Privacy Policy

Last updated: [DATE OF PUBLICATION] · Version: [1.0]

Your privacy matters to us. This Privacy Policy explains, in clear language, what personal data MAGHREB NOW collects when you read our blog, subscribe to our newsletter, create an account or contact us; why we collect it; who helps us process it; how long we keep it; and how you can exercise your rights. It complies with the EU General Data Protection Regulation 2016/679 (GDPR), Spanish Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights (LOPDGDD) and Spanish Law 34/2002 (LSSI-CE).

Key points at a glance

  • We collect only the data we need to run the blog, the newsletter and your account.
  • We do not sell your data and we do not use it for advertising profiles.
  • We do not use analytics or advertising cookies. See our Cookie Policy.
  • The newsletter is only sent if you confirm your subscription (double opt-in). You can leave with one click.
  • Our website, database and CRM run on our own server. We use carefully selected providers for hosting, email, security and backups, listed below.
  • You can access, correct or delete your data, or object to its use, at any time by writing to [PRIVACY CONTACT EMAIL].

1. Who is responsible for your data

Data controller: [LEGAL NAME OF THE COMPANY OR SOLE TRADER]
Tax ID (NIF/CIF): [TAX IDENTIFICATION NUMBER]
Registered address: [FULL REGISTERED ADDRESS]
Privacy contact: [PRIVACY CONTACT EMAIL, e.g. privacy@maghrebnow.com]
General contact: info@maghrebnow.com
Data Protection Officer: [NOT APPOINTED, AS NOT REQUIRED BY ARTICLE 37 GDPR AND ARTICLE 34 LOPDGDD — REVIEW IF ACTIVITY GROWS / OR NAME AND CONTACT OF THE DPO]

2. What this policy covers

This policy applies to maghrebnow.com and to the services available today: the blog, the newsletter, member accounts and the contact forms. If we launch new services (for example community spaces or paid memberships), we will update this policy before they start.

3. The data we process and why

The table below summarises each processing activity. More detail follows after the table.

3.1 Newsletter in more detail

When you subscribe, we save the information above in FluentCRM, a customer relationship tool installed on our own server (it is not a third-party cloud service). We then send you an email to confirm your subscription (double opt-in). Until you confirm, you will not receive the newsletter.

Our newsletter emails contain a small invisible image and links with tracking parameters. They tell us whether an email was opened and which links were clicked. We use this information only in aggregate to improve the newsletter, and to keep our list healthy (for example, removing addresses that never open our emails after a long time). If you click a link in our emails, our website may save a cookie that recognises you as a subscriber so you can manage your preferences without logging in. See the Cookie Policy.

You can withdraw your consent at any time using the unsubscribe link in every email or by writing to us. Withdrawing consent does not affect processing carried out before.

3.2 Data you must give us

Fields marked as required in our forms are necessary to provide the service you ask for. If you do not provide them, we will not be able to create your account, send you the newsletter or answer your message. Optional fields are clearly marked.

3.3 Where your data comes from

We obtain your data directly from you, from your use of the Platform and from the technical information your browser sends automatically. We do not buy data or obtain it from data brokers.

3.4 No automated decisions with legal effects

We do not take decisions about you based only on automated processing that produce legal effects or similarly significantly affect you. Our security systems automatically block IP addresses that show clearly abusive patterns (for example scanning for vulnerabilities or many failed logins). These blocks are temporary, are reviewed by an administrator and can be lifted on request.

4. Who has access to your data

We do not sell or rent your data. Your data is processed by our own team and by the service providers listed below, who act as data processors under contracts that require them to protect it and use it only on our instructions (Article 28 GDPR).

The software we use to run the Platform (WordPress, BuddyBoss, Fluent Forms, FluentCRM, FluentSMTP and our own security tools) is installed on our server. The companies that create this software do not receive your personal data through it.

We may also disclose data to public authorities, courts or law enforcement when the law requires it.

5. International transfers

Some of our providers are based in, or may access data from, countries outside the European Economic Area, in particular the United States. When this happens, we make sure the transfer is protected by an adequate safeguard:

  • the European Commission adequacy decision for the EU-U.S. Data Privacy Framework, for companies certified under it (such as Google, Cloudflare and Amazon Web Services); and/or
  • the Standard Contractual Clauses approved by the European Commission, together with additional measures where necessary.

You can ask us for more information about these safeguards by writing to [PRIVACY CONTACT EMAIL].

6. Google reCAPTCHA

We use Google reCAPTCHA v3 on the login, registration, password reset and account activation pages, and on our newsletter and contact forms. reCAPTCHA checks whether an action is being performed by a human or by an automated program. To do this, Google analyses information such as your IP address, the time spent on the page, mouse movements and browser data, and may read or set cookies from google.com. This information is processed by Google under its own Privacy Policy and Terms of Service. We use reCAPTCHA because we have a legitimate interest in protecting the Platform and our users from spam, fraud and automated attacks.

7. Security

We apply technical and organisational measures appropriate to the risk, including:

  • encrypted connections (HTTPS) across the whole Platform;
  • passwords stored using strong one-way encryption (hashing), never in plain text;
  • two-factor authentication for administrators and access limited to people who need it;
  • a firewall, automated blocking of abusive IP addresses and protection against brute-force attacks;
  • an activity log of administrative actions and login attempts;
  • regular software updates and security reviews;
  • regular backups, kept encrypted, with restoration tests.

No online service can be completely secure. If a personal data breach occurs that is likely to put your rights at risk, we will notify the Spanish Data Protection Agency within 72 hours and, where required, inform you without undue delay.

8. Your rights

You have the right to:

  • Access: know whether we process your data and get a copy of it.
  • Rectification: correct inaccurate or incomplete data. You can update most of your data from your account settings.
  • Erasure: ask us to delete your data when it is no longer needed or you withdraw your consent.
  • Restriction: ask us to limit the processing of your data in certain cases.
  • Portability: receive the data you gave us in a structured, commonly used format, or have it sent to another controller.
  • Objection: object to processing based on our legitimate interest, including for reasons related to your particular situation.
  • Withdraw consent: at any time, without affecting processing carried out before.
  • Not to be subject to automated decisions with legal or similarly significant effects.

To exercise your rights, write to [PRIVACY CONTACT EMAIL] or to our registered address, saying which right you want to exercise. If we have reasonable doubts about your identity, we may ask for information to confirm it, but only what is strictly necessary. We will reply within one month. This period may be extended by two more months for complex requests, in which case we will tell you why. Exercising your rights is free.

If you believe we have not handled your data correctly, you can file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or with the data protection authority of your country of residence in the EU. We would appreciate the chance to resolve your concern first.

9. Minors

Our services are not aimed at children. You must be at least [16] years old to create an account or subscribe to our newsletter. Under Article 7 of the LOPDGDD, people under 14 cannot consent to the processing of their data without the authorisation of their parents or guardians. If we learn that we hold data of someone below the minimum age without valid authorisation, we will delete it. If you believe this has happened, please contact us.

10. Links to other websites

Our articles may link to other websites or include embedded content (for example videos or social media posts). Those sites have their own privacy policies, and we are not responsible for how they process your data. Embedded content may collect data about you as if you had visited the other site directly.

11. Changes to this policy

We may update this Privacy Policy to reflect changes in the law, in our services or in the providers we use. We will publish the new version on this page with its date. If the changes are significant, we will inform Members and Subscribers by email or with a notice on the Platform before they take effect.

12. Contact

For any question about this policy or your personal data:

[LEGAL NAME OF THE COMPANY OR SOLE TRADER]
[FULL REGISTERED ADDRESS]
Privacy contact: [PRIVACY CONTACT EMAIL]
General contact: info@maghrebnow.com

See also our Terms of Service, Cookie Policy and Disclaimer.