Legal
Privacy Policy
Version 2026-08-11
Effective Date: August 11, 2026 Version: 2026-08-11 Last Updated: August 11, 2026
Summary (Non-Binding)
This summary is provided for convenience only. The full policy below governs.
- We collect account, billing, support, device, usage, and website analytics data.
- Revit Model Data and Uploaded Documents submitted for compliance processing are designed to be processed in-session and not retained afterward.
- We do not sell or share your personal information as those terms are defined under U.S. state privacy laws, and we do not use your Model Data or Uploaded Documents to train AI models.
- We use third-party subprocessors, including cloud hosting, payment processing, email delivery, analytics, identity, and AI inference providers.
- You have rights to access, correct, delete, and port your data, subject to legal exceptions.
- No system is perfectly secure, and we do not guarantee the security of any data.
1. Scope and Who We Are
This Privacy Policy ("Policy") explains how BIM Pro AI, Inc., a Georgia corporation doing business as "BIM Pro AI" ("BIM Pro AI," "we," "our," or "us"), collects, uses, discloses, and protects information in connection with:
- the websites at
bimproai.com,www.bimproai.com,account.bimproai.com,download.bimproai.com, anddocs.bimproai.com(the "Sites"); - the BIM Pro AI Autodesk Revit add-in and other client software (the "Software"); and
- the BIM Pro AI hosted platform, APIs, and account portal (the "Platform")
(collectively, the "Services").
This Policy is incorporated into and forms part of the Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
This Policy does not apply to any third-party website, product, or service, including Autodesk, our payment processor, or any other third party, each of which has its own privacy practices for which we are not responsible.
1.1 Business Service; Not Directed to Consumers or Children
The Services are a business-to-business commercial offering intended for professional and business use only. They are not directed to consumers acting for personal, family, or household purposes, and are not directed to children. We do not knowingly collect personal information from anyone under the age of eighteen (18). If we learn we have collected such information, we will delete it. Contact support@bimproai.com to report a concern.
1.2 Our Role: Controller and Processor
- When we handle account, billing, support, marketing, security, and website analytics data, we generally act as a controller (or "business").
- When we handle Customer Data you submit through the Software or Platform — including Model Data, Uploaded Documents, and project content — we generally act as a processor (or "service provider") on behalf of the Customer, and we process that data only per the Customer's instructions and our agreement with the Customer.
If you are an Authorized User accessing the Services through your employer's or firm's account, that organization is the controller of your account and usage data. Direct requests about that data to your organization. We will refer such requests to the Customer and will assist the Customer as required by law and by our agreement with them. Your organization may access, monitor, restrict, export, or delete your account and usage data, and may have visibility into your activity in the Services.
2. Information We Collect
2.1 Information You Provide
| Category | Examples |
|---|---|
| Account information | Name, business email address, password (stored only as a salted hash), account type, organization name, role, marketing preferences, legal acceptance records and versions |
| Organization and seat information | Organization name, billing email, website, member roles, seat assignments, invitations sent and received |
| Billing information | Billing name, billing email, billing address, tax identifiers, subscription plan, seat count, invoice history, and coupon codes. We do not collect, receive, or store full payment card numbers — card data is collected directly by our payment processor. |
| Support and sales information | Contact form submissions (name, company, email, role, phone, message, firm size, areas of interest), corporate quote requests, support tickets, and correspondence |
| Customer Data | Model Data extracted from Revit models, Uploaded Documents, project names and metadata, compliance settings, and configuration you supply |
2.2 Information Collected Automatically
| Category | Examples |
|---|---|
| Device and activation data | Device or machine identifier (which may be a hashed value), operating system, Revit version, Software version, activation and heartbeat events |
| Session and authentication data | Session identifiers, refresh and access token metadata, sign-in and sign-out events, IP address, approximate location derived from IP at a coarse level, user agent |
| Usage and telemetry data | Features used, actions taken, runs initiated, timestamps, counts, durations, performance metrics, and error and crash diagnostics |
| Download and entitlement data | Release downloaded, grant creation and redemption, update checks, entitlement checks and results |
| Website analytics | Pages visited, referring source, approximate location, device and browser type, aggregated at a level designed to minimize identification |
| Security logs | Access logs, rate-limiting events, suspected abuse, and audit records |
2.3 Information from Third Parties
- Autodesk Platform Services (APS): if you link an Autodesk account, we receive your Autodesk user identifier and, where provided, your Autodesk email address, to establish and verify the link.
