Privacy Policy | AI Gestion
Version: 3.1.0, last updated: August 4, 2026.
The terms "Agency", "User", "Client", "Expert", "Case" and "Operator" have the meaning given to them in Article 2 of the Terms of Service.
Article 1: Purpose
This policy describes the conditions under which personal data is collected, used, retained, disclosed, and protected through the Platform.
It applies to Users, Clients, Experts, and any other person whose information is entered or processed within a Case.
Article 2: Data Controller
For data relating to the creation and management of accounts, security, billing, and the technical operation of the Platform, processing is carried out by the Operator of the AI Gestion Platform.
For data contained in claim Cases, the relevant Agency determines the professional purposes of the processing and remains responsible for the lawfulness of collecting and using that data.
The Operator then acts as a technical service provider on behalf of the Agency, within the limits of the lawful instructions given to it.
Article 3: Categories of Data Processed
The Platform may process identity and contact data, including first name, last name, email address, and phone number.
The Platform may process information relating to Users' accounts, roles, authorizations, and activities on the Platform.
The Platform may process information relating to contracts, vehicles, claims, repairs, estimates, amounts, case references, and the various stages of processing.
The Platform may process documents such as quotes, invoices, reports, photographs, supporting documents, and correspondence.
The Platform may process communications exchanged between Agencies, Clients, Experts, and other relevant parties.
The Platform may process technical data, connection information, security logs, and data enabling the detection of anomalies or unauthorized access.
The Platform may process data necessary for managing the subscription, billing, and payments.
Only information necessary for the operation of the Platform and the processing of Cases should be collected.
Article 4: Purposes of Processing
Data may be processed to create and manage accounts, authenticate Users, and control their authorizations.
Data may be processed to create, organize, track, and close claim Cases.
Data may be processed to receive, store, file, and transmit documents necessary for processing Cases.
Data may be processed to enable communications between Agencies, Clients, Experts, and other authorized parties.
Data may be processed to send follow-ups, notifications, and information relating to the progress of a Case.
Data may be processed to provide automated assistance, filing, summarization, or analysis features.
Data may be processed to prevent fraud, detect misuse, and protect the security of the Platform.
Data may be processed to manage subscriptions, quotes, billing, and payments.
Data may be processed to comply with a legal obligation, respond to a competent authority, or establish, exercise, or defend a legal right.
Article 5: Legal Basis for Processing
Depending on the situation, processing may be necessary for the performance of a requested service, the performance of a contractual relationship, the processing of a claim Case, compliance with a legal obligation, or the protection of the legitimate interests of the Agency or the Operator.
Where applicable law requires it, processing may also be based on the consent of the data subject.
The Agency is responsible for determining the legal basis applicable to the data it enters into the Platform.
Article 6: Recipients of Data
Data may be accessible to the Agency responsible for the Case and to the Users it has authorized.
Data may be disclosed to the relevant Clients where such disclosure is necessary for processing their Case.
Data may be disclosed to Experts designated by the Agency, limited to the information necessary for carrying out their assignment.
Data may be accessible to authorized persons acting on behalf of the Operator where such access is necessary for operation, maintenance, security, or technical support.
Data may be processed by technical providers necessary for hosting, communication, storage, payment, security, or the operation of the Platform's features.
Data may be disclosed to administrative, judicial, or regulatory authorities where required by a legal provision, a formal request, or an enforceable decision.
Data is not sold to third parties and is not used for advertising purposes unrelated to the operation of the Platform.
Article 7: Hosting and Processing Abroad
The Platform's core data is hosted in Nuremberg, Germany.
Hosting or processing data outside Moroccan territory may constitute a data transfer abroad.
The operations concerned must be carried out in compliance with the formalities, conditions, and safeguards required by applicable Moroccan regulations.
Article 8: Retention Period
Data is retained only for the period necessary for the purposes for which it was collected or processed.
Data may be retained longer where such retention is necessary to comply with a legal, accounting, tax, contractual, evidentiary, or litigation-related obligation.
Data may also be retained where necessary for the security of the Platform, fraud prevention, incident management, proof of a transaction, or the defense of a legal right.
Where data is no longer necessary, it is deleted, anonymized, or permanently rendered inaccessible, subject to applicable technical and legal constraints.
