UPDATED 2026-09-30
Privacy policy
How VeraBIM processes personal data about you if you have an account or appear in a project.
1. Controller
VeraBIM is operated by Bäckman, Kungälv, Sverige, the controller for the processing of data about your account and your use of the service. You can reach us at support@verabim.com. For data that a company or a project owner enters in its projects (for example names of responsible persons, photos from the construction site, site diary entries, distribution lists and safety observations), the company or project owner is the controller, and we process the data as a processor in accordance with the data processing agreement.
2. What data we process
- Account details: name, e-mail address and password (stored as a salted hash, never in plain text).
- Sign-in and security: sessions with time and browser/device, the number of failed sign-in attempts, settings for two-factor sign-in, and one-time links for confirmation and reset.
- Acceptance of terms: which version of the terms of use you accepted and when.
- Settings: selected language and notification settings.
- Memberships: which companies and projects you belong to and in what role.
- Content you create: tasks, comments, checks, diary entries, markups, photos and files, with your name as sender and the time.
- Activity log: what has been changed in a project, by whom and when. The log belongs to the project.
- People without an account: the email address of recipients of a distribution list and when the recipient confirmed via their acknowledgement link, as well as what is submitted in a public QR form for safety observations (title, description and, if provided, name and photo). This data belongs to the project.
- Push notifications: if you turn on notifications, we store the address that the browser or app gives us to reach the device (no location information).
- Search index: text from uploaded PDF and Word documents is indexed for search within the project. The index is deleted together with the file.
- Sign-in via company directory: name and e-mail address from the company's directory, and a temporary record (a few minutes at most) that links the sign-in attempt together.
- Location: “My location” reads the phone's GPS only in your browser in order to show you in the model. The location is not sent to the server and is not stored.
- Technical data: IP address, time and requested address in server logs for operation, security and troubleshooting. The IP address is also used to limit the number of attempts at sign-in and in public forms.
Name and email address are required to create an account; without them we cannot provide the service. We do not make any decisions based solely on automated processing, and we do not use profiling.
3. Purposes and legal basis
- To provide the service, your account, sign-in, project access and support: performance of a contract (Article 6(1)(b) of the General Data Protection Regulation).
- To send emails and push notifications about your account, invitations, distribution lists, reminders and projects you are part of: performance of a contract (Article 6(1)(b)). We do not send any marketing without your consent.
- To protect the service and the accounts against misuse, keep server logs and troubleshoot: legitimate interest (Article 6(1)(f)).
- To be able to show which terms you have accepted and to establish, exercise or defend legal claims: legitimate interest (Article 6(1)(f)).
- To comply with requirements under law or decisions of public authorities: legal obligation (Article 6(1)(c)).
4. Recipients and sub-processors
What you enter in a project becomes visible to the project's members according to their roles and to recipients to whom the project sends documents. The service runs on our own server in Sweden; the database, the files and the backups are stored in Sweden. Email (confirmations, resets, invitations, distribution lists and reminders) is sent via Simply.com in Denmark, within the EU, which means that the recipient address, subject and message text are processed there. Push notifications are delivered via the push service belonging to your browser or device (for example Google, Apple, Microsoft or Mozilla). The content of the notification is encrypted so that the push service cannot read it.
We disclose data to public authorities when required by law or a decision of a public authority. If the operation of the service is transferred to a company or someone else, the data is transferred with it, and we will inform you of this. We never sell personal data.
5. Transfers outside the EU/EEA
The database, the files and email are processed within the EU/EEA. The push services are operated by companies that may process data outside the EU/EEA, for example in the USA. They receive the device's push address and the time and size of each notification, but cannot read the content. The transfer to the USA is supported by the European Commission's adequacy decision (EU–US Data Privacy Framework) for the providers that participate in it, and otherwise by the fact that it is necessary to deliver notifications that you yourself have turned on (Article 49(1)(b)). If you wish to avoid the transfer, you can refrain from turning on push notifications.
6. Retention period
- Account details: for as long as the account exists. When you delete your account, the account, sessions and memberships are erased immediately, and your name on comments is replaced with “Deleted user”.
- Project content: for as long as the project exists. Deleted items remain in the trash for 30 days. The activity log belongs to the project and is kept for as long as the project exists.
- Data about people without an account (recipients of distribution lists and safety observations): for as long as the project exists or until the project's owner deletes it. Acknowledgement links expire after 30 days.
- One-time links: 48 hours (confirmation) and 60 minutes (password reset) respectively. Sessions: 30 days from the most recent sign-in.
- Server logs: 30 days. Backups of the database and files: 14 days. Copies taken before an update of the service are kept only for as long as they are needed to be able to roll back the update.
- Sign-in attempts per IP address: 15 minutes. Expired one-time links and completed directory sign-ins are deleted on an ongoing basis.
- We may retain data for longer if required by law or if it is needed to establish, exercise or defend a legal claim.
7. Your rights
You have the right to request access to your personal data, rectification, erasure, restriction of processing and data portability, and to object to processing based on legitimate interest. On the account page you can yourself change your name, download a copy of your data in a machine-readable format and delete the account. Other requests should be sent to support@verabim.com. We respond within one month. That period may be extended by a further two months if the request is complex or if there are many requests, in which case we will tell you why. We may need to verify your identity.
For data that a company or a project owner processes in its projects, you should in the first instance contact them. You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.
8. Cookies and local storage
The service uses only necessary cookies, listed below, and the browser's local storage for settings, to speed up 3D models and for offline mode, where the project's data and selected files are stored on the device until you sign out or remove them. No tracking cookies or third-party analytics are used, which is why no cookie banner is shown. Do not share a signed-in device with others.
- verabim_session keeps you signed in. It is kept for 30 days or until you sign out.
- verabim_lang remembers the language you have chosen. It is kept for one year.
- verabim_sso ties a sign-in through your company's directory to your browser. It is kept for at most 10 minutes.
- verabim_native shows that the page is opened in the VeraBIM app for desktop or mobile. It is kept for one year.
9. Security
Traffic between your device and the service is encrypted with HTTPS (TLS). Passwords are stored as salted hashes (PBKDF2-SHA-256), and two-factor sign-in can be turned on from the account page. Sign-in is temporarily blocked after repeated failed attempts, and access to project data is checked on the server for every request. No service is completely secure, and we cannot guarantee that unauthorised persons will never gain access to data. In the event of a personal data breach, we will inform you and the Swedish Authority for Privacy Protection when the General Data Protection Regulation so requires.
10. Changes to the policy
We may update the policy. The date at the top shows when it was last changed, and we will announce material changes in the service or by email.
11. Contact
Questions about personal data: support@verabim.com. No data protection officer has been appointed.