Responsible data use for a trusted international network.
This Notice explains how personal data is handled when people apply, communicate, participate or interact with GOB. It is designed around data minimization, institutional accountability, security and the legal requirements that may apply in Morocco, Spain, the European Union and other relevant jurisdictions.
GOB is a project of MYCDIC rather than a separate legal person. Unless a specific notice states otherwise, the institutional entity responsible for core GOB processing is MYCDIC acting through the GOB project administration.
Privacy Notice
For applicants, members, supporters, partners, visitors and participants.
Contents
- Scope
- Who is responsible
- Privacy principles
- Data we may collect
- Sources of data
- Purposes and lawful grounds
- Membership applications
- Supporters and partners
- Events and safeguarding
- Communications
- Directories and publicity
- Website and technical data
- Cookies and analytics
- Sensitive data
- Children and young people
- Who may receive data
- Service providers
- International transfers
- Retention
- Security
- Automated decisions
- Your rights
- Complaints
- Legal frameworks
- Changes
- Contact
1. Scope
This Notice applies to personal data processed through gob.ma and the core administrative activities of the Global Organization of Bridges (GOB), including organization membership, individual supporter engagement, institutional partnerships, inquiries, events, program participation, member services, safeguarding, communications, directories and related institutional records.
Separate notices or agreements may apply to a specific event, grant, research activity, employment relationship, partner platform or service. Where a specific notice gives more detailed information for that activity, it should be read together with this Notice.
2. Who is responsible for the processing
GOB is a strategic project of the Moroccan Youth Council for Diplomatic and International Cooperation (MYCDIC), not a separate legal person. Unless a specific notice identifies another arrangement, the institutional entity responsible for determining the purposes and means of core GOB processing is MYCDIC acting through the GOB project administration.
Contact for privacy matters: gob@mycdic.org. General institutional contact information is available on the Contact page.
Where GOB and a partner jointly determine the purposes and means of a specific activity, the parties may act as joint controllers or equivalent responsible entities where recognized by applicable law. The relevant notice or agreement will explain the arrangement where required.
3. Privacy principles
GOB seeks to apply the following principles across its data practices:
- Lawfulness, fairness and transparency: processing should have a legitimate and identifiable basis and should not be concealed from the people concerned.
- Purpose limitation: data should be collected for specified institutional purposes and not reused incompatibly without an appropriate legal basis or required authorization.
- Data minimization and proportionality: information should be adequate, relevant and limited to what is reasonably necessary.
- Accuracy: reasonable steps should be taken to keep material data accurate and current.
- Storage limitation: identifiable data should not be kept indefinitely without a justified reason.
- Integrity and confidentiality: technical and organizational safeguards should protect data from unauthorized access, loss, misuse or disclosure.
- Accountability: important processing activities should be documented and assigned to responsible roles.
4. Categories of data we may collect
| Category | Examples |
|---|---|
| Identity and contact | Name, role, organization, email, phone, country, city, professional contact details |
| Organization information | Association name, legal registration, field, size, website, governance or public profile information |
| Application information | Motivation statement, eligibility answers, uploaded legal documents, verification notes, decision status |
| Participation records | Programs, events, attendance, applications, certificates, invitations, feedback, support requests |
| Partner and supporter data | Professional profile, expertise, institution, cooperation interests, proposed contributions |
| Communications | Emails, contact-form messages, correspondence, complaints, support requests and follow-up notes |
| Media data | Photographs, video, quotes or biographies where appropriate consent or another lawful basis exists |
| Technical and security data | IP address, device or browser information, logs, timestamps, security events and fraud-prevention signals where collected |
| Compliance data | Due-diligence findings, conflict declarations, safeguarding records or legal-risk information when necessary and lawful |
5. Sources of personal data
Data may come directly from the person concerned, from an authorized representative of an organization, from public institutional or professional sources, from GOB or MYCDIC personnel, from a partner administering a joint activity, or from lawful verification of information already made public by the organization or individual.
If an organization provides information about another person, it should have authority and a lawful basis to do so and should direct that person to this Notice where appropriate.