Article 9: Accuracy of Data
The Agency and Users must ensure that data entered into the Platform is accurate, complete, relevant, and up to date.
Any person who notices incorrect information may request its rectification under the conditions provided by applicable regulations.
Article 10: Security and Confidentiality of Data
The Operator implements reasonable technical and organizational measures designed to preserve the confidentiality, integrity, availability, and traceability of data.
Access to data is limited to authorized persons based on their roles and needs.
Technical details of security measures are not published so as not to reduce their effectiveness.
The Agency and Users must also adopt reasonable security measures, in particular by protecting their credentials and limiting access to authorized persons.
Article 11: Rights of Data Subjects
Any data subject may exercise the rights recognized under applicable Moroccan legislation on the protection of personal data.
Depending on applicable legal conditions, these rights may include a right of access, a right of rectification, and a right of objection.
Any request may be sent to: aigestionmaroc@gmail.com.
The request must contain the information necessary to identify the person, the Case, and the data concerned.
Where the request concerns a Case managed by an Agency, it may be forwarded to that Agency to be handled in its capacity as controller for the Case.
Article 12: Requests from Authorities
Data may be disclosed to an administrative, judicial, or regulatory authority where required by a legal provision, a formal request, or an enforceable decision.
The Operator may retain the information necessary to evidence such disclosure.
Article 13: Security Incident
When an incident likely to affect data is identified, the Operator takes reasonably necessary measures to identify the incident, limit its consequences, secure the systems concerned, and prevent its recurrence.
Agencies and Users must promptly report any incident, suspicious access, accidental disclosure, or data loss to: aigestionmaroc@gmail.com.
Article 13 bis: Use of Google Data
AI Gestion uses the Google permissions granted by the User to connect their Agency's professional Gmail mailbox. These permissions solely enable sending, receiving, filing, tracking, and archiving the emails necessary for processing claim cases.
AI Gestion does not use Google data for advertising, profiling, or resale to third parties. This data is only accessible to authorized Users of the relevant Agency and to the technical systems strictly necessary for the service's operation.
The User may withdraw AI Gestion's access at any time from their Google account's security settings.
Cookie policy
Article 14: Use of Cookies
The Platform may use cookies or other storage mechanisms strictly necessary for its operation.
These mechanisms may be used to maintain the User's session, enable authentication, strengthen security, remember certain functional preferences, and ensure continuity of use.
Disabling these mechanisms may prevent login or disrupt certain Platform features.
Article 15: Advertising Cookies
The Platform does not use advertising cookies or trackers intended for commercial profiling.
Should a non-essential mechanism be integrated in the future, Users would be informed and their consent requested where applicable regulations require it.
Article 16: Managing Cookies
The User may delete cookies or stored data through their browser settings.
Deleting a session cookie may result in the User's immediate logout.
Data retention policy
Article 17: General Principle
Data is retained only for the period necessary for the operation of the Platform, the processing of Cases, and compliance with applicable obligations.
Information that is manifestly unnecessary, excessive, or unrelated to the processing of a Case must not be entered into the Platform.
Article 18: Active Cases
Data relating to an active Case may be retained for the period necessary for its processing, tracking, and the completion of related operations.
Article 19: Closed Cases
After a Case is closed, data may be deleted, archived, or anonymized when it is no longer necessary.
Certain data may nonetheless be retained where such retention is necessary to comply with a legal, contractual, accounting, tax, evidentiary, or litigation-related obligation.
Article 20: User Accounts
Data relating to an account may be retained for the period the account is active.
After an account is deactivated, certain information may be retained temporarily to ensure security, traceability, management of the parties' rights and obligations, and defense against fraudulent use.
Article 21: Security and Login Logs
Login, security, and activity logs may be retained for the period necessary to prevent fraudulent access, identify incidents, evidence transactions, protect the Platform, and manage disputes.
Article 22: Billing Data
Information necessary for billing, accounting, and proof of payment may be retained for the periods required by applicable legal, tax, and accounting obligations.
Article 23: Exceptional Retention
Deletion of data may be suspended where that data is necessary for an investigation, a claim, a dispute, a request from an authority, or the establishment, exercise, or defense of a legal right.