
Trust & compliance
At Thinkproject we believe success for our customers comes from mutual trust, which is why we take your security and protecting your data seriously
Safeguarding data, building trust
Our Trust Centre will give you an oversight of how we protect your valuable information through rigorous security controls and compliance methods, ensuring your peace of mind and allowing you to focus on your projects.
As a SaaS company with decades of experience and knowledge, we understand the significance of protecting our customers’ data and prioritise the highest standards. We are committed to safeguarding, maintaining the utmost in confidentiality and adhering to the industry standard.
- GDPR compliance is a top priority at Thinkproject
- Thinkproject’s ISMS is regularly audited and up to date
- We pass the highest standards of certification with ISO 27001
- Thinkproject has implemented robust processes and measures to safeguard your data

Privacy as a priority
As a German-founded and EU-based company, standards like General Data Protection Regulation (GDPR) have the highest priority for Thinkproject.
With Thinkproject you can expect your data to be collected, processed and stored with privacy in mind.
We employ numerous measures to protect your data, including:
- Controlled access to physical and electronic data
- Data confidentiality, integrity and availability
- Established procedures to uphold data subjects’ rights
- Prompt and regular data erasure
- Continuous training for all employees on new data threats
Privacy as a priority
As a German-founded and EU-based company, standards like General Data Protection Regulation (GDPR) have the highest priority for Thinkproject.
With Thinkproject you can expect your data to be collected, processed and stored with privacy in mind.
We employ numerous measures to protect your data, including:
- Controlled access to physical and electronic data
- Data confidentiality, integrity and availability
- Established procedures to uphold data subjects’ rights
- Prompt and regular data erasure
- Continuous training for all employees on new data threats
Safeguarding your confidentiality, integrity & availability
With Thinkproject you can be assured we place top priority on the protection of your information security. We maintain and review our ISMS regularly to ensure a gold standard in compliance and remain up to date with industry best practices.
Our ISMS measures include:
- Regular internal and external auditing
- Training and testing for all employees
- Robust security measures
- Risk assessment and business continuity plans
- A comprehensive incident management strategy
- Controlled access
Thinkproject AI
As we continue to embed AI into our solutions, we are committed to doing so with clear governance, accountability and a focus on customer value, trusted AI-assisted workflows and innovation in complex, regulated environments.
Our Principles:
- Security at the forefront
- Data protection as a priority
- Governed, permission-aware experiences
- Visibility and oversight
- Human expertise stays in control
- Transparency you can act on
- Reliability through testing and continuous improvement
- Built for regulated environments
- Fairness, Non-Discrimination and Bias Control
800k
users
75k
projects
60
countries
Certified ISO 27001 in
Locations
Products
AI Trust Centre: FAQs
Thinkproject embeds AI capabilities into products and the platform to help teams find information faster, reduce repetitive work, prioritise what matters and support better decision-making across the built asset lifecycle.
For each AI capability we define what data is used and for what purpose. As a default position for our customers, the aim is that your project data is used to deliver the feature for your tenant, not to train models for other customers. Where any improvement or training use is offered, it will be clearly described and governed through contractual terms, under clear contractual governance and customer control.
AI features will respect the same permissions and governed access controls that apply across the Thinkproject pPlatform. If a user cannot access a document or dataset in the platform, the AI capability will not expose it in results.
We provide clear statements for each AI feature about where processing takes place and which sub processors are involved, including regional hosting commitments where offered. This is typically documented in the AI feature Trust Note and in the relevant contractual schedules.
Personal data may exist in file content and metadata depending on how a project or asset is managed. We support compliant data processing by applying access controls, security measures, and transparency on what each AI capability uses. The customer remains in control of what is stored in the platform and who can access it.
Thinkproject acts as a provider under the EU AI Act 2024 as has developed an AI system and functionality which is has put into service and offered for sale in the EU and other markets.
AI outputs are probabilistic and may be incomplete or wrong. We position AI based functionality in Thinkproject products as assistive and design features to support verification, for example by linking results back to source documents where possible, and by encouraging human review before decisions are made.
We test AI capabilities prior to release and monitor them after deployment. We also plan for regression testing and controlled change management when underlying models, providers and AI capabilities rapidly evolve, so performance remains reliable and changes are assessed before broad rollout.
AI features are covered by the same security management approach used across Thinkproject, including governance over suppliers and sub processors, access controls, and security monitoring. Thinkproject has an ISO/IEC 27001-certified ISMS, which provides a structured framework for information security management.
We can provide a packaged set of information to support due diligence, such as ISO 27001 certification information, an AI feature description, an AI data use statement and security and data protection summaries, with deeper materials available under NDA where appropriate.
Where improvement programmes are offered, we support clear choices. The contract should distinguish between using data to provide the feature to your organisation and using data to improve models beyond your tenant, with opt-in or opt-out mechanisms defined.
We align retention and deletion with contractual commitments and provide deletion upon termination in line with agreed terms, including defined windows for backups where applicable. For AI features, we aim to keep any derived artefacts and logs within defined retention policies that are documented for customers.
AI services are covered by our incident management process. Where an incident affects customer data or service availability, customers are notified in line with contractual and regulatory requirements and we provide appropriate remediation and reporting.
Effective AI depends on connected, governed and trustworthy data. In infrastructure environments information is often spread across systems, workflows and lifecycle stages. Thinkproject’s platform helps connect and structure that information so AI capabilities can provide more reliable, contextual, and actionable support.
Certifications
CONTRACTS
(CEMAR)
ISO 27001 (English & German)
Cyber Essentials Plus (English)
ISO 9001 (English) | ISO 22301 (English)
VDC MANAGER
(DESITE BIM)
ISO 27001 (English & German)
DOCUMENT & FIELD MANAGER
(KAIRNIAL)
ISO 27001 (English & German)
CDE ENTERPISE
(TP CDE)
ISO 27001 (English & German)
Thinkproject
(CLOUD)
ISO 27001 (English & German)
THINKPROJECT CDE
(CONCLUDE CDE)
ISO 27001 (English & German)
C5 Type 1 (English & German)
SOC 2 Type 1 (English & German)
CDE INFRASTRUCTURE
(EPLASS CDE)
ISO 27001 (English & German)
C5 Type 1 (English & German)
SOC 2 Type 1 (English & German)
ASSET & WORK MANAGER
(RAMM)
ISO 27001 (English & German)
COSTS
(TP CONTROL)
ISO 27001 (English & German)
C5 Type 1 (English & German)
SOC 2 Type 1 (English & German)
CONTRACTS
(CEMAR)
ISO 27001 (English & German)
Cyber Essentials Plus (English)
ISO 9001 (English) | ISO 22301 (English)
VDC MANAGER
(DESITE BIM)
ISO 27001 (English & German)
DOCUMENT & FIELD MANAGER
(KAIRNIAL)
ISO 27001 (English & German)
CDE ENTERPISE
(TP CDE)
ISO 27001 (English & German)
Thinkproject
(CLOUD)
ISO 27001 (English & German)
THINKPROJECT CDE
(CONCLUDE CDE)
ISO 27001 (English & German)
C5 Type 1 (English & German)
SOC 2 Type 1 (English & German)
CDE INFRASTRUCTURE
(EPLASS CDE)
ISO 27001 (English & German)
C5 Type 1 (English & German)
SOC 2 Type 1 (English & German)
ASSET & WORK MANAGER
(RAMM)
ISO 27001 (English & German)
COSTS
(TP CONTROL)
ISO 27001 (English & German)
C5 Type 1 (English & German)
SOC 2 Type 1 (English & German)



























