Data controller and contact
The data controller is the entity that determines the purposes and means of the processing activities described in this policy.
- Trade name
- Corevia Technologie
- Data controller (registered company name)
- [To be completed]
- Registered office
- [To be completed]
- Country of establishment
- Morocco
- Data protection contact point
- contact@coreviatechnologie.com
- Telephone
- +212 681 177 394
- Data protection officer (if appointed)
- [To be completed]
All questions and requests relating to personal data should be sent to the contact point above (contact@coreviatechnologie.com). Where a data protection officer is appointed, their contact details are published in the table above and, for processing subject to the GDPR, notified to the competent supervisory authority.
The contact form is intended for professional use. The website does not target minors and does not knowingly collect their data; any data submitted by a minor is deleted as soon as it is reported.
Personal data collected
The website applies the data minimisation principle: only the data strictly necessary to handle an enquiry is collected. There is no customer area, no user account and no prospect database fed from the site.
The only data you provide to us directly comes from the contact form:
- Full name
- Mandatory, to identify the person making the enquiry and personalise the reply.
- Email address
- Mandatory, to send the reply and continue the exchange.
- Telephone number
- Optional, to call you back if you wish. Leaving it blank does not prevent your enquiry from being handled.
- Subject or service concerned
- Mandatory, to route the enquiry to the relevant contact person.
- Message
- Mandatory. Free-text content written by the data subject. We recommend not including any sensitive or confidential information.
This data is not stored in any database hosted with the website: submitting the form triggers an email to the publisher's business mailbox, through an authenticated SMTP server over an encrypted connection. The data then resides in that mailbox and with the email provider.
Independently of any form, the hosting provider generates technical logs for each request:
- Connection IP address, necessary to route the response and to detect abuse.
- Request timestamp, HTTP method, requested resource address and server response code.
- User agent string sent by the browser (browser type and version, operating system).
These logs are generated and retained by the hosting provider for security, incident detection and technical operation purposes. The publisher consults them occasionally when an incident occurs and keeps no lasting copy of them.
As at the last update date shown on this page, the website implements:
- No audience measurement or web analytics tool, whether Google Analytics or any equivalent.
- No advertising cookie, no tracking pixel, no web beacon, no third-party tracker.
- No social media buttons or content loaded from a third-party server: the fonts and scripts needed for rendering are served from the site's own domain.
- No profiling, no targeted advertising, no sale, rental or commercial disclosure of data.
- No automated individual decision-making within the meaning of Article 22 GDPR.
- No collection of special category data (origin, opinions, beliefs, health, sex life, biometric or criminal data) within the meaning of Article 9 GDPR and of law no. 09-08.
Purposes and legal bases
Each processing activity pursues a defined purpose and rests on an identified legal basis. The legal bases cited are those of Article 6 GDPR. For processing governed by Moroccan law, they correspond to the lawfulness grounds set out in Article 4 of law no. 09-08: the data subject's consent or the legitimate interest pursued by the controller.
- Responding to an enquiry submitted through the contact form
- Legal basis: legitimate interest of the controller (Article 6(1)(f) GDPR), namely replying to an enquiry initiated by the data subject. Where the enquiry concerns a quotation or a proposal, the processing is necessary for steps taken at the data subject's request prior to entering into a contract (Article 6(1)(b)).
- Following up the enquiry and the exchanges arising from it
- Legal basis: legitimate interest (Article 6(1)(f) GDPR), strictly limited to the scope of the original enquiry and to follow-ups directly related to it.
- Sending unsolicited commercial communications
- Legal basis: the data subject's prior, freely given, specific and informed consent (Articles 6(1)(a) and 7 GDPR). No such communication is sent without consent, and consent may be withdrawn at any time.
- Securing the website and preventing abuse
- Legal basis: legitimate interest (Article 6(1)(f) GDPR). The processing seeks to preserve the integrity and availability of the service and to detect intrusion attempts and automated submissions.
