Privacy policy
BrandHub collects on brandhub.ma the data it needs to answer and follow up your enquiries, to run and improve its free diagnostic, to measure the site's audience without cookies and to protect it against abuse. This page explains which data, why, how long it is kept, where it is hosted and how to exercise your rights under Moroccan Law 09-08.
Who is the data controller?
The controller of the data collected on brandhub.ma is BrandHub, the publisher of the site. BrandHub decides why and how this data is used, so it is the one to contact with any question about your personal data or to exercise your rights.
Legal identity of the controller: Brand HUB solution, auto-entrepreneur (a Moroccan sole-trader status).
For any question about your data, write to BrandHub on WhatsApp or by email, using the details on the BrandHub contact page. The legal notice of brandhub.ma gives further information on the publisher and the host of the site.
Which data is collected, and why?
BrandHub processes five kinds of data on brandhub.ma: the enquiries you send, your answers to the free diagnostic, audience measurement, protection against abuse and the WhatsApp conversations you start. The table gives, for each one, the data concerned, what it is used for and the basis for processing it.
| Processing | Data | Purpose | Basis |
|---|---|---|---|
| Contact, quote and software requests | Name, company, WhatsApp number, email (optional), city, team size, number of sales outlets, priority, system used today, message, language and page the request was sent from, where the visit came from, country and device type (mobile, tablet or computer) | Answering your request and following it up commercially | Your consent: a box you tick yourself, never ticked in advance, and a notice below the form |
| Free diagnostic | Answers about your business (sector, size, ranges), scores, estimates, page language, where the visit came from, country and device type; no name, no telephone number and no IP address | Showing your result, improving the diagnostic model and producing aggregate statistics | Anonymous data; it only becomes personal if you link it to a request, and then has the same basis as requests |
| Audience measurement | Name of the event (a click, a form being sent), page, language, channel, referring site (domain name only), campaign parameters, country and device type, with no IP address, no identifier and no cookie; plus Cloudflare Web Analytics, which also works without cookies | Knowing which pages bring enquiries | BrandHub's legitimate interest; this data is not linked to any person |
| Protection against abuse | IP address and browser signals, processed by Cloudflare Turnstile and by a rule that limits the number of submissions; BrandHub never stores them | Blocking spam and attacks | BrandHub's legitimate interest |
| WhatsApp conversations | Telephone number and the messages of the conversation you start from the site | Replying to you; when a conversation becomes a real request, BrandHub records it in its database like a request sent through a form | You start the conversation |
In the forms, required fields are marked; the others say “optional”.
Who receives your data?
Only BrandHub uses your data. To run the site, BrandHub relies on three technical providers that host or transmit this data: Cloudflare, Supabase and Resend. WhatsApp, a Meta service, is involved only if you choose to write to BrandHub that way. Part of the data is hosted or processed outside Morocco.
The database is hosted in France, and Cloudflare, Supabase and Resend run their services from outside Morocco. Law 09-08 governs these transfers of data out of Morocco, and the CNDP (Commission nationale de contrôle de la protection des données à caractère personnel), Morocco's data protection authority, oversees its application. BrandHub completes the formalities the CNDP requires for these transfers before storing any personal data in this database, whether it comes from a form on the site or from a WhatsApp conversation.
The role of each provider:
- Cloudflare: hosting of the site, spam protection and audience measurement.
- Supabase: the database that stores requests, diagnostics and measurement events, hosted in the Paris region, France.
- Resend: sending BrandHub email alerts about new requests. These alerts contain no name, telephone number, email address or message: only the type of request, the city, the choices made in the form, the scores of any diagnostic, the page the request was sent from, where the visit came from and the request's reference in the database.
- WhatsApp (Meta): the messages you send when you write to BrandHub on WhatsApp.
How long is the data kept?
BrandHub keeps each kind of personal data only as long as its purpose requires, then deletes it, automatically or by hand; anonymous diagnostic answers, which contain no name or number, are kept for statistics. Requests marked as spam go first; those of clients stay for the length of the relationship and of the accounting obligations.
| Data | Retention period | How it is deleted |
|---|---|---|
| Requests marked as spam | 30 days | Automatically, every week |
| Requests that did not lead to a client relationship | 24 months after their last update | Automatically, every week |
| Requests from people who became clients | For the whole client relationship, then for the legal accounting retention periods | By hand |
| Anonymous diagnostic answers | Kept for aggregate statistics | Not applicable: these answers contain no name or number |
| Audience measurement events | 400 days | Automatically, every week |
| WhatsApp conversations with people who are not clients | Deleted after 24 months | By hand, in the WhatsApp Business app |
You can ask for your data to be deleted before these periods end: how to do so is explained in the section on your rights, just below.
What are your rights, and how do you exercise them?
Law 09-08 gives you the right to access your data, to have it corrected and to object to its processing; BrandHub also acts on requests for deletion. To exercise any of these rights, write to BrandHub on WhatsApp or by email, saying what you want to see, correct, refuse or erase.
The details for writing to BrandHub are on the contact page. Before replying, BrandHub checks that the request really comes from you, so that your data is never handed to someone else: either it arrives from the WhatsApp number recorded with your request, or you answer a question only you can answer.
BrandHub then finds your data and gives you a copy, corrects it, stops using it or deletes it, as you asked. You receive the answer in writing, and BrandHub keeps a record of the date of the request and of what was done.
You can also contact the CNDP, the Moroccan authority responsible for overseeing the protection of personal data.
Cookies and browser storage
The brandhub.ma website sets no cookies. It keeps only three technical items in your browser's storage, with no identifier, and measures its audience without cookies. Cloudflare, which protects the site, may however set strictly technical cookies for its security checks when traffic looks suspicious.
Audience measurement works without cookies: Cloudflare Web Analytics counts visits, and BrandHub records its own events (a click on WhatsApp, a form being sent) with no identifier at all.
If measurement or advertising tools that use cookies are ever added, they will only load after you agree, and this page will be updated before they arrive.
The three items the site keeps in your browser:
- bh_touch (sessionStorage): the landing page, the name of the site you came from, the campaign parameters (UTM) and the channel of the visit, for example a search, a social network or WhatsApp. This information goes with measurement events and forms, and is erased when you close the tab.
- bh_diag (sessionStorage): your progress in the online diagnostic, also erased when you close the tab.
- bh_lang_dismissed (localStorage): remembers that you closed the bar suggesting another language of the site. It stays in your browser until you clear it.
Security and updates to this policy
The site is served over HTTPS only, and the access keys to its services are kept out of the source code. The database is closed to the public: only the site's server and BrandHub can access it, and neither measurement events nor technical logs contain personal data. Every form is protected against spam, and the accounts of the services used are secured with two-step verification.
This policy may change. The date of its last update is shown at the bottom of this page.
Updated