Legal & Privacy

Privacy Policy

This Privacy Policy explains how Mrhbazhni collects, uses, shares, stores and protects personal information when you browse our website, contact our team, create an account or book a tourism activity.

Website operator ZHNI AGENCE
Applicable framework Moroccan Law No. 09-08
Last updated 26 July 2026
Continue to the Full Policy

About this policy

Who We Are and What This Policy Covers

Mrhbazhni is a brand operated by ZHNI AGENCE, a Moroccan single-member limited liability company. Through Mrhbazhni, ZHNI AGENCE provides an online platform for booking tourism activities, including guided visits, and for connecting travellers with independent guides in Morocco.

Our Role as Data Controller

ZHNI AGENCE is responsible for determining why and how personal information is processed through the Mrhbazhni website, booking system, customer accounts, contact channels and related support services.

In this Privacy Policy, the terms “Mrhbazhni”, “we”, “us” and “our” refer to ZHNI AGENCE when it processes personal information through the Mrhbazhni brand and services.

Services Covered by This Policy

This Privacy Policy applies when you interact with Mrhbazhni, including when you:

  • browse mrhbazhni.com;
  • use the contact form or communicate with our team;
  • create or manage a customer account;
  • select, request or book a tourism activity;
  • make or coordinate a payment;
  • receive booking, account or support communications;
  • request assistance concerning an existing reservation;
  • interact with an independent guide in connection with a booking.

Independent Guides

Guided activities available through Mrhbazhni may be performed by independent guides. ZHNI AGENCE may provide a relevant guide with the limited information reasonably necessary to organise and deliver the booked activity.

The specific information shared with guides and the purposes of that sharing are explained later in this Privacy Policy.

Third-Party Services

Some parts of the Mrhbazhni service depend on external providers, including website hosting, payment processing, fraud prevention, email delivery and technical services.

Where an external provider processes information under its own terms and privacy policy, this Privacy Policy does not replace that provider’s own privacy information.

Scope limitation

This Privacy Policy does not govern unrelated third-party websites or services that you may access through an external link. We encourage you to review their privacy information before providing personal data.

Information we process

Personal Data We Collect

We collect personal information that you provide directly, information generated through your use of our services and limited information received from providers involved in a booking or payment.

Some information is required to create an account, process a booking, respond to a request or provide the selected activity. Other information is optional and is identified as such when collected.

Directly provided

Contact and Enquiry Information

When you use our contact form, email us or otherwise request assistance, we may collect:

  • your full name;
  • your email address;
  • your telephone or WhatsApp number, when provided;
  • the type of assistance requested;
  • your preferred destination;
  • your preferred travel date;
  • the expected number of travellers;
  • your booking reference, where relevant;
  • the contents of your message and subsequent correspondence.
Why this information is collected

To understand your request, respond to you, recommend relevant available services and provide support concerning a reservation.

Customer account

Account and Identification Information

When you create or use a customer account, we may collect and maintain:

  • your name and account display information;
  • your email address;
  • your telephone number, where required or provided;
  • your username or customer account identifier;
  • billing or contact details entered during checkout;
  • account creation and account activity information;
  • your saved order and reservation history.

Account passwords are not displayed to ZHNI AGENCE in readable form. The website stores the technical authentication information required to secure and operate your account.

Why this information is collected

To create and secure your account, identify your reservations, provide account functions and support access to booking records.

Tour reservation

Booking and Participant Information

When you request or book an activity through Mrhbazhni, we may collect or generate:

  • the selected tour or tourism activity;
  • the destination, date and time slot;
  • the number of adults and children included in the booking;
  • the booking identifier and reservation reference;
  • the quoted or confirmed price, currency and applicable adjustments;
  • the booking, payment and confirmation status;
  • the customer contact details associated with the reservation;
  • the guide assignment and operational booking information;
  • support notes reasonably necessary to manage the activity.

Where you make a booking for other participants, you should provide only information that is necessary for the activity and ensure that you are authorised to provide it.

Why this information is collected

To create, confirm, manage and deliver the requested activity, coordinate with the relevant independent guide and provide booking-related communications.

Transactions

Payment and Transaction Information

Depending on the payment method selected, we may receive or retain:

  • the selected payment method;
  • the transaction amount and currency;
  • the payment status;
  • a transaction or payment reference;
  • the date and time of the transaction;
  • limited payer or billing information returned by the provider;
  • bank-transfer references or supporting information you provide.

Payments made through PayPal or by card through PayPal are processed within PayPal’s payment environment. ZHNI AGENCE does not ask you to submit your complete card number, security code or PayPal password through the Mrhbazhni contact form.

For a direct bank transfer, the banking instructions supplied by ZHNI AGENCE must be used only for the relevant reservation. Please do not send confidential online-banking credentials.

Why this information is collected

To identify and reconcile payments, confirm reservations, manage refunds where applicable, prevent fraud and maintain financial and accounting records.

Customer assistance

Communications and Support Records

We may retain records of communications connected with your use of Mrhbazhni, including:

  • contact-form submissions;
  • emails sent to or received from our team;
  • booking and payment confirmations;
  • account and password-reset communications;
  • customer-support requests and responses;
  • complaints, cancellation requests and refund correspondence;
  • communications needed to coordinate with an independent guide.
Why this information is collected

To provide customer support, document requests and decisions, manage complaints and maintain an accurate history of the reservation relationship.

Website operation

Technical, Security and Usage Information

When you access the website, our systems and technical service providers may automatically process limited technical information, such as:

  • your IP address;
  • browser, device and operating-system information;
  • the date and time of requests;
  • pages or website functions accessed;
  • referring and destination URLs;
  • session, cookie and account authentication information;
  • server, application, security and error logs;
  • anti-spam and fraud-prevention signals, including reCAPTCHA data.

Additional information about cookies, reCAPTCHA and external technical services is provided later in this Privacy Policy.

Why this information is collected

To operate and secure the website, maintain sessions, detect abuse, prevent spam, diagnose errors and improve the reliability of our services.

Please do not submit unnecessary sensitive information

Unless we provide a specific and secure method for a legitimate purpose, do not send card numbers, passwords, passport copies, national identity documents, medical information or other sensitive personal information through the contact form or ordinary email.

Purposes and justification

How and Why We Use Your Data

ZHNI AGENCE processes personal information only where it is reasonably necessary for a defined purpose connected with the Mrhbazhni services or where processing is required or permitted under applicable law.

