Legal

Privacy Policy

Effective 2026-09-29

This policy explains what personal data Azzeddine BOURAS ("we") collects through azzeTech Post, why, who we share it with, and the choices you have. We are the controller of your account data. For content and social-account data you manage in the Service, we process it on your instructions.

Controller: Azzeddine BOURAS, Hassan 1 Street 3, New City, Meknes, Morocco, privacy@azzetech.com. This processing is declared to Morocco's data-protection authority, the CNDP (Law 09-08), under declaration no. [CNDP declaration number].

1. What we collect

DataWhere it comes fromWhy we use it
Name, email, password (hashed), time zoneYou, at sign-up; or Google if you sign in with Google (name, email, profile picture)To create and secure your account and contact you about it
Workspaces, team members, invites, rolesYou and your teamTo run shared workspaces
Posts, captions, hashtags, topics, images and videos you upload or generate, schedulesYou and your teamTo draft, schedule and publish your posts
Connected social accounts: account/page/board IDs, names, usernames, profile pictures, and access tokensThe networks you connect (Meta for Facebook, Instagram and Threads; LinkedIn; Pinterest; TikTok; X), with your permissionOnly to show which accounts are connected and to publish the content you schedule to them
Publishing results: post IDs, links, error messagesThe networksTo show you what was published and what failed
Subscription status, plan, billing intervalPaddle, our payment providerTo apply your plan. We never see or store your card details
Usage counts and technical logs (IP address, browser, errors)Your use of the ServiceSecurity, abuse prevention, fixing problems, plan limits

2. How we use data from social networks

  • We use data received from social networks only to provide the features you use: listing your accounts, publishing your content, and showing results. We don't use it for advertising, sell it, or use it to build profiles of you or your audience.
  • We don't read your private messages, followers or other people's data.
  • Access tokens are encrypted at rest and never shown in the browser. Disconnecting an account deletes its tokens immediately.
  • You can revoke our access at any time in each network's settings (for example, Facebook → Settings → Business integrations). Removing the app in Facebook or Threads automatically triggers deletion (see Data deletion).

3. Legal bases

  • Performing our contract with you: running your account, publishing, billing.
  • Legitimate interests: security, preventing abuse, improving the Service.
  • Consent: where you choose to connect a social account or use optional features. You can withdraw it at any time by disconnecting.
  • Legal obligations: tax and accounting records (kept by Paddle as merchant of record).

4. Who we share data with

We use these service providers, bound by data-processing terms, only to run the Service:

  • Supabase: database, authentication and file storage.
  • Netlify: application hosting.
  • Paddle: checkout, payments, invoices and tax, as merchant of record under its own privacy policy.
  • Resend: sending emails such as invitations and publishing alerts.
  • AI providers (Groq, Google Gemini) receive the topic and settings you ask to write about; Pollinations and Pexels receive image descriptions or search terms. We don't send them your account details.
  • The social networks you choose receive the posts you publish to them.

We may disclose data if the law requires it, or to protect our users and the Service. We don't sell personal data.

5. International transfers

Our service providers are located outside Morocco, in the European Union and the United States, so using the Service means your data is transferred there. These transfers are necessary to provide the Service you ask for (Law 09-08, article 44) and are covered by our declaration to the CNDP. Where the EU GDPR applies, transfers outside the EU rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

6. How long we keep it

  • Account and workspace data: until you delete it or your account.
  • Social-account tokens: until you disconnect the account, revoke access, or delete your account.
  • Technical logs: up to 30 days. Backups: overwritten within 30 days of deletion.
  • Billing records: kept by Paddle as required by tax law.

7. Your rights

Under Morocco's Law 09-08 you can ask to access, correct or delete your data and object to its processing; depending on where you live (for example under the EU GDPR) you may also ask to export it, restrict processing, and withdraw consent. Most of this you can do yourself in the app; otherwise email privacy@azzetech.com. We reply within 30 days. You may also complain to the CNDP (www.cndp.ma) or your local data-protection authority.

8. Cookies

We use only essential cookies: to keep you signed in and to protect sign-in flows. Your light/dark preference is stored in your browser. Paddle's checkout sets its own cookies when you open it to process a payment.

9. Security

Data is encrypted in transit; tokens are encrypted at rest; each workspace's data is isolated by database access rules. No system is perfectly secure: if a breach affects your data, we'll tell you as the law requires.

10. Children

The Service isn't directed at children under 16, and we don't knowingly collect their data.

11. Changes and contact

We'll post updates here and notify you of material changes. Contact: privacy@azzetech.com · Azzeddine BOURAS, Hassan 1 Street 3, New City, Meknes, Morocco.