CoPIMS Privacy Policy

Effective date: August 22, 2026  |  Last revised: August 22, 2026

This Privacy Policy explains how the Construction Project Information Management System (CoPIMS), operated for the Ministry of Water and Energy (MoWE) and affiliated construction stakeholders in Ethiopia, collects, processes, stores, and protects information about you. By registering an account or using the Service, you acknowledge that you have read and understood this Policy. Expand each section below for the full details.

CoPIMS collects information across the following categories to operate the platform and deliver its features to construction organizations and stakeholders.

1.1 Account & Identity Data

Collected when you register or update your profile:

  • Full name (first name, last name), username, and email address.
  • Phone number, date of birth, sex, and physical/mailing address.
  • Job title, professional role, and organizational affiliation.
  • Profile photograph (where uploaded).

1.2 Authentication & Security Data

Generated and stored to secure your account:

  • Salted and hashed passwords (never stored in plain text).
  • Email activation tokens and password-reset tokens.
  • Login session identifiers, timestamps, and IP addresses of sign-in events.

1.3 Employee & Human Resource Data

Entered by authorized HR personnel into the Human Resource module:

  • Employee personal records: full name, national ID reference, date of birth, sex, marital status, address, emergency contacts.
  • Professional records: education qualifications, work experience, professional licences, professional training, skills, and volunteer experience.
  • Employment details: position, pay grade, bank account information for payroll processing, employment start/end dates.
  • Payroll data: salary figures, deductions, allowances, payslips.
  • Uploaded HR documents: employment letters, contracts, certificates.

1.4 Project & Construction Data

Entered by project teams into CoPIMS modules:

  • Project records: project name, contract signing and commencement dates, original and revised durations, client, contractor, and consultant identities, contract amounts.
  • Bill of Quantities (BoQ): line items, unit rates, quantities, variation orders, supplementary items, and associated financial totals.
  • Payment records: interim payment certificates (IPCs), subcontractor payment records, retention amounts, VAT, penalty deductions, and financial progress data.
  • Plan & Report: master schedules, daily/weekly/monthly progress reports, physical and financial progress percentages, milestone records.
  • Duration records: original contract duration, delay logs, extension of time (EOT) applications and approvals.
  • Subcontract records: subcontractor identity, scope of work, payment terms, and performance records.

1.5 Procurement & Logistics Data

  • Purchase requests and purchase orders: material descriptions, quantities, unit prices, supplier identities.
  • Logistics delivery records: material receipt, delivery quantities, warehouse stock levels.
  • Current market price records maintained by the organization.

1.6 Plant & Equipment Data

  • Equipment registration details: make, model, serial number, assigned project.
  • Utilization logs, fuel consumption records, and maintenance schedules.

1.7 Quality, Safety & Security Records

  • Quality: inspection checklists, inspection results, non-conformance reports (NCRs), corrective actions.
  • Safety: incident reports (including descriptions of individuals involved), toolbox-talk attendance records, hazard logs.
  • Security: site-access logs, daily security reports, records of personnel entering and exiting project sites.

1.8 Approval Audit Trail Data

  • For every record passing through the Approval Workflow (Draft → Submitted → Checked → Approved/Rejected), the system records: the acting User's identity, the action taken, any remarks provided, and the exact timestamp of each transition.
  • This audit trail is permanent and immutable.

1.9 Files & Documents

  • All files uploaded through the File Management module or attached to any record: drawings, blueprints, scanned documents, photographs, reports, and other project-related files.

1.10 Usage & Diagnostic Data

  • IP address, browser type, device metadata, page views, feature interactions, and error/crash logs used to maintain and improve the platform.

1.11 Support & Communication Data

  • Messages submitted via the Contact page, support emails, feedback forms, and any information you include in correspondence with the CoPIMS team.

CoPIMS processes the information described above for the following specific purposes:

  • Account provision & authentication: to create, verify, and secure your individual user account; to manage session access; and to send account activation and password-reset communications.
  • Delivery of core construction management features: to enable you to create and manage projects, enter and review BoQ items, process payments, manage HR records, run procurement workflows, log safety incidents, and use all other modules available under your Organization's Licence.
  • Approval Workflow operation: to record and enforce the multi-step approval process (Submit → Check → Approve) for financial and operational records, including maintaining the immutable audit trail that documents who acted on each record and when.
  • Financial processing & reporting: to calculate project totals, physical and financial progress, payment certificates, payroll figures, and to generate reports and dashboards.
  • Licence & billing management: to activate and manage your Organization's Licence, track usage limits, issue invoices, and process payments.
  • Notifications & communications: to send system-generated email notifications (e.g., account activation, approval status changes, password resets, licence expiry alerts).
  • Platform security & integrity: to detect and prevent unauthorized access, abuse, and fraudulent use; to maintain activity logs; and to investigate security incidents.
  • Legal & regulatory compliance: to comply with applicable Ethiopian law, MoWE regulatory requirements, court orders, or other lawful obligations.
  • Platform improvement: to analyze aggregated, anonymized usage patterns to improve features, fix bugs, and plan future development.
  • Support delivery: to respond to support requests, resolve issues, and provide onboarding or training assistance.

