Skip to content
BOMproof

Legal

Privacy policy

How we handle your personal data and your engineering data.

Last updated: 19 September 2026

1. Who we are

BOMproof is a platform of De Gier Engineering B.V., located at Santplaet 190, 3144 DT Maassluis, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 82348111. Wherever this privacy policy says “we” or “BOMproof”, it means De Gier Engineering B.V.

We are the controller for the personal data processed through this website. For data processed within the BOMproof platform we generally act as a processor on behalf of our customer; we conclude a data processing agreement for that.

2. Which data we process

Depending on how you get in touch with us, we process:

  • Contact details: name, business email address, company name and optionally a phone number.
  • Content of messages: what you send us through the contact form or by email.
  • Account data: name, email address, (encrypted) password or the link with your Google or Microsoft account, and possibly your profile picture from that provider.
  • Usage data: technical data such as IP address, browser type and time of visit, for security and debugging.
  • Engineering data: CAD files, metadata and bills of materials that you upload to the platform (see section 4).
Purpose Data Legal basis
Answering questions and demo requests Contact details, messages Legitimate interest
Carrying out a pilot or subscription Account and engineering data Performance of a contract
Security and abuse prevention Usage data Legitimate interest
Complying with legal obligations Invoicing data Legal obligation

4. CAD files and engineering data

CAD models and bills of materials usually contain little personal data, but they do contain valuable intellectual property. We treat this data as confidential:

  • Engineering data is processed solely to carry out the analyses you requested.
  • Engineering data is not used to train AI models, neither by us nor by the providers we work with. We select and configure our providers so that your data is not used for training; this is also stated in the data processing agreement.
  • Access within BOMproof is limited to staff who need it for support, and only with your permission.

5. AI processing and subprocessors

Your files are first read by our own software: product structure, positions and materials from the model, text and lines from the drawing, and rows from the bill of materials. To assess these we use language models, which we access through Merge Gateway. During a check only the data needed for it is sent to the model, such as the product structure, dimensions, drawing text and bill of materials rows. The 3D model itself is not sent to the language model.

We work with the following categories of subprocessors, among others:

  • Hosting and processing: Google Cloud and Firebase (Firestore, Cloud Run), storage location Europe
  • Storage of your files (model, drawings, bills of materials): Cloudflare R2, storage location within the EU
  • Accounts and signing in: Google Firebase Authentication (including signing in with Google or Microsoft)
  • AI model access: Merge Gateway and the underlying model providers, who process only the data needed for your check, on our instructions
  • Website statistics (only with your consent): Google Analytics 4, loaded through Cloudflare Zaraz
  • Email: Google Firebase sends the emails that belong to your account, such as the verification email and emails for resetting your password
  • Contact form: Resend sends your message to our inbox; your contact details and the content of your message are processed via Resend (United States)

When data is processed outside the European Economic Area, we ensure appropriate safeguards, such as the standard contractual clauses of the European Commission. On request we will send you a current list of subprocessors with the data they process and their processing locations via info@bomproof.nl. We announce new subprocessors in the same way and give you the opportunity to object before we engage them.

6. Retention periods

We do not keep data longer than necessary:

  • Contact requests: up to 12 months after the last contact.
  • Account data: as long as the account is active, and a maximum of 3 months afterwards.
  • Engineering data: until the customer deletes it, or at the latest 30 days after the end of the agreement.
  • Invoicing data: 7 years, in line with the statutory tax retention obligation.

7. Sharing with third parties

We never sell your data. We only share data with subprocessors we need for our services, or when we are legally obliged to do so.

8. Security

We take appropriate technical and organisational measures, including encrypted connections (TLS), role-based access control, access logging and the principle of data minimisation.

9. Your rights

Under the General Data Protection Regulation (GDPR) you have the right of access, rectification, erasure, restriction of processing, data portability and objection. Send your request to info@bomproof.nl. We respond within one month.

10. Cookies

Read in our cookie policy which cookies this website uses.

11. Complaints

Not satisfied with how we handle your data? Please contact us first. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

12. Changes

We may change this privacy policy, for example when the platform gets new features. The most recent version is always on this page.