Privacy Policy

Version 0.1 — [publication date]

Provisional document awaiting validation by a Moroccan legal professional (including retention periods). Registration will not open until this version is validated.
Automatically translated document — in case of discrepancy, the French version prevails. To be verified by a legal professional.

1. Who is responsible for your data?

In plain words

Here is who looks after your data and how to contact us.

The data controller within the meaning of Law No. 09-08 on the protection of individuals with regard to the processing of personal data is: [TO BE COMPLETED — name, legal form and address of the publisher].

Contact for any question regarding personal data: [TO BE COMPLETED — dedicated email].

This processing has been the subject of a prior declaration to the CNDP (National Commission for the Protection of Personal Data) — receipt No. [TO BE COMPLETED once obtained] issued on [date] (Law 09-08, arts. 12, 13 and 19).

2. What data do we collect, and why?

In plain words

We only ask for what is needed to create your account, run your association and prepare your official documents. We never ask for your national ID card number.

In accordance with Article 3 of Law 09-08, the data collected is limited to what is necessary for the purposes described below.

CategoryDataPurpose
User accountFirst name, surname, date of birth, email, WhatsApp number (optional), password (stored in protected form)Create and secure your account; check whether you are a minor
Parental consent (minors)Parent/guardian email, relationship to the child, status and date of the responseLegal obligation: collect and prove the guardian's consent (Family Code)
Association and journeyName, mission, city, official contact details, association bank details, content of the bylaws, step progressGuide you through creating and then managing your association
Board membersName (FR/AR), date and place of birth, nationality, address, profession, email, WhatsAppGenerate the declaration file required by the Dahir of 15 November 1958 (art. 5)
DocumentsGenerated documents (bylaws, minutes, requests) and uploads (filing receipt, official receipt)Build and keep your association's official file
AI CoachDaily message counter (conversations are not stored)Enforce the daily usage limit
Audit trailLog of changes to association settings (who, what, when)Security and traceability within the association
Technical logsError and access logs with no identifying data (anonymous identifiers only)Security and troubleshooting

2a. Zero ID number

The Service does not collect any national identity card (CIN) number — not yours, not the board members', not your guardian's. The "CIN" fields of generated documents are to be filled in by hand after printing.

Whether each field is mandatory or optional is indicated in the forms (Law 09-08, art. 5). Without the mandatory fields, the Service cannot work (for example: without a date of birth, it is impossible to know whether parental consent is required).

3. On what basis do we process your data?

In plain words

We process your data because you give us your agreement at sign-up (and your parent does too if you are a minor), and because it is necessary to provide the service you request.

Processing is based on (Law 09-08, art. 4):

  • your consent, given at sign-up via a checkbox — and, if you are a minor, the consent of your parent or legal guardian, collected before your account is activated;
  • the performance of the service you request (art. 4-b);
  • legal obligations, for keeping proof of parental consent.

You can withdraw your consent at any time by requesting the deletion of your account (section 7).

4. Who receives your data? Where is it hosted?

In plain words

Your data is never sold. It is stored with technical providers located outside Morocco — which is why we ask for your explicit agreement at sign-up.

Your data is neither sold, nor rented, nor shared with third parties for commercial purposes. No commercial prospecting is carried out (Law 09-08, art. 10): the only emails sent relate to the operation of the Service (sign-up confirmation, parental consent, invitations, security notifications).

The Service relies on technical processors (Law 09-08, art. 23), who act only on the instructions of the data controller:

ProviderRoleData concerned
SupabaseDatabase hosting, authentication, document storageAll data described in section 2
VercelApplication hostingData passing through the application; anonymous technical logs
ResendTransactional email sendingRecipient email address, email content
GroqGeneration of AI Coach answers and translationsContent of messages sent to the Coach (not stored by the Service)

4a. International transfer

International transfer (Law 09-08, arts. 43 and 44): these providers are established outside the Kingdom of Morocco. This transfer is based on your express consent (and that of your guardian if you are a minor), collected via a checkbox at sign-up (art. 44), and is mentioned in the CNDP declaration.

Within the association, your contact details and membership are visible to the other board members — this is necessary for the association to operate. No one else has access to your data, except where the law requires it.

5. How long do we keep your data?

In plain words

As long as your account or association exists. Afterwards, we delete or anonymise. One exception: the proof of your parent's agreement, which we must keep longer because it is a legal obligation.