Depending on the circumstances, processing may be necessary to respond to a request you have made, prepare or perform a booking, comply with a legal obligation, protect the website and our services, or pursue a legitimate business interest that does not override your rights.

Before booking

Responding to Enquiries and Travel Plans

We use the information submitted through the contact form, email or another approved contact channel to:

  • identify and understand your request;
  • answer questions about available activities;
  • help you choose a suitable destination or experience;
  • prepare information relating to your proposed travel date;
  • respond to a request for a personalised experience;
  • maintain a record of our response and subsequent correspondence.
Primary justification

Taking steps at your request before a possible booking and, where required for optional processing, your consent.

Account services

Creating and Managing Customer Accounts

We use account and identification information to:

  • create and maintain your customer account;
  • authenticate access to protected account areas;
  • display your orders and reservations;
  • manage password-reset and account notifications;
  • connect bookings with the correct customer record;
  • provide support concerning account access.
Primary justification

Providing the account functions you request, performing services connected with a booking and protecting account security.

Reservation fulfilment

Creating and Managing Bookings

We process booking and participant information to:

  • record the selected activity, date and time slot;
  • calculate and confirm the applicable price;
  • create the booking and reservation references;
  • confirm availability and booking status;
  • send booking-related communications;
  • manage changes, cancellations and applicable refunds;
  • retain an accurate record of the booked service.
Primary justification

Taking steps requested by you before booking and performing the reservation and tourism activity you have selected.

Financial processing

Managing Payments and Financial Records

We use transaction and payment-related information to:

  • identify the selected payment method;
  • verify whether a payment has been completed;
  • reconcile PayPal and direct bank-transfer transactions;
  • associate a transaction with the correct reservation;
  • manage applicable refunds or payment disputes;
  • prevent duplicate or unauthorised transactions;
  • maintain financial, tax and accounting records.
Primary justification

Performing the booking transaction, complying with financial and accounting obligations, and protecting against payment fraud.

Activity delivery

Coordinating with Independent Guides

Where an independent guide is involved in a booked activity, we may use and share limited booking information to:

  • identify the relevant activity and reservation;
  • confirm the destination, date and time slot;
  • communicate the expected number of participants;
  • provide the contact information needed for coordination;
  • confirm guide availability and assignment;
  • communicate an agreed meeting point or operational update;
  • address an issue affecting delivery of the activity.

Independent guides should receive only the information reasonably necessary to prepare and deliver the relevant activity.

Primary justification

Performing the booked activity and taking the operational steps necessary to provide the service requested by the traveller.

Customer relationship

Providing Support and Managing Complaints

We use communications and reservation records to:

  • respond to account or booking-support requests;
  • investigate reservation or payment issues;
  • manage cancellation and refund requests;
  • record and respond to complaints;
  • communicate important changes affecting an activity;
  • document the resolution of a customer-service issue;
  • protect the legitimate interests of customers and ZHNI AGENCE.
Primary justification

Performing and supporting the booking relationship, responding to your request and maintaining reliable records of service issues.

Legal responsibilities

Meeting Legal and Administrative Obligations

We may process and retain relevant information where necessary to:

  • maintain accounting and transaction records;
  • respond to a valid request from a competent authority;
  • comply with applicable consumer-protection requirements;
  • document consent or other processing justification;
  • exercise or defend legal rights and claims;
  • manage disputes, suspected fraud or unlawful activity;
  • demonstrate compliance with applicable obligations.
Primary justification

Compliance with legal obligations and the establishment, exercise or defence of legitimate legal rights.

Protection and reliability

Securing and Improving Our Services

We use limited technical, security and usage information to:

  • maintain website sessions and authentication;
  • detect spam, abuse and suspicious activity;
  • prevent unauthorised account access;
  • diagnose technical errors and service interruptions;
  • maintain server and application security logs;
  • protect reservations and customer information;
  • improve the reliability and usability of website functions.
Primary justification

ZHNI AGENCE’s legitimate interest in protecting its customers, website, accounts, bookings and technical infrastructure, subject to the rights and interests of the persons concerned.

What happens if information is not provided?

You may choose not to provide optional information. However, where information is necessary to identify you, respond to your request, process payment, create a booking or coordinate the selected activity, we may be unable to provide the relevant service without it.

Operational processing

Bookings, Payments and Independent Guides

Booking an activity through Mrhbazhni involves several connected operations, including creating a reservation record, confirming payment, coordinating the activity and providing relevant information to the independent guide assigned to the booking.

ZHNI AGENCE seeks to limit the information processed at each stage to what is reasonably necessary to prepare, confirm, deliver and document the requested activity.

Activity selected
Reservation created
Payment confirmed
Guide coordinated

Reservation lifecycle

Booking and Provisional Reservation Records

When you select an activity and begin the booking process, the Mrhbazhni booking system may create a provisional reservation record before payment is completed.

This record may include:

  • the selected activity or tour;
  • the destination, activity date and time slot;
  • the number of adults and children;
  • the calculated price and currency;
  • the customer name, email address and contact information;
  • a reservation identifier or secure booking reference;
  • the provisional, pending, confirmed or cancelled status;
  • technical information needed to connect the reservation with checkout.

A provisional reservation does not necessarily mean that payment has been completed or that the activity has been finally confirmed. The booking status is updated as the checkout and payment process progresses.

Incomplete bookings

Records connected with an incomplete or unsuccessful booking are retained only in accordance with the retention periods described later in this Privacy Policy.

Online payment provider

PayPal and Card Payments Through PayPal

Customers may be able to pay using a PayPal account or an eligible payment card processed through PayPal. These transactions are processed within PayPal’s payment services and are also subject to PayPal’s terms and privacy information.

To initiate, identify and reconcile a transaction, ZHNI AGENCE and PayPal may exchange limited information such as:

  • the booking or order reference;
  • the transaction amount and currency;
  • the customer or payer name;
  • the payer email address;
  • limited billing or contact information;
  • the PayPal payer or transaction identifier;
  • the payment authorisation and completion status;
  • refund, reversal, dispute or fraud-prevention information.

ZHNI AGENCE does not require customers to enter complete card numbers, card security codes or PayPal passwords into the Mrhbazhni contact form.

Separate PayPal processing

PayPal may process information for its own payment, security, fraud-prevention, compliance and dispute-management purposes under its applicable privacy information.

