Home / Privacy

Privacy Policy

Effective date: 2026-05-22 Version: 1.1

We at Aedificon AB ("Aedificon", "we", "us", "our") care about your privacy and want you to feel safe when we process your personal data. This Privacy Policy explains what personal data we collect, why we collect it, the legal bases on which we rely, how long we keep it, with whom we share it, and what rights you have under the EU General Data Protection Regulation 2016/679 ("GDPR") and Swedish data-protection law.

This Privacy Policy applies to:

  • visitors to our website at https://aedificon.ai;
  • users and account holders of the A+ Tool Suite plugin for Autodesk® Revit® (the "Software");
  • people who contact us by email or other written channels.

The Software is sold and licensed to businesses only. Where we refer to "your company" in this Policy, we mean your employer or the organisation you represent. We will only process your personal data in your business role.


1. Who is responsible — controller and contact

Aedificon AB is the data controller for the personal data described in this Policy.

Aedificon AB Organisationsnummer: 559157-8587 Valentin Sabbats gata 5, 113 61 Stockholm, Sweden Privacy contact: privacy@aedificon.ai General contact: hello@aedificon.ai

Aedificon has not formally appointed a Data Protection Officer (DPO) — appointment of a DPO is required under GDPR Article 37 only in specific circumstances (such as large-scale systematic monitoring or processing of special categories), and our processing does not trigger those criteria. Privacy queries are handled directly by the privacy@aedificon.ai contact above.

If you have any questions about how we process your personal data, or you want to exercise any of your rights under data-protection law, please contact us at privacy@aedificon.ai.


The following table sets out our processing activities. The legal bases are those listed in Article 6 of the GDPR.

2.1 Account data

Item Detail
Categories of data Name; email address; company name; country; password hash; account preferences.
Purpose Creating and administering your account; identifying you when you log in; assigning licenses to Named Users; communicating with you about your account, the Services, and security matters.
Source Provided by you or your company at sign-up.
Legal basis Contract performance — Art. 6(1)(b) GDPR — necessary for the performance of the contract with the company you represent and for taking steps at your request prior to entering into a contract. Legitimate interest — Art. 6(1)(f) — for security, fraud prevention, and account management (we have concluded that our interest in operating a secure and reliable service outweighs the limited privacy impact of these processing activities).
Retention For the duration of the license/subscription, plus seven (7) years thereafter to the extent the data is part of accounting records, in accordance with the Swedish Bookkeeping Act (Bokföringslagen 1999:1078). Thereafter the data is deleted or anonymised.

2.2 Billing data

Item Detail
Categories of data Limited billing metadata received from Paddle, such as invoice ID, country, VAT status, and order amount. Aedificon does not receive or store full payment-card details, bank account numbers, or other payment instruments — these are handled exclusively by Paddle (see §3 and §4 below).
Purpose Reconciling sales with our merchant of record; financial reporting; complying with VAT and accounting law.
Source Received from Paddle in connection with each transaction.
Legal basis Legal obligation — Art. 6(1)(c) — accounting and tax law. Contract performance — Art. 6(1)(b) — managing the license relationship.
Retention Seven (7) years in accordance with the Swedish Bookkeeping Act (Bokföringslagen 1999:1078).

2.3 Technical and usage data (Software telemetry)

Item Detail
Categories of data IP address (recorded at login and at license-activation events); Autodesk Revit version; A+ Tool Suite plugin version; Autodesk Account email (collected at license activation to bind the license to a specific Revit user); license-activation telemetry (which license key activated, which Named User, which device, timestamps); for accounts on the Free subscription, the date, time, tool identifier and credit cost of each successful tool invocation (recorded so the daily and monthly credit allowance can be enforced); aggregate non-identifying usage statistics. Error logs are stored on your local device and are only transmitted to Aedificon if you explicitly choose to send them — for example, by attaching them to an email when reporting an issue.
Purpose Activating and validating licenses; binding each license to a specific Autodesk Account so the license is enforceable per Named User; enforcing the Free-subscription credit allowance; preventing license abuse and fraud; diagnosing issues; improving the Software.
Source Generated automatically when the Software is installed, activated or used; or provided by you when reporting an issue.
Legal basis Contract performance — Art. 6(1)(b) — for license activation and validation, which is part of delivering the Software. Legitimate interest — Art. 6(1)(f) — for fraud prevention, security, license enforcement, and product improvement (see §6 below for our balancing assessment).
Retention Six (6) months for telemetry and activation logs, after which they are deleted or anonymised. Error logs you choose to send to us by email are retained as part of the support correspondence (see §2.4).

