Privacy Commitment
Marasim complies with Moroccan Law 09-08, CNDP guidelines, and GDPR standards.
Compliance with Moroccan Law 09-08 and GDPR standards
Marasim complies with Moroccan Law 09-08, CNDP guidelines, and GDPR standards.
Account details, event information, guest RSVP lists, and technical logs. Card data is processed via CMI without storage on Marasim servers.
When a third-party service is connected voluntarily, data may include the external account identifier and username, encrypted OAuth tokens and permissions, connection and synchronization status, and professional content the account holder chooses to import or manage.
Service delivery, WhatsApp OTP verification, ERP management, and B2B billing.
Connected-service data is used to enrich vendor listings, synchronize portfolios and reviews, keep business details current, and perform actions expressly requested by the vendor from the dashboard.
Marasim strictly never sells, rents, or monetizes personal data or guest lists.
Exchanges with Meta and Google are limited to the data and permissions needed for the vendor-selected connection; imported data is not used for targeted advertising or data brokerage.
Immediate soft-deletion from public views, followed by automated permanent deletion after 30 days.
Disconnecting a third-party service does not automatically delete copies already imported to a listing: it stops future access and deletes stored authorization tokens. Imported content may be removed through listing-management tools or by requesting deletion at privacy@marasim.ma, subject to the purge period above.
Access, rectify, or erase your data by contacting: privacy@marasim.ma.
Vendors may withdraw Instagram or Google authorization through Marasim integrations or the provider's settings at any time, without affecting the lawfulness of processing completed before withdrawal.
Marasim uses secure cloud infrastructure to deliver the service: the database and identity service are deployed in a specific European Union region (Frankfurt, Paris, or Ireland), while files, documents, and contracts are stored in Cloudflare R2 buckets with the EU jurisdiction restriction.
Data is encrypted in transit using SSL/TLS, R2 objects are automatically encrypted at rest, and private documents are isolated with PostgreSQL Row Level Security (RLS) controls.
OAuth tokens for connected services are stored in encrypted form. Marasim neither receives nor stores the vendor's Instagram or Google password.
Essential session, language, and anonymized analytics cookies.
Approval of the underlying CNDP processing declaration or authorization, followed by the F-118 application for transfers abroad, are production-launch conditions for personal-data processing. Receipt or authorization references will be published here after they are issued; this wording does not claim that approval has already been obtained.
Marasim selects Ireland (eu-west-1) as Resend's email-sending region. Resend states that account data, email metadata, logs, and API records remain stored in the United States regardless of sending region. That transfer is governed by Resend's DPA and Standard Contractual Clauses (SCCs) and must be identified explicitly in the F-118 filing.
Account connections and synchronization may pass through Meta and Google infrastructure outside Morocco, depending on the service selected. These flows, recipients, and destination countries must be included in the processing declaration and F-118 transfer filing before production activation.
Marasim must execute the applicable Supabase, Cloudflare, Resend, and enabled integration-provider DPAs and contractual transfer safeguards before launch.