Direct payment

Direct Bank Transfer or Account Deposit

Where direct bank payment is available, ZHNI AGENCE provides the customer with payment instructions linked to the relevant reservation.

To identify and confirm the payment, we may process:

  • the booking or order reference;
  • the amount and currency paid;
  • the payment or deposit date;
  • the bank transaction reference;
  • the account-holder or depositor name displayed on the transaction;
  • a payment receipt or confirmation supplied by the customer;
  • the resulting payment and booking status.

Bank-transfer and deposit information may also be retained where required for transaction reconciliation, accounting, refund management, fraud prevention or the resolution of a payment issue.

Protect your banking credentials

Do not send an online-banking username, password, verification code, card security code or other confidential authentication credential to Mrhbazhni.

Activity delivery

Independent Guides and Operational Coordination

Tourism activities made available through Mrhbazhni may be performed by independent guides. Guides are not presented as employees of ZHNI AGENCE unless expressly stated otherwise.

Once a guide is assigned to a reservation, ZHNI AGENCE may provide the guide with limited information reasonably necessary to prepare and deliver the relevant activity, including:

  • the activity name and destination;
  • the booking or reservation reference;
  • the scheduled date and time slot;
  • the number of expected participants;
  • the customer’s name;
  • a telephone number or other contact method needed for coordination;
  • the agreed meeting point or pickup information, where applicable;
  • relevant operational notes voluntarily provided by the customer.

A guide may use the provided contact information to communicate with the customer before or during the activity, for example to confirm the meeting point, report a delay or address an operational issue.

If the assigned guide becomes unavailable, necessary booking information may be provided to a replacement guide involved in delivering the same activity.

Limited operational use

Information supplied for a reservation must not be used by an independent guide for unrelated advertising or marketing without an appropriate legal justification and the required information being provided to the person concerned.

Data minimisation

Information Not Routinely Shared with Guides

Independent guides do not routinely need access to all information held in the Mrhbazhni customer, payment or support systems.

Unless a specific situation lawfully requires otherwise, information not routinely provided to a guide includes:

  • complete card or payment-account credentials;
  • PayPal or online-banking passwords;
  • customer account passwords or authentication information;
  • unnecessary billing-address information;
  • internal fraud-prevention or security records;
  • unrelated order or reservation history;
  • internal administrative notes unrelated to the activity;
  • complete customer correspondence where only a summary is necessary.

Access to operational booking information should be limited to the guide assigned to the activity and authorised persons who need that information to manage the reservation.

Bookings Made for Other Participants

If you provide information about another participant, you should provide only information that is relevant to the booked activity and ensure that you are authorised to provide it. You should also make the participant aware that their information may be processed for booking coordination and activity delivery.

Controlled access and disclosure

Service Providers and Data Recipients

ZHNI AGENCE may provide limited personal information to service providers, independent guides and other authorised recipients where this is reasonably necessary to operate Mrhbazhni, perform a booking, process a payment, provide support or comply with applicable law.

The role of each recipient may differ. Some providers process information to supply a technical service to ZHNI AGENCE, while others, such as payment providers or public authorities, may process information under their own legal responsibilities and privacy terms.

Limited purpose

Information is disclosed only for an identified operational, contractual, security or legal purpose.

Necessary access

A recipient should receive only the information reasonably required to perform its role.

Confidentiality

Service relationships should include appropriate confidentiality, security and restricted-use obligations.

Website infrastructure

Hosting and Technical Infrastructure

The Mrhbazhni website and its connected booking information are hosted through Zume, a trading name of Alpha Internet Limited. The hosting environment currently used for Mrhbazhni is located in London, United Kingdom.

Hosting and infrastructure services may technically store or transmit information including:

  • website files and databases;
  • customer-account information;
  • orders and reservation records;
  • contact-form submissions;
  • server and application logs;
  • IP addresses and security information;
  • website backups;
  • technical support information where assistance is requested.

Authorised hosting personnel may have limited technical access where this is necessary to maintain infrastructure, investigate an incident, restore a backup or provide technical support.

Provider Zume / Alpha Internet Limited
Hosting location London, United Kingdom
Review Zume’s Privacy Policy

Transaction processing

PayPal, Banks and Financial Institutions

Where you pay through PayPal or use a card processed through PayPal, relevant transaction information is provided to and received from PayPal to initiate, authorise, complete, reconcile or refund the transaction.

Depending on the transaction, relevant recipients may include:

  • PayPal and companies involved in its payment services;
  • card-payment networks and payment processors;
  • the customer’s card issuer or financial institution;
  • ZHNI AGENCE’s financial institution;
  • fraud-prevention and transaction-verification providers;
  • parties involved in a payment dispute or refund.

Information exchanged may include the transaction reference, amount, currency, payment status, payer name, payer email address and limited billing or contact information.

PayPal processes certain information under its own privacy statement and may use service providers, payment networks, financial institutions and fraud-prevention organisations to provide and protect its services.

Payment credentials

ZHNI AGENCE does not require you to provide complete card numbers, card security codes or PayPal passwords through the Mrhbazhni contact form.

Review PayPal’s Privacy Statement

Activity fulfilment

Independent Guides

A guide assigned to a confirmed activity may receive limited information needed to prepare and deliver that specific activity.

Depending on the booking, this may include:

  • the customer’s name;
  • a telephone number or approved contact method;
  • the activity and destination;
  • the date and scheduled time slot;
  • the expected number of participants;
  • the booking reference;
  • the meeting point or pickup information;
  • relevant operational notes supplied for the activity.

Guides must not routinely receive full payment credentials, customer-account passwords, unrelated reservation history or internal information that is not necessary for the activity.

Where a guide is replaced, the necessary operational information may be provided to the replacement guide involved in delivering the same activity.

Independent status

Guides provide their services as independent professionals. Information supplied for a booking must be used only for legitimate coordination and delivery of the relevant activity.

Email and support

Communication and Email Services

ZHNI AGENCE uses email, mailbox and technical communication services to receive enquiries and send operational messages connected with accounts, reservations, payments and customer support.

The information processed through these services may include:

  • names and email addresses;
  • sender and recipient information;
  • message content;
  • booking and order references;
  • booking, payment and account notifications;
  • technical delivery information;
  • security and anti-abuse information;
  • email attachments voluntarily supplied by the customer.

