E-DISTI d.o.o. (“E-DISTI”, “AdriaBIM”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have in relation to your data when you use our website and services.
This policy applies to all visitors, customers, and users of adriabim.com and its language versions, operated by E-DISTI for the promotion and distribution of engineering and BIM software and for the AdriaBIM Academy.
By using our website, creating an account, submitting a form, registering for an event, or placing an order, you acknowledge that you have read and understood this Privacy Policy. We process your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Slovenian Personal Data Protection Act (ZVOP-2).
1. Data Controller
The data controller responsible for your personal data is:
E-DISTI d.o.o.
Litijska cesta 259, 1261 Ljubljana, Slovenia
VAT ID: SI72537094
Registration Number: 3792234000
Email: [email protected]
For any questions or requests regarding your personal data, you may contact us at the email address above.
2. Personal Data We Collect
2.1 Data you provide directly
We collect personal data that you voluntarily provide when using our website:
- Contact form: name, company, address, email address, phone number, country, the software you are interested in, and the content of your message
- Software trial and inquiry forms: name, company, city, country, email address, phone number, and qualification details you choose to provide (industry, reason for interest, purchase timeframe, number of licenses, academic use)
- Event registrations and ticket purchases: name, email address, company, phone number, an optional note, and — for paid tickets — billing details (name, company name, address, VAT ID, company type)
- Access to event recordings: name, email address, and company, where a recording requires registration
- Account registration: name, email address, and password
- Support requests: name, email address, the software and category concerned, the subject and content of your ticket, and any files you attach
- Newsletter and marketing: email address and language preference, where you have opted in
2.2 Data collected automatically
When you visit our website, certain technical data is collected automatically:
- Device and browser information: browser type and version, operating system, screen resolution, and device type
- Usage data: pages visited, time spent on pages, referring URL, and navigation paths
- Network data: IP address and approximate geographic location derived from IP
- Campaign attribution data: campaign parameters and advertising click identifiers from the URL you arrived on (such as UTM parameters, gclid, fbclid, msclkid) and the referring page — stored for up to 30 days in your browser and attached to forms you subsequently submit, so we know which campaign an inquiry came from
- Cookies and similar technologies: as described in our Cookie Policy
2.3 Data received when you email us
When you reply to a support notification by email, our email service provider (Brevo) processes the incoming message — including its content and attachments — so it can be attached to your existing support ticket. We do not use the content of support correspondence for any other purpose.
3. Purposes and Legal Bases for Processing
We process your personal data only when we have a valid legal basis under Article 6 of the GDPR:
3.1 Performance of a contract (Art. 6(1)(b))
- Processing and fulfilling event ticket orders and registrations, including delivering confirmations and webinar joining links
- Creating and managing your user account
- Organising and running AdriaBIM Academy events you have registered for
- Providing customer support and processing support tickets
- Communicating with you about your orders, registrations, or support requests
3.2 Legitimate interest (Art. 6(1)(f))
- Responding to inquiries submitted via contact, trial request, and inquiry forms
- Managing customer relationships through our CRM system
- Attributing inquiries and orders to the marketing campaign they came from
- Improving our website, offering, and services based on aggregated usage data
- Protecting against fraud, abuse, and security threats
- Maintaining internal business records and analytics
3.3 Legal obligation (Art. 6(1)(c))
- Retaining invoicing and transaction records as required by Slovenian tax and accounting law
- Responding to lawful requests from regulatory authorities
3.4 Consent (Art. 6(1)(a))
- Sending marketing communications, newsletters, or promotional offers (only when you have explicitly opted in)
- Setting non-essential cookies as described in our Cookie Policy
You may withdraw your consent at any time by clicking the unsubscribe link in any marketing email, using the “Cookie settings” button on our Cookie Policy page, or by contacting us at [email protected]. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. How We Share Your Data
We do not sell your personal data. We share data only with trusted third-party service providers who process it on our behalf or as necessary to deliver our services:
4.1 Customer communication and management
- Brevo — used for transactional emails (order and registration confirmations, support notifications), processing of inbound support emails, and, where you have consented, marketing communications. Data processed: name, email address, phone number, language, and interaction history. Brevo Privacy Policy
- Intrix CRM — used for managing customer relationships, inquiries, trial requests, and event leads. Data processed: name, email, phone, company, country, inquiry details, and campaign attribution. Intrix Privacy Policy
4.2 Analytics and advertising
- Google (Google Analytics 4, Google Tag Manager, Google Ads) — website analytics and advertising measurement, operated under Consent Mode so that cookies are only set with your consent. Google Privacy Policy
- Meta (Facebook Pixel) — advertising measurement, only with your consent. Meta Privacy Policy
- Microsoft (Clarity) — anonymised usage analysis such as heatmaps and session replays, only with your consent. Microsoft Privacy Statement
4.3 Embedded content
Event recordings and product videos are hosted on YouTube and embedded in privacy-enhanced mode, meaning YouTube does not set cookies until you play a video. Google Privacy Policy
4.4 Payments
Payment for event tickets is made by bank transfer to our business account; we do not process payment cards online. If additional payment methods are offered at checkout in the future, the respective payment provider will process your payment data under its own terms, and this policy will be updated accordingly.
