Privacy Policy | AI Gestion

Version: 3.1.0, last updated: August 4, 2026.


The terms "Agency", "User", "Client", "Expert", "Case" and "Operator" have the meaning given to them in Article 2 of the Terms of Service.

Article 1: Purpose

This policy describes the conditions under which personal data is collected, used, retained, disclosed, and protected through the Platform.

It applies to Users, Clients, Experts, and any other person whose information is entered or processed within a Case.

Article 2: Data Controller

For data relating to the creation and management of accounts, security, billing, and the technical operation of the Platform, processing is carried out by the Operator of the AI Gestion Platform.

For data contained in claim Cases, the relevant Agency determines the professional purposes of the processing and remains responsible for the lawfulness of collecting and using that data.

The Operator then acts as a technical service provider on behalf of the Agency, within the limits of the lawful instructions given to it.

Article 3: Categories of Data Processed

The Platform may process identity and contact data, including first name, last name, email address, and phone number.

The Platform may process information relating to Users' accounts, roles, authorizations, and activities on the Platform.

The Platform may process information relating to contracts, vehicles, claims, repairs, estimates, amounts, case references, and the various stages of processing.

The Platform may process documents such as quotes, invoices, reports, photographs, supporting documents, and correspondence.

The Platform may process communications exchanged between Agencies, Clients, Experts, and other relevant parties.

The Platform may process technical data, connection information, security logs, and data enabling the detection of anomalies or unauthorized access.

The Platform may process data necessary for managing the subscription, billing, and payments.

Only information necessary for the operation of the Platform and the processing of Cases should be collected.

Article 4: Purposes of Processing

Data may be processed to create and manage accounts, authenticate Users, and control their authorizations.

Data may be processed to create, organize, track, and close claim Cases.

Data may be processed to receive, store, file, and transmit documents necessary for processing Cases.

Data may be processed to enable communications between Agencies, Clients, Experts, and other authorized parties.

Data may be processed to send follow-ups, notifications, and information relating to the progress of a Case.

Data may be processed to provide automated assistance, filing, summarization, or analysis features.

Data may be processed to prevent fraud, detect misuse, and protect the security of the Platform.

Data may be processed to manage subscriptions, quotes, billing, and payments.

Data may be processed to comply with a legal obligation, respond to a competent authority, or establish, exercise, or defend a legal right.

Article 5: Legal Basis for Processing

Depending on the situation, processing may be necessary for the performance of a requested service, the performance of a contractual relationship, the processing of a claim Case, compliance with a legal obligation, or the protection of the legitimate interests of the Agency or the Operator.

Where applicable law requires it, processing may also be based on the consent of the data subject.

The Agency is responsible for determining the legal basis applicable to the data it enters into the Platform.

Article 6: Recipients of Data

Data may be accessible to the Agency responsible for the Case and to the Users it has authorized.

Data may be disclosed to the relevant Clients where such disclosure is necessary for processing their Case.

Data may be disclosed to Experts designated by the Agency, limited to the information necessary for carrying out their assignment.

Data may be accessible to authorized persons acting on behalf of the Operator where such access is necessary for operation, maintenance, security, or technical support.

Data may be processed by technical providers necessary for hosting, communication, storage, payment, security, or the operation of the Platform's features.

Data may be disclosed to administrative, judicial, or regulatory authorities where required by a legal provision, a formal request, or an enforceable decision.

Data is not sold to third parties and is not used for advertising purposes unrelated to the operation of the Platform.

Article 7: Hosting and Processing Abroad

The Platform's core data is hosted in Nuremberg, Germany.

Hosting or processing data outside Moroccan territory may constitute a data transfer abroad.

The operations concerned must be carried out in compliance with the formalities, conditions, and safeguards required by applicable Moroccan regulations.

Article 8: Retention Period

Data is retained only for the period necessary for the purposes for which it was collected or processed.

Data may be retained longer where such retention is necessary to comply with a legal, accounting, tax, contractual, evidentiary, or litigation-related obligation.

Data may also be retained where necessary for the security of the Platform, fraud prevention, incident management, proof of a transaction, or the defense of a legal right.

Where data is no longer necessary, it is deleted, anonymized, or permanently rendered inaccessible, subject to applicable technical and legal constraints.

