← Back to home
Legal Document

CiteFlow is committed to the highest standards of data protection and regulatory compliance, in accordance with Moroccan law and international standards.

1. Applicable Regulatory Framework

CiteFlow operates under Moroccan law, including:

2. GDPR / Law 09-08 Compliance

CiteFlow adheres to the fundamental principles of Law 09-08:

3. Data Processing Agreements (DPA)

For future paying clients, CiteFlow will provide a Data Processing Agreement (DPA) compliant with Article 28 of the GDPR / Article 8 of Law 09-08.

The DPA will define:

To request a DPA, contact: contact@citeflow.ma

4. Security Measures

CiteFlow implements the following technical and organizational security measures:

5. Data Breach Response Procedure

Pursuant to Law 09-08, CiteFlow maintains a documented incident response procedure:

  1. Detection — identify and confirm the breach within 24 hours
  2. Assessment — analyze the nature and extent of affected data within 48 hours
  3. CNDP notification — within 72 hours if the risk is confirmed (Art. 10, Law 09-08)
  4. Data subject notification — if the risk is high, as soon as possible
  5. Remediation — corrective measures to eliminate the cause and limit damage
  6. Post-incident — review and improve security measures

6. Audit and Inspection Rights (paying clients)

For paying clients, CiteFlow provides the following:

These rights will be formalized in the service contract for paying clients.

7. Sub-processor List

Currently, CiteFlow does not use third-party sub-processors for personal data processing. Potential sub-processors for future services include:

Any new sub-processor will be listed here and clients will be notified by email 30 days before addition.

8. Compliance Certification

✓ CiteFlow confirms compliance with Law 09-08 on the protection of personal data.

This statement is regularly updated and reviewed at least annually or upon any significant change in data processing.

For any questions regarding compliance, contact: contact@citeflow.ma