Legal & Privacy
Privacy Policy
This Privacy Policy explains how Mrhbazhni collects, uses, shares, stores and protects personal information when you browse our website, contact our team, create an account or book a tourism activity.
About this policy
Who We Are and What This Policy Covers
Mrhbazhni is a brand operated by ZHNI AGENCE, a Moroccan single-member limited liability company. Through Mrhbazhni, ZHNI AGENCE provides an online platform for booking tourism activities, including guided visits, and for connecting travellers with independent guides in Morocco.
Our Role as Data Controller
ZHNI AGENCE is responsible for determining why and how personal information is processed through the Mrhbazhni website, booking system, customer accounts, contact channels and related support services.
In this Privacy Policy, the terms “Mrhbazhni”, “we”, “us” and “our” refer to ZHNI AGENCE when it processes personal information through the Mrhbazhni brand and services.
Services Covered by This Policy
This Privacy Policy applies when you interact with Mrhbazhni, including when you:
- browse mrhbazhni.com;
- use the contact form or communicate with our team;
- create or manage a customer account;
- select, request or book a tourism activity;
- make or coordinate a payment;
- receive booking, account or support communications;
- request assistance concerning an existing reservation;
- interact with an independent guide in connection with a booking.
Independent Guides
Guided activities available through Mrhbazhni may be performed by independent guides. ZHNI AGENCE may provide a relevant guide with the limited information reasonably necessary to organise and deliver the booked activity.
The specific information shared with guides and the purposes of that sharing are explained later in this Privacy Policy.
Third-Party Services
Some parts of the Mrhbazhni service depend on external providers, including website hosting, payment processing, fraud prevention, email delivery and technical services.
Where an external provider processes information under its own terms and privacy policy, this Privacy Policy does not replace that provider’s own privacy information.
This Privacy Policy does not govern unrelated third-party websites or services that you may access through an external link. We encourage you to review their privacy information before providing personal data.
Information we process
Personal Data We Collect
We collect personal information that you provide directly, information generated through your use of our services and limited information received from providers involved in a booking or payment.
Some information is required to create an account, process a booking, respond to a request or provide the selected activity. Other information is optional and is identified as such when collected.
Directly provided
Contact and Enquiry Information
When you use our contact form, email us or otherwise request assistance, we may collect:
- your full name;
- your email address;
- your telephone or WhatsApp number, when provided;
- the type of assistance requested;
- your preferred destination;
- your preferred travel date;
- the expected number of travellers;
- your booking reference, where relevant;
- the contents of your message and subsequent correspondence.
To understand your request, respond to you, recommend relevant available services and provide support concerning a reservation.
Customer account
Account and Identification Information
When you create or use a customer account, we may collect and maintain:
- your name and account display information;
- your email address;
- your telephone number, where required or provided;
- your username or customer account identifier;
- billing or contact details entered during checkout;
- account creation and account activity information;
- your saved order and reservation history.
Account passwords are not displayed to ZHNI AGENCE in readable form. The website stores the technical authentication information required to secure and operate your account.
To create and secure your account, identify your reservations, provide account functions and support access to booking records.
Tour reservation
Booking and Participant Information
When you request or book an activity through Mrhbazhni, we may collect or generate:
- the selected tour or tourism activity;
- the destination, date and time slot;
- the number of adults and children included in the booking;
- the booking identifier and reservation reference;
- the quoted or confirmed price, currency and applicable adjustments;
- the booking, payment and confirmation status;
- the customer contact details associated with the reservation;
- the guide assignment and operational booking information;
- support notes reasonably necessary to manage the activity.
Where you make a booking for other participants, you should provide only information that is necessary for the activity and ensure that you are authorised to provide it.
To create, confirm, manage and deliver the requested activity, coordinate with the relevant independent guide and provide booking-related communications.
Transactions
Payment and Transaction Information
Depending on the payment method selected, we may receive or retain:
- the selected payment method;
- the transaction amount and currency;
- the payment status;
- a transaction or payment reference;
- the date and time of the transaction;
- limited payer or billing information returned by the provider;
- bank-transfer references or supporting information you provide.
Payments made through PayPal or by card through PayPal are processed within PayPal’s payment environment. ZHNI AGENCE does not ask you to submit your complete card number, security code or PayPal password through the Mrhbazhni contact form.
For a direct bank transfer, the banking instructions supplied by ZHNI AGENCE must be used only for the relevant reservation. Please do not send confidential online-banking credentials.
To identify and reconcile payments, confirm reservations, manage refunds where applicable, prevent fraud and maintain financial and accounting records.
Customer assistance
Communications and Support Records
We may retain records of communications connected with your use of Mrhbazhni, including:
- contact-form submissions;
- emails sent to or received from our team;
- booking and payment confirmations;
- account and password-reset communications;
- customer-support requests and responses;
- complaints, cancellation requests and refund correspondence;
- communications needed to coordinate with an independent guide.
To provide customer support, document requests and decisions, manage complaints and maintain an accurate history of the reservation relationship.
Website operation
Technical, Security and Usage Information
When you access the website, our systems and technical service providers may automatically process limited technical information, such as:
- your IP address;
- browser, device and operating-system information;
- the date and time of requests;
- pages or website functions accessed;
- referring and destination URLs;
- session, cookie and account authentication information;
- server, application, security and error logs;
- anti-spam and fraud-prevention signals, including reCAPTCHA data.
Additional information about cookies, reCAPTCHA and external technical services is provided later in this Privacy Policy.
To operate and secure the website, maintain sessions, detect abuse, prevent spam, diagnose errors and improve the reliability of our services.
