Trust & compliance

At Thinkproject we believe success for our customers comes from mutual trust, which is why we take your security and protecting your data seriously

Safeguarding data, building trust

Our Trust Centre will give you an oversight of how we protect your valuable information through rigorous security controls and compliance methods, ensuring your peace of mind and allowing you to focus on your projects.

As a SaaS company with decades of experience and knowledge, we understand the significance of protecting our customers’ data and prioritise the highest standards. We are committed to safeguarding, maintaining the utmost in confidentiality and adhering to the industry standard.

  • GDPR compliance is a top priority at Thinkproject
  • Thinkproject’s ISMS is regularly audited and up to date
  • We pass the highest standards of certification with ISO 27001
  • Thinkproject has implemented robust processes and measures to safeguard your data

  • Our CTO says
    “Information security is not just a necessity; it’s the backbone of our operations. At Thinkproject, we understand that our clients trust us with their most valuable asset—their data. Thinkproject is committed to upholding your trust. We invest in modern security technologies, clear strategy, and ongoing training to ensure the confidentiality, integrity, and availability of your data throughout our operations.”
    Ralf Hundhammer

Privacy as a priority

As a German-founded and EU-based company, standards like General Data Protection Regulation (GDPR) have the highest priority for Thinkproject.

With Thinkproject you can expect your data to be collected, processed and stored with privacy in mind.

We employ numerous measures to protect your data, including:

 

  • Controlled access to physical and electronic data
  • Data confidentiality, integrity and availability
  • Established procedures to uphold data subjects’ rights
  • Prompt and regular data erasure
  • Continuous training for all employees on new data threats

Privacy as a priority

As a German-founded and EU-based company, standards like General Data Protection Regulation (GDPR) have the highest priority for Thinkproject.

With Thinkproject you can expect your data to be collected, processed and stored with privacy in mind.

We employ numerous measures to protect your data, including:

 

  • Controlled access to physical and electronic data
  • Data confidentiality, integrity and availability
  • Established procedures to uphold data subjects’ rights
  • Prompt and regular data erasure
  • Continuous training for all employees on new data threats

Safeguarding your confidentiality, integrity & availability

With Thinkproject you can be assured we place top priority on the protection of your information security. We maintain and review our ISMS regularly to ensure a gold standard in compliance and remain up to date with industry best practices.

 

Our ISMS measures include:

 

  • Regular internal and external auditing
  • Training and testing for all employees
  • Robust security measures
  • Risk assessment and business continuity plans
  • A comprehensive incident management strategy
  • Controlled access

Thinkproject AI

As we continue to embed AI into our solutions, we are committed to doing so with clear governance, accountability and a focus on customer value, trusted AI-assisted workflows and innovation in complex, regulated environments.

 

Our Principles:

  • Security at the forefront
  • Data protection as a priority
  • Governed, permission-aware experiences
  • Visibility and oversight
  • Human expertise stays in control
  • Transparency you can act on
  • Reliability through testing and continuous improvement
  • Built for regulated environments
  • Fairness, Non-Discrimination and Bias Control

800k

users


75k

projects


60

countries


Certified ISO 27001 in

Locations

  • Austria
  • Germany
  • India
  • Netherlands
  • New Zealand
  • Spain
  • United Kingdom

Products

  • CONTRACTS (CEMAR)
  • THINKPROJECT CDE (CONCLUDE CDE)
  • VDC MANAGER (DESITE BIM)
  • CDE INFRASTRUCTURE (EPLASS CDE)
  • DOCUMENT & FIELD MANAGER (KAIRNIAL)
  • ASSET & WORK MANAGER (RAMM)
  • CDE ENTERPRISE (TP CDE)
  • Thinkproject (TP CLOUD)
  • COSTS (TP CONTROL)

AI Trust Centre: FAQs

Thinkproject embeds AI capabilities into products and the platform to help teams find information faster, reduce repetitive work, prioritise what matters and support better decision-making across the built asset lifecycle.

For each AI capability we define what data is used and for what purpose. As a default position for our customers, the aim is that your project data is used to deliver the feature for your tenant, not to train models for other customers. Where any improvement or training use is offered, it will be clearly described and governed through contractual terms, under clear contractual governance and customer control.

AI features will respect the same permissions and governed access controls that apply across the Thinkproject pPlatform. If a user cannot access a document or dataset in the platform, the AI capability will not expose it in results.

We provide clear statements for each AI feature about where processing takes place and which sub processors are involved, including regional hosting commitments where offered. This is typically documented in the AI feature Trust Note and in the relevant contractual schedules.

Personal data may exist in file content and metadata depending on how a project or asset is managed. We support compliant data processing by applying access controls, security measures, and transparency on what each AI capability uses. The customer remains in control of what is stored in the platform and who can access it.

