Privacy Policy
MaCaisse is point-of-sale software for merchants (café-restaurant, retail shop, hair salon), consisting of a tablet application and an online area at macaisse.net. This page describes, as factually as possible, which data is actually processed by the software, why, with whom it is shared, how long it is retained and how to exercise your rights.
We have deliberately written this document on the basis of how the product actually works, including where it has limitations. Below you will therefore find information that most privacy policies leave unmentioned (no automatic purge, unhashed point-of-sale passwords, unencrypted local database).
1. Who is responsible for what
MaCaisse is published by SAGATEC — Société d’informatique, domotique et sécurité, limited liability company (SARL) under Moroccan law, with registered office at Lot Kortoba, Secteur 1, Meknès, Morocco — ICE [[ICE]], RC [[RC]], IF [[IF]]. Contact: info@sagatec.ma — +212 5 35 46 32 58 (landline) — +212 6 45 56 02 90 (management).
Data processing by MaCaisse falls into two distinct legal roles, which it is important not to confuse:
| Type of data | Data controller | MaCaisse's role |
|---|---|---|
| Merchant account data: identity of the subscriber, billing details and tax information, shops, tablets, subscription, invoices and payments, connection logs. | SAGATEC — Société d’informatique, domotique et sécurité (the publisher) | Data controller. We decide the purpose and the means: management of the account, the licence, billing and the security of the service. |
| Business operating data: records of the merchant's end customers, sales and receipts, credit and loyalty, point-of-sale employees, suppliers, catalogue, settings. | The subscribing merchant (the point-of-sale user) | Processor. We host and synchronise this data solely in order to perform the service requested by the merchant, in accordance with their instructions, without using it for our own purposes. |
Practical consequence. If you are a customer of a business that uses MaCaisse (loyalty card, credit account, delivered order) and you wish to access your data, correct it or have it deleted, your point of contact is the merchant themselves, not MaCaisse. We can act on that data only on the merchant's instruction, or to assist them in handling your request — see the Your rights section.
We never exploit our customers' business data (sales, end customers, catalogue) for advertising, resale, profiling or commercialised statistics. The application contains no advertising SDK and no behavioural analytics tool.
2. Data collected
The list below is as complete as possible and corresponds to what the software actually records and transmits; we update it with every change to the product. Depending on your configuration (local SQL Server mode without cloud, SQLite mode with synchronisation, Glovo enabled or not, etc.), some categories may not apply to you.
2.1 Data for which MaCaisse is the controller (account, licence, billing)
| Category | Data concerned | Source |
|---|---|---|
| Merchant account identity | Name, company name, e-mail address (unique identifier), password (stored hashed, never in clear text), e-mail verification date, "remember me" token, language, country, status (super-administrator, reseller, attachment to a reseller), creation and modification dates. | Entered on the tablet during activation, or created by our team / by a reseller. |
| Billing details and tax information | Billing address, ICE identifier, telephone number (mandatory at sign-up), country; and, per shop: billing mode, company name, address, ICE, country. | Tablet activation form and merchant area. |
| Shop identity | Name, address and telephone number of the business, number of authorised tablets, applicable rates. | Entered during activation. |
| Hardware and network identifiers of the tablets | Unique device identifier, name, platform (Android/iOS), model, application version, connection mode, operating mode, activation date, last connection date, revocation date; in a multi-tablet configuration: role (master/client), local IP address of the master tablet, port and pairing key. | Transmitted by the application at activation and then at each "heartbeat" (every 15 minutes). |
| Reserved local IP addresses | IP address (IPv4/IPv6) of the business's local network and port, where a master tablet is revoked, with date, author and note. | Revocation carried out from the tablet or the back office. |
| E-mail verification codes | E-mail address, hash of the code (the code is never stored in clear text), expiry date, date of use, number of attempts. The 6-digit code is, however, sent in clear text by e-mail, including in the subject line of the message. | Activation request from the tablet. |
