CNDP Compliance
certify.ma is fully compliant with Morocco's Law 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data.
Lawful Processing (Art. 3)
All personal data is processed on a lawful basis: consent for student accounts, contractual necessity for institutional accounts, and legitimate interest for security monitoring.
Purpose Limitation (Art. 3)
Data is collected exclusively for credential issuance, storage, verification, and sharing. It is never used for advertising, profiling, or purposes beyond those stated.
Data Minimization (Art. 3)
We collect only the minimum data required: name, email, institution, and credential metadata. No biometric data, no social media profiles, no financial data beyond billing.
Right to Access (Art. 7)
Users can request a complete copy of their personal data at any time via their account settings or by contacting [email protected].
Right to Rectification (Art. 8)
Users can request correction of inaccurate data. Institutions can update credential metadata through the admin portal.
Right to Erasure (Art. 9)
Users can request account deletion. Personal data is erased within 30 days. Credential hashes are retained for verification integrity (anonymized).
Data Security (Art. 23)
AES-256 encryption at rest, TLS 1.3 in transit, bcrypt password hashing, role-based access control, and regular penetration testing.
Cross-Border Transfer (Art. 43)
Production data is hosted in Morocco (OVH Casablanca). No cross-border transfer occurs without adequate safeguards and CNDP notification.
Data Breach Notification (Art. 24)
In the event of a data breach, the CNDP will be notified within 72 hours. Affected users will be notified immediately with remediation steps.
CNDP Registration (Art. 12)
certify SAS has filed a declaration with the Commission Nationale de contrôle de la protection des Données à caractère Personnel.
Data Protection Officer
For all CNDP-related inquiries, data access requests, or complaints:
certify SAS · Technopark · Casablanca 20000 · Morocco

