MYCDIC logoA strategic project of MYCDICMoroccan Youth Council for Diplomatic and International Cooperation
Global Organization of Bridges logoGlobal Organization of BridgesGOBOne Voice, One Future
Privacy notice

Responsible data use for a trusted international network.

This Notice explains how personal data is handled when people apply, communicate, participate or interact with GOB. It is designed around data minimization, institutional accountability, security and the legal requirements that may apply in Morocco, Spain, the European Union and other relevant jurisdictions.

Effective 25 August 2026Version 4.3Applies to gob.ma and core GOB administration
Institutional responsibilityMYCDIC, acting through GOB.

GOB is a project of MYCDIC rather than a separate legal person. Unless a specific notice states otherwise, the institutional entity responsible for core GOB processing is MYCDIC acting through the GOB project administration.

PurposeData is used for defined institutional, membership, security and communication needs
MinimumGOB seeks to collect only what is reasonably necessary for the stated purpose
ControlAccess is limited according to role, need and authorized workflow
RightsAccess, correction, objection and other rights are supported where applicable

Privacy Notice

For applicants, members, supporters, partners, visitors and participants.

1. Scope

This Notice applies to personal data processed through gob.ma and the core administrative activities of the Global Organization of Bridges (GOB), including organization membership, individual supporter engagement, institutional partnerships, inquiries, events, program participation, member services, safeguarding, communications, directories and related institutional records.

Separate notices or agreements may apply to a specific event, grant, research activity, employment relationship, partner platform or service. Where a specific notice gives more detailed information for that activity, it should be read together with this Notice.

2. Who is responsible for the processing

GOB is a strategic project of the Moroccan Youth Council for Diplomatic and International Cooperation (MYCDIC), not a separate legal person. Unless a specific notice identifies another arrangement, the institutional entity responsible for determining the purposes and means of core GOB processing is MYCDIC acting through the GOB project administration.

Contact for privacy matters: gob@mycdic.org. General institutional contact information is available on the Contact page.

Where GOB and a partner jointly determine the purposes and means of a specific activity, the parties may act as joint controllers or equivalent responsible entities where recognized by applicable law. The relevant notice or agreement will explain the arrangement where required.

3. Privacy principles

GOB seeks to apply the following principles across its data practices:

  • Lawfulness, fairness and transparency: processing should have a legitimate and identifiable basis and should not be concealed from the people concerned.
  • Purpose limitation: data should be collected for specified institutional purposes and not reused incompatibly without an appropriate legal basis or required authorization.
  • Data minimization and proportionality: information should be adequate, relevant and limited to what is reasonably necessary.
  • Accuracy: reasonable steps should be taken to keep material data accurate and current.
  • Storage limitation: identifiable data should not be kept indefinitely without a justified reason.
  • Integrity and confidentiality: technical and organizational safeguards should protect data from unauthorized access, loss, misuse or disclosure.
  • Accountability: important processing activities should be documented and assigned to responsible roles.

4. Categories of data we may collect

CategoryExamples
Identity and contactName, role, organization, email, phone, country, city, professional contact details
Organization informationAssociation name, legal registration, field, size, website, governance or public profile information
Application informationMotivation statement, eligibility answers, uploaded legal documents, verification notes, decision status
Participation recordsPrograms, events, attendance, applications, certificates, invitations, feedback, support requests
Partner and supporter dataProfessional profile, expertise, institution, cooperation interests, proposed contributions
CommunicationsEmails, contact-form messages, correspondence, complaints, support requests and follow-up notes
Media dataPhotographs, video, quotes or biographies where appropriate consent or another lawful basis exists
Technical and security dataIP address, device or browser information, logs, timestamps, security events and fraud-prevention signals where collected
Compliance dataDue-diligence findings, conflict declarations, safeguarding records or legal-risk information when necessary and lawful

5. Sources of personal data

Data may come directly from the person concerned, from an authorized representative of an organization, from public institutional or professional sources, from GOB or MYCDIC personnel, from a partner administering a joint activity, or from lawful verification of information already made public by the organization or individual.

If an organization provides information about another person, it should have authority and a lawful basis to do so and should direct that person to this Notice where appropriate.

6. Purposes and lawful grounds

The lawful basis depends on the jurisdiction and the processing context. Where the GDPR applies, GOB/MYCDIC may rely on consent, steps requested before entering an agreement, performance of an agreement, compliance with legal obligations, legitimate interests, or another lawful basis recognized by law. Under Moroccan Law 09-08, processing is carried out subject to the applicable requirements on lawful, legitimate and transparent processing, purpose, proportionality, notification and authorization where required.

