PRIVACY POLICY
1. General provisions
This Privacy Policy (hereinafter: the "Policy") sets out the rules for processing the personal data of persons using the website https://inspectrabim.com/ (hereinafter: the "Website"), including the user account and the support case system available in accordance with its functionalities, as well as communication by electronic mail (e-mail), the newsletter or the Inspectra BIM software. The document also covers the rules for processing data in connection with the purchase, activation and servicing of licences for the Inspectra BIM software, including through the use of services of third parties such as Paddle.com Market Ltd. (hereinafter: "Paddle") with its registered office in London (United Kingdom), Keygen LLC (hereinafter: "Keygen") with its registered office in Austin (USA) and Hostinger operations UAB (hereinafter: "Hostinger") with its registered office in Vilnius (Lithuania).
The Policy has been prepared taking into account the nature of the business, which consists in offering BIM software in a desktop model for the Windows operating system, with a user account, a licensing mechanism, support case handling, manual downloading of updates and newsletter communication that is planned or launched. As a rule, the Inspectra BIM software does not send BIM models or the content of the software user's files to the Controller's server – connections with external systems concern primarily sign-in, licences, account servicing, support cases and updates.
2. Data controller
The controller of personal data is Wiktor Mertka, conducting business under the name Mervision Wiktor Mertka, with its registered office in Rotmanka (83-010) at ul. Bajki 15a/13 (Poland), holding NIP (Tax ID): 6040272133, REGON: 545305973, contact e-mail address: contact@inspectrabim.com.
Contact in matters of personal data protection is possible at the e-mail address: contact@inspectrabim.com. The Controller has not appointed a Data Protection Officer, because according to the current assessment the conditions for mandatory appointment of a DPO arising from Article 37(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; hereinafter: "GDPR") do not arise. Should the scale, nature or scope of processing change, this decision should be re-examined.
3. Scope of services and sources of data
Personal data may be obtained directly from the Website user or the user of the Inspectra BIM software, in particular when registering an account, signing in, purchasing a licence, signing up to the newsletter, submitting enquiries, filing technical support cases, contacting us by electronic mail (e-mail) or using the functionalities of the Website. Some data may also be provided to the Controller by the providers used to handle purchases, licences or infrastructure, to the extent necessary to perform the service.
The sources from which data are obtained include:
- the Website and the Website user account running in the WordPress environment;
- the local (desktop) Inspectra BIM software intended for the Windows operating system;
- the licensing mechanism operated using services supplied by Keygen;
- purchase and payment handled by Paddle in the Merchant of Record model;
- the technical support case system and correspondence concerning cases within the Website and the Inspectra BIM software;
- system messages, including activation messages, licensing messages, messages concerning the status of support cases and unfinished purchase processes on the Website;
- the newsletter, informational, product and marketing communication conducted solely towards persons who have signed up to the newsletter or given the required consent;
- cookies and similar technologies used on the website.
4. Categories of data processed
| Area | Categories of data |
|---|---|
| Website user account | first name and surname, e-mail address, password in secured/hashed form, optionally company, account status, user identifier, timestamps. |
| Licences and access to modules | Website user account data, licence identifier, licence status, scope of entitlements, product module, date of activation and validity, change history. |
| Licence purchase via Paddle | e-mail address, Website user account identifier, transaction confirmation, data visible in the seller's panel, purchase history, billing data to the extent made available to the Controller. |
| Technical support and cases | case number, case content, correspondence, category, status, application version, operating system, optional .txt diagnostic log, technical metadata. |
| Newsletter | e-mail address, first name or name if provided, information about consent given, date, time and source of sign-up, IP address or other technical metadata of the sign-up, subscription status, history of unsubscription or withdrawal of consent. |
| E-mail correspondence | e-mail address, first name and surname, message content, data identifying the company, attachments, correspondence history. |
| Cookies and technical data | IP address, cookie identifiers, session data, information about the browser, device, system, cookie preferences. |
| Website visit statistics | IP address, information about the browser and system, the address of the subpage visited, the date and time of the visit. The IP address is processed solely in the server's memory — in order to determine the country and to generate a non-persistent technical hash allowing consecutive views within one visit to be distinguished — and is not stored. |
