1. Who we are
BOMproof is a platform of De Gier Engineering B.V., located at Santplaet 190, 3144 DT Maassluis, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 82348111. Wherever this privacy policy says “we” or “BOMproof”, it means De Gier Engineering B.V.
We are the controller for the personal data processed through this website. For data processed within the BOMproof platform we generally act as a processor on behalf of our customer; we conclude a data processing agreement for that.
2. Which data we process
Depending on how you get in touch with us, we process:
- Contact details: name, business email address, company name and optionally a phone number.
- Content of messages: what you send us through the contact form or by email.
- Account data: name, email address, (encrypted) password or the link with your Google or Microsoft account, and possibly your profile picture from that provider.
- Usage data: technical data such as IP address, browser type and time of visit, for security and debugging.
- Engineering data: CAD files, metadata and bills of materials that you upload to the platform (see section 4).
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Answering questions and demo requests | Contact details, messages | Legitimate interest |
| Carrying out a pilot or subscription | Account and engineering data | Performance of a contract |
| Security and abuse prevention | Usage data | Legitimate interest |
| Complying with legal obligations | Invoicing data | Legal obligation |
4. CAD files and engineering data
CAD models and bills of materials usually contain little personal data, but they do contain valuable intellectual property. We treat this data as confidential:
- Engineering data is processed solely to carry out the analyses you requested.
- Engineering data is not used to train AI models, neither by us nor by the providers we work with. We select and configure our providers so that your data is not used for training; this is also stated in the data processing agreement.
- Access within BOMproof is limited to staff who need it for support, and only with your permission.
5. AI processing and subprocessors
Your files are first read by our own software: product structure, positions and materials from the model, text and lines from the drawing, and rows from the bill of materials. To assess these we use language models, which we access through Merge Gateway. During a check only the data needed for it is sent to the model, such as the product structure, dimensions, drawing text and bill of materials rows. The 3D model itself is not sent to the language model.
We work with the following categories of subprocessors, among others:
- Hosting and processing: Google Cloud and Firebase (Firestore, Cloud Run), storage location Europe
- Storage of your files (model, drawings, bills of materials): Cloudflare R2, storage location within the EU
- Accounts and signing in: Google Firebase Authentication (including signing in with Google or Microsoft)
- AI model access: Merge Gateway and the underlying model providers, who process only the data needed for your check, on our instructions
- Website statistics (only with your consent): Google Analytics 4, loaded through Cloudflare Zaraz
- Email: Google Firebase sends the emails that belong to your account, such as the verification email and emails for resetting your password
- Contact form: Resend sends your message to our inbox; your contact details and the content of your message are processed via Resend (United States)
When data is processed outside the European Economic Area, we ensure appropriate safeguards, such as the standard contractual clauses of the European Commission. On request we will send you a current list of subprocessors with the data they process and their processing locations via info@bomproof.nl. We announce new subprocessors in the same way and give you the opportunity to object before we engage them.
6. Retention periods
We do not keep data longer than necessary:
- Contact requests: up to 12 months after the last contact.
- Account data: as long as the account is active, and a maximum of 3 months afterwards.
- Engineering data: until the customer deletes it, or at the latest 30 days after the end of the agreement.
- Invoicing data: 7 years, in line with the statutory tax retention obligation.
7. Sharing with third parties
We never sell your data. We only share data with subprocessors we need for our services, or when we are legally obliged to do so.
8. Security
We take appropriate technical and organisational measures, including encrypted connections (TLS), role-based access control, access logging and the principle of data minimisation.
9. Your rights
Under the General Data Protection Regulation (GDPR) you have the right of access, rectification, erasure, restriction of processing, data portability and objection. Send your request to info@bomproof.nl. We respond within one month.
10. Cookies
Read in our cookie policy which cookies this website uses.
11. Complaints
Not satisfied with how we handle your data? Please contact us first. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
12. Changes
We may change this privacy policy, for example when the platform gets new features. The most recent version is always on this page.