4.5 Hosting and infrastructure
Our website is hosted on servers located within the European Union. We use industry-standard hosting providers that maintain appropriate technical and organisational security measures.
4.6 Legal requirements
We may disclose your data if required by law, court order, or regulatory authority, or if disclosure is reasonably necessary to protect the rights, property, or safety of E-DISTI, our customers, or the public.
5. International Data Transfers
Where possible, your data is processed within the European Economic Area (EEA). Some of our service providers (such as Google, Meta, and Microsoft) may transfer data outside the EEA. In such cases, we ensure that appropriate safeguards are in place, including:
- European Commission adequacy decisions (including the EU–US Data Privacy Framework)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The service provider’s certification under an applicable framework
You may request information about the specific safeguards applied to transfers of your data by contacting us.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law:
- Account data: retained for the lifetime of your account and deleted within 30 days of account deletion, unless retention is required by law
- Order and transaction records: retained for a minimum of 10 years from the date of the transaction, as required by Slovenian tax and accounting legislation
- Contact, inquiry, and trial request data: retained for up to 2 years from the date of the last interaction, or until you request deletion
- Event registration data: retained together with the records of the event, and for paid events as part of transaction records
- Support tickets: retained for up to 2 years after the ticket is closed, so we can refer back to your history when helping you again
- Marketing data: retained until you withdraw consent or unsubscribe
- Campaign attribution data: stored in your browser for up to 30 days; where attached to an inquiry, retained with that inquiry
- Automatically collected data: aggregated analytics data is retained indefinitely; raw data containing IP addresses is retained for up to 26 months
When data is no longer needed, it is securely deleted or anonymised so that it can no longer be linked to you.
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data. You may exercise any of these rights by contacting us at [email protected].
- Right of access — you may request a copy of the personal data we hold about you
- Right to rectification — you may request correction of inaccurate or incomplete data
- Right to erasure (“right to be forgotten”) — you may request deletion of your data, subject to legal retention obligations
- Right to restriction of processing — you may request that we limit how we use your data in certain circumstances
- Right to data portability — you may request your data in a structured, commonly used, machine-readable format
- Right to object — you may object to processing based on legitimate interest, including profiling and direct marketing
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
- Right to lodge a complaint — you have the right to file a complaint with the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec) at www.ip-rs.si
We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days, in which case we will inform you of the extension and the reasons for it.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- SSL/TLS encryption for all data transmitted between your browser and our servers
- Secure password hashing for user accounts
- Support ticket attachments stored outside the public media library and served only to the ticket owner and our support team
- Access controls limiting employee access to personal data on a need-to-know basis
- Regular security updates and monitoring of our systems
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you become aware of a security vulnerability or breach, please contact us immediately.
9. Cookies
Our website uses cookies and similar technologies to ensure proper functionality, analyse usage, and improve your experience. For detailed information about the cookies we use, their purposes, and how to manage your preferences, please refer to our Cookie Policy.
10. Children’s Privacy
Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a person under 18, we will take prompt steps to delete it. If you believe a child has provided us with personal data, please contact us immediately.
11. Third-Party Links
Our website may contain links to third-party websites and services. This Privacy Policy applies only to our website. We are not responsible for the privacy practices of third-party websites, and we encourage you to review their privacy policies before providing any personal data.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or services. Changes will be posted on this page with an updated “Last Updated” date.
Material changes — such as new categories of data processing or new data sharing arrangements — will be communicated to registered users via email before taking effect. Your continued use of the website after changes are posted constitutes acceptance of the revised policy.
13. Contact
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a concern about how we handle your data, please contact us:
E-DISTI d.o.o.
Litijska cesta 259, 1261 Ljubljana, Slovenia
Email: [email protected]
VAT ID: SI72537094
You also have the right to lodge a complaint with the supervisory authority:
Information Commissioner of the Republic of Slovenia
(Informacijski pooblaščenec)
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Website: www.ip-rs.si