Products ▾
Apps
CloyaFilumbimover
Archicad add-ons
LocusCloyaBridge
About Contact Login
EN ▾
DE EN

Last updated: 21 September 2026

Only the German text is legally binding, in every country. Any other language version is a translation and serves only to aid understanding. Where it differs from the German text, the German text applies.

Filum Privacy

This page describes what the Filum app does with data. Filum archives project email out of Microsoft 365 mailboxes into storage the office chooses itself.

For bimover’s website, account, licensing and payment data, see the general Privacy Policy. That policy and this one fit together: it covers what happens around the app, this page covers the app.

1. Controller and contact

bimover GmbH, Hammer 19, 5000 Aarau, Switzerland Email: privacy@bimover.ch

For the mail inside an archive, the office running Filum is the controller, not bimover. See Section 2.


2. The mail does not reach bimover

Filum archives project email out of Microsoft 365 mailboxes into a folder on storage the office chooses itself, for example the office’s own NAS. The mail does not reach bimover. It travels from Microsoft into the app on your machine and from there onto your storage.

We operate no server in that path and we hold no copy. That also means we cannot read an archive, cannot change it and cannot switch it off. For the personal data inside an archive, the office running Filum is the controller.


3. What Filum reports to us

Filum sends us the following. When Filum is connected to your bimover account, the account’s sign-in goes along so that we know which office it belongs to. When it is not connected, the licence question, the report after a run and the request before converting still go out, only without the sign-in, and we turn them away. The requests go from your machine and carry what any request carries, including your IP address.

When setting up and before each run Filum asks whether there is a licence for each mailbox a project archives from. It checks as soon as the project is set up and then every time Filum shows the project’s page; nothing is taken up by that. Before a run begins, Filum asks once more and takes up the licences. If the sign-in cannot be renewed at that moment, the request is omitted and we receive nothing. Otherwise we receive one hash per mailbox instead of the address (SHA-256 over a fixed prefix and the address in lower case). If no licence is free for a mailbox, Filum does not archive it; we have still received its hash with the request.

After an archive run we receive, provided the sign-in could be renewed:

  • the same hash for each mailbox the run archived from
  • an identifier of the archive, the identifier of the run, and the time of the run
  • the checksum of the run record, how many messages the archive holds, and which run in order it was

Before converting an archive, when Filum converts mail it has already filed because “Store attachments only once” was switched on or off, Filum reloads your account’s licence record so that your office’s settings apply; if the sign-in cannot be renewed at that moment, this request is omitted too. When Filum is connected, the same request also goes out at start-up and before a run when the stored record needs renewing, and when you click “Check” in the settings. Apart from the sign-in it carries only the app’s identifier.

On the Mac Filum also asks for the state of your account while it is connected and the sign-in can be renewed: when connecting, when the sign-in is renewed, and from time to time before a run or when you click “Check”. This request carries the sign-in, your account’s identifier and the app’s identifier.

No addresses in clear text, no subject lines, no file names, no attachments and no messages. The sample project built into Filum reports nothing.

We treat a mailbox hash as personal data. It is pseudonymous, not anonymous: the same mailbox always produces the same hash, and anyone who already holds an address can compute it and compare. We do not hold the addresses behind these hashes and we do not try to resolve them. We use this information for three purposes: to say before a run which mailboxes have a licence, to count how many different mailboxes an office archived in a year, which is what the licence is measured against, and to notice later that an archive is reporting fewer runs or fewer messages than it once did.

Legal basis: performance of the licence contract for the question of free licences, reloading the licence record, the account status request and the mailbox count (Article 6(1)(b) GDPR), and our legitimate interest in correct billing and in the comparison with earlier reports (Article 6(1)(f) GDPR). For Swiss law, see Section 12 of the general Privacy Policy.


4. Sign in with Microsoft

When you sign in with Microsoft, we process the identity token Microsoft issues and take from it the identifier Microsoft gives your account and your email address, in order to find or create your bimover account. Where the token names your Microsoft organisation, we process that identifier as well. We do not process passwords. Authentication is performed by Microsoft.

Filum signs in with Microsoft only, because the same sign-in also reaches the mailboxes it archives; there is no second login.

In Filum the same sign-in also authorises the app to read the mailbox folders you name. Access is delegated: Filum acts as you and reaches only the mailboxes and folders you can reach yourself. We hold no company-wide permission over your mailboxes. Filum asks for access to your own mail and to mailboxes shared with you (Mail.ReadWrite and Mail.ReadWrite.Shared). Write access is part of that for one reason: on your request Filum moves a message into the folder you archive from. The app does not send messages and does not delete them. In the Microsoft admin centre the registration is listed as “Filum Mailarchiv”.

That mail travels between your device and Microsoft. It does not pass through us, and we never store it. The Microsoft tokens stay on the device.


5. The timestamp service

Every run record is timestamped by an independent service (RFC 3161), so that the time of a state can be attested by somebody other than the office that owns the disk. Filum sends that service a checksum of the record and nothing else.

The request goes from your machine and carries what any request carries, including your IP address. The default is SwissSign in Switzerland; a German service (DFN) can be chosen in the settings. We receive none of it.


6. Support: the diagnostic log

Filum keeps a rolling log of what it last tried, on your device: runs, failures, folder and file names, counts. It goes nowhere on its own. It reaches us only when you release it, and the app shows you the whole text before you do. A random, resettable installation identifier goes with it, so that several tickets from one installation can be put together.

Archive file names are built from the date, the sender and the subject. Before a log leaves your computer, Filum replaces every such name in it with a placeholder, attachment names included. A log never carries message bodies or attachments anyway. If a case is particularly sensitive, send the ticket without the log and we will ask for what we need.


7. Support: a session you release

Filum can also take instructions from the bimover support app when that app is installed on the same machine under the same user account. The two exchange files in a shared folder on your disk; there is no network connection and no open port for this.

The channel is shut until you switch it on, a release lasts one hour and then closes by itself, and an instruction older than two minutes is refused. While a release is open, a support agent can ask for the same things you can see: your projects and sign-in state, the diagnostic report, what a mail folder currently holds, and the result of checking an archive. The agent can also start an archiving run, which is the same run your own button starts.

Nothing can be done through this channel that a button in the app cannot do, and every instruction is recorded in the app.


8. The Outlook add-in

The add-in for Outlook is a button that opens the Filum app. It reads neither messages nor details of your mailbox from Outlook, and it passes no details from Outlook on to bimover. It asks Outlook for the lowest permission level.

For Outlook to show the add-in, it loads the add-in’s page from www.bimover.ch and the office.js program library from Microsoft. As with any page request, your IP address and the usual details of your browser go to these servers. Outlook usually adds details of the program, platform, version and language to the address. How we handle them is described in the general Privacy Policy; for Microsoft, Microsoft’s own privacy statement applies.

The button calls the address www.bimover.ch/filum/oeffnen. If Filum is installed, the operating system takes over the address and starts the app. Otherwise the browser shows a page with a link to the product page. The address carries no data.


9. Your rights

For the account, licensing and billing data around Filum, the rights set out in the general Privacy Policy apply, and requests go to privacy@bimover.ch.

For the mail inside an archive, we are not the controller and cannot act: the archive sits on the office’s own storage and we hold no copy. Requests about that mail go to the office running Filum.

Imprint Privacy Terms
© 2026 bimover

The original of this website is written in German. Other languages are translated from it automatically. Suggestions for better wording are welcome at support@bimover.ch.