuals who, having the minimum required age in order to access our information society services, access the account made available to them by the organizations together with their work or collaboration and choose to register on DIMA AI and create an Account, having therefore direct access to the AI services and also the possibility to access other additional features such as: AI agent interactions, workflow automation, document processing, and others (the "User", "Users" or "you").

User's Account

Comprises of the identification and authentication details that Users provide to register on our Platform.

4. Categories of Personal Data That We Process

For the purpose of offering DIMA AI's Services we process different categories of Personal Data. The Platform is deployed per client on a private server with isolated infrastructure and database; data is stored within your organization's deployment. Where sub-processors are used (e.g., LLM providers, embedding services), they receive only the data necessary to perform the requested services. We collect and process:

  • Identification data such as: username, name (first and last);
  • Contact data such as: e-mail address (company name may be provided at account creation);
  • Authentication and session data such as: hashed password, session tokens, IP address and user-agent (when session-based authentication is used);
  • Data on how you use the service such as: chat prompts and AI responses (stored in your deployment database), workspace and thread interactions, document uploads and processing events, workflow and agent run data, event logs (e.g., workspace name, model used—no chat content), internal analytics (response time, token usage per workspace);
  • Data related to third-party integrations such as: OAuth tokens for Google services (Drive, Calendar, etc.) when you choose to connect them—stored encrypted within your deployment; account identifiers for external platforms you integrate;
  • Data from your device such as: files and documents uploaded for AI processing or RAG (when you provide them);
  • Data introduced by you within the Platform such as: chat prompts and responses, workspace configurations, agent instructions, workflow definitions, document content for embedding and search, pinned messages and tables, saved images and products;
  • Financial information such as: Stripe customer identifier and purchase metadata for credit packs (payment card details are processed by Stripe and are not stored by DIMA AI).

Note: The Platform does not collect telemetry or usage analytics by default; such features are disabled in this build. No data is sent to analytics or advertising services.

5. Categories of Data Subject of Whom We Process Personal Data

In order to be able to offer our Services, allow organizations to register their Organization Users and to create the Organization Platform and offer it to their team members, respectively to Users, we process the Personal Data of the following categories of data subjects:

  • Users: Please consider that if you are a User, we will not process your financial data.
  • Organization Users: Team members and employees of organizations using the platform.

6. Purposes of Processing

Platform Registration, Access and Connectivity

For this purpose, we process your data in order to perform activities such as:

  • Identify you and authorize you to access our Platform;
  • Allow you to create a profile and User Account;
  • Facilitate the invitation of others to our Platform;
  • Verifying that you are the legitimate holder of the created user account;
  • Verifying your age and/or the consent of the holder of the parental responsibility.

Provide DIMA AI's Services, AI Agent Access, and Workflow Management

For this purpose, we process your data in order to perform activities such as:

  • Allow you to access the Organization Platform by Login;
  • Allow you to access the different AI features, made available to you by the organization, such as specific AI models, agents, and automation workflows;
  • Facilitate the interaction with AI agents and team members through functionalities such as chat, shared workspaces, and collaborative AI tools.

Removing Errors and Improving Platform Functionality & Security

For this purpose, we process your data in order to perform activities such as:

  • Keep the Platform running by removing errors, enhancing security, combating spam and verifying identity or service access;
  • Monitor and log events (e.g., workspace actions, model usage) within your deployment for operational and support purposes—such data stays within your deployment and is not sent to external analytics;
  • Perform analysis of functionalities to enhance features and adapt the Platform to your needs.

To Provide Customer Support

For this purpose, we process your data in order to provide you with professional assistance, upon your request. To this end we will perform activities such as:

  • Provide information about the Platform, respond to inquiries, complaints and requests for support;
  • Connect you with the organization where needed;
  • Connect you with relevant service providers which may be able to solve your requests.

Marketing and Communications (where applicable)

If your organization has agreed to receive marketing communications from DIMA AI, we may process your contact data to send you information about Platform features and updates. Such processing is based on consent or legitimate interest and you may opt out at any time. The core Platform does not build user profiles for advertising or send third-party marketing messages.

Analyzing Usage Patterns and Creating Statistics (Internal Only)

For this purpose, we process data to create aggregated statistical information and internal analytics (e.g., response times, token usage per workspace). Such data remains within your organization's deployment and is not transmitted to external analytics providers. The Platform does not use third-party analytics, telemetry, or audience measurement by default.

Enforcing Our Terms & Conditions, Perform Our Legal Obligations or Communicate with Relevant Authorities

When using the Platform, you agree to our Terms and Conditions, that define how you can use it. To ensure that the usage is in accordance with our policies we store your personal data and we may process it for purposes such as:

  • Investigate, prevent and mitigate any potentially prohibited or illicit activities related to, for e.g. fraud, IP infringement etc.
  • Enforce our agreements with third parties;
  • Comply with applicable legal obligations.

