Skip to content
Legal

Privacy Policy

Version 1.0 · Effective date: September 25, 2026

This Privacy Policy explains how SynTrait - Ingénierie (“Paramettrik”, “we”) processes personal data when you use the Paramettrik plugins and Platform. It complies with Regulation (EU) 2016/679 (“GDPR”) and the French Loi Informatique et Libertés.

In one paragraph: the three local library browsers work entirely on your machine and send us nothing — no models, no families, no project data. We only receive data through the cloud features (Paramettrik Browse), and only when you explicitly sign in, publish, rate, or download. The one exception is the update check: once per Revit startup, the plugin asks our servers whether a newer version has been released. It sends no account, no machine identifier and no content — see §2. Let's be precise about a point others gloss over: when you download a family from a cloud library, we record that it was you, which family, and when (§3) — this is necessary to deliver the file, count your organisation's storage quota, and prevent abuse. By contrast, manufacturers only ever receive aggregates (§4): they do not know who you are. And we never map the Revit projects you work on: our server never sees your models, your project names, or the contents of your files.

1. Data controller

SynTrait - Ingénierie, 37 Avenue de la Résistance, 77500 Chelles, France, SIREN 993 686 328. Contact: support@paramettrik.com. No Data Protection Officer has been appointed; privacy questions are handled at the address above.

2. Local-first principle

  • Local Features (Internal Families, Asset Browser, Project Families) run offline and require no account. They index and process your Revit content only on your device. This data is never transmitted to us.
  • Cloud Features (Manufacturer, Community, Organisation browsers) require sign-in and transmit data only on your explicit action (publish / download / rate).
  • Update check (the only automatic request). Once per Revit startup, the plugin performs a single anonymous request to our release feed to find out whether a newer version of the plugin has been published. It is not tied to an account and works signed-out. Its request body contains only the name of the feed being read — no account, no e-mail, no Machine Identifier, no installed version number, no Revit content. Like any request over the internet, it necessarily exposes your IP address and its timestamp to our host (Supabase, EU — §6), where it may appear in technical logs. We do not use these logs to profile individuals. The version comparison itself happens on your machine: our server is never told what you have installed. If the request fails (offline, corporate proxy), the plugin simply carries on — nothing is retried, nothing is queued.

3. What we process, why, and on what legal basis

DataPurposeLegal basis (GDPR Art. 6)
Email, display name / handle, password (hashed), profile photo (optional, only if you upload one)Account creation & authenticationContract (Art. 6(1)(b))
Device data for licensing: Machine Identifier (non-reversible SHA-256 fingerprint) as well as its raw components — Windows Machine GUID and user SID — plus the machine name, Revit version, OS version, and last-seen dateLicense enforcement, device-limit, fraud prevention. The raw components are retained because device matching is deliberately fuzzy (70/30): this stops you from burning a device slot when only your SID changes (new Windows profile, machine rejoined to a domain).Legitimate interest (Art. 6(1)(f)) & Contract
Subscription status, Active modules, billing interval, Stripe customer/subscription IDsProvide and manage the paid serviceContract
Activation log: license events, including the IP address of the requestSecurity, detecting fraudulent use of a license key, supportLegitimate interest (Art. 6(1)(f))
Contributions you publish (family files, thumbnails, documents, metadata)Operate the cloud libraries you publish toContract
Ratings given to families (your account + star count)Display a reliable average rating, one rating per person per familyContract
Organisation membership, role, seat allocationOperate organisation accountsContract
Download log — attributable: your account, the family and version downloaded, the Revit version, the timestampDeliver the file, count your organisation's storage quota, feed the public "downloaded N times" counter, measure a manufacturer's audience in aggregate form (§4), prevent abuseContract & Legitimate interest (Art. 6(1)(f))
IP address + timestamp of the startup update check (§2) — no account or identifier attachedTell you a new version exists; keep the service secure (abuse prevention/rate-limiting at the host)Legitimate interest (Art. 6(1)(f))
Support correspondence, logsProvide support, security, debuggingLegitimate interest
Comments posted on a manufacturer family (text, display name, profile photo)Public display on the product page, in the Manufacturers tab of the website (paramettrik.com)Contract (Art. 6(1)(b))

We do not sell personal data. We do not build behavioural profiles of a designer's project work: we know that an account downloaded a given family, not which project, building, or client you are working on — that information never leaves your machine.

Manufacturer download history, on the plugin side. The "Manufacturer" window shows your own downloads per brand. This tally is kept in a local file on your machine (%APPDATA%\Paramettrik\SmartBrowse\); it is never transmitted and disappears if you delete it.

