dibby
Platform
Industries
Private equityMore funds. Same team.Financial marketsEvery trade, under control.
Enterprise
Log inBook a demo
Book a demo
Legal information

Terms of service

The terms of our work with your business.

French version is authoritative17 September 2026
PrivacyTerms of service

In this document

  1. 1. Provider and scope
  2. 2. Contract documents and acceptance
  3. 3. Services and order scope
  4. 4. Accounts, permissions and access security
  5. 5. Customer data and content
  6. 6. Workflows, agents and artificial intelligence
  7. 7. Integrations and third-party services
  8. 8. Hosting, maintenance and support
  9. 9. Term, renewal and changes to the offering
  10. 10. Prices, invoicing and payment
  11. 11. Intellectual property
  12. 12. Personal data protection
  13. 13. Confidentiality
  14. 14. Liability
  15. 15. Suspension and termination for breach
  16. 16. Exit assistance and end of service
  17. 17. Force majeure
  18. 18. Changes, notices and governing law
  19. Annex A. Personal data processing agreement
  20. Annex B. Particulars to complete before signing

A question about your data?

[email protected]
The French version is authoritative.

This English translation is provided for convenience. In case of any discrepancy, the French text prevails.

Lire la version française
Document contents
  1. 1. Provider and scope
  2. 2. Contract documents and acceptance
  3. 3. Services and order scope
  4. 4. Accounts, permissions and access security
  5. 5. Customer data and content
  6. 6. Workflows, agents and artificial intelligence
  7. 7. Integrations and third-party services
  8. 8. Hosting, maintenance and support
  9. 9. Term, renewal and changes to the offering
  10. 10. Prices, invoicing and payment
  11. 11. Intellectual property
  12. 12. Personal data protection
  13. 13. Confidentiality
  14. 14. Liability
  15. 15. Suspension and termination for breach
  16. 16. Exit assistance and end of service
  17. 17. Force majeure
  18. 18. Changes, notices and governing law
  19. Annex A. Personal data processing agreement
  20. Annex B. Particulars to complete before signing

Terms of service - version dated 17 September 2026. These terms govern the provision and use of dibby services by businesses. They are supplemented by the order and its schedules, including the data processing agreement below.

1. Provider and scope

Dibby, a French simplified joint-stock company registered with the Paris Trade and Companies Register under number 939 503 181, with its registered office at 70 avenue de la Grande Armée, 75017 Paris, France (“dibby”), provides a platform for creating and operating business applications, workflows and artificial intelligence agents. Contractual and personal data contact: [email protected].

These terms (“Terms”) apply exclusively to legal entities and individuals acting for the purposes of their professional activity (“Customer”). Employees, contractors and other permitted individuals access the service on the Customer’s behalf (“Authorised Users”). Registering as an Authorised User does not make that individual a Customer in a personal capacity.

The person subscribing represents that they have authority to bind the Customer. These Terms are not intended for consumer subscriptions; they nevertheless preserve any mandatory provisions applicable to a Customer, including particular cases of off-premises contracts between professionals.

2. Contract documents and acceptance

The contract comprises the accepted quotation or order form, its service and security schedules, the data processing annex below and these Terms. Specific terms take precedence over these Terms. For personal data protection, the data processing annex prevails over conflicting provisions, without reducing mandatory GDPR requirements. The Customer’s purchasing terms apply only if expressly accepted by dibby in writing.

The contract takes effect on the date agreed in the order. The accepted version of the Terms, the date and evidence of acceptance are retained and made available to the Customer. A durable copy of the contract can be saved or printed.

3. Services and order scope

Depending on the subscribed offering, the services enable Customers to organise data, build applications, collaborate, connect third-party systems and run workflows or agents. The order specifies available features, usage limits, implementation assistance, hosting arrangements, any availability commitments and support arrangements.

A demonstration, mock-up or feature announced on the roadmap is not a delivery commitment unless expressly included in the order. Experimental features are identified as such and must not be used for critical operations without an appropriate agreement.

The Customer defines its requirements and approves delivered configurations against the agreed criteria. Additional services, migrations, bespoke development or capacity increases require agreement on their scope and price before performance.