7. Legal Basis for Processing

In general, the processing of personal data is necessary in order to carry out the activity specific to the purpose of processing, more precisely, the provision of the different functionalities of the AI Platform.

In order to process your personal data, we rely on various legal grounds, as follows:

Contract

In this case the processing is necessary either for entering into a contract (e.g. you have registered on the Platform and we have to take the necessary steps to implement your registration) or for performing contract concluded (e.g. utilizing the AI Platform);

Consent

You gave us your consent for processing your personal data for a specific purpose. Please take into account that in line with the applicable legislation, consent can be granted in multiple ways. In this sense, you give us your consent by clicking a tick-box, by performing a certain action, by voluntarily introducing data or by facilitating a certain interaction, depending on the situation. We optimize the way in which you grant consent for experience and usability purposes. You can always withdraw your consent and, if we do not have another legal basis for processing your data, we will immediately stop such processing. Please consider that consent withdrawal is not retroactive and so it affects only future processing activities. Also, the implementation of the withdrawal will be executed considering the time needed for technical implementation and the timelines provided by law.

Legal Obligation

The processing is necessary for us to comply with the applicable laws.

Legitimate Interest

The processing is necessary for our legitimate interests or the legitimate interest of a third party, as long as such legitimate interests are not out-weighted by your rights and interests. Such legitimate interests could refer to:

  • Delivering, developing and improving our AI Services;
  • Enabling us to enhance, customize or modify our services and content;
  • Evaluating your feedback and solving your queries;
  • Enhancing data security and detecting fraud or misbehavior;
  • Marketing our AI products and services to existing users (where applicable).

8. Categories of Recipients

In our capacity as Data Processors, in order to fulfill our contractual obligations with the Data Controllers, the organizations, your data is disclosed to and/or collected from the organizations according to our Terms & Conditions and according to the Data Processing Addendum. Also, as stated in the introduction, the processing of your personal data is governed by the privacy policy of your organization, of which you have accessed the account so please read that.

Furthermore, for running our AI Platform and for making our services more efficient for some of the processes we may involve third parties. We guarantee that all our business partners, technicians, suppliers or independent third parties are obliged by contractual commitments to process the personal data shared with them only in accordance with our instructions, this Policy and the applicable data protection legislation.

In order to facilitate the activities related to the purposes of processing detailed above, we may communicate data to third parties, including partners and sub-processors. Important: Each client's Platform runs on a private server with isolated database; data stays within your deployment unless a configured integration requires it. Sub-processors receive only the data necessary for their service. Such parties include:

Third parties which help us with AI services (when configured by your organization):

  • LLM providers (e.g., OpenAI, Anthropic, Azure OpenAI, Groq, Mistral, DeepSeek, Perplexity, or self-hosted/local models such as Ollama)—receive prompts and context when generating responses;
  • Embedding providers (e.g., OpenAI, or local/native embeddings)—receive document chunks when generating vector embeddings for RAG;
  • Vector database providers—when a cloud option (e.g., Pinecone) is used instead of local LanceDB, vector data and associated metadata may be stored there;
  • Image and media generation providers (e.g., Ideogram, Replicate)—when such features are used, prompts and parameters are sent.

Third parties which help us with payments and infrastructure:

  • Stripe—processes payment card details for credit purchases; DIMA AI stores only Stripe customer identifiers and purchase metadata, not card data;
  • SMTP/email providers—for password reset, invitations, and notifications (when configured);
  • Optional: Google—when you connect Google Drive, Calendar, or other services via OAuth; tokens are stored encrypted within your deployment.

Third parties which help us with operations and support:

  • Managing contact and support requests;
  • Customer relationship management (where applicable).

Infrastructure and other third parties:

  • Hosting and backup services (for your deployment);
  • Companies from the group to which DIMA AI belongs;
  • Professional advisers, regulatory authorities, or public authorities for compliance with applicable regulations.

Data Transfers: When sub-processors are located outside the European Economic Area, we ensure appropriate safeguards (e.g., adequacy decisions, standard contractual clauses) and that they process data in accordance with our instructions and applicable law.

9. Data Subjects Rights

Right of Access

Upon request you have the right to be informed if your personal data are processed, and if so, you have the right to request access to your data. This allows you to obtain information about:

  • The purposes of processing;
  • The categories of personal data we are processing;
  • The recipients or categories of recipients to whom your personal data has been or will be disclosed;
  • For how long the data will be processed or the criteria to determine that period.

You have the right to obtain a copy of the personal data processed free of charge. For additional copies, we may charge a reasonable fee based on administrative costs.

Right to Rectification

You have the right to request and obtain the modification of any personal data that is incorrect or obsolete.

Right to Erasure ("right to be forgotten")

You have the right to ask us to delete your personal data and we will honor such request unless the circumstances do not allow us to do so like, for e.g. in the case in which we are legally obliged to keep specific details for a number of years.

