Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the ForensicBIM Terms of Service and applies automatically to every customer that accepts them. Customers who need a signed copy can request one at support@forensicbim.business; it contains the same terms.
Parties
This DPA is entered into between:
- ForensicBIM, Claude Debussylaan 82-84, 1082 MD Amsterdam, The Netherlands ("ForensicBIM" or "Processor"); and
- the organisation that accepts the ForensicBIM Terms of Service or signs this DPA ("Customer" or "Controller").
Background. ForensicBIM provides an online platform that audits and values IFC model data (the "Service") under the ForensicBIM Terms of Service or another agreement for the Service (the "Main Agreement"). When Customer uploads models, ForensicBIM processes personal data contained in them on Customer's behalf. This DPA sets out the terms of that processing as required by Article 28 of the GDPR and other Data Protection Laws. It forms part of the Main Agreement and takes effect when Customer accepts the Terms of Service or, for a signed copy, on the date of the last signature.
1. Definitions
1.1 Terms such as "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meaning given to them in the GDPR.
1.2 In this DPA:
- Customer Personal Data means personal data that ForensicBIM processes on behalf of Customer under the Main Agreement, as described in Annex 1.
- Data Protection Laws means Regulation (EU) 2016/679 ("GDPR"), the Dutch GDPR Implementation Act (Uitvoeringswet AVG), the UK GDPR and Data Protection Act 2018, and any other data protection law that applies to the processing, including US state privacy laws where applicable.
- Model Content means the IFC files and other content Customer uploads to the Service, and the files and analysis results generated from them.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- Region means the storage and processing region Customer selects for each upload.
- SCCs means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 and, for transfers from the UK, the UK International Data Transfer Addendum.
- Sub-processor means any third party engaged by ForensicBIM that processes Customer Personal Data.
2. Scope and roles
2.1 For Model Content and the Customer Personal Data it contains, Customer is the controller and ForensicBIM is the processor.
2.2 ForensicBIM is an independent controller for the personal data it needs to run its own business: user account details, sign-in and security logs, billing records, support correspondence and website statistics. ForensicBIM's Privacy Policy applies to that data. ForensicBIM is also an independent controller for the use of Model Content to improve the Service, within the limits of section 12.
2.3 Annex 1 describes the subject matter and duration of the processing, its nature and purpose, the types of personal data and the categories of data subjects.
2.4 Customer is responsible for the lawfulness of the Customer Personal Data it uploads, including having a legal basis to share the personal data contained in its models, such as the names and contact details of model authors.
3. Processing on documented instructions
3.1 ForensicBIM processes Customer Personal Data only on Customer's documented instructions, including with regard to transfers, unless EU or Member State law requires otherwise. In that case ForensicBIM informs Customer before processing, unless that law prohibits it.
3.2 Customer's instructions are this DPA, the Main Agreement, and the choices Customer's users make in the Service, such as the Region, the optional buildingSMART validation, share links and deletions.
3.3 ForensicBIM informs Customer without delay if, in its opinion, an instruction infringes Data Protection Laws.
3.4 Optional buildingSMART validation. If a user selects this option, Customer instructs ForensicBIM to send the IFC file to buildingSMART International Limited through validate.buildingsmart.org. buildingSMART processes the file under its own terms as an independent party, not as ForensicBIM's Sub-processor. Files over 256 MB and files without an official IFC schema are never sent. Customer can prevent such transfers by instructing its users not to select the option.
4. Confidentiality and staff access
4.1 ForensicBIM ensures that everyone it authorises to process Customer Personal Data is bound by a duty of confidentiality.
4.2 Analyses run automatically. ForensicBIM staff access Model Content only:
- to provide support that Customer requests, or when a user sends feedback and allows access to the analysis and model;
- to test and calibrate its algorithms, where the account's setting allows it (section 12);
- to investigate a security incident or abuse of the Service; or
- where EU or Member State law requires it.
4.3 Every download of a model file by ForensicBIM staff is logged with the staff member, the file, the time and the IP address. On request, ForensicBIM gives Customer an extract of these logs for its Model Content.