Access to business mailboxes should be restricted to authorised persons who require access for customer support, booking management, administration or technical maintenance.

Ordinary email is not a payment channel

Do not send card security codes, account passwords or online banking credentials through email.

Spam and abuse prevention

Google reCAPTCHA and Security Services

Mrhbazhni uses Google reCAPTCHA to help distinguish legitimate interactions from automated spam, abuse and potentially fraudulent activity.

When reCAPTCHA is executed, Google may process technical and interaction information needed to perform its risk analysis, including information about the browser, device, request and interaction with the protected page or form.

reCAPTCHA may also use a necessary cookie for risk analysis. The detailed use of cookies and reCAPTCHA is explained in the next section of this Privacy Policy.

Provider Google
Purpose Spam, abuse and fraud prevention

Professional and legal recipients

Advisers, Insurers and Public Authorities

Relevant personal information may be provided to professional advisers or competent authorities where this is reasonably necessary and permitted or required by applicable law.

These recipients may include:

  • accountants and financial advisers;
  • legal advisers;
  • auditors;
  • insurers and claims handlers;
  • banks and payment-dispute services;
  • courts and judicial authorities;
  • law-enforcement or regulatory authorities;
  • tax, consumer-protection or data-protection authorities.

A disclosure to an authority will be limited to the information lawfully requested or reasonably necessary to comply with the request, protect a person, investigate suspected unlawful activity, resolve a dispute or establish, exercise or defend legal rights.

Professional confidentiality

Professional advisers should receive only information relevant to the service, audit, claim, dispute or legal matter for which they have been engaged.

No Sale of Personal Information

ZHNI AGENCE does not sell personal information collected through Mrhbazhni. We do not provide customer booking or contact information to unrelated third parties for their own independent advertising.

Website Software and Components

Mrhbazhni uses WordPress, WooCommerce and custom booking components hosted within its website environment. Software operating within that environment is not automatically a separate external recipient. However, where a component communicates with an external provider, the relevant provider and purpose are described in this Policy where applicable.

Website operation and security

Cookies, reCAPTCHA and Technical Data

Mrhbazhni uses cookies and comparable technical mechanisms where they are needed to operate the website, maintain customer sessions, manage accounts and bookings, protect forms and diagnose technical problems.

The exact technologies used may depend on the page you visit, whether you are signed in, whether you add an activity to the cart and which website functions you choose to use.

Essential

Sessions, accounts, cart, checkout and booking operation.

Security

Spam, abuse, fraud and unauthorised-access prevention.

Optional

Used only when activated with the required information and controls.

Cookie Inventory and Updates

ZHNI AGENCE may periodically review the active cookies, browser storage, scripts and external requests used by Mrhbazhni. This Privacy Policy will be updated where a material new technology, provider or purpose is introduced.

Cross-border processing

International Data Transfers

ZHNI AGENCE is established in Morocco. However, operating the Mrhbazhni website and providing certain payment, hosting and security functions may require personal information to be hosted, transmitted or otherwise processed outside Morocco.

ZHNI AGENCE remains responsible for identifying the relevant transfers, limiting the information involved and ensuring that the requirements of applicable Moroccan data-protection law are addressed.

Business operator Morocco

ZHNI AGENCE operates the Mrhbazhni service.

Website hosting London, United Kingdom

Website, booking and technical information may be hosted here.

External providers International processing

Payment and security providers may operate in multiple countries.

Website infrastructure

Hosting in London, United Kingdom

The Mrhbazhni website is currently hosted through Zume, a trading name of Alpha Internet Limited. The hosting location used for the website is London, United Kingdom.

As a result, information stored or processed through the website may be transferred from Morocco to the United Kingdom, including:

  • website and customer-account information;
  • contact-form submissions;
  • orders and reservation records;
  • booking and participant information;
  • server, application and security logs;
  • email and notification records hosted within the environment;
  • website files, databases and backups;
  • technical support information where assistance is required.

Hosting personnel may have limited technical access where necessary to maintain the infrastructure, restore information, investigate a technical incident or provide authorised support.

Hosting provider Zume / Alpha Internet Limited
Current hosting location London, United Kingdom
Review Zume’s Privacy Policy

External services

PayPal, Google and International Providers

Certain external providers used by Mrhbazhni operate internationally and may process personal information in countries other than Morocco or the country where the customer is located.

Payment services

PayPal

PayPal may process transaction, payer, fraud-prevention and dispute-related information through its international operations, affiliated entities and service providers.

Countries involved in processing may have data-protection laws that differ from those applicable in Morocco.

Review PayPal’s Privacy Statement

Security services

Google reCAPTCHA

Google operates servers and technical infrastructure in different countries. Information processed through reCAPTCHA may therefore be processed outside Morocco.

This may include IP address, browser and device information, interaction signals, security identifiers and other information used for spam, abuse and fraud-prevention analysis.

Provider-specific processing

The countries and technical locations used by an external provider may change according to its infrastructure, service providers and legal obligations. Its current privacy information should be reviewed for additional details.

Applicable legal framework

Moroccan Law No. 09-08

Transfers of personal information from Morocco to another country are governed in particular by Articles 43 and 44 of Moroccan Law No. 09-08.

These provisions require the data controller to consider the legal conditions applicable to the destination, the nature of the information, the purpose and duration of processing and the safeguards connected with the transfer.

Depending on the destination and circumstances, a transfer may require an applicable legal condition, supporting safeguards and formalities before the Moroccan data-protection authority.

No automatic equivalence assumption

This Policy does not claim that every country used by an external provider offers the same legal protection as Morocco.

Protection measures

Measures Applied to International Processing

ZHNI AGENCE seeks to reduce the risks connected with international processing by applying measures appropriate to the provider, information and purpose concerned.

These measures may include:

  • selecting established providers with published privacy terms;
  • limiting information to what is necessary for the service;
  • using encrypted HTTPS connections for website communications;
  • restricting access to authorised persons and accounts;
  • using strong authentication and account-security controls;
  • reviewing provider privacy and security information;
  • using contractual confidentiality and restricted-use clauses;
  • maintaining limited retention and backup schedules;
  • reviewing material changes to providers or hosting locations;
  • completing applicable Moroccan notification formalities.

No technical or organisational measure can eliminate every risk. ZHNI AGENCE therefore reviews the information involved and seeks to avoid unnecessary transfers.

Data minimisation

A provider should receive only the information reasonably needed to provide its hosting, payment, security or technical service.

