1. Introduction
ABRID SOLUTIONS SARL (“Abrid”, “we”) attaches great importance to protecting the privacy and personal data of the people who use its platform and services.
This Privacy Policy explains what data we collect, why, how we use it, with whom we share it, how long we keep it, and what your rights are. It applies to our website, our SaaS platform and all of our services.
Controller: ABRID SOLUTIONS SARL, a limited liability company (société à responsabilité limitée) with registered office at Immeuble A, 3ème étage, Bureau n° A34, Borj Malak, Route de Safi, Marrakech, Maroc — ICE: 003510690000061.
For any question relating to this Policy or to your data, you may contact us at contact@abrid.io.
2. Our dual role: controller and processor
Depending on the context, Abrid acts in two distinct capacities:
- As controller: for data we collect directly on our own behalf — creating and managing the accounts of our professional clients and their users, invoicing, business development, support, and browsing on our website.
- As processor: for data that our professional clients (agencies, DMCs, tour operators) enter into the platform about their own clients and travellers. In that case our client is the controller and we act on its instructions. Individuals whose data this is must exercise their rights with the agency or business that collected it.
3. Data we collect
This Policy mainly describes the processing for which Abrid acts as controller. Processing carried out on behalf of our clients is governed by the service contract and, where applicable, by a separate data processing agreement.
We collect the following categories of data:
- Account and identification data: first and last name, business email address, telephone number, job title, company name, login credentials.
- Billing data: company name, address, tax identifiers, bank details, subscription and payment history.
- Data entered into the platform: content created by the user (quotations, trips, bookings, invoices, contacts, suppliers), including where applicable data relating to travellers — processed as a processor on behalf of the client.
- Technical and connection data: IP address, browser and device type, connection logs, pages viewed, timestamps, and data from cookies and trackers.
- Communication and support data: email exchanges, support requests, feedback and messages you send us.
4. Purposes and lawful bases
We use this data for the following purposes:
- Provision of the service: creating and managing accounts, enabling access to the platform and its features (performance of the contract).
- Invoicing and administration: issuing invoices, tracking payments and meeting our accounting and tax obligations (performance of the contract and legal obligation).
- Support and improvement: responding to assistance requests, resolving incidents, improving the security and performance of the service (legitimate interest).
- Communication: informing you of changes to the service and, with your consent where required, sending you commercial communications (consent or legitimate interest).
- Security and fraud prevention: securing the platform and preventing abuse (legitimate interest and legal obligation).
7. Hosting and transfers outside Morocco
We do not sell your personal data and do not rent it to third parties for advertising purposes. Our providers acting as processors are bound by contractual confidentiality and security undertakings.
Depending on the technical configuration of our infrastructure, certain data may be hosted or processed outside Morocco by our providers. In that case we ensure that such transfers are covered by appropriate safeguards providing an adequate level of data protection, in accordance with the applicable regulations.
8. Retention
We keep your data only for as long as necessary for the purposes for which it was collected:
- Account and usage data: for the duration of the contractual relationship, then deleted or anonymised within a reasonable period after the end of the contract.
- Billing and accounting data: kept for the period required by the accounting and tax obligations in force.
- Technical data and connection logs: kept for a limited period for security and diagnostic purposes, not exceeding twelve (12) months.
- Data entered into the platform (travellers, clients): kept for as long as our client uses it, then returned or deleted in accordance with its instructions and the terms of the service contract.
9. Data security
We implement appropriate technical and organisational measures to protect your data against loss, alteration, disclosure or unauthorised access: access control, encryption of communications, separation of environments, regular backups and logging.
Despite these measures, no system being infallible, we cannot guarantee absolute security. In the event of a breach likely to create a risk for the individuals concerned, we take the required measures and inform the affected parties as soon as possible.
10. Your rights
In accordance with the applicable data protection regulations, you have the following rights over your personal data:
- Right of access: to obtain confirmation that data concerning you is being processed and to receive a copy of it.
- Right of rectification: to have inaccurate or incomplete data corrected.
- Right of erasure: to request deletion of your data, within the limits of statutory retention obligations.
- Right to object: to object, on legitimate grounds, to certain processing, in particular to direct marketing.
- Right to restriction and portability: to request restriction of processing or the return of your data in a structured format.
11. Exercising your rights
To exercise these rights, write to us at contact@abrid.io, specifying your request. We may ask you for proof of identity and will respond within a reasonable period.
If your data was entered into the platform by a client agency or business, your request must be addressed directly to that organisation, which is the controller for that processing.
12. Minors’ data
The service is intended for professionals and is not designed to collect data from minors. Where data relating to minor travellers is entered by our clients in the course of their business, it is entered under the responsibility and control of those clients.
13. Changes to this Policy
We may update this Policy to reflect changes to our services or to the regulations. Any material change will be brought to your attention by an appropriate means (email or publication on our website). The applicable version is the one published on the date you use the service.
14. Contact
For any question, request or complaint relating to your personal data, you may contact us:
- By email: contact@abrid.io
- By post: ABRID SOLUTIONS SARL, Immeuble A, 3ème étage, Bureau n° A34, Borj Malak, Route de Safi, Marrakech, Maroc