Skip to content
marasim
Venues
PlanningInspirationBudget Planner
Sign inCreate account
Explore vendors
Official Certified Legal CharterVersion 1.2 (Official Consolidated & Certified Edition)

Comprehensive Legal Charter & Regulatory Policies

Marasim Morocco Platform (marasim.ma) · September 2026

Applicable Legal Framework & Statutes

  • Moroccan Law No. 09-08 (Protection of Personal Data / CNDP)
  • Moroccan Law No. 53-05 (Electronic Exchange of Legal Data & E-Signatures)
  • Moroccan Law No. 31-08 (Consumer Protection Measures)
  • Moroccan Dahir of Obligations and Contracts (DOC)

Table of Articles

  • Part III · Privacy & CNDPPrivacy Policy & Personal Data Protection
    • Article 1: Privacy Commitment
    • Article 2: Data Collected
    • Article 3: Purposes of Processing
    • Article 4: No Data Selling
    • Article 5: Data Retention & 30-Day Permanent Hard-Delete
    • Article 6: User Rights
    • Article 7: Data Security
    • Article 8: Cookies
    • Article 9: CNDP Formalities and International Transfers
    • Article 10: Instagram, Google Business Profile, and Third-Party Connections
Part III · Privacy & CNDP

Privacy Policy & Personal Data Protection

Compliance with Moroccan Law 09-08 and GDPR standards

Governing Law: Moroccan Law 09-08 & CNDP Regulations
Article 1

Privacy Commitment

Marasim complies with Moroccan Law 09-08, CNDP guidelines, and GDPR standards.

Article 2

Data Collected

Account details, event information, guest RSVP lists, and technical logs. Card data is processed via CMI without storage on Marasim servers.

When a third-party service is connected voluntarily, data may include the external account identifier and username, encrypted OAuth tokens and permissions, connection and synchronization status, and professional content the account holder chooses to import or manage.

Article 3

Purposes of Processing

Service delivery, WhatsApp OTP verification, ERP management, and B2B billing.

Connected-service data is used to enrich vendor listings, synchronize portfolios and reviews, keep business details current, and perform actions expressly requested by the vendor from the dashboard.

Article 4

No Data Selling

Marasim strictly never sells, rents, or monetizes personal data or guest lists.

Exchanges with Meta and Google are limited to the data and permissions needed for the vendor-selected connection; imported data is not used for targeted advertising or data brokerage.

Article 5

Data Retention & 30-Day Permanent Hard-Delete

Immediate soft-deletion from public views, followed by automated permanent deletion after 30 days.

Disconnecting a third-party service does not automatically delete copies already imported to a listing: it stops future access and deletes stored authorization tokens. Imported content may be removed through listing-management tools or by requesting deletion at privacy@marasim.ma, subject to the purge period above.

Article 6

User Rights

Access, rectify, or erase your data by contacting: privacy@marasim.ma.

Vendors may withdraw Instagram or Google authorization through Marasim integrations or the provider's settings at any time, without affecting the lawfulness of processing completed before withdrawal.

Article 7

Data Security

Marasim uses secure cloud infrastructure to deliver the service: the database and identity service are deployed in a specific European Union region (Frankfurt, Paris, or Ireland), while files, documents, and contracts are stored in Cloudflare R2 buckets with the EU jurisdiction restriction.

Data is encrypted in transit using SSL/TLS, R2 objects are automatically encrypted at rest, and private documents are isolated with PostgreSQL Row Level Security (RLS) controls.

OAuth tokens for connected services are stored in encrypted form. Marasim neither receives nor stores the vendor's Instagram or Google password.

Article 8

Cookies

Essential session, language, and anonymized analytics cookies.

Article 9

CNDP Formalities and International Transfers

Approval of the underlying CNDP processing declaration or authorization, followed by the F-118 application for transfers abroad, are production-launch conditions for personal-data processing. Receipt or authorization references will be published here after they are issued; this wording does not claim that approval has already been obtained.

Marasim selects Ireland (eu-west-1) as Resend's email-sending region. Resend states that account data, email metadata, logs, and API records remain stored in the United States regardless of sending region. That transfer is governed by Resend's DPA and Standard Contractual Clauses (SCCs) and must be identified explicitly in the F-118 filing.

Account connections and synchronization may pass through Meta and Google infrastructure outside Morocco, depending on the service selected. These flows, recipients, and destination countries must be included in the processing declaration and F-118 transfer filing before production activation.

Marasim must execute the applicable Supabase, Cloudflare, Resend, and enabled integration-provider DPAs and contractual transfer safeguards before launch.

Article 10

Instagram, Google Business Profile, and Third-Party Connections

1. Voluntary connection and consent

  • A connection is initiated only by the vendor or an authorized organization member through the provider's OAuth flow. The authorization screen presents the requested access, and the user confirms that they own the account or are legally authorized to manage it.
  • Marasim follows permission minimization and uses connected data only for the integration features visible in the professional workspace.

2. Instagram synchronization

  • Marasim may access the professional account identifier and username, together with photos, videos, Reels, thumbnails, provider media identifiers, captions, publication dates, and like and comment counts made available by the API.
  • Marasim does not request private messages, comment content, or Insights data. Synchronized media is copied to Marasim storage and enters moderation before appearing on the listing or inspiration surfaces.

3. Google Business Profile synchronization

  • Marasim may access account and location identifiers, business name, phone number, website, address, opening hours, and public profile details, together with public reviews, reviewer names and photos, ratings, text, dates, links, and vendor replies.
  • Profile changes or review replies are sent to Google only after an explicit vendor action in the dashboard.

4. Display, rights, and responsibility

  • The vendor grants Marasim a non-exclusive, limited, and revocable license to copy, store, technically format, and display imported content to operate the vendor listing and discovery services, without transferring ownership to Marasim.
  • The vendor remains responsible for content rights and the consent of people shown in it. Any affected person may report content or request removal at privacy@marasim.ma.

5. Disconnection and provider availability

  • Disconnection deletes encrypted access tokens held by Marasim and stops new synchronization and remote actions; previously imported copies require separate deletion under Article 5.
  • Third-party services remain subject to Meta and Google terms and policies and may change or become unavailable. Marasim is not affiliated with or a representative of Meta or Google and is not responsible for provider-caused outages.
marasim

Moroccan weddings, beautifully orchestrated.

Discover, compare and contact verified wedding professionals across Morocco.

Discover

Venues & riadsCaterersNeggafas & caftansPhoto & filmInspiration

Featured Cities

Agadir & SoussMarrakechCasablancaRabat–Salé–TemaraTangierFezMeknesKenitraOujdaTetouanEl JadidaSafiBeni MellalNadorLaayoune & DakhlaTaghazoutTaroudantInezgane

Professionals

Join MarasimVendor workspaceAdministrationCouple sign in

Information

Budget plannerLegal charterTerms of useData protectionQuotes & signatures
marasim

Reviewed profiles · MAD pricing · Protected data

© 2026 Base Workers SARL · All rights reserved.

Home
New
Reels
Vendors
Budget
Planning