Main business data hosted in the EU
Main business data is stored with AWS in Ireland (eu-west-1) through Supabase. Optional processing outside the EU is detailed in the subprocessor register.
Security & compliance
Kopro protects managers' and landlords' data through primary hosting in the European Union, encryption in transit and at rest, and role-based access rules. Here is the current position, clearly explained.
GDPR
EU 2016/679
EU hosting
AWS Ireland
PCI-DSS
Certified Stripe provider
TLS / AES-256
In transit and at rest
Alur law
Co-owner extranet
Élan law
Remote voting
How Kopro is designed to protect personal information, bank account details and your residences' financial flows.
Main business data is stored with AWS in Ireland (eu-west-1) through Supabase. Optional processing outside the EU is detailed in the subprocessor register.
TLS 1.3 in transit and AES-256 at rest for the database and file storage. Backups use the same encryption.
Passwords hashed with bcrypt. Magic links for residents, with OAuth and two-factor authentication available for manager accounts. Revocable JWT sessions.
PostgreSQL Row-Level Security (RLS): access rules filter data by agency, residence and role, alongside application-level checks.
Verifiable backup exports that can be encrypted are produced. Frequency and restoration are documented without claiming point-in-time recovery that is not enabled.
Critical business events are logged with timestamps and identities where available. Log coverage is being expanded progressively.
Application errors collected with Sentry and a public health endpoint for the app and database. Checks that are not automated are identified as such.
Automated Vitest tests and build checks before release, complemented by targeted security and access-control reviews.
Features designed to support GDPR, Alur and Élan obligations. Stripe processes subscriptions and GoCardless processes optional SEPA Direct Debits after activation.
Kopro is a processor under the GDPR. You, the property manager or landlord, are the controller. These are the principles we apply and document.
Purpose, location and contractual safeguards documented in a single register.
Your business data is hosted in the European Union, in Ireland : Amazon Web Services infrastructure, region eu-west-1, operated through Supabase. Subscriptions use Stripe (Ireland), optional rent collection uses GoCardless (France), and transactional emails use Resend (Germany). Some optional subprocessors operate from the United States under standard contractual clauses: backup AI assistant providers and website advertising trackers if you have accepted them.
The full list, including each subprocessor's purpose, data processed, location and legal basis, is maintained on a dedicated page. Agency clients are notified of changes 30 days in advance.
View the subprocessor registerResponsible disclosure
We take security reports seriously. If you believe you have found a vulnerability, contact security@go-kopro.com (response within 48 hours). We do not currently offer a financial bug bounty, but can acknowledge you publicly on this page if you wish.
French regulation is not an add-on in Kopro: it is the product's skeleton.
Checks for the 21-day meeting notice period, works reserve tracking and accounting records: built into your workflow.
Encrypted data hosted in the European Union (AWS Ireland), with self-service account deletion.
Kopro subscriptions are paid through Stripe. Optional rent collection is processed by GoCardless after a SEPA mandate; bank details do not pass through our servers.
French condominium chart of accounts, OSCAR exports and one-click sale statements.