- Technical operation, availability and incident diagnosis
- Legal basis: legitimate interest (Article 6(1)(f) GDPR), relying on the technical logs generated by the hosting provider.
- Complying with legal, accounting and tax obligations and responding to requests from authorities
- Legal basis: compliance with a legal obligation to which the controller is subject (Article 6(1)(c) GDPR) and obligations arising from applicable Moroccan legislation.
- Handling data subject requests and retaining evidence of their handling
- Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR, Chapter III) and, for retaining evidence that the request was handled, legitimate interest (Article 6(1)(f)).
Providing the data marked as mandatory is a condition for handling the enquiry: without it, the publisher cannot reply. Optional data may be omitted with no consequence whatsoever.
Where processing relies on legitimate interest, the data subject may object at any time under Article 21 GDPR; the publisher will then stop the processing unless it can demonstrate compelling legitimate grounds.
Recipients and processors
Data is never sold, rented or traded. It is accessible only to authorised staff of the publisher who need it to handle the enquiry, and to the processors listed below, which act on the controller's documented instructions within the meaning of Article 28 GDPR.
- Vercel Inc. (United States)
- Hosting, delivery and technical logging of the website. Processes the connection data required to serve the pages. The processing is framed by the provider's Data Processing Addendum.
- Email provider / outbound SMTP server (identity and country of establishment)
- [To be completed]
- Development and maintenance providers
- Where applicable, occasional and controlled access to the technical environments, strictly limited to maintenance work and subject to a confidentiality undertaking.
- Administrative and judicial authorities
- Disclosure limited to the cases provided for by law, upon a valid and reasoned request.
The email provider routes and hosts the messages generated by the form and therefore has technical access to their content. Its identity and country of establishment must be filled in the table above before the website goes live.
Transfers outside the European Union: Vercel Inc. is established in the United States, a third country within the meaning of Chapter V GDPR. Transfers to this provider are framed by the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914) incorporated into its Data Processing Addendum, where applicable supplemented by its certification under the EU-U.S. Data Privacy Framework. If the email provider is established outside the European Union, the same contractual safeguards apply to it.
In Morocco, transferring personal data to a foreign country is subject to the conditions and prior formalities set out in law no. 09-08, overseen by the National Commission for the Control of Personal Data Protection (CNDP). The references of the formalities completed are set out below.
- CNDP processing notification (number and date)
- [To be completed]
- CNDP cross-border transfer authorisation (number and date)
- [To be completed]
Retention periods
Each purpose carries a defined retention period. At the end of that period, the data is deleted or, where the law requires it, archived with restricted access.
- Enquiry with no commercial follow-up
- 12 months from the last exchange, after which the message and its copies are deleted, including from the trash and archive folders.
- Enquiry that led to a proposal or a commercial relationship
- 3 years from the last inbound or outbound contact (the customary business-to-business prospecting period), after which the data is deleted.
- Contractual documents and accounting records
- 10 years from the end of the financial year concerned, in accordance with the retention obligations applicable to accounting and commercial records in Morocco.
- Technical logs held by the hosting provider
- The retention period applied by the hosting provider under its own service, ranging from a few hours to one month depending on the type of log. The publisher keeps no lasting copy.
- Evidence of consent to marketing
- For as long as the consent remains valid, then 3 years after its withdrawal, solely in order to evidence it.
- Email address recorded on the suppression list
- 3 years, for the sole purpose of not contacting the data subject again.
- Data subject request and the reply given
- 3 years from the reply, so that the handling of the request can be demonstrated to the supervisory authority.
- Proof of identity provided in support of a request
- Deleted as soon as the verification is complete; it is never kept beyond the time needed for that verification.
Data subject rights
Every data subject has rights over the data concerning them. The applicable rights depend on the legal framework to which they are subject; in case of doubt, the publisher applies the more protective regime.
Under Regulation (EU) 2016/679 (GDPR):
- Right of access to the data processed and to the information relating to its processing (Article 15).
