Data Protection & Privacy Policy
Preamble
Alyf is owned by Paymob SARL, a Moroccan limited liability company with capital of ninety thousand dirhams (90,000 dhs), headquartered at Casablanca, 259 Lotissement Lina, 1st floor Sidi Maarouf, registered under number 392123 with the Casablanca Trade and Companies Register. Paymob SARL respects your privacy and is committed to applying transparent privacy protection rules. This Data Protection & Privacy Policy explains how we collect, use and share your personal information in connection with your use of the Alyf application and explains your rights with respect to how we treat your personal information.
Protecting your personal data and privacy is one of our top priorities. That's why, at (hereinafter referred to as "Alyf" or "we" or "us" or "our"), we detail this Policy explaining our practices regarding the collection, use and disclosure of the information we receive, when you use our Application (Alyf) and our services.
This Data Protection & Privacy Policy applies only to the Services available on the Alyf Application. Paymob collects your personal data in order to comply with regulatory provisions and to ensure the best quality of service.
Personal data concerning the User may be subject to the exercise of the right of access, rectification, and opposition in accordance with the provisions of Law 09-08
This can be done by sending an email to support@paymob.ma or by sending a written letter with acknowledgment of receipt to Customer Service at the following address: Paymob, 259 Lotissement Lina, 1st floor, Sidi Maarouf, Casablanca, mentioning "Alyf Complaint" in the subject line.
Table of Contents
- 1. Purpose of this Data Protection Policy
- 2. Information Collected by Alyf
- 3. Data Storage & Security
- 4. Safety Measures
- 5. Security Incident Management
- 6. Use of Information
- 7. Sharing of Information
- 8. Data Retention
- 9. Training and Awareness
- 10. Your Rights
- 11. Modifications to the Policy
- 12. Contact
1. Purpose of this Data Protection Policy
The personal data protection policy applies to all users and prospects for the provision of products and services defined in Alyf's General Terms of Use. It is regularly updated to reflect changes in Alyf's practices as well as potential changes in the regulations applicable to personal data. Alyf encourages its users to consult it regularly to be aware of any modifications or updates made.
As a Moroccan company, Paymob complies with all regulations and recommendations issued by the National Commission for the Control of Personal Data Protection (CNDP).
In accordance with the provisions of Law No. 09-08 relating to the protection of individuals with regard to the processing of personal data, the User acknowledges and accepts that their personal data is intended for Alyf and is subject to processing operations for the management of their Account and the execution of the Contract, such as:
- collection;
- recording;
- storage in various forms and for any duration;
- any other processing in general, including all transfers by Alyf to its business partners, advisors, subcontractors, and judicial authorities.
The purposes of processing this data are: technical purposes, information on the subscribed Services, adaptation of the subscribed Services, and Account management.
2. Information Collected by Alyf
2.1 Required Data During Alyf Application Operation
When you sign up on the Alyf application, we collect your language preferences and phone number. An automatic message with a verification code is sent to verify your phone number. We gather various data to enhance the service we provide, including:
Device Information
Device type, OS version, Android or iOS identifier (Device ID), IP address, device model, software version, screen size, mobile operator name, time zone, download location of the application, and type of network used (e.g., WiFi).
Usage and Connection Information
Time and date of app opening, pages visited within the app, time and date of app closure, duration of app usage, and transaction data (details below). Alyf also collects crash data or cookies.
Transaction Data
Transaction times, dates, senders, recipients, amounts transferred, amounts received within the application, amounts funded via credit card, funds transferred from Alyf to a bank account, and funds withdrawn from an ATM. The transaction history, including sender/recipient names, times, dates, and amounts, is stored and accessible to users.
Geolocation Information
Alyf may collect location information determined by data such as IP address or GPS of the mobile phone to provide a better user experience and enhance security (geolocation can, for example, serve as a control in case of suspected fraud). Most mobile phones allow users to control or disable location services in applications through the device settings menu. Note that your city and region can be inferred based on the IP address.
Contacts Using Alyf
Users can link their contact directories to the application to identify which of their contacts use Alyf. Alyf collects and processes a hashed representation (fingerprint) of phone numbers and email addresses from the user's address book to maintain user privacy. No raw contact data is stored on Alyf's servers. This feature requires explicit user consent, which can be managed and revoked at any time through the support feature in the 'More' menu of the app or by contacting support or by going to https://alyf.ai/ and selecting 'contactez-nous', or going to https://paymob.atlassian.net/servicedesk/customer/portals
Communications with Alyf Support
Alyf retains the history of communications that the user may have had with Alyf's support or customer service, such as email exchanges.
