Broco Privacy Policy

Morocco

Effective September 17, 2026

This version applies to new commitments from its effective date. Notice rules and conditions applicable to existing customers are preserved; this publication is not a retroactive amendment of their contracts.

1. Who we are and what this Policy covers

Broco Technologies, Inc. (“Broco”, “we”, “us”) is a company incorporated in Delaware, United States, with its registered address at 1111B S Governors Avenue, Ste 96387, Dover, DE 19904, United States. For privacy questions or requests, contact support@broco.app, with “Privacy — Morocco” in the subject.

This Policy explains our use of personal information in connection with Broco websites, applications, profiles, dashboards, APIs and services used in Morocco. It covers Personal users and the individuals involved with Pro and Business profiles, including representatives, beneficial owners, administrators, staff, merchants, agents, transporters, senders and recipients. You can have privacy rights even if you do not hold a Broco account.

The country-specific provisions reflect Law No. 09-08 on the protection of individuals with regard to the processing of personal data and its implementing rules, where that law applies to the processing. Selecting a country or using English does not change the law that protects you. This is a standalone Policy: you do not need to combine it with the Global Privacy Policy to understand the processing described here. A notice provided at a particular collection point adds details for that operation and cannot reduce mandatory rights.

We are the controller where we determine the purposes and means of processing. Where we process an organisation's information solely on its instructions, the applicable processing arrangement governs that activity. A financial-service entity, merchant or other participant may be independently responsible for its own processing. We remain responsible for the processing that is ours.

This Policy provides information. It is not a blanket consent, a financial-service agreement or a guarantee that every catalogue service is available.

2. Information involved

The information depends on your role and the functions you use.

CategoryInformation and context
Profile and contactName, contact details, address, account identifiers, preferences and profile settings.
Identity and eligibilityDate of birth, nationality or residence, identity-document information, photographs, verification results, business registration, ownership, authorised representatives and source-of-funds information required for the relevant checks.
Verification imagesSelfie or liveness information and, where the actual verification process uses it, biometric information subject to the additional legal requirements.
Accounts and transactionsFunding references, balance and ledger entries, instructions, amounts, currencies, fees, transaction status, counterparties, recipients, merchant or bill references, card-related records and subscription records.
Professional and delivery activityPermissions, business activity, agent or transporter references, orders, shipment and delivery evidence, cash handovers and reconciliation records.
Device and useIP address, device and application identifiers, operating-system information, access and security events, and use of enabled functions. Location information is limited to the relevant feature and applicable permissions.
Communications and choicesSupport correspondence, complaints, privacy requests, consent or objection records and marketing preferences. Cookie or analytics information depends on the technologies actually used and applicable choices.

A list of possible categories does not mean every category is collected from every person. We do not require sensitive information simply because it appears in an identity document. Collection and access must be limited to what is needed and lawfully permitted.

For services enabled in Morocco, records may include local funding or payout references, recipient information, merchant payments and cash-agent reconciliation. Cross-border instructions add the destination, currency and beneficiary details needed for the selected route. A pilot or eligibility assessment uses only information relevant to admission and the proposed operation; it does not give automatic access to every service.

3. Where information comes from and what you must provide

Information comes from you, your authorised representatives, your use of Broco, and the participants involved in an enabled service. Depending on the operation, these may include verification and financial-service entities, your organisation's administrators, merchants, cash agents, delivery participants, billers and lawful public sources. A sender may provide recipient details; a business may provide details of its authorised staff or beneficial owners. Indirect collection remains subject to applicable notice and collection requirements.

If you supply another person's information, provide only what the operation requires and make sure you have authority or another lawful basis to supply it. Where applicable, that person must receive the relevant privacy information. This does not transfer Broco's own notice obligations to you.

Required fields or supporting information relate to the requested function, security or an applicable legal requirement. If necessary information is missing, we may be unable to open the requested profile, verify eligibility or complete that operation. Refusing optional marketing or unrelated analytics does not, by itself, prevent use of the core service.