Unless we provide a specific and secure method for a legitimate purpose, do not send card numbers, passwords, passport copies, national identity documents, medical information or other sensitive personal information through the contact form or ordinary email.
Purposes and justification
How and Why We Use Your Data
ZHNI AGENCE processes personal information only where it is reasonably necessary for a defined purpose connected with the Mrhbazhni services or where processing is required or permitted under applicable law.
Depending on the circumstances, processing may be necessary to respond to a request you have made, prepare or perform a booking, comply with a legal obligation, protect the website and our services, or pursue a legitimate business interest that does not override your rights.
Before booking
Responding to Enquiries and Travel Plans
We use the information submitted through the contact form, email or another approved contact channel to:
- identify and understand your request;
- answer questions about available activities;
- help you choose a suitable destination or experience;
- prepare information relating to your proposed travel date;
- respond to a request for a personalised experience;
- maintain a record of our response and subsequent correspondence.
Taking steps at your request before a possible booking and, where required for optional processing, your consent.
Account services
Creating and Managing Customer Accounts
We use account and identification information to:
- create and maintain your customer account;
- authenticate access to protected account areas;
- display your orders and reservations;
- manage password-reset and account notifications;
- connect bookings with the correct customer record;
- provide support concerning account access.
Providing the account functions you request, performing services connected with a booking and protecting account security.
Reservation fulfilment
Creating and Managing Bookings
We process booking and participant information to:
- record the selected activity, date and time slot;
- calculate and confirm the applicable price;
- create the booking and reservation references;
- confirm availability and booking status;
- send booking-related communications;
- manage changes, cancellations and applicable refunds;
- retain an accurate record of the booked service.
Taking steps requested by you before booking and performing the reservation and tourism activity you have selected.
Financial processing
Managing Payments and Financial Records
We use transaction and payment-related information to:
- identify the selected payment method;
- verify whether a payment has been completed;
- reconcile PayPal and direct bank-transfer transactions;
- associate a transaction with the correct reservation;
- manage applicable refunds or payment disputes;
- prevent duplicate or unauthorised transactions;
- maintain financial, tax and accounting records.
Performing the booking transaction, complying with financial and accounting obligations, and protecting against payment fraud.
Activity delivery
Coordinating with Independent Guides
Where an independent guide is involved in a booked activity, we may use and share limited booking information to:
- identify the relevant activity and reservation;
- confirm the destination, date and time slot;
- communicate the expected number of participants;
- provide the contact information needed for coordination;
- confirm guide availability and assignment;
- communicate an agreed meeting point or operational update;
- address an issue affecting delivery of the activity.
Independent guides should receive only the information reasonably necessary to prepare and deliver the relevant activity.
Performing the booked activity and taking the operational steps necessary to provide the service requested by the traveller.
Customer relationship
Providing Support and Managing Complaints
We use communications and reservation records to:
- respond to account or booking-support requests;
- investigate reservation or payment issues;
- manage cancellation and refund requests;
- record and respond to complaints;
- communicate important changes affecting an activity;
- document the resolution of a customer-service issue;
- protect the legitimate interests of customers and ZHNI AGENCE.
Performing and supporting the booking relationship, responding to your request and maintaining reliable records of service issues.
Legal responsibilities
Meeting Legal and Administrative Obligations
We may process and retain relevant information where necessary to:
- maintain accounting and transaction records;
- respond to a valid request from a competent authority;
- comply with applicable consumer-protection requirements;
- document consent or other processing justification;
- exercise or defend legal rights and claims;
- manage disputes, suspected fraud or unlawful activity;
- demonstrate compliance with applicable obligations.
Compliance with legal obligations and the establishment, exercise or defence of legitimate legal rights.
Protection and reliability
Securing and Improving Our Services
We use limited technical, security and usage information to:
- maintain website sessions and authentication;
- detect spam, abuse and suspicious activity;
- prevent unauthorised account access;
- diagnose technical errors and service interruptions;
- maintain server and application security logs;
- protect reservations and customer information;
- improve the reliability and usability of website functions.
ZHNI AGENCE’s legitimate interest in protecting its customers, website, accounts, bookings and technical infrastructure, subject to the rights and interests of the persons concerned.
Some information is necessary to respond to your request, perform a booking, process a payment or comply with legal obligations. Where a particular optional use requires your consent, we will provide appropriate information and request that consent separately.
What happens if information is not provided?
You may choose not to provide optional information. However, where information is necessary to identify you, respond to your request, process payment, create a booking or coordinate the selected activity, we may be unable to provide the relevant service without it.
Operational processing
Bookings, Payments and Independent Guides
Booking an activity through Mrhbazhni involves several connected operations, including creating a reservation record, confirming payment, coordinating the activity and providing relevant information to the independent guide assigned to the booking.
ZHNI AGENCE seeks to limit the information processed at each stage to what is reasonably necessary to prepare, confirm, deliver and document the requested activity.
Reservation lifecycle
Booking and Provisional Reservation Records
When you select an activity and begin the booking process, the Mrhbazhni booking system may create a provisional reservation record before payment is completed.
This record may include:
- the selected activity or tour;
- the destination, activity date and time slot;
- the number of adults and children;
- the calculated price and currency;
- the customer name, email address and contact information;
- a reservation identifier or secure booking reference;
- the provisional, pending, confirmed or cancelled status;
- technical information needed to connect the reservation with checkout.
A provisional reservation does not necessarily mean that payment has been completed or that the activity has been finally confirmed. The booking status is updated as the checkout and payment process progresses.
Records connected with an incomplete or unsuccessful booking are retained only in accordance with the retention periods described later in this Privacy Policy.
Online payment provider
PayPal and Card Payments Through PayPal
Customers may be able to pay using a PayPal account or an eligible payment card processed through PayPal. These transactions are processed within PayPal’s payment services and are also subject to PayPal’s terms and privacy information.
