Hazim Systems

Legal

Privacy Policy

Last updated 2 September 2026

This policy explains what personal data I collect through this site and in the course of client work, why I hold it, and what you can do about it. Any question about it can go to hamza@hazimsystems.com.

Who I am

Hamza Hazim, trading as Hazim Systems, based in Morocco. I am the data controller for the personal data described below, within the meaning of Moroccan Law 09-08 on the protection of individuals with regard to the processing of personal data. Contact: hamza@hazimsystems.com.

What I collect

Three categories, and they are treated differently:

Why I use it, and on what basis

I do not sell personal data, I do not share it with advertisers, and I do not use it to build profiles.

Who else sees it

Only the service providers needed to run the business: email hosting, calendar scheduling, cloud storage, invoicing and accounting. Each is bound by a contract that restricts what they may do with the data.

I do not move your customer data out of systems you control unless you ask me to and the engagement agreement provides for it.

Where it goes

Some providers process data outside Morocco. Where that happens, the transfer relies on Standard Contractual Clauses, an adequacy decision, or an equivalent safeguard.

How long I keep it

Your rights

You can ask me to give you a copy of your data, correct it, delete it, restrict how I use it, or send it to someone else. You can object to processing based on legitimate interest, and withdraw consent where consent is the basis.

Write to hamza@hazimsystems.com and I will respond within one month. If you are not satisfied you can complain to your data protection authority, which in Morocco is the CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel).

How it is protected

Read access rather than administrative access wherever the work allows it. Credentials in a password manager, multi-factor authentication on every account that supports it, full-disk encryption on every device.

No system is perfectly secure and I will not pretend otherwise. If a breach affects your data I will tell you and the relevant authority within the time the law requires.

Children

These services are sold to businesses. I do not knowingly collect personal data from anyone under 16.

Changes

If this policy changes, the revised version appears here with a new date at the top. Material changes will be notified to active clients by email.

This document is provided in good faith and is not legal advice. Have it reviewed against the law that applies to you before relying on it.