6. Purposes and lawful grounds
The lawful basis depends on the jurisdiction and the processing context. Where the GDPR applies, GOB/MYCDIC may rely on consent, steps requested before entering an agreement, performance of an agreement, compliance with legal obligations, legitimate interests, or another lawful basis recognized by law. Under Moroccan Law 09-08, processing is carried out subject to the applicable requirements on lawful, legitimate and transparent processing, purpose, proportionality, notification and authorization where required.
| Purpose | Typical basis or justification |
|---|---|
| Review membership applications | Steps requested by the applicant, legitimate institutional interest, consent where required |
| Administer active membership | Membership relationship, legitimate interests, legal or governance obligations |
| Verify identity and credibility | Fraud prevention, integrity, safeguarding and network protection |
| Provide programs and member services | Requested service, legitimate interests, program terms |
| Maintain records and audit trails | Accountability, legal obligations, dispute prevention and institutional continuity |
| Send operational communications | Membership or program administration and legitimate interests |
| Send optional newsletters or promotional updates | Consent or another lawful basis where permitted, with opt-out rights |
| Publish directory or media information | Consent, public professional context, legitimate interests, or specific program terms as applicable |
| Protect systems and users | Security, fraud prevention, legal compliance and legitimate interests |
7. Membership applications and legal documents
The membership form may collect organization information, representative contact data, motivation text and legal documents needed to review eligibility and credibility. Applicants should upload only documents requested for the review and should redact unrelated personal data where possible.
GOB may use application records to assess eligibility, contact the applicant, prevent duplicate or fraudulent applications, maintain an audit trail, manage reapplications and protect network integrity. A rejection does not necessarily require immediate deletion of every record where proportionate retention is needed for those purposes or required by law.
The current application workflow uses Google Apps Script and related Google services for submission and administration. Because such infrastructure may involve processing or storage outside Morocco, any processing requiring Moroccan transfer formalities is subject to the applicable CNDP rules and required approvals or safeguards before or as legally required for deployment.
8. Individual supporters and institutional partners
Supporter and partner information may be used to assess suitability, match expertise, prepare cooperation proposals, manage relationships, document contributions and communicate about relevant opportunities. Partnership discussions do not make submitted information public unless there is a separate basis to do so.
9. Events, programs, travel and safeguarding
For events and programs, GOB may need additional data such as attendance, dietary or accessibility needs, travel information, emergency contacts or safeguarding information. Such data is collected only when relevant to the activity and may be subject to a specific notice.
Health, disability, safeguarding or other sensitive information should be requested only where necessary, handled with heightened access controls, and processed under a lawful basis or authorization appropriate to the jurisdiction.
10. Communications
GOB may send service and administrative messages needed to manage an application, membership, event, complaint, security issue or partnership. These messages are not treated as optional marketing where they are necessary for the relationship.
Optional newsletters, campaigns or promotional communications will provide an unsubscribe or objection mechanism where required. Unsubscribing from marketing does not prevent necessary administrative or legal communications.
11. Member directory, biographies and public recognition
GOB may publish organization-level information such as organization name, logo, country, field, website, public description and membership status to support discoverability and institutional transparency. Personal contact data is not intended for public display by default.
Leadership names, professional biographies, photographs or quotes may be published where there is consent, a clear professional-public context, or another lawful basis appropriate to the use. Individuals may request correction of inaccurate information and may raise an objection where applicable.
12. Website, logs and security information
Servers and security tools may process technical data necessary to deliver the website, detect attacks, prevent abuse, troubleshoot errors and maintain logs. Such information may include IP address, time, browser, requested page, referrer, security event and device-related data.
Security logs are not intended to build advertising profiles. Access should be restricted to people who need it for technical, security, legal or audit purposes.
14. Sensitive and special-category data
Applicants and visitors should not submit sensitive personal data unless specifically requested for a legitimate purpose. Depending on law, sensitive data may include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health data, genetic or biometric data, or information about offences and convictions.
Where Moroccan Law 09-08 requires prior authorization for certain sensitive processing, national identity numbers, offence data, changes of purpose or file interconnection, the relevant processing is subject to the required CNDP formalities.
15. Children and young people
GOB's mission involves youth and civil society, but the public organization-membership form is intended to be completed by an authorized adult representative. GOB does not intentionally seek unnecessary personal data from children through the general website.
Where a specific youth program includes participants under the age of majority, GOB will apply age-appropriate information, consent or authorization rules, safeguarding measures, limited access and additional program-specific procedures as required.
16. Who may receive personal data
Access may be provided only where necessary to:
- authorized GOB project personnel and authorized MYCDIC personnel;
- reviewers or governance bodies involved in admission, safeguarding, integrity or complaints;
- technology, hosting, email, storage, security or professional service providers acting under appropriate terms;
- event, training or program partners where sharing is necessary and disclosed;
- professional advisers, auditors, insurers or legal representatives where justified;
- public authorities, regulators or courts where disclosure is legally required or necessary to establish, exercise or defend legal rights.
GOB does not sell personal data to advertisers.
17. Service providers and processor controls
Where a service provider processes personal data on behalf of GOB/MYCDIC, GOB seeks to use providers that offer appropriate confidentiality and security safeguards and to put contractual or equivalent controls in place where required.
