Skip to main content
Logo Tachrone — Plateforme BTP MarocAccueil Tachrone.ma

TACHRONE PRIVACY POLICY

Last updated: August 6, 2026

This Privacy Policy explains how Tachrone collects, uses, shares and protects your personal data when you use the Tachrone.ma platform, on the web and in the mobile application. It sets out the data we process, the purposes and legal bases of these processing operations, the third parties with which data is shared, how long it is kept, and the rights you have and how to exercise them.

1. Data controller

TACHRONE, a company incorporated under Moroccan law, registered with the Trade Register of Mohammedia under number 35301, with its registered office at BD PALESTINE 4, LOT HOURIA 1, ETAGE 2 APPT 3, Mohammedia, Morocco, is the controller of the personal data collected on the Tachrone.ma platform (the website tachrone.ma and the mobile application).

For any question regarding this policy or your personal data, you may contact our privacy point of contact at [email protected].

The processing of data has been notified to and authorised by the National Commission for the Control of Personal Data Protection (CNDP) under number D-765/2024, in accordance with Law No. 09-08 enacted by Dahir 1-09-15 of 18 February 2009.

2. Data we collect

  • Account data: last name, first name, email, phone, password (stored encrypted), account type;
  • Professional profile data: company name, trade register (RC), company identifier (ICE), address, city, logo, description, social media links, years of experience, certifications;
  • Professional verification documents ("Verified Company" badge): copy of ICE/RC, tax compliance certificate, proof of years of activity, photos of premises, director's name, WhatsApp number, and contact details of reference clients (name and contact) that you provide;
  • Team members: when you add collaborators to your professional profile, their name, email and photo that you provide;
  • Content you publish: cover photos, products, projects, reviews, messages, voice messages (audio recordings captured via your device's microphone when you record a message in the inbox), quote requests;
  • Conversational assistant data: the content you enter in the assistant, your preferences, browsing history (profiles, products, categories, cities), project information (type, phase, indicative budget) and useful notes, to personalise recommendations;
  • Third-party authentication data: identifier and email provided by Google or Apple when you use sign-in via these services;
  • Technical and usage data: device type, operating system, connection logs, device identifier for push notifications, and contact events (call, WhatsApp) between users;
  • Usage statistics: we measure how the service is used, for internal monitoring and improvement purposes. We record: the pages viewed and the sequence of visits within a single session (entry page, exit page, duration, number of pages), the listings, products and projects viewed together with their city and category, the searches carried out (terms entered, filters applied, number of results obtained and the result selected, if any), where the visit came from and the domain name of the referring site, the type of device used (website, iOS or Android application), the actions performed on the service (adding to favourites, saving a project, requesting a quote, sending a message, publishing content or a review, progress through the sign-up journey, subscription), as well as technical display-performance measurements intended to detect slow pages. This measurement is carried out with our own means, with no advertising cookie and no third-party analytics tool, and these statistics are not displayed to any user of the service. You may object at any time to these measurements being linked to your account (see the "Your rights" section).
  • IP address: it is never kept in clear text. At sign-up, only an irreversible cryptographic fingerprint is stored, in order to prevent fraudulent account creation. For view statistics, it is used solely to derive a fingerprint using a key that is renewed every day and never retained: after twenty-four hours, that fingerprint can no longer be linked back to an address, including by us. Finally, it is used on a transient basis for request rate-limiting.
  • Favourites and saved items: products, service providers and projects you add to your favourites or save;
  • Simulator data: when you request an estimate by email, the email address provided and the simulation parameters and results;
  • Newsletter: if you subscribe to it from the website, your email address and the date of your subscription. This subscription is independent from creating an account and you may unsubscribe at any time via the link included in every mailing or by writing to us;
  • Location: only the city you declare. We do not collect your precise GPS location.

3. Purposes and legal bases

We only process your data for specified, explicit and legitimate purposes, on the following legal bases:

  • Performance of the contract: creation and management of the account, connecting professionals and users, messaging, quote requests, favourites;
  • Consent: microphone access for voice messages, push notifications, content submitted to the conversational assistant, sending estimates by email, and subscription to our newsletter (direct marketing). You may withdraw your consent at any time, and unsubscribe from the newsletter via the link included in every mailing;
  • Legitimate interest: platform security, fraud and abuse prevention, content moderation, service and recommendation improvement;
  • Legal obligation: retention of documents related to transactions and responding to requests from competent authorities.

4. Sources of data

The data we process comes from:

  • information you provide directly to us (registration, profile, content);
  • data generated by your use of the service (technical data, history);
  • the Google and Apple authentication providers when you choose to sign in via these services;
  • third-party data you provide to us (team members, reference clients) — see section 11.

5. Recipients and processors

We never sell your personal data. We only share it with the technical providers strictly necessary for the operation of the service, acting as processors on our behalf:

  • Amazon Web Services (AWS) — hosting and file storage (European Union);
  • Google Firebase — authentication (Google and Apple) and push notifications;
  • Payzone — payment of professional subscriptions (on the web);
  • Meilisearch — internal search engine (hosted on our infrastructure);
  • Anthropic (Claude) — conversational assistant and recommendations;
  • Voyage AI — semantic indexing of content for search;
  • MapTiler and OpenStreetMap / Nominatim — map display and city geocoding;
  • Sentry — technical monitoring and error detection (personal data filtered);
  • Upstash — rate-limiting based on IP address;
  • Email delivery provider (SMTP) — transactional emails and newsletter.

We may also disclose data where required by law, at the request of a competent authority, or in connection with a corporate reorganisation, with appropriate safeguards.

