How NAZRA collects, uses and protects the personal information of guests, property owners and the people we work with.
NAZRA Concierge is the trading name of Morocco Stay Services SAS, a company registered in Rabat, Morocco. We manage private residences and provide concierge services to the guests who stay in them.
We decide how and why the personal information described here is used, which makes us the data controller for it. If you want to reach us about anything in this notice, write to management@nazraconcierge.com.
We collect only what a stay actually requires.
| Information | Where it comes from |
|---|---|
| Name, contact number, email | You, or the platform you booked through |
| Booking details — dates, residence, number of guests | Airbnb, Booking.com, or direct with us |
| Passport or national identity document details for each guest | You, before or on arrival |
| Messages you send us, and our replies | WhatsApp, email, or the platform's message thread |
| Requests and preferences — arrival time, transport, dietary notes | You, during the stay |
| Vehicle registration, where parking is arranged | You |
We do not collect payment card numbers. Payments are handled by the booking platform or by our payment provider, and card details never reach us.
We do not sell personal information, and we do not share it with anyone for their own marketing.
Moroccan law requires every establishment offering accommodation to declare all guests to the competent authorities within 24 hours of arrival. This applies to every guest in the party, not only the person who made the booking. Children under 15 are recorded on the accompanying adult's form.
To do this we need each guest's identity document details. You can supply them through your arrival link or by sending us the passport photo page.
This is a legal obligation, not a choice we make. We cannot host a guest we are unable to declare, and we cannot release door access until registration is complete.
We use these details for the declaration and for nothing else. They are not used for marketing, not shared with property owners, and not passed to any other party.
Some routine messages — check-in times, the address, parking, what the kitchen has — are answered automatically, using answers we have written and approved in advance. This lets us reply quickly at any hour.
Anything beyond routine goes to a person before it reaches you. That includes prices, changes to your booking, complaints, anything about access or security, and anything we are not certain about.
If you ask whether you are speaking to a person, we tell you honestly. You can ask for a person at any point and one will take over.
No decision that affects you is made automatically. Automation drafts and answers; it does not decide whether you may stay, what you pay, or how a complaint is resolved.
Our guest records are held in a database hosted in the European Union (Frankfurt, Germany).
We use a small number of established service providers to run the business. Each holds only what it needs, and each is bound to use it solely to provide its service to us:
Some of these providers are based outside Morocco and the European Union, and your information may be processed in those countries under the safeguards their terms require. Where a booking is made through Airbnb or Booking.com, that platform handles your information under its own privacy policy as well as this one.
We run a written retention policy, and deletion is automatic rather than left to memory. Every period is counted from the date you leave, not the date you arrive.
| What | Kept for |
|---|---|
| Passport and identity document images | 90 days after departure, then deleted |
| Door codes and arrival-link keys | 30 days after departure |
| Contact details — phone, email, notes | 365 days after departure |
| The registration record itself — name, date of birth, nationality, document type and number | 5 years, as Moroccan law requires |
The distinction in that last line matters. Moroccan law obliges us to keep a register of arrivals for five years. It does not oblige us to keep a photograph of anyone's passport, so we don't — once the registration is filed and checked, the image is deleted on schedule and the record shows the date it went.
Every deletion is written to a log, so we can evidence that the policy ran.
You can ask us to:
Write to management@nazraconcierge.com and we will respond within one month. There is no charge.
Guests in Morocco may also complain to the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP). Guests in the European Union may complain to their national data protection authority.
One limit worth stating plainly: we cannot delete identity details we are legally required to hold for guest registration until that obligation has run its course.
Access to guest records is limited to the people who need it to do their work, and is removed when someone leaves. We protect the accounts that hold personal information with two-factor authentication wherever the provider supports it, and we are extending that to the remaining systems. Identity documents are handled only for the registration described in section 04, and are not circulated by message or stored on personal devices.
No system is beyond reach. If a breach ever affects your information in a way likely to put you at risk, we will tell you and the relevant authority without undue delay.
If we change how we handle personal information, we will update this notice and change the version and date at the top. Material changes will be communicated to guests with an active booking.