1. Who We Are
Customer Obsession SARL ("we", "us", "our") is a Moroccan company headquartered at 4 ème étage, Bureau 62, Centre d'affaire Malizia, Casablanca. We operate five digital brands: CloudLink, Toutsuite, Twily, Jungle, and Sure. This policy explains how we collect, use, and protect your personal data in compliance with Morocco's Law 09-08 (CNDP) and the EU General Data Protection Regulation (GDPR).
2. What Data We Collect
We collect information you provide directly (name, email, phone, company name), technical data (IP address, browser type, pages visited), and usage data (features used, clicks, session duration). We never sell your personal data to third parties.
3. How We Use Your Data
Your data is used to provide and improve our services, communicate important updates, process transactions, prevent fraud, and comply with legal obligations. Marketing communications are only sent with your explicit consent.
4. Legal Basis for Processing
We process your data under the following legal bases: (a) Contract performance — to provide services you have requested; (b) Legitimate interest — to improve our platforms and prevent fraud; (c) Consent — for marketing and non-essential cookies; (d) Legal obligation — to comply with tax, regulatory, and law enforcement requirements.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Upon account deletion, we purge personal data within 30 days, except where we are legally required to retain it. Financial records are kept for 10 years per Moroccan tax law. Audit logs are retained for 5 years.
6. Your Rights
You have the right to access, correct, or delete your personal data. You may also object to processing, request a portable copy of your data, or withdraw consent at any time. Contact us at
[email protected] to exercise your rights. We respond within 30 days.
7. Cookies
We use essential cookies for authentication and session management, and optional analytics cookies. You can manage your cookie preferences at any time via our Cookie Settings panel. See our dedicated Cookie Policy for full details.
8. International Transfers
If your data is transferred outside Morocco or the EEA, we ensure adequate safeguards are in place through Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the CNDP.
9. Data Security
Technical and organizational security measures are selected for the relevant service. Applicable security responsibilities and regulated or contractual requirements are documented for the engagement.
10. Data Breach Notification
In the event of a personal data breach, we will notify the CNDP within 72 hours and affected individuals without undue delay, in accordance with GDPR Article 33 and Moroccan data protection regulations.
11. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we discover we have inadvertently collected data from a child, we will promptly delete it.
12. Automated Decision-Making
Some of our services (particularly Sure's vendor trust scoring) use automated decision-making. You have the right to request human review of any automated decision that significantly affects you.
13. Third-Party Services
We may use third-party services for analytics, payment processing, and communication. These providers are contractually obligated to protect your data and use it only for our stated purposes. Our current sub-processors include: AWS (hosting), Stripe (payments), SendGrid (email), and Cloudflare (CDN).
14. Changes to This Policy
We may update this policy periodically. Material changes will be communicated via email and prominent website notice. The "Last updated" date at the top of this page indicates when it was last revised.
15. Contact
For privacy inquiries:
[email protected]
Data Protection Officer:
[email protected]
Customer Obsession SARL
4 ème étage, Bureau 62, Centre d'affaire Malizia, Casablanca 20000, Morocco
Phone: +212 605713080
This document is published by Customer Obsession SARL, registered in the Kingdom of Morocco. Last updated: January 1, 2026. All rights reserved. For inquiries: [email protected] · DPO: [email protected] · Security: [email protected] · 4 ème étage, Bureau 62, Centre d'affaire Malizia, Casablanca 20000, Morocco
Download this document
PDFDOCX
Document Version History
3.0January 1, 2026
Major update: Added CNDP alignment, expanded data breach procedures, SLA formalization.
2.1July 15, 2025
Minor update: Updated sub-processor list, clarified cookie retention periods.
2.0January 1, 2025
GDPR alignment update, added accessibility statement, expanded privacy rights.
1.0June 1, 2024
Initial publication of all legal documents.
Language Notice
This document is available in English, French, and Arabic. In the event of any discrepancy between language versions, the French version shall prevail for Moroccan operations, and the English version for international operations. Translations are provided for convenience only.
Applicability by Brand
CloudLink: Additional enterprise SLA terms may apply for dedicated infrastructure clients.
Toutsuite: Moroccan fiscal compliance addendum applies to all ERP clients.
Twily: Legal service retainer agreements supersede general terms where applicable.
Jungle: Web development project terms are governed by individual SOWs.
Sure: Marketplace terms of sale apply between buyers and vendors independently.
Jurisdiction & Governing Law
Morocco
Law 09-08 (Data Protection), Code de Commerce
Casablanca Commercial Court
European Union
GDPR (Regulation 2016/679)
Local competent court per consumer domicile
United States
CCPA, State consumer protection laws
State of Delaware courts