To initiate, identify and reconcile a transaction, ZHNI AGENCE and PayPal may exchange limited information such as:
- the booking or order reference;
- the transaction amount and currency;
- the customer or payer name;
- the payer email address;
- limited billing or contact information;
- the PayPal payer or transaction identifier;
- the payment authorisation and completion status;
- refund, reversal, dispute or fraud-prevention information.
ZHNI AGENCE does not require customers to enter complete card numbers, card security codes or PayPal passwords into the Mrhbazhni contact form.
PayPal may process information for its own payment, security, fraud-prevention, compliance and dispute-management purposes under its applicable privacy information.
Direct payment
Direct Bank Transfer or Account Deposit
Where direct bank payment is available, ZHNI AGENCE provides the customer with payment instructions linked to the relevant reservation.
To identify and confirm the payment, we may process:
- the booking or order reference;
- the amount and currency paid;
- the payment or deposit date;
- the bank transaction reference;
- the account-holder or depositor name displayed on the transaction;
- a payment receipt or confirmation supplied by the customer;
- the resulting payment and booking status.
Bank-transfer and deposit information may also be retained where required for transaction reconciliation, accounting, refund management, fraud prevention or the resolution of a payment issue.
Do not send an online-banking username, password, verification code, card security code or other confidential authentication credential to Mrhbazhni.
Activity delivery
Independent Guides and Operational Coordination
Tourism activities made available through Mrhbazhni may be performed by independent guides. Guides are not presented as employees of ZHNI AGENCE unless expressly stated otherwise.
Once a guide is assigned to a reservation, ZHNI AGENCE may provide the guide with limited information reasonably necessary to prepare and deliver the relevant activity, including:
- the activity name and destination;
- the booking or reservation reference;
- the scheduled date and time slot;
- the number of expected participants;
- the customer’s name;
- a telephone number or other contact method needed for coordination;
- the agreed meeting point or pickup information, where applicable;
- relevant operational notes voluntarily provided by the customer.
A guide may use the provided contact information to communicate with the customer before or during the activity, for example to confirm the meeting point, report a delay or address an operational issue.
If the assigned guide becomes unavailable, necessary booking information may be provided to a replacement guide involved in delivering the same activity.
Information supplied for a reservation must not be used by an independent guide for unrelated advertising or marketing without an appropriate legal justification and the required information being provided to the person concerned.
Data minimisation
Information Not Routinely Shared with Guides
Independent guides do not routinely need access to all information held in the Mrhbazhni customer, payment or support systems.
Unless a specific situation lawfully requires otherwise, information not routinely provided to a guide includes:
- complete card or payment-account credentials;
- PayPal or online-banking passwords;
- customer account passwords or authentication information;
- unnecessary billing-address information;
- internal fraud-prevention or security records;
- unrelated order or reservation history;
- internal administrative notes unrelated to the activity;
- complete customer correspondence where only a summary is necessary.
Access to operational booking information should be limited to the guide assigned to the activity and authorised persons who need that information to manage the reservation.
Bookings Made for Other Participants
If you provide information about another participant, you should provide only information that is relevant to the booked activity and ensure that you are authorised to provide it. You should also make the participant aware that their information may be processed for booking coordination and activity delivery.
Controlled access and disclosure
Service Providers and Data Recipients
ZHNI AGENCE may provide limited personal information to service providers, independent guides and other authorised recipients where this is reasonably necessary to operate Mrhbazhni, perform a booking, process a payment, provide support or comply with applicable law.
The role of each recipient may differ. Some providers process information to supply a technical service to ZHNI AGENCE, while others, such as payment providers or public authorities, may process information under their own legal responsibilities and privacy terms.
Information is disclosed only for an identified operational, contractual, security or legal purpose.
A recipient should receive only the information reasonably required to perform its role.
Service relationships should include appropriate confidentiality, security and restricted-use obligations.
Website infrastructure
Hosting and Technical Infrastructure
The Mrhbazhni website and its connected booking information are hosted through Zume, a trading name of Alpha Internet Limited. The hosting environment currently used for Mrhbazhni is located in London, United Kingdom.
Hosting and infrastructure services may technically store or transmit information including:
- website files and databases;
- customer-account information;
- orders and reservation records;
- contact-form submissions;
- server and application logs;
- IP addresses and security information;
- website backups;
- technical support information where assistance is requested.
Authorised hosting personnel may have limited technical access where this is necessary to maintain infrastructure, investigate an incident, restore a backup or provide technical support.
Transaction processing
PayPal, Banks and Financial Institutions
Where you pay through PayPal or use a card processed through PayPal, relevant transaction information is provided to and received from PayPal to initiate, authorise, complete, reconcile or refund the transaction.
Depending on the transaction, relevant recipients may include:
- PayPal and companies involved in its payment services;
- card-payment networks and payment processors;
- the customer’s card issuer or financial institution;
- ZHNI AGENCE’s financial institution;
- fraud-prevention and transaction-verification providers;
- parties involved in a payment dispute or refund.
Information exchanged may include the transaction reference, amount, currency, payment status, payer name, payer email address and limited billing or contact information.
PayPal processes certain information under its own privacy statement and may use service providers, payment networks, financial institutions and fraud-prevention organisations to provide and protect its services.
ZHNI AGENCE does not require you to provide complete card numbers, card security codes or PayPal passwords through the Mrhbazhni contact form.
Activity fulfilment
Independent Guides
A guide assigned to a confirmed activity may receive limited information needed to prepare and deliver that specific activity.
Depending on the booking, this may include:
- the customer’s name;
- a telephone number or approved contact method;
- the activity and destination;
- the date and scheduled time slot;
- the expected number of participants;
- the booking reference;
- the meeting point or pickup information;
- relevant operational notes supplied for the activity.
Guides must not routinely receive full payment credentials, customer-account passwords, unrelated reservation history or internal information that is not necessary for the activity.
Where a guide is replaced, the necessary operational information may be provided to the replacement guide involved in delivering the same activity.
Guides provide their services as independent professionals. Information supplied for a booking must be used only for legitimate coordination and delivery of the relevant activity.
Email and support
Communication and Email Services
ZHNI AGENCE uses email, mailbox and technical communication services to receive enquiries and send operational messages connected with accounts, reservations, payments and customer support.
The information processed through these services may include:
- names and email addresses;
- sender and recipient information;
- message content;
- booking and order references;
- booking, payment and account notifications;
- technical delivery information;
- security and anti-abuse information;
- email attachments voluntarily supplied by the customer.
Access to business mailboxes should be restricted to authorised persons who require access for customer support, booking management, administration or technical maintenance.
Do not send card security codes, account passwords or online banking credentials through email.
Spam and abuse prevention
Google reCAPTCHA and Security Services
Mrhbazhni uses Google reCAPTCHA to help distinguish legitimate interactions from automated spam, abuse and potentially fraudulent activity.
When reCAPTCHA is executed, Google may process technical and interaction information needed to perform its risk analysis, including information about the browser, device, request and interaction with the protected page or form.
reCAPTCHA may also use a necessary cookie for risk analysis. The detailed use of cookies and reCAPTCHA is explained in the next section of this Privacy Policy.
No Sale of Personal Information
ZHNI AGENCE does not sell personal information collected through Mrhbazhni. We do not provide customer booking or contact information to unrelated third parties for their own independent advertising.
Website Software and Components
Mrhbazhni uses WordPress, WooCommerce and custom booking components hosted within its website environment. Software operating within that environment is not automatically a separate external recipient. However, where a component communicates with an external provider, the relevant provider and purpose are described in this Policy where applicable.
Cross-border processing
International Data Transfers
ZHNI AGENCE is established in Morocco. However, operating the Mrhbazhni website and providing certain payment, hosting and security functions may require personal information to be hosted, transmitted or otherwise processed outside Morocco.
ZHNI AGENCE remains responsible for identifying the relevant transfers, limiting the information involved and ensuring that the requirements of applicable Moroccan data-protection law are addressed.
ZHNI AGENCE operates the Mrhbazhni service.
Website, booking and technical information may be hosted here.
Payment and security providers may operate in multiple countries.
Website infrastructure
Hosting in London, United Kingdom
The Mrhbazhni website is currently hosted through Zume, a trading name of Alpha Internet Limited. The hosting location used for the website is London, United Kingdom.
As a result, information stored or processed through the website may be transferred from Morocco to the United Kingdom, including:
- website and customer-account information;
- contact-form submissions;
- orders and reservation records;
- booking and participant information;
- server, application and security logs;
- email and notification records hosted within the environment;
- website files, databases and backups;
- technical support information where assistance is required.
Hosting personnel may have limited technical access where necessary to maintain the infrastructure, restore information, investigate a technical incident or provide authorised support.
External services
PayPal, Google and International Providers
Certain external providers used by Mrhbazhni operate internationally and may process personal information in countries other than Morocco or the country where the customer is located.
Payment services
PayPal
PayPal may process transaction, payer, fraud-prevention and dispute-related information through its international operations, affiliated entities and service providers.
Countries involved in processing may have data-protection laws that differ from those applicable in Morocco.
Review PayPal’s Privacy StatementSecurity services
Google reCAPTCHA
Google operates servers and technical infrastructure in different countries. Information processed through reCAPTCHA may therefore be processed outside Morocco.
This may include IP address, browser and device information, interaction signals, security identifiers and other information used for spam, abuse and fraud-prevention analysis.
The countries and technical locations used by an external provider may change according to its infrastructure, service providers and legal obligations. Its current privacy information should be reviewed for additional details.
Applicable legal framework
Moroccan Law No. 09-08
Transfers of personal information from Morocco to another country are governed in particular by Articles 43 and 44 of Moroccan Law No. 09-08.
These provisions require the data controller to consider the legal conditions applicable to the destination, the nature of the information, the purpose and duration of processing and the safeguards connected with the transfer.
Depending on the destination and circumstances, a transfer may require an applicable legal condition, supporting safeguards and formalities before the Moroccan data-protection authority.
The provider, destination or category of destinations should be identified as accurately as reasonably possible.
Information must not be transferred for an unrelated or undefined purpose.
Notifications, requests or supporting documentation must be completed where required under applicable Moroccan law.
This Policy does not claim that every country used by an external provider offers the same legal protection as Morocco.
Protection measures
Measures Applied to International Processing
ZHNI AGENCE seeks to reduce the risks connected with international processing by applying measures appropriate to the provider, information and purpose concerned.
These measures may include:
- selecting established providers with published privacy terms;
- limiting information to what is necessary for the service;
- using encrypted HTTPS connections for website communications;
- restricting access to authorised persons and accounts;
- using strong authentication and account-security controls;
- reviewing provider privacy and security information;
- using contractual confidentiality and restricted-use clauses;
- maintaining limited retention and backup schedules;
- reviewing material changes to providers or hosting locations;
- completing applicable Moroccan notification formalities.
No technical or organisational measure can eliminate every risk. ZHNI AGENCE therefore reviews the information involved and seeks to avoid unnecessary transfers.
A provider should receive only the information reasonably needed to provide its hosting, payment, security or technical service.
Transparency and contact
Your Rights Remain Available
International hosting or processing does not remove your ability to contact ZHNI AGENCE concerning personal information processed through Mrhbazhni.
Subject to applicable Moroccan law, you may contact us to request:
- information about the processing of your personal data;
- access to personal information concerning you;
- correction of inaccurate or incomplete information;
- opposition to processing where the applicable conditions are met;
- information about relevant recipients or transfer destinations;
- review of a concern relating to an external provider;
- deletion where no overriding legal or operational reason requires retention;
- additional information about the safeguards used for a transfer.
An external provider may also offer separate privacy rights, account controls or complaint procedures under its own policy.
CNDP References and Transfer Formalities
ZHNI AGENCE does not publish a CNDP receipt, declaration or transfer authorisation number in this Privacy Policy unless and until an official reference has been issued for the relevant processing.
Any required notification, request or supporting documentation must be handled in accordance with Moroccan Law No. 09-08 and the procedures of the competent Moroccan data-protection authority.
Storage limitation
Data Retention
ZHNI AGENCE retains personal information only for as long as reasonably necessary for the purpose for which it was collected, subject to applicable accounting, legal, security and dispute-management requirements.
At the end of the applicable period, information is deleted, anonymised or isolated from routine use unless a longer period is required for a specific lawful reason.
Information is kept only while its original purpose remains active.
Archived information is not intended for routine operational use.
Expired information is deleted or anonymised where appropriate.
24 months
Last meaningful exchangeUp to 90 days
Creation or last booking activityActive use plus 3 years of inactivity
Last account activityUp to 5 years
Activity date or closure of the support case10 years
End of the relevant accounting periodNormally up to 12 months
Date of the recorded eventNormally up to 90 days
Date the backup was createdThese standard periods may be shortened where information is no longer required. They may be extended only where an applicable legal obligation, active dispute, security incident or other documented reason requires it.
General assistance
Contact Enquiries and Unconverted Requests
Contact-form submissions, emails and related correspondence that do not result in a booking are normally retained for up to 24 months after the last meaningful exchange.
This period allows ZHNI AGENCE to:
- respond to the original enquiry;
- continue a travel-planning discussion;
- understand previous information supplied by the customer;
- manage a follow-up request;
- document how the enquiry was handled;
- investigate misuse or spam where necessary.
Information that is clearly irrelevant, duplicated or submitted as spam may be deleted earlier.
Booking not completed
Incomplete and Provisional Reservations
A provisional reservation may be created before checkout or payment is completed. Where no order or confirmed booking follows, the related operational record is normally retained for no more than 90 days.
A limited period may be needed to:
- complete or diagnose the booking workflow;
- prevent duplicate reservations;
- resolve a failed or interrupted checkout;
- investigate a payment-status mismatch;
- respond to a customer who asks about the attempted booking;
- protect the system against abuse or fraud.
Browser cart cookies and sessions may expire earlier than the corresponding server-side provisional record.
Customer access
Customer Accounts
Customer-account information is normally retained while the account remains active and for up to three years after the last meaningful account activity.
Before deleting or anonymising an inactive account, ZHNI AGENCE may consider whether the account remains connected with:
- an upcoming activity;
- an active reservation;
- an unresolved payment;
- a cancellation or refund request;
- a complaint or legal dispute;
- records subject to a statutory retention period.
Deleting an account does not necessarily require deletion of invoices or accounting records that must be retained separately. Where possible, information that is no longer needed for the account service may be anonymised.
Tour records
Confirmed Bookings and Customer Support
Booking, participant, guide-assignment and related customer-support records are normally retained for up to five years after the activity date or closure of the relevant customer-service matter.
This period supports:
- booking history and account access;
- customer-service follow-up;
- cancellations and refund management;
- complaint handling;
- quality and operational review;
- fraud or duplicate-booking investigation;
- the establishment, exercise or defence of legal rights.
Information not required for those purposes may be removed earlier or separated from the active booking environment.
Guides should delete customer contact details and operational copies within 90 days after the activity, unless an active complaint, incident or lawful obligation requires temporary retention for longer.
Statutory records
Payments, Invoices and Accounting Information
Invoices, accounting records and supporting transaction documentation are normally retained for ten years in accordance with applicable Moroccan accounting and tax requirements.
The information retained may include:
- order and booking references;
- customer or payer identification details;
- transaction amount and currency;
- payment date and payment method;
- PayPal or bank transaction references;
- refund and reversal information;
- invoices and accounting entries;
- documents supporting financial reconciliation.
This does not mean that ZHNI AGENCE retains complete card numbers, security codes, PayPal passwords or online-banking credentials.
Infrastructure
Technical Logs, Security Records and Backups
Server, application, login, email-delivery and security logs are normally retained for no longer than 12 months.
Individual log categories may be retained for a shorter period according to their operational purpose, storage volume and security relevance.
A record connected with a confirmed security incident may be isolated and retained for longer where necessary to investigate the incident, protect affected persons or establish legal rights.
Information deleted from the active website may remain temporarily in a secured rotating backup until that backup expires or is overwritten. Backups are intended for restoration and continuity, not routine customer-data access.
End of retention
Deletion, Anonymisation and Legal Holds
At the end of the applicable retention period, ZHNI AGENCE may:
- securely delete the information;
- remove it from routine operational systems;
- anonymise it so that it no longer identifies an individual;
- retain only the elements required by law;
- restrict access to an authorised archive;
- allow it to expire through a controlled backup rotation.
A standard period may be suspended or extended where information is reasonably necessary for:
- an active booking or unresolved payment;
- a cancellation, refund or chargeback;
- a customer complaint;
- a suspected security incident or fraud investigation;
- a request from a competent authority;
- an accounting or tax obligation;
- the establishment, exercise or defence of legal rights.
Once the exceptional reason ends, the information is reviewed again and deleted, anonymised or returned to the standard retention process.
A request to delete an account cannot require ZHNI AGENCE to destroy invoices, transaction records or evidence that must still be retained under applicable law.
Questions About Retention or Deletion
You may contact ZHNI AGENCE to ask whether information concerning you is still retained or to request deletion where the applicable legal conditions are met.
Confidentiality and protection
Data Security
ZHNI AGENCE applies and reviews technical and organisational measures intended to protect personal information processed through Mrhbazhni against accidental loss, destruction, alteration, unauthorised access, disclosure or other unlawful processing.
The measures applied depend on the nature of the information, the website function concerned, the service provider involved and the reasonably foreseeable security risks.
Information should be accessible only where required for an authorised role.
Administrative, technical and operational controls work together.
Measures are reviewed as systems, risks and service providers change.
Infrastructure protection
Technical and Organisational Measures
Depending on the relevant system and service, measures used or reviewed by ZHNI AGENCE may include:
- HTTPS encryption for website communications;
- restricted administrative and hosting access;
- strong and unique passwords for privileged accounts;
- multi-factor authentication where supported and appropriate;
- software, plugin and server security updates;
- firewall, anti-abuse and access-control mechanisms;
- spam and automated-submission protection;
- security, application and login-event logging;
- controlled backups and restoration procedures;
- separation of customer, booking and administrative permissions;
- monitoring of suspicious or unexpected activity;
- periodic review of obsolete accounts and access rights.
The presence of a security measure does not mean that it eliminates every possible threat. Measures are selected and adjusted according to the risks reasonably identified.
The level of protection should be proportionate to the sensitivity, volume and operational importance of the information concerned.
Internal confidentiality
Access Control and Confidentiality
Access to personal information should be limited to authorised persons who need it for a defined operational, customer-support, technical, accounting or legal purpose.
Organisational controls may include:
- access rights based on role and responsibility;
- separate accounts for authorised users;
- removal of access when it is no longer required;
- confidentiality obligations for authorised persons;
- limited visibility of payment and security information;
- controlled access to business email accounts;
- review of privileged WordPress and hosting accounts;
- prohibition of unnecessary copying or local storage;
- secure handling of exported or downloaded records;
- awareness of phishing, impersonation and password risks.
Persons who receive access must use the information only for the authorised purpose and must not disclose it to unrelated persons.
Access to personal information does not create a right to reuse, copy or disclose that information for another purpose.
Customer authentication
Customer Accounts and Password Security
Mrhbazhni uses authentication mechanisms to restrict customer account information to the relevant account user and authorised administrative personnel.
Account protections may include:
- password-based authentication;
- password-reset links sent to the registered email address;
- session and authentication cookies;
- protection against unauthorised administrative access;
- login and security-event records;
- restrictions on account and order visibility;
- automatic expiration of certain temporary links or sessions;
- technical storage of password-verification information.
ZHNI AGENCE does not need to know or request a customer’s existing account password. Customers should never send their password by email, contact form or messaging service.
Use a unique password, keep access to your email account secure and contact us promptly if you suspect that another person has accessed your Mrhbazhni account.
Transaction protection
Payment Information
Payments made through PayPal or by card through PayPal are processed through PayPal’s payment environment and security controls.
ZHNI AGENCE may retain transaction references, payment status, amount, currency and limited payer or billing information needed to identify and reconcile the transaction.
Mrhbazhni does not ask customers to send the following through its ordinary contact form or email:
- a complete payment-card number;
- a card security or verification code;
- a PayPal password;
- an online-banking password;
- a one-time bank authentication code;
- answers to banking-security questions;
- remote access to a customer’s device or bank account;
- other confidential authentication credentials.
For direct bank payments, customers should use only the payment instructions supplied through an authorised Mrhbazhni or ZHNI AGENCE channel and should verify unexpected requests before making a payment.
A booking is confirmed according to its recorded payment and reservation status, not solely on the basis of an unverified screenshot or message.
External access
Service Providers and Independent Guides
Where personal information is processed by a service provider or shared with an independent guide, access should be limited to the information reasonably necessary for the relevant service or booked activity.
Protective measures may include:
- selection of providers with published security information;
- confidentiality and restricted-use provisions;
- defined purposes and access limitations;
- review of hosting, payment and security providers;
- limited customer information supplied to guides;
- prohibition of unrelated advertising use;
- deletion of operational guide copies after the applicable period;
- replacement or withdrawal of access when an assignment ends;
- security review following a material incident;
- contractual or operational controls proportionate to the service.
Independent guides should not receive complete payment credentials, customer-account passwords, unrelated booking history or internal security records.
Some external providers, including payment providers, may also apply their own security measures and legal responsibilities under their terms and privacy information.
Detection and response
Security Incident Management
Where ZHNI AGENCE becomes aware of a suspected security incident, it may take measures appropriate to the nature and seriousness of the event.
These measures may include:
- recording and assessing the suspected incident;
- restricting or suspending affected access;
- resetting credentials or terminating active sessions;
- reviewing relevant server and application logs;
- isolating affected systems or information;
- contacting a hosting, payment or security provider;
- restoring information from a controlled backup;
- identifying affected data and persons where possible;
- preserving relevant evidence;
- implementing corrective and preventive actions.
Where notification to a person, provider or competent authority is legally required or reasonably appropriate, ZHNI AGENCE will assess the information that should be communicated according to the circumstances.
Safe use of the service
Your Security Responsibilities
Customers also play an important role in protecting account, booking and payment information.
When using Mrhbazhni, you should:
- use a strong password that is not reused elsewhere;
- protect access to the email address connected with your account;
- sign out when using a shared or public device;
- avoid sending passwords or payment credentials by email;
- verify the website address before signing in or paying;
- avoid clicking unexpected payment or password-reset links;
- keep booking references private where appropriate;
- inform us promptly about suspicious account activity;
- verify unexpected changes to bank-payment instructions;
- keep your device, browser and security software updated.
ZHNI AGENCE will never need your PayPal password, card security code or online-banking password to provide customer support.
Do not complete an unexpected payment or disclose credentials. Contact Mrhbazhni using the contact details published directly on mrhbazhni.com.
Security Limitations
Although ZHNI AGENCE takes measures intended to protect personal information, no internet transmission, website, payment service, email system or storage environment can be guaranteed to be completely secure in every circumstance.
Customers should therefore avoid sending unnecessary sensitive information and should report suspected misuse as soon as possible.
Information, access and control
Your Rights Under Moroccan Law No. 09-08
Subject to the conditions and limitations of Moroccan Law No. 09-08, you may exercise rights concerning personal information processed by ZHNI AGENCE through Mrhbazhni.
These rights are intended to help you understand how information is used, obtain access to information concerning you, correct inaccurate records and object to certain processing where the legal conditions are met.
Know who processes your data, why and for which recipients.
Access information and request correction where appropriate.
Object to qualifying processing and direct marketing.
Article 5
Right to Information
When personal information is collected directly from you, you should receive clear information about the relevant processing.
Depending on the circumstances, this information may include:
- the identity of the data controller;
- the purposes for which the information is collected;
- the recipients or categories of recipients;
- whether a requested response is mandatory or optional;
- the possible consequences of not providing required information;
- the existence of rights of access and rectification;
- relevant information about international processing;
- the CNDP declaration or authorisation reference, once available.
This Privacy Policy provides general information about processing through Mrhbazhni. Additional information may also appear beside a form, account function, checkout or other collection point.
A form should explain its purpose and clearly distinguish required information from optional information.
Article 7
Right of Access
After establishing your identity, you may ask ZHNI AGENCE to confirm whether personal information concerning you is being processed through Mrhbazhni.
Where applicable, you may request information concerning:
- the purposes of the processing;
- the categories of personal information concerned;
- the recipients or categories of recipients;
- an intelligible communication of information concerning you;
- available information concerning the origin of the data;
- the logic underlying relevant automated processing;
- booking, order and account information linked to you;
- relevant contact, support or payment-reference records.
Access requests may be made at reasonable intervals and are handled without charge, subject to the conditions of applicable law.
A manifestly abusive request, including one that is excessive because of its repetitive nature, may be handled in accordance with the procedure permitted by Moroccan Law No. 09-08.
Information will not be disclosed until ZHNI AGENCE has taken reasonable steps to ensure that the requester is the person concerned or is properly authorised to act for that person.
Article 8
Updating, Correction, Erasure or Blocking
After establishing your identity, you may request the updating or correction of personal information that is inaccurate, incomplete, ambiguous or out of date.
Where processing does not comply with applicable law, the request may also concern the erasure or blocking of the relevant information, subject to the applicable legal conditions.
A request may concern, for example:
- an incorrect name, email address or telephone number;
- an inaccurate account or billing detail;
- incorrect participant information;
- an incorrect activity date or reservation record;
- duplicate personal information;
- information connected with the wrong customer;
- outdated contact or account information;
- data processed in a manner that does not comply with applicable law.
Where Article 8 applies, the necessary rectification must be completed without charge within the legally applicable period of ten clear days.
Where reasonably possible, relevant corrections, erasures or blocking actions are also communicated to third parties to whom the affected information was previously disclosed.
Information may still need to be retained where required for accounting, tax, payment, dispute, security or other applicable legal purposes.
Article 9
Right to Object
After establishing your identity, you may object on legitimate grounds to certain processing of personal information concerning you.
A request should explain:
- the processing activity to which you object;
- the information concerned;
- the legitimate grounds supporting the objection;
- the account, booking or communication involved;
- the outcome you are requesting;
- any information needed to locate the relevant record.
An objection does not necessarily require ZHNI AGENCE to stop processing that is required by law or necessary to maintain records that must legally be retained.
It may also be necessary to continue limited processing to manage an active booking, payment, refund, complaint, security incident or legal claim.
Each objection is reviewed according to the processing purpose, the grounds presented and the applicable legal obligations.
Articles 9 and 10
Direct Marketing Communications
You may object without charge to the use of your personal information for direct-marketing purposes.
Where prior consent is legally required for direct marketing by email or comparable electronic means, such communications should not be sent without the required consent or another condition expressly permitted by applicable law.
Any direct-marketing communication sent by Mrhbazhni must provide a clear and practical method for requesting that such communications stop.
Booking confirmations, payment information, account-security notices, activity reminders and support responses are sent to manage the requested service.
Promotional messages concern offers or services beyond the operational administration of the current booking.
An objection to marketing does not prevent necessary operational communications concerning an active account, payment, reservation or customer-support matter.
Article 11
Decisions Based on Automated Processing
Moroccan Law No. 09-08 provides protection against certain decisions producing legal effects where those decisions are based solely on automated processing intended to evaluate aspects of a person or define that person’s profile.
Mrhbazhni may use automated technical operations to:
- calculate a displayed tour price;
- apply a seasonal or group-pricing rule;
- check participant limits;
- create a provisional reservation reference;
- record a payment or order status;
- assign or propose an available guide;
- identify spam or security risk through reCAPTCHA;
- send operational booking notifications.