4. Accounts, permissions and access security

The Customer appoints its administrators, reviews its Authorised Users’ permissions and revokes access that is no longer needed. Credentials are individual; API keys, secrets and access tokens must not be shared beyond authorised people or systems. Service accounts and agents receive permissions limited to their tasks.

dibby provides the access controls within its service scope. The Customer remains responsible for the permissions it configures, its devices and the systems it connects. Each party reports any compromise of which it becomes aware without undue delay and cooperates to limit the consequences.

Bypassing access controls, accessing another customer’s data, introducing malicious code or conducting intrusive tests without written authorisation is prohibited. These restrictions do not limit rights that cannot lawfully be excluded.

5. Customer data and content

The Customer retains its rights in data, documents, instructions and content it supplies or produces in its workspaces (“Customer Data”). Software elements, applications, workflows and configurations generated using dibby are subject to the separate provisions in Article 11, without transferring to dibby the Customer’s pre-existing rights in its own contributions. The Customer warrants that it has the rights and lawful bases needed to process its data and make it available to the service.

Customer Data is private by default. Access depends on permissions and sharing features expressly enabled by the Customer. Uploading data or creating an account does not make that data public.

The Customer authorises only the operations necessary to provide, secure, maintain and support the services, within its instructions and the contract. dibby does not sell this data or reuse it to train its own or third-party models. Any other purpose requires a separate agreement and an appropriate lawful basis; it does not arise from these Terms.

Commercial references. Unless the Customer objects or the order provides otherwise, the Customer grants dibby a non-exclusive, royalty-free authorisation to name it and reproduce its logo, together with testimonials it supplies for publication, on dibby’s website and commercial presentation materials accessible worldwide. This authorisation applies during the contractual relationship and subsequently for as long as the reference remains accurate and relevant; it does not permit a former customer to be presented as a current customer. It covers neither non-public Customer Data nor an endorsement, result or testimonial the Customer has not actually expressed.

The Customer may refuse this use when subscribing or object subsequently by emailing [email protected]. dibby stops further distribution and removes the reference from materials under its control within thirty days of receiving the request. Elements containing an individual contact’s name, image or other personal data remain subject to that person’s rights and, where necessary, consent; the Customer’s acceptance does not replace them.

6. Workflows, agents and artificial intelligence

Agents and workflows operate within their configuration, assigned permissions and enabled integrations. The Customer defines permitted actions, human approvals, thresholds and any business restrictions. dibby remains responsible for its own security obligations and the proper execution of agreed configurations.

AI outputs may be inaccurate, incomplete or unsuitable. The Customer arranges checks proportionate to the consequences of their use, particularly before a decision affecting a person, a payment, an external communication or a regulated operation. The service does not, by itself, constitute legal or financial advice or a compliance assessment.

Limitations and responsibility for automated uses. Unless expressly committed in the order, dibby does not guarantee the accuracy, completeness or suitability of generated outputs for a particular purpose, or the achievement of a commercial or regulatory outcome. The Customer remains responsible for decisions and actions it takes or authorises based on those outputs, including when it chooses automatic execution without human approval.

Within the limits of Article 14 and applicable law, dibby is not liable for damage arising from incorrect instructions or data supplied by the Customer, permissions or configurations defined by it, use contrary to the documentation or reliance on outputs without the required checks, to the extent that the damage is not attributable to a breach by dibby. These exclusions do not cover defects in access controls for which dibby is responsible or failure to execute agreed configurations correctly.

The models, providers and processing arrangements used for a feature are documented before activation. A model selected or supplied by the Customer remains subject to the agreed allocation of responsibilities and, when processing personal data, the data processing annex.

Uses prohibited by law are forbidden. Uses subject to particular obligations, including solely automated decisions producing legal effects or high-risk AI systems, require prior assessment and appropriate contractual arrangements. Access to dibby alone does not establish that such a use is compliant.

7. Integrations and third-party services

The Customer authorises connections to its systems and checks that the necessary permissions are in place. It may revoke authorisations through the means provided by the service or relevant provider. Granted permissions must remain proportionate to the need.

Third-party services selected directly by the Customer are subject to their own terms. dibby informs the Customer of known limitations affecting an integration and remains responsible for the subprocessors it appoints under the contract. Dependency on a third party is not a general exclusion of liability.

