Version 0.1 — [publication date]
In plain words
Here is who looks after your data and how to contact us.
The data controller within the meaning of Law No. 09-08 on the protection of individuals with regard to the processing of personal data is: [TO BE COMPLETED — name, legal form and address of the publisher].
Contact for any question regarding personal data: [TO BE COMPLETED — dedicated email].
This processing has been the subject of a prior declaration to the CNDP (National Commission for the Protection of Personal Data) — receipt No. [TO BE COMPLETED once obtained] issued on [date] (Law 09-08, arts. 12, 13 and 19).
In plain words
We only ask for what is needed to create your account, run your association and prepare your official documents. We never ask for your national ID card number.
In accordance with Article 3 of Law 09-08, the data collected is limited to what is necessary for the purposes described below.
| Category | Data | Purpose |
|---|---|---|
| User account | First name, surname, date of birth, email, WhatsApp number (optional), password (stored in protected form) | Create and secure your account; check whether you are a minor |
| Parental consent (minors) | Parent/guardian email, relationship to the child, status and date of the response | Legal obligation: collect and prove the guardian's consent (Family Code) |
| Association and journey | Name, mission, city, official contact details, association bank details, content of the bylaws, step progress | Guide you through creating and then managing your association |
| Board members | Name (FR/AR), date and place of birth, nationality, address, profession, email, WhatsApp | Generate the declaration file required by the Dahir of 15 November 1958 (art. 5) |
| Documents | Generated documents (bylaws, minutes, requests) and uploads (filing receipt, official receipt) | Build and keep your association's official file |
| AI Coach | Daily message counter (conversations are not stored) | Enforce the daily usage limit |
| Audit trail | Log of changes to association settings (who, what, when) | Security and traceability within the association |
| Technical logs | Error and access logs with no identifying data (anonymous identifiers only) | Security and troubleshooting |
The Service does not collect any national identity card (CIN) number — not yours, not the board members', not your guardian's. The "CIN" fields of generated documents are to be filled in by hand after printing.
Whether each field is mandatory or optional is indicated in the forms (Law 09-08, art. 5). Without the mandatory fields, the Service cannot work (for example: without a date of birth, it is impossible to know whether parental consent is required).
In plain words
We process your data because you give us your agreement at sign-up (and your parent does too if you are a minor), and because it is necessary to provide the service you request.
Processing is based on (Law 09-08, art. 4):
You can withdraw your consent at any time by requesting the deletion of your account (section 7).
In plain words
Your data is never sold. It is stored with technical providers located outside Morocco — which is why we ask for your explicit agreement at sign-up.
Your data is neither sold, nor rented, nor shared with third parties for commercial purposes. No commercial prospecting is carried out (Law 09-08, art. 10): the only emails sent relate to the operation of the Service (sign-up confirmation, parental consent, invitations, security notifications).
The Service relies on technical processors (Law 09-08, art. 23), who act only on the instructions of the data controller:
| Provider | Role | Data concerned |
|---|---|---|
| Supabase | Database hosting, authentication, document storage | All data described in section 2 |
| Vercel | Application hosting | Data passing through the application; anonymous technical logs |
| Resend | Transactional email sending | Recipient email address, email content |
| Groq | Generation of AI Coach answers and translations | Content of messages sent to the Coach (not stored by the Service) |
International transfer (Law 09-08, arts. 43 and 44): these providers are established outside the Kingdom of Morocco. This transfer is based on your express consent (and that of your guardian if you are a minor), collected via a checkbox at sign-up (art. 44), and is mentioned in the CNDP declaration.
Within the association, your contact details and membership are visible to the other board members — this is necessary for the association to operate. No one else has access to your data, except where the law requires it.
In plain words
As long as your account or association exists. Afterwards, we delete or anonymise. One exception: the proof of your parent's agreement, which we must keep longer because it is a legal obligation.
In accordance with Article 3-1-e of Law 09-08, data is kept in identifiable form only as long as necessary for the purposes. Retention periods are PROPOSALS — legal validation in progress:
Proof of parental consent (guardian and child identity, relationship, dates, accepted terms version) is kept in a restricted-access archive (no access from the application), separate from live data, to meet the legal obligation of proof. It is permanently deleted at expiry.
| Data | Retention period | At expiry |
|---|---|---|
| User account | Life of the account | Deletion, or anonymisation if an official file has been filed |
| Proof of parental consent | Life of the account + 5 years [PROPOSAL — legal review] | Permanent deletion |
| Association, journey, bylaws | Life of the association on the platform | Cascading deletion or anonymisation |
| Board members | Life of the association | Cascading deletion or anonymisation |
| Invitations and consent links | Expiry + 30 days | Purge |
| Generated and uploaded documents | Life of the association | Storage deletion; official documents anonymised in the database |
| Settings log | Life of the association | Cascading deletion |
| AI Coach counter | Life of the account | Cascading deletion |
| Technical logs (hosts) | Providers' retention period [TO BE COMPLETED] | Automatic rotation |
In plain words
You can find out what we hold about you, correct what is wrong, object to processing and delete your account. It is free. Write to us — we reply within the legal deadlines.
In accordance with Law 09-08, any data subject has the following rights, upon proof of identity:
How to exercise these rights: by email to contact@assocrea.com; some deletions are also available directly in the application where the option is offered. Reply within a maximum of [30 days — PROPOSAL; ten clear days for rectifications, art. 8].
Complaint: if you believe your rights are not respected, you can refer the matter to the CNDP (www.cndp.ma).
In plain words
If you are a minor, your parent can see your data, have it corrected or have your account deleted — at any time, not only at sign-up.
The parent or legal guardian of a minor user may, at any time:
These rights are exercised by email to contact@assocrea.com. The guardian's identity is verified before any processing, by matching the email address recorded during parental consent. Parental consent cannot be bypassed: without it, a minor's account is not activated.
In plain words
When you delete your account, your personal details disappear. If your association has already been officially declared, the documents shared with the other members remain, but your name in them is replaced by an anonymous value — permanently.
When an account is deleted:
For minors, this anonymisation is an obligation of result: no technical log keeps identifying data after the operation.
The arrangements vary according to the situation (details in the Terms, Article 10): immediate cascading deletion if the association has not yet been declared; 7 days' notice to board members if the president of a declared association deletes their account; email request procedure for replacement cases.
In plain words
Encryption, partitioning (everyone only sees their own associations), and zero personal data in our technical logs.
In accordance with Article 23 of Law 09-08, appropriate technical and organisational measures are implemented, in particular:
Any substantial change to this policy is notified to users (and to the legal guardians of minor users where their rights or their child's data are concerned) and, where applicable, declared to the CNDP (art. 15, last paragraph). The date and version appear at the top of the document.