| Single-use login links | Account and tablet concerned, hash of the token, expiry date and date of use, IP address of the requester and IP address that opened the link. | "Settle my subscription" button from the point of sale. |
| Web sessions | Session identifier, associated account, IP address, user agent (browser), technical content of the session, timestamp of last activity. | Browsing in the merchant, reseller or administrator area. |
| Tablet authentication tokens | Hash of the API token, name, permissions, date of last use, expiry date. The clear-text token is stored on the tablet, in the application settings. | Created at activation. |
| Subscription invoices and receipts | Number (FAC-/REC-), issue date, name, company, address, ICE, country and e-mail of the customer, invoice lines, amounts, VAT, currency, issuer's details, any cancellation and its reason. These documents are a frozen snapshot as at the issue date: the details they contain are not subsequently modified, and these records are retained even after the account is deleted (see section 11). | Confirmation of a subscription payment. |
| Subscription payments | Internal reference, amount, currency, method (cash, bank transfer, card, PayPal), status, description, period covered, payment date, author of the entry, provider references, raw response from the payment gateway recorded as is (it therefore contains the payer information that PayPal returns to us), any refunds and their reason. | Payment recorded by our team or by a reseller, or automatic response from PayPal. |
| Use of artificial intelligence features | Account and shop charged, feature used (menu import, image description or image matching, illustration generation), model called, number of tokens consumed, number of images, cost. No text and no image is retained in these records. | Each call to the AI features. |
| Authentication log | Lines of "event + IP address + e-mail address" recorded on activation or verification failures, in a file read by our brute-force attack protection tool. | Activation attempts from a tablet. |
| Application logs | Tablet connections (account, device, IP address), refused links, reset operations carried out by the administrator, payment events, and — where a menu import fails — a 400-character extract of the model's response, which may contain an extract of the merchant's menu. | Operation of the server. |
2.2 Data processed on behalf of the merchant (MaCaisse is a processor)
In SQLite mode with cloud synchronisation, the tablet pushes all of the business's operating data to macaisse.net. This data belongs to the merchant:
| Category | Data concerned |
|---|---|
| End customer records | Customer number, name, two telephone numbers, e-mail address, postal address, city, country, postcode, loyalty card or badge number, free-text remarks entered by the business, registration date, loyalty points, discount granted, reseller price applied, status of the record. |
| End customers' credit and top-up accounts | Account opening, movements (debit/credit), amounts, dates, linked receipt, payment type, cheque number and date, employee who made the entry, status, credit note number. |
| Sales and receipts | Checkout number, amount, date, status, table, identifier of the cashier and of the salesperson, payment type, settlement status, number of covers, order and document number, linked customer, document type (receipt, invoice, credit note), delivery date, preparation and printing status, originating tablet. |
| Sale lines | Item, quantity, price incl. tax, discount, VAT, salesperson, cashier, date, item type. |
| Receipt settlements | Payment type, amount, cheque number and date, payment date, credit note number, loyalty points used and their value, cashier and salesperson. |
| Point-of-sale employees | CIN (national identity card) number (used as identifier), surname, first name, point-of-sale password, role, status, overall commission rate and rate per item. Important: this password is currently stored and transmitted in clear text — see the Security section. The use of the CIN number also has legal consequences for the merchant — see the Merchant's obligations section. |
| Permissions per employee | Permission codes assigned to each employee and administrator status in the local back office. |
| Cancellations | Receipt, date, item, quantity, price, cashier and salesperson charged. |
| Purchases and goods receipts | Goods receipt notes (date, supplier, status, payment type, employee), lines (item, purchase price, quantity, VAT, amount incl. tax). |
| Suppliers | Company name, address, three telephone numbers, e-mail, country, city, postcode, national register, status, creating employee; as well as supplier payable accounts and their movements (amounts, cheques, dates). Any image attached to the record is not transmitted. |
