Products ▾
Apps
Cloyabimover
Archicad add-ons
Locus
About Contact Login
EN ▾
EN DE

Last updated: 31 July 2026

1. Controller and Contact

The controller responsible for data processing under applicable data protection laws (including the Swiss Federal Act on Data Protection (revDSG) and the EU General Data Protection Regulation (GDPR)) is:

bimover GmbH
Hammer 19
5000 Aarau
Switzerland
UID: CHE-132.862.302
Email: support@bimover.ch


2. Scope of This Privacy Policy

This Privacy Policy applies to:

  • the use of our applications (“Apps”)
  • our website at bimover.ch, including subdomains

We aim to process only the data required to operate authentication, licensing, purchases, support and security.


3. Data We Process

Depending on your usage, we process the following categories of personal data:

  • Apple Sign in subject identifiers (SIWA subject) and email address (including Apple relay email, if used)
  • internal account identifier (usr_...)
  • licensing and entitlement records (license tier, grants, redeem/transfer code status, eligibility status, add-on download counters/timestamps)
  • payment/commerce records (transaction references, order status, line-item references, optional customer email, webhook reconciliation records)
  • security/session records (API session token hashes, device ID, optional device metadata, last-used timestamps, limited request metadata such as IP-derived network information for pricing/tax preview and fraud controls)
  • audit and operations records (request IDs, event logs, security-relevant events)
  • in-app notification preferences for the bimover app (see below)

We do not build advertising profiles and we do not use analytics or marketing pixels on our website.

In-app notices (bimover app)

The bimover app can display notices from us inside the app: operational and security notices (always shown), product news and offers (both can be disabled in the app settings at any time, per category).

For this feature we store only your per-category choice (allow product news yes/no, allow offers yes/no) linked to your account. Which notices you have read is stored locally on your device only — we do not track reading behaviour on our servers, and we do not build profiles from this feature. Notices are delivered when the app fetches them; no marketing emails and no advertising push notifications are sent.

If you submit a feature request or vote on one in the app, we process the content you wrote, your vote and your account identifier. Submissions are reviewed before publication and are shown to other users without your name or email address; internally we keep the link to your account so we can inform you about the status and remove your submission on request. Legal basis: our legitimate interest in improving our products together with our customers (Article 6(1)(f) GDPR); submitting is entirely voluntary. Please don’t put personal data of others or confidential project information into a submission (see Terms §9.2).

We also process support ratings you choose to give: after a support ticket is solved you may rate it in the app (an overall score, or separate scores for solution, process and friendliness, plus an optional comment). Rating is voluntary, one rating per ticket, and is linked to your account and that ticket so we can improve our support. Please don’t put sensitive information into the free-text comment.

Legal basis: operational and security notices are processed for contract performance (Article 6(1)(b) GDPR); product news and offers to existing customers rely on our legitimate interest in informing customers about our own, similar products and services (Article 6(1)(f) GDPR and Swiss law incl. the Unfair Competition Act), always combined with the free, immediate opt-out in the app. Support ratings are processed on the basis of your voluntary submission and our legitimate interest in support quality (Article 6(1)(f) GDPR). Images shown in notices are hosted by us — no third-party servers are contacted from within the app. Your category choice is kept until you change it or your account is deleted.

Cloya app telemetry (opt-in)

The statement above continues to apply to this website. Separately, the Cloya app offers anonymous usage statistics — only with your explicit consent (opt-in, off by default), fully anonymous (a random, resettable installation ID; never linked to your account), and no IP addresses are stored server-side. Details, legal basis and retention: Cloya App Privacy — Telemetry.


4. Cookies and Similar Technologies

Our website uses strictly necessary cookies for account login/session management:

CookiePurposeDurationType
bimover_web_sessionKeeps you logged in to your website accountUp to 30 days or until logoutEssential, first-party
bimover_web_deviceStable device identifier for secure web session issuanceUp to 365 daysEssential, first-party

These cookies are required to provide the login/account service requested by you. Cookie attributes used for these cookies include HttpOnly and SameSite=Lax; Secure is used on HTTPS/production.

We do not use analytics/marketing cookies.

If you use third-party login or checkout components (Apple, Microsoft, Payrexx), those providers may use their own technologies under their own policies.


5. Sign in with Apple (Unified Account for Apps and Website)

We use Sign in with Apple for website authentication and app authentication. The same identity is used across website and supported apps; we do not operate a separate app/web account-linking model.