Tracking of Actions by Alyf-Employees
Alyf employees may be involved in managing an account, and as such their activities will be logged on these operations may be retained.
Face Data and Biometric Processing
When upgrading to a Level 2 account, Alyf collects and processes your biometric face data (e.g., a selfie and photo of your National Identity Card) for the purpose of identity verification and fraud prevention. As part of this process:A liveness check is conducted (e.g., requiring you to smile or blink) to ensure the identity verification is legitimate.No face data is permanently stored during the liveness check. All such data is processed locally on your device and is not transmitted to or stored on Alyf's servers.Face data used for eKYC purposes (e.g., matching your selfie with your National Identity Card) is encrypted and securely stored within Morocco, as required by local regulations. This data is retained only for as long as necessary to fulfill regulatory and fraud prevention requirements and is securely deleted afterward.Face data used for eKYC purposes is processed for a limited duration to complete identity verification. All raw facial images and liveness check data are permanently deleted immediately after verification is complete, ensuring no sensitive biometric data is stored beyond the verification process.No Face Data is transmitted to any third party companies
2.2 Information provided by Users
During registration, Alyf collects the following information directly from Users:
- Name (Optional, Required for level 2 and above)
- First Name (Optional, Required for level 2 and above)
- Phone Number (Required)
- Residential Address (Optional, Required for level 2 and above)
- Date of Birth (Optional, Required for level 2 and above)
- Email Address (Optional)
- National ID Number (Optional, required for Level 2 and above)
- Photo (Optional, required for Level 2 and above)
- Biometric Data: Face Matching (Optional, required for Level 2 and above)
- Gender / Sex (Optional, Required for level 2 and above)
We use this data for marketing studies and targeted promotional campaigns within Alyf. We are committed to ensuring the protection of your personal data in accordance with our privacy policy. Your information is handled with utmost care and is only used in the provision of our services.
3. Data Storage & Security
We take appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. However, no method of transmission or electronic storage is completely secure, and we cannot guarantee the absolute security of your information.
3.1 Secure storage
All our users' data is securely stored by our trusted data center partners. Sensitive information is encrypted during transfer and storage, to guarantee confidentiality.
4. Safety Measures
4.1 Encryption
We use robust encryption protocols to protect our users' data:
- Encryption of data in transit: TLS (Transport Layer Security) is used to protect data in transit between our servers and users' devices.
- Encryption of data at rest: Sensitive information stored in our databases is encrypted to prevent unauthorized access.
4.2 Access control
Access to personal data is strictly controlled to guarantee their security:
- Multi-factor authentication (MFA): Use of multi-factor authentication methods to protect access to our internal systems.
- Permission management: only authorized employees who need access to information in order to do their jobs can view users' personal data.
4.3 Monitoring and auditing
We have set up monitoring and auditing systems to detect and respond rapidly to security incidents:
- Continuous monitoring: Our systems are constantly monitored for suspicious or unauthorized activity.
- Regular audits: We carry out regular security audits to assess the effectiveness of our protection measures and identify potential vulnerabilities.
5. Security Incident Management
In the event of a security incident, we have rigorous protocols in place to manage the situation:
- Detection: Use of advanced technologies for rapid detection of security incidents.
- Response: Dedicated teams ready to react quickly to minimize impacts and restore services.
- Notification: In the event of a data breach that involves personal data, Alyf will promptly notify affected users through the application and/or via email, in compliance with applicable laws. We will provide details on the nature of the breach, the potential impact, and steps taken to mitigate risks.
Your Benefits
Once your account is verified, you will enjoy:
- Enhanced protection of your personal data
- Personalized services and offers
- Priority access to our customer service
- If you contact us through the designated form in the application for any complaints, we may collect data to identify you, such as your name, first name, or residential address. We will use this information to process your request. We will retain your personal data for as long as you are registered on Alyf. If you choose to unsubscribe from Alyf, your data will be deleted one year after deactivating your account. You can withdraw your consent for further storage and processing of your data at any time. Any processing of your data before your withdrawal will not be affected and will be covered by your prior consent.