| Point-of-sale settings | Company identity displayed on receipts (name, address, e-mail, website, telephone numbers, fax, Facebook page, RC, patente (business tax), ICE, IF, currency), receipt notices, printing configuration, the business's Wi-Fi key, permissions per role and authorised payment methods, display preferences, language and currency. This package also carries, in clear text, the MasterKey and the modification and cancellation passwords of the point of sale. The tablet's token, its unique identifier, the account e-mail, the Glovo key and the multi-tablet pairing parameters are, on the other hand, deliberately excluded from this transmission. |
| The business's printers | Name, role (point of sale/kitchen), IP address and port, paper width, cutting options, cash drawer and number of copies. |
| Catalogue and images | Items (code, name, information, prices, images, authoring employee), categories and their images, VAT rates, compositions. Photos may contain anything the merchant chooses to photograph: take care not to include people or identifying documents in them. |
| Photo of the menu (menu import) | The image sent is resized in memory and then transmitted to the AI provider. It is not saved on our servers; only the text proposed on screen results from it. |
| Glovo delivery orders (if enabled) | Order identifier and code, pickup code, status, total, fees, payment method, name and telephone number of the end customer receiving the delivery. A customer record is created automatically in the point of sale from this information, then synchronised to macaisse.net like any other customer record. |
| Local database on the tablet | The tablet keeps locally, in the application's private storage, the entire mirror of the point of sale: customer records, employees and point-of-sale passwords, sales, settlements, Glovo orders, API token, pairing keys. This database is not encrypted — see Security. |
2.3 Image bank
MaCaisse provides a collection of illustrations (label, keywords, images in three sizes) built and maintained by our team. This collection is shared by all merchants, is not attached to any account and contains no personal data of any merchant or end customer.
3. Purposes and legal bases
The processing operations described above fall under Moroccan law 09-08 (loi 09-08, the Moroccan personal data protection act) relating to the protection of individuals with regard to the processing of personal data. The legal bases relied upon are the following:
| Purpose | Data concerned | Legal basis |
|---|---|---|
| Creating and managing the merchant account, activating and revoking tablets, enforcing the licence quota | Account identity, shops, tablets, tokens, verification codes | Performance of the subscription contract |
| Billing the subscription, collecting payments, processing refunds | Billing and tax details, payments, invoices and receipts | Performance of the contract, and legal obligation for accounting and tax retention |
| Providing the point-of-sale and synchronisation service: saving the configuration, restoring a tablet, consulting sales and reports from the web | All of the business's operating data (section 2.2) | Performance of the contract, on the merchant's instruction, the merchant being the controller for this data |
| Ensuring the security of the service: detecting fraudulent access attempts, blocking brute-force attacks, arbitrating the master tablet role | Authentication log (IP + e-mail), sessions, login links, reserved local IPs | Legitimate interest of the publisher in protecting the service and its users |
| Diagnosing incidents and providing support | Application logs | Legitimate interest |
| Building a catalogue from a photo of the menu, illustrating items | Photo of the menu (transient), product names, AI usage metadata | Performance of the contract, at the explicit request of the merchant who triggers the feature |
| Receiving and preparing delivery orders | Glovo orders, name and telephone number of the customer receiving the delivery | Performance of the contract between the merchant and their delivery platform; MaCaisse acts as a processor |
| Sending the only two e-mails the product sends: verification code and acceptance of the trial period | E-mail address, first name/surname, trial dates | Performance of the contract |
We send no commercial or promotional e-mail from the product, and the software contains no automated prospecting mechanism.
4. Recipients and processors
4.1 Within MaCaisse
Access to data is limited to the people who need it: the technical team of SAGATEC — Société d’informatique, domotique et sécurité (support, server operations) and, where applicable, the partner reseller to which your account is attached. A reseller sees the accounts and shops they have themselves created, as well as their billing.