In accordance with Article 3-1-e of Law 09-08, data is kept in identifiable form only as long as necessary for the purposes. Retention periods are PROPOSALS — legal validation in progress:

Proof of parental consent (guardian and child identity, relationship, dates, accepted terms version) is kept in a restricted-access archive (no access from the application), separate from live data, to meet the legal obligation of proof. It is permanently deleted at expiry.

DataRetention periodAt expiry
User accountLife of the accountDeletion, or anonymisation if an official file has been filed
Proof of parental consentLife of the account + 5 years [PROPOSAL — legal review]Permanent deletion
Association, journey, bylawsLife of the association on the platformCascading deletion or anonymisation
Board membersLife of the associationCascading deletion or anonymisation
Invitations and consent linksExpiry + 30 daysPurge
Generated and uploaded documentsLife of the associationStorage deletion; official documents anonymised in the database
Settings logLife of the associationCascading deletion
AI Coach counterLife of the accountCascading deletion
Technical logs (hosts)Providers' retention period [TO BE COMPLETED]Automatic rotation

6. Your rights (and how to exercise them)

In plain words

You can find out what we hold about you, correct what is wrong, object to processing and delete your account. It is free. Write to us — we reply within the legal deadlines.

In accordance with Law 09-08, any data subject has the following rights, upon proof of identity:

  • Right of access (art. 7): obtain, free of charge and at reasonable intervals, confirmation that your data is processed, its communication in intelligible form, the purposes and recipients.
  • Right of rectification (art. 8): obtain the updating, rectification, erasure or blocking of inaccurate or incomplete data, free of charge and within ten clear days. In case of refusal or silence, you can refer the matter to the CNDP.
  • Right to object (art. 9): object, on legitimate grounds, to the processing of your data — and free of charge to any use for prospecting purposes (which the Service does not practise).
  • Right to withdraw consent / deletion: request the deletion of your account (section 7).

How to exercise these rights: by email to contact@assocrea.com; some deletions are also available directly in the application where the option is offered. Reply within a maximum of [30 days — PROPOSAL; ten clear days for rectifications, art. 8].

Complaint: if you believe your rights are not respected, you can refer the matter to the CNDP (www.cndp.ma).

6a. Rights of the parent or legal guardian

In plain words

If you are a minor, your parent can see your data, have it corrected or have your account deleted — at any time, not only at sign-up.

The parent or legal guardian of a minor user may, at any time:

  • consult all the data recorded about their child;
  • request the correction of inaccurate data;
  • request the complete deletion of their child's account and data.

These rights are exercised by email to contact@assocrea.com. The guardian's identity is verified before any processing, by matching the email address recorded during parental consent. Parental consent cannot be bypassed: without it, a minor's account is not activated.

7. Account deletion and anonymisation

In plain words

When you delete your account, your personal details disappear. If your association has already been officially declared, the documents shared with the other members remain, but your name in them is replaced by an anonymous value — permanently.

When an account is deleted:

  • identifying personal data (surname, first name, email, date of birth, WhatsApp) is deleted;
  • functional data linked to associations to which other members have access (membership, participation, official documents) is irreversibly anonymised — kept under a non-traceable identifier, with no possible link to your identity (implementation of the erasure obligation of Law 09-08).

For minors, this anonymisation is an obligation of result: no technical log keeps identifying data after the operation.

The arrangements vary according to the situation (details in the Terms, Article 10): immediate cascading deletion if the association has not yet been declared; 7 days' notice to board members if the president of a declared association deletes their account; email request procedure for replacement cases.

8. How do we protect your data?

In plain words

Encryption, partitioning (everyone only sees their own associations), and zero personal data in our technical logs.

In accordance with Article 23 of Law 09-08, appropriate technical and organisational measures are implemented, in particular:

  • encryption of exchanges (HTTPS) and protected password storage;
  • partitioned database access: each user can only access the data of their own associations (security policies on every table);
  • no identifying data in technical logs (anonymous identifiers only);
  • limited staff access to data, bound by professional secrecy (art. 26);
  • contractual framework for processors (art. 23).

9. Cookies and trackers

In plain words

Only the cookies needed to stay logged in. No ads, no tracking.

The Service uses only technical cookies necessary for authentication and session maintenance. No advertising cookies, no third-party audience measurement tools, no profiling trackers are used. No automated decision producing legal effects is taken on the basis of your data (Law 09-08, art. 11).

10. Changes to this policy

Any substantial change to this policy is notified to users (and to the legal guardians of minor users where their rights or their child's data are concerned) and, where applicable, declared to the CNDP (art. 15, last paragraph). The date and version appear at the top of the document.