Legal document
Privacy Policy
Last updated: 9 September 2026
Kopro SAS (hereinafter “Kopro” or “we”) places fundamental importance on protecting your personal data. This policy describes what data we collect, why, how we use it and your rights, in accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and the amended French Data Protection Act (Loi Informatique et Libertés).
01.Data controller
Company: Kopro SAS
SIREN: 102 335 023
Address: 47 rue Vivienne, 75002 Paris, France
Email: contact@go-kopro.com
02.Data collected and purposes
Account creation and management
Surname, first name, email address, telephone number and role (co-ownership manager, property manager, resident or landlord). Purpose: authentication, platform access and notifications.
Building and co-ownership management
Information about units, co-ownership shares, leases, property inspections and co-ownership documents. Purpose: providing business features (general meetings, accounting and incidents).
Payments
Stripe processes Kopro subscriptions. When a professional activates rent collection, GoCardless SAS processes the SEPA mandate and related payments. Kopro does not store bank details entered with either provider; it retains only the identifiers, amounts, due dates and statuses needed for tracking.
Browsing data (analytics cookies)
IP address (anonymised), pages viewed and session duration. Purpose: improving the user experience and producing aggregate usage statistics.
Communications
Content of messages exchanged through the built-in messaging service and transactional emails (rent receipts, general meeting notices and reminders). Purpose: performing the service.
03.Legal basis for processing
Performance of a contract (GDPR Article 6(1)(b)): processing necessary to provide the subscribed service.
Legal obligation (GDPR Article 6(1)(c)): retention of certain accounting and contractual data required by French law.
Legitimate interests (GDPR Article 6(1)(f)): improving the service, securing the platform and preventing fraud.
Consent (GDPR Article 6(1)(a)): non-essential cookies and marketing communications (with explicit opt-in).
04.Retention periods
Active account data: the subscription period plus 30 days after cancellation (withdrawal period).
Accounting data and supporting documents: 10 years (legal obligation under Article L. 123-22 of the French Commercial Code).
Connection logs: 12 months (requirement under the French LCEN law).
Analytics and advertising cookies: a maximum of 13 months (CNIL recommendation). Your consent is requested again after this period.
05.Sub-processors and transfers outside the EU
Where your data is stored. The database, files and user accounts are hosted in the European Union, in Ireland, on Supabase infrastructure running on AWS in the eu-west-1 region. The www.go-kopro.com website and web application are distributed by Vercel. Kopro makes no claim of hosting in France or sovereign hosting.
Kopro uses sub-processors whose contractual safeguards are documented in their applicable terms. The complete, up-to-date list is published on the sub-processors and recipients page, which specifies each provider’s purpose, the data processed, its location and the legal basis for processing. Any changes are announced to agency customers by email 30 days in advance.
A minority of the sub-processors in the register process data from the United States (the AI assistant’s fallback providers) or may transfer data there (advertising trackers, and only if you have accepted them). These transfers are governed by the European Commission’s Standard Contractual Clauses (GDPR Article 46(2)) and, where the sub-processor is certified, the Data Privacy Framework. No transfer outside the EU takes place for the operational storage of your data.
Details of the Stripe Payments Europe sub-processor. Stripe processes payments for the Kopro subscription. Collecting payments on behalf of other users (resident-to-resident marketplace and paid common-space bookings) is not currently activated. The data below describes the planned scope of a potential future service; its processing, responsibilities and conditions must be validated and communicated before activation.
- Address: 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (Central Bank of Ireland authorisation C181278).
- Data processed: identity (surname, first name, date of birth and address), bank details (IBAN), identity documents for marketplace sellers (collected and stored by Stripe without passing through Kopro), and transaction history.
- Retention period: 10 years (French accounting and tax obligations).
- Location: European Union (Ireland). Transfers to the United States are possible under the Data Privacy Framework (DPF); see stripe.com/legal/privacy-shield.
- Privacy Policy: stripe.com/privacy.
Details of GoCardless SAS. The service is optional and only processes data after activation by the professional and approval of a SEPA mandate by the payer. Bank details are entered on GoCardless’s secure page and do not pass through Kopro.
- Address: 7 rue de Madrid, 75008 Paris, France (GoCardless SAS, authorised by the ACPR, bank code 17118).
- Data processed: payer identity and contact details, IBAN, SEPA mandate, amount, due date, reference and payment status.
- Purpose: set up the mandate, submit Direct Debits, pay out the professional and process failures or disputes.
- Payer privacy notice: gocardless.com/fr-fr/privacy/payeurs/.
06.Your rights
Under the GDPR, you have the following rights over your personal data:
Right of access (Article 15): obtain a copy of your data.
Right to rectification (Article 16): correct inaccurate data.
Right to erasure (Article 17): request deletion of your data, subject to legal retention requirements.
Right to data portability (Article 20): receive your data in a structured, machine-readable format.
Right to object (Article 21): object to processing based on legitimate interests.
Right to restriction of processing (Article 18): temporarily suspend processing.
To exercise these rights, contact us at contact@go-kopro.com. We will respond within a maximum of 30 days.
You also have the right to lodge a complaint with the CNIL (the French data protection authority, Commission nationale de l’informatique et des libertés): www.cnil.fr.
07.Data security
Kopro implements appropriate technical and organisational measures to protect your data against unauthorised access, loss or destruction: TLS encryption in transit, encryption at rest (AES-256), role-based access control (RLS), access logging and regular security audits.
08.Cookie Policy
The go-kopro.com website uses the following cookie categories:
Strictly necessary cookies: authentication sessions and language preferences. No consent is required.
Audience measurement: understanding which pages are viewed and detecting errors and slowdowns. Recipients: Sentry (application errors, EU), Honeycomb via OpenTelemetry (performance), and our own page counter. These cookies are set only with your consent.
Advertising and campaign measurement: identifying which adverts lead to registrations and limiting repeated displays of the same advert. Recipients: Meta Platforms Ireland (Facebook and Instagram) and Google Ireland (Google Ads), which set their own trackers. None of these trackers is loaded before you explicitly accept this category, which is separate from audience measurement.
These three categories correspond exactly to those in the consent banner displayed on your first visit. You can change your choice at any time using the Manage my cookies link at the bottom of each page, or through your browser settings. Withdrawing consent stops future collection.
09.Data Protection Officer (DPO)
Under GDPR Article 37, Kopro is not currently required to appoint a Data Protection Officer (DPO). However, for any questions about the processing of your personal data, to exercise your rights or to report a privacy incident, you can write to:
dpo@go-kopro.com
Response within 30 days under GDPR Article 12(3).
You can also lodge a complaint with the CNIL at www.cnil.fr/fr/plaintes.
10.Changes
Kopro reserves the right to change this policy at any time. In the event of a substantial change, you will be informed by email at least 15 days before it takes effect. The date of the last update is shown at the top of this page.