4.2 Processors and third-party services actually called by the software
| Provider | Role | What is transmitted to them | Location |
|---|---|---|---|
| Alibaba Cloud — Model Studio / DashScope | Artificial intelligence model: reading a photographed menu, describing the photos in the image bank, matching product names with illustrations, generating images. | The photo of the menu or of the product (converted into a compressed image) together with a text instruction; or a list of product names without any image; or a description text to generate an illustration. No end customer data, no sale, no e-mail and no account identifier is transmitted. The access key remains on our server; the tablet never calls the provider directly. | International access point, Singapore by default |
| PayPal | Online collection of the MaCaisse subscription and refunds. The subscription is taken out on the website, never in the mobile application. | Outgoing: amount converted into euros at a rate set by the publisher, currency, internal payment reference, description, brand name "MaCaisse", return addresses. No name, e-mail or address of the merchant, and no sales or end customer data, is transmitted. Incoming: PayPal's response (order, capture, notification) is recorded as is in our database; the payer information that PayPal returns to us is therefore retained there. Your bank card details are entered at PayPal and never pass through our servers. | United States / European Union |
| "my-cash-system" middleware (licence.my-cashsystem.com) and Glovo upstream | Gateway between the point of sale and the delivery platform: receiving orders, acknowledgements of receipt, "order ready" signal, publishing the menu. Only if the merchant enables this feature. | Outgoing: the business's menu (item names, prices, images), authenticated by a key specific to the shop. Incoming: the orders, including the name and telephone number of the end customer receiving the delivery. | Depending on the provider concerned; Glovo operates from Spain / the European Union |
| Google Fonts (fonts.googleapis.com, fonts.gstatic.com) | Loading the fonts of the public site and of the back office. | No application data is sent by our code, but the visitor's browser contacts Google directly, which as a result receives their IP address, their user agent and the page consulted. The fonts are not hosted on our server. | United States / global infrastructure |
| Tailwind CDN (cdn.tailwindcss.com) | Loading the back office's style sheet. | No application data is sent by our code; the merchant's or administrator's browser contacts the CDN, which receives their IP address and their user agent. | Global infrastructure |
| Namecheap, Inc. (serveur SMTP server191.web-hosting.com) (e-mail delivery) | Delivery of the only two messages the product sends. | The merchant's e-mail address, and the content of the message: the six-digit verification code, in clear text (also present in the subject line), or the name and the dates of the trial period. | United States |
| Host of the macaisse.net server | Hosting of the application server and of the database. | All of the data described in sections 2.1 and 2.2, by the very nature of the hosting service. | Germany (European Union) — Contabo GmbH |
Finally, we may be required to disclose data to a Moroccan judicial or administrative authority where the law obliges us to do so.
5. Transfers outside Morocco
Certain operations involve a transfer of data outside Moroccan territory:
- the call to the Alibaba Cloud artificial intelligence model (international access point, Singapore by default) during a menu import or an image processing operation;
- the processing of the subscription payment by PayPal (United States / European Union);
- the exchange with the delivery middleware and Glovo, if this feature is enabled;
- the delivery of e-mails by Namecheap, Inc. (serveur SMTP server191.web-hosting.com) (United States);
- the loading of the fonts and of the style sheet from Google and the Tailwind CDN, which receive the visitor's IP address;
- the hosting of the server, located in Germany (European Union).
In accordance with law 09-08, any transfer of personal data to a foreign State is subject to the approval of the CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel, the Moroccan data protection authority). The corresponding formalities are the responsibility of SAGATEC — Société d’informatique, domotique et sécurité for the merchant account data; CNDP file reference: [[N_RECEPISSE_CNDP]].
Please note: for the data of their own customers, it is the merchant, as controller, who must complete their formalities with the CNDP — see the Merchant's obligations section.
6. Retention periods
We must be clear on this point: to date, the software applies no automatic purge of operating data. We prefer to write this rather than announce periods that would not be complied with in practice.
6.1 What is actually deleted automatically
- E-mail verification codes: deleted after 24 hours, by a daily task.
- Single-use login links: deleted 24 hours after their expiry, on the occasion of a new link request.
- Web sessions: expired after 120 minutes of inactivity, then erased by random garbage collection.
- Menu import quota counters: lifetime of one day.
6.2 What is retained without any time limit
All other data is, in the current state of the product, retained without any deadline for as long as the account exists: end customer records, credit and loyalty accounts, sales, sale lines, settlements, cancellations, purchases and goods receipts, suppliers and supplier payables, point-of-sale employees and their permissions, catalogue, VAT, settings, printers, tablets, reserved local IPs, invoices, subscription payments (including PayPal's raw response), AI usage metadata, image bank, user accounts.
6.3 Deletions made at the point of sale are not erasures
When a record is deleted from the tablet, synchronisation applies a logical deletion: the row remains present in the server's database, marked as deleted, and can be restored if the item is republished. A customer record "deleted" at the point of sale therefore remains in our database for as long as deletion of the account, or a reset, has not been requested.
6.4 Actual erasures
- Account deletion: triggered by you from the application, it immediately destroys the shops and all their synchronised content, the tablets and their tokens, and the subscriptions; the account row survives, emptied of all personal data, for the sole purpose of carrying the subscription invoices that accounting regulations oblige us to retain. The details are set out in the Account and data deletion section.
- Reset of a shop (sales, stock, customers, suppliers or tablets), without deleting the account: physical deletion of the rows concerned, at the merchant's request, carried out by our team after verifying the origin of the request. Technical caveat: rows resulting from old synchronisations that are not attached to a shop are not deleted by this operation; they are only counted and reported. We then handle them manually on request.
6.5 Logs
The authentication log (IP address + e-mail address pairs, used against brute-force attacks) and the application logs are written to a single file on the server, without automatic rotation. They are purged periodically during maintenance operations; as things stand, we cannot announce a specific retention period that would be complied with by the product itself.
6.6 On the tablet
The application does not purge anything either: the local database retains the entire history (sales, customer records, delivery orders) for as long as the application is not uninstalled or its data erased from the system settings.
6.7 Our commitment
We undertake to put in place explicit retention periods and an automated purge, and to update this page when that is the case. In the meantime, any merchant may at any time request the deletion of their data — see Account and data deletion. Invoices and accounting records are, for their part, retained for the period required by Moroccan accounting and tax regulations.
7. Security
7.1 Measures actually in place
- Encryption of communications: all exchanges between the tablet, the browser and macaisse.net take place over HTTPS.
- Web account passwords hashed: the password used to log in to the merchant area is stored as a hash (bcrypt) and can never be viewed, either by us or by a reseller.
- Tablet authentication by token: each tablet has a revocable API token; only the hash of the token is stored on the server.
- E-mail address verification by single-use code, with expiry, a limit on the number of attempts and storage of the hash of the code only.
- Partitioning by shop: synchronisation is bounded by the shop associated with the tablet; a tablet does not access the data of another shop or of another merchant.
- Protection against brute-force attacks: activation and verification failures are logged and used by a tool that automatically blocks IP addresses.
- Single-use login links: hashed token, limited lifetime, single use, IP addresses of creation and of use recorded.
- No advertising tracker and no behavioural analytics tool in the application.
7.2 Limitations we prefer to point out to you
No system is perfectly secure, and we refuse to write phrases such as "end-to-end encryption" or "absolute security" that would not correspond to the reality of the product. You should be aware of the following points:
- Point-of-sale employees' passwords are not hashed. They are stored in clear text in the tablet's local database and transmitted in clear text to the server during synchronisation (the connection itself remains encrypted over HTTPS). A point-of-sale password is set at installation: it is your responsibility to change it as soon as the system goes live and never to reuse in it a password used elsewhere (e-mail, bank, merchant area).
- The modification and cancellation passwords of the point of sale, as well as the MasterKey and the business's Wi-Fi key, are carried in clear text in the settings package synchronised to the server. The same precautions apply.
- The tablet's local database is not encrypted. It resides in the application's private storage, protected by the operating system, but a tablet that is lost, stolen, unlocked (root/jailbreak) or from which a backup is extracted may expose customer records, sales histories, point-of-sale passwords and the API token. Lock your tablets with a passcode, enable device encryption and immediately revoke a lost tablet from the merchant area.
- On Android, the application allows unencrypted HTTP traffic (necessary for the link between tablets and for network printing). This authorisation is not restricted to the local network, unlike the iOS version which limits it to the local network. Communication with macaisse.net, for its part, always remains over HTTPS.
- PayPal's raw response is stored without filtering, which includes the payer information that PayPal transmits to us.
- The authentication log retains IP address + e-mail address pairs without automatic rotation; it is purged during maintenance operations.
