
Dimagi and GDPR
CertReports found no public GDPR evidence for Dimagi as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 5 May 2018
- Expires or valid through
- 4 Mar 2027
- Scope
- Dimagi offers various digital platforms that aid frontline workers in gathering actionable data. As part of this data collection process, Dimagi’s products capture and process personal information, primarily health-related. Our Privacy Policy, available at https://www.dimagi.com/terms/latest/privacy/, provides clear guidelines on how we manage and share this data. 1. Types of Data Collected and how it is used o Account Data: Personal contact details (e.g., name, address, email) and billing information required for account setup and payment. o User Content: Any data users upload or create while using Dimagi’s services, which may include personally identifiable information (PII) collected by users from their own data subjects. o Usage Information: Details about how users interact with the services, used to improve features and provide support. o Device Information: Data such as IP addresses and browser details to enhance service functionality and user support. o Cookies & Tracking Technologies: Used to remember user preferences, analyze service usage, and enhance security. o Aggregate Data Sets: Dimagi may create anonymized, aggregated data sets based on collected data for research purposes and to improve the services delivered by Dimagi. Users can opt out by contacting Dimagi. 2. Data Sharing o Internal & Trusted Partners: Third-party providers like Twillio access data only as needed to perform tasks on Dimagi’s behalf. o Analytics Tools: Services like Google Analytics, Kissmetrics, and HubSpot analyze usage. o Cloud Data Storage: Services like AWS, Microsoft Azure etc are used to store the User Content as part of delivering services to users. Here is the list of sub processor with whom we share the data (https://dimagi.atlassian.net/wiki/spaces/commcarepublic/pages/2143976145/List+of+Sub-processors)
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Dimagi: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 e09519a6fb |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Dimagi GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Nonprofit and fundraising category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Nonprofit and fundraising vendor has GDPR evidence in the index yet.