When you sign in, we process:

  • Apple subject identifier
  • email address (or Apple relay address)

We do not process passwords. Authentication is performed by Apple.

App login claim flow

When app login is started from a supported app, the website can issue a short-lived app-login claim token.

For this flow, we generate a short-lived token (default: 15 minutes), store only a hash of that token server-side, and complete app login after successful claim confirmation from the matching app bundle. The deep link payload contains technical claim context (for example bundle_id and a claim token).

Purpose:

  • sign the app into your existing website account identity
  • allow the app to retrieve the correct license and entitlement state

6. Licensing, Eligibility and Account Data

To operate licensing, we process:

  • account ID, app bundle ID, SIWA-linked identity records
  • license/entitlement state and hierarchy (for example trial/personal/professional)
  • redeem and transfer code lifecycle (unused/redeemed/revoked)
  • eligibility requests (for example educational eligibility), including token hash/hint and status data

This processing is required to enforce license rules, entitlement integrity, and anti-abuse controls.


7. Payments, Invoicing and Payrexx

We sell our subscriptions ourselves; bimover GmbH is the contracting party and issues the invoice. Card payments are processed by our payment service provider Payrexx AG (Switzerland), which processes payment method data on our behalf. Business customers may instead be invoiced.

From Payrexx transactions and webhooks, we may process and store:

  • transaction and subscription IDs and our own order references
  • status changes (including failed payments, refunds and chargebacks)
  • amount, currency and billing period
  • the business details you provide for invoicing (company, address, country, VAT ID where applicable)
  • webhook payload data required for reconciliation, accounting evidence, fraud prevention, and entitlement changes after a refund

We use this data to activate, renew, suspend and end subscriptions correctly, and to meet our bookkeeping obligations.

We never receive or store full card numbers or CVV — those stay with the payment service provider.

Payrexx privacy policy: https://www.payrexx.com/en/privacy-policy/


8. Security, Session and Audit Logging

We process technical security/session data, including:

  • API token hashes (not plaintext token storage)
  • device/session metadata (device ID, optional device name/platform/version)
  • session usage/revocation timestamps
  • audit/security events with request identifiers

Error and audit logs may include operational request context (for example bundle ID, offer code, request ID, and status/error codes). Sensitive token/secret fields are redacted in structured error logging. Audit logs are used for security monitoring, incident handling, and legal defense.


9. Data Sharing

We do not sell personal data.

Data may be shared with:

  • Apple (authentication)
  • Payrexx AG (payment processing on our behalf)
  • infrastructure/service providers required to operate our services (for example hosting/network delivery), under applicable confidentiality and data protection obligations
  • authorities or courts where legally required

10. International Transfers

Depending on provider infrastructure (for example Apple, Microsoft, hosting/network providers), data may be processed outside Switzerland/EU/EEA. Payment processing itself runs with a Swiss provider.

Where required, transfers are based on applicable legal transfer mechanisms and safeguards.


11. Data Retention

We retain data only as long as necessary for the stated purposes and legal obligations.

Typical retention logic:

  • web session cookie: up to 30 days
  • web device cookie: up to 365 days
  • app-login claim token validity: short-lived (default 15 minutes); expired/consumed tokens become unusable (related hashed records may remain until operational cleanup)
  • eligibility request token validity: limited lifetime (default 14 days unless resolved earlier); related request records may be retained for support, anti-abuse, and audit/legal needs
  • account/licensing/payment records: for contract execution, fraud/security controls, and legally required accounting/tax retention periods
  • audit logs: operational retention windows (default cleanup policy targets 6 months unless longer retention is required)

You may request deletion of your data at any time, unless retention is legally required.


12. Legal Basis for Processing

Under GDPR, processing is generally based on:

  • Article 6(1)(b) GDPR (contract performance)
  • Article 6(1)(c) GDPR (legal obligations, where applicable)
  • Article 6(1)(f) GDPR (legitimate interests: secure service operation, fraud prevention, entitlement integrity, and in-app product information to existing customers with opt-out)

Under Swiss law, processing is based on lawful purpose, proportionality, transparency and data security under the revised FADP (revDSG).


13. Your Rights

Depending on applicable law, you may have rights to:

  • access your data
  • rectification
  • deletion
  • restriction or objection
  • data portability (where applicable)

Contact: support@bimover.ch

You may also contact the competent supervisory authority.


14. Changes to This Privacy Policy

We may update this Privacy Policy as our services evolve or legal requirements change.

The current version is always published on our website.


Imprint Privacy Terms
© 2026 bimover