Kopexa GmbH ("Kopexa") understands that privacy matters to you and is committed to protecting your personal data. This Privacy Policy explains how we collect, use and share information when you use our website, services or other Kopexa content. By accessing the Kopexa website or using our services, you agree to the practices described in this Privacy Policy.
What does this Privacy Policy cover?
This Privacy Policy applies to the collection and processing of personal data when you use the Kopexa website or our services. It does not apply to companies we do not own or control, or to individuals we do not manage.
Kopexa acts as a data processor for its customers, who act as data controllers. We process personal data only in accordance with our customers' instructions and implement technical and organizational measures to ensure compliance with the General Data Protection Regulation (GDPR).
Privacy rights for California residents
Under the California Consumer Privacy Act (CCPA), California residents may request information about the categories of personal data shared with third parties for marketing purposes. To exercise your rights, contact us at [email protected].
Cooperation with data protection authorities
Kopexa works with the European Union Data Protection Authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) to resolve unresolved complaints related to the transfer of data from the EU and Switzerland.
Collection of personal data
Kopexa may collect the following personal data:
- When registering for Kopexa services: name, email address and IP address.
- When visiting our website: IP address, browser type and interaction logs.
- When using Kopexa services: login data, account activity and customer-submitted content.
We may also receive personal data from third parties, including our customers, service providers and publicly available sources.
Use of personal data
We process personal data for the following purposes:
- Providing, maintaining and improving our services.
- Authenticating and managing user accounts.
- Ensuring security and protection against fraud.
- Sending relevant product updates and marketing communications, subject to user preferences.
Marketing communications
By providing us with your email address, you agree to receive marketing communications about the use of the website, Kopexa services and our products. You can unsubscribe from marketing communications at any time via the unsubscribe link in our emails or by contacting us directly.
Download offers and email series
On our website you can request templates and checklists, for example the GRC requirements catalogue.
Purpose. We use your details to provide the download you requested and to then send you a series of five emails over 14 days with guidance on selecting GRC software and on the offerings of Kopexa GmbH. After this series you will receive no further emails unless you consent again.
Data processed. First name, last name, company, email address, your role in the company, the company size and the decision period you stated, and voluntarily your phone number. As evidence of your consent we also store the time, IP address and browser identification (user agent) of the signup and of the confirmation.
Double opt-in. After you submit the form you receive an email with a confirmation link. Your signup is complete only once you click that link. Only then do we send you the download link and the email series. Without confirmation your signup stays inactive, no further emails are sent to you, and we delete the signup after 30 days.
Legal basis. Your consent under Art. 6(1)(a) GDPR. We store the evidence of your consent to meet our accountability obligation on the basis of Art. 6(1)(c) GDPR.
Recipients. For sending the emails and managing your consent we use CleverReach GmbH & Co. KG, Rastede, Germany, as a processor. After your confirmation we also transfer your details into our self-hosted CRM system Twenty in order to handle your enquiry in sales. No other services receive your data.
Retention. We store your details until you withdraw your consent. If you do not withdraw it, we delete them at the latest 24 months after our last contact with you. Separately from this, we keep the evidence of your consent until three years have passed after the end of the year in which you gave or withdrew your consent. It serves solely to demonstrate that consent.
Withdrawal. You can withdraw your consent at any time, with one click via the unsubscribe link in every email or by message to [email protected]. This does not affect the lawfulness of the processing carried out up to the withdrawal.
Sharing of personal data
Kopexa does not sell personal data. However, we share data with:
- Service providers (sub-processors) that support necessary business processes.
- Business partners where required for the provision of services.
- Authorities where we are legally required to do so.
- Meta Platforms Ireland Ltd. (with onward transfer to Meta Platforms Inc., USA) for measuring and optimizing the performance of our advertising. You can find the legal bases (consent for the browser pixel, legitimate interest for the server-side Conversions API) and further details in the "Cookies and tracking technologies" section.
- CleverReach GmbH & Co. KG, Rastede, for sending requested downloads and the associated email series. Details are in the "Download offers and email series" section.
A list of our sub-processors is available upon request.
Data transfers and security measures
Personal data may be processed outside the European Economic Area (EEA). In such cases, we ensure adequate protection through the following measures:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Participation in the EU-U.S. Data Privacy Framework (DPF) for applicable data transfers.
All data is encrypted during transfer and storage. We use AES-256 encryption for stored data and TLS 1.2+ for secure transfers. Our infrastructure includes firewall protection, intrusion detection systems and access controls.
Cookies and tracking technologies
Kopexa uses the following categories of cookies and tracking technologies on our website, aligned with our cookie consent banner (c15t):
- Necessary: Technically required for the website to function (for example, storing your cookie preferences). No consent required.
- Analytics/Measurement: Only active with your consent. Used to analyze website usage and detect errors.
- Marketing: Only active with your consent. Used to measure and optimize the performance of our advertising.
Specifically, we use the following services:
-
Matomo (web analytics): Self-hosted at stats.kopexa.com. Matomo runs server-side via the HTTP Tracking API, sets no cookies and does not load client-side JavaScript in the browser. Visits are recognized via a pseudonymous visitor ID derived from the IP address and user agent. Purpose: reach and usage statistics. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Because Matomo runs exclusively on our own infrastructure in the EU, no data is transferred to third countries. Consent is not required for Matomo.