6. Data transfers outside Morocco

All of your data, including all sensitive verification documents (RC/ICE, tax certificate, photos of premises, reference clients), your private messages and their attachments, is hosted within the European Union (Amazon Web Services, France).

Only three limited categories of data are transferred to the United States, to providers subject to protection safeguards:

  • authentication identifiers (Google and Apple), when you use sign-in via these services;
  • push notification tokens and the notification preview (via Google Firebase Cloud Messaging);
  • the content you voluntarily submit to the conversational assistant and, where applicable, the semantic indexing of public profile descriptions (via Anthropic and Voyage AI).

These transfers are governed by appropriate safeguards, such as the EU-US Data Privacy Framework and standard contractual clauses. Your verification documents, payments and private messages are never transferred to these providers.

7. Data retention

We keep your data for the entire duration of the contractual relationship, that is, as long as your account is active. After your account is closed, your data is deleted or anonymised at the latest 5 years after that closure.

However, certain data may be kept beyond this period where required by law (in particular documents related to transactions, subject to the applicable legal periods) or to preserve the integrity of exchanges with other users.

Usage statistics: the link between a view and the visitor's account is kept for 5 years, then permanently removed. Beyond that point, only traffic data remains, from which no one can be identified; it is kept without a time limit so that the audience history of profiles stays accurate over time. Deleting your account immediately detaches your identity from those views, without waiting for that period to elapse.

8. Your rights

In accordance with Law No. 09-08 and, where you reside in the European Union, with the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access: obtain confirmation that your data is being processed and receive a copy;
  • Right to rectification: correct your inaccurate or incomplete data (directly from your profile or on request);
  • Right to erasure: obtain the deletion of your data (see section 10);
  • Right to object: object, on legitimate grounds, to a processing of your data. As regards usage statistics, this right is exercised directly in the application, under Dashboard › My account › Usage measurement, without having to write to us. Once enabled, the objection takes effect immediately and your views are no longer linked to your account; they remain counted anonymously within traffic volumes, from which no one can be identified;
  • Right to restriction: request the temporary suspension of a processing;
  • Right to portability: receive a copy of your data in a structured format, upon request sent to [email protected];
  • Right to withdraw your consent at any time, for the processing operations that depend on it (microphone, notifications, assistant).

To exercise these rights, write to us at [email protected]. We respond to your request as soon as possible and within the time limits provided by law.

9. Complaint to the supervisory authority

If you consider that the processing of your data does not comply with the regulations, you have the right to lodge a complaint with the National Commission for the Control of Personal Data Protection (CNDP) in Morocco. Residents of the European Union may also refer the matter to the supervisory authority of their country.

10. Deletion of your account and data

You can delete your account at any time, directly in the app as well as on the web, from Dashboard > My account > Delete my account.

Without going through the app, the request can be made from tachrone.ma/en/dashboard?section=mon-compte#supprimer-mon-compte (sign-in required), or simply by email to [email protected] from the address associated with your account.

Deletion results in the erasure or anonymisation of your personal data and the removal of associated files (documents, photos, voice recordings). Merely deactivating or suspending the account does not amount to deletion: deletion is permanent. Some information may be kept in anonymised form or where required by law, under the conditions described in section 7.

11. Third-party data you provide to us

When you provide data about other people (members of your team, reference clients as part of professional verification), you warrant that you are entitled to provide them to us and that you have informed those persons of the use of their data. You undertake not to provide us with the private contact details of third parties without their consent. These persons may exercise their rights by contacting us at [email protected].

12. Microphone, audio data, biometrics and permissions

The application may access your device's microphone only when you voluntarily record a voice message in the inbox. This access is requested contextually, at the time of recording, and requires your explicit authorisation. We never use the microphone in the background. Audio recordings are stored securely within the European Union. Likewise, access to your photos and documents only occurs when you choose a file to send.

Biometric lock. The application offers an optional lock using Face ID, Touch ID or fingerprint, which you enable yourself from "My account". Verification is performed entirely by your device: we do not receive, process or store any biometric data. The system only returns a "success" or "failure" result to us. You can disable this lock at any time.

13. Automated decisions and artificial intelligence

Our conversational assistant relies on an artificial intelligence model provided by Anthropic (Claude). It receives the content you voluntarily submit to it as well as the public information of the profiles it recommends to you. We also use semantic indexing to rank and recommend service providers.

These processing operations do not produce any fully automated decision having a legal effect on you. The generated responses may be inaccurate and do not constitute professional advice. You may at any time request human intervention by writing to us at [email protected], and report any inappropriate content generated by the assistant directly in the application.

Technical usage logs of the assistant (consumption and quality monitoring) are kept in pseudonymized form — tied to a non-reversible identifier rather than to your account — and do not retain the text of your conversations.

14. Cookies and trackers

We only use cookies strictly necessary for the operation of the service: secure authentication cookies (httpOnly) and language preference. We do not use advertising cookies or third-party tracking tools for marketing purposes, and we do not use any advertising purpose without your consent.

15. Data security

We implement appropriate technical and organisational measures to protect your data: encryption of communications in transit (HTTPS/TLS), storage of passwords in encrypted form, authentication tokens kept in secure cookies (httpOnly), access control and logging. In the event of a data breach likely to create a risk to your rights, we take the required measures in accordance with applicable regulations.

16. Reserved for adults

The Tachrone.ma platform is strictly reserved for persons aged 18 and over. We do not knowingly collect data concerning minors. If we find that an account has been created by a person under 18, we delete it along with the associated data.

17. Changes to this policy

We may amend this Privacy Policy to reflect changes in our services or in regulations. In the event of a material change, we will inform you by appropriate means. The date of last update appears at the top of this page. We encourage you to review it regularly.

Privacy Policy — Morocco Construction Platform | Tachrone.ma