Your use of BIMachine constitutes your acceptance of this Agreement.
Welcome to BIMachine!
When you use our services, you entrust us with your information. We understand that this is a privilege and we recognize the importance of protecting this information. That is why we strive to process it responsibly and in compliance with applicable data protection laws in all countries where BIMachine operates.our mission is to enable organizations to grow and scale through technology by empowering people.
Thus, to offer our services, BIMachine, through the platform http://app.bimachine.com.br, our website https://www.bimachine.com.br/, http://store.bimachine.com.br/ of the specific url of customers and partners and the synchronized mobile application, collects various data and information, with the aim, above all, to offer an ever better experience for you and your company. We recognize that ensuring the confidentiality of personal and business data of the users of our platform is very relevant and therefore we are committed and take all possible measures to safeguard your privacy.
In this regard, this Policy is intended to help you understand what personal information and business data we collect, why we collect it, how it is handled, stored, used, shared and processed from individuals, customers, business partners, suppliers and other organizations with which BIMachine has or may have a business relationship and for what purposes we prepare this document, as well as how you can update, manage, export and delete this information.
This document is an integral part of our Terms of Use and Services, which contains a general description of our platform. It has been written in a simple and accessible way so that you can read and understand how we use your information to provide you with a safe and comfortable experience when using the services we offer you. Therefore, all personal and business information relating to members, customers or visitors using BIMachine will be treated in accordance with the Personal Data Protection Act of August 14, 2018 (Law No. 13,709).
Acceptance of our Policy will be made by logging in and registering your user on our platform for the enjoyment of our services, even if it is in the form of POC (Proof of Concept). If you do not agree with this policy, do not continue with the registration procedure and do not use our services.
However, please inform us of your disagreement so that we can improve it. Please note that if you do not agree with the contents of this policy, we do not recommend that you register your information or provide any data.
1. About data collection
BIMachine collects data from you and your company, through the registration you do when you log into the tool, the structures you register, the loads you perform and the daily use. You provide this data directly.Provided by you – When you add a user and register, you provide us with personal information. This information is collected and may include your name, e-mail, password, phone number, cell phone profile, and area of expertise, among others – by filling out the registration form in "My Profile". Eventually, the request for some information may be made through direct contact from BIMachine support with users via email or phone.
When we ask you to provide your personal data or upload business data of any nature, whether financial, commercial, industrial, accounting, legal, etc., you can refuse. If you choose not to provide the data necessary for the provision of a product or feature, you will not be able to use it. Similarly, when we need to collect personal data, upload it when required by law, enter into or perform a contract with you and you do not provide it, you will not be able to enter into the contract.
We do not collect information that includes unique identifiers, browser type and settings, device type and settings, operating system, mobile network including carrier name and phone number, and system or application version number.
We collect information about how apps, browsers and devices interact with our services, including IP address, error reports, system activity, and the date, time and URL referencing your request, as is common practice in the industry.
When you use our services, we do not collect information about your location. We do collect information about your activity on our services and use such information for logging purposes, for example. The activity information we collect may include the terms you search for, the Webinar videos you watch, the objects you access, and other activities.Site Navigation Information – When you visit our site, a cookie is placed in your browser by Google Analytics software to identify how often you return to our address. Information such as IP address, geographical location, referral source, browser type, length of visit and pages visited is collected.
Contact history – We store information regarding all the contacts you have already made with our users, such as interactions via email. Data generated when using our services or if you open a ticket – If you use any of our other services, we may also collect other information from you such as contact data such as your name, email and phone number, local data such as country, city and state where the access is taking place, professional profile data, including, but not limited to, job title, company name and segment where you work. We will also collect your name and email information through the tool we use for opening calls, and we will ask for your authorization before using the information for purposes not covered in this Privacy Policy.
We use software to better understand the functionality of the platform in order to constantly improve it. This software may record application usage information such as events that occur within the application, aggregate usage, performance data and where the mobile application was downloaded from, your city location, the device model and version, the device identifier (or "UDID"), the operating system version, and your BIMachine log in credentials.
