Data controller
Digital Era Solutions SARL, a limited liability company under Moroccan law, with share capital of MAD 100,000. Registered office: Résidence Al Aziza, Boulevard Royaume Arabie Saoudite, 3rd floor No. 20, Tangier, Morocco. Trade Register (RC) Tangier No. 107627 · IF No. 45953907 · ICE No. 002594794000073. (“Calendify”, “we”). Data Protection Officer: privacy@calendify.ma.
1. Applicable framework
This Policy is governed first and foremost by Moroccan Law No. 09-08 on the protection of individuals with regard to the processing of personal data, and by the decisions and authorizations of the National Commission for the Control of Personal Data Protection (CNDP). For individuals located in the European Union, the General Data Protection Regulation (GDPR) applies in addition, where relevant.
2. Who is responsible for your data
Calendify is the controller for the account, booking, and billing data we collect to operate the Service. When you book with a Professional, that Professional is a separate, independent controller for the clinical and care data they collect about you; for that data, Calendify acts as a processor (we host and process it on their behalf and on their instructions).
For any question about your data, our Data Protection Officer is reachable at privacy@calendify.ma.
3. Data we collect
Account information
- First name, last name, email address, phone number.
- A hashed password (we never see or store your password in plain text).
- For Professionals: clinic name, address, city, profession, registration/authorization number, bio, profile photo.
- For Patients: city (optional) and national ID number (CIN) only where a Professional needs to link you to an in-person walk-in record. CIN processing is limited to this purpose and included in the scope declared to the CNDP.
Appointment and health data
- Bookings (date, time, service, status, completion notes), queue positions and wait estimates, reviews you post.
- Health data: the health-related information you or the Practitioner enter as part of a consultation (reason, clinical notes) constitutes sensitive data, processed under the conditions of Section 6.
Technical data
- Device type, operating system, browser, app version; push-notification tokens, so we can send you queue updates and reminders.
Payment data
- For services paid online (Teleconsultations, Home Visits): the history and status of transactions. Card data is entered and processed directly by our Payment Service Provider; Calendify neither collects nor stores any card data (see Section 8).
4. How we use your data
- Run the Service: authenticate you, show your appointments, send reminders, show your queue position, and enable online payment of consultations.
- Communicate with you: account emails, booking confirmations, changes to our Terms, and — only if you opt in — product news.
- Improve the Service: aggregated, anonymized statistics on feature usage.
- Keep things safe: detect fraud, spam, abuse, and unauthorized access.
- Meet legal obligations: retain billing records, respond to lawful requests, and comply with tax, accounting, and data-protection law.
5. Legal basis for processing
Under Law 09-08 (and the GDPR where it applies), we rely on:
- Performance of the contract: for data needed to provide the Service (create bookings, send reminders, enable payment).
- Legitimate interest: security, fraud prevention, and Service improvement, balanced against your rights and freedoms.
- Consent: for optional marketing communications and, where required, certain analytics.
- Legal obligation: retention of fiscal and billing records, and responses to valid requests from authorities.
For health data (sensitive data), the legal basis is your explicit consent and/or the provision of medical care by a healthcare professional bound by professional secrecy, under the conditions of Section 6.
6. Health data (sensitive data)
Data relating to your health is sensitive data within the meaning of Law 09-08. Its processing by Calendify is subject to prior authorization from the CNDP, granted under number [● CNDP authorization number to be entered once granted]. This data is processed only to enable booking, the performance of the consultation by the Practitioner, and the resulting follow-up.
The Practitioner is the controller for the health data collected in the course of care; Calendify acts as a technical processor, on their instructions, and applies enhanced security measures (Section 11). Access to this data is strictly limited to the Patient concerned, the Practitioner they consulted, and, where applicable, the staff authorized by that Practitioner.
8. Payments
Payments for Teleconsultations and Home Visits are operated by a payment service provider licensed in Morocco (Payzone / Vantage Payment Systems). Card data is entered on the Payment Service Provider’s secure interface, which acts as controller for that data; Calendify does not collect, see, or store any card data. Calendify retains only the information needed to track the transaction (amount, status, date, appointment identifier) and for billing. Processing by the Payment Service Provider is governed by its own privacy policy.
9. Transfer of data outside Morocco
Some data is hosted in data centers located in the European Union (see Section 10). This transfer outside Morocco is covered by a transfer authorization issued by the CNDP under number [● CNDP transfer-authorization number to be entered once granted], to a country ensuring an adequate level of protection. Other occasional transfers (for example push notifications routed through Apple’s or Google’s global infrastructure) rely on appropriate safeguards. No data is transferred outside Morocco without the legal basis required by Law 09-08.
10. Where we store your data
Personal data is stored on managed database infrastructure operated by Supabase, in data centers located in the European Union, under the transfer conditions of Section 9.
11. How we protect your data
- Encryption in transit: all traffic is served over HTTPS (TLS 1.2+).
- Encryption at rest: the database is encrypted at rest using AES-256.
- Row-level security: every table enforces access rules at the database layer, so a user only sees the data they are authorized to see.
- Password hashing: passwords are hashed (bcrypt); we never see the originals.
- IP hashing: we never store raw IP addresses, only a salted SHA-256 hash.
- Least-privilege access: only a small number of staff can access production data, with logged and audited access.
12. How long we keep your data
- Account data: as long as your account is active, plus 30 days after closure (to allow reactivation).
- Appointment data: kept while your relationship with the Professional is active; after closure, the Professional may be required to retain clinical records longer, independently of Calendify.
- Billing and invoices: kept for 10 years, as required by Moroccan accounting law.
- Analytics events: up to 24 months, in anonymized form.
- Backups: encrypted snapshots kept for 30 days for disaster recovery, then deleted.
13. Your rights
Under Law 09-08 (and the GDPR where it applies), you have the rights of access, rectification, erasure (subject to legal retention obligations), portability, restriction, and objection, as well as the right to withdraw your consent at any time. To exercise them, email privacy@calendify.ma from the address associated with your account; we respond within 30 days.
You may also lodge a complaint with the CNDP, or with your local supervisory authority if you are in the EU.
14. Data breach
We have measures in place to detect, contain, and address any data breach. In the event of a breach likely to affect your rights, we undertake to notify the CNDP and the individuals concerned as soon as possible, and to describe the measures taken to address it.
15. Minors
The Service is reserved for adults (18 years). Appointments for a minor are booked and managed by their legal representative, from that representative’s account, who is responsible for the information shared on the minor’s behalf. We do not knowingly collect data about a minor outside this framework.
17. Analytics
Product analytics events are recorded in our own infrastructure (hosted on Supabase, in the EU) and are not sent to third parties such as Google Analytics or Facebook. They contain the event name, a few properties, the anonymous session ID, a coarse geo hint (country), and a hashed IP. To be excluded from analytics entirely, email privacy@calendify.ma.
18. Changes to this Policy
We update this Policy when our practices or regulations change. When we do, we update the date at the top of the page and, for material changes, notify you by email or in-app. Continuing to use the Service after a change takes effect constitutes acceptance.
19. Contact
For any question, concern, or request to exercise your rights:
- Data protection / DPO: privacy@calendify.ma
- Security: security@calendify.ma
- General questions: hello@calendify.ma