Legal

Data processing addendum.

Effective October 4, 2026

These terms govern personal information that BIMRelay processes on a business customer's behalf.

1. Scope and documented instructions

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement governing BIMRelay between Sabrene Software LLC ("Sabrene") and the business customer identified in its account, billing records, or order ("Customer"). It applies when Sabrene processes personal information in Customer Data on Customer's behalf ("Customer Personal Data"), including when applicable data-protection law describes the parties as controller and processor, or processor and subprocessor. Customer must have authority from the relevant controller. Independent account, billing, security, and website processing is described in the Privacy Policy.

Each party will comply with data-protection law applicable to its role. Customer determines the purposes and means of processing, the information it submits, and the lawfulness of its instructions. The agreement, this DPA, selected settings, and actions by authorized users constitute documented instructions to provide, support, secure, and maintain the requested Service. Sabrene will process Customer Personal Data only on those instructions, including for transfers, unless law requires otherwise. We will notify Customer before legally required processing unless prohibited, and promptly inform it if we believe an instruction infringes applicable data-protection law. Additional instructions require agreement where they change the Service.

Sabrene will not sell Customer Personal Data, use it for cross-context behavioral advertising, train general-purpose AI models with it, or permit its AI providers to train their models with it. Where service provider or contractor restrictions under applicable U.S. state privacy law apply, Sabrene will not retain, use, or disclose this information outside the direct business relationship or for purposes other than the specified services, or combine it with unrelated personal information except as permitted by that law. We will notify Customer if we can no longer meet those obligations and allow reasonable steps to stop and remediate unauthorized processing.

2. Confidentiality and security

Sabrene will restrict access to people who need it for authorized purposes and are subject to confidentiality duties. We will maintain appropriate technical and organizational measures taking account of the processing, risks, and available technology. Section 7 describes the measures for this Service. We may update measures without materially reducing the overall protection of Customer Personal Data. Customer remains responsible for its credentials, authorized users, access decisions, source data, and secure use of the Service.

3. Subprocessors

Customer generally authorizes the subprocessors identified in the provider list for the purposes described there. Before a new or replacement subprocessor processes Customer Personal Data, Sabrene will give the designated customer contact at least 30 days' notice, ordinarily by email, identifying the provider and purpose. Updating the list alone does not replace that notice. Customer may object within that period on reasonable data-protection grounds. The parties will seek a reasonable resolution; if none is available, Customer may terminate the affected service before the change and receive a refund of unused prepaid fees for that service.

Sabrene will impose binding confidentiality and data-protection obligations appropriate to the processing and no less protective than the applicable obligations of this DPA. Sabrene remains responsible for its subprocessors' performance of those obligations. Providers that Customer contracts with independently, or directs us to connect to, remain subject to their own agreements; this does not excuse Sabrene's own processing obligations. Customer must maintain an accurate contact for notices.

4. Requests, security incidents, and compliance assistance

Taking account of the processing and information available to us, Sabrene will reasonably assist Customer with individual privacy requests, security obligations, impact assessments, and consultation with authorities. We will refer requests about customer-controlled information to Customer rather than make independent decisions about them, unless law requires otherwise. Customer can contact hello@bimrelay.com for assistance.

Sabrene will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, provide available information needed for Customer's obligations, supplement it as the investigation progresses, and take appropriate mitigation steps. Notice is not an admission of liability. Customer decides and makes its own required notices to individuals and authorities. Unsuccessful attempts without compromise of personal information are not personal-data breaches.

We will make information reasonably necessary to demonstrate compliance available to Customer and allow legally required audits, including inspections. Ordinarily, review starts with relevant documentation, and any further audit uses an independent auditor, reasonable notice, confidentiality, and safeguards for other customers and system security. Routine audits occur no more than annually; that limit does not apply where law, an authority, or a reasonable concern about a breach requires additional review. Customer bears reasonable costs of additional assistance and audits unless caused by Sabrene's breach or applicable law requires otherwise. These procedures do not prevent a required audit or delay a statutory response.

5. Return and deletion

Customer may obtain supported exports during its authorized access and instruct deletion through the Service or by contacting us. At the end of processing services, Sabrene will, at Customer's choice, return or delete Customer Personal Data and delete remaining copies unless law requires retention. The retention and deletion procedures explain the processing schedule, recovery limitations, and backup handling. Where those procedures cannot meet a mandatory legal requirement, we will coordinate a compliant return or deletion with Customer; the ordinary schedule does not override law. Retained information remains protected and restricted to its lawful purpose. Cancellation alone does not instruct deletion while Customer continues to use retained or archived content.

6. International transfers

Customer instructs processing in countries where Sabrene and its authorized providers operate, subject to applicable transfer requirements. Sabrene will use a legally available transfer mechanism before making a restricted transfer, complete required assessments, and implement necessary supplementary safeguards. An adequacy decision applies to the recipient and processing within its scope. The contractual safeguards below apply to eligible transfers from Customer to Sabrene.

