1. Legal framework
EnvoiSMS.ma operates under Law No. 09-08 on the protection of individuals with regard to the processing of personal data (Dahir No. 1-09-15 of 18 February 2009), its implementing Decree No. 2-09-165 and the deliberations of the National Commission for the Control of Personal Data Protection (CNDP). Morocco acceded to Council of Europe Convention 108 on 28 May 2019; our commitments are written to remain valid under the pending reform of Law 09-08 (GDPR alignment).
2. Who is responsible for what
The law distinguishes the data controller, who decides purposes and means, from the processor, who acts on the controller's instructions (Article 23).
| Party | Role (Law 09-08) | Duties |
|---|
| The customer | Controller of its contacts and messages | CNDP declaration or authorisation (Art. 12), information (Art. 5), consent to marketing (Art. 10), right to object (Art. 9), retention period, notification of transfers (Art. 43-44) |
| EnvoiSMS.ma | Processor (Art. 23) for delivery; controller for its own customer accounts, billing and logs | Act on instructions, secure, contract in writing (DPA), keep the suppression list, allow export and erasure, log access |
| Moroccan carriers (IAM, Orange, Inwi) and gateways | Sub-processors for SMS | Network delivery; data limited to number, content and delivery receipts |
| Meta / WhatsApp | Sub-processor for WhatsApp Business API | Routing and hosting of messages; its terms make the customer the Controller and include an international transfer addendum |
3. Our own processing
•Our declaration formalities for the processing we control (customer accounts, billing, support, security logs) are carried out with the CNDP in accordance with Article 12.
•Purposes are limited to providing the service: we never sell, rent or profile our customers' contact databases (Privacy Policy, DPA).
•Periods applied platform-side: routing logs and delivery receipts 30 to 90 rolling days, then purge or irreversible anonymisation; account data deleted or anonymised within 30 days of closure, accounting obligations aside.
•Security (Art. 23-24): encryption in transit and at rest, hashed secrets, named and logged access, encrypted backups, incident procedure with notification within 72 hours.
4. What the customer remains bound to do
•File the processing with the CNDP before the first send (form F214 for a framework model such as customer management — deliberation 32-2015 — or newsletters — deliberation D-940-2025; F211 outside a model; F112 for sensitive data, profiling or interconnection).
•Show the receipt number and the Article 5 notices (identity, purposes, recipients including Meta for WhatsApp, rights, contact) on every collection medium.
•Collect free, specific and informed consent before any marketing by SMS or WhatsApp (Art. 10) and keep timestamped evidence of it.
•Offer in every marketing message a simple, free means of objection (STOP) and honour it without delay (Art. 9 and 10).
•Set a retention period, declare it and respect it (Art. 55).
•Notify any transfer of data abroad with form F118, at the same time as the declaration (Art. 43-44).
5. The tooling we provide for those obligations
| Customer obligation | EnvoiSMS.ma tool |
|---|
| Proof of consent (Art. 10) | Append-only consent ledger (GET/POST /v1/consents): every grant and every withdrawal is timestamped with its source and evidence; STOP/START keywords received on WhatsApp and SMS are written automatically; CSV export per number |
| Objection (Art. 9) | Suppression list shared between SMS and WhatsApp (GET/POST/DELETE /v1/optouts), multilingual STOP keywords handled without human intervention, preventive blocking on every campaign |
| Rights of access, rectification and erasure (Art. 7-8) | Full JSON export and self-service erasure request from the dashboard, handled within 30 days |
| Written processing contract (Art. 23) | Public Data Processing Agreement and sub-processor list, changes announced 30 days in advance |
| Traceability (Art. 23-24) | API access audit log and WhatsApp Business account activity log |
| Message categories and Article 10 | Every WhatsApp template carries its Meta category (marketing, utility, authentication); the inbox separates customer-opened conversations |
6. International transfers
SMS to Morocco is delivered to the national carriers. WhatsApp Business API is provided by Meta, whose Cloud API hosts messages in the United States by default — a State absent from the list of countries with sufficient protection set by the CNDP (deliberation No. 236-2015). That transfer exists whatever the intermediary provider; we do not hide it.
•The customer, as controller, notifies this transfer to the CNDP (form F118) and grounds it on an Article 44 basis: the person's express consent, contractual necessity for service and authentication messages, or an express CNDP authorisation based on Meta's contractual clauses.
•Our Data Processing Agreement describes the roles, sub-processors and contractual clauses that apply, so it can be attached to the F118 file.
•Our guide “WhatsApp API and the CNDP” details the procedure article by article, with opt-in wordings that name the transfer.
A provider claiming that no WhatsApp data leaves Morocco describes an infrastructure Meta does not offer: Cloud API local storage is open to about ten markets, and Morocco is not one of them.
7. Exercising your rights and contacting us
Any data subject may exercise their rights of access, rectification and objection (Art. 7 to 9) by writing to [email protected]. We answer within 30 days. Where the request concerns messages sent by one of our customers, we forward it to that customer without delay, as the controller, and assist with the answer.