5. Security of processing
5.1 ForensicBIM implements the technical and organisational measures described in Annex 2, which ensure a level of security appropriate to the risk, as required by Article 32 GDPR.
5.2 ForensicBIM may update these measures, provided the overall level of security does not decrease.
5.3 Customer is responsible for the security of its own use of the Service, including keeping sign-in emails and share links confidential and removing users who should no longer have access.
6. Sub-processors
6.1 Customer gives ForensicBIM general written authorisation to engage Sub-processors. The Sub-processors approved on signing are listed in Annex 3.
6.2 ForensicBIM informs Customer at least 30 days before adding or replacing a Sub-processor, by email to Customer's contact in Annex 1 or, if none is named, to the account holder's email address, and by updating the list of Sub-processors on this page.
6.3 Customer may object on reasonable data protection grounds within those 30 days. The parties will discuss the objection in good faith. If they cannot resolve it, Customer may terminate the affected part of the Service and receive a pro-rata refund of fees prepaid for it.
6.4 ForensicBIM imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA. ForensicBIM remains fully liable to Customer for the performance of its Sub-processors.
7. Data location and international transfers
7.1 Model files and the files generated from them are stored in the Region Customer selects for each upload, and analysed by a worker in that same Region. If that worker cannot be started, the analysis fails; ForensicBIM never processes the file in another Region instead. The available Regions are the Netherlands, United States (Iowa), United Kingdom (London), Singapore, Hong Kong, Australia (Sydney), Japan (Tokyo) and Brazil (São Paulo).
7.2 Analysis records, which can contain personal data read from model files (such as author and organisation names), are stored in Google Cloud Firestore in the EU (Belgium and the Netherlands).
7.3 Selecting a Region outside the European Economic Area is Customer's instruction to store and process Model Content there.
7.4 ForensicBIM ensures that any transfer of Customer Personal Data by ForensicBIM or its Sub-processors to a country outside the EEA or the UK without an adequacy decision is covered by the SCCs (Module 3, processor to processor) concluded with the relevant Sub-processor, or by the EU-U.S. Data Privacy Framework where that Sub-processor is certified.
7.5 Where Customer is established outside the EEA, Module 4 (processor to controller) of the SCCs applies between the parties for transfers from ForensicBIM to Customer and is incorporated by reference. For clauses 17 and 18 of Module 4, the parties choose Dutch law and the courts of Amsterdam. Annexes 1 to 3 of this DPA complete the annexes of the SCCs.
8. Assistance
8.1 Taking into account the nature of the processing, ForensicBIM assists Customer, through appropriate technical and organisational measures, in responding to requests from data subjects. In the Service itself, Customer can download model files and reports, delete analyses and delete user accounts.
8.2 If ForensicBIM receives a request from a data subject about Customer Personal Data, it forwards the request to Customer without undue delay and does not respond to it, other than to confirm that it has been forwarded.
8.3 ForensicBIM provides reasonable assistance, with the information available to it, for Customer's data protection impact assessments and prior consultations with supervisory authorities.
8.4 ForensicBIM may charge its standard rates for assistance that goes beyond the self-service functions of the Service and the information in this DPA, unless the assistance is needed because ForensicBIM breached this DPA.
9. Personal Data Breaches
9.1 ForensicBIM notifies Customer without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach.
9.2 The notification describes, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information that is not yet available is provided in phases, without further undue delay.
9.3 ForensicBIM takes reasonable steps to contain and remedy the breach, and cooperates with Customer on any notification to supervisory authorities and data subjects. Customer decides whether to make those notifications.
9.4 Notifications are sent to Customer's contact in Annex 1 or, if none is named, to the email address of the account holder concerned.
10. Audits and information
10.1 ForensicBIM makes available to Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including its security policies, answers to reasonable security questionnaires and, once available, third-party audit reports.
10.2 If that information is not sufficient, Customer may audit ForensicBIM, itself or through an independent auditor bound by confidentiality. Audits take place at most once a year, with at least 30 days' written notice, during business hours and without unreasonable disruption. An additional audit is allowed after a Personal Data Breach or when a supervisory authority requires one.