Transparency and contact

Your Rights Remain Available

International hosting or processing does not remove your ability to contact ZHNI AGENCE concerning personal information processed through Mrhbazhni.

Subject to applicable Moroccan law, you may contact us to request:

  • information about the processing of your personal data;
  • access to personal information concerning you;
  • correction of inaccurate or incomplete information;
  • opposition to processing where the applicable conditions are met;
  • information about relevant recipients or transfer destinations;
  • review of a concern relating to an external provider;
  • deletion where no overriding legal or operational reason requires retention;
  • additional information about the safeguards used for a transfer.

An external provider may also offer separate privacy rights, account controls or complaint procedures under its own policy.

CNDP References and Transfer Formalities

ZHNI AGENCE does not publish a CNDP receipt, declaration or transfer authorisation number in this Privacy Policy unless and until an official reference has been issued for the relevant processing.

Any required notification, request or supporting documentation must be handled in accordance with Moroccan Law No. 09-08 and the procedures of the competent Moroccan data-protection authority.

Storage limitation

Data Retention

ZHNI AGENCE retains personal information only for as long as reasonably necessary for the purpose for which it was collected, subject to applicable accounting, legal, security and dispute-management requirements.

At the end of the applicable period, information is deleted, anonymised or isolated from routine use unless a longer period is required for a specific lawful reason.

Purpose first

Information is kept only while its original purpose remains active.

Limited access

Archived information is not intended for routine operational use.

Secure disposal

Expired information is deleted or anonymised where appropriate.

Information category Standard retention period Starting point
Contact enquiries not resulting in a booking

24 months

Last meaningful exchange
Incomplete or abandoned provisional reservations

Up to 90 days

Creation or last booking activity
Customer account without an active legal record

Active use plus 3 years of inactivity

Last account activity
Confirmed bookings and operational support records

Up to 5 years

Activity date or closure of the support case
Invoices, payment and accounting records

10 years

End of the relevant accounting period
Application and security logs

Normally up to 12 months

Date of the recorded event
Rotating website backups

Normally up to 90 days

Date the backup was created

These standard periods may be shortened where information is no longer required. They may be extended only where an applicable legal obligation, active dispute, security incident or other documented reason requires it.

General assistance

Contact Enquiries and Unconverted Requests

Contact-form submissions, emails and related correspondence that do not result in a booking are normally retained for up to 24 months after the last meaningful exchange.

This period allows ZHNI AGENCE to:

  • respond to the original enquiry;
  • continue a travel-planning discussion;
  • understand previous information supplied by the customer;
  • manage a follow-up request;
  • document how the enquiry was handled;
  • investigate misuse or spam where necessary.

Information that is clearly irrelevant, duplicated or submitted as spam may be deleted earlier.

Standard period 24 months after the last meaningful exchange

Booking not completed

Incomplete and Provisional Reservations

A provisional reservation may be created before checkout or payment is completed. Where no order or confirmed booking follows, the related operational record is normally retained for no more than 90 days.

A limited period may be needed to:

  • complete or diagnose the booking workflow;
  • prevent duplicate reservations;
  • resolve a failed or interrupted checkout;
  • investigate a payment-status mismatch;
  • respond to a customer who asks about the attempted booking;
  • protect the system against abuse or fraud.

Browser cart cookies and sessions may expire earlier than the corresponding server-side provisional record.

Maximum operational period Up to 90 days after creation or last activity

Customer access

Customer Accounts

Customer-account information is normally retained while the account remains active and for up to three years after the last meaningful account activity.

Before deleting or anonymising an inactive account, ZHNI AGENCE may consider whether the account remains connected with:

  • an upcoming activity;
  • an active reservation;
  • an unresolved payment;
  • a cancellation or refund request;
  • a complaint or legal dispute;
  • records subject to a statutory retention period.

Deleting an account does not necessarily require deletion of invoices or accounting records that must be retained separately. Where possible, information that is no longer needed for the account service may be anonymised.

Standard account period Active use plus up to 3 years of inactivity

Tour records

Confirmed Bookings and Customer Support

Booking, participant, guide-assignment and related customer-support records are normally retained for up to five years after the activity date or closure of the relevant customer-service matter.

This period supports:

  • booking history and account access;
  • customer-service follow-up;
  • cancellations and refund management;
  • complaint handling;
  • quality and operational review;
  • fraud or duplicate-booking investigation;
  • the establishment, exercise or defence of legal rights.

Information not required for those purposes may be removed earlier or separated from the active booking environment.

Copies held by independent guides

Guides should delete customer contact details and operational copies within 90 days after the activity, unless an active complaint, incident or lawful obligation requires temporary retention for longer.

Standard booking period Up to 5 years after the activity or case closure

Statutory records

Payments, Invoices and Accounting Information

Invoices, accounting records and supporting transaction documentation are normally retained for ten years in accordance with applicable Moroccan accounting and tax requirements.

The information retained may include:

  • order and booking references;
  • customer or payer identification details;
  • transaction amount and currency;
  • payment date and payment method;
  • PayPal or bank transaction references;
  • refund and reversal information;
  • invoices and accounting entries;
  • documents supporting financial reconciliation.

This does not mean that ZHNI AGENCE retains complete card numbers, security codes, PayPal passwords or online-banking credentials.

Statutory accounting period 10 years

Infrastructure

Technical Logs, Security Records and Backups

Server, application, login, email-delivery and security logs are normally retained for no longer than 12 months.

Individual log categories may be retained for a shorter period according to their operational purpose, storage volume and security relevance.

Routine application and server logs Up to 12 months
Security and access events Up to 12 months
Local anti-spam or reCAPTCHA-related records Up to 12 months or less
Rotating website backups Up to 90 days

A record connected with a confirmed security incident may be isolated and retained for longer where necessary to investigate the incident, protect affected persons or establish legal rights.

Backups

Information deleted from the active website may remain temporarily in a secured rotating backup until that backup expires or is overwritten. Backups are intended for restoration and continuity, not routine customer-data access.

End of retention

Deletion, Anonymisation and Legal Holds

At the end of the applicable retention period, ZHNI AGENCE may:

  • securely delete the information;
  • remove it from routine operational systems;
  • anonymise it so that it no longer identifies an individual;
  • retain only the elements required by law;
  • restrict access to an authorised archive;
  • allow it to expire through a controlled backup rotation.

