How we handle your data at Dimel
Last updated: 7 August 2026.
Dimel is a platform that gives businesses an AI-powered WhatsApp assistant, an admin panel, and order and appointment management tools. This notice explains what personal data we process, for what purpose, and what rights you have — whether you run a business using Dimel, or you're an end customer of one of those businesses messaging them on WhatsApp.
One important point: two different roles
If your business uses Dimel, we process your own end customers' data on your behalf — you decide what information to collect and how to use it; we only process it technically to provide you the service. Toward your end customers, you remain responsible for that relationship; we are your technology provider (what the law usually calls a "processor").
What data we collect
| From businesses (our direct customers) | From their end customers (via WhatsApp) |
|---|---|
| Business name, email, WhatsApp number, password (encrypted) | Phone number |
| Business configuration: hours, catalog, prices | Content of messages sent to the assistant |
| Team accounts (name, role) | Name (if provided), orders, booked appointments |
If you requested demo access
To request access we collect your name, your email, your business name and its industry, and optionally a phone number and a message. They are used to give you access and to reply about your enquiry, nothing else: they are not used for advertising and are not shared with anyone. If the enquiry doesn't end in an account, that data is deleted automatically after 90 days — sooner if you ask us at magallanesdimel@gmail.com.
What we use this data for
- Automatically replying to WhatsApp messages, consistent with each business's information.
- Recording and pricing orders against each business's real catalog.
- Booking appointments when a business enables that feature.
- Showing each business its own conversations, customers, and reports in its panel.
- Keeping an access audit trail, for security.
Legal basis
We process this data because it's necessary to provide the contracted service (contract performance), and, for security and audit records, because of a legitimate interest in protecting the platform and our customers from unauthorized access.
Who we share data with
We don't sell data to anyone. To operate the platform, we use the following providers, which process data on our behalf under their own data protection commitments:
| Provider | What for |
|---|---|
| Anthropic (Claude) | Generates the assistant's replies from message content |
| Meta (WhatsApp Cloud API) | WhatsApp messaging infrastructure |
| Render | Hosts the application and database |
| Supabase | Database and file storage (catalog photos) |
| Google Calendar (optional) | Only if the business enables appointment booking |
| Google Speech-to-Text (optional) | Transcribes voice notes sent by end customers, only if the business has that feature enabled |
| Outbound email provider (optional) | Sends the platform's emails: password recovery, payment reminders and the demo access link |
International transfers
Some of these providers process data outside Switzerland, including in the United States. When this happens, we rely on the transfer mechanisms recognized by Swiss data protection law (revFADP/nFADP) for such cases, such as standard contractual clauses or recognized adequacy frameworks.
How long we keep data
We retain data for as long as a business keeps its account active on the platform. If a business closes its account, its data and its end customers' data are deleted within 90 days, unless we're legally required to keep it longer. Deletion also covers files stored outside the database — catalogue photos, logo and uploaded documents — which are removed from storage along with everything else.
Security
- Passwords are stored encrypted (bcrypt), never in plain text.
- Every business is isolated from the others — none can see another's data.
- Login attempt limits to slow down brute-force attacks.
- An audit trail of who logged in and what changed in each account.
Your rights
You can request access, correction, deletion, or object to the processing of your personal data by writing to magallanesdimel@gmail.com. If you're an end customer of a business using Dimel, we recommend contacting that business directly first — it decides what data of yours it keeps; we only provide it the technical means to serve you. The concrete steps to request deletion are in how to delete your data.
Cookies
We only use our own technical cookies: those strictly necessary for the service to work. We don't use advertising or tracking cookies, nor any third-party analytics. That's why you won't see a banner asking for permission: the law only requires it for cookies that aren't necessary, and we set none.
| Cookie | What it does |
|---|---|
| panel_session_… | Keeps you signed in to your business panel. |
| csrf_login | Protects the sign-in form against forged requests from another site. |
| panel_lang | Remembers the language you chose, so we don't ask again. |
| demo_visitante | Only in the demo: tells visitors apart to apply the message limit. It doesn't identify the person and isn't combined with any other data. |
All of them are first-party — set by this site, not by a third party — and are marked HttpOnly, so no script can read them.
Minors
Dimel is not directed at minors. We do not knowingly collect data from minors as direct users of the platform.
Changes to this notice
We may update this notice if our providers or how we process data change. We will always post the last-updated date above.
Questions about this notice? Write to us at magallanesdimel@gmail.com.