Privacy Policy
Last updated: 18 August 2026 — Version 1.0
This Privacy Policy explains how NOERIS collects, uses, shares and protects personal data. It is published in accordance with Moroccan Law No. 09-08 of 18 February 2009 on the protection of individuals with regard to the processing of personal data (Dahir No. 1-09-15) and its implementing decree No. 2-09-165, and — where it applies to visitors and clients in the European Economic Area — with Regulation (EU) 2016/679 (GDPR).
1. Scope
This Policy applies to personal data collected through https://noeris.studio, the contact form, the Business Scan, email, WhatsApp, meetings, proposals, onboarding and client administration.
It applies when NOERIS decides why and how personal data is used and therefore acts as data controller (responsable de traitement). Personal data that NOERIS processes solely on a client’s instructions — for example the customers or staff of a client whose CRM or website we operate — is governed by that client’s own privacy information and by the Data Processing Agreement between NOERIS and that client. In those cases NOERIS acts as processor (sous-traitant).
2. Who is responsible for your data
| Data controller | NOERIS SARL AU, trading as NOERIS Creative Studio |
| Registered office | Oasis Offices Latitudes, Route de l’Oasis, Bureau 304, Maarif, Casablanca, Morocco |
| Commercial Register (RC) | 723695 — Casablanca |
| ICE | 003937652000052 |
| Email for privacy requests | contact@noeris.studio |
| Person responsible for data protection | Alexandra Penneman, Gérante. NOERIS has not appointed a formal Data Protection Officer under Article 20 of Law No. 09-08; privacy requests are handled directly by the manager named here. |
| CNDP declaration reference | Declaration to the CNDP is in preparation. The récépissé reference will be published here once issued. |
| EU representative (GDPR Art. 27) | A representative established in Belgium is being designated under Article 27 GDPR. Full name and contact address will be published here once the designation is signed. |
3. What personal data we collect
| Context | Data concerned |
|---|---|
| Website visit | IP address, device and browser information, operating system, requested pages, referring page, timestamps, security events, and cookie or consent choices where applicable |
| Contact form | First name, last name, email address, company name, your message, and your privacy acknowledgement and optional marketing choice |
| Business Scan | Email address, your answers, calculated category scores, the recommended NOERIS pillar, technical submission data, privacy acknowledgement and optional contact or marketing choice |
| Direct contact | Name, business name, role, email, phone or WhatsApp number, preferred language, website or social link, appointment details and related correspondence |
| Proposal and onboarding | Business needs, goals, budget range, project brief, billing details, signatory details, feedback, approvals, meeting notes and supplied materials |
| Active client relationship | Contract, invoices, payment status, project communications, account access, deliverables, support history and records required to provide the services |
| Marketing | Contact details, consent record, communication preferences, engagement with messages and unsubscribe record |
NOERIS asks visitors to share only the information relevant to their enquiry. Sensitive data within the meaning of Article 1 of Law No. 09-08 — data revealing racial or ethnic origin, political, philosophical or religious opinions, trade-union membership, or concerning health — as well as identity documents, criminal-offence data and children’s data, should be provided only where NOERIS has expressly requested them through a suitable secure process.
4. Which information is required and which is optional
Fields marked as required on our forms are necessary to submit the form and obtain the requested reply or result. If you do not provide them, we cannot process the enquiry.
- Contact form — name, email and message are required in order to respond. Company name is optional.
- Business Scan — an email address and your answers are required to generate and send the result.
- Marketing consent — always optional, always presented as a separate unticked box. Declining has no effect on your ability to contact us, receive your Business Scan result or request a proposal.
5. Why we use personal data, and on what legal basis
| Purpose | Legal basis under Law No. 09-08 | Corresponding GDPR basis |
|---|---|---|
| Answer an enquiry, arrange a call and prepare a requested proposal | Consent of the data subject / pre-contractual steps (Art. 4) | Art. 6(1)(b) pre-contractual steps; Art. 6(1)(f) legitimate interests |
| Run the Business Scan, calculate and display the result, save the submission and prevent spam | Consent of the data subject (Art. 4) | Art. 6(1)(f) legitimate interests; Art. 6(1)(a) consent where required |
| Create, manage and deliver a client engagement | Performance of a contract (Art. 4) | Art. 6(1)(b) contract |
| Administer invoices, tax, accounting and legal records | Compliance with a legal obligation (Art. 4) | Art. 6(1)(c) legal obligation |
| Maintain website, account and system security | Legitimate interest of the controller (Art. 4) | Art. 6(1)(f) legitimate interests |
| Improve services using aggregated or de-identified patterns | Legitimate interest, with data minimisation | Art. 6(1)(f) legitimate interests |
| Send newsletters, offers or promotional follow-up | Prior express consent (direct marketing) | Art. 6(1)(a) consent |
| Measure audience or advertising performance through optional cookies | Prior consent, per CNDP Deliberation D-939-2025 | Art. 6(1)(a) consent |
Where NOERIS relies on legitimate interests, it weighs the business need, your reasonable expectations, the amount of data involved and the possible effect on your rights.
