Privacy policy
Last updated: 23 September 2026
This policy explains what personal data Aithenor collects through www.aithenor.com, why, and what rights you have. It applies Moroccan Law 09-08 on the protection of personal data and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The data controller is Aithenor SAS, Casablanca, Morocco. For any data-protection question, contact us through our contact form and mention “personal data” in your message.
2. What we collect
When you request a demo or apply as a founding hotel
First name, last name, professional email, role, hotel name, city, country, number of rooms and hotel category, plus the date of your request and which button you used. Fields marked * are required; without them we cannot answer your request.
When you browse the Site
Our host records standard technical data (IP address, browser type, pages requested, date and time) to deliver and secure the Site. Your cookie choice is stored on your device (see our Cookie policy).
We do not collect sensitive data, and the Site is not intended for children.
3. Why we use it
| Purpose | Legal basis |
|---|---|
| Answering your demo or founding-hotel request and organising the demonstration | Your request (steps taken before a contract) and your consent |
| Following up with you about Aithenor as a hotel professional | Our legitimate interest in B2B prospecting — you can object at any time |
| Operating and securing the Site | Our legitimate interest |
We do not sell your data, and we do not use it for advertising.
4. Who receives it
Only the Aithenor team. We use two service providers that process data on our behalf and under our instructions:
- Supabase — database, hosted in the European Union (Paris, France).
- Vercel — website hosting (United States; global delivery network).
We may also disclose data where required by law.
5. Transfers outside Morocco
Form data is stored in the European Union. Technical data handled by our host may be processed in the United States, under contractual safeguards (EU Standard Contractual Clauses). Transfers of personal data outside Morocco are made in accordance with Law 09-08; the related CNDP formalities are in progress.
6. How long we keep it
- Demo and founding-hotel requests: 3 years from our last contact with you, unless you become a customer (then for the duration of the relationship) or ask us to delete them earlier.
- Technical logs: according to our host’s standard retention, typically a few days to a few weeks.
- Your cookie choice: 6 months.
7. Security
Data is encrypted in transit and at rest. Access to form submissions is restricted to the Aithenor team; the public website can submit a request but cannot read stored requests.
8. Your rights
Under Law 09-08 you have the right to access, rectify and object to the processing of your data, including for prospecting. Where the GDPR applies, you also have the right to erasure, restriction, portability and to withdraw your consent at any time.
To exercise these rights, contact us through our contact form. We reply within one month. You may also lodge a complaint with the CNDP (cndp.ma) in Morocco or, if you are in the EU, with your national data-protection authority.
9. CNDP
The declaration of this processing to the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) is in progress; its reference will be published on this page.
10. Hotel data inside the Aithenor platform
This policy covers the website only. Data that hotels load into the Aithenor platform is governed by the customer agreement. That data is kept separate for each hotel, is never pooled with or used for other hotels, and the AI providers we use are not allowed to train on it.
11. Changes
We may update this policy. The version in force is published on this page with its date of last update.