Last updated: 30 August 2026
SecureWeb (“SecureWeb”, “we”, “us”) provides website security auditing, penetration testing, secure-code review and related cybersecurity services through secureweb.ma. This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights you have over it.
We wrote this policy to satisfy both Moroccan Law No. 09-08 on the protection of individuals with regard to the processing of personal data (supervised by the CNDP) and the EU General Data Protection Regulation (GDPR), which applies where we process the data of people in the European Union.
1. Who is responsible for your data
The data controller is:
| Legal entity | Secureweb SARL |
| Legal form | Société à Responsabilité Limitée (SARL) |
| Commercial register (RC) | 30354378 |
| ICE | 003951934000013 |
| Privacy contact | Privacy@secureweb.ma |
| General contact | contact@secureweb.ma |
2. Scope
This policy covers the website secureweb.ma (including its French and Arabic versions), the free tools we publish on it, and the client engagements that begin through it. It does not cover third-party websites you reach via links from our site, or the security posture of websites you ask us to scan.
3. What we collect, why, and on what legal basis
3.1 Information you give us directly
Contact, quote and service request forms — including Contact Us, Free Assessment, Premium Plan, Basic Plan, Premium Scanner, Secure Coding and Bug Bounty Program request.
- Data: name, email address, telephone number, website URL, and any message you write.
- Purpose: to answer you, prepare a quote, and deliver the service you asked for.
- Legal basis: performance of a contract or pre-contractual steps at your request (GDPR Art. 6(1)(b)); your consent under Law 09-08.
Free Website Scanner (/free-website-scanner/)
- Data: your email address and the URL of the website you asked us to scan.
- Purpose: to run the scan, return your report, and follow up about our services.
- Storage: the email/URL pair is stored in a dedicated database on our server and added to our marketing contact list at Brevo.
- Legal basis: consent (GDPR Art. 6(1)(a)) and our legitimate interest in following up on a tool you voluntarily used (Art. 6(1)(f)).
Source Code Review submissions (/free-code-review-service/)
- Data: your email address, plus any source code you paste or upload.
- Purpose: to perform the review you requested and send you the findings.
- Legal basis: performance of a contract / pre-contractual steps (Art. 6(1)(b)).
- Source code you submit is treated as confidential. We do not publish it, reuse it, share it with other clients, or use it to train any model.
Vulnerability reports and bug-bounty writeups (/secureweb-vulnerability-disclosure-program/, /writeup/)
- Data: your name, email, optional social profile link, the vulnerability details you describe, and any files you attach.
- Purpose: to triage, verify and remediate the reported issue, and — where you ask us to — to credit you publicly.
- Legal basis: consent, and our legitimate interest in operating a coordinated disclosure programme (Art. 6(1)(f)).
Newsletter subscription
- Data: email address, and optionally your website.
- Purpose: to send you security updates and offers.
- Legal basis: consent only. Our signup requires an explicit consent checkbox and will not submit without it. You can withdraw at any time using the unsubscribe link in every email.
3.2 Information collected automatically
Server and CDN logs. Our hosting provider and Cloudflare record your IP address, the time of your request, the page requested, your browser user-agent and referring page. We use these to keep the site available, diagnose faults, and detect abuse. Legal basis: legitimate interest in the security and stability of our service (Art. 6(1)(f)).
Comments. If you comment on an article, WordPress stores the name, email and IP address you submit alongside the comment.
3.3 Our free tools — what they do not collect
We build security tools, so we are specific about this:
- Password Strength Checker (
/password-checker/) runs entirely in your browser. The password you type is never transmitted to our server, never logged, and never stored. You can verify this by loading the page and disconnecting from the network. - Website Safety Checker (
/website-safety-checker/) does not store the URLs you submit. Each URL is checked live and the result is discarded. The URL is, however, sent to the third-party reputation services listed in section 5 in order to perform the check. - The Free Website Scanner does store your email and the scanned URL — see 3.1.
4. Cookies and tracking
We do not use advertising, profiling or analytics cookies. A visit to our public pages sets no cookies at all. We do not run Google Analytics, Meta Pixel, or any session-recording or heatmap tool.
Cookies appear only in these limited cases:
| Cookie source | When | Purpose |
|---|---|---|
| Google reCAPTCHA | When you interact with a form | Distinguishes humans from bots. Loaded only once you begin using a form — not on page load. |
| WordPress session/comment cookies | If you comment, or log in as staff | Remembers your comment details; authenticates staff accounts. |
| Cloudflare | Site-wide, as needed | Security and bot mitigation for our infrastructure. |
Because we set no tracking cookies, we do not display a consent banner. If we ever introduce analytics or advertising technology, we will add a consent mechanism and update this policy before doing so.
5. Who we share data with
We do not sell your personal data. We share it only with service providers (“sub-processors”) that help us operate:
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Contabo GmbH | Hosting of our server | All site data at rest | Lauterbourg, France (EU) |
| Cloudflare | CDN, DNS and security proxy | IP address, request metadata | Global edge network |
| Brevo (Sendinblue) | Email marketing and transactional email | Email address, website URL | France (EU) |
| Google (reCAPTCHA) | Bot protection on forms | IP address, browser signals | United States |
| Google (Safe Browsing API) | URL reputation lookups for the Safety Checker | The URL you submit | United States |
| PhishTank (Cisco) | Phishing reputation lookups | The URL you submit | United States |
| Automattic (Gravatar) | Comment avatars | Hashed email address | United States |
We may also disclose data where we are legally required to — for example, in response to a valid order from a Moroccan judicial or administrative authority.
International transfers. Our hosting and email infrastructure are located in the European Union. Transfers to the US providers above rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Transfers from Morocco follow the conditions of Articles 43–44 of Law 09-08.
6. How long we keep data
| Data | Retention period |
|---|---|
| Contact, quote and service-request submissions | 24 months from the last contact with you |
| Free Website Scanner records (email + scanned URL) | 12 months |
| Newsletter subscriptions | Until you unsubscribe, then removed within 30 days |
| Uploaded source code and files submitted for review | Deleted 90 days after the review is delivered |
| Vulnerability reports | 24 months, to maintain a remediation record |
| Client engagement records and invoices | As required by Moroccan accounting and tax law (currently 10 years) |
| Server and CDN logs | 12 months |
| Comments | Until you ask us to delete them |
When a period expires we delete the data or irreversibly anonymise it.
7. Your rights
Under both Law 09-08 and the GDPR you may:
- Access the personal data we hold about you and obtain a copy.
- Rectify data that is inaccurate or incomplete.
- Erase your data (“right to be forgotten”) where we have no overriding obligation to keep it.
- Object to processing based on our legitimate interests, and to direct marketing at any time.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Withdraw consent at any time, without affecting processing carried out before withdrawal.
- Data portability (GDPR) — receive your data in a structured, machine-readable format.
To exercise any of these, email Privacy@secureweb.ma. We respond within 30 days. We may ask you to confirm your identity before acting on a request.
Complaints.
- In Morocco: you may lodge a complaint with the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) — www.cndp.ma.
- In the EU/EEA: you may complain to the supervisory authority of your country of residence.
8. How we protect your data
- All traffic to secureweb.ma is encrypted with HTTPS/TLS.
- Access to our server and databases is restricted to authorised personnel using key-based authentication.
- Administrative accounts are limited in number and reviewed periodically.
- Uploaded files and client source code are stored on EU-based infrastructure and access is limited to the staff performing the review.
- We apply security updates to our platform and monitor for unauthorised access.
No system is perfectly secure. If a breach affects your personal data and presents a risk to your rights, we will notify the CNDP and — where the GDPR applies — the relevant supervisory authority within 72 hours, and inform you directly where the risk is high.
9. Children
Our services are directed at businesses and website owners. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
10. Changes to this policy
We may update this policy as our services or the law change. The “last updated” date at the top always reflects the current version. Material changes will be announced on this page before they take effect.
11. Contact
Questions about this policy, or about how we handle your data:
Secureweb SARL
Email: Privacy@secureweb.ma
Website: https://secureweb.ma