- Synchronisation is not a backup service. To date we offer neither continuous backup of your data nor any restoration commitment: keep your own copies of the information you need.
In the event of a data breach likely to adversely affect your rights, we will inform you and will carry out the required notifications to the CNDP.
8. Cookies and trackers
The site uses only cookies that are strictly necessary for its operation. There are only three:
| Cookie | Role | Duration |
|---|---|---|
| Session cookie | Keeping you logged in to the merchant, reseller or administrator area. | 120 minutes of inactivity |
| "Remember me" cookie | Recognising you on your next visit, set only if you tick the corresponding box when you log in. | Until you log out or the token expires |
| Anti-CSRF token | Protecting forms against fraudulent submissions from another site. | Duration of the session |
No advertising cookie, no third-party audience measurement, no tracking pixel is set by the site or by the application.
External resources: the pages of the public site and of the back office load fonts from Google Fonts and a style sheet from the Tailwind CDN. These requests, made by your browser, communicate your IP address and your user agent to those providers, even though no data from your account is transmitted to them.
9. Mobile application permissions
The application requests only what is strictly necessary for it to work:
| Permission | Why |
|---|---|
| Internet access (Android) | Activation, synchronisation with macaisse.net, connection to the SQL server on the local network, network printing, delivery gateway. |
| Network state (Android) | Detecting whether the tablet is online or offline. |
| Wi-Fi state (Android) | Reading the tablet's local IP address, published to the cloud when it acts as master in a multi-tablet setup. Neither the network name nor its hardware identifier is read, and no location permission is requested. |
| Camera (Android and iOS) | Barcode scanner, photo of an item or of a category, photo of the menu for the import. The camera is not required in order to install the application. |
| Photo library (iOS) | Choosing an existing image for an item, a category or the menu import. |
| Local network (iOS) | Communicating with the master tablet and printing on Wi-Fi printers. |
The application requests no access to location, contacts, the microphone, SMS, the telephone, Bluetooth or external storage, and integrates no advertising or analytics kit.
10. Your rights
In accordance with law 09-08, you have a right of access, a right of rectification and a right to object on legitimate grounds to the processing of your data, as well as the right to obtain the erasure of data whose processing does not comply with the law. Deletion of the account and of the data is described in the next section.
10.1 If you are a merchant, a reseller or a visitor to the site
Send your request to info@sagatec.ma, from the e-mail address associated with your account, specifying the subject of the request. We may ask you for proof of identity if reasonable doubt remains as to the origin of the request. We reply as soon as possible, and at the latest within 30 days of receiving the request.
10.2 If you are an employee of a business using MaCaisse
Your data (CIN, surname, first name, point-of-sale password, commissions, cancellations and sales charged to you) is under the responsibility of your employer. Contact them first: they can modify or delete your record from the point of sale or the merchant area. If you obtain no response, you can write to us and we will pass the request on, or you can refer the matter directly to the CNDP.
10.3 If you are a customer of a business using MaCaisse
The business from which you purchased, took out a loyalty card, opened a credit account or placed a delivered order is the controller of your data. Send your request to them directly: they alone know the context of your record and can modify or delete it. We are not entitled to modify or delete this data on our own initiative.
If you are unable to identify the business or if it does not respond, write to us at info@sagatec.ma: we will relay your request to the merchant concerned, and we will carry out the erasure as soon as they instruct us to do so. In any event you retain the possibility of referring the matter to the CNDP.
11. Account and data deletion
The detailed procedure is described on a dedicated page: Delete my account and my data. Here is the essence of it.
11.1 How to request deletion
- From the application (normal route): side menu → Cloud account → at the bottom of the screen, red "Delete my account" button. A dialog box displays the warning and asks you for the password of your MaCaisse account (the one for the macaisse.net site, not the point-of-sale code); confirmation is given by "Delete permanently". Deletion is then immediate: there is no cooling-off period and no confirmation e-mail to validate.
- By e-mail, if you no longer have the tablet: write to info@sagatec.ma from the e-mail address of your account. We process the request within a maximum of 30 days.