A standard period may be suspended or extended where information is reasonably necessary for:

  • an active booking or unresolved payment;
  • a cancellation, refund or chargeback;
  • a customer complaint;
  • a suspected security incident or fraud investigation;
  • a request from a competent authority;
  • an accounting or tax obligation;
  • the establishment, exercise or defence of legal rights.

Once the exceptional reason ends, the information is reviewed again and deleted, anonymised or returned to the standard retention process.

A deletion request may be limited by legal obligations

A request to delete an account cannot require ZHNI AGENCE to destroy invoices, transaction records or evidence that must still be retained under applicable law.

Questions About Retention or Deletion

You may contact ZHNI AGENCE to ask whether information concerning you is still retained or to request deletion where the applicable legal conditions are met.

Confidentiality and protection

Data Security

ZHNI AGENCE applies and reviews technical and organisational measures intended to protect personal information processed through Mrhbazhni against accidental loss, destruction, alteration, unauthorised access, disclosure or other unlawful processing.

The measures applied depend on the nature of the information, the website function concerned, the service provider involved and the reasonably foreseeable security risks.

Restricted access

Information should be accessible only where required for an authorised role.

Layered protection

Administrative, technical and operational controls work together.

Continuous review

Measures are reviewed as systems, risks and service providers change.

Infrastructure protection

Technical and Organisational Measures

Depending on the relevant system and service, measures used or reviewed by ZHNI AGENCE may include:

  • HTTPS encryption for website communications;
  • restricted administrative and hosting access;
  • strong and unique passwords for privileged accounts;
  • multi-factor authentication where supported and appropriate;
  • software, plugin and server security updates;
  • firewall, anti-abuse and access-control mechanisms;
  • spam and automated-submission protection;
  • security, application and login-event logging;
  • controlled backups and restoration procedures;
  • separation of customer, booking and administrative permissions;
  • monitoring of suspicious or unexpected activity;
  • periodic review of obsolete accounts and access rights.

The presence of a security measure does not mean that it eliminates every possible threat. Measures are selected and adjusted according to the risks reasonably identified.

Security by proportion

The level of protection should be proportionate to the sensitivity, volume and operational importance of the information concerned.

Internal confidentiality

Access Control and Confidentiality

Access to personal information should be limited to authorised persons who need it for a defined operational, customer-support, technical, accounting or legal purpose.

Organisational controls may include:

  • access rights based on role and responsibility;
  • separate accounts for authorised users;
  • removal of access when it is no longer required;
  • confidentiality obligations for authorised persons;
  • limited visibility of payment and security information;
  • controlled access to business email accounts;
  • review of privileged WordPress and hosting accounts;
  • prohibition of unnecessary copying or local storage;
  • secure handling of exported or downloaded records;
  • awareness of phishing, impersonation and password risks.

Persons who receive access must use the information only for the authorised purpose and must not disclose it to unrelated persons.

Confidentiality principle

Access to personal information does not create a right to reuse, copy or disclose that information for another purpose.

Customer authentication

Customer Accounts and Password Security

Mrhbazhni uses authentication mechanisms to restrict customer account information to the relevant account user and authorised administrative personnel.

Account protections may include:

  • password-based authentication;
  • password-reset links sent to the registered email address;
  • session and authentication cookies;
  • protection against unauthorised administrative access;
  • login and security-event records;
  • restrictions on account and order visibility;
  • automatic expiration of certain temporary links or sessions;
  • technical storage of password-verification information.

ZHNI AGENCE does not need to know or request a customer’s existing account password. Customers should never send their password by email, contact form or messaging service.

Protect your account

Use a unique password, keep access to your email account secure and contact us promptly if you suspect that another person has accessed your Mrhbazhni account.

Transaction protection

Payment Information

Payments made through PayPal or by card through PayPal are processed through PayPal’s payment environment and security controls.

ZHNI AGENCE may retain transaction references, payment status, amount, currency and limited payer or billing information needed to identify and reconcile the transaction.

Mrhbazhni does not ask customers to send the following through its ordinary contact form or email:

  • a complete payment-card number;
  • a card security or verification code;
  • a PayPal password;
  • an online-banking password;
  • a one-time bank authentication code;
  • answers to banking-security questions;
  • remote access to a customer’s device or bank account;
  • other confidential authentication credentials.

For direct bank payments, customers should use only the payment instructions supplied through an authorised Mrhbazhni or ZHNI AGENCE channel and should verify unexpected requests before making a payment.

Transaction verification

A booking is confirmed according to its recorded payment and reservation status, not solely on the basis of an unverified screenshot or message.

External access

Service Providers and Independent Guides

Where personal information is processed by a service provider or shared with an independent guide, access should be limited to the information reasonably necessary for the relevant service or booked activity.

Protective measures may include:

  • selection of providers with published security information;
  • confidentiality and restricted-use provisions;
  • defined purposes and access limitations;
  • review of hosting, payment and security providers;
  • limited customer information supplied to guides;
  • prohibition of unrelated advertising use;
  • deletion of operational guide copies after the applicable period;
  • replacement or withdrawal of access when an assignment ends;
  • security review following a material incident;
  • contractual or operational controls proportionate to the service.

Independent guides should not receive complete payment credentials, customer-account passwords, unrelated booking history or internal security records.

Provider responsibility

Some external providers, including payment providers, may also apply their own security measures and legal responsibilities under their terms and privacy information.

Detection and response

Security Incident Management

Where ZHNI AGENCE becomes aware of a suspected security incident, it may take measures appropriate to the nature and seriousness of the event.

These measures may include:

  • recording and assessing the suspected incident;
  • restricting or suspending affected access;
  • resetting credentials or terminating active sessions;
  • reviewing relevant server and application logs;
  • isolating affected systems or information;
  • contacting a hosting, payment or security provider;
  • restoring information from a controlled backup;
  • identifying affected data and persons where possible;
  • preserving relevant evidence;
  • implementing corrective and preventive actions.

Where notification to a person, provider or competent authority is legally required or reasonably appropriate, ZHNI AGENCE will assess the information that should be communicated according to the circumstances.

Report a suspected security issue

contact@mrhbazhni.com +212 6 64 90 67 90

Safe use of the service

Your Security Responsibilities

Customers also play an important role in protecting account, booking and payment information.

