Privacy policy
What little data we handle when you visit the site or place an order.
Last updated: 11 September 2026
This site is deliberately thin on data. There is no analytics script, no advertising pixel, no tracker and no third-party cookie. What is described below is all of it.
What we never do, with anyone's data:
- We do not sell it, rent it or share it for anyone else's purposes. Not to advertisers, not to data brokers, not to a partner. The processors listed in section 4 act on our instructions and hold nothing of their own.
- We do not profile you or build a picture of you. No behavioural tracking, no scoring, no automated decision that affects you within the meaning of Article 22.
- We do not follow you across the web, and nothing on this site reports back to anybody who would.
- We do not collect anything we have no use for. There is no field on any form here that exists because the data might be handy one day.
- We do not knowingly hold data about anyone under 18 — see section 8, which says what happens if we find that we do.
What we do hold is in section 2, item by item, with the reason and the legal basis for each. That list is short on purpose, and it is the whole of it — a promise to collect nothing at all would be untrue, and an untrue privacy policy is worse than a frank one.
1. Who is responsible
The controller is DATUM — Ivo Ivanov, a natural person trading from Sofia, Bulgaria — support@datumbim.com. There is no company behind it, and the company details page says so openly rather than leaving a gap; for data protection what matters is that a named person decides these things and answers for them. Write to that address for anything in this policy, including to exercise any of the rights in section 6. We are not required to appoint a data protection officer and have not appointed one; the address above reaches the person who decides these things.
2. What we hold, why, and on what legal basis
Under Article 6 of the GDPR every use of personal data needs a lawful basis. Ours:
| Data | Why | Basis |
|---|---|---|
| Name, billing country, VAT number, payment details | To issue the invoice and charge the right VAT. Collected and held by the payment provider named at checkout, acting as merchant of record; we see the order and the e-mail address, never your card. | Performance of a contract, Art. 6(1)(b); legal obligation for invoicing and tax, Art. 6(1)(c) |
| Your account: e-mail address, a password hash, whether the address is confirmed, and the dates you signed in | To run the account you need in order to buy — where your licence key stays readable, where you release a seat, and where you download again what you have paid for. The password is never stored; what is kept is a PBKDF2 hash from which it cannot be recovered. | Performance of a contract, Art. 6(1)(b) |
| Your purchases: what you bought, when, for how much, and whether a subscription is still running | To know what your licence unlocks, to let you download it again, and to keep the accounting records the law requires. Held by us, in a database on Cloudflare. | Performance of a contract, Art. 6(1)(b); legal obligation to keep accounting records, Art. 6(1)(c) |
| Security records: sign-ins and failed sign-ins, password resets, activations, downloads, and the IP address each came from | To stop somebody guessing their way into your account, to show you which sessions and machines are live so you can end one, and to answer a dispute about whether a purchase was ever delivered. Kept for six months, then deleted automatically. | Legitimate interests, Art. 6(1)(f) — keeping accounts and licences secure. You can object; see section 6. |
| Licence key, and the machine identifier of the computer you activate on | To run the licence: to check the key is yours, to hold you to the seat count you paid for, and to let you move a seat to another machine. The machine identifier is a one-way hash of hardware characteristics — it is not a serial number and cannot be turned back into one. | Performance of a contract, Art. 6(1)(b) |
| The notification list: your e-mail address, the wording of the consent you gave and the moment you gave it, the page you gave it from, and the IP address and browser the request came from | To write to you when there is a release worth knowing about, and for nothing else. The last three are not marketing data — they are the evidence that the consent was actually given, which Article 7(1) requires us to be able to produce. Your address is added as pending until you click the link in the confirmation e-mail; an address that is never confirmed is never written to. | Consent, Art. 6(1)(a). Withdraw it with the unsubscribe link in any message, or by writing to us; withdrawing is as easy as giving it and costs you nothing else. |
| The content of e-mails you send us | To answer you, and to keep a record of what was agreed about an order. | Performance of a contract, Art. 6(1)(b); legitimate interest in keeping our own records, Art. 6(1)(f) |
| A question asked in the box at the side of every page: the question, your e-mail address, and which page you asked it from | To answer it. The question goes straight to our inbox as an e-mail and nothing of it is kept on the server. Your address is not added to the notification list or to anything else, and you are not written to again unless you ask to be. The IP address the question came from is held for an hour as a counter, so the box cannot be used to flood us, and is removed by the nightly clean-up after that. | Steps you asked us to take before any contract, Art. 6(1)(b); legitimate interest in answering questions about what we sell and in keeping the box usable, Art. 6(1)(f) |
| Server logs at our host — IP address, time, page requested, user agent | To serve the page and to keep the site up and unabused. Not used to build a profile, not joined to anything else. | Legitimate interest in operating and securing the site, Art. 6(1)(f) |
We do not process special categories of data, we do not profile you, and there is no automated decision-making that produces a legal or similarly significant effect on you within the meaning of Article 22.
3. What the plugin sends
The Revit add-in talks to two addresses of ours and to nothing else:
api.datumbim.com— the licence server. Receives your licence key, the machine identifier described below and the machine name you gave Windows, and returns a signed entitlement token. It is asked at activation and then roughly once a fortnight to revalidate.datumbim.com/update.json— a plain file listing the current version. Fetching it sends nothing but the request itself.
The machine identifier, exactly. It is a SHA-256 hash, truncated to sixteen bytes, of
two things joined together: the MachineGuid that Windows generated when it was
installed, and your Windows user name. Two consequences worth being straight about, because
this used to be described here as a hash of "hardware characteristics", which it is not:
- It identifies a Windows installation and a user account on it, not a piece of hardware. Reinstalling Windows produces a different one; changing a disk does not.