| Updates and technical logs | IP address, software version, operating system, licence or installation identifier, date and time of connection with the update server. |
5. Purposes and legal bases of processing
| Purpose | Legal basis | Description |
|---|---|---|
| Registration and maintenance of a user account | Article 6(1)(b) GDPR | The processing is necessary to create and maintain a user account on the Website, to enable signing in and using electronic services. |
| Conclusion and performance of the licence agreement / EULA | Article 6(1)(b) GDPR | The data are used to assign a licence, determine the scope of entitlements and enable use of the product. |
| Handling licence sales via Paddle and transaction confirmations | Article 6(1)(b) and (f) GDPR | The Controller processes the data necessary to activate the licence and handle the transaction; Paddle processes payment data as a separate controller acting as the seller in the Merchant of Record (MoR) model. |
| Sending the newsletter and marketing communication | Article 6(1)(a) GDPR; Article 398 of the Electronic Communications Law; Article 10 of the Act on the provision of services by electronic means | The newsletter is sent solely after a voluntary sign-up or the granting of the required consent. Consent may be withdrawn at any time, in particular by means of the unsubscribe link or an e-mail message to the Controller. |
| Documenting consent to the newsletter, its withdrawal and defence against claims | Article 6(1)(f) GDPR | The Controller may retain a minimal scope of evidential data in order to demonstrate when and to what extent consent was granted or withdrawn, and in order to protect against claims. |
| Handling support cases and technical support | Article 6(1)(b) or (f) GDPR | Depending on the nature of the case, the data are necessary to perform the agreement or to protect the legitimate interest consisting in providing support, security and product quality. |
| Ensuring security, updates and technical logs | Article 6(1)(f) GDPR | The legitimate interest is maintaining security, detecting errors, preventing abuse and delivering updates. |
| Website visit statistics | Article 6(1)(f) GDPR | The Controller's legitimate interest is to understand how the Website is used in order to develop it and to select its content. The statistics are kept by the Controller's own means, without cookies and without transferring data to third parties. The results are aggregate only, do not allow a person to be identified and are not linked to a user account. |
| Keeping settlements, tax and accounting records | Article 6(1)(c) GDPR | The processing results from legal obligations concerning accounting, taxes and documenting business events. |
| Establishment, pursuit or defence of claims | Article 6(1)(f) GDPR | The legitimate interest is safeguarding the Controller's legal interests. |
| Handling necessary cookies | Article 6(1)(f) GDPR and the provisions of the Electronic Communications Law | Necessary cookies serve to maintain the session, sign-in and security. Cookies other than necessary ones require separate consent if implemented. |
6. Paddle, Keygen, Hostinger and other recipients of the data
The Controller uses external technology service providers. The scope and role of these entities may differ depending on the particular processing activity. The Controller periodically verifies that the providers' documents are up to date, in particular their terms of service, the provisions of data processing agreements (DPAs), lists of sub-processors and mechanisms for transferring data outside the EEA.
| Entity | Role | Scope of data / function |
|---|---|---|
| Keygen LLC | Processor | Handling user accounts in the licensing system, generating licence tokens and entitlements, licence data and technical metadata. |
| Paddle.com Market Ltd | Independent controller in the MoR sales model and possibly a processor in selected services | Handling checkout, payments, taxes, invoicing, transaction data, webhook confirmations and data visible in the seller's panel. |
| Hostinger operations UAB | Processor | Hosting of the WordPress website, database, e-mail, SMTP, website infrastructure. |
| Provider of the newsletter delivery tool / mailing module | Processor or an element of the Controller's infrastructure | Handling the mailing list, sending messages, sign-ups, unsubscriptions, technical message delivery statistics, if implemented. |
| Certum / Asseco | Recipient of the entrepreneur's data | Code signing certificate and verification of the entrepreneur's data. |
| Public authorities or courts | Recipients on the basis of law | Data transferred solely to the extent required by law or by a properly served request. |
7. Transfers of data outside the EEA
Personal data may be transferred outside the European Economic Area in connection with the use of services of technology providers, in particular Keygen and, depending on the scope of services, Paddle, providers of mailing tools or their sub-processors. A transfer takes place solely with the application of the mechanisms provided for in the GDPR, in particular an adequacy decision, standard contractual clauses or other appropriate safeguards. The Controller keeps documentation confirming the basis of the transfer and updates it periodically.
