Privacy Policy
1. Who processes your data
The controller of your personal data is BIMtwin s.r.o., company ID (IČO) 194 19 881, registered office at náměstí Winstona Churchilla 1800/2, 130 00 Prague 3, Czech Republic. The company is registered in the Commercial Register kept by the Municipal Court in Prague, section C, file 386292 (“we” or “us”).
This policy covers the BIMtwin toolbox web tools at toolbox.bimtwin.cz, api.bimtwin.cz and editor.bimtwin.eu (the “toolbox”).
Send questions and requests about personal data to [email protected] or by post to our registered office. We have not appointed a data protection officer because the GDPR does not require us to.
2. In brief
- We collect only what we need to run your account and the tools, to keep them secure and to improve them.
- Wherever possible, your models and drawings stay in your browser. If the server has to process a file, we delete it as soon as processing is finished. We delete results within 10 days.
- We use no third-party advertising or analytics cookies. We do not sell data.
- We send marketing e-mails only with your consent, which you can withdraw at any time.
3. What data we process, why, and on what legal basis
Legal bases refer to Article 6(1) of Regulation (EU) 2016/679 (GDPR): (b) contract, (c) legal obligation, (f) legitimate interest, (a) consent.
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account, sign-in | e-mail, password (stored only as a hash), first and last name, sign-up method (e-mail, Google, Microsoft) and the page you signed up from, date of last login. Optional: company ID, company name and address, field of work, phone. | contract – (b). Optional data: legitimate interest – (f), to know who we build the tools for and to offer you a suitable licence. |
| Record of accepting the terms | time of acceptance and the versions of the terms and policy you accepted | legitimate interest – (f), to prove the contract |
| Providing the tools and processing files | files you upload (IFC, IDS, DWG, CSV/XLS etc.) and the processing results. For interface (API) access, the token used and a record of who started each job. Files may contain personal data that you put in them, such as the model author's name. | contract – (b). For public tools used without an account: legitimate interest – (f), to carry out the processing you asked for. |
| Service e-mails | e-mail address and message content (registration confirmation, notice of an attempt to register your address, notices of changes) | contract – (b) |
| Inquiries and customer care | From the inquiry form: name, e-mail, phone, company, message, the page you wrote from and your IP address. We also keep a record of our communication with you and the company you represent. For users with an account, we also keep an overview of which tools they use and how often. | steps before entering a contract at your request – (b); legitimate interest – (f), to handle inquiries, look after customers and offer a licence that fits how you use the tools |
| Usage statistics and product development | which tool you opened and when, working time, processing runs and result downloads, IP address, browser type (user agent) and the page you came from. In the gbXML editor and CAD Viewer we also record events such as opening a file, the tool used, the number of zones or storeys, the underlay type and error messages. For signed-in users, these records are linked to the account. | legitimate interest – (f), to see which tools are used and where they fail, and to improve them |
| Security and abuse prevention | IP address (limits on login, registration, inquiry and upload attempts) and server technical logs | legitimate interest – (f), to protect accounts and keep the service available |
| Error tracking | error description, page address, browser type, application version and, for signed-in users, the account | legitimate interest – (f), to fix bugs |
| Downloads of desktop tools | time of download, the tool and version downloaded, IP address, and your account if you are signed in | legitimate interest – (f), to know which versions are in use and to provide support |
| Marketing e-mails (news, offers) | e-mail, name, and the time consent was given and withdrawn | consent – (a). You can withdraw it at any time by writing to [email protected] or using the link in each message. Withdrawal does not affect processing that took place before it. |
| Legal obligations; establishing and defending claims | data needed in the given case, such as contract and accounting records for paid licences | legal obligation – (c); legitimate interest – (f) |
You need an e-mail address and password, or a Google or Microsoft account, to create an account. All other registration data is optional. We do not make automated decisions or carry out profiling with legal effects.
You may object to processing based on legitimate interest (see section 10).
4. Where the data comes from
- From you: when you register, send an inquiry or an e-mail, or use the tools.
- From Google or Microsoft, if you sign in with their account: first and last name, e-mail address and whether the address is verified. For Microsoft work accounts, this may also include profile data kept by your organisation, such as your job title. We do not store these services' access tokens.
- From the ARES public business register (Czech Ministry of Finance): when you enter a company ID, we look up the company name and address. We send only the company ID to ARES.
- From your browser and device: IP address, browser type and tool events (see section 3).