Thinkproject acts as a provider under the EU AI Act 2024 as has developed an AI system and functionality which is has put into service and offered for sale in the EU and other markets.

AI outputs are probabilistic and may be incomplete or wrong. We position AI based functionality in Thinkproject products as assistive and design features to support verification, for example by linking results back to source documents where possible, and by encouraging human review before decisions are made.

We test AI capabilities prior to release and monitor them after deployment. We also plan for regression testing and controlled change management when underlying models, providers and AI capabilities rapidly evolve, so performance remains reliable and changes are assessed before broad rollout.

AI features are covered by the same security management approach used across Thinkproject, including governance over suppliers and sub processors, access controls, and security monitoring. Thinkproject has an ISO/IEC 27001-certified ISMS, which provides a structured framework for information security management.

We can provide a packaged set of information to support due diligence, such as ISO 27001 certification information, an AI feature description, an AI data use statement and security and data protection summaries, with deeper materials available under NDA where appropriate.

Where improvement programmes are offered, we support clear choices. The contract should distinguish between using data to provide the feature to your organisation and using data to improve models beyond your tenant, with opt-in or opt-out mechanisms defined.

We align retention and deletion with contractual commitments and provide deletion upon termination in line with agreed terms, including defined windows for backups where applicable. For AI features, we aim to keep any derived artefacts and logs within defined retention policies that are documented for customers.

AI services are covered by our incident management process. Where an incident affects customer data or service availability, customers are notified in line with contractual and regulatory requirements and we provide appropriate remediation and reporting.

Effective AI depends on connected, governed and trustworthy data. In infrastructure environments information is often spread across systems, workflows and lifecycle stages. Thinkproject’s platform helps connect and structure that information so AI capabilities can provide more reliable, contextual, and actionable support.

Certifications

CONTRACTS
(CEMAR)

ISO 27001 (English & German)

Cyber Essentials Plus (English)

ISO 9001 (English) | ISO 22301 (English)

 

VDC MANAGER
(DESITE BIM)

ISO 27001 (English & German)

 

DOCUMENT & FIELD MANAGER
(KAIRNIAL)

ISO 27001 (English & German)

 

CDE ENTERPISE
(TP CDE)

ISO 27001 (English & German)

 

Thinkproject
(CLOUD)

ISO 27001 (English & German)

THINKPROJECT CDE
(CONCLUDE CDE)

ISO 27001 (English & German)

C5 Type 1 (English & German)

SOC 2 Type 1 (English & German)

 

CDE INFRASTRUCTURE
(EPLASS CDE)

ISO 27001 (English & German)

C5 Type 1 (English & German)

SOC 2 Type 1 (English & German)

 

ASSET & WORK MANAGER
(RAMM)

ISO 27001 (English & German)

 

COSTS
(TP CONTROL)

ISO 27001 (English & German)

C5 Type 1 (English & German)

SOC 2 Type 1 (English & German)

CONTRACTS
(CEMAR)

ISO 27001 (English & German)

Cyber Essentials Plus (English)

ISO 9001 (English) | ISO 22301 (English)

 

VDC MANAGER
(DESITE BIM)

ISO 27001 (English & German)

 

DOCUMENT & FIELD MANAGER
(KAIRNIAL)

ISO 27001 (English & German)

 

CDE ENTERPISE
(TP CDE)

ISO 27001 (English & German)

 

Thinkproject
(CLOUD)

ISO 27001 (English & German)

THINKPROJECT CDE
(CONCLUDE CDE)

ISO 27001 (English & German)

C5 Type 1 (English & German)

SOC 2 Type 1 (English & German)

 

CDE INFRASTRUCTURE
(EPLASS CDE)

ISO 27001 (English & German)

C5 Type 1 (English & German)

SOC 2 Type 1 (English & German)

 

ASSET & WORK MANAGER
(RAMM)

ISO 27001 (English & German)

 

COSTS
(TP CONTROL)

ISO 27001 (English & German)

C5 Type 1 (English & German)

SOC 2 Type 1 (English & German)

Auckland

ISO 27001 (English & German)

 

Berlin

ISO 27001 (English & German)

 

Gloucester

ISO 27001 (English & German)

 

Lyon

ISO 27001 (English & German)

 

Madrid

ISO 27001 (English & German)

 

Munich

ISO 27001 (English & German)

Neumarkt am Wallersee

ISO 27001 (English & German)

 

Paris

ISO 27001 (English & German)

 

Pune

ISO 27001 (English & German)

 

Utrecht

ISO 27001 (English & German)

 

Wuppertal

ISO 27001 (English & German)

 

Würzburg

ISO 27001 (English & German)

Insights

Ready to see Thinkproject in action?

Let us show you a platform overview, or deep dive into your needs in a specific area. Our 30-minute live demo can be tailored to your bespoke needs. Get in touch today, we‘re here to answer your questions! 

Want an initial discussion with our experts? Click to book some time.