COMPLIANCE & DATA PROTECTION NOTICE
Dimennet is committed to maintaining the highest standards of data compliance across jurisdictions. This section outlines our data protection obligations and your rights under applicable data regulations, including international frameworks such as the Data Processing Agreement (DPA), General Data Protection Regulation (GDPR), Personal Data Protection Acts (PDPA — Singapore & Malaysia), and the California Consumer Privacy Act (CCPA).
1. Data Processing Agreement (DPA)
When Dimennet processes data on behalf of a client as a service provider or consultant, we do so under strict contractual terms that ensure:
- Data is processed only according to client instructions
- Data remains the property of the client
- No unauthorized subcontracting without client approval
- Confidentiality is observed by all personnel
- Appropriate technical and organizational security measures are enforced
- Data is not transferred to third parties except where legally necessary or contractually agreed
Clients may request a signed DPA for additional legal assurance when engaging Dimennet for services.
2. GDPR Compliance – for EU/EEA Users
For users in the European Union or EEA, Dimennet adheres to GDPR principles of:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
Your GDPR rights include:
- Right to access personal information
- Right to correction
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to data processing
- Right not to be subject to automated decision-making
3. PDPA – Singapore & Malaysia
Dimennet complies with applicable PDPA regulations governing the handling of personal and professional information, including:
- Obtaining consent for data collection
- Limiting collection to relevant and necessary data
- Preventing unauthorized access, disclosure, or misuse
- Allowing users to correct or request removal of data
- Ensuring responsible retention and disposal practices
We do not collect national ID, passport numbers, or sensitive financial information unless explicitly required for compliance or verification.
4. CCPA Compliance – for California Users
For California-based users and clients, Dimennet provides:
You have the right to:
- Know what personal data is collected
- Know whether your data is sold or disclosed and to whom
- Request access to your data
- Request deletion of your data
- Opt-out of data selling practices (Dimennet does not sell personal data)
- Receive equal service and pricing without discrimination regardless of privacy choices
Dimennet does not sell or trade consumer data and does not monetize user information.
5. Lawful Basis of Processing
Dimennet processes personal information only when at least one lawful basis applies:
- Contractual necessity — to fulfill service engagements
- Legitimate interest — operational or analytical
- User consent — explicitly granted
- Legal obligation — regulatory compliance or documentation
- Security & fraud prevention
6. Cross-Border Data Transfer
As a cloud consulting service, data may be processed on servers located in different geographies. When data is transferred internationally:
- Transfers comply with relevant laws
- Standard Contractual Clauses (SCCs) may be applied
- Equivalent data protection safeguards are enforced
- Access is restricted to authorized personnel only
7. Data Breach Response Commitment
In the event of a data breach affecting personal or client-owned data:
- We will take immediate mitigation measures
- We will notify affected parties promptly
- We will maintain documentation for compliance and legal audit
- We will cooperate with regulatory authorities where required
8. Contact for Data & Compliance Matters
For requests or inquiries relating to the rights and regulations described above, please contact: [email protected] or reach out at CONTACT US.