Privacy policy

Last updated: 2026-07-21

BimDossier processes personal data of the people who use our portal, mobile app and public website: kwaliteitsborgers, contractors, project teams and prospective customers. This policy explains who we are, which data we process and in which role, for what purpose and on what legal basis, who we share it with, how long we keep it, and which rights you have under the GDPR. The service is currently offered in beta (pre-release); data you enter during the beta may be reset, migrated or deleted at any time (see the section on retention below).

Who we are

BimDossier (trading name) provides the BimDossier portal and mobile app. Contact us at info@bimdossier.nl for privacy questions, or support@bimdossier.nl to report a security concern. BimDossier is operated by Aniket Wachakawade, who is the controller for the processing described in this policy. Registration of the business with the Dutch Chamber of Commerce (KvK) is in progress; the KvK number and business address will be listed here once registration completes. Providing basic account data (name, email address) is a contractual requirement: without it we cannot create your account or deliver the service. You are never legally obliged to provide us with data.

Our two roles: controller and processor

For account and contact data, security and audit logs, website and waitlist enquiries, and product analytics, BimDossier is the controller, and this policy covers that processing. For project content that customer organisations upload (IFC models, photos, documents, findings, and any personal data of project participants they contain), the customer organisation is the controller and BimDossier is the processor: that processing is governed by our data processing agreement (DPA), not by this policy. If you are a project participant rather than a BimDossier user (for example, your name or a photo of you appears in a customer's project), that customer is responsible for informing you and handling your privacy requests, and on their instruction we help fulfil your rights.

Data we process as controller

Account and contact data (name, email address, organisation, language preference, and the email addresses of people you invite); billing and invoicing data once you take a paid subscription (company details and invoice records); data you submit via our website when requesting access or joining the waitlist (name, work email, company, role and any details you choose to share); and technical and security data (IP address, device/user-agent, and audit events) used to secure the service and prevent abuse. Project content (including photos, which may contain metadata such as capture time and location, and uploads made through shared capture links by people without an account) is processed on behalf of the customer organisation as described above.

Purposes and legal bases

Creating and managing your account and delivering the service: performance of our contract with you (Art. 6(1)(b) GDPR). Handling your access request or waitlist registration: steps prior to entering into a contract, at your request (Art. 6(1)(b)). Sending and managing invitations: our and the inviting organisation's legitimate interest in enabling collaboration (Art. 6(1)(f)); if someone invited you, we received your name and email address from the person who invited you. Securing the service (security logging, abuse prevention) and error monitoring: our legitimate interest in a safe and reliable service (Art. 6(1)(f)). Product analytics: our legitimate interest in understanding how the product is used so we can improve it (Art. 6(1)(f)). You can object at any time via info@bimdossier.nl; we will then stop linking events to your account and, on request, delete analytics data already associated with it. Invoicing and tax administration: a legal obligation (Art. 6(1)(c)). Where we ask for your consent (Art. 6(1)(a)), you can withdraw it at any time. We do not sell your data and do not use it for profiling or automated decision-making within the meaning of Art. 22 GDPR.

Cookies and local storage

We use one functional cookie (NEXT_LOCALE, valid for one year) to remember your language choice. The portal also uses your browser's local storage for strictly necessary and functional purposes: keeping you signed in (authentication tokens, removed on logout) and remembering interface preferences such as theme and viewer settings. We do not use advertising or cross-site tracking cookies, and our analytics stores nothing on your device.

Analytics and error monitoring

We use PostHog for product analytics (EU-hosted, cookieless, no session recording). On our public website this is anonymous visit measurement; for signed-in portal users, events are linked to your account. You can object to analytics at any time (see the section on purposes and legal bases). We use Sentry for error and crash monitoring of the portal, API and mobile app (EU data region; configured not to send request bodies or user identifiers).

Retention

Account data is kept for as long as your account exists and is anonymised or deleted after account deletion. Project data is kept for as long as the customer organisation keeps its account; when a project is deleted, its files and photos are permanently removed after 30 days, and remaining project records are deleted together with the organisation; an organisation is permanently deleted after a grace period of currently 30 days. Statutory dossier-retention obligations (such as the 10-year retention under the Quality Assurance in Construction Act (Wkb)) rest with the customer organisation, which can export dossiers at any time before deletion. Invoicing records are kept for 7 years (Dutch statutory tax retention). Security and audit logs and in-app notifications are retained for as long as the customer organisation's account exists and are permanently deleted when the organisation is deleted (after the 30-day grace period), unless a longer period is needed for an ongoing security investigation or a legal claim; website enquiries that do not lead to an account are deleted no later than 24 months after our last contact. While the service is in beta (pre-release), data you enter may additionally be reset, migrated or permanently deleted at any time and without notice as part of testing and iteration; we do not guarantee its retention, and you should keep your own copies of anything you need.

Your rights

You have the right to access, correction, deletion (within the limits of statutory retention), restriction of processing, data portability, and objection to processing based on our legitimate interests (Art. 21 GDPR). Where processing is based on consent, you may withdraw it at any time without affecting prior processing. Send requests to info@bimdossier.nl; we respond within one month (for complex requests we may extend this by up to two further months, in which case we tell you within the first month) and may ask you to verify your identity. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Hosting, sub-processors and transfers

All personal data is hosted and stored within the EU/EEA. We use a small number of service providers: infrastructure, hosting and object storage (EU), PostHog for product analytics (EU), Sentry for error monitoring (EU data region), and a transactional email provider. A current, named list of sub-processors is published at /legal/subprocessors and is also available on request via info@bimdossier.nl. Where a transfer outside the EEA is nonetheless required (for example, incidental support access by a service provider's non-EEA group entity), it only takes place under an adequacy decision (such as the EU-US Data Privacy Framework) or the EU Standard Contractual Clauses. We may disclose data to competent authorities where we are legally required to do so.

Changes to this policy

We may update this policy, for example when we add features or service providers. The date above shows the latest revision; material changes are announced in the portal or by email.