6. The Business Scan
The Business Scan uses your answers to assign scores across NOERIS’s Creative, Growth and Systems categories and displays a general recommendation. It is a rules-based diagnostic, not an automated decision producing legal or similarly significant effects, and it does not involve profiling for advertising purposes.
The result is general guidance. A human conversation and a written scope remain necessary before NOERIS recommends or sells a specific service. You may ask us at any time to explain how a result was produced.
7. Who receives your data
Access to personal data is limited to people who need it for the stated purpose. Recipients may include:
- NOERIS team members and contracted specialists working under confidentiality duties;
- Hostinger International Ltd (Cyprus) — website hosting, server infrastructure, email and backups;
- Elementor Ltd (Israel) — website builder and form handling software;
- email, calendar, video-call, cloud-storage and business-productivity providers;
- CRM, project-management, automation and client-support providers;
- analytics, advertising and social-media providers, only where you have made the relevant cookie choice;
- payment, banking, accounting, tax, legal and insurance providers; and
- public authorities, where disclosure is legally required.
For client projects, data may also be entered into platforms selected in the proposal or instructed by the client, such as a website CMS, hosting platform, CRM, booking system, advertising account, analytics service or communication tool.
NOERIS does not sell personal data and does not share it with third parties for their own marketing purposes.
8. Where your data is processed
NOERIS is established in Morocco. Data submitted through the website or during a project may be processed in Morocco and in countries where our approved service providers operate, including Cyprus, the European Union, Israel and the United States.
Under Moroccan law. Articles 43 and 44 of Law No. 09-08 require prior CNDP authorisation for a transfer of personal data to a country that does not provide an adequate level of protection. NOERIS includes its hosting and processing arrangements in its CNDP filings and will obtain the required authorisation for any transfer that falls within Article 43.
Under GDPR. Morocco has no European Commission adequacy decision. Where Chapter V of the GDPR applies to a transfer from the EEA, NOERIS and the relevant party use an approved safeguard — commonly the European Commission’s Standard Contractual Clauses — together with the applicable module, a transfer impact assessment and any supplementary measures. You may request information about the safeguard applied to a specific transfer by writing to contact@noeris.studio.
9. Cookies and similar technologies
A cookie is a small file placed on your device when you visit a website. NOERIS also treats browser local storage and similar terminal technologies as cookies for the purposes of this section.
Under CNDP Deliberation No. D-939-2025 of 28 November 2025, the placing of non-essential cookies on a user’s terminal requires prior consent, is subject to a simplified declaration to the CNDP, and cookie-derived personal data together with the record of your choice may be kept for a maximum of six months. Strictly necessary cookies do not require consent.
9.1 Cookies currently in use
As at the date of this Policy, NOERIS runs no analytics, advertising or social-media tracking on this website. Only the following strictly necessary and functional technologies may be set:
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| PHPSESSID | noeris.studio | Maintains the server session while you browse or submit a form | Strictly necessary | Session |
| wordpress_test_cookie | noeris.studio (WordPress) | Checks whether your browser accepts cookies | Strictly necessary | Session |
| _lscache_vary | noeris.studio (LiteSpeed Cache) | Serves you the correct cached version of a page | Strictly necessary | Session |
| elementor (local storage) | noeris.studio (Elementor) | Stores page interface state so components display correctly | Functional | Until cleared |
| wordpress_logged_in_*, wordpress_sec_*, wp-settings-* | noeris.studio (WordPress) | Authentication and interface preferences — set only for NOERIS staff who log in to the site administration. These are never set for ordinary visitors. | Strictly necessary | Session to 1 year |
Because no non-essential cookie is currently placed, browsing this website does not require a consent banner. This will change as soon as the technologies in section 9.2 are activated.
9.2 Technologies we plan to introduce
NOERIS intends to add audience measurement and advertising measurement. When these are activated, they will be placed only after you give consent through a consent banner that lets you accept or refuse each category with comparable ease, and change your choice later. This Policy and the table above will be updated at the same time, and the corresponding simplified declaration will be filed with the CNDP.
| Technology | Provider | Purpose | Category | Typical duration |
|---|---|---|---|---|
| Google Analytics 4 (_ga, _ga_*) | Google Ireland Ltd / Google LLC | Audience measurement: pages viewed, sessions, traffic sources | Analytics — consent required | Maximum 6 months, per CNDP D-939-2025 |
| Meta Pixel (_fbp, fr) | Meta Platforms Ireland Ltd | Measures the performance of advertising campaigns and builds audiences | Advertising — consent required | Maximum 6 months, per CNDP D-939-2025 |
| Consent record | noeris.studio | Stores your cookie choices so we do not ask again on every page | Strictly necessary | Maximum 6 months |
Where a cookie provider is established outside Morocco, the transfer rules in section 8 apply and the appropriate CNDP authorisation will be obtained before activation.
