Privacy Policy
How WE ARE TOGETHER collects, uses, shares, and protects your personal data, and the rights you have over it under Moroccan Law 09-08 and international best practice.
Executive Summary
This Privacy Policy explains what personal data WE ARE TOGETHER collects, why we collect it, how long we keep it, and the rights you have over it. We are the data controller for the information you provide us, we process it under the Kingdom of Morocco's Law No. 09-08, and — because serious investors expect nothing less — we voluntarily extend several protections inspired by international best practice (including the GDPR) to every user, regardless of where you are located. Questions at any time: privacy@wearetogether.example or our Data Protection Officer at dpo@wearetogether.example.
1. Introduction and Scope
This Privacy Policy applies to all personal data processed by WE ARE TOGETHER through wearetogether.example and its associated Services, including account registration, the Investment Strategy tool, Request Access and Project Submission workflows, Consultation bookings, the Newsletter, and any communication you have with our team. It should be read together with our Cookie Policy, which governs the specific technologies used to recognize your browser or device.
2. Who We Are
WE ARE TOGETHER is the commercial brand of its operating company, incorporated under the laws of the Kingdom of Morocco, with its registered office in Casablanca. Full corporate registration details — including our Commercial Registry (RC) and Common Enterprise Identifier (ICE) numbers — are published in our Legal Notice. For the purposes of applicable data protection law, we act as the data controller of your personal data.
3. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, or deletion. "Data Subject" means the individual to whom personal data relates — in most cases, you. "Data Controller" means the entity that determines the purposes and means of processing personal data — in this case, WE ARE TOGETHER. "Data Processor" means a third party that processes personal data on our behalf and under our instructions.
4. Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Identity data | Full name, date of birth, nationality, government-issued ID (where required for KYC) | Provided directly by you |
| Contact data | Email address, phone number, mailing address, country | Provided directly by you |
| Professional data | Organization, position, sector of interest, investment capacity range | Provided directly by you |
| Investment interest data | Opportunities viewed, saved, or expressed interest in; consultation topics | Generated by your use of the Platform |
| Technical data | IP address, browser type, device identifiers, cookies (see our Cookie Policy) | Collected automatically |
| Communications | Messages, consultation notes, support requests, and their content | Provided directly by you or generated during a consultation |
| Submitted project data | Business plans, financial documents, and related materials you upload for review | Provided directly by you |
5. How We Use Your Personal Data
| Purpose | Legal Basis |
|---|---|
| Creating and administering your Account | Performance of a contract with you |
| Matching you with relevant Opportunities, Partners, or research | Consent / legitimate interest in providing a relevant Service |
| Processing a Consultation, Request Access, or Project Submission | Performance of a contract with you |
| Sending the Newsletter and other marketing communications | Consent, which you may withdraw at any time |
| Conducting AML/KYC verification where applicable to a specific opportunity | Compliance with a legal obligation |
| Maintaining Platform security and preventing fraud | Legitimate interest in protecting our Users and our Platform |
| Improving our Services through aggregated, non-identifying analysis | Legitimate interest |
6. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Platform, remember your preferences, and — only with your consent — measure engagement. The categories of cookies we use, their purposes, and how to manage your preferences are set out in full in our Cookie Policy, which forms part of this Privacy Policy by reference.
7. How We Share Your Personal Data
We do not sell your personal data. We may share it with: (a) affiliated experts or Partners strictly to fulfil a Consultation or Opportunity introduction you have requested; (b) service providers who process data on our behalf under written instructions (e.g., hosting, email delivery, analytics) and who are contractually bound to protect it; (c) professional advisors (legal, audit) where necessary; and (d) regulators, courts, or public authorities where required by law. Any Partner introduction that involves sharing your data occurs only after you have expressed clear interest in that Partner or Opportunity.
Why this matters: an introduction should never feel like your information leaked somewhere you didn't expect. We only share your data with a named Partner once you have taken a clear action asking to be connected — never proactively, and never as a default.
8. International Data Transfers
Our infrastructure providers may process data outside Morocco. Where this occurs, we require contractual safeguards consistent with international best practice (including mechanisms comparable to the European Commission's Standard Contractual Clauses) so that your data receives an equivalent level of protection wherever it is processed.
9. Data Retention
| Data Category | Retention Period | Why |
|---|---|---|
| Account and identity data | Duration of your Account, plus 5 years after closure | Statute of limitations for civil and commercial claims under Moroccan law |
| KYC/AML records (where collected) | 10 years from the end of the relevant relationship | Anti-money-laundering recordkeeping obligations |
| Marketing consent records | Until you withdraw consent, plus 3 years | Evidencing lawful basis for past communications |
| Technical and security logs | Up to 13 months | Security investigation and fraud-prevention window |
| Submitted project materials | Duration of review, plus 2 years unless you request earlier deletion | Enabling follow-up and audit trail of our evaluation |
10. Your Rights
Under Law 09-08, you have the right to access, rectify, and object to the processing of your personal data, and the right to be informed before your data is transferred to a third party for commercial purposes. Because we hold ourselves to a higher standard, we voluntarily extend the following rights to every User, wherever located: the right to request a copy of your data in a portable format, the right to request deletion of your data (subject to our legal retention obligations above), and the right to restrict certain processing. To exercise any of these rights, contact dpo@wearetogether.example; we respond within 30 calendar days.
How do I request access to or deletion of my data?
Email dpo@wearetogether.example with your request. We verify your identity, then respond within 30 calendar days. Certain records may be retained where required by law (see Section 9, Data Retention).
11. Children's Privacy
The Platform is intended for individuals who have reached the age of majority and are capable of entering into investment-related engagements. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact dpo@wearetogether.example so we can act promptly.
12. Data Security
We maintain technical and organizational measures designed to protect your personal data against unauthorized access, loss, or misuse, including encryption in transit, access controls, and regular security review. Full detail is available in our Security Center.
13. Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights, we will notify the CNDP where required and inform affected Users without undue delay, together with guidance on protective steps you can take.
Our Supervisory Authority
Morocco's data protection authority is the National Commission for the Control of the Protection of Personal Data (Commission Nationale de contrôle de la protection des Données à caractère Personnel, "CNDP"), which supervises compliance with Law No. 09-08 on the Protection of Individuals with regard to the Processing of Personal Data.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes will be communicated through the Platform or by email with reasonable advance notice before they take effect.
15. Contact Us
For any question about this Privacy Policy or our data practices, contact our Data Protection Officer at dpo@wearetogether.example, or our general privacy team at privacy@wearetogether.example.
16. Version History
| Version | Date | Summary of Changes |
|---|---|---|
| 1.0 | 30 July 2026 | Initial publication of the Privacy Policy. |
Effective Date: 30 July 2026 Last Updated: 30 July 2026