1. Introduction
This Privacy Policy describes how Mujtahid processes personal data in connection with the Services.
Mujtahid is designed for private schools, institutes, training centers, and similar educational organizations in Morocco. This policy is drafted to support alignment with Moroccan Law No. 09-08 relating to the protection of individuals with regard to the processing of personal data and with the guidance and supervision of the CNDP.
2. Scope
- Organizations subscribing to the Services;
- principals, assistants, teachers, students, and staff using a tenant;
- website visitors, demo contacts, and support contacts;
- personal data processed for platform operations, communications, billing, support, and security.
3. Categories of Data Collected
- Student data such as names, identifiers, attendance, class assignments, academic records, behavior notes, contact data, and payment-related records entered by the Organization.
- Staff data such as names, roles, branch assignments, schedules, credentials, contact details, and activity records for principals, assistants, teachers, and staff.
- Organization data such as organization name, branches, billing contact details, subscription information, and account configuration.
- Usage and device data such as IP addresses, browser data, device information, system logs, timestamps, access events, and security signals.
- Communications and support data such as support requests, email communications, and onboarding records.
4. How Data Is Collected
- directly from the Organization, Principal, or Users;
- through manual entry, file imports, uploads, edits, and updates made within a tenant;
- automatically through platform logs, authentication events, security monitoring, and technical telemetry;
- from payment providers, email providers, hosting providers, and other service providers used to operate the Services.
5. Purposes of Processing
- to provide, host, maintain, and secure the Services;
- to manage tenant accounts, authentication, and permissions;
- to enable class, staff, student, and payment workflows configured by the Organization;
- to communicate with Organizations and Users about the Services;
- to issue invoices, process subscriptions, and track payments owed to Mujtahid;
- to provide technical support and resolve incidents;
- to detect misuse, fraud, suspicious activity, or security threats;
- to comply with legal obligations and protect rights and safety.
6. Legal/Operational Basis
For tenant data, the Organization is generally responsible for determining the lawful basis or legal justification for processing personal data under applicable Moroccan law and CNDP requirements.
Mujtahid processes such data on the Organization's instructions as a processor or service provider, except where Mujtahid must process data for its own legal compliance, billing, fraud prevention, or security purposes.
Where required, the Organization must ensure that valid consent has been obtained, especially for minors or categories of processing for which consent or express authorization is required.
7. Role of Mujtahid vs Role of the Organization
For personal data stored or processed within a tenant, the Organization is the Data Controller or responsable du traitement. The Organization decides what data is collected, why it is collected, which persons are concerned, how long it should be kept, and which users may access it.
Mujtahid acts as the Data Processor, sous-traitant, or service provider for that tenant data. Mujtahid processes tenant data to host, secure, maintain, organize, transmit, and support the Services in accordance with the Organization's instructions, contract terms, and applicable law.
9. International Transfers
If personal data is stored, accessed, or transferred outside Morocco, Mujtahid and the Organization must evaluate whether Moroccan law, CNDP requirements, contractual safeguards, or prior authorization apply. Where needed, the Organization remains responsible for ensuring that required cross-border formalities are satisfied.
10. Data Security
Mujtahid uses reasonable technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, destruction, and loss. Measures may include role-based access controls, tenant segregation, credential protections, encryption in transit, logging, backups, and incident response procedures.
No system can guarantee absolute security. Organizations also remain responsible for their own credential management, internal permissions, endpoint security, and lawful access practices.
11. Data Retention
Mujtahid retains personal data only for as long as reasonably necessary to provide the Services, fulfill contractual obligations, maintain security, preserve backups, resolve disputes, enforce agreements, and comply with law.
For tenant data, retention is generally driven by the Organization's instructions, contractual arrangements, and applicable legal obligations. After termination, data may be deleted, anonymized, or rendered inaccessible after a reasonable export or transition period, subject to backups, legal holds, and security requirements.
12. Student and Minor Data
Mujtahid may process student and minor data only as part of providing the Services to Organizations. The Organization is responsible for determining whether the collection and use of such data are lawful and for obtaining any parental, guardian, or institutional permissions required by Moroccan law or CNDP guidance.
The Organization must ensure that only data reasonably necessary for legitimate educational or operational purposes is uploaded and that required notices are provided to parents, guardians, students, and staff where applicable.
14. User Rights and Requests
Depending on applicable law and Mujtahid's role in the relevant processing, individuals may have rights of access, rectification, deletion, blocking, objection, or complaint.
Where a request relates to tenant data controlled by an Organization, the request should normally be directed first to that Organization. Mujtahid may assist the Organization as a processor where appropriate.
15. Changes to Privacy Policy
Mujtahid may update this Privacy Policy from time to time. The updated version becomes effective when posted or otherwise communicated. Continued use of the Services after an update means the revised policy applies to future use, subject to applicable law.
16. Contact Information
For privacy questions, CNDP-related inquiries, or data rights requests, contact Mujtahid by email at elgadaymane@gmail.com or by phone at 06 80 09 30 03.
In short
- Your organization generally decides why tenant data is collected and used, so it acts as the Data Controller under Law No. 09-08.
- Mujtahid generally processes that tenant data only to host, secure, support, and operate the platform as a processor or service provider.
- Your organization must provide required notices, determine the lawful basis, and obtain parental or guardian permission where required for minors.
- Mujtahid uses service providers only as needed for hosting, security, support, communications, and billing.
- Tenant data is logically isolated, and unauthorized access across organizations is prohibited.
- Rights requests about student or staff data usually need to be handled first by the organization that controls that tenant.