Legal

Privacy Policy

Version 1.4. Last updated 24 August 2026.

1. Who we are

Dimax Pro ("we") operates a B2B platform connecting brands with AI influencer owners. This policy explains how we handle your personal data in line with the GDPR and applicable laws.

2. Data we collect

Account information (name, company, email, country, phone), profile and listing data, chats sent through the platform, and transaction data needed to process bookings. Payment details are handled by our payment processor (Stripe); we do not store full card data.

If you sign up or sign in with Google, we receive your basic Google profile — your name, your email address and your profile picture. We use the name and email to create and run your account; we do not ask Google for anything else.

We also process technical data needed to run and secure the platform: when something on the platform breaks, an error report is generated — what failed, on which page, and the browser type — so that we can fix it. These reports are configured to exclude your identity and the content of your requests.

We keep a security log. When a request looks like an attempt to abuse the platform — a failed bot check, a request rate far above normal use, or an attempt to change data the account has no right to change — we record what happened, the page or endpoint involved, the account involved if it was signed in, and the IP address the request came from. We use this log to protect the platform and its users and to prevent fraud and abuse. Section 8 says how long it is kept.

3. Cookies and device storage

We only place cookies and device storage that are strictly necessary to run the platform: keeping you signed in, completing sign-in with Google, protecting our forms against bots (Cloudflare Turnstile), and keeping an unsent form on your own device. We do not use advertising cookies, analytics cookies or session recording. The full list, with each cookie's name, purpose and duration, is published in our Cookie Policy at dimaxpro.com/cookies.

4. How we use your data

To provide and secure the service, process bookings and payments, moderate the platform, detect and prevent fraud and abuse, communicate with you, and comply with legal obligations.

5. Sharing and international transfers

We share data with service providers that help us run the platform, under appropriate agreements: Supabase (database, sign-in and file storage), Stripe (payments), Resend (the emails the platform sends), Vercel (hosting), Cloudflare (the Turnstile bot check on our forms), and Sentry (error monitoring). The error reports described in Section 2 are processed for us by Sentry (Functional Software, Inc.) on servers in the United States; where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards such as standard contractual clauses. We do not sell your personal data.

6. Your rights

Under the GDPR you may access, correct, delete, or port your data, and object to certain processing. To exercise these rights, contact Dimax Pro support. Section 7 below sets out exactly what deleting your account removes, what it does not, and why.

7. Deleting your account

You can delete your account yourself, from your account settings. You cannot delete it while a campaign involving you has been paid for and is not yet completed or cancelled: those campaigns have to end first, or be cancelled by us.

When you delete your account we delete your login, your notifications, your verification codes, the verification documents you uploaded, your applications to list an AI influencer, and the images of your AI influencers.

What we do not delete is the record of what was transacted and agreed, because it is also the other party's record of a campaign they paid for. We remove you from it instead. Your messages keep their text, their date and their place in the conversation, but no longer identify you as the sender. Your campaigns keep their financial record; the brief, including its edit history, is deleted, and the campaign name is replaced. Your payments keep their amounts and dates without your identity. An AI influencer of yours that has campaigns or reviews against it is emptied and archived rather than deleted, and shown as a removed listing.

Records of your acceptance of these documents are not deleted. They are what evidences the agreement, they are kept as described in clause 25.4 of the Terms of Service, and they hold your user identifier and the email address you had at the time.

8. Data retention & security

We keep data only as long as needed for the purposes described or as required by law, and apply reasonable security measures to protect it.

Messages sent through the platform are retained. They are filtered automatically as described in clause 14.4 of the Terms of Service, and our staff can read a conversation where that is needed to moderate the platform, to keep it secure, or to resolve a dispute about a campaign — including a conversation the automatic filter has flagged for review.

The security log described in Section 2 is short-lived: individual events are deleted after 30 days, and the aggregated alerts built from them after 90 days. Records of your acceptance of these documents are kept as described in Section 7.

Our database is backed up daily and backups are kept for 7 days. Data that is deleted — including when you delete your account — can therefore persist in backups for up to 7 days before it is gone from them too. Backups are used only to restore the platform after a failure.

9. Contact

For privacy questions or requests, contact Dimax Pro support.

Privacy Policy version 1.4, in force from 24 August 2026, replacing version 1.3 of 19 August 2026, which remains available at /privacy/1.3. For privacy questions or requests, contact Dimax Pro at contact@dimaxpro.com.

All published versions: 1.4 (shown) — current · 1.3 · 1.2 · 1.1 · 1.0