2.4 Support correspondence

Item Detail
Categories of data Email correspondence, including any attachments, screenshots or error logs you send; ticket metadata (timestamps, ticket ID, status).
Purpose Responding to support requests; investigating and resolving issues; improving the Software and our support.
Source Provided by you when you contact support@aedificon.ai (or another Aedificon address).
Legal basis Contract performance — Art. 6(1)(b) — providing support is part of the Services. Legitimate interest — Art. 6(1)(f) — handling enquiries from people who interact with us in a business capacity, including those who are not yet customers.
Retention Two (2) years after the support ticket is closed, after which the correspondence is deleted.

2.5 Marketing communications (only if you opt in)

Item Detail
Categories of data Name; email address; company name; country; subscription preferences; engagement data (whether emails are opened, which links you click).
Purpose Sending you product news, updates and offers about the A+ Tool Suite if you have subscribed.
Source Provided by you when you subscribe.
Legal basis Consent — Art. 6(1)(a). You can withdraw consent at any time by clicking "unsubscribe" in any marketing email or by contacting privacy@aedificon.ai.
Retention Until you unsubscribe, plus a record of the unsubscribe (name, email, date) for two (2) years to evidence the opt-out and to ensure we do not send you further marketing.

2.6 Website cookies and analytics

We do not use analytics, advertising, social-media tracking, or functional/preference cookies on our website. Our website uses only strictly-necessary cookies required for the site to function (such as keeping you logged in). Because no consent is required for such cookies under the ePrivacy Directive, we do not show a cookie consent banner. For details, see our separate Cookie Notice linked from the website footer.


3. Recipients of your personal data

Your personal data is initially collected and processed by us. We do not sell your personal data.

We share personal data only with the following categories of recipients, and only to the extent necessary:

  • Aedificon employees — only those who need access to perform their work.
  • Paddle.com Market Limited (Ireland / United Kingdom) — our merchant of record. Paddle processes your payment as an independent controller for the payment transaction. Aedificon receives only limited billing metadata back from Paddle (see §2.2). Paddle's privacy notice is available at https://www.paddle.com/legal/privacy.
  • Microsoft Azure (Microsoft Ireland Operations Limited; West Europe region) — hosting and internal analytics infrastructure for our website, account portal and license-management backend. Acts as our processor.
  • Auth0 by Okta — authentication and identity management for the account portal. Acts as our processor.
  • One.com (Denmark) — hosting of email mailboxes, customer-support inbox, and transactional email sending. Acts as our processor.
  • Competent authorities and courts — where we are required to disclose personal data by law, court order, or other legal process; or where disclosure is necessary to establish, exercise or defend legal claims.
  • Successors and assigns — if Aedificon is involved in a merger, acquisition, asset sale or other corporate reorganisation, we may transfer personal data to the relevant counterparty, subject to appropriate confidentiality obligations and applicable law.

We have written agreements with all processors requiring them to process personal data only on our instructions and to apply appropriate technical and organisational security measures, in accordance with Article 28 GDPR.

If you would like the current detailed list of sub-processors (including their roles, locations and applicable transfer safeguards), please contact privacy@aedificon.ai.


4. International transfers

We strive to keep personal data within the European Economic Area (EEA). However, some of the recipients listed in §3 are based outside the EEA, or are EEA-based entities owned by non-EEA parents (notably Auth0/Okta, which is owned by a US parent). Personal data may therefore in some cases be transferred outside the EEA, or be subject to access by a non-EEA parent for support and operational purposes.

For all such transfers, we rely on the following safeguards under Chapter V of the GDPR:

  • EU Commission adequacy decisions where applicable (for example, the EU–US Data Privacy Framework, where the US recipient is certified under that framework, and the UK adequacy decision for transfers to the United Kingdom);
  • Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) where adequacy is not available, together with supplementary technical and organisational measures (such as encryption in transit and at rest) where appropriate following the Schrems II judgment of the Court of Justice of the European Union.

You may request a copy of the relevant transfer safeguards by contacting privacy@aedificon.ai.


5. Your rights

You have the rights set out below in relation to our processing of your personal data. To exercise any of these rights, please contact privacy@aedificon.ai. We will respond without undue delay and in any event within one month of receiving your request, in accordance with Article 12(3) GDPR. We may extend this period by up to two further months where necessary, taking into account the complexity and number of requests, and will inform you of any such extension.

5.1 Right of access (Art. 15)

You have the right to obtain confirmation of whether we are processing personal data about you and, if so, to obtain a copy of that data and information about how we process it (purposes, categories of data, recipients, retention periods, sources, the existence of automated decision-making, and details of any international transfers and applicable safeguards).