- The online merchant area does not, to date, include a deletion button: use the application or e-mail.
11.2 What deletion erases, and what it retains
Deletion is a purge accompanied by anonymisation. We prefer to say so precisely rather than write "everything is erased":
- Actually erased: your shops and the entirety of their synchronised content — sales, sale lines, payments received, items, categories, records of your end customers, salespeople and employees, permissions, VAT, settings — as well as your tablets and their access tokens, and your subscriptions.
- Retained but emptied: the row for your account survives, stripped of all personal data. Name, company, billing details, ICE and telephone number are reset to empty, and the password is replaced by a random value. It now serves only to link the accounting records.
- E-mail address released: your real address is replaced by a technical address at
@macaisse.invalid. You can therefore sign up again later with the same e-mail address. - Subscription invoices and receipts retained: accounting regulations oblige us to keep them. These documents are a snapshot frozen at their issue date and therefore contain the billing details as they were at that time — including the e-mail address as it then was. After deletion, these records are the only data concerning you that remains with us.
11.3 Erasing only part of your data
You may also request, by e-mail to info@sagatec.ma, a partial reset of a shop (sales, stock, customers, suppliers or tablets) without deleting your account. This operation is carried out by our team, with the technical caveat described in paragraph 6.4.
11.4 On the tablet
Uninstalling the application erases the data present on the device, but not the data already synchronised to macaisse.net: deletion of the account remains necessary for the latter.
12. The merchant's obligations towards their own customers
By using MaCaisse to record customer files, loyalty cards, credit accounts, delivered orders or employee records, you become a controller within the meaning of law 09-08. It is your responsibility in particular:
- to complete the formalities required with the CNDP for your files. Caution: the file of point-of-sale employees contains the CIN number, which the software uses as an identifier. As such, this processing is subject to the prior authorisation of the CNDP (article 12 of law 09-08) and not to a simple declaration. The file of your customers, for its part, is subject to declaration;
- to inform your customers — by a notice displayed in the shop, a statement on the loyalty enrolment form or on the receipt — of the collection of their data, its purpose, its recipient and their rights, and to obtain their consent where it is required;
- to inform your employees of the recording of their CIN, their sales, their cancellations and their commissions;
- to enter only relevant and necessary data, and in particular not to use the free-text remarks field to record sensitive information (health, opinions, origin, judicial record);
- to handle the requests for access, rectification, objection and deletion coming from your customers and your employees;
- to protect your tablets (lock code, device encryption, named point-of-sale accounts, distinct passwords changed as soon as the system is installed) and to report to us without delay the loss or theft of a device so that we can revoke it.
As a processor, MaCaisse undertakes to process this data only in order to provide the service, not to use it for other purposes, to partition it by shop, and to act upon your instructions for rectification or erasure.
13. Changes to this policy
This policy may change along with the product — in particular when we put in place automatic retention periods and the hashing of point-of-sale passwords. The version in force is the one published on macaisse.net, with the date of last update shown at the top of this page. We invite you to consult it from time to time; in the event of a significant change, we will inform subscribing merchants by e-mail at the address associated with their account.
14. Contact and complaints to the CNDP
For any question relating to this policy or to exercise your rights:
SAGATEC — Société d’informatique, domotique et sécurité — limited liability company (SARL) under Moroccan lawLot Kortoba, Secteur 1, Meknès, Morocco
E-mail: info@sagatec.ma
Telephone: +212 5 35 46 32 58 (landline) — +212 6 45 56 02 90 (management)
ICE: [[ICE]] — RC: [[RC]] — IF: [[IF]]
If, after contacting us, you consider that your rights are not being respected, you may refer the matter to the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP), the competent Moroccan authority, in Rabat — www.cndp.ma.
Users located in the European Union
MaCaisse is a Moroccan product, designed for the Moroccan market, and its frame of reference is law 09-08. We claim no GDPR compliance certification. If you are established in the European Union, we nevertheless undertake, on a voluntary basis, to apply the same principles of transparency, minimisation and respect for rights as those described above, and to examine your requests for access, rectification, erasure, restriction and portability within the same time limits.