Article 9: Accuracy of Data

The Agency and Users must ensure that data entered into the Platform is accurate, complete, relevant, and up to date.

Any person who notices incorrect information may request its rectification under the conditions provided by applicable regulations.

Article 10: Security and Confidentiality of Data

The Operator implements reasonable technical and organizational measures designed to preserve the confidentiality, integrity, availability, and traceability of data.

Access to data is limited to authorized persons based on their roles and needs.

Technical details of security measures are not published so as not to reduce their effectiveness.

The Agency and Users must also adopt reasonable security measures, in particular by protecting their credentials and limiting access to authorized persons.

Article 11: Rights of Data Subjects

Any data subject may exercise the rights recognized under applicable Moroccan legislation on the protection of personal data.

Depending on applicable legal conditions, these rights may include a right of access, a right of rectification, and a right of objection.

Any request may be sent to: aigestionmaroc@gmail.com.

The request must contain the information necessary to identify the person, the Case, and the data concerned.

Where the request concerns a Case managed by an Agency, it may be forwarded to that Agency to be handled in its capacity as controller for the Case.

Article 12: Requests from Authorities

Data may be disclosed to an administrative, judicial, or regulatory authority where required by a legal provision, a formal request, or an enforceable decision.

The Operator may retain the information necessary to evidence such disclosure.

Article 13: Security Incident

When an incident likely to affect data is identified, the Operator takes reasonably necessary measures to identify the incident, limit its consequences, secure the systems concerned, and prevent its recurrence.

Agencies and Users must promptly report any incident, suspicious access, accidental disclosure, or data loss to: aigestionmaroc@gmail.com.

Article 13 bis: Use of Google Data

AI Gestion uses the Google permissions granted by the User to connect their Agency's professional Gmail mailbox. These permissions solely enable sending, receiving, filing, tracking, and archiving the emails necessary for processing claim cases.

AI Gestion does not use Google data for advertising, profiling, or resale to third parties. This data is only accessible to authorized Users of the relevant Agency and to the technical systems strictly necessary for the service's operation.

The User may withdraw AI Gestion's access at any time from their Google account's security settings.

Cookie policy

Article 14: Use of Cookies

The Platform may use cookies or other storage mechanisms strictly necessary for its operation.

These mechanisms may be used to maintain the User's session, enable authentication, strengthen security, remember certain functional preferences, and ensure continuity of use.

Disabling these mechanisms may prevent login or disrupt certain Platform features.

Article 15: Advertising Cookies

The Platform does not use advertising cookies or trackers intended for commercial profiling.

Should a non-essential mechanism be integrated in the future, Users would be informed and their consent requested where applicable regulations require it.

Article 16: Managing Cookies

The User may delete cookies or stored data through their browser settings.

Deleting a session cookie may result in the User's immediate logout.

Data retention policy

Article 17: General Principle

Data is retained only for the period necessary for the operation of the Platform, the processing of Cases, and compliance with applicable obligations.

Information that is manifestly unnecessary, excessive, or unrelated to the processing of a Case must not be entered into the Platform.

Article 18: Active Cases

Data relating to an active Case may be retained for the period necessary for its processing, tracking, and the completion of related operations.

Article 19: Closed Cases

After a Case is closed, data may be deleted, archived, or anonymized when it is no longer necessary.

Certain data may nonetheless be retained where such retention is necessary to comply with a legal, contractual, accounting, tax, evidentiary, or litigation-related obligation.

Article 20: User Accounts

Data relating to an account may be retained for the period the account is active.

After an account is deactivated, certain information may be retained temporarily to ensure security, traceability, management of the parties' rights and obligations, and defense against fraudulent use.

Article 21: Security and Login Logs

Login, security, and activity logs may be retained for the period necessary to prevent fraudulent access, identify incidents, evidence transactions, protect the Platform, and manage disputes.

Article 22: Billing Data

Information necessary for billing, accounting, and proof of payment may be retained for the periods required by applicable legal, tax, and accounting obligations.

Article 23: Exceptional Retention

Deletion of data may be suspended where that data is necessary for an investigation, a claim, a dispute, a request from an authority, or the establishment, exercise, or defense of a legal right.