BIMtwin toolbox

Privacy Policy

1. Who processes your data

The controller of your personal data is BIMtwin s.r.o., company ID (IČO) 194 19 881, registered office at náměstí Winstona Churchilla 1800/2, 130 00 Prague 3, Czech Republic. The company is registered in the Commercial Register kept by the Municipal Court in Prague, section C, file 386292 (“we” or “us”).

This policy covers the BIMtwin toolbox web tools at toolbox.bimtwin.cz, api.bimtwin.cz and editor.bimtwin.eu (the “toolbox”).

Send questions and requests about personal data to [email protected] or by post to our registered office. We have not appointed a data protection officer because the GDPR does not require us to.

2. In brief

3. What data we process, why, and on what legal basis

Legal bases refer to Article 6(1) of Regulation (EU) 2016/679 (GDPR): (b) contract, (c) legal obligation, (f) legitimate interest, (a) consent.

PurposeDataLegal basis
Creating and running your account, sign-in e-mail, password (stored only as a hash), first and last name, sign-up method (e-mail, Google, Microsoft) and the page you signed up from, date of last login. Optional: company ID, company name and address, field of work, phone. contract – (b). Optional data: legitimate interest – (f), to know who we build the tools for and to offer you a suitable licence.
Record of accepting the terms time of acceptance and the versions of the terms and policy you accepted legitimate interest – (f), to prove the contract
Providing the tools and processing files files you upload (IFC, IDS, DWG, CSV/XLS etc.) and the processing results. For interface (API) access, the token used and a record of who started each job. Files may contain personal data that you put in them, such as the model author's name. contract – (b). For public tools used without an account: legitimate interest – (f), to carry out the processing you asked for.
Service e-mails e-mail address and message content (registration confirmation, notice of an attempt to register your address, notices of changes) contract – (b)
Inquiries and customer care From the inquiry form: name, e-mail, phone, company, message, the page you wrote from and your IP address. We also keep a record of our communication with you and the company you represent. For users with an account, we also keep an overview of which tools they use and how often. steps before entering a contract at your request – (b); legitimate interest – (f), to handle inquiries, look after customers and offer a licence that fits how you use the tools
Usage statistics and product development which tool you opened and when, working time, processing runs and result downloads, IP address, browser type (user agent) and the page you came from. In the gbXML editor and CAD Viewer we also record events such as opening a file, the tool used, the number of zones or storeys, the underlay type and error messages. For signed-in users, these records are linked to the account. legitimate interest – (f), to see which tools are used and where they fail, and to improve them
Security and abuse prevention IP address (limits on login, registration, inquiry and upload attempts) and server technical logs legitimate interest – (f), to protect accounts and keep the service available
Error tracking error description, page address, browser type, application version and, for signed-in users, the account legitimate interest – (f), to fix bugs
Downloads of desktop tools time of download, the tool and version downloaded, IP address, and your account if you are signed in legitimate interest – (f), to know which versions are in use and to provide support
Marketing e-mails (news, offers) e-mail, name, and the time consent was given and withdrawn consent – (a). You can withdraw it at any time by writing to [email protected] or using the link in each message. Withdrawal does not affect processing that took place before it.
Legal obligations; establishing and defending claims data needed in the given case, such as contract and accounting records for paid licences legal obligation – (c); legitimate interest – (f)

You need an e-mail address and password, or a Google or Microsoft account, to create an account. All other registration data is optional. We do not make automated decisions or carry out profiling with legal effects.

You may object to processing based on legitimate interest (see section 10).

4. Where the data comes from

5. Who receives the data

Your data is processed by our staff and by the following processors, who may use it only on our instructions:

RecipientRoleData location
DigitalOcean, LLCapplication hosting, database, file storage, operational logsdata centre in Frankfurt am Main (EU); US-based company
Microsoft Ireland Operations Ltd. (Microsoft 365)sending and receiving e-mailEuropean Union / EFTA

The following act as independent controllers:

We also disclose data to public authorities where the law requires it. We do not sell data or share it for third-party marketing.

6. Transfers outside the EU

We store data in the European Union. Some providers belong to US-based groups, so access from the US (for example during technical support) cannot be ruled out. Where that happens, the transfer relies on the European Commission's adequacy decision under the EU-US Data Privacy Framework: both DigitalOcean, LLC and Microsoft Corporation are certified under it. Should the framework cease to apply, the data processing agreements with both providers include the standard contractual clauses approved by the European Commission.

7. How long we keep data

DataRetention
Uploaded filesdeleted as soon as processing is finished (a DWG drawing right after conversion)
Processing results and report links10 days
Unconfirmed registration30 days
Account and registration dataas long as the account exists, then deleted within 30 days of closure. We delete accounts nobody has signed in to for 5 years — you will get an e-mail a month in advance.
Record of accepting the termsas long as the account exists, plus 5 years after closure
Usage statistics and telemetry5 years
Error records5 years
Rate-limit counters by IP addressup to 1 hour, in memory only
Server operational logsthe running application log is kept by DigitalOcean only briefly and we do not store it further; build and deployment records 90 days
Inquiries and business communication5 years from receiving the inquiry or from the last contact
Marketing consentuntil withdrawn; the record of granting and withdrawal is kept for 5 years
Accounting and tax records for paid licencesas required by law (10 years)

8. Cookies and browser storage

The toolbox uses only its own cookies and browser storage. We use no third-party analytics, advertising or tracking cookies. The only cookie that is not strictly necessary is used to count visits of tool visitors who are not signed in — we set it only if you allow it in the banner. Signed-in users need the session cookie to stay signed in anyway.

NameTypePurposeDuration
sessionidcookiekeeps you signed in and secures the Google/Microsoft sign-in steps (strictly necessary). For visitors of the tools who are not signed in, only with their consent, so that one visit counts once.2 weeks
bimtwin_cookiescookieremembers whether you allowed or declined visit counting (strictly necessary)1 year
csrftokencookieprotects forms against forged requests1 year
messagescookieone-off notice after an actionuntil the notice is shown
bemeditor.*localStoragegbXML editor settings (language, panel and column layout, pinned tools, snapping, dismissed notices)until you delete it
bimtwin.auth.viewlocalStorageremembers whether you last chose sign-in or registration in the dialoguntil you delete it
cadviewer.colorslocalStoragedrawing colours switched on in the CAD Vieweruntil you delete it
gbXML editor service workerbrowser registrationlets you install the editor on your desktop; stores nothinguntil uninstalled

Data in localStorage stays in your browser and is not sent to our server. You can delete or block cookies and localStorage in your browser settings. Without cookies, however, you cannot sign in.

9. Security

All communication is encrypted (HTTPS). We store passwords and access tokens only as one-way hashes. Only authorised staff who need the data for their work can access it. We limit the number of login and registration attempts. We regularly delete files that are no longer needed for processing. If a security breach occurs, we follow the GDPR, including notifying the supervisory authority and you where required.

10. Your rights

You have the right to:

Send your request to [email protected]. We will handle it without undue delay and within one month at the latest. To make sure we do not disclose data to someone else, we may verify your identity, usually by a reply from the e-mail address in your account.

If you believe we handle your data unlawfully, you can lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or with the supervisory authority in your EU country. We would appreciate the chance to resolve your concern first.

11. Changes to this policy

We update this policy when the way we process data changes, for example when we add a tool or a provider. We will tell you about significant changes in advance by e-mail or in the toolbox. The current version is always on this page, with the effective date at the top. We publish this policy in Czech and English. If they differ, the Czech version prevails.