Data & security

Privacy policy

Information on the collection, processing and protection of data within our SaaS solution.

1. Nature of the data processed

Two types of data are processed when using the Coperis platform:

Account creation data (Data Controller): Professional user information (name, email, role, organisation) required to manage the subscription and billing.

Business data (Data Processor): Financial and operational data and information relating to beneficiaries/members that the client (the organisation) hosts and manages on the platform. The client remains the sole owner of, and responsible for, this data.

2. Purposes and legal basis

Data is processed to deliver the subscribed SaaS service (performance of the contract), provide technical support, maintain the security of the infrastructure (legitimate interest), and comply with legal obligations. Coperis undertakes not to use its clients' business data for commercial or advertising purposes.

3. Security and hosting

Security is at the heart of our SaaS model. We apply end-to-end encryption (TLS) and encryption at rest (AES-256). Data is stored on ISO 27001-certified cloud servers with daily backup policies and a disaster recovery plan.

4. Sub-processing (sub-processors)

To deliver the SaaS service, Coperis uses technical sub-processors (hosting, transactional email delivery). These partners are rigorously selected for their compliance with data protection regulations (GDPR or equivalent).

5. User rights

In accordance with applicable regulation (GDPR, CDP), you have the right to access, rectify, erase and port your data. The client administrator of the SaaS workspace can exercise most of these rights directly from the application. For any specific request: [email protected]