Skip to content
dirr.

[ Legal ] Privacy

Privacy policy

The short version: we collect what we need to build and run your website and nothing more, we never sell it, advertising cookies only run if you say yes, and you can ask for a copy or its deletion any time. Our contact details are at the foot of this page.

1. Who is responsible

Lymn Media AB is the controller of the personal data described here. dirr is our product. Our registration details and contact address are in the company details at the bottom of this page.

We are not big enough to be required to appoint a data protection officer, so the person who answers that email is the person who deals with it.

2. What we collect

About you and the people at your business:

3. Where it comes from

Almost all of it comes from you, typed into the intake, the brief chat or an email.

Two exceptions. If you give us your existing website address, we read what is publicly published on that site to prefill your answers and draft your pages. And if you connect a Google Business Profile, we read what is public on it. We do not buy personal data and we do not scrape anything that is not public.

4. Why we use it, and what allows us to

Every use of personal data needs a legal basis under the GDPR. Ours are:

Running the service
Building, hosting and maintaining your site, handling edit requests, sending service email, and giving support. Basis: performance of our contract with you (art. 6(1)(b)).
Taking payment
Subscriptions, invoices, refunds and dunning, through Stripe. Basis: performance of our contract (art. 6(1)(b)).
Bookkeeping
Keeping invoices and accounting records. Basis: legal obligation under Swedish accounting law (art. 6(1)(c)).
Previews before you buy
Generating and storing design previews from your brief so you can see real pages before paying. Basis: steps at your request before entering a contract (art. 6(1)(b)).
Improving the product
Aggregate and internal analysis of how the funnel and the builder perform, so we can make them better. Basis: our legitimate interest in improving a service we sell (art. 6(1)(f)).
Security and abuse
Rate limiting, fraud prevention, server logs, blocking abuse. Basis: our legitimate interest in keeping the service safe (art. 6(1)(f)).
Advertising measurement
Meta Pixel and the matching server-side events, so we can tell whether an ad worked. Basis: your consent (art. 6(1)(a)), given in the cookie banner and withdrawable at any time.
Telling you about dirr
Email to the business contact who started a signup and did not finish it, about that signup. Basis: our legitimate interest in following up a live enquiry (art. 6(1)(f)). Every one of those emails has an unsubscribe link.

5. Cookies and tracking

We set one cookie of our own to remember the choice you made in the banner, and nothing else until you choose. If you accept, the Meta Pixel sets its own cookies so we can measure our ads. If you decline, none of them are set and the product works exactly the same.

The cookie policy lists every cookie by name, what it does and how long it lasts.

Cookie policy

6. Who we share it with

We do not sell personal data and we never will. We share it with the suppliers that run parts of the service for us, each under a written data processing agreement that limits them to our instructions.

The subprocessor page names every one of them, what they do and where they are.

Beyond that, we share data only when the law requires it, or when we have to in order to defend a legal claim.

Current subprocessors

7. Data outside the EU and EEA

Some of our suppliers are based in the United States, so some personal data is processed there. Where a supplier is certified under the EU-US Data Privacy Framework we rely on that. Otherwise we rely on the European Commission's Standard Contractual Clauses together with the supplier's own technical measures.

Ask us at any time and we will tell you which mechanism covers a specific supplier and send you a copy of the clauses.

8. How long we keep it

Enquiries that never buy
Intake answers, briefs and previews are deleted 12 months after your last activity.
Customer accounts
Kept while your subscription runs and for 12 months after it ends, so a returning customer keeps their site and history.
Site content
Deleted 90 days after an account closes, unless you ask for it sooner.
Invoices and accounting
Seven years, because Swedish accounting law requires it. This survives a deletion request.
Consent records
Three years, as proof that consent was given or refused.
Server and security logs
90 days.

9. AI and your data

We use AI models to draft your pages, propose layouts and run the brief chat. What we send to those models is what you gave us about your business, plus what is publicly on your existing site.

We use those models through business APIs on terms that do not permit training on our inputs or outputs. We do not send card details, passwords or login credentials to any model.

The terms of service explain where AI sits in the build and what a person checks before your site goes live.

How we use AI

10. Security

Data is encrypted in transit and at rest. Access to production data is limited to the people who build and run dirr, over individual accounts with multi-factor authentication. Admin surfaces are behind authentication and are never open. Customer accounts sign in with a one time code by email, so there is no password of yours for us to lose.

If a breach happens that is likely to put you at risk, we tell you and the supervisory authority within the deadlines the GDPR sets.

11. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or send it to another provider in a portable format. You can object to anything we do on the basis of legitimate interest, and you can withdraw consent for advertising cookies at any time without affecting what happened before.

Write to the contact address in the company details at the bottom of this page, or use dirr.ai/contact, and we answer within one month. We do not charge for this, and we do not make you jump through hoops to do it.

Deleting your account data does not remove invoices we are required by law to keep.

12. Visitors to the sites we build

When someone visits a site we built for a customer and fills in its contact form, that person's details belong to our customer, not to us. In that situation our customer is the controller and we are the processor: we pass the message on, store it for them, and do nothing else with it.

The data processing terms set out that relationship in full and apply automatically to every subscription.

Data processing terms

13. If you are in the United States

Most of our customers are American and we are a Swedish company, so European rules govern how we handle data. That works in your favour: the GDPR is stricter than most US state privacy law, and we apply it to everyone rather than running two standards.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in California and the other US state privacy laws. The advertising measurement in section 4 runs only on consent you gave in the banner, and you can withdraw it.

The rights in section 11 are open to you wherever you live. We do not make you prove you are covered by a particular statute before we answer.

14. Complaints

If you think we have handled your data badly, tell us first and we will fix it. You also have the right to complain to the Swedish Authority for Privacy Protection (IMY), https://www.imy.se, or to the supervisory authority where you live or work.

15. Changes to this policy

We update this page when what we do changes. The revision date at the bottom is the real one. If a change materially affects you, we email you before it takes effect.

Company details

Company
Lymn Media AB, registered in Sweden
Registration number
559505-4833
VAT number
SE559505483301
Registered office
Industrigatan 4C, Stockholm, Sweden
Contact
hello@dirr.aior the form at dirr.ai/contact

Last updated 2026-08-12 · questions: get in touch