2. About the use of your confidential personal and business data
BIMachine uses the data it collects to provide sophisticated and interactive experiences and to generate information through the data provided during the loading process performed on the database provided. This way for each database we store a name, port, host/IP, login, password, FTP, VPN and other access information that your company gives us so that we can access this data and translate it into useful information for you and your company, as well as create intelligence, which we also call analytical objects, and performance indicators, but we should not know the structure of the database of our clients’ systems.
However, if the need arises we can use other tools to visualize this structure, provided you provide access to the server. The collection of personal data is important for us to identify the profile of our users and be able to focus sales on the profiles with the most access, as well as stimulate the use for other areas by showing the importance of accessing the tool. However, you can change at any time the personal information provided in your registration, except email. To change your email or delete your user from an account or project, you must ask your company’s administrator or immediate superior.
If you lose access to your BIMachine account, you should contact your line manager who will provide you with new access. Specifically, we use this personal and business data to:
* Provide our products, including updating, security and troubleshooting, as well as providing support. This also includes sharing data when you perform and to provide the service or carry out the transactions you request;
* To communicate with you about products, services, promotions, news, updates, events, direct announcements or articles about BIMachine and the presentation of news in the tool (releases), conducting research and other subjects that you may be interested in;
* Your email is also used for the operation of sending the material or information requested by you and can also be used for sending Newsletters (we don’t have a specific frequency for this), related to the Digital Marketing theme, to communicate holidays, recess and internal working hours, platform maintenance information, update schedules, server migration, send messages such as alerts, notifications on monitoring objects and sending schedules.
* Improve and develop our product;
* Customize our product and make recommendations;
* Providing intelligence creation;
* Operating our business, including fulfilling our legal obligations and developing our workforce;
* For any purpose that you authorize at the time of data collection;
* When requesting a free trial of the BIMachine software, the user receives an agreement that specifies the extra information that will be required to use the trial period, as well as your privacy policy and the confidentiality with which this information will be treated.
We do not share confidential personal or business data of customers and partners with third parties, except as required by law or to respond to a legal process, to protect our customers; protect lives, maintain the safety of our products and protect the rights or property of BIMachine and its customers. Therefore, all these data are treated as confidential and secret, and we will only use them for the purposes described and authorized by you, mainly for you to use our services fully, always aiming to improve your user experience.
Eventually, we may use data for purposes not foreseen in this privacy policy, but these will be within your legitimate expectations. The occasional use of your data for purposes that do not comply with this prerogative will be made with your prior consent.
BIMachine reserves the right to monitor the entire platform, mainly to ensure that the rules described in our Terms of Use are being observed, or that there is no violation or abuse of applicable laws. To this end, we reserve the right to exclude any user, regardless of type, if this Policy is not respected.
We also reserve the right to exclude users who are not connected to any project or who have been inactive for more than 90 days. Finally, we also emphasize our right to deactivate data loading schedules in projects that have been without access for more than 60 days.
3. About access to your personal or business data
None of our clients can access the information of others, unless the client himself provides access data. If the client changes any connection data to the bank (password, login, port, etc.), he must update this information in BIMachine so that it does not give an access error to the bank. If this error occurs, the customer is prevented from generating a load until he updates the modified information. Thus, if this information is changed, the customer is responsible for making the change to the current data through the platform’s environment management, so that we can continue providing the information.
Only people with the proper authorizations according to your registration within the system and BIMachine’s employees can see your personal or business information when your project is actively supported. No personal or business data can be publicly disclosed, if you so wish. If you decide to disclose it, you can do so with the publisher and the submitter.
The user who is the Project Master can see if the users registered in his project are active in our product, including whether they are currently online, or when they last logged in. He can also see the personal information of the registered users or business of the organization to which he belongs, all your data is confidential and any use of it will be in accordance with this Policy.
BIMachine will undertake all reasonable market efforts to ensure the security of our systems and your data. Our servers are located in different locations around the world to ensure their stability and security, and can only be accessed through previously authorized communication channels.All your information will be, where possible, encrypted, if they do not invalidate their use by BIMachine.
At any time you can request a copy of your data stored in our systems. We will retain data and information only until such time as it is necessary or relevant for the purposes described in this Policy, or in the case of periods predetermined by law, or until such time as it is necessary for the maintenance of legitimate interests of BIMachine.