- Payment processor: subscription status, payment status, invoice records, the last four digits and brand of a card, and billing address — not the full card number.
- Email delivery provider: delivery, bounce, and complaint events.
- Fraud, spam, and security providers: risk and abuse signals.
2.4 Sensitive Information
Do not submit sensitive personal information to the Services. This includes government identifiers, financial account numbers, health information, biometric data, precise geolocation, racial or ethnic origin, religious beliefs, union membership, sexual orientation, or criminal records. We do not request such information, have no need for it, and disclaim all responsibility for sensitive information you choose to submit in violation of the Terms of Service.
3. How We Use Information
We use information for the following purposes:
- Providing the Services — creating and administering accounts, authenticating users, provisioning seats and entitlements, running compliance calculations, generating Outputs, delivering downloads and updates, and enabling integrations.
- Billing and payments — processing subscriptions, seats, renewals, invoices, taxes, and collections.
- Support — responding to inquiries, diagnosing issues, and communicating about your account.
- Security, integrity, and abuse prevention — authenticating access, detecting and preventing fraud, abuse, license circumvention, and unauthorized use, and maintaining audit trails.
- Reliability and improvement — monitoring performance, diagnosing errors, and improving the Services (using usage and telemetry data and aggregated or de-identified data, not Model Data or Uploaded Document content).
- Communications — sending transactional, service, security, billing, and legal notices. Transactional and service messages are not optional while you hold an account. Marketing messages are sent only where permitted, and you may opt out at any time.
- Legal and compliance — complying with law, responding to lawful requests, enforcing the Terms of Service, establishing, exercising, or defending legal claims, and protecting our rights and the rights of others.
- Corporate transactions — evaluating and completing a merger, acquisition, financing, reorganization, or sale of assets.
3.1 Legal Bases (EEA / UK / Switzerland)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Services and billing); legitimate interests (security, abuse prevention, service improvement, direct B2B marketing, defending legal claims), balanced against your rights; consent (where required, such as certain marketing or optional cookies — withdrawable at any time); and legal obligation (tax, accounting, and lawful requests).
4. Automated Processing and AI
As of the Effective Date, the Services do not include artificial intelligence or machine learning features, and no AI provider processes your content. Compliance results are produced by deterministic calculation logic. We expect to introduce AI-assisted features in the future; this Section states how they will be handled and takes effect for any such feature on the date it becomes available to you.
When AI-assisted features are introduced:
- You will be informed that you are interacting with an AI system. Content generated using AI — including explanations, summaries, citations, and narrative text — will be identified as AI-generated at the point it is presented, and will not have been authored or reviewed by a human beforehand.
- AI-generated content may be inaccurate, incomplete, or fabricated, and must be independently verified. See Section 3 of the Terms of Service.
- We will update this Policy and our subprocessor list at or before the time any AI inference provider begins processing your content, and will continue not to permit training on your content (Sections 5 and 6).
At all times, both now and after any AI feature launches: the Services are not used for automated decision-making that produces legal or similarly significant effects concerning individuals — including no automated decisions about employment, credit, housing, education, insurance, health care, lending, or access to services. We do not profile individuals, recognize emotions, or perform biometric categorization.
4.1 EU AI Act
The transparency obligations in Article 50 of Regulation (EU) 2024/1689 (the "EU AI Act") became applicable on 2 August 2026. They are not currently engaged because the Services include no AI system. The disclosure commitments above are designed to satisfy those obligations if and when AI features are introduced.
The Services are offered for use in the United States. We do not market, target, or offer the Services to individuals or organizations in the European Union or European Economic Area. See Section 19.15 of the Terms of Service.
5. Revit Model Data and Session Processing
We design the Services so that Model Data extracted through the Software is processed to run compliance calculations for your session and is not written to persistent storage for retention after that session ends.
We do not use Model Data to train, fine-tune, or otherwise improve any artificial intelligence or machine learning model operated by BIM Pro AI.
