Swift·Cap

Updated 27 July 2026

Privacy policy

What we collect, why, how long we keep it, and how to exercise your rights. Written to be read, not skimmed.

Data controller

The controller for data collected through this site is:

Company name
SWIFT CAP SARL
Legal form
Société à responsabilité limitée (SARL)
Registered office
19 Rue de Melilia, Oujda, Maroc
Share capital
100 000 MAD
Commercial register
40493Tribunal de Commerce d’Oujda
ICE number
003210496000076
Tax identifier
53574595
Publication director
Mohamed Bennaceur

For any question about your data, write to the contact address above. We answer within thirty days, the period set by Law 09-08.

What we collect

We collect only what we need in order to reply. We do not buy prospect lists and we do not sell data.

Contact form
First and last name, email address, and — if you provide them — phone and company. The service concerned, budget band, timeline and your message. We also record the date of your consent, the page you wrote from, the traffic source (UTM parameters, referrer) and your IP address.
Diagnostic tools
The security analyser and the DNS checker store nothing. The domain you enter is processed in memory to produce the report, then discarded. No result is saved or linked to you.
Client or internal account
Email address and role. Authentication is handled by our provider Supabase: your password is never transmitted to us in clear text and we have no access to it.
Technical logs
IP address and timestamp, used to limit abuse (a form submitted in a loop, automated calls to the tools). These counters are aggregated and purged.

Why the IP address: it distinguishes a real enquiry from an automated submission. It is personal data and is treated as such.

Purposes and legal basis

Answering your enquiry
Consent, collected through a checkbox that is not pre-ticked, or pre-contractual steps taken at your request.
Delivering and invoicing an engagement
Performance of the contract and statutory accounting obligations.
Preventing abuse of forms and tools
Legitimate interest in keeping the service available. The measure is limited to a count per address per time window.
Security and traceability of internal access
Legitimate interest and the duty to keep data secure. Administrative actions are logged.

We carry out no automated decision-making with legal effect for you, and no advertising profiling.

Retention periods

Enquiry that led nowhere
Three years from the last exchange.
Client file
Duration of the engagement, then three years.
Accounting records and invoices
Ten years, as required by Moroccan accounting rules. This period cannot be shortened at your request.
Anti-abuse counters
Thirty days.
Internal access audit logs
Twelve months.

These are maximums. Data whose purpose is exhausted is deleted sooner.

Recipients and processors

Your data is accessible only to the SWIFT CAP SARL staff who need it, and to the following technical providers, acting on our instructions:

Supabase Inc.
Base de données et authentificationUnion européenne (AWS eu-west-3, Paris)
Hostinger International Ltd.
Hébergement applicatifUnion européenne

We do not sell, rent or trade any data. Disclosure to a third party can occur only on the order of a judicial authority.

Transfers outside Morocco

Our data is hosted in the European Union. Transfer outside Morocco is governed by article 43 of Law 09-08 and requires an adequate level of protection, which the European Union provides. No transfer to any other country takes place without a legal basis and without updating this policy.

Your rights

Law 09-08 gives you rights you may exercise at any time, free of charge:

  • Access — confirm that data about you is processed, and receive a copy.
  • Rectification — have inaccurate, incomplete or outdated data corrected.
  • Objection — object to processing on legitimate grounds, and without giving reasons where the processing is direct marketing.
  • Erasure — have data deleted where its retention is no longer justified.
  • Withdrawal of consent — at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise a right, write to us stating what you are asking for. We may request proof of identity where there is reasonable doubt about who is asking — never otherwise.

If our answer does not satisfy you, you may refer the matter to the CNDP, the Moroccan data protection authority.

Security

We apply to our own data the measures we recommend to our clients:

  • Encryption in transit (strict HTTPS) and at rest in the database.
  • Row-level isolation in the database: every record is denied by default and readable only through explicitly authorised access.
  • Authorisation checked server-side on every request, never in the browser.
  • Logging of sensitive administrative actions.
  • Passwords delegated to a specialised authentication provider, never stored by us.

No system is invulnerable. In the event of a breach likely to harm you, we will inform you and the CNDP.

Changes

This policy changes as the service does. The date of the last update appears at the top of the page. A substantive change — a new purpose, a new recipient — is signalled to you before it takes effect where we have a means of reaching you.