10.3 Each party bears its own audit costs. Audits do not extend to other customers' data or to ForensicBIM's trade secrets, including the calculation methods behind its valuations.
11. Return and deletion
11.1 During the term, Customer can download and delete its Model Content at any time in the Service. Deleting an analysis removes the IFC file, every file generated from it, the analysis record and any share links to it.
11.2 When the Main Agreement ends, ForensicBIM deletes all Customer Personal Data within 30 days, unless Customer asks within that period to export it first, or EU or Member State law requires ForensicBIM to keep it. Deleted files are then permanently erased from Google Cloud Storage's recovery store after 7 days. Copies of IFC files used to improve the Service under section 12 are deleted at the same time.
11.3 On request, ForensicBIM confirms the deletion in writing.
11.4 Copies sent to buildingSMART on Customer's instruction (section 3.4) are outside ForensicBIM's control and are governed by buildingSMART's terms.
12. Use of data to improve the Service
12.1 The Service lets each user choose how Model Content may be used to improve ForensicBIM's algorithms, scoring, benchmarks and quality thresholds: "use analysis and IFC" (the default), "use analysis without IFC" or "do not use". Customer instructs ForensicBIM to use Model Content according to the setting of the account that uploaded it. A change applies to later uploads. Customer can ask ForensicBIM in writing to apply one setting to all its accounts and to Model Content already uploaded.
12.2 For the use described in this section, ForensicBIM acts as an independent controller and its Privacy Policy applies. Customer confirms that it may make Model Content available for this purpose, including any personal data it contains, and that it has informed the people concerned where the law requires it.
12.3 Under "use analysis and IFC", ForensicBIM may use IFC files and their analysis results to test and calibrate its algorithms. ForensicBIM:
- limits access to authorised staff and logs every download (section 4.3);
- does not use personal data contained in model files for any other purpose;
- never publishes or sells model files, and never shares them with third parties or other customers;
- uses only anonymised, aggregated results outside its own team, such as published benchmarks; and
- deletes its copies when the model is deleted or when Customer asks.
12.4 Under "use analysis without IFC", ForensicBIM uses only anonymised, aggregated analysis results, such as element counts, quality scores and data-density metrics. Before such use, it removes all personal data, such as author names, organisation names and contact details, and all information that identifies Customer or a specific asset, including file names and georeferenced locations.
12.5 Under "do not use", ForensicBIM does not use Model Content to improve the Service.
12.6 Unless the setting is "do not use", ForensicBIM may reuse the analysis results of a file when another customer uploads an identical file, instead of analysing it again. Customer's identity is not passed on.
12.7 Anonymised data is no longer personal data, and ForensicBIM may keep it after this DPA ends.
12.8 ForensicBIM never sells Customer Personal Data and never uses or shares it for advertising.
13. Liability, term and general provisions
13.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Main Agreement. This does not limit either party's liability towards data subjects under Article 82 GDPR.
13.2 This DPA applies for as long as ForensicBIM processes Customer Personal Data under the Main Agreement. Sections 10, 11 and 13 continue to apply after that for as long as needed.
13.3 If this DPA conflicts with the Main Agreement, this DPA prevails for the processing of Customer Personal Data. If it conflicts with the SCCs, the SCCs prevail.
13.4 If a provision of this DPA is invalid, the rest remains in force, and the parties replace the invalid provision with a valid one that comes as close as possible to its purpose.
13.5 Changes to a signed copy of this DPA are valid only in writing and signed by both parties. For other customers, ForensicBIM may update this DPA in the same way as the Terms of Service (section 18 of the Terms). ForensicBIM may update Annexes 2 and 3 as described in sections 5.2 and 6.2.
13.6 This DPA is governed by Dutch law. Disputes are submitted exclusively to the competent court in Amsterdam, unless the Main Agreement chooses another law and court or the SCCs require otherwise.