-
PostHog (product analytics and error tracking): Provided by PostHog Inc. (USA), but processed in the EU data region (eu.posthog.com). Purpose: usage analysis, error/exception tracking and conversion measurement. Legal basis: your consent (Art. 6(1)(a) GDPR) via the "Analytics/Measurement" category. Without consent, PostHog runs cookieless and anonymized; with consent, PostHog sets cookies and local storage entries (including ones prefixed "ph_"). Because the provider is based in the USA, transfers rely on Standard Contractual Clauses (SCCs).
-
Meta Pixel and Meta Conversions API (Facebook/Instagram advertising): Recipient is Meta Platforms Ireland Ltd., with onward transfer to Meta Platforms Inc., USA. Purpose: measuring the performance of our advertising and optimizing reach and retargeting. We use two separate mechanisms for this:
The Meta Pixel in the browser only loads after you have given consent to the "Marketing" category (Art. 6(1)(a) GDPR) and sets the "_fbp" cookie.
The Conversions API processes data server-side and without a cookie: if you arrive at our website via a Meta ad, we transmit event data (page views and conversion events), your IP address, your user agent, and the click ID (fbclid) to Meta. For contact or demo requests, we additionally transmit your email address and phone number in hashed form (SHA-256). We base this server-side processing on our legitimate interest in measuring and optimizing our advertising (Art. 6(1)(f) GDPR). You can object to this processing at any time, with effect for the future; to do so, contact us at [email protected].
Because the recipient is based in the USA, transfers rely on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses.
You can withdraw your consent to the "Analytics/Measurement" and "Marketing" categories at any time, with effect for the future, via the cookie settings in the website footer. For more information, see our Cookie Policy.
OpenAI Ads: advertising measurement
With your consent to the “Marketing” category, we use the OpenAI Ads Pixel and OpenAI Conversions API to measure the effectiveness of our advertisements in ChatGPT. The browser pixel is loaded only after this consent. Following successful delivery of a contact request, we also send a server-side conversion event. Browser and server use the same event ID to avoid double counting. The technical event name is appointment_scheduled; in this integration it indicates a submitted contact request and does not confirm a booked appointment.
The data processed includes event type, event ID, time and page address. Our server removes query parameters and URL fragments from that address. If available, the advertisement click identifier oppref and pseudonymous browser identifier obref are also transmitted. Our server integration does not transmit names, email addresses, telephone numbers or message contents to OpenAI. Loading the browser SDK involves connection data such as IP address and browser information. OpenAI's processing is additionally governed by its privacy notices and the advertising account settings.
The pixel may use the first-party cookies __oppref (up to 30 days) and __obref (up to 365 days). The legal bases are your consent under Art. 6(1)(a) GDPR and, for storage access, Section 25(1) TDDDG. Contact requests remain available without marketing consent. You may withdraw consent at any time through cookie settings with effect for the future; this integration then sends no further events.
OpenAI Ireland Limited is the recipient for processing EEA data. Under the Conversion Terms, Kopexa and OpenAI generally act as independent controllers. Where OpenAI processes data outside the EEA, the transfer mechanisms provided by its Ad Tools Data Processing Addendum apply. The cookie lifetimes above do not specify retention of event data already transmitted to OpenAI; the provider's purposes and retention rules apply to that data.
Further information: OpenAI Privacy Policy, Conversion Terms and Ad Tools Data Processing Addendum.
Retention of personal data
Personal data is retained only as long as necessary for the purposes described in this Privacy Policy. Retention periods are determined by:
- Legal requirements and compliance obligations.
- The duration of the customer relationship.
- Technical and operational considerations.
Data that is no longer needed is securely deleted in accordance with industry-standard security practices.
Rights to restrict the processing of personal data
If Kopexa processes your personal data on behalf of a customer, you should first contact that customer.
However, you may withdraw your consent to the processing of your data at any time by emailing [email protected]. Upon receipt of your request, Kopexa will delete your data unless there are legal or billing-related reasons for retention.
If your data is incorrect, you may request a correction at [email protected].
Right to information about data protection measures for international data transfers
Kopexa ensures that adequate data protection measures are in place for the transfer of personal data outside the EEA. For countries without an adequacy decision by the European Commission, Kopexa relies on contractual safeguards in accordance with the GDPR.
Reporting data breaches
In the event of a data breach, Kopexa will:
- Analyze the incident and assess its scope.
- Notify affected individuals and relevant authorities without undue delay.
- Implement corrective measures to prevent future incidents.
Questions or concerns about the Privacy Policy
If you have questions or concerns about our privacy practices, you can contact us at [email protected]. We will process your request as quickly as possible.
Changes to this Privacy Policy
Kopexa continuously improves its website and services. Therefore, this Privacy Policy may be updated from time to time.
Changes will be communicated through an updated version on our website, an email notification or other appropriate communication channels. Continued use of our services after updates constitutes acceptance of the revised policy.
Contact
For privacy inquiries or data requests, contact us at:
Kopexa GmbH
Data Privacy Office
Schauenburgerstraße 116
24118 Kiel
Email: [email protected]