1. Introduction
Sikmo Digital ("we", "us", "our") operates bIDMIO, a multi-tenant cloud-based ERP platform for construction project management. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our platform.
2. Data Controller
Sikmo Digital
CVR: 32014283
Address: Praestbrovej 22, 8464 Galten, Denmark
Contact: privacy@bidmio.com
For account, billing and website-visitor data, Sikmo Digital is the controller. For data you enter about your employees, customers and projects (tenant data), you are the controller and Sikmo Digital is the processor under the Data Processing Agreement.
3. Personal Data We Collect
3.1 Account Data
- Name, email address, phone number
- Company/organization details
- Job title and role
- Login credentials (securely hashed)
3.2 Employee Data
- Employee profiles (name, contact, job information)
- Work schedules and time logs
- Absence records (vacation, sick leave). Sick leave is a special category of personal data only if you choose to record it
- Emergency contact information
3.3 Project Data
- Customer and supplier information
- Project details and budgets
- Invoices and financial records
- Documents and files you upload
3.4 Technical Data
- IP addresses and device information
- Browser type and version
- Usage patterns and access logs
- Cookies and similar technologies
3.5 Acquisition Data
When you arrive on bIDMIO from an advertisement, a search engine or one of our marketing websites, we record how you got here so that we can measure which channels bring us customers:
- The address you landed on and the website that referred you
- Campaign parameters in the link you followed (source, medium, campaign, term, content)
- Advertising click identifiers supplied by Google, Microsoft or Meta
- Google analytics and advertising cookie identifiers, where they are readable
This information is held in a short-lived cookie during signup and, if you create an account, is stored once against that account. It is never linked to your activity inside the platform.
3.6 Google Ads Enhanced Conversions
After you successfully create an account, and only if you have granted marketing consent, we may send Google a normalized, one-way SHA-256 hash of the email address used for signup together with a conversion event. Google compares the hash with hashes associated with signed-in Google accounts to attribute the signup to an advertising interaction and improve conversion measurement and bidding.
- Data: The normalized SHA-256 hash of the signup email address and conversion-event metadata. The hash is pseudonymized personal data, not anonymous data. The raw email address is not placed in our marketing data layer or sent by this integration.
- Purpose and legal basis: Advertising measurement and campaign optimization, based on your consent.
- Recipient: Google, under the Google Ads Data Processing Terms and Customer Data Policies.
- Retention: bIDMIO does not retain the hash after dispatch; Google processes it under its applicable terms and policies.
- Your choice: Withdrawing marketing consent in Cookie settings stops future Enhanced Conversions transmissions. We do not use this processing to create Customer Match or conversion-based customer lists.
4. Legal Basis for Processing
We process personal data based on:
- Contract Performance: To provide our services
- Legitimate Interest: For security, analytics, and service improvement
- Legal Obligation: Compliance with applicable laws
- Consent: For optional features and marketing
5. How We Use Your Data
- Provide and maintain the bIDMIO platform
- Process transactions and manage subscriptions
- Send service notifications and updates
- Provide customer support
- Improve and develop our services
- Ensure platform security and prevent fraud
- Comply with legal obligations
6. Data Sharing
We may share data with:
- Service Providers: Cloud hosting, payment processing, email services, analytics, and customer support tools
- Within Your Organization: Other authorized users in your workspace
- Legal Requirements: Courts, regulators, or law enforcement
- Business Transfers: In case of merger or acquisition
6.1 Third-Party Service Providers
We use the following third-party services to operate and improve bIDMIO:
- Zoho PageSense: Website analytics to understand user behavior and improve our platform. Collects anonymized usage data, page views, and interaction patterns. Data is processed in accordance with Zoho's privacy policy.
- Zoho SalesIQ: Live chat support to provide real-time customer assistance. May collect chat transcripts, visitor information, and support interaction history.
- Hetzner: Application hosting in Germany and object storage for uploaded files in Nuremberg (nbg1).
- Neon: PostgreSQL database in the EU (Frankfurt).
- Stripe: Subscription payments (Ireland). Card numbers are not stored on Bidmio servers.
- Resend: Transactional email delivery service.
- OpenAI: Optional AI features. EU organisations must accept a non-EU processing consent before prompts may leave the EEA. AI can be turned off.
- Zoho PageSense / SalesIQ: Marketing-site analytics and chat on bidmio.* marketing domains, not tenant ERP records.
7. Google API Services
bIDMIO may allow users to connect their Google account to enable certain features or integrations.
When a user authorizes Google integration, bIDMIO may access limited Google account information as permitted by the user. This data may include:
- Basic profile information
- Email address
- Other data necessary for the requested integration
bIDMIO uses this data only to provide the requested functionality and does not sell or use this data for advertising purposes.
bIDMIO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. International Transfers
Data may be transferred outside the EU/EEA. We ensure appropriate safeguards through:
- EU Standard Contractual Clauses
- Adequacy decisions by the European Commission
- Other approved transfer mechanisms
9. Data Retention
- Active Accounts: Data retained while account is active
- After Termination: operational tenant data is retained for 30 days to allow export, then deleted
- Backups: retained for up to 90 days
- Accounting records: 5 years from the end of the relevant fiscal year where tax law requires it
- Advertising Click Identifiers: Campaign parameters and click identifiers stored with an account are deleted after 24 months, and immediately when the organization is deleted
10. Your Rights (GDPR)
You have the right to:
- Access: Request copies of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Restriction: Limit how we use your data
- Portability: Receive data in a portable format
- Object: Object to certain processing activities
- Withdraw Consent: Where processing is based on consent
11. Data Security
We implement robust security measures:
- Encryption in transit (TLS) and at rest
- Multi-tenant data isolation
- Regular security audits
- Access controls and authentication
- Employee security training
12. Cookies and Tracking Technologies
We use the following types of cookies and tracking technologies:
- Essential Cookies: Required for platform functionality, authentication, and security. These cannot be disabled.
- Analytics Cookies: Used by Zoho PageSense to understand how users interact with our platform. These help us improve usability and features.
- Chat Cookies: Used by Zoho SalesIQ to provide live chat support and remember conversation history.
- Preference Cookies: Remember your settings such as language and theme preferences.
- Attribution Cookie: A first-party cookie that remembers how you first reached bIDMIO so a signup can be credited to the right campaign. It expires after 30 days and is deleted as soon as an account is created.
Statistics, marketing and chat cookies are only set once you allow them. You can change or withdraw that choice at any time via Cookie settings in the footer of any page. Our Cookie Policy lists every cookie we set, its category, purpose and lifetime. You can also manage cookies through your browser settings, but note that disabling essential cookies may affect platform functionality.
13. Children's Privacy
bIDMIO is not intended for users under 16. We do not knowingly collect data from children.
14. Changes to This Policy
We may update this policy periodically. Significant changes will be communicated via email or platform notification.
15. Contact Us
For privacy inquiries or to exercise your rights, contact us at:
Email: privacy@bidmio.com
Last updated: September 1, 2026
Version 3.3