Who we are
STE BLUEPILL CONSULTING SARL AU is the data controller for personal data processed in connection with Ledenote accounts (newsroom operators, billing identifiers) and the processor for end-reader query data handled on behalf of newsroom customers.
Our active regulatory authority is the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP), under Morocco's Loi 09-08. For any privacy-related question or to exercise your rights, contact [email protected].
What data we collect
What we collect depends on how you interact with Ledenote:
- Landing site visitors: server logs (IP address, user-agent) used for security and abuse prevention; and first-party audience measurement — page address, referring site, browser, operating system, device type, screen-size bucket, country, and a daily-rotating pseudonymous visit identifier derived from your IP address and user-agent. See Cookies & analytics.
- Contact form leads: name, professional email, role, organisation, and the message you submit, plus the optional
?context=prefill from a referring page. - Dashboard users (newsroom operators): account email, bcrypt password hash, JWT tokens, billing identifiers, and connection logs.
- End-readers via newsroom widgets: we act as processor on behalf of each newsroom customer. We handle search queries, an anonymous session identifier, and derived analytics. Controllership of this data belongs to the newsroom; reader-side requests are routed through the newsroom first.
Why we process
Our legal bases under Loi 09-08 are: contract performance for service delivery to newsroom customers; legitimate interest for security, abuse prevention, and first-party audience measurement of our own website; and consent for any future optional cookies.
Sub-processors at a glance
Ledenote relies on a small set of sub-processors. The full list, including regions, processing purposes, and contractual safeguards, is provided in our Data Processing Agreement on request.
- Hetzner Online GmbH (Germany) — hosting infrastructure.
- Cloudflare Inc. (United States) — DDoS protection, CDN, Turnstile bot challenge, and network transit for website analytics requests.
- Resend (United States) — transactional email.
- Inference vendors (United States) — query understanding and answer generation; specific vendor identities are disclosed in the DPA.
Payments & Merchant of Record
Online subscriptions are sold by Paddle.com Market Limited and its affiliates (“Paddle”) as authorised reseller and Merchant of Record. For the buyer's payment and billing data, Paddle acts as an independent controller in its own right — not our processor or sub-processor: the buyer contracts with Paddle, and Paddle determines the purposes of payment processing, tax calculation and remittance, fraud screening, and KYC and regulatory compliance. This processing is governed by Paddle's own privacy notice.
Paddle shares a limited set of billing identifiers with us — purchaser name, email, phone number, company VAT number, and billing metadata — at which point we become the controller of that data for account administration and accounting. Paddle, as an independent controller, transfers data across its UK, EU, and US entities under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum; those safeguards are Paddle's, not part of our Data Processing Agreement.
Retention
We retain personal data only for as long as needed for the purpose for which it was collected, then delete or anonymise it. Indicative windows:
- Query logs: 90 days for analytics and abuse detection, then aggregated anonymously.
- Account data: duration of the contract plus 5 years for commercial archiving.
- Billing records (direct-invoice customers): 10 years for Moroccan tax compliance. For online subscriptions sold through Paddle as Merchant of Record, Paddle retains the underlying payment and transaction record under its own policy and tax obligations; we keep only the related settlement and reconciliation record.
- Contact-form leads: 2 years after last contact, or sooner on request.
Cross-border data flows
Service and end-user query data are stored on Hetzner infrastructure in Germany. Separately, billing and payment data for online subscriptions is processed by Paddle, our Merchant of Record, across its entities in the United Kingdom, the EU, and the United States, under Paddle's own Standard Contractual Clauses and UK International Data Transfer Addendum.
Under Loi 09-08, transferring personal data outside Morocco requires destination-country adequacy or prior CNDP authorization. Our CNDP declaration covering this processing — including the Paddle transfer — is being prepared and submitted; see the Compliance page for the regulatory overview.
Your rights
You have the following rights under Loi 09-08:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Opposition — object to processing on legitimate grounds.
- Removal — request deletion where the processing basis no longer applies.
To exercise any of these rights, email [email protected]. You also have the right to lodge a complaint with the CNDP if you believe your rights are not being respected.
Cookies & analytics
Ledenote sets strictly-necessary cookies only — an authentication session cookie on the dashboard and a single Cloudflare Turnstile challenge token on the contact form. We set no analytics cookie and use no advertising pixels.
We measure audience on this website with Plausible, an open-source analytics application that we run ourselves on the same Hetzner infrastructure in Germany that hosts the rest of the Service. No analytics data is sent to an external analytics provider, and no analytics vendor is involved: the only sub-processors that touch this data are the hosting and network providers already listed above. It sets no cookie and builds no cross-site or persistent profile. Each page view records the page address, the referring site, any campaign tags in the link you arrived from, and coarse technical details — browser, operating system, device type, screen-size bucket, and country. To recognise repeat visits across a short window, your IP address and user-agent are combined with this site's domain and a secret key that we rotate daily. The previous day's key is retained briefly so that a visit spanning midnight is not counted twice, and is then destroyed; the resulting value therefore stops being linkable to you within about 48 hours. Only that short numeric value is stored. Your IP address is used in transit for that calculation, for country lookup against a local database, and for abuse filtering — it is not stored in our analytics database. Our analytics script also reads a single opt-out flag from your browser's local storage, if you have set one.
Because this measurement produces site statistics only — no advertising, no profiling, and no recipient beyond the hosting and network providers listed above — Moroccan practice under Loi 09-08 does not require your prior consent for it, and we therefore do not display a consent banner. Any future optional or advertising technology would be introduced only with your prior consent.
Changes to this policy
We notify account holders by email when we make material changes to this policy. Non-material changes are reflected by updating the effective date at the top of this page.
Contact
Privacy questions, data-subject requests, and any other matter related to this policy: [email protected]. Postal mail may be sent to our registered office in Larache.