Imprint

Note on this translation:
This English version is a translation of the German-language original of this Legal Notice and Privacy Policy. In the event of any discrepancy or inconsistency between this English translation and the German original, the German version shall prevail and is legally binding.

Legal Notice, Disclaimer & Privacy Policy

XEOMETRIC GmbH
Hamoderstr. 4
A-4020 Linz
Tel: +43 732 34 15 74
E-Mail: office@xeometric.com

CEO: DI Dr. Wolfgang Stöger
Company register and court: FN 213077z at Landesgericht Linz
VAT number: ATU 52380800

Business purpose: Software development and sales, IT-services
Legal regulation: Gewerbeverordnung (www.ris.bka.gv.at)
Produced by: XEOMETRIC GmbH

Editorial policy: Information about following topics: IT, CAD, Architecture, Mechanics and all similar or related topics, sales and training courses.
Terms and conditions
Our disclaimer applies to the following domains:
elitecad.eu | elitecad.net | elitecad.de | elitecad.at | elitecad.co.uk | elitecad.fr | elitecad.be | elitecad.asia | elitecad.africa | bim2cost.at | bim2cost.de | elitecad-me.com | elitecadme.com | xeometric.at | xeometric.de | xeometric.eu | xeometric.com

The below is responsible for the websites:
XEOMETRIC GmbH
Hamoderstr. 4
A-4020 Linz
Tel: +43 732 34 15 74
E-Mail: office@xeometric.com


Disclaimer of XEOMETRIC GmbH
also referred to as "provider" or "the provider":

Security notices and reporting of vulnerabilities in accordance with the EU Cyber Resilience Act (CRA)

Coordinated Vulnerability Disclosure (CVD) Policy
1. Purpose
XEOMETRIC GmbH (“XEOMETRIC”) values the security of its products. This policy explains how you can report suspected vulnerabilities and how we handle them. The goal is coordinated disclosure that protects users before details become public.

2. Scope
This policy applies to XEOMETRIC products with digital elements (in particular ELITECAD and related modules) as well as the websites operated by XEOMETRIC and its internet licence server. Third-party products that XEOMETRIC merely resells are not covered; please report vulnerabilities in those to the respective original manufacturer.

3. How to report
Please report vulnerabilities by e-mail to security@xeometric.com. Do not include sensitive personal data of third parties.

4. What to include
Please provide where possible:
  • the affected product and version,
  • a description of the vulnerability and its potential impact,
  • steps to reproduce or a proof of concept,
  • a means of contact for follow-up (pseudonymous if you prefer).

5. Assurances to reporters
XEOMETRIC will not regard a report made in good faith and in accordance with this policy as an unlawful act, and will not initiate or recommend legal action against persons who comply with the rules below.

Provided that, during your research, you:
  • only access systems and data you are authorised to, and limit access to what is strictly necessary for the proof,
  • do not access, store, share or publish third parties’ personal data,
  • do not disrupt operations (no denial-of-service, no data manipulation or deletion),
  • do not exploit the vulnerability beyond what is needed to demonstrate it,
  • do not disclose details without prior coordination with XEOMETRIC (see section 8),
  • comply with applicable law.

This assurance concerns XEOMETRIC only and cannot waive third-party rights or mandatory law.

6. Out of scope
The following are out of scope, in particular:
  • social-engineering attacks (e.g. phishing),
  • denial-of-service / load testing,
  • attacks on third-party infrastructure,
  • purely theoretical vulnerabilities without credible proof.

7. Process and timelines
If you give us a means of contact, we acknowledge receipt within three (3) business days and provide an initial assessment within ten (10) business days. We then keep you informed about remediation progress.

Security-critical issues are prioritised, and security updates are provided within our support period. We also review anonymous reports that have no means of contact, but cannot respond to them.

8. Coordinated disclosure
We coordinate the timing of any publication with you. As a guideline, we disclose after a fix is available, and no later than ninety (90) days after receipt of the report.

The reporter is not publicly credited; no reward is granted for reports.

9. Handling of personal data
We process personal data from your report only to handle the report and the coordinated disclosure, in accordance with the GDPR; details are set out in our privacy notice.

Reporting security incidents or vulnerabilities related to XEOMETRIC products

You can submit a report either by email to security@xeometric.com or by using the form below: