Privacy Policy
Last updated: March 2026
1.Introduction & Controller Identity
Amali is operated from Morocco. Data controller contact: dpo@amali.ma. This policy complies with Law No. 09-08 on the protection of individuals with regard to the processing of personal data and its implementing decree.
2.Data We Collect
Account data: name, phone number, email (optional), city, preferred language. Profile data: bio, skills, languages, availability, CV (seekers); company name, logo, WhatsApp (employers). Usage data: job views, applications, saved jobs, search queries. Technical data: IP address, browser type, device type, access times. Communication data: messages exchanged between seekers and employers.
3.Legal Basis for Processing
Per Article 4 of Law 09-08: Consent given at account creation. Contract performance: processing applications, enabling messaging. Legitimate interest: platform improvement, fraud prevention. Legal obligation: tax records, legal requests.
4.How We Use Your Data
Matching seekers with relevant job postings. Enabling communication between seekers and employers. Personalizing job recommendations and search results. Sending notifications (application status, new jobs matching alerts). Platform analytics and improvement. Fraud prevention and security.
5.Data Sharing
With employers: when you apply, the employer sees your name, city, skills, and screening question answers. With service providers: hosting (Vercel, Railway), SMS (Twilio/Infobip), email (Resend). We NEVER sell your personal data to third parties. We may share data with authorities if required by Moroccan law.
6.Data Retention
Active accounts: data retained while account is active. Inactive accounts: anonymized after 24 months of inactivity. Deleted accounts: PII erased within 30 days, anonymized records kept for legal compliance (5 years per Moroccan commercial law). Messages: retained for 12 months after thread closure. OTP codes: deleted after verification or expiry.
7.Your Rights
Per Articles 7-9 of Law 09-08: Right of access (request a copy of your data). Right of correction (update inaccurate information). Right of deletion (request account deletion via settings or email). Right of opposition (object to marketing processing). Right to be informed (notification of any data breach within 72 hours). To exercise your rights: dpo@amali.ma or in-app profile settings.
8.Cookies & Local Storage
Authentication tokens (httpOnly cookies for refresh tokens). localStorage: saved jobs, job alerts, onboarding status, UI preferences. No third-party advertising cookies. No tracking pixels.
9.International Transfers
Data may be processed on servers outside Morocco (EU — Vercel/Railway). Transfers comply with Articles 43-44 of Law 09-08. EU servers provide an adequate level of protection per CNDP guidance.
10.Security Measures
Encryption in transit (TLS 1.3). Passwords hashed with bcrypt. Rate limiting on authentication endpoints. Regular security audits. Access restricted to authorized personnel only.
11.Children's Privacy
Amali is intended for users aged 16 and above. We do not knowingly collect data from children under 16.
12.Changes to This Policy
We will notify users of material changes via in-app notification. Continued use after notification constitutes acceptance.
13.Contact & Complaints
Data Protection Officer: dpo@amali.ma. CNDP: Commission Nationale de contrôle de la protection des Données à caractère Personnel, Rabat — www.cndp.ma
