Privacy Policy
How AYAM collects, uses and protects personal data.
Draft — This document is a working draft for professional legal review. It is not legal advice and has not been marked as compliant or approved. Where information is shown as “to be confirmed”, it will appear once configured by AYAM.
Data controller
The data controller responsible for your personal data is to be confirmed (the AYAM operator). Contact: to be confirmed. Where these details are shown as "to be confirmed", they will appear once configured in Admin → Settings → Legal & Privacy.
Purpose of this policy
This policy explains what personal data AYAM collects, why, the legal basis, who sees it, how long it is kept, and your rights. It reflects the actual AYAM system. It does not claim AYAM collects anything it does not collect.
Categories of personal data AYAM processes
- Booking data: stay dates, number of guests, booking reference, booking source (direct, Airbnb, Booking.com, other).
- Guest contact details: name, email, phone — to communicate about your stay and services.
- GuestAccess information: the record AYAM holds for your stay, including property access details reserved for registered guests.
- Digital check-in information: confirmed guest details and, where enabled, the status of your digital check-in.
- Identity documentation: where identity verification is configured, a copy of an identity document (e.g. passport, national ID). This is particularly sensitive and handled as set out below.
- Stay Agreement records: where digital check-in is enabled, the signed agreement, version and timestamp.
- Property / access information: physical access method, codes and instructions, released per the configured timing.
- Service order information: orders for Stock My Fridge, Make It Special, Personal Shopper and other services.
- Personal Shopper requests: your free-text request, optional reference images, preferred brand, budget preference, needed-when/where details.
- Uploaded reference images: optional images you upload for Personal Shopper, stored privately and viewable only through signed access.
- Communications with AYAM: messages you send via WhatsApp, the contact form, or the Guest Guide.
- Payment-related information: where you pay AYAM directly, payment is processed by a payment provider; AYAM holds references and amounts, never full card details.
- Technical / device information: limited technical data necessary for the service (such as user-agent at consent time). AYAM does not currently run analytics tracking.
- Cookies: see the Cookie Policy. AYAM uses essential technologies and, with your permission, optional preference cookies.
Purposes of processing and legal basis
- To deliver your stay and services: performance of the booking and AYAM's services to you.
- To communicate with you about your stay and services: legitimate interest in providing the booked service.
- To verify identity where configured: compliance with applicable legal obligations and the legitimate interest in secure access.
- To process payments where AYAM controls them: performance of the contract and legal/accounting obligations.
- To respond to your requests and complaints: legitimate interest in guest service.
- For security and access logs: legitimate interest in protecting guests and property.
- For optional cookies: consent, which you can withdraw at any time.
Recipients and service providers
- Payment providers: where AYAM processes payments directly, the connected payment provider receives payment data.
- Accommodation / property operators: where a property is managed for a third-party owner, relevant stay data may be shared with that operator as necessary for the stay.
- Third-party service suppliers: where you request a service supplied by a third party (florist, transport provider and similar), the necessary details are shared with that supplier to fulfil your request.
- Hosting: AYAM is hosted on the Base44 platform. Hosting location: to be confirmed (to be confirmed where not yet configured).
- AYAM does not sell your personal data.
International data transfers
Because AYAM uses cloud hosting, your data may be processed outside Morocco. Where applicable, this is subject to the international transfer reference: to be confirmed (to be confirmed where not yet configured). AYAM seeks to use providers that offer appropriate safeguards, subject to applicable law.
Retention
AYAM retains data only as long as necessary and as configured in Admin → Settings → Legal & Privacy (Retention). Identity documents are retained per the configured retention period and deleted thereafter unless a legal obligation requires longer. Accounting and contract records are retained as long as legally required. Personal Shopper reference images are retained for a shorter default period. You can ask about retention by contacting AYAM.
Security
AYAM uses reasonable technical and organisational measures to protect personal data. Identity documents are stored privately and accessed only through signed, time-limited access. Access to sensitive data is restricted to authorised administrators.
Identity documentation — sensitive data
Identity documents are collected only where configured (globally or per property) and only when required for check-in or legal compliance. They are stored privately, never public. Access is restricted to authorised admins. AYAM does not automatically OCR or store identification numbers unless separately configured and legally reviewed. Retention follows the configured period; deletion occurs thereafter unless a legal obligation requires otherwise.
Your rights
Subject to applicable law, you may have the right to access, rectify, object to, or request restriction or erasure of your personal data, and to data portability. To exercise these rights, contact AYAM at the contact details below. AYAM will respond within a reasonable time, subject to applicable law.
Children / minors
AYAM does not knowingly collect personal data from children. Bookings must be made by an adult. Where a minor is part of a guest party, their data is processed as part of the booking adult's reservation.
Moroccan data protection (Law 09-08)
AYAM's privacy architecture is designed with Moroccan Law 09-08 and CNDP requirements in mind. AYAM does not claim CNDP registration or authorization unless a real reference has been configured. CNDP declaration reference: to be confirmed (to be confirmed). CNDP authorization reference: to be confirmed (to be confirmed).
Complaints / contact
For any privacy matter, contact AYAM at to be confirmed (to be confirmed where not yet configured). You may also have the right to lodge a complaint with the competent supervisory authority, subject to applicable law.
Policy updates
AYAM may update this policy. The effective date is shown above. Material changes take effect from their effective date; the version you accepted is preserved on your consent record.
DRAFT — for professional legal review. This document is a working draft prepared for AYAM. It is not legal advice and has not been marked as compliant, approved, or registered with any authority. Final wording must be reviewed by a qualified legal professional before production use. Where company or legal information is shown as "to be confirmed", it will appear once configured by AYAM in Admin → Settings → Legal & Privacy.