Data Protection & Privacy
Privacy Policy
- No External BIM Data Transmission: Karo Modum plugins process your BIM data locally within your workstation. We do not transmit your Revit models, geometry, parameters, or project files to external servers.
- Payment Security: Payment details are processed by third-party commerce providers. We do not receive or store your credit card numbers or banking credentials.
- Minimal Data Collection: Where the Software performs license validation, only information necessary for that purpose is processed, such as license credentials and device or installation identifiers, where applicable.
- Your Privacy Rights: Where applicable law provides, you have rights to access, correct, export, or request deletion of your personal data.
1. Overview & Data Controller
This Privacy Policy describes how Karo Modum (“we”, “us”, “our”) collects, processes, and protects personal data when you visit our website (karomodum.com), purchase software licenses, use our plugins within Autodesk® Revit®, or communicate with customer support.
Karo Modum is the data controller responsible for the personal data described in this Policy. For questions regarding your data or to exercise your privacy rights, contact us at [email protected].
2. Information We Collect
We adhere to the principle of data minimization and collect only information necessary for the purposes described in this Policy:
A. Purchase & Account Information
We may receive transaction and customer information from payment or commerce providers involved in processing your purchase. This may include your name, email address, company name (if provided), country, and transaction identifiers. We do not receive, process, or store your payment card details.
B. License & Activation Information
Where the Software performs license validation or activation, we may process information necessary to verify your license entitlement and prevent unauthorized use. This may include, where applicable:
- License credentials: License identifiers, activation status, and product information.
- Device or installation information: A device or installation identifier used for license validation and abuse prevention, where applicable.
- Environment metadata: Technical environment information, such as operating system, Autodesk Revit, or Software version information, where applicable.
- Network information: IP address, which may be used for security, abuse prevention, and service protection purposes.
C. Website Usage
We do not use third-party cross-site behavioral tracking scripts or advertising cookies on our website. Standard server and CDN edge logs (such as IP address, user agent, and requested URL) may be collected automatically for security and service protection purposes.
D. Customer Support Communications
When you contact [email protected], we collect your email address, message contents, and any diagnostic information you voluntarily provide to help resolve your inquiry.
3. Revit / BIM Model Data
We respect the confidentiality of your architectural designs, engineering models, and client projects.
Karo Modum plugins process your BIM data locally within your workstation’s Autodesk Revit environment. The Software does not transmit your Revit model data to external servers. Specifically:
- No External Model Transmission: Your Revit project files (
.rvt), family files (.rfa), and template files (.rte) are not uploaded, transmitted, or sent to Karo Modum or any third-party server. - No External Geometry or Parameter Transmission: Coordinates, floor plans, structural layouts, schedules, and custom parameters remain on your local computer or local network storage.
- No Project Metadata Harvesting: We do not intentionally transmit project names, client identifiers, designer names, or file paths to external servers for telemetry, analytics, or licensing purposes.
The plugins read and process BIM data locally as necessary to perform their intended functions (such as visibility analysis, change detection, policy enforcement, or segment placement), but this data remains on your local system.
4. Third-Party Service Providers
We may use third-party service providers who process data on our behalf or in connection with our services:
- Payment & Commerce Providers (including Lemon Squeezy, LLC): Handle checkout, payment processing, billing, tax calculation, and receipt generation. Payment card information is processed directly by the commerce provider and is not handled or stored by Karo Modum.
- Hosting & CDN Infrastructure (including Cloudflare): May provide DNS, CDN, security, and related infrastructure services. Standard ephemeral access logs may be maintained for security and service protection purposes.
We select service providers that maintain appropriate security standards. For the most current list of our service providers, you may contact us at [email protected].
5. How We Use Information & Legal Bases
We process personal data for the purposes described below. Where the General Data Protection Regulation (GDPR) applies, we rely on the following legal bases:
Contractual Performance (Art. 6(1)(b) GDPR)
Processing purchase information, issuing and maintaining software licenses, verifying license entitlements, and providing technical support.
Legitimate Interests (Art. 6(1)(f) GDPR)
Protecting intellectual property against unauthorized use, verifying license compliance, defending infrastructure against abuse, and ensuring software stability and security.
Legal Compliance (Art. 6(1)(c) GDPR)
Maintaining required commercial and tax records as mandated by applicable law, in coordination with our commerce providers where applicable.
6. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide and maintain our services, comply with legal and tax obligations, resolve disputes, and enforce our agreements. Specifically:
- License & Activation Information: Retained for the active lifecycle of your license to enable license management and support.
- Transaction Records: Retained for as long as required by applicable tax, accounting, and commercial record-keeping laws.
- Support Communications: Retained for a reasonable period to provide consistent support and resolve ongoing issues.
- Server & CDN Logs: Ephemeral logs are rotated and deleted on a regular basis in accordance with our infrastructure providers’ practices.
When personal data is no longer necessary for the purposes for which it was collected, we delete or anonymize it in accordance with our internal data management practices and applicable law.
7. Data Security
We implement technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption in Transit: Data is transmitted using encrypted HTTPS connections.
- Access Controls: Access to systems containing personal data is restricted to authorized personnel.
- Service Provider Standards: We select infrastructure and service providers that maintain appropriate security practices.
No method of electronic transmission or storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security.
8. Your Privacy Rights
Depending on your location and applicable law (including, where applicable, the GDPR, UK GDPR, and California CCPA/CPRA), you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data, subject to any legal retention requirements.
- Right to Restrict or Object to Processing: Request limits on how your personal data is processed.
- Right to Data Portability: Request your personal data in a structured, commonly used, and machine-readable format.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the relevant data protection supervisory authority, where applicable.
To exercise any of these rights, email us at [email protected] with sufficient information to verify your identity and describe your request. We respond to privacy requests within the time required by applicable law and, where GDPR applies, generally within one month.
9. International Data Transfers
Our service providers may operate in multiple countries. Where personal data is transferred outside the European Economic Area (EEA), the United Kingdom, or Switzerland, we use legally recognized transfer mechanisms where required by applicable law, such as adequacy decisions or applicable Standard Contractual Clauses.
10. Cookies & Local Storage
Our website does not use third-party advertising cookies or cross-site tracking technologies. We may use browser local storage for strictly functional purposes, such as storing UI preferences. No personal data is stored in cookies or local storage for tracking purposes.
11. Children’s Privacy
Our products and website are intended for professional and commercial users and are not directed to children.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. When revisions occur, the “Effective & Last Updated” date at the top of this page will be updated. We encourage you to review this page periodically.
13. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us: