Effective date & scope
This statement applies to all personal data processed by Ledenote in the course of providing the Service. It is effective as of the date shown at the top of this page.
Active regulatory regime: Loi 09-08 (Morocco)
STE BLUEPILL CONSULTING SARL AU operates under Morocco's Loi 09-08 (loi n° 09-08 du 18 février 2009) on the protection of natural persons with regard to the processing of personal data. The supervisory authority is the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP). Ledenote's processing activities are being declared to CNDP as required by Loi 09-08.
Data residency
Service and end-user query data are stored on Hetzner infrastructure in Germany; backups are kept in the same EU region. Operational control sits with Bluepill Consulting from Morocco. Separately, billing and payment data for online subscriptions is processed by Paddle, our Merchant of Record, in the United Kingdom, the EU, and the United States, under Paddle's own Standard Contractual Clauses and UK International Data Transfer Addendum. Under Loi 09-08, our CNDP declaration covering this processing — including the Paddle transfer — is being prepared and submitted.
Roles
Bluepill Consulting is processor for end-reader query data — newsroom customers are the controllers of their readers' data — and controller for Ledenote account data (operator users, billing records).
Subject rights & request flow
Subject rights under Loi 09-08 include access, rectification, opposition, and removal. To exercise these rights, contact [email protected]. End-readers of newsroom widgets should route their requests through the newsroom they are querying first, as the newsroom is the controller of that data.
Sub-processors
A high-level list of our sub-processors is given in our Privacy Policy; the full list with regions, processing purposes, and contractual safeguards is available in our Data Processing Agreement on request.
Breach notification
Ledenote commits to notify affected controller customers without undue delay following discovery of a personal data breach, with the information necessary to enable the controller to fulfill its own notification obligations to CNDP and to data subjects.
Data Processing Agreement
Our DPA is available on request at [email protected]. Today's DPA addresses Loi 09-08 obligations; an SCC-annex variant is prepared for activation when EU customers are onboarded.
Looking ahead
Ledenote's V1 customer base is Moroccan newsrooms. When European customers are onboarded in the future — planned via a separate EU entity sitting under a holding structure that will also own Bluepill Consulting — additional GDPR-specific commitments will be in place at first EU customer onboarding: designation of an Article 27 EU representative, an SCC-annex DPA for cross-border transfers, formal breach notification within 72 hours per GDPR Article 33, and a public list of sub-processors with advance notice of changes.
Contact
Compliance, privacy, and data-processing questions: [email protected]. Postal mail may be sent to our registered office in Larache.