BIMachine considers your privacy extremely important and will do everything in its power to protect it. Although we work with good practices of protection and security, no web service has a 100% guarantee against invasions and we can not be responsible if this occurs. Thus, we cannot completely guarantee that all data and information about you and your company on our platform will be free from unauthorized access, especially if there is improper sharing of the credentials needed to access our platform or if users share documents with other colleagues who should not receive the information.
Therefore, you are solely responsible for keeping your access password in a safe place and sharing it with third parties is forbidden. You undertake to notify BIMachine immediately, by secure means, of any unauthorized use of your account, as well as unauthorized access by third parties to your account. You are also responsible for the documents you share with other users of the platform, including those you forward by email.
4. About data sharing
By clicking on the content sharing buttons available on our object pages, the user is sharing the content through his user profile. However, by sharing we are not responsible for the acts and content generated by our clients or business partners, since BIMachine does not control them. All data, information and content about you and your company can be considered assets in the case of negotiations in which BIMachine is part.
Therefore, we reserve the right to include your data among the assets of the company if it is sold, acquired or merged with another. By this policy you agree and are aware of this possibility. BIMachine reserves the right to provide your data and information about you and your company, if required to do so by law, act necessary for the company to comply with national laws, or if you expressly consent.
Our system allows you to share information and things with others, and you have control over how it is shared. For example, you can share items publicly or choose to keep it private. Keep in mind that when you share information publicly, the content can be accessed through search engines, including Google Search.
You should consider with whom you choose to share a document, file, or object, as people may decide to share it with others outside of our product, including people and companies outside the audience you shared it with. For example, when you share a document, they may download, take a screenshot of, or re-share that content with third parties.
We do not and never will sell any of your information to anyone. We also do not share personal or business information with companies, organizations or individuals outside of BIMachine, except as described below.
With your consent – We will share personal or business information outside of BIMachine when we have your consent. We will require your explicit consent to share any sensitive personal or business information.With domain administrators – Project administrator users can access user information from the "My Profile" screen, but cannot edit that information. It is likely that they can:
* access and view the information stored in your Profile;
* restore objects created outside of your home folder that have been deleted;
* suspend or terminate access to your account;
* receive information from your account to comply with any applicable law, regulation, court order or governmental request;
For legal reasons – BIMachine also undertakes not to sell, rent or pass on your information to third parties. The only exception is in cases where this information is required by law. We will share personal information outside of BIMachine if we have a good faith belief that access, use, retention or disclosure of the information is reasonably necessary to:
* comply with any applicable law, regulation, legal process or governmental request. comply with applicable Terms of Service, including investigation of potential violations;
* detect, prevent or otherwise address fraud, technical or security issues;
* protect against harm to the rights, property or safety of BIMachine, our users or the public as required or permitted by law.If BIMachine becomes involved in a merger, acquisition or asset sale, we will continue to ensure the confidentiality of your personal or business information and will provide notice to affected users before such information is transferred or subjected to a different data and privacy policy.
5. About the use of information provided to our customers
BIMachine makes available to its clients, through the BIMachine software, tools for creating intelligence, also called analytical objects, such as: analysis, KPI, map, organizational chart, dashboard and cockpits and allows the sending of email with the same.However, BIMachine does not control the information provided during the use of the system. This data belongs to the clients, who use, disclose and protect it according to their data and privacy policies. They are also responsible for uploading, managing and processing sensitive information.
To learn more about your responsibility for the data you collect, we recommend that you read the service agreement we have with your organization for the use of our systems. BIMachine allows the user to create filters and permissions for the objects, so that these objects can be shared only with whom the user wishes and with data restriction according to configured filters. This means that you are responsible for sharing the objects you have created, and if you do not want to share with a particular user, you can create, change, and remove these filters and permissions whenever you want. You can also create specific user profiles to perform certain actions on the system.
To learn more about this topic, see our knowledge base.
6. About unsubscribing and changing/deleting personal and business information
You can choose not to receive any further emails from BIMachine. In every email we send there is always an unsubscribe link available in the last lines. Clicking on this link will automatically unsubscribe you from the list. All data collected will be deleted from our servers when you so request or when they are no longer necessary or relevant to offer you our services, unless there is any other reason for their maintenance, such as any legal obligation to retain data or need to preserve them to protect the rights of BIMachine. To change your personal information or delete it from our database, simply send an email to contato@bimachine.com.br.