4. Why we use information and on what basis

We use the relevant information for:

  • opening and administering profiles, managing permissions and authenticating access;
  • handling requested funding, transfers, payments, purchases, subscriptions, delivery and reconciliation within our role;
  • assessing eligibility, supporting identity and business checks, and carrying out financial-crime or sanctions checks where applicable;
  • preventing misuse, investigating incidents, handling complaints and establishing or defending legal claims;
  • communicating transaction, security, account and service information;
  • maintaining the reliability of the platform and understanding permitted usage information;
  • optional marketing and measurement where the required choice or other lawful basis exists.

For processing governed by Moroccan law, we rely on consent or a ground permitted by Article 4 of Law No. 09-08: an applicable legal obligation, necessary performance of a contract or requested pre-contractual steps, protection of vital interests, or a legitimate interest that does not override the individual's rights and freedoms. A contract is used only for processing genuinely necessary to the service requested by that individual.

Sensitive information and other processing subject to specific formalities require the applicable additional conditions. Reading this Policy does not constitute consent. Marketing choices are separate from service acceptance and may be withdrawn or opposed through the relevant channel or support.

Processing necessary for a service is limited to that purpose. Broco does not rely on another entity's regulatory duties as an automatic justification for unrelated collection or indefinite retention. A new, incompatible purpose requires a separate lawful basis and the information or consent required before that use.

5. Verification and decisions

Checks may use automated tools to compare submitted information, identify unusual activity or assist eligibility and security decisions. Broco may access information through the verification interface for its permitted functions. That access does not mean that Broco stores a separate copy of every document held by a verification entity.

The relevant verification notice explains additional sensitive-data processing, its purpose and the applicable choice or legal condition. An operating-system camera permission is not blanket consent to every use of an image.

If a decision affects your access to a service or a transaction, you may contact support to challenge inaccurate information, explain your circumstances and request human review where provided or required. We handle the request within our role and direct you to the responsible decision-maker where another entity makes the decision. Applicable restrictions on decisions based solely on automated processing, and rights to the required explanation and review, remain effective. A review does not guarantee eligibility.

6. Who receives information

Information may be disclosed, only to the extent needed for the relevant purpose and legally permitted, to:

  • financial-service and payment entities for account functions, card-related operations, execution, settlement, checks and disputes;
  • identity and business-verification providers for the requested checks;
  • merchants, recipients, agents, billers and delivery participants for their part of an instruction, sale, cash operation or delivery;
  • cloud, communications, security and technical-service providers supporting the platform;
  • analytics or marketing providers where that processing is permitted by the applicable choice and law;
  • authorised administrators of the organisation whose profile you use;
  • advisers, courts, regulators and public authorities where disclosure has a lawful basis;
  • a person you validly authorise to receive specified information.

An agent, merchant or transporter does not need unrelated identity or financial records merely because they participate in one operation. Business administrators' access is limited by their role and the legitimate needs of that organisation.

Entities acting on our instructions are subject to the applicable confidentiality, security and processing requirements. Independent controllers remain responsible for their own notices and uses. Where a recipient's identity, address or other specific information must be disclosed, that information must accompany the relevant operation or collection notice; a generic category does not replace a mandatory disclosure.

7. Processing outside Morocco

Broco is based in the United States. An enabled service may involve foreign financial, verification, technical or support infrastructure and cross-border access. Your country selection does not guarantee that every record stays in Morocco. The actual destinations depend on the operation and infrastructure; incorporation alone does not establish the storage location of every record.

International transfers subject to Moroccan law must satisfy Articles 43 and 44 of Law No. 09-08 and the applicable CNDP formalities. The transfer must have an appropriate legal route, such as the required level of protection or a permitted exception with its conditions, and any necessary authorisation. Using a foreign infrastructure provider or agreeing to this Policy does not, by itself, satisfy these requirements.

You may request information about the destinations, recipient roles and safeguards relevant to your information by contacting support. Information legally required before collection or transfer must be provided at that stage, rather than only after a request. Neither a privacy notice nor your acceptance of terms establishes that a regulatory formality has been completed.

8. How long information is kept

Retention follows the purpose, applicable legal requirements and any justified dispute or preservation need. Different records can have different starting events and periods.

