Privacy Policy
1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. For detailed information on data protection, please refer to our privacy policy below.
Data Collection on this Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator's contact details in the legal notice of this website.
How do we collect your data?
Your data is collected in part by you providing it to us. This may include data you enter into a contact form. Other data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g., internet browser, operating system, or time of page access).
What do we use your data for?
Part of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances.
2. General Information and Mandatory Disclosures
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
Responsible Party
The responsible party for data processing on this website is:
zeit+raum – Sole Proprietorship
Dipl.-Ing., M.Sc. Architect Alexander Maier
Elbestraße 11
55122 Mainz-Gonsenheim, Germany
Phone: +49 (0)6131 – 32 71 400
Email: info@zeitundraum.de
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Data Protection Officer
The Data Protection Officer of the responsible party is:
Alexander Maier
Email: datenschutz@nexai.space
You may contact the Data Protection Officer at any time with questions regarding data protection or to exercise your data subject rights.
Storage Duration
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent for data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.
Legal Basis for Data Processing
We process personal data in compliance with the EU General Data Protection Regulation (GDPR). Processing is based on one or more of the following legal bases:
- Consent (Art. 6(1)(a) GDPR)
- Performance of a contract (Art. 6(1)(b) GDPR)
- Legal obligation (Art. 6(1)(c) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR)
Revocation of Consent
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Lodge a Complaint
If there has been a breach of data protection law, the person affected may lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues is the state data protection officer of the federal state in which our company is headquartered:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Postfach 30 40
55020 Mainz, Germany
3. Data Collection on this Website
Cookies
Our website uses cookies. Cookies are small text files that are stored on your device and saved by your browser. They do not cause any damage. We use cookies to make our website more user-friendly. Some cookies remain stored on your device until you delete them. They allow us to recognize your browser on your next visit.
If you do not agree to this, you can set your browser to inform you about the placement of cookies and only allow them in individual cases. Disabling cookies may limit the functionality of our website.
Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources. The basis for data processing is Art. 6(1)(f) GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.
Registration on this Website
You can register on our website to use additional functions. We use the data entered for this purpose only for the use of the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration.
For important changes, such as to the scope of the offer or technically necessary changes, we use the email address provided during registration to inform you in this way.
The data entered during registration is processed on the basis of your consent (Art. 6(1)(a) GDPR). You can revoke consent you have already given at any time. The legality of the data processing already carried out remains unaffected by the revocation.
4. Analytics
Umami Analytics (Self-Hosted)
This website uses Umami Analytics, a privacy-focused, self-hosted web analytics solution. Umami does not use tracking cookies and does not track users across websites. All data is anonymized and stored on our own European servers (IONOS, Germany).
Consent requirement: The Umami Analytics script is only loaded after your explicit consent via our cookie banner (Art. 6(1)(a) GDPR). Without your consent, no web analytics takes place. You can revoke your consent at any time via the cookie settings in the website footer.
Data collected: Page views, session duration, referrer, device type, and browser type – without any personal identification. No data is shared with third parties for advertising purposes.
5. Newsletter
If you wish to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the specified email address and that you agree to receive the newsletter (double opt-in).
We use HubSpot as our email marketing platform. Your data will be transferred to HubSpot for this purpose. HubSpot is a processor acting on our behalf (Art. 28 GDPR). HubSpot processes data in the EU region.
You can revoke your consent to the storage of data, the email address, and their use for sending the newsletter at any time, for example via the "unsubscribe" link in the newsletter.
6. Plugins and Tools
Google Fonts (CDN)
This website uses Google Fonts provided via a Content Delivery Network (CDN) for the uniform display of fonts. When you access a page, your browser loads the required fonts into your browser cache to display texts and fonts correctly.
For this purpose, the browser you use must connect to Google's servers. This gives Google knowledge that our website has been accessed via your IP address. The use of Google Fonts is in the interest of a uniform and appealing presentation of our online offerings. This represents a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
7. AI Data Processing
AI Model and Processing
nexAI.space uses artificial intelligence (Mistral AI 70B) for the analysis of BIM models (IFC files). The AI processing takes place exclusively on European servers (IONOS, Germany). No personal data is processed by the AI system.
The AI analyzes technical building model data (geometry, attributes, classifications) and generates quality reports. The uploaded IFC files are processed temporarily and deleted after analysis unless the user explicitly saves them in their project.
Continuous Learning Through Automatic Anonymization
To continuously improve AI inspection quality, inspection results and model data areautomatically and completely anonymized before being used for machine learning.
Legal basis: Since only anonymous data is processed, the GDPR does not apply to the training process (Recital 26 GDPR). No separate consent is required.
What is removed before training: User ID, Project ID, project name, building name, address, GPS coordinates, file names, author fields, organization metadata, all GlobalIds, and timestamps (rounded to month/year).
What is used for training (anonymous): Error types and severity levels, building element classes (e.g. IfcWall, IfcDoor), AI confidence scores, generic building typology, and geometric patterns.
After anonymization, it is technically impossible to trace data back to individual projects, persons, or buildings. For full details on the anonymization process, see our EU AI Act Compliance page.
EU AI Act Compliance
Our AI system is classified as a limited-risk AI assistant system under Article 52 of the EU AI Act. nexAI.space is a support tool – the final decision always remains with the engineer or architect. We comply with all transparency, documentation, and human oversight requirements. For detailed information, please see our EU AI Act Compliance page.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR) – You have the right to request confirmation as to whether personal data concerning you is being processed.
- Right to Rectification (Art. 16 GDPR) – You have the right to request the correction of inaccurate personal data.
- Right to Erasure (Art. 17 GDPR) – You have the right to request the deletion of your personal data.
- Right to Restriction (Art. 18 GDPR) – You have the right to request restriction of processing of your personal data.
- Right to Data Portability (Art. 20 GDPR) – You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21 GDPR) – You have the right to object to the processing of your personal data at any time.
To exercise any of these rights, please contact us at: datenschutz@nexai.space
Data Export (Art. 20 GDPR)
You can download your personal data stored with us at any time in a structured, commonly used, and machine-readable format (JSON). The export function is available in your account area under “Export my data”. The export includes:
- Account data (name, email, company, registration date)
- Subscription and license information
- Token balance and usage history
- Team memberships
- Marketing consents
Account Deletion (Art. 17 GDPR)
You can irrevocably delete your account and all associated data at any time. The deletion function is available in your account area under “Delete account”. After deletion, you will receive a confirmation email listing all removed data categories.
9. Retention Periods
Personal data is deleted as soon as the purpose of processing no longer applies and no legal retention obligations prevent deletion:
- User data after contract termination: 30 days (recycle bin), then permanent deletion
- Inactive accounts (no login for 24 months): Automatic deletion after advance notice via email (30-day grace period)
- BIM check results and project data: 6 months after project end or last access
- Cookie consent records (Art. 7(1) GDPR): 3 years from consent (proof obligation)
- Server log files: 90 days
- Email verification tokens: 24 hours
- Marketing opt-in tokens: 48 hours
- Billing data: 10 years (statutory retention obligation under German commercial and tax law)
After the respective period expires, data is automatically and irrevocably deleted, unless statutory retention obligations apply. You may request early deletion of your data pursuant to Art. 17 GDPR at any time.
Last updated: August 2026