7. Other important data and privacy information
If your organization grants you access to the BIMachine product, your use of the product will be subject to your organization’s policies, if any. You should direct your data and privacy questions, including any requests to exercise your data protection rights, to your organization’s administrator.
BIMachine is not responsible for our customers’ data, privacy or security practices, which may differ from those set forth in this policy.
About your privacy controls – You have choices regarding the information we collect and how it is used by managing your contact information, such as name, email and phone number in your registration. To delete this information you can: delete non-binding data from your profile and delete a user from the project.
When a customer tries out, purchases or uses our product or obtains support or professional consulting services for that product, BIMachine collects data to provide the service (including uses consistent with service provision), provide the best experiences with our products, conduct our business, and communicate with the customer. For example:
* When a customer or prospect enters into a contract or establishes contact with a member of BIMachine’s sales, partners or marketing department, we may collect the customer’s name and contact information (email, job title, phone number, area of practice, but not limited to these), along with information about the customer’s organization (name, address, website, CNPJ, phone number, industry, systems it owns, but not limited to these), to support that contract or initiate a relationship. This information, as well as all the history of contacts made are recorded in our CRM and access to this information is restricted to the directors of BIMachine and employees of these departments who have login, password and specific access profiles.
* When a customer interacts with a BIMachine support professional, we collect usage and device data or error reports to diagnose and resolve issues;
* When BIMachine sends communications to a customer, we use data to personalize the content of the communication;
* When a customer contracts with BIMachine for professional services, we collect the name and designated contact information of the customer and their organization, and use the information provided to perform the services the customer has requested.
8. Research and artificial intelligence
Search and artificial intelligence products connect you to information and intelligently detect, process and act upon it, learning and adapting over time. BIMachine uses the IBM Watson Assistant to assist in your navigation on our platform. With the IBM Watson™ Assistant service, you can build a solution that understands natural language input and uses machine learning to respond to customers in a way that simulates a conversation between humans. Users interact with your application through the implemented interface, whether it’s a simple chat window or mobile app or even a robot with a voice interface.
9. European Union Privacy Law
For privacy reasons European citizens have the right to request that their personal information be removed from BIMachine’s database under applicable laws (EU Privacy Act). Providing your information accurately thus helps us to investigate your request when opening a call for this purpose.
Remove Partial or Full Data – You may request removal of specific data from our database. To request removal of personal information, please send an email to suporte@bimachine.com.br.
Resubmit Data – In this email you will receive a copy of all your personal data that is part of BIMachine’s database. To request a copy simply email suporte@bimachine.com.br.
Security of Data Removal – In order to verify the suitability of the person who is requesting the removal of data, after your request, we will analyze the privacy rights and the data sent for identification. For example, data removal may be refused if we identify that it is an act of impersonation of another person’s identity or concealment of legal information in order to harm a third party (competition, company, customers, leads, etc.).
BIMachine will use this information only to review and document the authenticity of your request and will delete the copy within 72 hours of the date of the removal request, unless legally required to do so by contract (EU Privacy Act).In some cases, we store data for limited periods when it needs to be kept for legitimate business or legal purposes. We try to ensure that our services protect information from accidental or malicious deletion. Because of this, there may be a time lag between the time you delete something and the time copies are deleted from our active and backup systems.
BIMachine performs daily backups on the platform. You may have additional rights under local law applicable to the processing. For example, if the processing of your personal information is subject to the EU General Data Protection Regulation ("GDPR": General Data Protection Regulation), and your personal information is processed based on legitimate interests, you have the right to object to the processing based on your specific situation. Under the GDPR you may also have the right to request that your personal information be deleted or restricted and to request portability of your personal information.
10. About this policy
This Policy applies to the product and all services offered by BIMachine and its respective users, whether customers, employees, partners or anyone else who has or may have a business relationship or employment with us, but does not apply to:
* information collection practices of other companies and organizations that use our services;
* services offered by other companies or individuals, including products or websites.
11. Changes to this Policy
This Data and Privacy Policy may be updated from time to time. The BIMachine team reserves the right to change this agreement without notice. Therefore, we recommend that you consult this policy regularly in order to be up to date on changes.