8. Hosting, maintenance and support

The order specifies whether the service runs on infrastructure managed by dibby, in the Customer’s cloud environment or on other agreed infrastructure. Processing locations, operating responsibilities, backups and recovery procedures are documented for the selected deployment.

dibby implements risk-appropriate security measures and maintains components within its scope. The Customer maintains components within its own scope. Planned work likely to interrupt the service is announced with reasonable notice; urgent security work may occur without prior notice, with information provided as soon as possible.

These Terms alone do not guarantee an availability rate, recovery time or certification. Measurable commitments, support hours and any service credits are set out in a specific service agreement. This provision does not relieve dibby of its obligation to provide the agreed services with due care.

9. Term, renewal and changes to the offering

The initial term, billing periods and renewal arrangements are stated before ordering. Automatic renewal applies only where expressly provided. Unless a different notice period is accepted in the order, either party may give notice of non-renewal at least thirty days before expiry, or up to the day before expiry for a monthly subscription.

A materially adverse change is announced at least thirty days in advance and gives the Customer the option to terminate before it takes effect, with reimbursement of prepaid amounts for the period not provided.

10. Prices, invoicing and payment

Prices exclude taxes and follow the currency, volumes and payment schedule in the order. Applicable taxes are added to invoices. Credits, quotas, overages and expiry terms are presented before subscription. No paid option or quota increase is activated without the Customer’s authorisation through the agreed mechanism.

Unless another lawful payment date is agreed, invoices are payable within thirty days of issue. Disputes must be explained and undisputed amounts remain payable. Price changes are notified at least thirty days before application and do not retrospectively affect a period already subscribed at a fixed price.

Late payment automatically incurs interest from the day following the due date, without a reminder, at the European Central Bank refinancing rate plus ten percentage points, determined in accordance with Article L. 441-10 of the French Commercial Code, together with the fixed recovery charge of €40. Additional recovery costs may be claimed with supporting evidence where the legal conditions are met. Statutory exceptions, including those relating to insolvency proceedings, remain applicable.

11. Intellectual property

dibby and its licensors retain rights in the platform, its components, documentation and improvements. For the term and scope of the contract, the Customer receives a non-exclusive right to use them for its professional needs and those of its Authorised Users.

Applications created with dibby, including through AI. Creating an application, workflow, configuration or code using the service, paying a subscription or purchasing implementation assistance does not automatically assign to the Customer any intellectual property rights held by dibby in those elements. The Customer receives the right of use described above to operate its applications within the service.

Any assignment of those rights to the Customer, particularly for operation independently of dibby, requires a specific written and signed assignment agreement. It identifies the deliverables and rights actually assigned, their scope, permitted purposes, territory, duration, source code delivery arrangements and agreed remuneration. Without it, no assignment may be inferred solely from generating or using the application. The platform, its pre-existing components and third-party elements remain excluded from any assignment unless expressly included and subject to the necessary rights.

This provision concerns only existing, transferable rights held by dibby; it does not create rights in an AI output that is not legally protectable or guarantee its exclusivity. The Customer’s rights in its own data and pre-existing contributions, third-party licences and mandatory export or provider-switching rights remain unaffected. The absence of an assignment agreement does not permit refusal to return Customer Data and exportable assets under Article 16.

12. Personal data protection

Each party complies with the GDPR, the French Data Protection Act and other applicable legislation in its respective role. For business data processed on the Customer’s instructions, dibby acts as processor; the Customer is the controller or, when acting for another party, a processor with the necessary authorisation. Annex A applies to these processing activities.

For managing its contacts, commercial relationship, legal obligations and its own security or usage analytics purposes, dibby acts as controller as described in its privacy policy. That role does not authorise dibby to reuse business data for its own purposes.

The Customer informs its Authorised Users about processing activities it conducts itself. dibby’s session recording and other non-essential tracking are only activated after the individual makes the required choice. Refusing or withdrawing permission does not prevent access to the service’s essential features. Signing the contract does not allow an administrator to consent on behalf of all users.

13. Confidentiality

Each party protects non-public information received from the other and restricts access to people who need to know it and are subject to appropriate confidentiality obligations. It uses the information only to perform the contract.

This obligation does not cover information that becomes public without fault, was already lawfully known, is lawfully received from a third party or is independently developed. Legally required disclosure is limited to what is necessary and preceded by notice where permitted by law.

The obligation continues for three years after the contract ends, for as long as necessary for personal data, and for trade secrets for as long as they meet the legal conditions for protection.

