[ Legal ] Data processing
Data processing terms
When someone fills in the contact form on the site we built you, their details are yours, not ours. This is the article 28 agreement that says so, and it applies to every subscription without anyone signing anything.
1. When these terms apply
These terms apply automatically to every dirr subscription and form part of your agreement with Lymn Media AB. You do not need to sign anything.
They cover only the personal data we process on your behalf. Data about you and your account is a different matter, and the privacy policy covers that, where we are the controller rather than the processor.
2. Who is who
You are the controller. You decide that your site collects enquiries and what you do with them afterwards.
We are the processor. We run the site, receive what its visitors submit, store it and pass it to you. We do not decide what it is for and we do not use it for anything of our own.
3. What we process for you
- Subject matter
- Building, hosting and running your website, and delivering what its visitors send you.
- Duration
- For as long as your subscription runs, plus the deletion period in section 9.
- Nature and purpose
- Hosting, storage, transmission by email, and the automated generation and editing of your pages.
- Categories of people
- Visitors to your site, people who submit your contact or booking forms, and the staff at your business whose details appear on your pages.
- Types of data
- Name, email address, phone number, the message a visitor types, the time of submission, and the technical data a web server necessarily sees such as IP address and browser. Anything else is whatever you or your visitors choose to put in a form field.
- Special category data
- None. Do not configure a form to collect health, biometric, political or similar data. If you need to, talk to us first, because it changes what both of us have to do.
4. Our instructions
We process this data only on your documented instructions. Your instructions are this document, the subscription agreement, and what you configure or ask for in writing through the dashboard or by email.
If we ever have to process something because the law requires it, we tell you first unless the law forbids us from telling you.
If we think an instruction of yours breaks data protection law, we say so and we do not carry it out.
5. Confidentiality
Everyone at dirr with access to this data is bound by confidentiality obligations and gets access only where their work requires it. Access is over individual accounts with multi-factor authentication, and it is removed when it stops being needed.
6. Security
We keep appropriate technical and organisational measures under article 32: encryption in transit and at rest, least privilege access, isolation between customers, authentication on every non-public surface, rate limiting, logging, and backups.
We do not claim these measures are perfect. We claim they are appropriate to the risk of a small business website, and we review them when the risk changes.
7. Subprocessors
You give us general written authorisation to use subprocessors. The current list is published and we keep it current.
Before we add one that touches your data, we email you at least 30 days beforehand. If you object on reasonable data protection grounds and we cannot offer you an alternative, you can end your subscription without paying for the remaining months of the term.
Each subprocessor is bound by written terms at least as protective as these, and we stay responsible to you for what they do.
8. Helping you meet your own obligations
If one of your site's visitors asks you for access, correction, deletion or a copy of their data, we help you answer. If such a request comes to us directly, we do not answer it ourselves. We forward it to you, because it is yours to answer.
We tell you without undue delay, and in any case within 48 hours, if we become aware of a personal data breach affecting your data, with what we know about what happened, who is affected and what we are doing.
We help you with data protection impact assessments and with any consultation of a supervisory authority, to the extent the information is ours to give.
9. Deletion and return
When your subscription ends you can ask us for a copy of your site content and your collected leads, and we send it in a usable format.
We delete this data 90 days after the subscription ends, unless you ask us to delete it sooner or the law requires us to keep something. Backups age out on their own cycle and are deleted with it.
10. Showing our work
We make available the information you reasonably need to show that we are meeting these obligations, including our security measures and our subprocessor terms.
You can audit us, once a year and on 30 days notice, or more often if a supervisory authority requires it or after a breach affecting your data. In practice that means answering a written questionnaire and, if that is not enough, a remote session with the people who run the systems. You cover your own costs.
11. Transfers, and a signed copy
Some of our subprocessors are outside the EU and EEA. Where a supplier is certified under the EU-US Data Privacy Framework we rely on that. Otherwise we rely on the European Commission's Standard Contractual Clauses, which are incorporated into these terms, with you as data exporter and the supplier as data importer.
If your own compliance needs a signed document rather than a page, ask at dirr.ai/contact and we will sign a copy of these terms and send it back. The terms are identical either way.
12. What happens if these terms and the main terms disagree
On anything about the processing of personal data on your behalf, these terms win. On everything else, the subscription agreement wins.
Company details are in the terms.
Last updated 2026-08-12 · questions: get in touch