RecordsRetention approach
Account and profile recordsWhile needed for the relationship, then for necessary closure, outstanding obligations and applicable claims or recordkeeping.
Identity and verification informationFor the check and the legal or justified compliance purpose applying to that record; not automatically for as long as any transaction record.
Transaction, invoice and reconciliation recordsFor the accounting, financial, contractual or dispute period applicable to the entity and operation concerned.
Support, complaints and privacy requestsFor handling the matter and justified follow-up, rights enforcement or evidence of the response.
Technical and security recordsFor proportionate maintenance, detection and investigation needs, with longer preservation limited to a justified incident or obligation.
Consent and marketing choicesFor the relevant choice and necessary evidence; a limited suppression record may be retained to respect an opt-out.

The applicable collection or service notice supplies a specific retention period where the law requires one. You may ask for the period and trigger relevant to a particular record. These criteria do not permit unlimited retention or replace a mandatory disclosure of duration.

When information is no longer required, it is deleted or effectively anonymised, subject to lawful preservation and destruction procedures. Closing an account does not remove a record that must legally be kept, and is not a reason to retain every record indefinitely. An independent controller may have its own lawful retention obligations.

9. Your rights in Morocco

Under Moroccan law, you may obtain confirmation of processing, access information about its purposes, categories, recipients and source, and receive your information in an intelligible form. You may request updating, correction, erasure or blocking of information that is inaccurate, incomplete, ambiguous, out of date or otherwise processed unlawfully.

Rectifications covered by Article 8 of Law No. 09-08 must be carried out without charge within a maximum of ten clear days, including the required action with recipients of the data. You may object on legitimate grounds, and object without charge to direct marketing, subject to the statutory exceptions for non-marketing processing. Access requests follow the applicable CNDP procedure; a delay requiring the CNDP's intervention is not replaced by a unilateral extension.

Rights can be subject to conditions that protect other individuals, an applicable legal obligation or a legally protected investigation. We explain a limitation or refusal and the available next steps to the extent permitted. A request is not rejected simply because you no longer have an active account. Any additional right arising under another applicable law remains available.

10. How to make a request or complaint

Email support@broco.app and identify the right or concern, the relevant country and enough information to locate the record. You can also write to Broco at the registered address in section 1. Do not include your password, authentication codes or unnecessary complete identity documents.

We may ask for proportionate information to verify identity or representative authority and protect another person's information. A guardian, authorised representative or other person entitled by law may act within that authority. Verification is not used to frustrate a valid request.

Requests follow the applicable legal deadline and procedure, including the country-specific rules above. Where correction must be notified to recipients, we take the action required by law. Contact support promptly if a matter remains unresolved; an internal escalation does not suspend a statutory complaint deadline.

You may contact Commission nationale de contrôle de la protection des données à caractère personnel (CNDP) through its official website. You do not have to waive a right or exhaust Broco support before using an available regulatory or judicial remedy.

11. Security and incidents

We use technical and organisational measures designed to protect information against unauthorised access, loss, misuse, alteration and disclosure. Access must be appropriate to a person's responsibilities, and personnel and service providers must respect applicable confidentiality duties.

No method of transmission or storage can be guaranteed completely secure. Report suspected account compromise or exposure to support promptly. Where an incident requires notification, Broco must notify the competent authority and affected individuals in accordance with the applicable thresholds, timing and content requirements. This Policy does not claim a certification, a particular hosting region or an absolute security guarantee.

12. Cookies, marketing and device choices

The Cookie Policy explains cookies and similar technologies. Necessary technologies support requested functions such as session security. Optional technologies are subject to the applicable notice and choice requirements; consent is obtained where required before activation. Browser or device controls may affect how a function works.

You may stop optional marketing through the message's available unsubscribe control or by contacting support. Necessary account, transaction, security and legal communications may continue. Refusing optional marketing does not remove access to mandatory support or privacy rights. Device permissions can be reviewed in device settings; withdrawing a permission may prevent the specific feature that requires it.

13. Age, other notices and changes

Broco individual accounts are intended for people aged at least 18 who have the contractual capacity and eligibility required for the service.

Information about a child supplied in another context remains protected by the applicable law. Contact support if you believe it has been collected improperly.

An external website or independent service may provide its own privacy information. An integration does not remove Broco's responsibilities for its own processing. A profile held by a company can still contain protected information about natural persons.

We update this Policy when the relevant processing or requirements change. The published version identifies its applicable date, and we communicate changes where required. An update does not retroactively authorise incompatible processing or replace a consent or authorisation that must be obtained separately.

Privacy contact: support@broco.app.