14. Liability

Each party is liable for direct and foreseeable damage caused by a proven breach of its obligations. To the extent permitted by law, dibby’s aggregate liability under the contract is capped at the fees excluding taxes paid or payable for the affected services during the twelve months preceding the event giving rise to the claim. Indirect losses, including loss of commercial opportunity or reputational harm, are excluded within the same legal limits.

These limitations do not apply to fraud, gross negligence, personal injury or liability that cannot lawfully be limited. They do not deprive an essential obligation of its substance. They do not limit data subjects’ rights or an authority’s powers under the GDPR. Recourse between controllers and processors remains governed by applicable mandatory provisions.

The Customer does not assume responsibility for dibby’s own breaches. Claims are notified with useful supporting information within a reasonable time, without contractually shortening statutory limitation periods.

15. Suspension and termination for breach

In the event of a breach, the affected party may terminate after a written notice remains unremedied for fifteen days, specifying the breach and the intended consequence.

Immediate suspension, restricted to the necessary scope, is possible in the event of a security threat, manifestly unlawful use or legal obligation. dibby explains the reasons as soon as possible and restores the service once the cause has ceased. Non-payment justifies suspension only after notice and a reasonable opportunity to remedy it.

Termination does not release the Customer from payment for services properly due. If termination results from an unremedied breach by dibby, the prepaid period not provided is reimbursed. Confidentiality, return, deletion and provisions intended to survive the contract remain applicable.

16. Exit assistance and end of service

The Customer may request the return of its exportable data and digital assets, including metadata needed to use them, in a structured, commonly used format. The scope, formats, retrieval methods and any exclusions justified by third-party rights are described before ordering. An exclusion must not prevent mandatory provider-switching rights.

Where Chapter VI of Regulation (EU) 2023/2854 (“Data Act”) applies, dibby facilitates switching providers or transferring to the Customer’s infrastructure within the periods and safeguards required by that regulation. The notice period does not exceed two months; the transition period does not exceed thirty calendar days, subject to lawful, documented extensions. A retrieval period of at least thirty days follows the transition. Continuity and security are maintained in accordance with applicable obligations.

Switching charges must not exceed statutory limits and are abolished from 12 January 2027 where that obligation applies. Separate services must not be used to circumvent this rule.

After the retrieval period, or upon a valid deletion instruction, dibby deletes data in accordance with Annex A. Data retained to meet a legal obligation is isolated and restricted to that purpose. Operational deletion and backup rotation deadlines must be set in the processing particulars before signature.

17. Force majeure

In a force majeure event within the meaning of Article 1218 of the French Civil Code, the affected party informs the other without undue delay, explains the consequences and takes reasonable measures to limit them. Affected obligations are suspended for the duration of the impediment. If it continues for more than thirty days, either party may end the affected services by written notice, without prejudice to amounts due for services already performed.

18. Changes, notices and governing law

A new version of these Terms has no retrospective effect. Material changes are notified on a durable medium at least thirty days before application and obtain any required agreement; they do not silently replace the accepted version. The exit rights in Article 9 remain applicable.

Contractual notices are sent to the contacts designated in the order. The Customer keeps these details up to date. If a provision is unenforceable, the remaining provisions continue unless the essential balance of the contract is affected.

French law governs the contract. The parties seek an amicable solution without preventing urgent or protective measures. FOR DISPUTES BETWEEN PARTIES ALL ACTING IN THE CAPACITY OF TRADERS, EXCLUSIVE JURISDICTION IS EXPRESSLY GIVEN TO THE COMPETENT COURTS OF PARIS, subject to mandatory rules. In other cases, statutory jurisdiction rules apply.

The French version is authoritative. This English translation is provided for convenience; if there is a discrepancy, the French text prevails.

Annex A. Personal data processing agreement

This annex governs processing entrusted to dibby under Article 28 of the GDPR. It does not replace Customer-specific processing particulars, which must be completed and approved before any processing takes place.

A.1. Description and instructions

The subject matter is the provision of the subscribed services. Operations may include collection on instruction, hosting, organisation, consultation, document reconciliation, workflow execution, processing by authorised models, export and erasure. Purposes are exclusively those determined by the Customer for its business applications.