We will not reduce your rights under this Policy without your explicit consent. We always indicate the date on which the latest changes were published and provide access to archived versions for your review. If the changes are significant, we will provide a more prominent notice, which includes, in the case of some services, email notification of changes to the Policy or in BIMachine’s NEWS.Before using information for purposes other than those set forth in this Policy, we will ask for your authorization.
BIMachine is committed to maintaining a visible link to the data and privacy policy in the user login area of the platform, as well as in the footer of the company’s website and mobile app.
12. Applicable Law
This document is governed by and shall be interpreted in accordance with the laws of the Federative Republic of Brazil. The District Court of Lajeado, Rio Grande do Sul, is elected as the competent jurisdiction to settle any issues that may arise from this document, expressly waiving any other, however privileged it may be.
13. Service channels for user doubts or contact
Any questions regarding our policy can be clarified by contacting us. You can contact us for any questions, compliments, complaints, suggestions, consulting requests, problems or new features. Our main communication channel is through the opening of a call in the BIMachine platform itself, because through this, it is possible to keep all the history of messages exchanged between the support and the client, which helps us to check and streamline our control of calls and also keep a record of your request.
However, there are other ways to contact us and you can choose the one you want: You can select the "Open Technical Call" option within our platform. To learn more, please visit our knowledge base: https://support.bimachine.com.br/pt/article/como-abrir-um-ticket-no-suporte https://support.bimachine.com.br/pt/article/canais-de-apoio-suporte.
You can also open a ticket via email at suporte@bimachine.com.br, which we will evaluate and get back to you as soon as possible. You can also call support by phone: +55 51 3709.2950. We are located at Rua Alberto Torres, 613, sala 401 – Centro, Lajeado-RS CEP: 95900-188.
14. Compliance and cooperation with regulators
We regularly review this Policy and make sure that we process your information in accordance with it.Data transfers – We have servers all over the world and your information may be processed on servers located outside the country in which you live. Data protection laws vary from country to country, with some offering more protection than others. Regardless of where your information is processed, we apply the same protections described in this policy.
We also comply with certain legal frameworks relating to data transfer, such as the Privacy Shields between the European Union and the United States and Switzerland and the United States.When we receive formal written complaints, we respond by contacting the complainant. We work with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of data that we cannot resolve directly with you.
15. Cookies and Similar Technologies
Cookies are small text files placed on your device to store data that can be remembered by a web server in the domain that placed the cookie. We use cookies and similar technologies to store and respect your preferences and settings, allow you to log in, fight fraud (robots), analyze our product performance, and serve other legitimate purposes.
You have a variety of tools to control the data collected by cookies, web beacons, and similar technologies. For example, you can use the controls in your Internet browser to limit how the websites you visit may use cookies and withdraw your consent by clearing or blocking cookies.
Our platform uses cookies and web beacons, even if these data collection features are applied by partners or vendors (Google Analytics). For example, we use cookies to keep the user logged into the platform, which keeps the active section unused for up to two hours and we use web beacons to verify that the user has read the email sent by BIMachine.Your login and password information can be stored by the browser, if you check the "remember me" option of the browser, so that it is faster and easier for the browser to remind you of your login data, as long as you are using the same browser.
To avoid storing data in the browser there is the possibility of surfing the platform anonymously, so that the user’s actions are not identified by cookies or web beacons.User login and password are stored in our database, but passwords are encrypted so that it is not possible to discover them. Also stored is data that you have filled out in the "My Profile" of the user registration, as well as confidential customer data from data connections provided by the user himself.Our platform is hosted on Amazon.
For more information about the information security policies on our servers, please click on the links below:https://aws.amazon.com/pt/aup/https://aws.amazon.com/pt/security/https://aws.amazon.com/pt/compliance/data-privacy-faq/https://aws.amazon.com/pt/products/security/
16. Non Disclosure Agreement
All our employees and service providers sign a term of commitment to secrecy, confidentiality and undertake not to share or disclose confidential information owned by the company or customers and partners with third parties, whether information of any nature, such as personal data, financial, commercial, industrial, accounting, legal, etc.. In case of breach of this agreement, the employee identified will be disconnected and will be subject to civil or criminal action, as appropriate and fine, as established by contract, however, the BIMachine is not responsible and will not be penalized for information leakage that does not cause, and the offending employee will be responsible individually, bearing alone the burden of their actions.
