Bluebeam Security & Data Residency

Your project data stays in Europe.

Whether you work on your own machine or collaborate through the cloud, your project data is hosted in Europe, and protected to GDPR and equivalent local standards.

European by ownership

Bluebeam is part of the Nemetschek Group, a publicly listed company headquartered in Munich.

Your region, your contract

Customers contract with a Bluebeam entity in their region, and your local team handles support, billing and account questions.

GDPR COMPLIANT

  • DPA aligned with GDPR Article 28
  • Dedicated Data Protection Officer
  • European contracting entities

Where your data lives

Your project data lives in one of two places, and you choose which: on your
own machine, or in Bluebeam’s European cloud.

On your machine

Local by default

Bluebeam Revu is a desktop application that runs on your own computer.

  • What stays in your environment: All of your project data. Your PDFs, markups, tool sets and settings stay on your computer or your own network.
  • Who can access it: Only you, and the people you share files with through your own systems. Bluebeam has no access to your project data at any point.
  • What is transmitted: Only a licence check. When you sign in, Revu confirms your licence is valid with Bluebeam using your Bluebeam ID. That sends a small identity record, never your files or project content.

In the cloud

Hosted in Europe

Some Bluebeam capabilities are cloud-connected, and admins decide who can use each one.

  • Where it is hosted: Bluebeam-run cloud infrastructure on AWS, in European regions (Frankfurt, Stockholm or London) by default.
  • How it is protected: Encrypted on the way to the cloud and while stored there. Access is limited to authorised Bluebeam staff, and every access is logged.
  • How it is monitored: Continuously monitored, tested by independent penetration testers, and backed by a documented incident response plan.
  • What you control: Which cloud capabilities each user can access, through Org Admin Pro, and which European region your team uses.

Independently certified

Independent certifications covering the
cloud-hosted service.

ISO 27001

Annual external audit of our security controls

SOC 2 Type II

Independent audit of customer-data protection

Data Privacy Framework

EU-approved framework for cross-border data protection

Frequently asked questions

Is Bluebeam GDPR compliant?

Does Bluebeam support Single Sign-On and multi-factor authentication?

Where does my Bluebeam ID account data live?

How does Bluebeam protect against and respond to security threats?

How does Bluebeam handle requests for data from a government?

What if we cannot allow any internet connection at all?

Documentation & verification

Everything in one place, for procurement and security reviewers:

Documentation

Data Processing Agreement & sub-processor list

View Documentation

Audit reports

SOC 2 Type II & ISO 27001, under NDA

Request via your account team

Service status

Live availability & incident history

See Live Status

AI transparency

How AI features handle your content

Learn More

Questions about data residency or compliance?

Our privacy team is happy to help.