1. Who is responsible for what
Two roles live side by side in Coprio, and the distinction governs everything else. For the data in their portfolio — co-owners, lots, shares, invoices, payments — it is the syndic who decides what is collected and why: they are the data controller. Coprio hosts and processes that data on their behalf and on their instructions: we are the processor.
For the data of our own customer — the syndic’s account, their subscription, Coprio’s own billing, the service’s technical logs — Coprio is the data controller.
In practice: if you are a co-owner and you want your name or your share corrected, speak to your syndic first. They hold the mandate, and we do not change a portfolio’s data without their instruction.
2. The data we process
It arrives in three ways: you enter it, your syndic enters it, or the service produces it by running.
- Account and identity: name, e-mail address, phone number, role in the organisation, preferred language. A password is never kept in the clear — only its bcrypt hash is, and that hash cannot be turned back into the password.
- Portfolio: residences, buildings and lots, owners and their shares, and the history of transfers.
- Financial: charge calls, invoices and their lines, payments and allocations, receipts, reminders, expenses, budgets and balances.
- Documents and supporting files: assembly minutes, contracts, by-laws, expense receipts, issue photographs.
- Communication: published announcements, notifications, and per-recipient delivery and read status.
- Technical: access and error logs, IP address, device type, mobile notification tokens, and the audit log of financial and privileged actions.
3. Why we process it
Every processing operation has a purpose and a lawful basis under Law 09-08.
No data is sold, rented or handed to a third party for advertising. Coprio runs no targeted advertising, and the business model — a subscription priced per lot — is precisely what makes that promise affordable to keep.
- Performing the contract: keeping the co-ownership’s accounts, issuing charge calls, recording payments, producing receipts and statements, and keeping co-owners informed.
- Legal obligation: retaining financial records and the audit log for the periods set out below.
- Legitimate interest: securing the service, preventing fraud and abuse, measuring usage to size the subscription, and fixing and improving the product.
- Consent: mobile push notifications, which you can withdraw at any time from your device settings.
4. Who can reach it
Access is not a matter of trust but of mechanism: it is enforced on the server, and whatever the interface does not show, the API refuses as well.
- Inside your organisation, access follows the role: a co-owner sees only their own account, their own documents and the announcements addressed to them; the syndic’s team sees what its role allows.
- Isolation between organisations is enforced by the database itself, and checked by a dedicated test suite on every release. One syndic cannot see another’s data, whatever the request.
- Coprio staff reach a customer’s data read-only, for support or a technical investigation, and every such access is logged.
5. Hosting and sub-processors
Coprio relies on a small number of providers, each for one defined function.
- Application and database hosting: Hetzner Online GmbH, in the European Union.
- File storage: S3-compatible object storage, in the European Union. Object keys are unguessable, and every download goes through a signed link valid for fifteen minutes at most.
- E-mail delivery: a contracted SMTP relay, for charge notices, receipts, announcements and account messages.
- Mobile notifications: Expo’s notification service, which relays to Apple and Google.
- Technical monitoring: operational logs and metrics, kept on the same infrastructure.
6. Transfers outside Morocco
The servers are located in the European Union. A transfer of personal data outside Morocco is governed by Law 09-08 and declared to the CNDP.
Hosting inside Morocco is tracked as an Enterprise requirement. Until it is available, this page says exactly where the data is rather than staying vague about it.
7. How long we keep it
Nothing is kept "by default": each category has a period, and each period has a reason.
- Financial records — invoices, receipts, payments, expenses: ten years, in line with Moroccan commercial practice. A voided document is kept and never erased: the void is written after it, it does not rewrite the past.
- Audit log of financial and privileged actions: five years, append-only.
- Cancelled account: ninety days of retention, during which the full export stays available, then an anonymising purge.
- Mobile notification tokens: deleted on sign-out, and as soon as the device stops being reachable.
- Technical logs: kept as long as operations and security require, then deleted.
8. Your rights
Law 09-08 gives you a right of access, of rectification and of objection over your personal data, and a right to erasure within the limits of our retention obligations.
Write to us and we answer. If the request concerns a co-ownership’s data, we pass it to the syndic responsible for it. You may also refer the matter to the CNDP, Morocco’s personal-data protection authority.
- Access and portability: every module exports to Excel, and all your documents to a single archive. The export stays available after a subscription ends — freedom from lock-in is a Law 09-08 requirement before it is a selling point.
- Rectification: from the application for your own account; through your syndic for your co-ownership’s data.
- Erasure: we delete or anonymise whatever the law does not oblige us to keep. An issued invoice cannot be erased — it is an accounting record, and it can be relied on against us.
- Objection: you can switch off non-essential notifications. Charge notices and your syndic’s urgent messages are not marketing and cannot be switched off.
9. Security
No system is infallible. If a breach occurs that is likely to harm you, we inform the customers concerned and the authority without undue delay.
- Encryption in transit on every connection.
- Passwords stored as a high-cost bcrypt hash — never in the clear, never recoverable, including by us.
- Sessions on short-lived signed tokens, with refresh-token rotation and revocation of the whole family the moment an already-spent token is presented a second time.
- Organisation isolation enforced by the database, on top of the application-level check.
- Files reachable only through a short-lived signed link; uploads are checked for type and size, and no uploaded content is ever executed by our servers.
- Append-only audit log on every financial and privileged action.
11. Changes
This page changes when the product changes. The date at the top is the last revision. A change that affects your rights or the use of your data is announced in the application before it takes effect.
12. Contact us
For a question about this page, to exercise your rights, or to report a security problem, there is one address:
13. Publisher
Coprio is a product of the Bloomartcreations brand.
- Brand
- Bloomartcreations
- Publication manager
- Nabil Hajji
- Status
- Auto-entrepreneur registered in Morocco
- National auto-entrepreneur register number
- 002090733000038
- Tax identifier (IF)
- 25267572
- Professional tax number
- 57106212
- Hosting
- Hetzner Online GmbH — servers located in the European Union.
- Contact
- contact@coprio.io