PurposeTypical basis or justification
Review membership applicationsSteps requested by the applicant, legitimate institutional interest, consent where required
Administer active membershipMembership relationship, legitimate interests, legal or governance obligations
Verify identity and credibilityFraud prevention, integrity, safeguarding and network protection
Provide programs and member servicesRequested service, legitimate interests, program terms
Maintain records and audit trailsAccountability, legal obligations, dispute prevention and institutional continuity
Send operational communicationsMembership or program administration and legitimate interests
Send optional newsletters or promotional updatesConsent or another lawful basis where permitted, with opt-out rights
Publish directory or media informationConsent, public professional context, legitimate interests, or specific program terms as applicable
Protect systems and usersSecurity, fraud prevention, legal compliance and legitimate interests

7. Membership applications and legal documents

The membership form may collect organization information, representative contact data, motivation text and legal documents needed to review eligibility and credibility. Applicants should upload only documents requested for the review and should redact unrelated personal data where possible.

GOB may use application records to assess eligibility, contact the applicant, prevent duplicate or fraudulent applications, maintain an audit trail, manage reapplications and protect network integrity. A rejection does not necessarily require immediate deletion of every record where proportionate retention is needed for those purposes or required by law.

The current application workflow uses Google Apps Script and related Google services for submission and administration. Because such infrastructure may involve processing or storage outside Morocco, any processing requiring Moroccan transfer formalities is subject to the applicable CNDP rules and required approvals or safeguards before or as legally required for deployment.

8. Individual supporters and institutional partners

Supporter and partner information may be used to assess suitability, match expertise, prepare cooperation proposals, manage relationships, document contributions and communicate about relevant opportunities. Partnership discussions do not make submitted information public unless there is a separate basis to do so.

9. Events, programs, travel and safeguarding

For events and programs, GOB may need additional data such as attendance, dietary or accessibility needs, travel information, emergency contacts or safeguarding information. Such data is collected only when relevant to the activity and may be subject to a specific notice.

Health, disability, safeguarding or other sensitive information should be requested only where necessary, handled with heightened access controls, and processed under a lawful basis or authorization appropriate to the jurisdiction.

10. Communications

GOB may send service and administrative messages needed to manage an application, membership, event, complaint, security issue or partnership. These messages are not treated as optional marketing where they are necessary for the relationship.

Optional newsletters, campaigns or promotional communications will provide an unsubscribe or objection mechanism where required. Unsubscribing from marketing does not prevent necessary administrative or legal communications.

11. Member directory, biographies and public recognition

GOB may publish organization-level information such as organization name, logo, country, field, website, public description and membership status to support discoverability and institutional transparency. Personal contact data is not intended for public display by default.

Leadership names, professional biographies, photographs or quotes may be published where there is consent, a clear professional-public context, or another lawful basis appropriate to the use. Individuals may request correction of inaccurate information and may raise an objection where applicable.

12. Website, logs and security information

Servers and security tools may process technical data necessary to deliver the website, detect attacks, prevent abuse, troubleshoot errors and maintain logs. Such information may include IP address, time, browser, requested page, referrer, security event and device-related data.

Security logs are not intended to build advertising profiles. Access should be restricted to people who need it for technical, security, legal or audit purposes.

13. Cookies and analytics

GOB may use cookies or similar technologies that are strictly necessary for security, preferences or site functionality. If non-essential analytics, advertising or tracking technologies are introduced, GOB will update the relevant notice and deploy consent or preference controls where required by applicable law.

Users can also control cookies through browser settings, although disabling essential technologies may affect website functionality.

14. Sensitive and special-category data

Applicants and visitors should not submit sensitive personal data unless specifically requested for a legitimate purpose. Depending on law, sensitive data may include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health data, genetic or biometric data, or information about offences and convictions.

Where Moroccan Law 09-08 requires prior authorization for certain sensitive processing, national identity numbers, offence data, changes of purpose or file interconnection, the relevant processing is subject to the required CNDP formalities.

15. Children and young people

GOB's mission involves youth and civil society, but the public organization-membership form is intended to be completed by an authorized adult representative. GOB does not intentionally seek unnecessary personal data from children through the general website.

Where a specific youth program includes participants under the age of majority, GOB will apply age-appropriate information, consent or authorization rules, safeguarding measures, limited access and additional program-specific procedures as required.

16. Who may receive personal data

Access may be provided only where necessary to:

  • authorized GOB project personnel and authorized MYCDIC personnel;
  • reviewers or governance bodies involved in admission, safeguarding, integrity or complaints;
  • technology, hosting, email, storage, security or professional service providers acting under appropriate terms;
  • event, training or program partners where sharing is necessary and disclosed;
  • professional advisers, auditors, insurers or legal representatives where justified;
  • public authorities, regulators or courts where disclosure is legally required or necessary to establish, exercise or defend legal rights.