Annex 1: Description of the processing
| Item | Description |
|---|---|
| Subject matter | Storing, auditing and valuing Customer's IFC model data in the Service. |
| Duration | The term of the Main Agreement, plus up to 30 days for deletion (section 11). |
| Nature of the processing | Upload and storage; automated analysis of geometry, data and schema, and valuation; generation of 3D previews, thumbnails, heatmaps and reports; display to Customer's users; sharing through links Customer creates; optional transfer to buildingSMART (section 3.4); deletion. |
| Purpose | Providing the Service to Customer under the Main Agreement. |
| Categories of data subjects | People named in Model Content, such as model authors, designers, engineers and representatives of asset owners; Customer's users, to the extent their details are linked to Model Content or analysis records. |
| Types of personal data | Names, organisation names, roles, email addresses, phone numbers and other contact details contained in IFC headers, owner history and property values; the account email linked to each analysis; asset locations, where they can be linked to an individual (for example a private home). |
| Special categories of personal data | None. Customer does not upload special categories of personal data. |
| Frequency | Continuous, for as long as Customer uses the Service. |
| Customer contact for notifications | As named in a signed copy of this DPA; otherwise the account holder's email address. |
| ForensicBIM contact | support@forensicbim.business |
Annex 2: Technical and organisational measures
| Area | Measures |
|---|---|
| Encryption | HTTPS/TLS for all traffic, with HTTP Strict Transport Security (1 year, preload). Data at rest encrypted by Google Cloud (AES-256). |
| Regional isolation | A separate storage bucket per Region. Analysis runs in a dedicated worker job in the same Region, with no fallback to another Region or service. |
| Customer access control | Passwordless sign-in by email link or Google account. Storage rules limit uploads to the uploading account, under opaque user IDs instead of email addresses. Every download checks ownership. Sessions end after 60 minutes of inactivity. Secure, HttpOnly, SameSite cookies and CSRF protection. |
| Staff access control | Multi-factor authentication on cloud, code and password-manager accounts. Administrator rights only for named accounts with a verified email address. Least-privilege service accounts. Administrative actions and staff downloads of model files are logged and kept for 12 months. |
| Application security | Content Security Policy, clickjacking protection, MIME-sniffing protection, strict referrer and permissions policies. reCAPTCHA on uploads without an account. Disposable email domains blocked. Upload limits: IFC files only, 5 GB maximum. |
| Secrets | API keys and credentials kept out of source code (environment configuration and Google Secret Manager). Secret scanning in the build pipeline. |
| Monitoring and resilience | Automated platform watchdog every 10 minutes (stalled analyses, storage hygiene, security events). Security event logging. Server logs kept for 12 months. Deleted files recoverable for 7 days for error recovery only. Documented incident response and disaster recovery plans. |
| Change management | Version control, automated unit and end-to-end test suites, and a compliance pipeline before deployment. |
| Deletion | Self-service deletion of analyses and accounts removes model files, generated files, analysis records and share links. Every deletion is logged. |
| Governance | Written policies for information security, access control and MFA, incident response, disaster recovery, change management, vendor risk, and data retention and disposal, aligned with SOC 2 and ISO 27001 (no certification yet). |
Annex 3: Approved Sub-processors
| Sub-processor | Service | Customer Personal Data involved | Location |
|---|---|---|---|
| Google Cloud (Google Cloud EMEA Limited / Google LLC) | Hosting, regional file storage, analysis workers, database, logging | Model files, generated files, analysis records | Region selected per upload; database in the EU (Belgium, Netherlands) |
| Resend | Email delivery | File names and model thumbnails in analysis-complete emails to Customer's users | United States |
ForensicBIM also uses Stripe, Umami, Google reCAPTCHA and Firebase Authentication for its own purposes as controller (section 2.2). They do not receive Model Content.
Map views load map tiles directly from Esri and OpenStreetMap, and coordinate-system definitions from epsg.io, in the user's browser. These services receive the user's IP address and the map area around the asset. They are not Sub-processors, because ForensicBIM does not send them Customer Personal Data.