Important qualifications. The statements above describe our design intent and current architecture. They are not a warranty or guarantee, and the following may occur in normal operation:
- transient in-memory processing and short-lived caches;
- operational, security, and error logs that may incidentally include limited metadata or fragments of content;
- crash reports and diagnostic traces;
- routine encrypted backups from which data is purged on our ordinary cycle;
- processing by subprocessors as described in Section 7; and
- retention where required to comply with a legal obligation, a legal hold, or a lawful request.
Enterprise or on-premises deployments may be governed by different, separately agreed terms, which control for those deployments.
6. Uploaded Documents
Documents you upload for in-session processing — for example, code or standard PDFs you are licensed to use — are processed to support retrieval, citation, and explanation for that session.
- Uploaded Documents are designed not to be written to persistent storage for retention after the session ends, subject to the same qualifications listed in Section 5.
- We do not use Uploaded Documents to train, fine-tune, or otherwise improve any AI or machine learning model operated by BIM Pro AI.
- No AI provider currently processes Uploaded Documents (Section 4). Where we engage an AI subprocessor in the future, we will contract on terms intended to prevent training on your content — but we cannot and do not guarantee any third party's compliance with its own contractual commitments.
- You are solely responsible for ensuring you hold all rights, licenses, and permissions necessary to upload any document, and for ensuring you do not upload personal, confidential, privileged, or restricted information that should not be processed by the Services. We do not verify your license rights to any uploaded content. See Section 6.3 of the Terms of Service.
7. Disclosure of Information and Subprocessors
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
We disclose information only as follows:
7.1 Subprocessors and Service Providers
We use vendors that process information on our behalf under contracts requiring confidentiality and use limited to providing services to us. Current categories include:
| Category | Purpose | Provider(s) |
|---|---|---|
| Cloud hosting and infrastructure | Hosting the Sites, Platform, databases, and backups | Google Cloud Platform (Google LLC) |
| Payment processing | Subscriptions, invoices, tax, and card handling | Stripe, Inc. |
| Identity and account linking | Autodesk account linking via OAuth | Autodesk Platform Services (Autodesk, Inc.) |
| Transactional email | Verification, notification, and support email | Resend, Inc. |
| Website analytics | Aggregate traffic measurement | Plausible Analytics |
| Bot and spam protection | Protecting public contact and quote forms | Cloudflare Turnstile (Cloudflare, Inc.) |
| AI inference | Not currently used — see Section 4 | — |
A current list of subprocessors is available on request at support@bimproai.com. We may add, remove, or change subprocessors at any time and will update this Policy or our subprocessor list accordingly. Each subprocessor is subject to its own privacy practices, for which we are not responsible.
7.2 Within Your Organization
If you access the Services through an organization's account, we disclose your account, seat, entitlement, device, and usage information to that organization's owners, administrators, and billing contacts.
7.3 Legal and Protective Disclosures
We may disclose information if we believe in good faith that it is necessary to: comply with any applicable law, regulation, subpoena, court order, warrant, or governmental or law-enforcement request; enforce the Terms of Service; establish, exercise, or defend legal claims; investigate suspected fraud, abuse, or security incidents; or protect the rights, property, or safety of BIM Pro AI, our users, or the public. Where lawful and practicable, we will attempt to notify the affected Customer, but we are not obligated to do so and may be prohibited from doing so.
7.4 Corporate Transactions
In connection with a merger, acquisition, financing, reorganization, bankruptcy, receivership, or sale of all or part of our assets, information may be transferred to the counterparty or successor, subject to this Policy or a successor policy providing comparable protection.
7.5 Aggregated and De-Identified Information
We may create and use aggregated, anonymized, or de-identified information that does not identify any individual, customer, or project for any lawful business purpose, including analytics, benchmarking, research, product improvement, and marketing. We will maintain such information in de-identified form and will not attempt to re-identify it, except as permitted by law to test our de-identification. This information is not personal information and is not subject to this Policy.
7.6 At Your Direction
We disclose information to third parties when you direct or authorize us to do so.
8. Cookies and Similar Technologies
We use strictly necessary cookies and similar technologies for authentication, session management, security, load balancing, and preference storage. Refresh tokens for the account and admin portals are stored in httpOnly cookies.