Your comments on manufacturers' products, together with your display name and profile photo, are publicly visible on paramettrik.com.

4. What manufacturers see

This is the question every designer asks when downloading a branded family. Today, the answer is clear-cut.

  • A partner manufacturer has access to a dashboard that shows them, for their own families: the total number of downloads, the breakdown by Revit version, the trend over time, and a ranking of their most-downloaded families.
  • No identity is ever passed to them: not your email, not your name, not your organisation, not your IP address, not any identifier about you. They see "128 downloads, 41 of them on Revit 2024" — never "John Smith, firm X, downloaded this on Tuesday."
  • We do not sell, rent, or hand over your contact details to manufacturers.

If we ever introduce a named lead hand-off (for example, an RFQ where you identify yourself to the brand), it will be triggered by you, explicitly, and based on your consent — never on a silent background transmission. This policy will be updated before that happens, not after.

5. Payments

Payments are processed by Stripe, our payment processor. The seller is SynTrait - Ingénierie, operating under the Paramettrik brand. We do not receive or store your full card details; Stripe processes payment data under its own privacy terms. We receive limited billing metadata (e.g. subscription status, customer ID) to provision your entitlement.

6. Processors and where data is stored

We use the following processors under data-processing terms:

  • Supabase — authentication, database, storage backend. Region: EU (Paris, eu-west-3).
  • Cloudflare R2 — object storage for family files, thumbnails, documents (private buckets, presigned access). Buckets are located in Western Europe (Cloudflare region WEUR).
  • Stripe — payment processing.
  • Vercel — hosting of the website (paramettrik.com).

Account e-mails (sign-up, invitations, password resets) are sent by Supabase's built-in mailer; we use no other e-mail provider. We use no analytics, advertising, session-recording or error-tracking third party.

Personal data is hosted in the European Union.

7. International data access / transfers

Paramettrik's operator accesses systems from Madagascar, which is outside the EEA and is not covered by an EU adequacy decision. Where this results in a transfer of, or access to, EU personal data from outside the EEA, we implement appropriate safeguards under Chapter V of the GDPR, in particular technical measures limiting access to personal data: the platform's super-admin view does not expose members' e-mail addresses.

8. Retention

  • Account data: for the life of your account and 12 months thereafter, then deleted or anonymised.
  • Billing records: as required by tax/accounting law (typically up to 10 years in France for accounting records).
  • Community Contributions: kept while they are published, withdrawn by you or refused at moderation, and deleted when you delete them or when your account is deleted. Copies other users downloaded before that remain on their own devices, outside our control, and stay usable under the Community Licence (EULA §7.3).
  • Organisation Contributions: deleted or returned after the subscription ends, subject to legal retention.
  • Aggregated analytics: retained in aggregate form (not personally identifying).

9. Your rights

Subject to applicable law, you may: access, rectify, erase, restrict, or object to processing of your personal data, and request portability. To exercise these rights, contact support@paramettrik.com.

  • Erasure and Community Contributions: when we delete your account, we first delete all your Community Contributions, with their files, ratings, comments and likes. Copies other users downloaded before that remain usable under the Community Licence (EULA §7.3), and we cannot recall them. Organisation and account data are erased or anonymised as described above.
  • You may lodge a complaint with the French supervisory authority (CNIL, www.cnil.fr) or your local authority.

10. Security

We apply appropriate technical and organisational measures, including encryption in transit, DPAPI-encrypted local entitlement storage, presigned time-limited URLs for cloud object access, Row-Level Security on the database, and least-privilege service credentials. No system is perfectly secure; you are responsible for safeguarding your account credentials.

11. Cookies / website

This policy covers the plugins and the website (https://paramettrik.com). The website sets only strictly necessary cookies: the Supabase authentication session cookie, which keeps you signed in, and a language cookie (NEXT_LOCALE), written only if you pick a language yourself. Your light/dark preference is stored in your browser's local storage, not in a cookie. We set no analytics, advertising or tracking cookies, which is why the site shows no consent banner. If you pay, Stripe's hosted checkout sets its own cookies on Stripe's domain, under Stripe's privacy terms.

12. Children

The Platform is intended for professional use and is not directed to children under 15.

13. Changes

We may update this Policy. Material changes will be notified in-app or by email before taking effect. The "Effective date" reflects the latest version.

14. Contact

Privacy questions: support@paramettrik.com · SynTrait - Ingénierie · 37 Avenue de la Résistance, 77500 Chelles, France.