Providers may have their own independent obligations for data they process as separate controllers, for example when a member chooses to purchase a partner's service directly. In that case the partner's own privacy notice also applies.
18. International data transfers
GOB is designed for cross-border cooperation and may use providers or partners located outside the country of the person concerned. International transfer rules therefore matter.
Where Moroccan Law 09-08 applies, transfers of personal data abroad are subject to the applicable CNDP framework, including prior notification or authorization requirements and the conditions governing transfers to countries outside Morocco. Where the GDPR applies, transfers outside the EEA are subject to Chapter V safeguards, adequacy decisions, appropriate safeguards or recognized derogations as applicable.
GOB will seek to use lawful transfer mechanisms and appropriate contractual, technical or organizational safeguards. A specific activity may be delayed, reconfigured or limited where the required transfer basis or regulatory formality is not yet available.
19. Retention periods
Retention depends on purpose, legal requirements, risk, the relationship and the need to maintain a defensible institutional record. The following are general targets and may be shortened or extended where justified:
| Record | Typical target | Reason |
|---|---|---|
| Incomplete application | Up to 6 months after abandonment | Support, duplicate prevention and follow-up |
| Unsuccessful application | Up to 24 months after final decision | Reapplication context, audit, integrity and dispute management |
| Active member file | For membership duration | Administration and service delivery |
| Former member core record | Up to 5 years after closure | Institutional history, disputes, compliance and fraud prevention |
| Partnership and agreement records | Agreement term plus up to 5 years | Contract, audit and legal claims |
| Complaints and safeguarding records | As required by risk, safeguarding and applicable law | Protection, accountability and legal obligations |
| Routine website security logs | Usually up to 12 months | Security and incident investigation |
| Optional marketing data | Until withdrawal or inactivity review | Communication preference management |
A legal hold, regulatory request, safeguarding concern, active dispute, fraud-prevention need or statutory duty may justify a longer period. GOB may also retain minimal suppression records to respect an opt-out request.
20. Security and confidentiality
GOB seeks to use proportionate safeguards such as role-based access, limited administrative permissions, secure transport, strong authentication, backup controls, document-access restrictions, logging, confidentiality duties and incident response. Security measures are reviewed according to the sensitivity and risk of the processing.
No online system can be guaranteed absolutely secure. Users should use trusted devices, protect their accounts, avoid sending unnecessary sensitive data and report suspected misuse promptly.
21. Automated decision-making
GOB does not intend to make membership decisions that produce legal or similarly significant effects solely by automated processing. Technical tools may assist with routing, duplicate detection, validation, risk flags or administrative triage, but significant admission or integrity decisions remain subject to authorized human review.
22. Your privacy rights
Rights vary by jurisdiction. Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of certain automated decisions.
Under Moroccan Law 09-08, rights include access, rectification and opposition subject to the law. Where the GDPR applies, additional rights may be available under Articles 15 to 22.
Requests may be sent to gob@mycdic.org. GOB may need to verify identity before disclosing or changing personal data and may retain information where an exemption, legal duty or overriding legitimate ground applies.
23. Complaints and supervisory authorities
Privacy concerns should first be sent to GOB/MYCDIC through gob@mycdic.org so they can be investigated. This does not remove any right to contact a competent supervisory authority.
For processing subject to Moroccan Law 09-08, the competent authority is the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP). Where EU or Spanish data-protection law applies, a person may also have the right to complain to the competent EU supervisory authority, including the Spanish authority where relevant.
24. Legal and regulatory frameworks
This Notice is designed to operate within the legal framework that is applicable to the relevant processing. Key references may include:
- Moroccan Constitution privacy protections and Law No. 09-08 on the protection of individuals with regard to processing of personal data, together with Decree No. 2-09-165 and CNDP procedures;
- Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), where its territorial scope applies;
- Spanish Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights, where Spanish law applies;
- mandatory privacy, communications, safeguarding, record-keeping or sectoral laws in the country where a specific activity occurs.
Where a processing operation requires a filing, declaration, authorization, transfer request, consent or other regulatory step, GOB/MYCDIC will treat completion of the applicable formality as part of that processing operation's compliance requirements.
Regulatory discipline: the network may pause, limit or redesign a data flow if the required legal basis, notice, contract, transfer mechanism or supervisory formality is not available. This protects participants and the institutional integrity of GOB and MYCDIC.
25. Changes to this Notice
GOB may update this Notice when services, laws, infrastructure, partners or processing practices change. Material changes will be reflected by a new effective date and, where appropriate, additional notice will be provided to affected users.
26. Privacy contact
Email: gob@mycdic.org
Institutional context: GOB & MYCDIC
General contact: GOB Contact page
Complaints: Complaints channel
Official legal references
Public sources used to shape the legal framework of this Notice.


