1. Introduction
This Privacy Policy describes how OpenCoop ("we", "us", "our") collects, uses, and protects personal data when you use the OpenCoop platform ("Platform"). We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR) and applicable Belgian data protection laws.
2. Data Controller & Processor
For shareholder data: The Cooperative using the Platform is the Data Controller. OpenCoop acts as a Data Processor, processing data on behalf of the Cooperative.
For account and platform usage data: OpenCoop is the Data Controller.
3. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, password (hashed), preferred language
- Profile data: phone number, address, date of birth, national ID number (when required by the Cooperative)
- Company data: company name, registration number (KBO/BCE), VAT number, legal form
- Financial data: IBAN, BIC, share transactions, dividend payments
- Usage data: login timestamps, IP addresses, browser information
- Communication data: messages sent through the Platform
4. Purposes of Processing
We process personal data for the following purposes:
- Providing and maintaining the Platform
- Managing cooperative shareholder records
- Processing share transactions and payments
- Calculating and distributing dividends
- Generating legal documents (certificates, statements)
- Communicating with users about their accounts
- Improving the Platform and user experience
- Complying with legal obligations
5. Legal Basis (GDPR Art. 6)
We process personal data based on the following legal grounds:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Platform services
- Legitimate interests (Art. 6(1)(f)): Platform security, fraud prevention, and service improvement
- Legal obligation (Art. 6(1)(c)): Compliance with Belgian cooperative law and tax regulations
- Consent (Art. 6(1)(a)): Where explicitly provided, such as for marketing communications
6. Data Retention
We retain personal data for as long as necessary to fulfill the purposes described in this policy:
- Account data: retained while the account is active and for 12 months after deletion
- Transaction data: retained for 7 years as required by Belgian accounting regulations
- Usage data: retained for 12 months
- Communication data: retained for 24 months
7. Your Rights
Under the GDPR, you have the following rights:
- Right of access: obtain a copy of your personal data
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: request deletion of your data (subject to legal retention requirements)
- Right to data portability: receive your data in a structured, machine-readable format
- Right to restrict processing: limit how we use your data
- Right to object: object to processing based on legitimate interests
- Right to withdraw consent: where processing is based on consent
To exercise these rights, contact us at
[email protected] or contact the Cooperative that manages your shareholder data.
8. Sub-processors
We use the following categories of sub-processors:
- Cloud hosting providers (EU-based)
- Email delivery services
- Payment processing services
- Error monitoring services
All sub-processors are bound by data processing agreements and are required to maintain appropriate security measures. A list of current sub-processors is available upon request.
9. International Transfers
We primarily store and process data within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses.
10. Cookies
The Platform uses essential cookies required for the proper functioning of the service, such as authentication tokens and language preferences. These cookies are strictly necessary and do not require consent. We do not use tracking or advertising cookies.
11. Data Security
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, regular security audits, and secure development practices.
12. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours as required by the GDPR. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email or through the Platform.
14. Contact
For privacy-related inquiries:
- Email:
[email protected]
- Supervisory authority: Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), Drukpersstraat 35, 1000 Brussels,
[email protected]