Privacy Policy
What personal data Asrar processes when you use Veille, why, on what basis, for how long, who it is shared with and how to exercise your rights — under Moroccan Law No. 09-08 and, for data subjects in the European Union, the GDPR.
What changed in 1.1: Clarified roles for the firm’s clients’ data (the firm is the controller, § 2); added the optional AI provider (§ 6); retention periods by plan (§ 8); rights before the CNDP and European authorities (§ 10).
On this page (12 sections)
This policy explains how Asrar Studio SARL (“Asrar”, “we”) processes personal data when you visit our website, create an account, use Veille (the “Service”) or contact us. Questions: privacy@asrar.example or our data protection officer: dpo@asrar.example.
1. Legal framework
We are established in Morocco and apply Law No. 09-08 on the protection of individuals with regard to the processing of personal data, under the supervision of the Moroccan National Commission for the Control of Personal Data Protection (CNDP). When we process data of people located in the European Union — for example consultants and clients of French firms — we also apply Regulation (EU) 2016/679 (GDPR). Our representative in the European Union (Article 27 GDPR) is: Asrar EU Representative (placeholder), 00 Rue Exemple, 75000 Paris, France.
2. Who is responsible for what
- Asrar is the controller of your account data (identity, sign-in, preferences, consents), billing data and browsing data on our website.
- Your firm is the controller of the data it enters about its clients: client contacts (name, position, email of report recipients), site information, notes and supporting documents. For that data, Asrar acts as processor, under the Data Processing Agreement.
- Collected official texts (laws, decrees, orders…) are public documents; they do not, in principle, contain personal data processed for our own purposes.
3. Data we process
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account | Name, work email, password (hashed), interface language, time zone | Create and secure your account, identify you | Performance of the contract |
| Firm and roles | Firm name, members, roles, invitations | Provide the workspace and control access | Performance of the contract |
| Professional activity | Approvals, edits, justifications, author and date of each decision | Traceability required by a decision-support tool (“prepared by / approved by”) | Legitimate interest and performance of the contract |
| Firm’s client data | Recipient contacts, site profiles, facts, registers, reports | Provide the Service to the firm (processing on its behalf) | The firm’s instructions |
| Consents | Documents accepted, version, wording shown, language, date, IP address, browser | Prove your acceptance and choices | Legal obligation and legitimate interest |
| Technical logs | IP address, browser, timestamps, errors | Security, abuse prevention, diagnostics | Legitimate interest |
| Emails | Address, content, delivery status | Sending service emails and reports | Performance of the contract |
| Audience measurement | Aggregated statistics | Improve the website | Consent (cookie banner) |
| Marketing | Product news and tips | Consent, withdrawable at any time |
4. Sensitive data
The Service is not designed to process sensitive data (health, biometrics, opinions…). The facts of client profiles describe installations and activities (flammable liquid storage, night work, pressure equipment…) rather than individuals. Do not enter individual employee health data.
5. Recipients
Your data is accessible to your firm’s authorised members according to their role, to our authorised staff when necessary (support, security) and to our subprocessors. We do not sell or rent your data.
6. Artificial intelligence
By default, the Service analyses texts with a built-in engine running on our servers. When an AI model provider is enabled, passages of official texts and the strictly necessary information from the client profile may be sent to it to produce a summary or a proposal; that provider is not allowed to use them to train its models. See the AI Policy.
7. Transfers outside Morocco and the European Union
Some subprocessors are located outside Morocco or the European Union (for example in the United States for email delivery). These transfers are governed by the European Commission’s Standard Contractual Clauses and, for Morocco, carried out in accordance with Law No. 09-08 and the authorisations required by the CNDP.
8. Retention periods
- Account: while you use the Service, then 30 days after deletion.
- Registers, reports, matches and approvals: 2 years (Solo) or 7 years (Cabinet), or until the firm is deleted.
- Consent evidence: 5 years after the end of the relationship.
- Technical logs: 12 months.
- Backups: erased within 35 days after the active data is deleted.
9. Security
Encryption in transit (TLS) and of secrets at rest, strict isolation between firms, private files served only through temporary links, role-based access control, logging of sensitive actions, regular backups.
10. Your rights
You have the rights of access, rectification, objection and, depending on the case, erasure, restriction and portability, as well as the right to withdraw your consent at any time. Write to privacy@asrar.example. If your data is processed by a firm as a client or a report recipient, contact that firm first; we will help it answer. You can lodge a complaint with the Moroccan National Commission for the Control of Personal Data Protection (CNDP) or, in the European Union, with the data protection authority of your country (in France, the CNIL).
11. Cookies
See the Cookie Policy.
12. Changes
We inform you of any material change at least 30 days in advance. Previous versions remain available.
In case of discrepancy between this English version and the French version, the French version prevails.