Privacy Policy

Last updated: 2025-12-16

This Privacy Policy explains how the BIMGO team ("BIMGO", "we", "us", or "our") collects, uses, discloses, and safeguards your information when you use our BIM viewing platform and AI-powered collaboration services (the "Service"). We are committed to protecting your privacy and handling your data transparently.

1. Information We Collect

We collect information you provide directly, information generated by your use of the Service, and information from third parties. The types of information include:

  • Account Information: Email address, name, profile picture, company name, job title, and authentication credentials when you create an account or sign in via third-party providers (Google, Microsoft, etc.).
  • BIM Model Data: CAD files, IFC models, Revit files, DWG drawings, and other construction project files you upload, along with associated metadata such as file names, sizes, upload timestamps, and version history.
  • AI Conversation Data: Questions, prompts, and messages you send to our AI assistant, as well as generated responses, model queries, and analysis reports.
  • Project Collaboration Data: Sharing settings, collaborator lists, comments, annotations, measurements, and markups you create within shared models.
  • Usage Analytics: Pages viewed, features used, session duration, click patterns, device information (browser type, operating system, screen resolution), and IP address for service optimization.
  • Payment Information: Billing details, subscription plans, and transaction records processed through secure third-party payment providers.
  • Cookies and Tracking Technologies: Information collected through cookies, web beacons, and similar technologies to maintain sessions, remember preferences, and improve user experience.

2. How We Use Your Information

We use the collected information to provide, maintain, improve, and secure the Service. Specific purposes include:

  • Service Delivery: Enabling BIM model upload, conversion, viewing, and collaboration features; processing AI queries and generating intelligent responses.
  • Account Management: Creating and maintaining your account, authenticating access, managing subscriptions, and processing payments.
  • Communication: Sending service updates, security alerts, technical notices, billing reminders, and responding to support requests.
  • AI Model Training: Using anonymized and aggregated interaction data to improve our AI assistant's understanding of construction and engineering terminology (you may opt out).
  • Product Improvement: Analyzing usage patterns to enhance user experience, optimize performance, and develop new features.
  • Security and Fraud Prevention: Detecting and preventing unauthorized access, abuse, spam, and other malicious activities.
  • Legal Compliance: Meeting regulatory requirements, responding to legal requests, and enforcing our terms of service.

3. BIM Model Data Handling

We understand that your BIM models may contain sensitive project information. Here's how we handle your model data:

  • Ownership: You retain full ownership of all BIM models and project files you upload. We do not claim any intellectual property rights over your content.
  • Processing: Models are converted and optimized for web viewing using secure server-side processing. Original files are stored encrypted at rest.
  • Access Control: Only you and collaborators you explicitly authorize can access your models. Our technical staff may access data only for troubleshooting purposes under strict protocols.
  • AI Analysis: When you use AI features, relevant model metadata and element information may be processed to generate responses. This data is not used to train AI models without your consent.
  • Deletion: When you delete a model, it is marked for permanent removal and completely erased from our systems within 30 days, including all backups.

4. AI Features and Data Processing

Our AI-powered features are designed with privacy in mind:

  • Conversation Privacy: AI chat sessions are associated with your account and are not shared with other users. You can view and delete your conversation history at any time.
  • Data Minimization: The AI processes only the information necessary to respond to your queries. It does not have access to unrelated account data or other users' information.
  • Third-Party AI Services: Some AI features may utilize third-party AI providers (e.g., OpenAI, Google AI). Data sent to these providers is governed by their privacy policies and our data processing agreements.
  • Opt-Out Options: You can choose not to use AI features. Disabling AI chat will not affect core model viewing functionality.
  • No Automated Decisions: We do not use AI to make automated decisions that significantly affect your account or access to the Service.

5. How We Share Information

We do not sell, rent, or trade your personal information. We may share information only in the following circumstances:

  • With Your Consent: When you explicitly share models, invite collaborators, or publish content to public links.
  • Service Providers: With trusted third-party vendors who assist us in operating the Service (cloud hosting, payment processing, email delivery, analytics), bound by confidentiality agreements.
  • Legal Requirements: When required by law, subpoena, court order, or government request, or to protect the rights, property, or safety of BIMGO, our users, or the public.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, where user data may be transferred as part of the transaction (with prior notice to you).
  • Aggregated Data: We may share anonymized, aggregated statistics that cannot identify individual users for research or marketing purposes.

6. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

  • Essential Cookies: Required for authentication, session management, and security. Cannot be disabled without affecting core functionality.
  • Functional Cookies: Remember your preferences (language, theme, viewer settings) for a personalized experience.
  • Analytics Cookies: Help us understand how users interact with the Service through tools like Google Analytics. Data is collected anonymously.
  • Managing Cookies: You can control cookie preferences through your browser settings or our cookie consent banner. Disabling certain cookies may limit functionality.
  • Do Not Track: We respect browser Do Not Track signals when supported, though no universal standard exists for handling them.

7. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption for stored files and database records.
  • Infrastructure: Our services run on enterprise-grade cloud infrastructure (AWS/Alibaba Cloud) with SOC 2 Type II compliance.
  • Access Controls: Role-based access controls, multi-factor authentication, and audit logging protect against unauthorized access.
  • Regular Audits: We conduct periodic security assessments, penetration testing, and vulnerability scanning.
  • Incident Response: We maintain incident response procedures and will notify affected users within 72 hours of detecting a data breach.
  • Your Responsibility: You are responsible for maintaining the confidentiality of your account credentials and promptly reporting any unauthorized access.

8. Data Retention

We retain your information only as long as necessary for the purposes described in this policy:

  • Active Accounts: Account information and associated data are retained while your account remains active.
  • Model Data: Uploaded models are retained until you delete them or your account is terminated. Deleted models are purged within 30 days.
  • AI Conversations: Chat history is retained for 12 months by default. You can delete conversations at any time.
  • Logs and Analytics: Usage logs and analytics data are retained for up to 24 months for security and improvement purposes.
  • Legal Obligations: Certain data may be retained longer if required for legal, tax, or regulatory compliance.
  • Account Closure: Upon account deletion request, we will delete your personal data within 30 days, except where retention is legally required.

9. International Data Transfers

BIMGO operates globally, and your data may be transferred internationally:

  • Our servers are located in regions including the United States, European Union, and Asia-Pacific to ensure optimal performance.
  • When transferring data across borders, we rely on legal mechanisms such as Standard Contractual Clauses (SCCs), adequacy decisions, or your explicit consent.
  • For users in the European Economic Area (EEA), UK, or Switzerland, we ensure adequate protection for personal data transferred outside these regions.
  • We work with cloud providers that maintain certifications including ISO 27001, SOC 2, and GDPR compliance.

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Correct inaccurate or incomplete information in your account.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Right to Portability: Receive your data in a structured, machine-readable format for transfer to another service.
  • Right to Restrict Processing: Limit how we process your data in certain circumstances.
  • Right to Object: Object to processing based on legitimate interests, including for direct marketing.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
  • To exercise these rights, please contact us at the email below. We will respond within 30 days (or as required by applicable law).

11. Children's Privacy

The Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will promptly delete it. If you believe a child has provided us with personal information, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service features. Material changes will be communicated via email or a prominent notice on the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our privacy team:

Email: support@bimgo.net

For terms governing your use of the Service, see our Terms of Service