We do not use your Project Data or personal data for advertising, behavioral profiling, or sale to third parties.

Access to data within CoPIMS is governed by a strict role-based access control system. Not all users can see all data. The following principles apply:

  • Organization-level isolation: each Organization's data is logically separated. Users of one Organization cannot access the projects, records, or personnel data of a different Organization.
  • Project-level role assignment: within a project, a User's assigned Role (e.g., Engineer, Project Manager, Finance Officer, HR Officer, Site Supervisor) determines which modules and records they can view, create, submit, check, or approve. A User may hold different roles in different projects.
  • HR & payroll data: access to employee personal records, payroll figures, and bank account information is restricted to Users holding HR-related positions within the Organization. Site supervisors and field engineers cannot access payroll data.
  • Financial records: BoQ totals, IPC values, subcontractor payment amounts, and financial progress data are accessible only to Users with finance, project management, or approval roles on the relevant project.
  • Safety & security logs: site-access logs and safety incident reports are accessible to Safety Officers, Security Officers, and Project Managers on the relevant project.
  • Platform administrators: CoPIMS system administrators have elevated access for maintenance, licence management, and support purposes, and are bound by strict confidentiality obligations.
  • Audit trail: approval audit records are accessible to any User with read access to the parent record and to administrators for compliance purposes.

CoPIMS does not sell or commercially share your personal data or Project Data. We disclose information only in the following limited circumstances:

  • Within your Organization: data is shared among the Users of your Organization in accordance with the role-based access rules described in Section 3.
  • Technical subprocessors: we engage trusted third-party service providers (cloud hosting, email delivery, database services) who process data on our behalf under strict data protection contracts. These providers cannot use your data for their own purposes.
  • MoWE and regulatory bodies: where required by Ethiopian law or MoWE directives, we may disclose project performance data, financial summaries, or records to the Ministry of Water and Energy or other competent government authorities. We will notify you where legally permitted.
  • Legal process: we may disclose information in response to valid court orders, lawful government requests, or to protect the legal rights, safety, and property of CoPIMS, its users, or the public.
  • Business transfers: in the event of a merger, acquisition, or organizational restructuring, data may be transferred as part of that transaction under confidentiality protections.
  • With your explicit consent: in any other circumstance, we will obtain your explicit consent before sharing your personal data with third parties.

CoPIMS implements multiple layers of technical and organizational security controls:

  • Data in transit: all communication between your browser and the CoPIMS server is encrypted using TLS (Transport Layer Security).
  • Password security: passwords are never stored in plain text. They are processed using industry-standard salted hashing algorithms before storage.
  • Role-based access controls (RBAC): every view, form submission, and data operation is gated behind permission checks that verify the acting User's role and position before allowing access.
  • Session management: authenticated sessions are secured with CSRF protection and session tokens. The system automatically enforces login requirements for all protected pages.
  • Activity logging: significant actions (logins, approvals, data modifications) are logged with user identity and timestamp for forensic and audit purposes.
  • Input sanitization: all rich-text input is processed through a whitelist-based HTML sanitizer to prevent cross-site scripting (XSS) attacks before storage.
  • Security reviews: the platform undergoes periodic internal security reviews and vulnerability assessments.
  • Incident response: we maintain documented procedures for detecting, containing, and recovering from data security incidents.

Your responsibility: you must also take reasonable steps to protect your account, including using a strong unique password, logging out on shared devices, and reporting suspicious activity to support@copims.com immediately.

No system can guarantee absolute security. In the event of a confirmed data breach that is likely to affect your rights and interests, we will notify affected Organizations and, where required, the relevant Ethiopian regulatory authority, within a reasonable timeframe.