8. Data retention periods
| Category | Retention period |
|---|---|
| Website user account | For the period of use of the Website user account and, after its deletion, for the period necessary to demonstrate the fulfilment of obligations, to handle claims or in accordance with the law. |
| Licence data | For the period of validity of the licence and thereafter for the limitation period for claims or tax and settlement obligations. |
| Transaction data | For the period required by tax, accounting and settlement regulations and for the period necessary to handle claims. |
| Newsletter | For the period of the newsletter subscription, i.e. until unsubscription or withdrawal of consent. After withdrawal of consent, the Controller may retain minimal evidential data concerning the granting and withdrawal of consent for the limitation period for potential claims or for the period required by law. |
| Technical support and cases | For the period of handling the case and thereafter, as a rule, up to 24 months from closing the matter covered by the case, unless a longer period is needed to defend against claims. |
| Diagnostic logs | For the time necessary to handle the case or analyse the error, and thereafter they are deleted or anonymised, unless they are necessary for the purposes of security, pursuit of or defence against claims. |
| Server and update technical logs | For the period adopted in the security configuration and no longer than is necessary for the purposes of security, diagnostics and accountability. |
| Visit statistics data | The IP address is not stored. The technical hash used to distinguish views within a single visit is deleted after 24 hours. Aggregate statistics are kept for no longer than 13 months. |
| Correspondence | For the period of handling the matter and thereafter for a period justified by the nature of the relationship or by the limitation period for claims. |
| Cookie data | In accordance with the lifetime of the given cookie file or until the cookies are deleted by the user; cookies other than necessary ones in accordance with the consent granted. |
9. Rights of data subjects
A data subject has the right to access their data, obtain a copy of them, request their rectification, erasure, restriction of processing, portability, to object to processing based on a legitimate interest, and to withdraw consent to the processing of such data where the processing takes place on the basis of consent. Requests should be sent to: contact@inspectrabim.com.
In the case of the newsletter, withdrawal of consent or cancellation of the subscription is possible at any time, in particular by means of the unsubscribe link placed in a message delivered as part of the newsletter or by contacting the Controller. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. If a Website user withdraws consent to the newsletter, the Controller will not use their data further for sending the newsletter, unless there is another independent legal basis for limited processing, e.g. documenting the withdrawal of consent or defending claims.
The Controller responds without undue delay, as a rule within one month of receiving the request. This period may be extended by a further two months due to the complex nature of the request or the number of requests. A data subject also has the right to lodge a complaint with the President of the Personal Data Protection Office.
10. A request to delete an account and the Keygen system
Deletion of a Website user account need not automatically result in the deletion of data in the Keygen system, over which the Controller may have no influence.
11. Newsletter and marketing communication
The newsletter is a voluntary service. Signing up to the newsletter is not a condition for creating a user account on the Website, purchasing a licence for the Inspectra BIM software, using the free version of the product or obtaining technical support. The newsletter may cover in particular information about the product, updates, educational materials, events, promotions, new functionalities of the Inspectra BIM software and content concerning BIM technology.
In order to use the newsletter, the user should provide at least an e-mail address and give the required consents.
The Controller may apply a sign-up confirmation mechanism, including double opt-in, i.e. sending a message with an activation link. If the newsletter has not yet been launched, a Website user's sign-up may be treated as a declaration of the wish to receive the newsletter once it is launched, while retaining the right to cancel before sending begins.
Cancellation of the newsletter is possible at any time, without giving a reason and without incurring costs other than the ordinary costs of data transmission. Cancellation of the newsletter does not result in deletion of the Website user account or loss of the licence for the Inspectra BIM software, unless the Website user independently requests the exercise of a separate right concerning personal data.
12. Cookies and similar technologies
The Website may use cookies necessary to ensure the proper operation of the site, signing in, security, maintaining the user session and remembering decisions concerning the cookie banner. If analytical, marketing or other than necessary cookies are implemented in the future, the Controller should implement a prior consent mechanism compliant with the GDPR and other generally applicable laws, including in particular the Act of 12 July 2024 – Electronic Communications Law, and update this privacy policy.
13. Automated decision-making
The Controller does not take decisions in relation to users based solely on automated processing of data that would produce legal effects concerning them or similarly significantly affect them. The licensing mechanism may automatically assign entitlements to product features on the basis of the type of licence, but this does not constitute profiling within the meaning of the decisions referred to in Article 22 GDPR.
14. Data security
The Controller applies technical and organisational measures appropriate to the risk, in particular access control, individual Website user accounts, the principle of least privilege, password protection, encryption where adequate, backups, restriction of administrative access, documenting breaches and periodic reviews of providers and systems. Data transferred for the purposes of the newsletter should be accessible solely to the persons and systems necessary to handle sending, document consents and carry out unsubscriptions.
15. Changes to the Policy
The Policy may be updated in the event of a change in the functionality of the Inspectra BIM software, the launch of or a change to the rules of the newsletter, the implementation of the use of new cookies or replacement of those currently used, a change of technology providers, a change in the law, a change in the scope of data or the commencement of employing staff.