Privacy Policy – COPRO AG

Status: 05 December 2025

1. Data Controller

The controller responsible for processing your personal data within the meaning of the GDPR is:

COPRO AG
Jägerstraße 4
10117 Berlin
Email: datenschutz@copro-gruppe.de

2. Principles of Data Processing

Personal data is processed only to the extent permitted by law or if consent has been given.
The legal bases are in particular:

  • Art. 6 (1) lit. a GDPR (consent),
  • Art. 6 (1) lit. b GDPR (performance of a contract and pre-contractual measures),
  • Art. 6 (1) lit. c GDPR (legal obligations),
  • Art. 6 (1) lit. f GDPR (legitimate interests, e.g. operation and security of the website), provided that your interests or fundamental rights do not override these interests.

In exceptional cases, processing may be necessary to protect vital interests pursuant to Art. 6 (1) lit. d GDPR.

3. Collection of General Access Data (Log Files)

When you access our website, your browser automatically transmits information to our server, which is stored in log files. This includes in particular:

  • browser type and browser version,
  • operating system used,
  • referrer URL,
  • pages and files accessed,
  • date and time of access,
  • IP address,
  • internet service provider.

The purpose of processing is the technically error-free operation, functionality, security (e.g. defense against attacks), and evaluation for administrative purposes.
The legal basis is Art. 6 (1) lit. f GDPR; our legitimate interest lies in the secure and stable operation of the website.
Where possible, IP addresses are shortened or deleted after a short period so that personal reference exists only for the duration of the security review.

4. Cookies and Consent Management

Cookies and similar technologies are used on our website. We distinguish between:

  • technically necessary cookies, which are required for the operation and certain functions of the website (e.g. session cookies, consent cookie),
  • optional cookies and tools (e.g. statistics, marketing), which are used only with your consent.

Non-essential cookies and tools are only loaded after you have given your consent via the consent banner. You can revoke or adjust your consent at any time with effect for the future via the consent banner settings.

4.1 Google Analytics (Statistics)

If you consent, we use Google Analytics to measure reach and analyze the use of our website.
The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, or Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses cookies and similar technologies that may process, among other things, the following data:

  • pages accessed, time spent, click paths,
  • shortened IP address,
  • information on browser, device type, and operating system,
  • technical events (e.g. loading times).

The IP address is generally shortened before analysis (IP anonymization), reducing direct personal reference.
The legal basis for this processing is your consent pursuant to Art. 6 (1) lit. a GDPR.

Data may be transferred to Google servers in the USA; Google relies, among other things, on Standard Contractual Clauses and the EU–U.S. Data Privacy Framework. Nevertheless, access by U.S. authorities cannot be completely ruled out.
You can revoke your consent at any time and also install a browser add-on to disable Google Analytics.

4.2 Social Media and Marketing Tools (Optional)

The following tools may be used on our website only with your consent:

  • Facebook Pixel (Meta Platforms, Inc., USA): for evaluating and optimizing advertising campaigns and displaying interest-based advertising; information about visited pages, interactions, and technical data may be processed to assign users to target groups.
  • LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company / LinkedIn Corporation, USA): for reach measurement, conversion tracking, and creation of target audiences for advertising.
  • YouTube (Google LLC / Google Ireland Limited): for embedding videos; IP address, device information, and usage data may be processed even if videos are only viewed.

The legal basis is your consent pursuant to Art. 6 (1) lit. a GDPR. Without consent, the relevant content is only loaded in a limited manner or not at all.
Data transfers to the USA are possible; Standard Contractual Clauses or the EU–U.S. Data Privacy Framework are used, but a residual risk of government access remains.
You may revoke your consent at any time via the consent banner.

Further details on individual tools (purpose, storage duration, providers) can be found in the cookie and tool overview (Section 14).

5. Contact Form and Email Communication

If you send us inquiries via the contact form or email, the data you provide (e.g. name, contact details, content of the inquiry) will be processed exclusively to handle and respond to your request.
The legal bases are Art. 6 (1) lit. b GDPR (pre-contractual measures/contract) or Art. 6 (1) lit. f GDPR (legitimate interest in responding to inquiries).

Data will only be passed on to third parties if this is necessary for processing, you have given consent, or there is a legal obligation.