17. Information Security
We build security into our services to protect your information. BIMachine is built with robust security features that continuously protect your information. The insights we get from maintaining our product help us automatically detect and block security threats before they reach you. And if we detect something dangerous and noteworthy, we will notify you and guide you through the steps you need to take to stay safe.
So we work hard to protect you, your company, and BIMachine from unauthorized access, alteration, disclosure, or destruction of the information we hold, which includes:
* the use of encryption to keep your data private while in transit from server to client when using the https protocol;
* the provision of a variety of security features such as Secure Browsing, Security Scanning and Two-Step Verification to help you protect your account. To learn more about this, we recommend reading our Password Policy;
* the restriction on access to personal information by BIMachine employees, contractors and representatives who need that information to process it.
Any person with such access is subject to strict contractual obligations of confidentiality, and may be disciplined or dismissed if they fail to comply with such obligations.
18. Privacy and Data Security Principles for BIMachine Cloud Services
The technical and organizational measures provided herein apply to the BIMachine Cloud Services, including any underlying applications, platforms and infrastructure components operated and managed by BIMachine in providing the Cloud Service, except where Customer is responsible for data security and privacy or if otherwise specified in a contract document.
Customer is responsible for:
(a) determining whether the Cloud Service is suitable for Customer’s use;
b) implementing and managing the security and privacy measures for elements not provided and managed by BIMachine within the Cloud Service, such as systems and applications created or implemented by Customer and or Customer’s end user access control to the software.
1. Data Protection
The security and privacy measures for each Cloud Service are designed in accordance with BIMachine’s secure engineering and design privacy practices to protect the input of content into a Cloud Service, and to maintain the availability of such content as per the agreement and applicable documents. Customer is the sole controller of any personal and business data included in the content and appoints BIMachine as a processor to process such personal data (as those terms are defined in the General Data Protection Regulation (EU) 2016/679). BIMachine will treat all Content as confidential without disclosing it except to BIMachine employees, contractors and sub-processors, and only to the extent necessary to deliver the Cloud Service, unless otherwise set forth in a contract.
2. Security Policies.
a. BIMachine will maintain and follow IT security policies and practices that are integral to BIMachine’s business and mandatory for all BIMachine employees. BIMachine’s CIO will maintain executive responsibility and oversight of such policies, including formal governance management and review, employee education, and compliance enforcement.
b. BIMachine will review its IT security policies at least annually and amend such policies as BIMachine deems reasonable to maintain the protection of the Cloud Services and the content processed therein.
c. BIMachine will maintain and follow its standard mandatory employment verification requirements for all new hires. In accordance with BIMachine’s internal processes and procedures, these requirements will be reviewed periodically and include, but are not limited to, criminal background checks, proof of identity validation, and additional checks as BIMachine deems necessary.
d. BIMachine employees will sign the security and privacy document and will abide by BIMachine’s policies on ethical business conduct, confidentiality, secrecy and security.
a. BIMachine will investigate unauthorized access and use of content of which it becomes aware (security incident) and, in the scope of the Cloud Service, define and execute an appropriate response plan. Customer may notify BIMachine of a suspected vulnerability or incident by submitting a technical support request.
b. BIMachine will notify the customer, without undue delay, when it confirms a security incident known or reasonably suspected by BIMachine to affect the customer. BIMachine will provide the customer with reasonably requested information about such security incident and the status of any remediation and restoration activities.
4. Access Control, Intervention, Transfer and Shutdown
a. BIMachine will maintain measures for a Cloud Service that are designed to logically separate and prevent content from being exposed to or accessed by unauthorized persons. BIMachine will maintain appropriate isolation of its production and non-production environments (test environment, replicated environment, or homologation environment), and if content is transferred to a non-production environment, for example, to reproduce an error at the request of the customer, the data, security, and privacy protections in the non-production environment will be equivalent to those in the production environment.
b. BIMachine will encrypt content not intended for public or unauthenticated viewing when transferring content via public networks, and will allow the use of a cryptographic protocol, such as HTTPS, SFTP, and FTPS, for the secure transfer of content from the customer to and from the Cloud Service via public networks.
c. If the Cloud Service includes cryptographic key management, BIMachine will maintain documented procedures for secure key generation, issuance, distribution, storage, rotation, revocation, recovery, backup, destruction, access, and use.
d. Consistent with industry standard practices, and to the extent natively supported by each component managed by BIMachine within the Cloud Service, BIMachine will maintain technical measures imposing inactive session timeout that is two hours, account lockout after multiple sequential failed login attempts, strong password or passphrase authentication, and measures requiring secure transfer and storage of such passwords and passphrases.