Our website analytics provider is configured to minimize the collection of personally identifiable information and, in its default configuration, is designed not to set tracking cookies for visitors.
We do not use advertising cookies, third-party ad networks, or cross-site tracking for behavioral advertising, and we do not respond to browser "Do Not Track" signals because no common industry standard for them has been adopted. Where required by law, we honor Global Privacy Control (GPC) opt-out preference signals for the jurisdictions in which that obligation applies.
You can control cookies through your browser, but disabling strictly necessary cookies will prevent the Services from functioning, including sign-in.
9. Data Retention
We retain information only as long as necessary for the purposes described in this Policy, and then delete or de-identify it.
| Data | Typical retention |
|---|---|
| Account and organization records | For the life of the account, then up to [X] days after closure, subject to legal holds |
| Billing, invoice, and tax records | As required by tax and accounting law, typically seven (7) years |
| Legal acceptance records | For the life of the account plus the applicable limitations period |
| Support and sales correspondence | Up to [X] years after last contact |
| Security, audit, and access logs | Up to [X] days, longer where needed for an investigation |
| Device, session, and usage telemetry | Up to [X] months, or aggregated thereafter |
| Website analytics | Aggregated; retained per provider configuration |
| Model Data and Uploaded Documents | Session-scoped — not retained after the session, subject to the qualifications in Section 5 |
| Backups | Purged on our ordinary backup rotation, typically within [X] days |
We may retain information longer where required by law, where subject to a legal hold, or where necessary to establish, exercise, or defend legal claims. Deletion from active systems may not immediately remove data from backups, which are overwritten on our ordinary cycle.
10. Data Security
We implement technical and organizational measures designed to protect information, which may include encryption in transit, encryption at rest, access controls and least-privilege permissions, hashed credentials, httpOnly token storage, session revocation, device revocation, audit logging, and vendor due diligence.
No method of transmission or storage is completely secure. We do not and cannot guarantee the security of any information, and we expressly disclaim any warranty or representation of absolute security. You are responsible for safeguarding your credentials and devices, for configuring your organization's access appropriately, and for promptly reporting any suspected compromise to support@bimproai.com.
In the event of a security incident affecting personal information, we will provide notification as and to the extent required by applicable law. Nothing in this Policy creates any notification obligation beyond what applicable law requires, and our liability for any security incident is subject to the limitations in Section 11 of the Terms of Service.
11. Your Privacy Rights
Depending on where you are located and your relationship with us, you may have rights to:
- Know / access the personal information we hold about you and how we process it;
- Correct inaccurate personal information;
- Delete personal information, subject to exceptions;
- Port a copy of certain personal information in a portable format;
- Opt out of the sale or sharing of personal information (we do not sell or share) and of certain profiling;
- Limit the use of sensitive personal information (we do not collect it for such uses);
- Withdraw consent where processing is based on consent;
- Object to or restrict certain processing; and
- Not be discriminated or retaliated against for exercising these rights.
11.1 Exercising Your Rights
Account holders can access, correct, export, and delete much of their data directly in the account portal, including profile settings, session and device management, data export, and account deletion.
Otherwise, email support@bimproai.com with the subject line "Privacy Request." We must verify your identity before acting and may request information sufficient to do so, including confirming control of the account email. We will respond within the timeframe required by applicable law (generally 45 days under U.S. state laws, extendable by an additional 45 days; generally one month under the GDPR, extendable by two months).
An authorized agent may submit a request on your behalf with proof of authorization and verification of your identity.
We may decline a request where an exception applies, where we cannot verify identity, where the request is manifestly unfounded, excessive, or repetitive, or where fulfilling it would adversely affect the rights of others. We will explain the basis for any denial and, where available, describe how to appeal.
11.2 Appeals
If we deny your request, you may appeal by emailing support@bimproai.com with the subject line "Privacy Appeal." We will respond within the period required by applicable law. If your appeal is denied, you may contact your state attorney general or supervisory authority.
11.3 Requests About Customer Data
If your request concerns data we process as a processor on behalf of a Customer (for example, your employer's account), we will refer your request to that Customer and assist them as required. Direct such requests to your organization.
