Data controller
The controller for data collected through this site is:
- Company name
- SWIFT CAP SARL
- Legal form
- Société à responsabilité limitée (SARL)
- Registered office
- 19 Rue de Melilia, Oujda, Maroc
- Share capital
- 100 000 MAD
- Commercial register
- 40493 — Tribunal de Commerce d’Oujda
- ICE number
- 003210496000076
- Tax identifier
- 53574595
- Publication director
- Mohamed Bennaceur
- Contact
- info@swiftcapsarl.com · +212 661 593 149
For any question about your data, write to the contact address above. We answer within thirty days, the period set by Law 09-08.
What we collect
We collect only what we need in order to reply. We do not buy prospect lists and we do not sell data.
- Contact form
- First and last name, email address, and — if you provide them — phone and company. The service concerned, budget band, timeline and your message. We also record the date of your consent, the page you wrote from, the traffic source (UTM parameters, referrer) and your IP address.
- Diagnostic tools
- The security analyser and the DNS checker store nothing. The domain you enter is processed in memory to produce the report, then discarded. No result is saved or linked to you.
- Client or internal account
- Email address and role. Authentication is handled by our provider Supabase: your password is never transmitted to us in clear text and we have no access to it.
- Technical logs
- IP address and timestamp, used to limit abuse (a form submitted in a loop, automated calls to the tools). These counters are aggregated and purged.
Why the IP address: it distinguishes a real enquiry from an automated submission. It is personal data and is treated as such.
Purposes and legal basis
- Answering your enquiry
- Consent, collected through a checkbox that is not pre-ticked, or pre-contractual steps taken at your request.
- Delivering and invoicing an engagement
- Performance of the contract and statutory accounting obligations.
- Preventing abuse of forms and tools
- Legitimate interest in keeping the service available. The measure is limited to a count per address per time window.
- Security and traceability of internal access
- Legitimate interest and the duty to keep data secure. Administrative actions are logged.
We carry out no automated decision-making with legal effect for you, and no advertising profiling.
Retention periods
- Enquiry that led nowhere
- Three years from the last exchange.
- Client file
- Duration of the engagement, then three years.
- Accounting records and invoices
- Ten years, as required by Moroccan accounting rules. This period cannot be shortened at your request.
- Anti-abuse counters
- Thirty days.
- Internal access audit logs
- Twelve months.
These are maximums. Data whose purpose is exhausted is deleted sooner.
Recipients and processors
Your data is accessible only to the SWIFT CAP SARL staff who need it, and to the following technical providers, acting on our instructions:
- Supabase Inc.
- Base de données et authentificationUnion européenne (AWS eu-west-3, Paris)
- Hostinger International Ltd.
- Hébergement applicatifUnion européenne
We do not sell, rent or trade any data. Disclosure to a third party can occur only on the order of a judicial authority.
Transfers outside Morocco
Our data is hosted in the European Union. Transfer outside Morocco is governed by article 43 of Law 09-08 and requires an adequate level of protection, which the European Union provides. No transfer to any other country takes place without a legal basis and without updating this policy.
Your rights
Law 09-08 gives you rights you may exercise at any time, free of charge:
- Access — confirm that data about you is processed, and receive a copy.
- Rectification — have inaccurate, incomplete or outdated data corrected.
- Objection — object to processing on legitimate grounds, and without giving reasons where the processing is direct marketing.
- Erasure — have data deleted where its retention is no longer justified.
- Withdrawal of consent — at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise a right, write to us stating what you are asking for. We may request proof of identity where there is reasonable doubt about who is asking — never otherwise.
If our answer does not satisfy you, you may refer the matter to the CNDP, the Moroccan data protection authority.
Security
We apply to our own data the measures we recommend to our clients:
- Encryption in transit (strict HTTPS) and at rest in the database.
- Row-level isolation in the database: every record is denied by default and readable only through explicitly authorised access.
- Authorisation checked server-side on every request, never in the browser.
- Logging of sensitive administrative actions.
- Passwords delegated to a specialised authentication provider, never stored by us.
No system is invulnerable. In the event of a breach likely to harm you, we will inform you and the CNDP.
Changes
This policy changes as the service does. The date of the last update appears at the top of the page. A substantive change — a new purpose, a new recipient — is signalled to you before it takes effect where we have a means of reaching you.