GOB does not sell personal data to advertisers.

17. Service providers and processor controls

Where a service provider processes personal data on behalf of GOB/MYCDIC, GOB seeks to use providers that offer appropriate confidentiality and security safeguards and to put contractual or equivalent controls in place where required.

Providers may have their own independent obligations for data they process as separate controllers, for example when a member chooses to purchase a partner's service directly. In that case the partner's own privacy notice also applies.

18. International data transfers

GOB is designed for cross-border cooperation and may use providers or partners located outside the country of the person concerned. International transfer rules therefore matter.

Where Moroccan Law 09-08 applies, transfers of personal data abroad are subject to the applicable CNDP framework, including prior notification or authorization requirements and the conditions governing transfers to countries outside Morocco. Where the GDPR applies, transfers outside the EEA are subject to Chapter V safeguards, adequacy decisions, appropriate safeguards or recognized derogations as applicable.

GOB will seek to use lawful transfer mechanisms and appropriate contractual, technical or organizational safeguards. A specific activity may be delayed, reconfigured or limited where the required transfer basis or regulatory formality is not yet available.

19. Retention periods

Retention depends on purpose, legal requirements, risk, the relationship and the need to maintain a defensible institutional record. The following are general targets and may be shortened or extended where justified:

RecordTypical targetReason
Incomplete applicationUp to 6 months after abandonmentSupport, duplicate prevention and follow-up
Unsuccessful applicationUp to 24 months after final decisionReapplication context, audit, integrity and dispute management
Active member fileFor membership durationAdministration and service delivery
Former member core recordUp to 5 years after closureInstitutional history, disputes, compliance and fraud prevention
Partnership and agreement recordsAgreement term plus up to 5 yearsContract, audit and legal claims
Complaints and safeguarding recordsAs required by risk, safeguarding and applicable lawProtection, accountability and legal obligations
Routine website security logsUsually up to 12 monthsSecurity and incident investigation
Optional marketing dataUntil withdrawal or inactivity reviewCommunication preference management

A legal hold, regulatory request, safeguarding concern, active dispute, fraud-prevention need or statutory duty may justify a longer period. GOB may also retain minimal suppression records to respect an opt-out request.

20. Security and confidentiality

GOB seeks to use proportionate safeguards such as role-based access, limited administrative permissions, secure transport, strong authentication, backup controls, document-access restrictions, logging, confidentiality duties and incident response. Security measures are reviewed according to the sensitivity and risk of the processing.

No online system can be guaranteed absolutely secure. Users should use trusted devices, protect their accounts, avoid sending unnecessary sensitive data and report suspected misuse promptly.

21. Automated decision-making

GOB does not intend to make membership decisions that produce legal or similarly significant effects solely by automated processing. Technical tools may assist with routing, duplicate detection, validation, risk flags or administrative triage, but significant admission or integrity decisions remain subject to authorized human review.

22. Your privacy rights

Rights vary by jurisdiction. Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of certain automated decisions.

Under Moroccan Law 09-08, rights include access, rectification and opposition subject to the law. Where the GDPR applies, additional rights may be available under Articles 15 to 22.

Requests may be sent to gob@mycdic.org. GOB may need to verify identity before disclosing or changing personal data and may retain information where an exemption, legal duty or overriding legitimate ground applies.

23. Complaints and supervisory authorities

Privacy concerns should first be sent to GOB/MYCDIC through gob@mycdic.org so they can be investigated. This does not remove any right to contact a competent supervisory authority.

For processing subject to Moroccan Law 09-08, the competent authority is the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP). Where EU or Spanish data-protection law applies, a person may also have the right to complain to the competent EU supervisory authority, including the Spanish authority where relevant.

25. Changes to this Notice

GOB may update this Notice when services, laws, infrastructure, partners or processing practices change. Material changes will be reflected by a new effective date and, where appropriate, additional notice will be provided to affected users.

26. Privacy contact

Email: gob@mycdic.org

Institutional context: GOB & MYCDIC

General contact: GOB Contact page

Complaints: Complaints channel

Official legal references

Public sources used to shape the legal framework of this Notice.

Institutional frameworkMoroccan Youth Council for Diplomatic and International Cooperation identity

GOB is a strategic project of MYCDIC.

The Global Organization of Bridges develops within the institutional framework of the Moroccan Youth Council for Diplomatic and International Cooperation. The relationship provides GOB with its institutional home while the project focuses on structured cooperation, organizational development, network building and international engagement. Partnership and general enquiries can be directed to gob@mycdic.org.