Data Protection & GDPR
Our data protection compliance posture — how we apply Moroccan Law 09-08 and voluntarily adopt GDPR-inspired practices for every User.
Executive Summary
This page is our data protection compliance statement — it sits alongside our Privacy Policy to explain, specifically, how WE ARE TOGETHER approaches Moroccan Law 09-08 and international frameworks including the GDPR, why the two are not in tension, and how an institutional investor or partner subject to their own compliance requirements can rely on us.
1. Purpose of This Page
Where our Privacy Policy explains what data we collect and why, this Data Protection statement explains our compliance posture and governance — the legal frameworks we operate under, how we apply them consistently across jurisdictions, and how institutional counterparties can assess our practices as part of their own diligence.
2. Our Primary Legal Framework: Law 09-08
As a platform operating from and processing personal data connected to Morocco, our primary legal obligation is Law No. 09-08 on the Protection of Individuals with regard to the Processing of Personal Data, supervised by the CNDP. Morocco's data protection authority is the National Commission for the Control of the Protection of Personal Data (Commission Nationale de contrôle de la protection des Données à caractère Personnel, "CNDP"), which supervises compliance with Law No. 09-08 on the Protection of Individuals with regard to the Processing of Personal Data.
3. Why We Also Apply GDPR-Inspired Practices
Law 09-08 does not require us to comply with the EU General Data Protection Regulation (GDPR), and we do not claim GDPR certification. However, because our Users include individuals and institutions accustomed to GDPR-level standards, we have voluntarily adopted several of its practices as our own baseline — including data minimization, purpose limitation, a documented legal basis for every processing activity, and rights of access, rectification, erasure, and portability extended to every User regardless of location.
Why this matters: a Moroccan platform operating only to the minimum required by local law is not, by itself, a red flag. But a Moroccan platform that voluntarily holds itself to a higher, internationally recognized standard is making a deliberate statement about the caliber of investor and partner it intends to serve.
4. Governance and Accountability
We maintain a record of processing activities, apply data protection considerations when designing new features ("privacy by design"), and limit data collection to what is necessary for the stated purpose. Our Data Protection Officer oversees compliance and is reachable directly at dpo@wearetogether.example.
5. Processor Oversight
Where a third-party processor handles personal data on our behalf (e.g., hosting, email delivery), we require a written agreement establishing their obligations, limiting their use of the data to our documented instructions, and requiring them to maintain equivalent security standards.
6. International Institutional Counterparties
If your organization requires specific data protection representations, a data processing addendum, or evidence of our compliance posture as part of your own onboarding or diligence process, contact dpo@wearetogether.example — we regularly support this for institutional Partners and are able to respond to standard due diligence questionnaires.
7. Your Rights
Full detail on your rights as a data subject — access, rectification, opposition, erasure, portability, and restriction — is set out in our Privacy Policy, Section 10. To exercise any right, contact dpo@wearetogether.example.
8. Contact
Questions about our data protection governance may be directed to our Data Protection Officer at dpo@wearetogether.example.
9. Version History
| Version | Date | Summary of Changes |
|---|---|---|
| 1.0 | 30 July 2026 | Initial publication of the Data Protection statement. |
Effective Date: 30 July 2026 Last Updated: 30 July 2026