Privacy Policy
Last updated: 8 August 2026
1. Who are we?
Nobtek (nobtek.ma) is an online appointment marketplace for service businesses in Morocco — hairdressers, barbers, hammams, spas and, over time, other sectors — operated from Belgium. For platform data (business accounts and bookings made through nobtek.ma), Nobtek is the data controller. For the client records each business keeps in its management area, Nobtek acts as a processor on behalf of that business (the controller). For any question about your data, you can contact us at privacy@nobtek.ma.
2. What data do we collect?
We process the following personal data:
- Business account data: name, email address, company name, phone number
- Booking data and client records: first name, last name, phone number, email address (optional), and, where applicable, date of birth and notes added by the business
- Appointment data: date, time, service, listed price, status, notes
- Intake forms: answers to questions asked by the business (preferences and information relevant to the service)
- Technical data: IP address, browser type (for functional and security purposes only)
3. Why do we process this data?
- Managing and scheduling appointments
- Sending confirmations and reminders by email
- Keeping client history available to the business
- Improving our services
4. Legal basis
We process personal data on the basis of:
- Performance of a contract (art. 6.1.b GDPR): necessary for making and managing appointments
- Legitimate interest (art. 6.1.f GDPR): sending reminders and improving our service
- Consent (art. 6.1.a GDPR): for marketing communications (you can withdraw this consent at any time)
5. Retention period
We keep personal data for as long as your account is active, plus a period of 2 years after the account is closed. After that, your data is permanently deleted unless a legal obligation requires longer retention.
Data obtained via Google OAuth (see section 12) is an exception to the retention period above: it is immediately and permanently deleted as soon as you revoke the Google connection, without the 2-year retention period.
If you delete your account yourself (via Settings in your dashboard), a shorter period applies: your account is deactivated immediately and your data is permanently erased 30 days later. During those 30 days we keep your data solely so the deletion can be undone if you change your mind (restriction of processing, art. 18 GDPR); it is used for nothing else, your listing is no longer visible and no more reminders go out to your clients. Appointments falling within that period are cancelled and your clients told. You receive a confirmation email with a restore link valid until that date, and a second confirmation once the deletion has been carried out.
6. Sharing with third parties
We only share personal data with the following parties:
- Email delivery — emails (confirmations, reminders, review invitations) are sent from our own mail server located in the EU (Hetzner, Germany); there is no external email processor
- Google (Google LLC) — only for the optional "Sign in with Google" and Google Calendar sync features, available to businesses. See section 12 for details
- Cloudflare (Cloudflare, Inc.) — our site is served and protected through Cloudflare's infrastructure, which processes visitor IP addresses for that purpose
We have concluded data processing agreements with each of these parties. We never sell your data to third parties. No payments are processed by the platform: Nobtek collects no banking data.
7. Your rights
Under the GDPR, you have the following rights:
- Right of access (art. 15): you can ask which data we process about you
- Right to rectification (art. 16): you can have inaccurate data corrected
- Right to erasure (art. 17): you can request deletion of your data
- Right to portability (art. 20): you can receive your data in a structured format
- Right to object (art. 21): you can object to the processing of your data
- Right to restriction (art. 18): you can request that processing be restricted
To exercise your rights, contact us at privacy@nobtek.ma. We respond to your request within 30 days.
8. Cookies and analytics
Nobtek uses only functional cookies necessary for the website to work (for example session cookies and cookie-consent preferences). We use no tracking or analytics cookies. Audience measurement relies on a self-hosted, cookieless tool (Umami) that produces only aggregated, anonymous statistics — never personal data, never the content of your searches.
9. Data location
All of our servers, databases and mail server are located in the European Union (EU). Some processors (Google, Cloudflare) may process data outside the EU, but do so on the basis of adequacy decisions or standard contractual clauses (SCCs).
10. Security
We take appropriate technical and organisational measures to protect your data, including encryption of data in transit (TLS) and at rest, access controls and regular security audits.
11. Filing a complaint
If you have a complaint about the processing of your personal data, you can contact the Belgian Data Protection Authority (DPA):
Autorité de protection des données (APD)Rue de la Presse 35
1000 Brussels
Tel.: +32 2 274 48 00
Email: contact@apd-gba.be
Website: www.autoriteprotectiondonnees.be
Users located in Morocco can also contact the CNDP (the Moroccan national commission for the protection of personal data).
12. Google OAuth and Google Calendar
Nobtek offers businesses two optional features based on Google OAuth. Both require your explicit consent through Google's official consent screen. You can revoke the connection at any time in Settings → Google Calendar.
Sign in with Google — When you choose to sign in with Google, we only receive your name, email address and Google account identifier (scopes: openid, email, profile). This data is used solely to create your Nobtek account and authenticate you. We do not share this data with third parties and do not use it for profiling, advertising, or training machine-learning models.
Google Calendar sync — If you connect Google Calendar (scope: https://www.googleapis.com/auth/calendar.events), Nobtek reads and writes appointments only in your primary calendar ("primary") to detect conflicts and sync your Nobtek appointments. We do not read other users' calendars, we do not modify events we did not create ourselves, and we never use calendar data for advertising, analytics or AI-model training. This use fully complies with the Google API Services User Data Policy, including the Limited Use requirements.
Storage and security — Access and refresh tokens are stored encrypted (AES-256) in our database located in the EU. Only server-side processes tied to your account can decrypt them.
Revoking the connection — When you revoke the Google connection, (1) the watch channel with Google is stopped, (2) the refresh token is explicitly revoked with Google via oauth2.googleapis.com/revoke, and (3) all locally stored tokens and sync state are immediately deleted. You can also revoke access yourself at any time via myaccount.google.com/permissions.
13. Changes
We may update this privacy policy from time to time. Changes are published on this page. We recommend reviewing this policy regularly.