9.3 Web fonts
All typefaces used on this website are served from NOERIS’s own servers. No font request is made to Google or any other third party when you load a page, so your IP address is not transmitted to a font provider.
9.4 Managing cookies
You can delete or block cookies at any time through your browser settings. Blocking strictly necessary cookies may prevent parts of the website from working correctly.
10. How long we keep your data
NOERIS keeps identifiable data only for the period needed for the stated purpose, for legal obligations, and for the establishment or defence of legal claims.
| Record | Retention period |
|---|---|
| General contact enquiry that does not become a project | 24 months after the last meaningful contact |
| Business Scan email, answers and result | 12 months after submission or last follow-up, then deletion or irreversible aggregation |
| Optional marketing record | Until consent is withdrawn, or 24 months without meaningful engagement; a minimal suppression record is kept so that we do not contact you again |
| Proposal that does not proceed | 24 months after expiry or last discussion |
| Active client and project records | For the duration of the engagement plus a reasonable handover and support period |
| Contracts, invoices, payment and accounting records | 10 years, as required by Article 22 of the Moroccan Commercial Code and applicable tax law |
| Project files and backups | According to the proposal, maintenance plan, backup cycle and agreed handover; stated during onboarding |
| Server and security logs | 6 months, unless an incident requires longer preservation |
| Cookie-derived data and record of cookie choice | 6 months maximum, per CNDP Deliberation D-939-2025 |
A legal hold, an active dispute, fraud prevention or a valid request from an authority may justify a longer period for the records concerned.
11. How we protect your data
NOERIS applies technical and organisational measures proportionate to the nature of the data and the services involved, in accordance with Article 23 of Law No. 09-08. These include controlled and role-based access, confidentiality commitments for staff and contractors, encrypted transmission (HTTPS) across the whole site, account protection, software maintenance and updates, backups appropriate to the service, and documented procedures for removing access and responding to incidents.
Every online transmission carries some residual risk. Please use the contact form for ordinary business enquiries, and agree a secure method with us before sending sensitive or high-risk information.
12. Your rights
Under Law No. 09-08 and, where applicable, the GDPR, you may exercise the following rights free of charge:
- Right of information and access (Art. 7 of Law 09-08; Art. 15 GDPR) — obtain confirmation that we process your data, a copy of it, and information about how it is used;
- Right of rectification (Art. 8; Art. 16 GDPR) — have inaccurate or incomplete data corrected or updated;
- Right of erasure (Art. 8; Art. 17 GDPR) — have data deleted where it is inaccurate, incomplete, out of date, or where its collection, use or storage is prohibited;
- Right to object (Art. 9; Art. 21 GDPR) — object on legitimate grounds to processing, and object to direct marketing at any time without giving a reason;
- Right to restriction of processing (Art. 18 GDPR, where the GDPR applies);
- Right to data portability (Art. 20 GDPR, where the GDPR applies) — receive data you provided in a structured, commonly used, machine-readable format;
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
How to exercise them. Write to contact@noeris.studio, or by post to NOERIS SARL AU, Oasis Offices Latitudes, Route de l’Oasis, Bureau 304, Maarif, Casablanca, Morocco. State which right you wish to exercise and the email address or reference concerned. We may ask for proportionate information to verify your identity and protect your data from unauthorised disclosure.
Our response time. We reply within 30 days of a verified request. Where a request is complex or we receive several requests from you, we may extend this period once and will tell you why.
To unsubscribe from marketing messages, use the unsubscribe link in any message or write to contact@noeris.studio. Unsubscribing takes effect immediately and at the latest within 3 working days.
13. Complaints
If you are not satisfied with our response, you may lodge a complaint with the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP), the Moroccan supervisory authority: www.cndp.ma.
Where the GDPR applies to you, you may also contact the data-protection supervisory authority of the EEA country of your habitual residence, your workplace, or the place of the alleged infringement.
14. Children
This website and NOERIS’s services are directed to adults acting in a professional context. We do not knowingly collect personal data from anyone under 18. A person under 18 should use this website through a parent, guardian or authorised organisational representative. If you believe a minor has provided us with personal data, write to contact@noeris.studio and we will delete it promptly.
15. Changes to this Policy
NOERIS may update this Policy when its website, forms, services, providers or legal obligations change. The current version and its date appear at the top of this page. A material change affecting an existing marketing consent or an ongoing client processing arrangement will be communicated to the people concerned where required.
Previous versions are available on request from contact@noeris.studio.
16. Contact
NOERIS SARL AU — NOERIS Creative Studio
Oasis Offices Latitudes, Route de l’Oasis, Bureau 304, Maarif, Casablanca, Morocco
contact@noeris.studio
See also our Terms and Conditions.