5. Service Integrity and Availability Control
BIMachine will:
(a) perform security and privacy risk assessments of its Cloud Services at least annually;
b) perform intrusion testing and vulnerability assessments, including automated system and security application scanning, manual ethical hacking, prior to production release and annually thereafter;
c) recruit a qualified independent third party to perform intrusion testing at least once a year;
d) perform automated management and routine verification of underlying components’ compliance with security configuration requirements; and
e) remediate identified vulnerabilities or non-compliance with its security configuration requirements based on associated risk, exploitability, and impact. BIMachine will follow reasonable steps to avoid disruption of the Cloud Service when performing its testing, assessment, scanning, and the execution of remediation activities.
f) BIMachine will maintain policies and procedures designed to manage risks associated with applying changes to its Cloud Services. Prior to implementation, changes to a Cloud Service, including its underlying systems, networks and components, will be documented in a recorded change request, which includes a description and reason for the change, details and timeline of the implementation, a risk statement addressing the impact to the Cloud Service and its customers, the expected outcome, the recovery plan, and documented approval by authorized staff.
g) BIMachine will maintain an inventory of all information technology assets used in its operation of the Cloud Service. BIMachine will continuously monitor and manage the health, including capacity, and availability of the Cloud Service and underlying components.
h) Each Cloud Service will be separately assessed for business continuity and disaster recovery requirements as per documented risk management guidelines. Each BIMachine Cloud Service will, to the extent warranted by such risk assessment, have business continuity and disaster recovery plans defined, documented, maintained and validated annually, consistent with industry standard practices.
(i) AWS maintains measures designed to evaluate, test and apply recommended security patches for the Cloud Service and its associated underlying systems, networks, applications and components within the scope of the Cloud Service, except in terms of the operating system which is BIMachine’s responsibility. Upon determination that a recommended security patch is applicable and appropriate, BIMachine will apply the patch in accordance with the documented severity and risk assessment guidelines.
6. Other aspects of the BIMachine Cloud Privacy Policy
The evaluation, purchase, maintenance and verification of operation of any non-BIMachine product, program or service are the responsibility of the customer. BIMachine may, at any time, improve and/or change products or programs described in this publication without notice. All references in this information to non-BIMachine websites are provided for convenience only and not in order to serve as an endorsement of those websites. The materials contained on those websites are not part of this BIMachine product materials and use of those websites is at the customer’s own risk.
BIMachine may use or distribute the information provided in any manner it deems appropriate without incurring any obligation to the customer.Information regarding BIMachine products has been obtained from the suppliers of the respective products, their published advertisements or other publicly available sources. BIMachine has not tested these products and cannot confirm the accuracy of performance, compatibility or any other statements regarding non-BIMachine products. Questions about the capabilities of non-BIMachine products should be referred directly to their vendors.
BIMachine’s innovative cloud computing platform combines platform as a service (PaaS) with infrastructure as a service (IaaS) and includes a catalog of cloud services that can be integrated with PaaS and IaaS to build area-specific business applications.BIMachine Cloud has implementations to fit your needs. You can develop in a borderless cloud, in which you can connect your services and systems to available BIMachine Cloud services.
You and your team can access the applications, services and infrastructure in the BIMachine Cloud and use existing data, systems, processes, PaaS tools and IaaS tools. With BIMachine Cloud, you no longer have to make large investments in hardware to test or run a new application. Instead, we manage everything for you and charge only for what you use. BIMachine Cloud provides integrated, dedicated, on-premise deployment models. In addition to the platform’s own features, BIMachine Cloud also provides flexible deployment.
BIMachine enables you to:
* Test and adopt a wide variety of cloud services and features from BIMachine, open source communities and third-party developers.