11.4 California
If the CCPA as amended by the CPRA applies to our processing of your information: in the preceding twelve months we may have collected the categories of personal information described in Section 2 (identifiers; commercial information; internet or network activity; geolocation at a coarse level derived from IP; professional or employment-related information; and inferences drawn only for service operation), from the sources described in Section 2, for the business purposes described in Section 3, and disclosed them for business purposes to the categories of recipients described in Section 7.
We have not sold personal information, and have not shared personal information for cross-context behavioral advertising, in the preceding twelve months, and we do not knowingly sell or share the personal information of minors under 16.
California residents may also request information under California's "Shine the Light" law (Civil Code § 1798.83) by emailing support@bimproai.com.
11.5 Other U.S. States
Residents of states with comprehensive consumer privacy laws may exercise the applicable rights above through the same process. As of the Effective Date, those states include California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, with additional states taking effect over time. We apply the rights described in this Section to residents of any state whose law grants them, whether or not that state is listed above.
Important scope note: with the exception of California, these laws generally exclude personal information about individuals acting in a commercial, business-to-business, or employment context. Because the Services are a business-to-business offering, most information we hold about Authorized Users falls within that exclusion. Where an exclusion or statutory threshold applies, we may decline a request on that basis, and we will explain the basis for any denial.
Georgia. Our home state, Georgia, has not enacted a comprehensive consumer privacy law as of the Effective Date. Georgia's data breach notification statute (O.C.G.A. § 10-1-912) applies to us, and we will provide breach notice as that statute and any other applicable law require.
11.6 EEA, UK, and Switzerland
If the GDPR or UK GDPR applies, you have the rights described above and the right to lodge a complaint with your local supervisory authority (or, in the UK, the Information Commissioner's Office). We encourage you to contact us first at support@bimproai.com.
Because we do not offer or target the Services to individuals in the EU/EEA (Section 4.1), we have not appointed an Article 27 representative. If that changes, we will appoint one and update this Policy.
12. International Data Transfers
We are based in the United States, and we and our subprocessors process information in the United States and potentially in other countries. Data protection laws in those countries may differ from, and may be less protective than, the laws of your country, and government authorities in those countries may be able to access data under their laws.
By using the Services, you acknowledge that your information will be transferred to and processed in the United States and other jurisdictions.
Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary measures where necessary. Copies of relevant transfer mechanisms are available on request at support@bimproai.com.
13. Data Processing Addendum
Customers who require a Data Processing Addendum (DPA) — including Standard Contractual Clauses — may request one at support@bimproai.com. Where an executed DPA is in place, it controls over this Policy with respect to Customer Data processed on the Customer's behalf.
14. Third-Party Sites and Services
The Services contain links to and integrations with third-party websites and services, including Autodesk and our payment processor. We are not responsible for the privacy practices, content, security, or terms of any third party. Review their policies before providing information to them.
15. Changes to This Policy
We may update this Policy at any time. We will post the revised version with an updated Effective Date and, for material changes, provide reasonable additional notice by email or in-product notification.
Changes are effective upon the stated Effective Date, and your continued use of the Services after that date constitutes acceptance of the updated Policy. If you do not agree, you must stop using the Services and close your account. We are not obligated to provide notice of non-material changes, including clarifications, formatting changes, or subprocessor list updates.
16. Limitation
Nothing in this Policy creates any contractual right, warranty, guarantee, representation, or cause of action beyond those required by applicable law. This Policy describes our practices and is not a promise of any particular technical outcome. All use of the Services, and all claims relating to this Policy, are subject to the Terms of Service, including Section 9 (Disclaimer of Warranties), Section 11 (Limitation of Liability), Section 12 (Indemnification), and Section 16 (Binding Arbitration and Class Action Waiver).
17. Contact
| Purpose | Contact |
|---|---|
| Privacy inquiries and rights requests | support@bimproai.com |
| Security incidents and vulnerability reports | support@bimproai.com |
| Legal notices | support@bimproai.com |
| General inquiries | support@bimproai.com |
| Mailing address | BIM Pro AI, Inc., 2451 Cumberland Parkway SE, Suite 3704, Atlanta, GA 30339 |
To exercise a privacy right, use the subject line "Privacy Request." To appeal a denial, use "Privacy Appeal."