6. Applications

As part of application processes, we process the data you submit (e.g. personal data, contact details, qualifications, application documents) exclusively for the purpose of carrying out the application procedure.
The legal basis is Art. 6 (1) lit. b GDPR and, where applicable, Art. 6 (1) lit. c GDPR (legal obligations) and Art. 6 (1) lit. f GDPR (legitimate interest in efficient personnel planning).

In the event of rejection, application documents are generally deleted after 2 months unless statutory retention obligations or overriding legitimate interests (e.g. defense against legal claims) apply.
If employment is established, the data will be further processed for the execution and administration of the employment relationship.

7. Processors and Recipients

External service providers who process personal data on our behalf (e.g. hosting providers, IT service providers, analytics or marketing service providers) act on the basis of a data processing agreement pursuant to Art. 28 GDPR.
These providers are bound by our instructions and are regularly monitored for compliance with data protection requirements.

8. Transfers to Third Countries

If data is transferred to recipients in third countries outside the EU/EEA, in particular the USA, this is done on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR (e.g. Standard Contractual Clauses or an adequacy decision such as the EU–U.S. Data Privacy Framework).
Nevertheless, access by authorities in third countries cannot be completely ruled out; we expressly point this out.

9. Storage Period and Deletion

Personal data is stored only for as long as necessary for the respective purposes or as long as we are subject to statutory retention obligations.
After the purpose ceases to apply or statutory retention periods expire, the data is deleted or anonymized, unless statutory retention obligations (e.g. under commercial or tax law) require otherwise.

10. Rights of Data Subjects

Within the framework of the statutory provisions, you have the following rights:

  • right of access to your stored data (Art. 15 GDPR),
  • right to rectification of inaccurate or incomplete data (Art. 16 GDPR),
  • right to erasure (“right to be forgotten”, Art. 17 GDPR),
  • right to restriction of processing (Art. 18 GDPR),
  • right to data portability (Art. 20 GDPR),
  • right to object to processing based on Art. 6 (1) lit. e or f GDPR, in particular to direct marketing (Art. 21 GDPR),
  • right to withdraw consent at any time with effect for the future (Art. 7 (3) GDPR).

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular at your place of residence, workplace, or the place of the alleged infringement.

11. Obligation to Provide Data

The provision of certain personal data may be required by law or contract or necessary for the conclusion of a contract (e.g. for contract processing, invoicing, or tax obligations).
Without this data, a contract conclusion or the provision of certain services may not be possible or may only be possible to a limited extent.

12. Updates to This Privacy Policy

We reserve the right to amend this privacy policy if legal requirements, our processing procedures, or the tools used change.
The current version is always available on our website.

13. Contact and Supervisory Authority

For questions or to exercise your rights regarding data protection, please contact:

COPRO AG
Jägerstraße 4
10117 Berlin
Email: datenschutz@copro-gruppe.de

The competent supervisory authority in Berlin is currently:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
www.datenschutz-berlin.de

14. Cookie and Tool Overview

  • JSESSIONID: technically necessary; purpose: session management; storage period: duration of the session; provider: own server; no consent required.
  • WHGACE: technically necessary (load balancer); storage period: 1 day; provider: own server; no consent required.
  • WHGCOOKIECONSENT: technically necessary; purpose: storage of your cookie consent; storage period: 6 months; provider: own server; consent required as your selection is documented.
  • Google Analytics: statistics and reach analysis; cookie storage period: generally 6 months to 2 years; provider: Google LLC / Google Ireland Limited (USA/EU); consent required; IP anonymization enabled; possible data transfer to the USA.
  • Facebook Pixel (optional): advertising tracking and conversion measurement; storage period: approx. 3 months to 2 years; provider: Meta Platforms, Inc., USA; consent required; possible data transfer to the USA.
  • LinkedIn Insight Tag (optional): marketing analysis and conversion tracking; storage period: approx. 6 months to 2 years; provider: LinkedIn Ireland Unlimited Company / LinkedIn Corporation, USA; consent required; possible data transfer to the USA.
  • YouTube (optional): embedding of videos; storage period: generally up to 6 months; provider: Google LLC / Google Ireland Limited; consent required; IP address and further usage data may be transferred to the USA.

Optional tracking and marketing tools are only activated after consent has been given; consent can be withdrawn at any time via the consent banner.
All external service providers used are contractually obligated to comply with data protection requirements.