* Connect all your legacy systems and apps from a single, scalable cloud platform via the private network and API capabilities.
* Move resources in real-time as your business needs or workload demands change.
You can use BIMachine Cloud Mobile services to embed pre-built, managed and scalable cloud services into your mobile apps. Watson gives your apps the power of cognitive computing with a full set of expression, vision, and data APIs. BIMachine’s Internet of Things service enables your apps to communicate with your devices, sensors and connected gateways, and consume data that is collected by them. Our guidelines make it easy for you to get devices connected to our Internet of Things cloud. Your apps can then use our real-time APIs and REST to communicate with your devices and consume the data you have defined for them to consume.
BIMachine provides a mobile backend infrastructure in which you can build cross-platform, native or hybrid apps while also being able to monitor and test them. You can also enhance your app with analytics, security, user insight and continuous delivery. BIMachine Cloud ResiliencyThe BIMachine Cloud is designed to host resilient and scalable apps and app artifacts that can scale to meet your needs, remain highly available and be quick to recover from problems. The BIMachine Cloud separates the components that control the state of interactions (stateful) from those that do not (stateless).
This separation allows BIMachine Cloud to move apps flexibly as needed for scalability and resiliency.There may be one or more instances running for your app. For multiple instances of a single app, the app is uploaded only once. However, BIMachine Cloud deploys the requested number of instances of the app and distributes them among as many virtual servers as possible. You must save all persistent data to a stateful data store that is outside your app, such as one of the data storage services that BIMachine Cloud provides.
Because anything cached in memory or on disk may still not be available after a reboot, you can use the memory space or file system of a single BIMachine Cloud instance as a single transaction brief cache. With a single instance configuration, the request to your app may be interrupted because of the stateless nature of BIMachine Cloud. A best practice is to use at least three instances for each app to ensure its availability.
The entire BIMachine Cloud infrastructure and specific management components are highly available. Multiple instances of the infrastructure are used to balance the load.Integration with systems of record BIMachine Cloud can help developers by connecting two broad categories of systems in a cloud environment:
* Systems of record include apps and databases that store business records and automate standardized processes.
* Systems of engagement are features that expand the usefulness of systems of record and make them more engaging for users.When integrating a system of record with the app you create in BIMachine Cloud, you can perform the following actions:
* Enable secure communication between the app and the backend database by downloading and installing a secure connector in place.
* Call a database in a secure manner.
* Create APIs from integration flows with databases and backend systems, such as the customer relationship management system
* Expose only the schemas and tables that you want exposed to the app.
* As the manager of the BIMachine Cloud organization, publish an API as a private service that is visible only to members of your organization.
Prerequisites for using the BIMachine Cloud platform – minimum browser software version required for BIMachine Cloud:
* Chrome: latest version for your operating system
* Firefox: latest version for your operating system
* Edge: latest version for Windows
* Safari: latest version for Mac
19. For clients who use the BIMachine On Premise platform services
In order for us to provide our services properly, please check the requirements that need to be met, as specified below:
Desirable hardware requirements:
APP Server
– 12 GB RAM, 12 or more processor cores.
* 1 volume of 30GB for the OS
* 1 volume of 30GB for DB* CentOS operating system
* Preferably SSD disks
OLAP Server
– 12 GB RAM, 12 or more processor cores.
* 1 x 30GB volume for the OS
* 1 x 20GB volume for OLAP
* CentOS operating system
* SSD disks preferred
DW Server
– 12 GB RAM, 12 or more processor cores
* 1 x 30GB volume for the OS
* 1 x 100GB volume for DW
* CentOS operating system
* SSD disks preferred
Desirable hardware requirements for server Planning:
Server – 12GB RAM, 8 or more processor cores.
* 1 volume of 30GB for the OS
* 1 x 150GB volume for DB
* CentOS operating system
* Preferably SSD disks
Minimum hardware requirements for server Planning:
Server – 8GB RAM, 4 processor cores.
* 1 volume of 30GB for the OS
* 1 x 100GB volume for DB
* CentOS operating system
* SSD disks preferred
If the client does not meet these requirements, we are not responsible for performance and availability issues of the platform, nor will we be penalized civilly or criminally for any losses that arise from this, nor will we incur in moral or patrimonial damages.
Last modified: December 30, 2019