1. Who we are
Drimt ("we", "us") provides Digital Risks Management Tools — an AI-powered platform for identifying, anonymizing and mitigating digital, cyber and ESG risks. This policy explains what personal data we process when you use drimt.ai and our application.
2. Data we collect
- Account data: email, display name, workspace name, authentication identifiers.
- Billing data: processed by our payment provider Stripe (we never store full card numbers). We retain customer ID, subscription status, invoices and tax information.
- Usage data: pages visited, features used, error logs and timestamps.
- Connector data: logs and metadata you send from connected sources (Linear, GitHub, etc.).
3. Anonymization by design
All ingested logs pass through our Crypto Anonymization Engine before AI analysis. Personal identifiers, secrets and tokens are stripped or hashed at the edge.
4. Legal basis (GDPR)
- Contract — to deliver the service you subscribed to.
- Legitimate interest — security, fraud prevention, product improvement.
- Legal obligation — accounting, tax, regulatory requests.
- Consent — optional analytics or marketing communications.
5. Sub-processors
- Supabase / Lovable Cloud — hosting, database, authentication.
- Stripe — payment processing and tax compliance.
- Google, OpenAI — AI inference (anonymized inputs only).
6. Retention
Account data is retained while your workspace is active and for up to 90 days after deletion. Invoices are retained for 10 years to meet tax obligations.
7. Your rights
Under GDPR you can request access, rectification, erasure, portability, or object to processing. Email privacy@drimt.ai.
8. International transfers
Data is hosted in the EU. Transfers outside the EU rely on Standard Contractual Clauses.
9. Cookies
We use cookies and similar technologies to keep you signed in and to operate the service. See our Cookie Policy for details.
10. Contact
Drimt — privacy@drimt.ai