Data may concern Authorised Users, employees, customers, prospects, investors, suppliers or other Customer contacts: professional identity, contact details, roles, contractual data and business documents. The particulars specify actual categories, individuals, purposes, operations, volumes, frequency and duration. Special category data under Article 9, criminal data under Article 10 and processing requiring sector-specific safeguards are permitted only after written agreement and definition of the required measures.

Processing continues during the contract and then only for the agreed exit assistance and erasure. Instructions consist of the contract, authorised configurations and the Customer’s written requests. dibby immediately informs the Customer if an instruction appears contrary to applicable law. If legislation requires other processing, dibby informs the Customer before acting unless legally prohibited.

A.2. Confidentiality and security

dibby restricts access to authorised people bound by confidentiality. It implements the appropriate measures required by Article 32 of the GDPR, taking account of the nature of the data and risks.

For the selected deployment, the security schedule describes authentication and permissions, environment isolation, protection of transmission and storage, vulnerability management, logging, backups, recovery testing, incident management and deletion. It identifies measures actually implemented, their owner and options still to be activated. Undocumented measures are not represented as already in place.

A.3. Subprocessors

The initial subprocessor list is supplied and approved before processing; it identifies each provider, its role, processing locations and transfer safeguards. The Customer authorises their use within that scope.

Any addition or replacement is announced at least thirty days in advance. The Customer may raise a substantiated data protection objection within fifteen days of notice. The parties seek a reasonable solution; if none is found, the Customer may end the affected service before the new subprocessor becomes involved, with reimbursement of unused prepaid fees.

dibby imposes equivalent data protection obligations on its subprocessors and remains responsible to the Customer for their performance. No general provision authorises a provider to reuse data for model training.

A.4. Locations and transfers

Hosting, processing and remote access locations are identified in the particulars. Hosting within the European Union does not by itself rule out an international transfer.

Any transfer outside the European Economic Area complies with the Customer’s instructions and Chapter V of the GDPR. The parties document the applicable mechanism, necessary assessments and relevant supplementary measures before transfer. dibby provides safeguards on request and reports changes affecting their validity.

A.5. Rights, impact assessments and breaches

dibby assists the Customer with rights requests, impact assessments and, where necessary, consultation with the authority. Requests received directly are forwarded to the Customer without undue delay; dibby responds on the substance only on instruction or as required by law.

dibby notifies the Customer of any personal data breach without undue delay after becoming aware of it. It supplies available information: the nature of the incident, affected categories and volumes, likely consequences, measures taken and a follow-up contact. Further information is supplied progressively without delaying the initial alert.

The Customer decides on notifications to the authority and individuals, with dibby’s assistance. Any statutory deadline applicable to the Customer is not a period dibby may wait before alerting it. A more specific contractual alert target may be defined according to agreed operating capabilities.

A.6. Evidence and audits

dibby makes available information needed to demonstrate compliance with this annex and permits audits, including inspections, by the Customer or its appointed auditor bound by confidentiality. A documentary review may be conducted first without eliminating inspection rights where needed.

Routine audits are organised with reasonable notice, protecting other customers and security. Neither frequency limits nor charges may prevent an audit justified by an incident, serious risk, non-compliance or an authority’s request. Corrective measures and follow-up are documented.

A.7. Return and deletion

At the Customer’s choice, dibby returns or deletes data at the end of the services and destroys copies unless retention is legally required. Backups retained temporarily are isolated, protected and eliminated according to the agreed schedule; they are used only for necessary recovery, with deletion instructions reapplied.

Confirmation of return or deletion is provided on request. Customer Data may not be retained as security for payment to the detriment of mandatory data protection or exit obligations.

Annex B. Particulars to complete before signing

Complete below or refer to the attached quotation and schedules, stating their version and date.

ItemTo complete
Customer (legal name and address)
Representative (name, position, email)
Quotation or order (reference, date)
Attached schedules
Specific terms, if any
Place and date
Customer signature
dibby signature

The quotation specifies the offering, price and term. The schedules specify contacts, data processing, hosting, security, providers and the return and deletion arrangements required by Annex A.

These blank particulars do not constitute acceptance of the contract.

The French version is authoritative.

Lire en français
dibby

Your operations. Your rules.

PlatformHow it worksEnterprise & securityBook a demo
IndustriesPrivate equityFinancial markets
Get in touch[email protected]Log in to dibby
© 2026 dibby
Privacy noticeTerms of service
Built for people. Ready for agents.