Privacy Policy
How Mizan handles personal data, in line with Moroccan Law 09-08.
Last updated:
1. Introduction
This Privacy Policy explains how Mizan collects and processes personal data when you use the Service, and how we support Firms in meeting their own obligations under Law No. 09-08 on the protection of individuals with regard to the processing of personal data, and the decisions of the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).
2. Who is responsible
The Service is operated by {{OWNER: legal entity name}}, {{OWNER: registered address}}. For questions about data protection, contact {{OWNER: data-protection contact email}}. Where required, our processing is declared to the CNDP under {{OWNER: CNDP declaration/authorisation number, if applicable}}.
3. Controller and processor roles
- For account and platform data (the Firm's own users, subscription and usage), Mizan is the data controller.
- For the personal data a Firm enters about its clients and matters (Firm Data), the Firm is the data controller and Mizan is a processor acting only on the Firm's documented instructions.
4. What data we process
- Account data: name, professional email, firm name, workspace address, role, password (stored only as a secure hash), and preferences.
- Usage and technical data: log-in events, IP address, device and browser information, and audit logs used for security and troubleshooting.
- Communications: waitlist, callback and support messages you send us, and messages exchanged with the marketing chat assistant on our website.
- Firm Data: client and matter records, hearing and procedure data, uploaded documents and case material, and billing data — processed on the Firm's behalf.
5. Why we process it and on what basis
We process account and usage data to provide, secure, support and improve the Service, to bill you, and to comply with legal obligations — on the basis of performing our contract with you, our legitimate interest in a secure and functioning service, and legal requirements. Firm Data is processed solely to deliver the Service to the Firm on its instructions. We do not sell personal data, and we do not use it for advertising.
6. AI processing — transparency
The Service includes AI features that extract, summarise and draft information from Firm Data. In the interest of an honest and safe use of AI:
- AI features are grounded in the Firm's own data; they are not a general search of the internet and do not draw on other firms' data.
- AI-generated output is preliminary and is clearly marked as such until a User reviews and confirms it. A human always remains in control; the system does not take legal decisions or auto-file anything.
- AI processing runs within the platform's per-firm isolation controls. Where a third-party AI provider is used to run a model, data is sent only to serve the request and is not used by us to train third-party foundation models.
- AI output may be inaccurate; it must be verified by a qualified professional and is not legal advice.
7. Where data is hosted
Firm Data and account data are hosted at {{OWNER: hosting location and provider — e.g. datacentre country/region and provider name}}. We choose hosting with appropriate security and, where relevant, we address any transfer of data outside Morocco in line with Law 09-08 and CNDP requirements (see section 12).
9. How long we keep data
We keep account data for as long as your Firm Account is active and for a limited period afterwards. Firm Data is retained under the Firm's control and deleted or anonymised after account closure per our Terms, except where the law requires longer retention. Backups are kept for a limited rolling period and then overwritten.
10. Security
We apply technical and organisational measures appropriate to the risk, including strict logical isolation between Firm Accounts, encryption of data in transit, access controls and audit logging, role-based permissions, and least-privilege access for AI features. No system is perfectly secure, but we work continuously to protect your data and will notify affected parties and the CNDP of a personal-data breach as required by law.
11. Your rights under Law 09-08
Subject to the conditions of Law 09-08, individuals have the right to be informed and to access, rectify and — on legitimate grounds — object to or request deletion of their personal data. For account data, contact us at {{OWNER: data-protection contact email}}. If your personal data was entered into the Service by a Firm (its client), please contact that Firm, which is the controller; we will assist the Firm in responding. You also have the right to lodge a complaint with the CNDP.
12. International transfers
If personal data is transferred outside Morocco (for example to a subprocessor abroad), we take the steps required by Law 09-08, which may include CNDP authorisation and appropriate contractual safeguards: {{OWNER: describe transfer mechanism / countries, or state that data stays in Morocco}}.
14. Not directed to children
The Service is a professional tool for law firms and is not directed to children. We do not knowingly collect personal data directly from children through the Service.
15. Changes to this policy
We may update this Privacy Policy. We will post the updated version with a new “last updated” date and, for material changes, notify you through the Service or by email.
16. Contact
For any question about this policy or about how your personal data is handled, contact {{OWNER: data-protection contact email}} or write to {{OWNER: registered address}}.
Items marked {{OWNER: …}} are placeholders the firm's owner (a practising lawyer) will complete before publication.