When using Mrhbazhni, you should:

  • use a strong password that is not reused elsewhere;
  • protect access to the email address connected with your account;
  • sign out when using a shared or public device;
  • avoid sending passwords or payment credentials by email;
  • verify the website address before signing in or paying;
  • avoid clicking unexpected payment or password-reset links;
  • keep booking references private where appropriate;
  • inform us promptly about suspicious account activity;
  • verify unexpected changes to bank-payment instructions;
  • keep your device, browser and security software updated.

ZHNI AGENCE will never need your PayPal password, card security code or online-banking password to provide customer support.

Suspected impersonation or fraud

Do not complete an unexpected payment or disclose credentials. Contact Mrhbazhni using the contact details published directly on mrhbazhni.com.

Security Limitations

Although ZHNI AGENCE takes measures intended to protect personal information, no internet transmission, website, payment service, email system or storage environment can be guaranteed to be completely secure in every circumstance.

Customers should therefore avoid sending unnecessary sensitive information and should report suspected misuse as soon as possible.

Information, access and control

Your Rights Under Moroccan Law No. 09-08

Subject to the conditions and limitations of Moroccan Law No. 09-08, you may exercise rights concerning personal information processed by ZHNI AGENCE through Mrhbazhni.

These rights are intended to help you understand how information is used, obtain access to information concerning you, correct inaccurate records and object to certain processing where the legal conditions are met.

Be informed

Know who processes your data, why and for which recipients.

Review accuracy

Access information and request correction where appropriate.

Raise an objection

Object to qualifying processing and direct marketing.

Article 5

Right to Information

When personal information is collected directly from you, you should receive clear information about the relevant processing.

Depending on the circumstances, this information may include:

  • the identity of the data controller;
  • the purposes for which the information is collected;
  • the recipients or categories of recipients;
  • whether a requested response is mandatory or optional;
  • the possible consequences of not providing required information;
  • the existence of rights of access and rectification;
  • relevant information about international processing;
  • the CNDP declaration or authorisation reference, once available.

This Privacy Policy provides general information about processing through Mrhbazhni. Additional information may also appear beside a form, account function, checkout or other collection point.

Information at the point of collection

A form should explain its purpose and clearly distinguish required information from optional information.

Article 7

Right of Access

After establishing your identity, you may ask ZHNI AGENCE to confirm whether personal information concerning you is being processed through Mrhbazhni.

Where applicable, you may request information concerning:

  • the purposes of the processing;
  • the categories of personal information concerned;
  • the recipients or categories of recipients;
  • an intelligible communication of information concerning you;
  • available information concerning the origin of the data;
  • the logic underlying relevant automated processing;
  • booking, order and account information linked to you;
  • relevant contact, support or payment-reference records.

Access requests may be made at reasonable intervals and are handled without charge, subject to the conditions of applicable law.

A manifestly abusive request, including one that is excessive because of its repetitive nature, may be handled in accordance with the procedure permitted by Moroccan Law No. 09-08.

Identity protection

Information will not be disclosed until ZHNI AGENCE has taken reasonable steps to ensure that the requester is the person concerned or is properly authorised to act for that person.

Article 8

Updating, Correction, Erasure or Blocking

After establishing your identity, you may request the updating or correction of personal information that is inaccurate, incomplete, ambiguous or out of date.

Where processing does not comply with applicable law, the request may also concern the erasure or blocking of the relevant information, subject to the applicable legal conditions.

A request may concern, for example:

  • an incorrect name, email address or telephone number;
  • an inaccurate account or billing detail;
  • incorrect participant information;
  • an incorrect activity date or reservation record;
  • duplicate personal information;
  • information connected with the wrong customer;
  • outdated contact or account information;
  • data processed in a manner that does not comply with applicable law.

Where Article 8 applies, the necessary rectification must be completed without charge within the legally applicable period of ten clear days.

Where reasonably possible, relevant corrections, erasures or blocking actions are also communicated to third parties to whom the affected information was previously disclosed.

Article 8 rectification period Ten clear days
Erasure is not always available

Information may still need to be retained where required for accounting, tax, payment, dispute, security or other applicable legal purposes.

Article 9

Right to Object

After establishing your identity, you may object on legitimate grounds to certain processing of personal information concerning you.

A request should explain:

  • the processing activity to which you object;
  • the information concerned;
  • the legitimate grounds supporting the objection;
  • the account, booking or communication involved;
  • the outcome you are requesting;
  • any information needed to locate the relevant record.

An objection does not necessarily require ZHNI AGENCE to stop processing that is required by law or necessary to maintain records that must legally be retained.

It may also be necessary to continue limited processing to manage an active booking, payment, refund, complaint, security incident or legal claim.

Individual assessment

Each objection is reviewed according to the processing purpose, the grounds presented and the applicable legal obligations.

Articles 9 and 10

Direct Marketing Communications

You may object without charge to the use of your personal information for direct-marketing purposes.

Where prior consent is legally required for direct marketing by email or comparable electronic means, such communications should not be sent without the required consent or another condition expressly permitted by applicable law.

Any direct-marketing communication sent by Mrhbazhni must provide a clear and practical method for requesting that such communications stop.

Operational communications

Booking confirmations, payment information, account-security notices, activity reminders and support responses are sent to manage the requested service.

Marketing communications

Promotional messages concern offers or services beyond the operational administration of the current booking.

An objection to marketing does not prevent necessary operational communications concerning an active account, payment, reservation or customer-support matter.

Article 11

Decisions Based on Automated Processing

Moroccan Law No. 09-08 provides protection against certain decisions producing legal effects where those decisions are based solely on automated processing intended to evaluate aspects of a person or define that person’s profile.

Mrhbazhni may use automated technical operations to:

  • calculate a displayed tour price;
  • apply a seasonal or group-pricing rule;
  • check participant limits;
  • create a provisional reservation reference;
  • record a payment or order status;
  • assign or propose an available guide;
  • identify spam or security risk through reCAPTCHA;
  • send operational booking notifications.

These technical operations are not intended to evaluate a customer’s personality or create a behavioural profile for making a decision with legal effects.

Where a qualifying automated decision is used, you may request information about the underlying logic and an opportunity to present relevant observations, subject to applicable law.

Human support remains available

A customer may contact ZHNI AGENCE where an automated booking, payment, availability or security outcome appears incorrect.

External recourse

Complaint to the CNDP

You are encouraged to contact ZHNI AGENCE first so that we can identify the relevant information and attempt to resolve your request.

