← Back to home
Legal Document
CiteFlow is committed to the highest standards of data protection and regulatory compliance, in accordance with Moroccan law and international standards.
1. Applicable Regulatory Framework
CiteFlow operates under Moroccan law, including:
- Law 09-08 — on the protection of individuals with regard to the processing of personal data (Moroccan equivalent of GDPR)
- Dahir n° 1-06-20 — on electronic commerce in Morocco
- CNDP Guidelines — recommendations and guides from the Commission Nationale de Contrôle des Données à Caractère Personnel
2. GDPR / Law 09-08 Compliance
CiteFlow adheres to the fundamental principles of Law 09-08:
- Lawfulness, fairness, transparency — processing on a legal basis (consent for free service)
- Purpose limitation — data collected only for the stated purpose (sending audit results)
- Data minimization — only strictly necessary data is collected
- Accuracy — users may correct their data at any time
- Storage limitation — data deleted after defined retention periods in the privacy policy
- Integrity and confidentiality — appropriate technical and organizational measures
- Accountability — register of processing activities maintained and available to CNDP
3. Data Processing Agreements (DPA)
For future paying clients, CiteFlow will provide a Data Processing Agreement (DPA) compliant with Article 28 of the GDPR / Article 8 of Law 09-08.
The DPA will define:
- The nature and purpose of processing
- Data types and categories of data subjects
- CiteFlow's obligations and responsibilities as a data processor
- Technical and organizational security measures
- Sub-processing and data transfer conditions
To request a DPA, contact: contact@citeflow.ma
4. Security Measures
CiteFlow implements the following technical and organizational security measures:
- Encryption in transit — HTTPS/TLS for all communications
- Encryption at rest — sensitive data encrypted in the database
- Access control — principle of least privilege, strong authentication for admin access
- Backups — automatic daily encrypted backups
- Vulnerability management — regular security updates, vulnerability scanning
- Logging — access and activity logs retained for 90 days
- Incident response plan — documented procedure for responding to security breaches
5. Data Breach Response Procedure
Pursuant to Law 09-08, CiteFlow maintains a documented incident response procedure:
- Detection — identify and confirm the breach within 24 hours
- Assessment — analyze the nature and extent of affected data within 48 hours
- CNDP notification — within 72 hours if the risk is confirmed (Art. 10, Law 09-08)
- Data subject notification — if the risk is high, as soon as possible
- Remediation — corrective measures to eliminate the cause and limit damage
- Post-incident — review and improve security measures
6. Audit and Inspection Rights (paying clients)
For paying clients, CiteFlow provides the following:
- Compliance attestation — annual report on security measures implemented
- Audit request right — for Enterprise clients, ability to request an independent security audit (at client's expense)
- SOC 2 Type II compliance report — in preparation for 2026
These rights will be formalized in the service contract for paying clients.
7. Sub-processor List
Currently, CiteFlow does not use third-party sub-processors for personal data processing. Potential sub-processors for future services include:
- OpenAI — audit data processing (on our behalf, data not used for training)
- Postmark / AWS SES — transactional email delivery
- Stripe — payment processing (if applicable)
Any new sub-processor will be listed here and clients will be notified by email 30 days before addition.
8. Compliance Certification
✓ CiteFlow confirms compliance with Law 09-08 on the protection of personal data.
This statement is regularly updated and reviewed at least annually or upon any significant change in data processing.
For any questions regarding compliance, contact: contact@citeflow.ma