Article 1 — Purpose and roles
This Data Processing Agreement ("DPA") governs the processing of personal data that EnvoiSMS.ma carries out on behalf of its customers within the framework of the Service (message sending, OTP verification, contact management). For that processing, the customer is the Controller and EnvoiSMS.ma acts as Processor, within the meaning of Moroccan loi n° 09-08 and, where it applies, of Article 28 GDPR.
This DPA forms an integral part of the CGV/CGU. A countersigned copy may be requested at
[email protected] for the purposes of your own compliance records.
Article 2 — Data processed and purposes
- Categories of data: recipients' telephone numbers, message content, contact identifiers (name, custom attributes) imported by the customer, technical routing metadata.
- Data subjects: the recipients of the customer's communications (end customers, users, prospects who have consented).
- Exclusive purpose: the performance of the Service ordered by the customer — routing of messages, OTP verification, management of unsubscriptions and return of the logs to the customer.
- EnvoiSMS.ma processes this data on no instruction other than those of the customer, expressed through their API calls and their configuration, and never uses it for its own purposes (no advertising, no resale, no profiling).
Article 3 — Duration and retention
- The DPA applies for the entire duration of the customer account.
- Message logs are retained for the periods indicated in the Privacy Policy, then purged automatically.
- On closure of the account, the personal data processed on behalf of the customer is deleted or anonymised within 30 days — with the exception of billing data subject to Moroccan legal accounting obligations, which is retained for the required period.
Article 4 — Security measures
- Encryption in transit (TLS) on all exchanges, and encryption at rest on the storage infrastructure.
- Sensitive secrets (OTP codes, TOTP secrets) are stored hashed or encrypted (AES-256); API keys are retained only in hashed form.
- Logging and auditing of access (API audit log, log of administration actions attributed to their author).
- Strict partitioning of data by customer account; IP address allow-lists available per API key.
- Principle of least privilege for internal access, limited to the strictly necessary operational team.
Article 5 — Sub-processing
- The customer gives general authorisation to the use of the sub-processors appearing on the Sub-processor List published at https://envoisms.ma/en/legal/subprocessors/.
- EnvoiSMS.ma imposes on each sub-processor data protection obligations equivalent to those of this DPA.
- Any substantial change to that list is announced at least 30 days before it takes effect (notification by email or in the dashboard). The customer may object in writing; failing a solution, they may close their account before it takes effect.
Article 6 — Assistance and data subject rights
- EnvoiSMS.ma forwards to the customer without delay any request to exercise rights (access, rectification, erasure, objection) received directly from a data subject, without responding to it itself unless legally obliged.
- The platform provides the customer with the necessary tools: log export, contact deletion, automatic management of unsubscriptions (STOP), full export of the account data from the dashboard.
- EnvoiSMS.ma reasonably assists the customer with their impact assessments and their security obligations, taking into account the nature of the processing.
Article 7 — Breach notification
EnvoiSMS.ma notifies the customer, as soon as possible and at the latest 72 hours after becoming aware of it, of any personal data breach affecting the data processed on their behalf, documenting the nature of the breach, the categories of data concerned and the measures taken or proposed.
Article 8 — Location and transfers
The Service is operated on the global edge infrastructure of Cloudflare, with delivery as close as possible to Morocco. Certain sub-processors (see the Sub-processor List) are established outside Morocco, in particular in the United States and in the European Union; these transfers are framed by appropriate contractual safeguards (standard contractual clauses, applicable certifications of the providers).
Article 9 — Audit and documentation
EnvoiSMS.ma makes available to the customer the documentation reasonably necessary to demonstrate compliance with this DPA (this documentation, responses to security questionnaires). Requests for additional information are addressed to [email protected] and handled within 30 days.
Article 10 — Contact