You may also submit a complaint to the Moroccan Commission Nationale de contrôle de la protection des Données à Caractère Personnel, commonly known as the CNDP, where you believe that your rights under Moroccan Law No. 09-08 have not been respected.

This may be relevant where, for example:

  • an access request has been refused without an appropriate reason;
  • inaccurate information has not been corrected;
  • an objection has not been appropriately considered;
  • personal information appears to have been used unlawfully;
  • information has been disclosed without an appropriate purpose;
  • a privacy request has received no appropriate response.
Visit the Official CNDP Complaint Page
Independent authority

The CNDP is the Moroccan authority responsible for overseeing compliance with Law No. 09-08 and handling complaints within its legal powers.

Submit a request

How to Exercise Your Rights

Send your request to ZHNI AGENCE using the contact details below. Clearly identify the right you wish to exercise and provide enough information for us to locate the relevant account, booking, transaction or communication.

Email subject Privacy Rights Request
Responsible entity ZHNI AGENCE

Where relevant, include your full name, account email, booking reference, the information concerned and the action requested. Please do not send passwords or full payment-card information.

Identity Verification and Authorised Representatives

ZHNI AGENCE may request information reasonably necessary to confirm your identity and protect personal information against unauthorised disclosure or modification.

Do not send a passport or national identity-card copy unless ZHNI AGENCE specifically determines that additional verification is necessary and provides an appropriate method for supplying it.

A person acting for another individual may be required to provide evidence of authority to submit and manage the request.

Legal and Operational Limitations

Privacy rights are subject to the conditions and exceptions of applicable law. A request may not require ZHNI AGENCE to delete accounting records, disrupt an active booking, conceal a payment dispute or destroy information needed to establish, exercise or defend legal rights.

Depending on your place of residence or the circumstances of the service, additional mandatory rights may also apply. This Policy does not limit rights that cannot lawfully be excluded.

Privacy assistance and transparency

Contact, Complaints and Policy Updates

ZHNI AGENCE is responsible for addressing questions and requests concerning personal information processed through Mrhbazhni.

We encourage you to contact us first where you have a question, correction request, objection, security concern or complaint. This allows us to identify the relevant account, booking, transaction or communication and review the matter directly.

Contact us

Describe the request or concern and identify the relevant record.

Identity check

We may verify that the request concerns you or an authorised person.

Review

We examine the relevant processing, records and legal obligations.

Response

We communicate the outcome or any information reasonably required.

Data controller

Contact ZHNI AGENCE

Questions concerning this Privacy Policy or the processing of personal information through Mrhbazhni should be addressed to ZHNI AGENCE.

Responsible entity ZHNI AGENCE
Legal form Single-member limited liability company — SARL AU
Brand Mrhbazhni
Country of establishment Morocco
Registered office
Angle Rues Mustapha Sedki Rafii et Omar Ebn El Khattab,
Bureau 10, Résidence Oum El Qoura,
Kénitra, Morocco
Visit the Mrhbazhni Contact Page

Exercise of rights

Submitting a Privacy Request

To help us locate and assess the relevant information, a privacy request should clearly describe the right or action concerned.

Where applicable, please include:

  • your full name;
  • the email address associated with your account or booking;
  • your booking or order reference;
  • the information or processing concerned;
  • the correction, access or other action requested;
  • relevant dates or communication references;
  • information explaining an objection or complaint;
  • a safe method for us to contact you.
Email subject Privacy Rights Request — Mrhbazhni Start an Email Request

Internal review

Raising a Privacy Complaint

If you believe that personal information has been collected, used, disclosed, retained or secured inappropriately, you may submit a complaint to ZHNI AGENCE.

A complaint should, where possible, explain:

  • what happened;
  • when the event occurred or was discovered;
  • which information appears to be affected;
  • the account, booking or communication involved;
  • any previous request made to Mrhbazhni;
  • the response already received, where applicable;
  • the outcome or corrective action you are seeking;
  • any supporting information that is safe and relevant to provide.

ZHNI AGENCE may review relevant account, booking, email, transaction, access or technical records in order to understand and respond to the complaint.

No retaliation for a privacy request

Submitting a legitimate privacy request or complaint does not remove your contractual or legal rights and should not result in discriminatory treatment.

External complaint

Complaints to the CNDP

You may submit a complaint to the Moroccan Commission Nationale de contrôle de la protection des Données à Caractère Personnel, commonly known as the CNDP, where you believe that your rights under Moroccan Law No. 09-08 have not been respected.

Contacting ZHNI AGENCE first may allow the matter to be identified and resolved directly, but it does not remove your ability to contact the CNDP in accordance with applicable law.

Moroccan data-protection authority

CNDP

Commission Nationale de contrôle de la protection des Données à Caractère Personnel.

Independent review

The CNDP handles complaints and exercises its powers independently under the applicable Moroccan legal framework.

Policy maintenance

Changes to This Privacy Policy

ZHNI AGENCE may update this Privacy Policy to reflect changes in the Mrhbazhni services, booking processes, payment methods, providers, security measures, legal requirements or data-protection practices.

An update may be required, for example, where:

  • a new booking or account function is introduced;
  • a payment method or payment provider changes;
  • the hosting provider or server location changes;
  • a new external service processes personal information;
  • cookie or security technologies change materially;
  • retention periods or internal procedures are updated;
  • applicable law or CNDP guidance changes;
  • the business identity or contact information changes.

The updated version will be published on this page with a revised “Last updated” date. Where a change materially affects the way personal information is processed, an additional notice may be provided through the website, customer account, email or another appropriate channel.

Changes apply from the effective date stated in the updated version, unless a different date is expressly indicated.

Review this page periodically

Customers and visitors should review the current version when using the website or making a new booking.

Publication record

Effective Date and Version

This version describes the personal-data processing practices intended to apply to the current Mrhbazhni website, customer accounts, booking system, payment methods and customer-support activities.

Policy version Privacy Policy V1.0
Last updated
Responsible entity ZHNI AGENCE
Applicable framework Moroccan Law No. 09-08
Publication-date control

The date above must match the “Last updated” date displayed in the Privacy Policy Hero. If the page is published later, both dates must be replaced with the actual publication date.

Privacy support

Questions About Your Personal Information?

Contact ZHNI AGENCE using the official Mrhbazhni contact details. Please include only the information necessary to explain your request.