These technical operations are not intended to evaluate a customer’s personality or create a behavioural profile for making a decision with legal effects.
Where a qualifying automated decision is used, you may request information about the underlying logic and an opportunity to present relevant observations, subject to applicable law.
A customer may contact ZHNI AGENCE where an automated booking, payment, availability or security outcome appears incorrect.
External recourse
Complaint to the CNDP
You are encouraged to contact ZHNI AGENCE first so that we can identify the relevant information and attempt to resolve your request.
You may also submit a complaint to the Moroccan Commission Nationale de contrôle de la protection des Données à Caractère Personnel, commonly known as the CNDP, where you believe that your rights under Moroccan Law No. 09-08 have not been respected.
This may be relevant where, for example:
- an access request has been refused without an appropriate reason;
- inaccurate information has not been corrected;
- an objection has not been appropriately considered;
- personal information appears to have been used unlawfully;
- information has been disclosed without an appropriate purpose;
- a privacy request has received no appropriate response.
The CNDP is the Moroccan authority responsible for overseeing compliance with Law No. 09-08 and handling complaints within its legal powers.
Submit a request
How to Exercise Your Rights
Send your request to ZHNI AGENCE using the contact details below. Clearly identify the right you wish to exercise and provide enough information for us to locate the relevant account, booking, transaction or communication.
Where relevant, include your full name, account email, booking reference, the information concerned and the action requested. Please do not send passwords or full payment-card information.
Identity Verification and Authorised Representatives
ZHNI AGENCE may request information reasonably necessary to confirm your identity and protect personal information against unauthorised disclosure or modification.
Do not send a passport or national identity-card copy unless ZHNI AGENCE specifically determines that additional verification is necessary and provides an appropriate method for supplying it.
A person acting for another individual may be required to provide evidence of authority to submit and manage the request.
Legal and Operational Limitations
Privacy rights are subject to the conditions and exceptions of applicable law. A request may not require ZHNI AGENCE to delete accounting records, disrupt an active booking, conceal a payment dispute or destroy information needed to establish, exercise or defend legal rights.
Depending on your place of residence or the circumstances of the service, additional mandatory rights may also apply. This Policy does not limit rights that cannot lawfully be excluded.
Privacy assistance and transparency
Contact, Complaints and Policy Updates
ZHNI AGENCE is responsible for addressing questions and requests concerning personal information processed through Mrhbazhni.
We encourage you to contact us first where you have a question, correction request, objection, security concern or complaint. This allows us to identify the relevant account, booking, transaction or communication and review the matter directly.
Describe the request or concern and identify the relevant record.
We may verify that the request concerns you or an authorised person.
We examine the relevant processing, records and legal obligations.
We communicate the outcome or any information reasonably required.
Data controller
Contact ZHNI AGENCE
Questions concerning this Privacy Policy or the processing of personal information through Mrhbazhni should be addressed to ZHNI AGENCE.
Bureau 10, Résidence Oum El Qoura,
Kénitra, Morocco
Exercise of rights
Submitting a Privacy Request
To help us locate and assess the relevant information, a privacy request should clearly describe the right or action concerned.
Where applicable, please include:
- your full name;
- the email address associated with your account or booking;
- your booking or order reference;
- the information or processing concerned;
- the correction, access or other action requested;
- relevant dates or communication references;
- information explaining an objection or complaint;
- a safe method for us to contact you.
Internal review
Raising a Privacy Complaint
If you believe that personal information has been collected, used, disclosed, retained or secured inappropriately, you may submit a complaint to ZHNI AGENCE.
A complaint should, where possible, explain:
- what happened;
- when the event occurred or was discovered;
- which information appears to be affected;
- the account, booking or communication involved;
- any previous request made to Mrhbazhni;
- the response already received, where applicable;
- the outcome or corrective action you are seeking;
- any supporting information that is safe and relevant to provide.
ZHNI AGENCE may review relevant account, booking, email, transaction, access or technical records in order to understand and respond to the complaint.
Submitting a legitimate privacy request or complaint does not remove your contractual or legal rights and should not result in discriminatory treatment.
External complaint
Complaints to the CNDP
You may submit a complaint to the Moroccan Commission Nationale de contrôle de la protection des Données à Caractère Personnel, commonly known as the CNDP, where you believe that your rights under Moroccan Law No. 09-08 have not been respected.
Contacting ZHNI AGENCE first may allow the matter to be identified and resolved directly, but it does not remove your ability to contact the CNDP in accordance with applicable law.
The CNDP handles complaints and exercises its powers independently under the applicable Moroccan legal framework.
Policy maintenance
Changes to This Privacy Policy
ZHNI AGENCE may update this Privacy Policy to reflect changes in the Mrhbazhni services, booking processes, payment methods, providers, security measures, legal requirements or data-protection practices.
An update may be required, for example, where:
- a new booking or account function is introduced;
- a payment method or payment provider changes;
- the hosting provider or server location changes;
- a new external service processes personal information;
- cookie or security technologies change materially;
- retention periods or internal procedures are updated;
- applicable law or CNDP guidance changes;
- the business identity or contact information changes.
The updated version will be published on this page with a revised “Last updated” date. Where a change materially affects the way personal information is processed, an additional notice may be provided through the website, customer account, email or another appropriate channel.
Changes apply from the effective date stated in the updated version, unless a different date is expressly indicated.
Customers and visitors should review the current version when using the website or making a new booking.
Publication record
Effective Date and Version
This version describes the personal-data processing practices intended to apply to the current Mrhbazhni website, customer accounts, booking system, payment methods and customer-support activities.
The date above must match the “Last updated” date displayed in the Privacy Policy Hero. If the page is published later, both dates must be replaced with the actual publication date.
Privacy support