- Your user name goes into it, and a Windows user name is often a person's own name. It cannot be read back out — a hash does not work that way, and we never receive the name itself — but it is honest to say that it went in rather than to imply the input was anonymous.
What it is for is holding you to the seat count you paid for and letting you move a seat to another machine. It is not used to recognise you anywhere else, and it is never joined to anything outside the licence records.
The add-in does not read, upload or transmit your Revit models, your drawings or any project content. Nothing about what you draw leaves your machine.
4. Who else sees it
| Who | What for | Where |
|---|---|---|
| {{Provider:legal}} | Merchant of record for every purchase: they take the payment, charge and remit the VAT for your country, issue the invoice and deliver the licence key. The payment contract is with them, so for that transaction they are a controller in their own right and their own privacy notice applies alongside this one. They do not hold your DATUM account — that is ours, and section 2 says what is in it. | United States; transfers rest on the safeguards set out in their own terms, and we see the order and the e-mail address, never your card |
| Cloudflare | Hosting and delivery of this site, the licence server, and the database holding accounts, purchases and licence keys | EU and global edge — standard contractual clauses |
| Resend | Sending the e-mails this site and the licence server send, and delivering the questions asked in the box at the side of the page to our inbox | United States — standard contractual clauses |
| Our e-mail provider | Receiving and answering your messages | EU |
Nobody else. We do not sell personal data, we do not share it for advertising, and we have no advertising partners. Where a recipient is outside the EEA, the transfer rests on the standard contractual clauses adopted by the European Commission under Article 46(2)(c) GDPR; write to us for a copy of the relevant clauses.
5. How long
- Orders, invoices and tax records — as long as Bulgarian accounting and tax law requires us to keep them, which is longer than we would otherwise choose.
- Licence keys and activations — for as long as the licence lives, plus a short period afterwards to settle disputes and reissues.
- The notification list — until you unsubscribe, and then the record of the consent is kept a short while longer as proof that writing to you had been lawful. An address that never confirms is deleted rather than kept in case it changes its mind.
- Security records — six months, then deleted by a job that runs nightly. That is not a policy statement about an intention; it is a scheduled deletion in the licence server.
- E-mail correspondence, including questions asked in the box at the side of the page — up to three years from the last message in the thread.
- Server logs — short-lived, and kept by our host under its own retention.
6. Your rights
Under Articles 15 to 22 GDPR you may ask us for a copy of your data, to correct it, to erase it, to restrict or object to its use, and to receive it in a portable form. Where we rely on consent, you may withdraw it at any time, and withdrawing does not affect what was lawful before. Where we rely on legitimate interest, you may object and we will stop unless we have compelling grounds that override yours.
Write to support@datumbim.com. We answer within one month, free of charge.
Some of it we cannot delete on request: an invoice we are legally required to keep stays until that requirement ends. We will say so plainly rather than quietly ignoring the part we cannot do.
You may complain to a supervisory authority. In Bulgaria that is the Commission for Personal Data Protection (Комисия за защита на личните данни, cpdp.bg). If you live elsewhere in the EU, you may complain to your own country's authority instead.
7. Cookies and what the browser stores
There is no consent banner on this site, and nothing here needs one. No analytics, no advertising, no third-party tag, no embed. Since the typefaces were brought in-house there is no request to any other domain at all, so there is nobody to consent to.
The full list — two strictly necessary cookies and about a dozen local-storage keys, each with what it holds and why — is on the cookies page, kept separately because it is the part that changes most often and it is easier to keep honest on its own.
This section used to open with "This site sets no cookies", and that had
stopped being true. Two are set: datum-preview, which is how the pre-launch gate
recognises the owner's own browser, and the sign-in session cookie set by the licence server
when somebody opens an account. Both fall squarely within the strictly-necessary exemption in
Article 5(3) of the ePrivacy Directive, so the conclusion — no banner — was right. The sentence
was still wrong, and a privacy policy that overstates how little it does is not worth more than
one that understates it.
The other correction: the typefaces used to load from
fonts.googleapis.com, which handed every visitor's IP address to Google before a
word appeared. A German court held that unlawful without consent (LG München I, 20 January 2022,
3 O 17493/20). They are now served from this domain, and the Content-Security-Policy no longer
permits Google as a source at all, so it cannot quietly come back.
8. Children and young people
These are professional tools sold to practising architects and studios. The site and the products are not directed at anyone under 18, they are not advertised to children or in places aimed at them, and there is nothing here designed to interest a child.
You must be 18 or over to open an account. You are asked to confirm this at sign-up, on the same tick as accepting these terms. We do not knowingly create an account for, take payment from, or hold data about anyone under 18.
If we learn that we hold a minor's data, we delete it. Not on request and not after a review — the account is closed and the personal data removed, promptly and without asking for a reason. Records the law obliges us to keep, such as an invoice already issued, are kept only for as long as that obligation lasts and are used for nothing else.
If you are a parent, guardian or teacher and believe a child has given us data, write to support@datumbim.com from any address and say so. You do not need to prove anything or fill in a form; we would rather delete something we did not have to than keep something we should not.
Under Article 8 of the GDPR, a child's consent to an online service is valid only above an age each country sets between 13 and 16 — in Bulgaria, 14. That threshold is not what we rely on. The account is limited to 18 because the products are professional tools bought under a contract, and a contract is not something a 15-year-old should be signing with us.
9. Changes
If this policy changes, the date at the top changes with it. If a change matters to people who have already bought, we will say so by e-mail rather than quietly editing the page.
10. The rules this policy follows
- Regulation (EU) 2016/679 (GDPR)
- Directive 2002/58/EC (ePrivacy), as amended by Directive 2009/136/EC
- Закон за защита на личните данни (Bulgaria)
Who the controller is, in the legal sense, is set out on the company details page. See also the cookies page and the refunds page.