European Economic Area

Where a transfer from Customer to Sabrene requires contractual safeguards and these clauses are legally available for that transfer, the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated into this DPA without modification. Read the official EU SCCs. Module Two applies when Customer is a controller and Module Three when Customer is a processor. Customer is the exporter and Sabrene the importer. Clause 7 applies; the optional language in Clause 11 does not. Clause 9 uses general authorization with the 30-day notice period in section 3. Clause 17 uses Option 1 and Irish law, and Clause 18 specifies the courts of Ireland. The competent supervisory authority is determined under Clause 13 by Customer's establishment, representative, or the location of relevant individuals. Section 7 supplies Annex I and Annex II; the provider list identifies the authorized subprocessors.

United Kingdom

For eligible UK restricted transfers requiring contractual safeguards, the EU SCCs above apply with the International Data Transfer Addendum issued by the UK Information Commissioner ("UK Addendum"). Its Part 1 tables are completed as follows: Table 1 uses the parties, contacts, and effective date in section 7; Table 2 uses the EU SCCs and selections above; Table 3 uses section 7 for the appendix information; Table 4 selects neither party as entitled to end the Addendum solely because the approved Addendum changes. The following mandatory clauses are incorporated by reference:

Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.

Official UK Addendum and guidance. The mandatory text above is reproduced under the Open Government Licence v3.0.

Mandatory transfer clauses control over conflicting provisions, including liability, audit, governing-law, and dispute provisions. Their individual third-party-beneficiary rights are not limited by the Terms. Where the selected clauses are not legally available, or cannot provide required protection, the parties must establish another lawful mechanism before the affected transfer, or suspend it. Customer may request a copy of the applicable safeguards and the relevant completed details from our contact below.

7. Processing and transfer details

Parties and acceptance — Annex I.A

Customer's legal identity, address, and designated contact are those supplied in its account, billing records, or written order; Customer must provide accurate details and any missing transfer-party information before a restricted transfer. Customer's activity is using BIMRelay for its business projects, as controller or processor according to the applicable instructions. Sabrene is the processor or subprocessor providing BIMRelay: Sabrene Software LLC, 3400 Cottage Way, Ste G2 #9114, Sacramento, CA 95825, United States; contact hello@bimrelay.com. Acceptance of the agreement incorporating this DPA constitutes the parties' electronic execution of this DPA and any applicable incorporated transfer clauses. The effective date for those parties is the date of that acceptance, or a different date in their signed agreement. An invited user's personal acceptance does not substitute for an organization's authorized acceptance.

Processing description — Annex I.B

  • Individuals: authorized users, collaborators, customer and supplier contacts, and other individuals whose information Customer includes in project content.
  • Information: names, business contact details, roles, identifiers, authorship, activity, and personal information embedded in model files, workbook content, comments, settings, and deliverables. Customer determines the content; unnecessary personal information should not be submitted.
  • Sensitive information: sensitive or specially regulated information is not intended for the Service. Any agreed exception requires a separate written agreement specifying permitted categories and additional safeguards before processing.
  • Purpose and operations: receiving, storing, accessing, organizing, generating, validating, analyzing, transmitting, displaying, and deleting information to provide the instructed model, workbook, collaboration, AI-assisted, support, and export functions.
  • Frequency and duration: ongoing as users interact with the Service, for the agreement's duration and the return, deletion, or lawful retention period described in section 5. Subprocessors process only for their listed service functions and applicable duration.

Technical and organizational measures — Annex II

  • Access and confidentiality: authenticated accounts, server-side workspace and project membership checks, and role restrictions on changes. Access sessions expire or can be revoked; refresh credentials are rotated and held in encrypted, HTTP-only cookies. Personnel access is limited to authorized purposes and subject to confidentiality obligations.
  • Credentials and transmission: account passwords are stored as hashes, persisted Autodesk tokens and service-account private keys are encrypted, and deployment secrets are restricted to the server-side configuration. Public service connections use encrypted transport. Object-storage transfers use signed URLs with an expiration; workbook download links expire after five minutes.
  • Integrity and reliability: server-side request and permission validation, recorded workbook changes and operational events, extraction and export job-status tracking, and retry handling for failed background work. Operational logs and hosting monitoring support investigation of failures and access incidents.
  • Lifecycle and response: workbook export functions, a scheduled project-deletion process, and queued cleanup of stored project objects and Autodesk artifacts with retries for failed cleanup. Incident handling includes investigation, mitigation, and the notifications and privacy-request assistance described in section 4.
  • Providers and review: binding processing restrictions, restricted provider access, and review of safeguards as the Service and risks change. AI processing is limited to requested features and excludes model training.

Additional security, service-level, or data-residency requirements may be agreed in writing. The competent authority for Annex I.C is determined as described in section 6; Customer must identify it where needed to complete the transfer record.

8. General terms

This DPA controls over the agreement on processing Customer Personal Data; mandatory transfer clauses control over this DPA. Otherwise the agreement's liability limits and dispute terms apply, without creating a separate liability cap or limiting nonwaivable rights. A signed customer-specific DPA may replace this DPA where expressly agreed. Changes follow the agreement's notice and acceptance provisions and cannot reduce mandatory transfer protections. Relevant obligations survive for as long as Sabrene retains Customer Personal Data. Requests and notices may be sent to hello@bimrelay.com.