Security and privacy are core to how we build and run Dime.Scheduler. The service runs on a tier-1 European cloud platform that is independently certified under internationally recognised standards including ISO 27001 and SOC 2 Type 2 (see Hosting and infrastructure for the full list), and Dime Software operates a defined set of engineering, operational, and access controls on top of it (see Application security and engineering practices).
Our internal practices are organised around the same control areas that underpin those frameworks: access management, secure development, logging and monitoring, incident response, and business continuity. Dime Software does not yet hold its own ISO 27001 or SOC 2 certification, but we operate as if we did, and we are happy to walk security and procurement teams through our controls in detail.
As a Belgian company, Dime Software operates under the EU General Data Protection Regulation (GDPR) and applies its principles in how we collect, process, and retain personal data: lawful basis, purpose limitation, data minimization, and the rights of data subjects. See our Privacy Policy for the formal statement of these rights and how to exercise them.
Privacy by design
Privacy and data minimization are deliberate product choices, not afterthoughts. Dime.Scheduler is intentionally built as a thin scheduling layer on top of a customer's back-office system: the master records customers care about (resources, jobs, customers, items) stay in the system of record, and we hold only the operational data needed to run the planning board. That keeps the volume and sensitivity of data we process on customers' behalf small by design.
Data Processing Agreement
A Data Processing Agreement (DPA) covering how we process personal data on behalf of customers is available on request. Email [email protected] and we will send it over.