01Data Controller Identity

The controller of personal data collected via www.souhalegal.com is:

Souha Legal — Maître Abdelkarim Souha

CapacityAttorney registered at the Rabat Bar (Law 28-08)
Address12, Bahr Alchamal, Hay El Fath, Rabat 10000 — Morocco

02Data Collected and Purposes

We apply the data minimisation principle — only data strictly necessary for the stated purpose is collected.

CategoryPurposeSource
Identity: name, surnameClient relationship management, file openingContact form, e-mail, phone
Contact details: e-mail, phoneResponding to enquiries, sending documentsContact form, e-mail, phone
Case data: facts, documents, legal informationLegal services (advice, representation)Voluntary transmission within the mandate
Browsing data: IP address, pages visited, session durationSite security, aggregated analyticsAutomatic server collection
Billing data: bank details for wire transferContract performance, statutory accounting obligationsProvided by client upon payment of fees

Sensitive data: No sensitive data (racial/ethnic origin, political opinions, religious beliefs, health, biometric data) is collected without your express written consent and only when strictly necessary to defend your interests.

03Legal Bases for Processing

Pursuant to Article 4 of Moroccan Law 09-08 and Article 6 of the GDPR, each processing activity has an identified legal basis:

a) Contract performance (Art. 6(1)(b) GDPR · Art. 4 Law 09-08)

Data necessary for the attorney's engagement is processed to perform the mandate you entrust to us, or to take pre-contractual steps at your request.

b) Legal obligation (Art. 6(1)(c) GDPR)

Accounting and tax obligations (Moroccan Law 9-88, General Tax Code), anti-money laundering (Law 43-05), file archiving in accordance with the Rabat Bar regulations.

c) Legitimate interests (Art. 6(1)(f) GDPR)

Site security (connection logs, firewall) and anonymous audience measurement, provided these do not override your fundamental rights and freedoms.

d) Consent (Art. 6(1)(a) GDPR · Art. 4 Law 09-08)

For marketing communications, non-essential cookies or sensitive data, we will obtain your prior, free, specific, informed and unambiguous consent. You may withdraw it at any time without retroactive effect.

04Retention Periods

Data typeRetention periodLegal basis
Active client files (mandate documents)Duration of mandate + 10 years after closureRabat Bar regulations, civil limitation periods
Accounting and billing data10 years from end of financial yearMoroccan General Tax Code art. 212, Law 9-88
Prospect contact requests (no engagement)3 years from last contactCommercial limitation periods, CNDP guidelines
Server logs / browsing data12 monthsStatutory obligation (cybercrime)
AML data (anti-money laundering)5 years after end of business relationshipMoroccan Law 43-05, EU Directive 2015/849

Upon expiry of these periods, data is either permanently deleted or anonymised for statistical purposes.

05Recipients and Data Processors

Technical processors

Each processor is bound by a Data Processing Agreement (DPA) ensuring an adequate level of protection.

Legally authorised third parties

Your data may be disclosed to Moroccan judicial, administrative or tax authorities when required by law (court order, AML reporting obligation), or in the context of your mandate (courts, court registries, opposing party where necessary for your defence).

We never sell, rent or otherwise trade your personal data to third parties for advertising or commercial purposes.

06International Data Transfers

Where possible, your data is hosted and processed in Morocco or in the European Economic Area (EEA). When a transfer outside these areas is required, we ensure one of the following safeguards applies:

Google LLC is certified under the EU-US DPF for Fonts and Maps services.

07Your Rights

Under Moroccan Law 09-08 (Articles 7–14) and the GDPR (Articles 15–22), you have the following rights:

📄 Right of access (Art. 15 GDPR / Art. 7 Law 09-08)

Obtain a copy of your data and information about how it is processed.

✏️ Right to rectification (Art. 16 GDPR / Art. 8)

Have inaccurate data corrected or incomplete data completed.

🗑️ Right to erasure (Art. 17 GDPR / Art. 9)

Request deletion when data is no longer necessary or consent is withdrawn.

⏸️ Right to restriction (Art. 18 GDPR)

Suspend processing while a dispute is being verified.

📦 Right to data portability (Art. 20 GDPR)

Receive your data in a structured, machine-readable format.

🚫 Right to object (Art. 21 GDPR / Art. 12)

Object to processing based on legitimate interests or to direct marketing.

🤖 Automated decision-making (Art. 22 GDPR)

Not to be subject to a decision based solely on automated processing.

↩️ Withdrawal of consent (Art. 7(3) GDPR)

Withdraw consent at any time, without affecting prior lawful processing.

How to exercise your rights

Submit a written request to contact@souhalegal.com or by post to the firm. Response time: 30 days (extendable to 3 months for complex requests, with reasoned notice). Proof of identity may be requested.

Right to lodge a complaint — Morocco: CNDP (Commission Nationale de contrôle de la Protection des Données à caractère Personnel): www.cndp.ma.
EU residents may also contact the data protection authority of their Member State: EDPB member list.
California residents (CCPA) may submit requests via the same e-mail address above.

08Attorney–Client Privilege

As an attorney registered at the Rabat Bar, Maître Abdelkarim Souha is bound by absolute professional secrecy enshrined in Dahir n° 1-08-101 of 20 October 2008 enacting Law n° 28-08 on the organisation of the legal profession (Article 32), and by the deontological rules of the Rabat Bar.

This privilege covers all confidential information communicated in the attorney–client relationship: consultations, correspondence, case documents and personal information. It is permanent, general and absolute.

Data processed under the mandate is protected by this reinforced regime, which is distinct from and complementary to data protection law.

09Cookies and Trackers

Strictly necessary cookies

Essential for the site to function (security, navigation). No consent required. No personally identifiable data is collected.

Third-party cookies (Google Fonts & Maps)

Integration of Google Fonts and Google Maps Embed may place cookies by Google LLC, subject to Google's Privacy Policy. You may disable these through your browser settings.

No advertising cookies

We use no targeting, retargeting or behavioural tracking cookies. No browsing data is sold or shared with advertising networks.

Managing your preferences

Configure your browser (Chrome, Firefox, Safari, Edge) or visit youronlinechoices.eu to manage third-party cookies.

10Data Security

We implement appropriate technical and organisational measures in line with the state of the art (Art. 32 GDPR / Art. 23 Law 09-08):

In the event of a data breach (Art. 33–34 GDPR), we will notify the CNDP within 72 hours and inform you directly if the risk to your rights is high.

11Minors

Our site and services are not directed at persons under 16 years of age. We do not knowingly collect data relating to minors. If you are a parent or legal guardian and believe a child has sent us personal data, please contact us for immediate deletion.

In proceedings involving minors, processing is governed by special child protection rules and attorney–client privilege.

12Policy Updates

We reserve the right to update this policy to comply with changes in applicable law (Law 09-08, GDPR, CNDP or CJEU decisions) or our processing practices. The "last updated" date in the header will be revised accordingly. Significant changes will be highlighted on the site.

The version in force at the time of your visit applies.

13Contact and Complaints

Data Protection Contact

ResponsibleMaître Abdelkarim Souha
Address12, Bahr Alchamal, Hay El Fath, Rabat 10000 — Morocco
Response time30 days maximum (Art. 12 GDPR)

Supervisory Authority — Morocco

CNDP — Commission Nationale de contrôle de la Protection des Données à caractère Personnel
Corner rue Tichka and avenue Omar Ibn Khattab, Hay Riad, Rabat — www.cndp.ma

Supervisory Authority — European Union

EU residents may contact their national data protection authority: EDPB member list.