We retain different categories of data for different periods based on operational need and legal obligation:

  • Active account & profile data: retained for as long as your account is active and your Organization's Licence is valid.
  • Project Data (BoQ, payments, progress reports, HR records, etc.): retained throughout the active Licence period. This data constitutes operational records of construction projects and may be retained longer where required to comply with MoWE reporting obligations or Ethiopian financial record-keeping law.
  • Approval audit trail: permanently retained for as long as the associated project record exists, as it forms an immutable compliance record. Audit entries cannot be deleted on request, as they may be required as evidence in contractual disputes or government audits.
  • Financial & billing records: invoices, licence agreements, and payment records are retained for a minimum of seven (7) years in accordance with Ethiopian tax and financial regulation.
  • Account closure / Licence expiry: upon closure of an individual account or expiry of an Organization's Licence, personal data is retained in backup form for up to 90 days. After this window, personal data is deleted except where retention is legally required.
  • Safety incident records: safety incident data may be retained for longer periods in accordance with applicable Ethiopian occupational health and safety regulations.

To request deletion of personal data associated with your individual account, submit a written request to support@copims.com with proof of identity. We will evaluate each request and comply where required by law. Note that deletion of personal data linked to approved financial or operational records may not be fully possible without compromising the integrity of audit trails.

Depending on applicable law, you may have the following rights regarding your personal data held in CoPIMS:

  • Access: you may request a summary of the personal data we hold about you — including your account information, profile data, and records of actions you have taken in the system.
  • Rectification: if your personal data (name, contact details, HR profile fields) is inaccurate or outdated, you may update it through account settings or request a correction via support.
  • Erasure: you may request deletion of your personal identifiers where we have no overriding legal basis to retain them. This right does not extend to Project Data records or approval audit entries that are part of your Organization's operational history.
  • Data portability: you may request an export of your personal data and your Organization's Project Data in a structured, machine-readable format (where technically feasible). Export requests should be submitted to support@copims.com.
  • Restriction of processing: in certain circumstances you may request that we restrict processing of your data while a dispute or correction request is being resolved.
  • Objection: you may object to processing of your data where it is based on legitimate interests, unless we can demonstrate compelling grounds to continue.
  • Withdraw consent: where processing is based on your consent (e.g., optional marketing communications), you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact support@copims.com. We will verify your identity before processing any request and aim to respond within 30 days. Some requests may take longer or may be declined where we have a legal obligation to retain the data.

CoPIMS uses browser-side storage mechanisms for the following purposes:

  • Session cookies: essential cookies that maintain your authenticated login session. Without these, you would need to re-authenticate on every page. These are deleted when you close your browser or log out.
  • CSRF tokens: short-lived security tokens embedded in forms to protect against Cross-Site Request Forgery attacks. These are not used for tracking.
  • Local storage preferences: the platform stores minor UI preferences (such as sidebar collapsed/expanded state) in your browser's local storage. This data never leaves your device.

CoPIMS does not use third-party advertising cookies, behavioral tracking cookies, or persistent cross-site tracking mechanisms. No data from cookies is sold or shared with advertising networks.

CoPIMS may connect with third-party services where enabled by your Organization:

  • Email delivery: outgoing system emails (activation links, approval notifications, password resets) are sent via a third-party email delivery provider. Only the recipient's email address and the message content are transmitted; no other personal data is shared with the provider beyond what is necessary for delivery.
  • Cloud infrastructure: the platform may be hosted on cloud infrastructure. The hosting provider processes data as a technical subprocessor under a data processing agreement and does not have independent access to your data.
  • Linked external resources: the platform may display links to external websites. CoPIMS is not responsible for the privacy practices of those sites. We recommend reviewing their privacy policies before sharing any information.

We require all third-party processors to implement appropriate technical and contractual safeguards for any data they handle on our behalf.

Governing Law: This Privacy Policy is governed by the laws of the Federal Democratic Republic of Ethiopia. Where Ethiopian privacy and data protection law applies, its requirements take precedence. Where your Organization operates in a jurisdiction with additional privacy requirements (such as GDPR for EU-related activities), we will work with you to address those requirements on a case-by-case basis.

Children's Data: CoPIMS is a professional enterprise platform intended for use by adults in a construction industry context. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor's data has been entered into the system, please contact us immediately at support@copims.com.

Policy Updates: We may update this Privacy Policy periodically to reflect changes in the platform, legal requirements, or our data practices. Material changes will be communicated through the platform's News and Updates section. The updated effective date will always appear at the top of this page. Continued use of the Service after an update constitutes acceptance of the revised Policy.

Contact & Privacy Requests:

By using CoPIMS, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of your information as described herein. For related terms governing your use of the platform, please also review our Terms of Service.