Privacy Commitment
Marasim complies with Moroccan Law 09-08, CNDP guidelines, and GDPR standards.
Compliance with Moroccan Law 09-08 and GDPR standards
Marasim complies with Moroccan Law 09-08, CNDP guidelines, and GDPR standards.
Account details, event information, guest RSVP lists, and technical logs. Card data is processed via CMI without storage on Marasim servers.
Service delivery, WhatsApp OTP verification, ERP management, and B2B billing.
Marasim strictly never sells, rents, or monetizes personal data or guest lists.
Immediate soft-deletion from public views, followed by automated permanent deletion after 30 days.
Access, rectify, or erase your data by contacting: privacy@marasim.ma.
Marasim uses secure cloud infrastructure to deliver the service: the database and identity service are deployed in a specific European Union region (Frankfurt, Paris, or Ireland), while files, documents, and contracts are stored in Cloudflare R2 buckets with the EU jurisdiction restriction.
Data is encrypted in transit using SSL/TLS, R2 objects are automatically encrypted at rest, and private documents are isolated with PostgreSQL Row Level Security (RLS) controls.
Essential session, language, and anonymized analytics cookies.
Approval of the underlying CNDP processing declaration or authorization, followed by the F-118 application for transfers abroad, are production-launch conditions for personal-data processing. Receipt or authorization references will be published here after they are issued; this wording does not claim that approval has already been obtained.
Marasim selects Ireland (eu-west-1) as Resend's email-sending region. Resend states that account data, email metadata, logs, and API records remain stored in the United States regardless of sending region. That transfer is governed by Resend's DPA and Standard Contractual Clauses (SCCs) and must be identified explicitly in the F-118 filing.
Marasim must execute the applicable Supabase, Cloudflare, and Resend DPAs and contractual transfer safeguards before launch.