[ Legal ] Privacy
Privacy policy
The short version: we collect what we need to build and run your website and nothing more, we never sell it, advertising cookies only run if you say yes, and you can ask for a copy or its deletion any time. Our contact details are at the foot of this page.
1. Who is responsible
Lymn Media AB is the controller of the personal data described here. dirr is our product. Our registration details and contact address are in the company details at the bottom of this page.
We are not big enough to be required to appoint a data protection officer, so the person who answers that email is the person who deals with it.
2. What we collect
About you and the people at your business:
- Contact details: name, email address, phone number if you give us one.
- What you tell us about your business in the intake and the brief chat: business name, industry, city, services, prices, opening hours, style preferences, and anything else you type into it.
- Files you upload: logos, photos, documents.
- Account and billing data: your subscription, plan, term dates, invoices, and the last four digits and card type that Stripe reports back to us. We never see or store a full card number.
- Usage data: which step of the funnel you reached, which designs you looked at and picked, edit requests you sent, and support email.
- Technical data: IP address, browser and device type, and server logs, kept for security and troubleshooting.
3. Where it comes from
Almost all of it comes from you, typed into the intake, the brief chat or an email.
Two exceptions. If you give us your existing website address, we read what is publicly published on that site to prefill your answers and draft your pages. And if you connect a Google Business Profile, we read what is public on it. We do not buy personal data and we do not scrape anything that is not public.
4. Why we use it, and what allows us to
Every use of personal data needs a legal basis under the GDPR. Ours are:
- Running the service
- Building, hosting and maintaining your site, handling edit requests, sending service email, and giving support. Basis: performance of our contract with you (art. 6(1)(b)).
- Taking payment
- Subscriptions, invoices, refunds and dunning, through Stripe. Basis: performance of our contract (art. 6(1)(b)).
- Bookkeeping
- Keeping invoices and accounting records. Basis: legal obligation under Swedish accounting law (art. 6(1)(c)).
- Previews before you buy
- Generating and storing design previews from your brief so you can see real pages before paying. Basis: steps at your request before entering a contract (art. 6(1)(b)).
- Improving the product
- Aggregate and internal analysis of how the funnel and the builder perform, so we can make them better. Basis: our legitimate interest in improving a service we sell (art. 6(1)(f)).
- Security and abuse
- Rate limiting, fraud prevention, server logs, blocking abuse. Basis: our legitimate interest in keeping the service safe (art. 6(1)(f)).
- Advertising measurement
- Meta Pixel and the matching server-side events, so we can tell whether an ad worked. Basis: your consent (art. 6(1)(a)), given in the cookie banner and withdrawable at any time.
- Telling you about dirr
- Email to the business contact who started a signup and did not finish it, about that signup. Basis: our legitimate interest in following up a live enquiry (art. 6(1)(f)). Every one of those emails has an unsubscribe link.
5. Cookies and tracking
We set one cookie of our own to remember the choice you made in the banner, and nothing else until you choose. If you accept, the Meta Pixel sets its own cookies so we can measure our ads. If you decline, none of them are set and the product works exactly the same.
The cookie policy lists every cookie by name, what it does and how long it lasts.
6. Who we share it with
We do not sell personal data and we never will. We share it with the suppliers that run parts of the service for us, each under a written data processing agreement that limits them to our instructions.
The subprocessor page names every one of them, what they do and where they are.
Beyond that, we share data only when the law requires it, or when we have to in order to defend a legal claim.
7. Data outside the EU and EEA
Some of our suppliers are based in the United States, so some personal data is processed there. Where a supplier is certified under the EU-US Data Privacy Framework we rely on that. Otherwise we rely on the European Commission's Standard Contractual Clauses together with the supplier's own technical measures.
Ask us at any time and we will tell you which mechanism covers a specific supplier and send you a copy of the clauses.
8. How long we keep it
- Enquiries that never buy
- Intake answers, briefs and previews are deleted 12 months after your last activity.
- Customer accounts
- Kept while your subscription runs and for 12 months after it ends, so a returning customer keeps their site and history.
- Site content
- Deleted 90 days after an account closes, unless you ask for it sooner.
- Invoices and accounting
- Seven years, because Swedish accounting law requires it. This survives a deletion request.
- Consent records
- Three years, as proof that consent was given or refused.
- Server and security logs
- 90 days.
9. AI and your data
We use AI models to draft your pages, propose layouts and run the brief chat. What we send to those models is what you gave us about your business, plus what is publicly on your existing site.
We use those models through business APIs on terms that do not permit training on our inputs or outputs. We do not send card details, passwords or login credentials to any model.
The terms of service explain where AI sits in the build and what a person checks before your site goes live.
10. Security
Data is encrypted in transit and at rest. Access to production data is limited to the people who build and run dirr, over individual accounts with multi-factor authentication. Admin surfaces are behind authentication and are never open. Customer accounts sign in with a one time code by email, so there is no password of yours for us to lose.
If a breach happens that is likely to put you at risk, we tell you and the supervisory authority within the deadlines the GDPR sets.
11. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or send it to another provider in a portable format. You can object to anything we do on the basis of legitimate interest, and you can withdraw consent for advertising cookies at any time without affecting what happened before.
Write to the contact address in the company details at the bottom of this page, or use dirr.ai/contact, and we answer within one month. We do not charge for this, and we do not make you jump through hoops to do it.
Deleting your account data does not remove invoices we are required by law to keep.
12. Visitors to the sites we build
When someone visits a site we built for a customer and fills in its contact form, that person's details belong to our customer, not to us. In that situation our customer is the controller and we are the processor: we pass the message on, store it for them, and do nothing else with it.
The data processing terms set out that relationship in full and apply automatically to every subscription.
13. If you are in the United States
Most of our customers are American and we are a Swedish company, so European rules govern how we handle data. That works in your favour: the GDPR is stricter than most US state privacy law, and we apply it to everyone rather than running two standards.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in California and the other US state privacy laws. The advertising measurement in section 4 runs only on consent you gave in the banner, and you can withdraw it.
The rights in section 11 are open to you wherever you live. We do not make you prove you are covered by a particular statute before we answer.
14. Complaints
If you think we have handled your data badly, tell us first and we will fix it. You also have the right to complain to the Swedish Authority for Privacy Protection (IMY), https://www.imy.se, or to the supervisory authority where you live or work.
15. Changes to this policy
We update this page when what we do changes. The revision date at the bottom is the real one. If a change materially affects you, we email you before it takes effect.
Company details
- Company
- Lymn Media AB, registered in Sweden
- Registration number
- 559505-4833
- VAT number
- SE559505483301
- Registered office
- Industrigatan 4C, Stockholm, Sweden
- Contact
- hello@dirr.aior the form at dirr.ai/contact
Last updated 2026-08-12 · questions: get in touch