- Right to rectification of inaccurate or incomplete data (Article 16).
- Right to erasure of the data, in the cases provided for by the Regulation (Article 17).
- Right to restriction of processing (Article 18).
- Right to object to processing based on legitimate interest and, with no justification required, to direct marketing (Article 21).
- Right to data portability for the data you have provided, where the processing is based on consent or on a contract (Article 20).
- Right to withdraw your consent at any time, without affecting the lawfulness of processing already carried out (Article 7(3)).
- Right to lodge a complaint with a supervisory authority, in particular that of your Member State of residence, place of work or place of the alleged infringement (Article 77).
Under Moroccan law no. 09-08 on the protection of individuals with regard to the processing of personal data:
- Right to be informed of the controller's identity, the purposes pursued, whether answers are mandatory or optional, and the recipients of the data.
- Right of access to the data processed and to its communication in an intelligible form.
- Right to rectification, updating, blocking or erasure of data that is inaccurate, incomplete, ambiguous or unlawfully collected.
- Right to object, on legitimate grounds, to the processing of the data, and with no grounds required where it is used for marketing purposes.
- Right to refer the matter to the National Commission for the Control of Personal Data Protection (CNDP), the Moroccan supervisory authority, in particular where no reply or an unsatisfactory reply is received (cndp.ma).
To exercise these rights, send your request to contact@coreviatechnologie.com, stating the right invoked and, if needed, the details allowing your original enquiry to be located (date, subject). Proof of identity is not required as a matter of course: it is requested only where there is reasonable doubt as to the requester's identity, and only to the extent necessary to resolve that doubt.
A reply is provided within one month of receipt of the request. That period may be extended by up to two further months where the request is complex or where several requests are made, in which case the data subject is informed of the extension and of its reasons within one month of receipt (Article 12(3) GDPR). Exercising these rights is free of charge, except for manifestly unfounded or excessive requests.
If, after contacting us, you consider that your rights have not been respected, you may refer the matter to the competent supervisory authority: the CNDP in Morocco (cndp.ma), or the data protection authority of your country of residence within the European Union.
Data security
The publisher implements technical and organisational measures appropriate to the risks, in accordance with Article 32 GDPR. The measures actually applied to this website are as follows:
- Encryption of data in transit using TLS (HTTPS) across all pages and the contact form.
- Transmission of form messages to the mail server over an encrypted, authenticated connection (SMTP over implicit TLS).
- Storage of technical secrets, in particular the mail server credentials, in the hosting platform's encrypted environment variables, outside the source code and outside the code repository.
- Minimisation: no contact database is built from the website and no field is collected beyond those shown in the form.
- Access to the business mailbox restricted to authorised personnel only.
- Ongoing updates to the site's software stack and application dependencies.
- Hosting on infrastructure administered by the provider, which ensures the physical security, redundancy and monitoring of its data centres.
No measure can guarantee absolute security: transmitting information over the internet carries a residual risk. We therefore ask you not to send sensitive information, trade secrets, technical credentials or confidential documents through the contact form; such exchanges should use an agreed, secured channel.
In the event of a personal data breach, the publisher carries out the notifications required by Articles 33 and 34 GDPR, together with the steps required by law no. 09-08. The competent supervisory authority is informed within 72 hours where the breach poses a risk to individuals' rights and freedoms, and the data subjects are informed where that risk is high.
This section describes solely the measures applied to this presentation website. It constitutes neither a compliance attestation nor a certification of the publisher under any security framework.
Changes to this policy
This policy may be amended to reflect changes to the website, to the tools used or to the applicable legal framework. The last update date shown at the top of the page identifies the version in force.
Any material change (a new purpose, a new recipient, a new transfer outside the European Union, the introduction of a tracker or a longer retention period) will be clearly communicated before it takes effect and, where the processing relies on consent, a fresh consent will be obtained.
We recommend reviewing this page before sending any information through the contact form. For any question about this policy, write to contact@coreviatechnologie.com.