5.1 Banking data
IBAN / Bank Card Details: These details are necessary for transferring funds to a bank account or for funding your Alyf account via credit card. All credit card funding operations for your Alyf account are managed by our partner, the Centre Monétique Interbancaire (CMI). Alyf only receives transaction success or failure data. However, Alyf must retain the IBAN and account holder's name for fund transfers from your Alyf account to your bank account.
Regarding funding your Alyf account via credit card, Alyf does not directly collect card information. This process is handled by our partners CMI. The card transactions are processed through CMI, ensuring the security and confidentiality of your banking data.
6. Use of Information
6.1. Purposes of Processing
The information we collect is used for the following purposes:
- Providing our services: Processing transactions, managing User accounts, responding to support requests, and improving the functionality of the Application.
- Improving our services: Analyzing the usage of our Application to better understand User needs, developing new features and services, and enhancing the User experience.
- Securing our services: Detecting and preventing fraudulent activities, protecting the security of our systems and User information.
- Communicating with you: Sending important notifications, updates on your transactions, information about our services, promotions, and special offers, subject to your consent.
6.2. Legal Basis of Processing
We process your personal data on the following legal bases:
- Contractual Necessity: The collection and processing of your personal data are necessary for the performance of our contract with you. Where sensitive data such as biometric or location information is collected, explicit consent will be sought prior to processing, and users can withdraw their consent at any time via the Support or Contact Us feature in the More section or by going to https://alyf.ai/ and selecting 'contactez-nous', or going to https://paymob.atlassian.net/servicedesk/customer/portals
- Legitimate Interest: We may process your personal data to serve our legitimate interests, such as improving our services, securing our Application, and preventing fraud.
- Consent: Where required by law, we collect your consent before processing your personal data.
8. Data retention
We will retain your personal data for as long as you are registered on Alyf. If you choose to unsubscribe and deactivate your Alyf account, your personal data will be deleted one year from the date of deactivation unless retention is required by law or for fraud prevention. Biometric data is processed temporarily and securely deleted immediately after verification. Users may request data deletion through the support feature in the 'More' menu of the app or by contacting support by going to https://alyf.ai/ and selecting 'contactez-nous', or going to https://paymob.atlassian.net/servicedesk/customer/portals)
Biometric data is processed temporarily and is not stored beyond the completion of verification. Any necessary derived data (e.g., anonymized verification results) is securely deleted within 30 days unless required by law.
You may withdraw your consent for further storage and processing of your data at any time by contacting us. Please note that any processing of your data conducted prior to your withdrawal remains lawful and based on your consent at the time.
9. Training and awareness-raising
We regularly train our employees on best security practices and data protection:
- Ongoing training: Regular training programs to make employees aware of the latest security threats and protective measures.
- Internal policies: Adoption and dissemination of strict internal data security policies.
10. Your Rights
You have certain rights regarding your personal data, including:
- Access: You have the right to request access to your personal data that we hold.
- Rectification: You can request the correction of your inaccurate or incomplete personal data.
- Deletion: You can request the deletion of your personal data by following the steps to delete your account subject to certain conditions via the Delete Your Account feature in the Advanced Parameters subsection in the More section, and /or request more details on the process via the Support feature in the 'More' menu of the app or by going to https://alyf.ai/ and selecting 'contactez-nous', or going to https://paymob.atlassian.net/servicedesk/customer/portals.Data deletion requests are processed in compliance with applicable laws and will be completed within a reasonable timeframe.
- Objection: You can object to the processing of your personal data in certain circumstances.
- Portability: You can request the portability of your personal data in a structured, commonly used, and machine-readable format.
To exercise your rights, you can contact us at the following address: support@paymob.ma
11. Modifications to the Data Protection & Privacy Policy
Data security at Alyf is subject to continuous improvement. Our security and privacy policies are regularly reviewed and updated to adapt to new threats and technologies.
We may update this policy from time to time. We will inform you of any substantial changes by posting the new Policy on our Application and updating the "Last Updated" date at the top of this page. We encourage you to check this page regularly to stay informed about our data protection practices.
12. Contact
For any questions regarding this Privacy Policy or our data protection practices, please contact us at:
Paymob, 259 Lotissement Lina, 1st Floor, Sidi Maarouf, Casablanca, or by email at support@paymob.ma