5. Who receives the data
Your data is processed by our staff and by the following processors, who may use it only on our instructions:
| Recipient | Role | Data location |
|---|---|---|
| DigitalOcean, LLC | application hosting, database, file storage, operational logs | data centre in Frankfurt am Main (EU); US-based company |
| Microsoft Ireland Operations Ltd. (Microsoft 365) | sending and receiving e-mail | European Union / EFTA |
The following act as independent controllers:
- Google and Microsoft, when you sign in with their account. Their own privacy policies describe how they handle your data.
We also disclose data to public authorities where the law requires it. We do not sell data or share it for third-party marketing.
6. Transfers outside the EU
We store data in the European Union. Some providers belong to US-based groups, so access from the US (for example during technical support) cannot be ruled out. Where that happens, the transfer relies on the European Commission's adequacy decision under the EU-US Data Privacy Framework: both DigitalOcean, LLC and Microsoft Corporation are certified under it. Should the framework cease to apply, the data processing agreements with both providers include the standard contractual clauses approved by the European Commission.
7. How long we keep data
| Data | Retention |
|---|---|
| Uploaded files | deleted as soon as processing is finished (a DWG drawing right after conversion) |
| Processing results and report links | 10 days |
| Unconfirmed registration | 30 days |
| Account and registration data | as long as the account exists, then deleted within 30 days of closure. We delete accounts nobody has signed in to for 5 years — you will get an e-mail a month in advance. |
| Record of accepting the terms | as long as the account exists, plus 5 years after closure |
| Usage statistics and telemetry | 5 years |
| Error records | 5 years |
| Rate-limit counters by IP address | up to 1 hour, in memory only |
| Server operational logs | the running application log is kept by DigitalOcean only briefly and we do not store it further; build and deployment records 90 days |
| Inquiries and business communication | 5 years from receiving the inquiry or from the last contact |
| Marketing consent | until withdrawn; the record of granting and withdrawal is kept for 5 years |
| Accounting and tax records for paid licences | as required by law (10 years) |
8. Cookies and browser storage
The toolbox uses only its own cookies and browser storage. We use no third-party analytics, advertising or tracking cookies. The only cookie that is not strictly necessary is used to count visits of tool visitors who are not signed in — we set it only if you allow it in the banner. Signed-in users need the session cookie to stay signed in anyway.
| Name | Type | Purpose | Duration |
|---|---|---|---|
sessionid | cookie | keeps you signed in and secures the Google/Microsoft sign-in steps (strictly necessary). For visitors of the tools who are not signed in, only with their consent, so that one visit counts once. | 2 weeks |
bimtwin_cookies | cookie | remembers whether you allowed or declined visit counting (strictly necessary) | 1 year |
csrftoken | cookie | protects forms against forged requests | 1 year |
messages | cookie | one-off notice after an action | until the notice is shown |
bemeditor.* | localStorage | gbXML editor settings (language, panel and column layout, pinned tools, snapping, dismissed notices) | until you delete it |
bimtwin.auth.view | localStorage | remembers whether you last chose sign-in or registration in the dialog | until you delete it |
cadviewer.colors | localStorage | drawing colours switched on in the CAD Viewer | until you delete it |
| gbXML editor service worker | browser registration | lets you install the editor on your desktop; stores nothing | until uninstalled |
Data in localStorage stays in your browser and is not sent to our server. You can delete or block cookies and localStorage in your browser settings. Without cookies, however, you cannot sign in.
9. Security
All communication is encrypted (HTTPS). We store passwords and access tokens only as one-way hashes. Only authorised staff who need the data for their work can access it. We limit the number of login and registration attempts. We regularly delete files that are no longer needed for processing. If a security breach occurs, we follow the GDPR, including notifying the supervisory authority and you where required.
10. Your rights
You have the right to:
- access your data and get a copy,
- rectify inaccurate data,
- erasure where we no longer need the data or process it unlawfully,
- restriction of processing,
- portability of data you gave us under a contract or consent,
- object to processing based on legitimate interest, and to marketing at any time without giving a reason,
- withdraw consent at any time, without affecting the lawfulness of earlier processing.
Send your request to [email protected]. We will handle it without undue delay and within one month at the latest. To make sure we do not disclose data to someone else, we may verify your identity, usually by a reply from the e-mail address in your account.
If you believe we handle your data unlawfully, you can lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or with the supervisory authority in your EU country. We would appreciate the chance to resolve your concern first.
11. Changes to this policy
We update this policy when the way we process data changes, for example when we add a tool or a provider. We will tell you about significant changes in advance by e-mail or in the toolbox. The current version is always on this page, with the effective date at the top. We publish this policy in Czech and English. If they differ, the Czech version prevails.