5.2 Right to rectification (Art. 16)

You have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you, and to have incomplete personal data completed.

5.3 Right to erasure ("right to be forgotten") (Art. 17)

You have the right to ask us to erase your personal data where:

  • the data are no longer necessary for the purposes for which they were collected;
  • you withdraw consent on which the processing is based and there is no other legal ground;
  • you object to processing under Art. 21(1) and there are no overriding legitimate grounds, or you object under Art. 21(2);
  • the data have been unlawfully processed; or
  • the data must be erased to comply with a legal obligation in EU or Member State law.

This right is subject to exceptions, in particular where processing is necessary to comply with a legal obligation (for example, retention under the Swedish Bookkeeping Act) or for the establishment, exercise or defence of legal claims.

5.4 Right to restriction of processing (Art. 18)

You have the right to obtain restriction of processing where:

  • the accuracy of the data is contested by you (for the period needed to verify accuracy);
  • the processing is unlawful and you oppose erasure and instead request restriction;
  • we no longer need the data but you need it for the establishment, exercise or defence of legal claims; or
  • you have objected to processing under Art. 21(1), pending verification of whether our legitimate grounds override yours.

5.5 Right to object (Art. 21)

You have the right to object at any time to processing that is based on our legitimate interest, including any related profiling. We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or if the processing is needed for the establishment, exercise or defence of legal claims.

You have an unconditional right to object to processing of your personal data for direct-marketing purposes. If you make such an objection, we will stop processing your personal data for those purposes immediately.

5.6 Right to data portability (Art. 20)

Where our processing is based on your consent or on contract performance, and is carried out by automated means, you have the right to receive the personal data that you have provided to us in a structured, commonly used, machine-readable format, and (where technically feasible) to have it transmitted to another controller.

5.7 Right to withdraw consent (Art. 7(3))

Where our processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

5.8 Right to lodge a complaint with a supervisory authority (Art. 77)

You always have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU/EEA Member State of your habitual residence, your place of work, or where the alleged infringement occurred. The Swedish supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten — IMY, https://www.imy.se/en/). We would, however, appreciate the opportunity to address your concerns first — please feel free to contact us at privacy@aedificon.ai.

5.9 Automated decision-making

We do not subject you to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).


6. Balancing of interests — legitimate-interest assessments

Where we rely on legitimate interest as our legal basis (see §2 above), we have carried out balancing-of-interests assessments and concluded that our legitimate interest outweighs the limited privacy impact on you. In summary:

  • Account security and fraud prevention. Our interest in operating a secure service and preventing license abuse is significant; the data used (account identifiers, IP at login, activation telemetry) is limited and necessary for the purpose.
  • License enforcement. Our interest in ensuring that licenses are used in accordance with the Agreement, including our limited audit-log activity, is significant; the data used is limited to identifying the Named User and device using a license and the timestamps of activation events.
  • Product improvement. Our interest in understanding which features are used and where errors occur is significant; the data used is minimised (no content of your Revit projects, no project-specific data), and you control whether to send error logs.
  • Customer support and pre-sales correspondence. Our interest in responding to enquiries is significant; the processing is limited to what you yourself have shared with us.

You can request more information about any of these assessments at privacy@aedificon.ai.


7. Security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include encryption in transit (TLS), encryption at rest where supported by our hosting provider, access controls based on the principle of least privilege, multi-factor authentication for administrative access, and regular review of our processing activities and sub-processors.

No method of transmission or storage is completely secure. If you become aware of any actual or suspected security incident affecting your personal data, please contact privacy@aedificon.ai without delay.


8. Children

The Services are sold and licensed to businesses and are not directed to children. We do not knowingly process personal data of persons under 16. If you believe we have inadvertently collected personal data from a person under 16, please contact privacy@aedificon.ai and we will delete it.


9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The current version, with its effective date, is always available at https://aedificon.ai/privacy.

We will notify users by email at least thirty (30) days before any material change takes effect (a change is material if it would reduce your rights, change the legal basis we rely on, or extend the categories of recipients). Non-material updates (such as clarifications, contact-detail changes, or additions to the sub-processor list) take effect on the date posted with the change.


10. Contact

For all questions about this Privacy Policy or our processing of your personal data, including to exercise any of your rights:

privacy@aedificon.ai Aedificon AB Valentin Sabbats gata 5, 113 61 Stockholm, Sweden


End of Privacy Policy. Effective 2026-05-05.