1. What we declare for you
Under Law 09-08, you and Kartalik are jointly responsible for your customers' data: you run your programme, we operate the platform. We declare to the CNDP the platform's processing — loyalty programmes and digital business cards — and the transfers it involves: hosting in the European Union, and Apple Wallet and Google Wallet in the United States — for a loyalty card on the express consent your customer gives on the enrollment form, for your own business-card pass on our contract with you. Our receipt numbers are cited on the enrollment page, where Law 09-08 wants your customers to find them.
2. What remains yours
- any processing you run outside the Service — a customer file of your own, exports, cameras, a newsletter tool — is yours to declare;
- your staff: tell each person before you create their scan-manager account, because every scan is recorded against it;
- the campaigns you send and the use of the data for your programme only;
3. The facts, if a customer or the CNDP asks you
- Platform publisher: NOVASTACK SARL, with a share capital of 100 000 MAD, registered in the Marrakech Commercial Register under No. 185521, registered office at APPT N 7 ETG 2 LOT AL MASAR N 643, Marrakech, contact contact@kartalik.com;
- Purpose of the processing: managing a customer loyalty program — enrollment, digital card delivery to Apple Wallet / Google Wallet, visit and points tracking, and card messages;
- Data collected: first name, last name, phone number, optional email and birthday; card and points data; visit history (date, points, amount paid, optional note, point of sale); consent records;
- If you enable referrals: which existing customer's invitation a new customer joined through, the kind of link they chose to declare (family, friend, colleague, neighbour, other), and the points you granted for it;
- Recipients: your establishment (your own customers only), Apple Inc. or Google LLC (pass delivery, United States), and Hostinger International Ltd. (European Union) for hosting and transactional email;
- Retention: card and identity data for as long as the card is used, and in any case no more than 36 months after the customer's last visit; visit history for the life of the card, then kept without identity; technical wallet records 90 days to 6 months; technical logs 30 days;
- Security measures: encrypted transport (HTTPS/TLS), sensitive secrets encrypted at rest, hashed passwords, role-based access, per-establishment isolation, forgery-protected scan codes;
- Data subject rights: access, correction, objection and erasure honoured via your dashboard (on-the-spot erasure) or contact@kartalik.com.
4. What the platform already enforces for you
- Consent first: no card is created without the customer ticking the privacy consent on the enrollment form — the moment of acceptance is recorded;
- Marketing opt-in (art. 10): promotional pushes only ever reach customers who separately opted in, and they can withdraw at any time;
- Erasure on demand: deleting a customer removes their personal details immediately and closes their card; the visit records stay for your statistics, stripped of everything that identifies them;
- Automatic retention: technical records are purged on the schedule above, and a card with no visit for 36 months is erased automatically — without any action on your part.
5. The CNDP
Forms, model decisions and guidance: www.cndp.ma.
This page is practical guidance — it is not legal advice. For your specific situation, consult a lawyer or the CNDP.
6. Questions
Questions about your data obligations: contact@kartalik.com.
Data Processing Agreement · Privacy Policy · Terms of Use & Sale