Right to Restriction of the Processing

You have the right to request a restriction on the processing of your personal data and this is applicable in different circumstances such as:

  • We no longer need your data but you ask us to keep it so that you can establish, exercise or defend legal claims;
  • You appreciate that the personal data we hold is not accurate and you request us to review it;
  • You oppose to the processing of your personal data based on our legitimate interests.

Right to Data Portability

You have the right to ask us to transfer your data either directly to you or, if possible, to another service provider. This is applicable only for the data that you have actively provided to us and that we process automatically based on your consent or based on a contract. Where possible, we will transfer your data in a structured, commonly used, machine-readable format.

Right to Object to the Processing

You have the right to object to the processing of your personal data, for reasons related to your situation, at any time and free of charge. In relation to direct marketing, such objection can be made at any time and without any justification. In relation to the processing based on our legitimate interest, for objecting, you will need to provide a specific reason.

Right Not to Be Subjected to Automated Decision-Making

We may use your data for taking decisions by automated means, without any human involvement. This processing activity is taking place in compliance with the data protection regulation, respectively if: (a) it is necessary for entering into, or for performing the contract between the User/Organization and DIMA AI, (b) is authorized by Union or Member State law, or (c) we have your explicit consent.

With respect to such decisions, you have the right to (a) obtain human intervention, (b) express your point of view and, (c) contest the decision.

Exercising Your Rights: For exercising any of your rights under the data protection laws please contact us at privacy@dima-ai.com. We will make our best to respond to your request as soon as possible and always within one month.

10. Data Security and Storage

Each client's Platform is deployed on a private server with firewall and network protections, an isolated instance, and a dedicated database. Data is stored within your organization's deployment. Where sub-processors are used (e.g., LLM providers, cloud vector databases), data transfer and storage follow the configurations chosen by your organization.

We take all necessary measures to ensure that data is stored and processed in accordance with applicable data protection regulations. When data is transferred or stored outside the EU/EEA (e.g., via certain LLM or cloud providers), we implement appropriate safeguards (adequacy decisions, standard contractual clauses, or equivalent mechanisms).

We have taken appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, loss, or destruction. These measures are regularly reviewed and adapted. Your deployment benefits from infrastructure-level protections (firewall, isolated instance, separate database per client).

Security Notice: No electronic transmission is ever fully secure or error-free; please take care in deciding what information you disclose. We are not responsible for the security measures of third-party providers you choose to integrate.

11. Cookies

Cookies are small text files stored in browsers by websites. DIMA AI uses cookies only for essential purposes:

  • User authentication—session cookies to keep you logged in and verify your identity;
  • Preferences—storing UI preferences (e.g., sidebar state) where applicable.

The Platform does not use cookies for advertising, audience measurement, or third-party tracking. We do not employ analytics cookies, advertising cookies, or allow third parties to place cookies for marketing or tracking purposes. Session data (including IP address and user-agent when using session-based auth) is stored server-side within your deployment database for security and support purposes.

Additional preferences may be stored in your browser's local storage (e.g., model selection, sidebar collapse) and remain on your device.

12. Retention Period

We limit the storage period of your personal data to the time necessary to fulfill the purpose for which we have collected it and, as a general principle, for the period required or permitted by applicable law, as follows:

  • If the data is collected and processed for the purpose of a contract, we will retain such data for the entire period of its performance;
  • If the data is collected and processed with your consent, we will retain it until you withdraw such consent;
  • If the data is collected and processed based on our legitimate interest, we will retain it until such interest is fulfilled and, as a general rule, for a period of 3 (three) years from the termination of the contractual relationship;
  • If the data is collected and processed pursuant to a legal obligation, the time frame will depend on the legal provisions regarding mandatory retention periods.

Please consider that the period may be longer if we are required to store the data for the purpose of satisfying any legal, accounting or reporting obligations or to resolve any legal disputes.

Also please note that internal analytics (e.g., response times, token usage) are stored within your deployment. When data is no longer necessary for its purpose, we will remove or delete it from our systems and records and/or anonymize it so that you can no longer be identified. Afterwards, the rights related to access, erasure, rectification and transfer will not be enforceable.

13. Final Provisions

We may change this Privacy Policy at any time and the changes will apply to any Personal Data we already hold and to any new personal data collected after the change. Independently of the changes, we:

  • Compromise ourselves to always respect your privacy;
  • If we make any material changes to this Policy, we will endeavor to notify you by email or by posting a prominent notice on the Platform prior to the change becoming effective.

We encourage you to periodically review this page for the latest information as your continued use of our services after the effective date of this Privacy Policy constitutes an acceptance of the amended terms. You may refer to the "Last updated" date to determine if the Policy has changed since the date of your last visit.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@dima-ai.com

Company: GuidefAI OÜ
Postal address: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, Estonia