This policy explains what personal data Azzeddine BOURAS ("we") collects through azzeTech Post, why, who we share it with, and the choices you have. We are the controller of your account data. For content and social-account data you manage in the Service, we process it on your instructions.
Controller: Azzeddine BOURAS, Hassan 1 Street 3, New City, Meknes, Morocco, privacy@azzetech.com. This processing is declared to Morocco's data-protection authority, the CNDP (Law 09-08), under declaration no. [CNDP declaration number].
1. What we collect
| Data | Where it comes from | Why we use it |
|---|---|---|
| Name, email, password (hashed), time zone | You, at sign-up; or Google if you sign in with Google (name, email, profile picture) | To create and secure your account and contact you about it |
| Workspaces, team members, invites, roles | You and your team | To run shared workspaces |
| Posts, captions, hashtags, topics, images and videos you upload or generate, schedules | You and your team | To draft, schedule and publish your posts |
| Connected social accounts: account/page/board IDs, names, usernames, profile pictures, and access tokens | The networks you connect (Meta for Facebook, Instagram and Threads; LinkedIn; Pinterest; TikTok; X), with your permission | Only to show which accounts are connected and to publish the content you schedule to them |
| Publishing results: post IDs, links, error messages | The networks | To show you what was published and what failed |
| Subscription status, plan, billing interval | Paddle, our payment provider | To apply your plan. We never see or store your card details |
| Usage counts and technical logs (IP address, browser, errors) | Your use of the Service | Security, abuse prevention, fixing problems, plan limits |
2. How we use data from social networks
- We use data received from social networks only to provide the features you use: listing your accounts, publishing your content, and showing results. We don't use it for advertising, sell it, or use it to build profiles of you or your audience.
- We don't read your private messages, followers or other people's data.
- Access tokens are encrypted at rest and never shown in the browser. Disconnecting an account deletes its tokens immediately.
- You can revoke our access at any time in each network's settings (for example, Facebook → Settings → Business integrations). Removing the app in Facebook or Threads automatically triggers deletion (see Data deletion).
3. Legal bases
- Performing our contract with you: running your account, publishing, billing.
- Legitimate interests: security, preventing abuse, improving the Service.
- Consent: where you choose to connect a social account or use optional features. You can withdraw it at any time by disconnecting.
- Legal obligations: tax and accounting records (kept by Paddle as merchant of record).
4. Who we share data with
We use these service providers, bound by data-processing terms, only to run the Service:
- Supabase: database, authentication and file storage.
- Netlify: application hosting.
- Paddle: checkout, payments, invoices and tax, as merchant of record under its own privacy policy.
- Resend: sending emails such as invitations and publishing alerts.
- AI providers (Groq, Google Gemini) receive the topic and settings you ask to write about; Pollinations and Pexels receive image descriptions or search terms. We don't send them your account details.
- The social networks you choose receive the posts you publish to them.
We may disclose data if the law requires it, or to protect our users and the Service. We don't sell personal data.
5. International transfers
Our service providers are located outside Morocco, in the European Union and the United States, so using the Service means your data is transferred there. These transfers are necessary to provide the Service you ask for (Law 09-08, article 44) and are covered by our declaration to the CNDP. Where the EU GDPR applies, transfers outside the EU rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
6. How long we keep it
- Account and workspace data: until you delete it or your account.
- Social-account tokens: until you disconnect the account, revoke access, or delete your account.
- Technical logs: up to 30 days. Backups: overwritten within 30 days of deletion.
- Billing records: kept by Paddle as required by tax law.
7. Your rights
Under Morocco's Law 09-08 you can ask to access, correct or delete your data and object to its processing; depending on where you live (for example under the EU GDPR) you may also ask to export it, restrict processing, and withdraw consent. Most of this you can do yourself in the app; otherwise email privacy@azzetech.com. We reply within 30 days. You may also complain to the CNDP (www.cndp.ma) or your local data-protection authority.
8. Cookies
We use only essential cookies: to keep you signed in and to protect sign-in flows. Your light/dark preference is stored in your browser. Paddle's checkout sets its own cookies when you open it to process a payment.
9. Security
Data is encrypted in transit; tokens are encrypted at rest; each workspace's data is isolated by database access rules. No system is perfectly secure: if a breach affects your data, we'll tell you as the law requires.
10. Children
The Service isn't directed at children under 16, and we don't knowingly collect their data.
11. Changes and contact
We'll post updates here and notify you of material changes. Contact: privacy@azzetech.com · Azzeddine BOURAS, Hassan 1 Street 3, New City, Meknes, Morocco.