Copilote IA Business
🇪🇺 GDPR Compliance

GDPR & Data Protection

Your rights under the General Data Protection Regulation

At Copilote IA Business, we are committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR)and other applicable data protection laws.

This page provides detailed information about how we comply with GDPR requirements and how you can exercise your data protection rights.

1. Data Controller Information

Data Controller: Copilote IA Business

Location: Lausanne, Switzerland

Contact Email: contact.copilote.ai.business@gmail.com

Data Protection Officer (DPO): Loïc Gugelmann

2. Your GDPR Rights

Under the GDPR, if you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

🔍 Right to Access

You have the right to request a copy of all personal data we hold about you. We will provide this information in a structured, commonly used format within 30 days of your request.

How to exercise: Email us at contact.copilote.ai.business@gmail.com with the subject "Data Access Request"

✏️ Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it.

How to exercise: Update your profile in your account settings, or contact us to request corrections

🗑️ Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

How to exercise: Delete your account from your account settings, or email us with a deletion request

⏸️ Right to Restriction of Processing

You can request that we restrict processing of your personal data in specific situations, such as while we verify the accuracy of disputed data.

How to exercise: Email us with details of why you want processing restricted

📦 Right to Data Portability

You have the right to receive your personal data in a structured, machine-readable format and transmit it to another service provider.

How to exercise: Request a data export from your account settings or contact us

🚫 Right to Object

You have the right to object to our processing of your personal data for direct marketing or where processing is based on legitimate interests.

How to exercise: Opt out of marketing emails using the unsubscribe link, or contact us

🤝 Right to Withdraw Consent

Where we process your data based on your consent, you have the right to withdraw that consent at any time.

How to exercise: Adjust your privacy settings in your account, or contact us

⚖️ Right to Lodge a Complaint

If you believe we have not handled your data properly, you have the right to file a complaint with your local data protection authority.

Swiss DPA: Federal Data Protection and Information Commissioner (FDPIC)

3. Legal Basis for Processing

We process your personal data under the following legal bases:

Contractual Necessity
To provide our Services as per our agreement with you (e.g., account management, service delivery)
Legitimate Interests
To improve our Services, prevent fraud, and ensure security
Consent
For marketing communications and non-essential cookies
Legal Obligation
To comply with applicable laws and regulations

4. Data We Collect and Process

We collect and process the following categories of personal data:

  • Identity Data: Name, email address, username
  • Contact Data: Email address, communication preferences
  • Financial Data: Payment information (processed securely by Stripe)
  • Technical Data: IP address, browser type, device information, usage data
  • Profile Data: Business information, preferences, settings
  • Usage Data: How you interact with our Services
  • AI Interaction Data: Inputs you provide to our AI features and generated outputs
  • Marketing Data: Your preferences for receiving marketing communications

5. How We Use Your Data

We use your personal data for the following purposes:

  • To provide and deliver our Services
  • To manage your account and subscriptions
  • To process payments and prevent fraud
  • To communicate with you about your account and our Services
  • To improve and personalize our Services
  • To send you marketing communications (with your consent)
  • To comply with legal obligations
  • To protect the security and integrity of our Services

6. Data Sharing and Third Parties

We do not sell your personal data. We share your data only with trusted service providers necessary to operate our Services:

🤖 OpenAI

Purpose: AI-powered content generation

Data shared: Your prompts and AI interaction data

Location: United States

💳 Stripe

Purpose: Payment processing

Data shared: Payment information, billing details

Location: United States

📊 MongoDB Atlas

Purpose: Database storage

Data shared: All application data

Location: Configurable (EU available)

☁️ Vercel & Railway

Purpose: Hosting and infrastructure

Data shared: Application data, logs

Location: Multiple regions

All our data processors are contractually bound to protect your data and use it only for the purposes we specify. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses).

7. Data Retention

We retain your personal data for as long as necessary to:

  • Provide our Services to you
  • Comply with legal, accounting, or regulatory requirements
  • Resolve disputes and enforce our agreements

When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are legally required to retain certain information (e.g., for tax or fraud prevention purposes).

8. Data Security

We implement robust security measures to protect your personal data:

  • Encryption: Data in transit (HTTPS/TLS) and at rest
  • Access Controls: Role-based access and authentication
  • Secure Hashing: Passwords are hashed using bcrypt
  • Regular Audits: Security assessments and vulnerability scans
  • Monitoring: 24/7 monitoring for suspicious activity
  • Backups: Regular encrypted backups with secure storage

9. International Data Transfers

As we use service providers located in various countries (including the United States), your personal data may be transferred outside the EEA. We ensure that:

  • Transfers are necessary for the performance of our contract with you
  • Appropriate safeguards are in place (e.g., Standard Contractual Clauses)
  • Our data processors comply with GDPR-equivalent data protection standards

10. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential Cookies: Required for the platform to function (e.g., session management)
  • Analytics Cookies: To understand how you use our Services (with consent)
  • Preference Cookies: To remember your settings and preferences

You can manage cookie preferences through your browser settings. Note that disabling essential cookies may affect functionality.

11. Children's Data

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will delete it immediately.

12. Automated Decision-Making

We use AI to generate business recommendations and content. However, we do not use automated decision-making that produces legal effects or similarly significant effects on you. All AI outputs are advisory in nature, and final decisions rest with you.

13. How to Exercise Your Rights

To exercise any of your GDPR rights, please:

  1. Send an email to: contact.copilote.ai.business@gmail.com
  2. Include "GDPR Request" in the subject line
  3. Clearly state which right you wish to exercise
  4. Provide sufficient information to verify your identity

We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days, in which case we will inform you.

Note: We may request additional information to verify your identity before processing your request to ensure the security of your personal data.

14. Supervisory Authority

If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the relevant supervisory authority:

Switzerland:

Federal Data Protection and Information Commissioner (FDPIC)

Website: www.edoeb.admin.ch

EU/EEA: Your local Data Protection Authority

Find your authority: European Data Protection Board

15. Updates to This Page

We may update this GDPR Compliance page from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or through a prominent notice on our platform.

16. Contact Us

For any questions or concerns about GDPR compliance or your data protection rights:

Email: contact.copilote.ai.business@gmail.com

Data Protection Officer: Loïc Gugelmann

Address: Lausanne, Switzerland

For general privacy information, see our .
For terms of use, see our .

Product

Company

Legal

Contact

contact.copilote.ai.business@gmail.com

Lausanne, Switzerland

© 2025 Copilote IA Business. All rights reserved.