Privacy Policy

Last updated: April 28, 2026

This Privacy Policy explains how personal data is collected, used, and protected when you visit www.mementomorocco.com and use our travel planning and booking services.

This policy complies with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the UK Data Protection Act 2018.

1. Controller Information

The controller responsible for data processing on this website is:

Memento Universe Ltd
27 Old Gloucester Street, London, WC1N 3AX
United Kingdom
Company registered in England and Wales
Email: contact@mementomorocco.com
Director: Mr. Badr-Eddine Rachadi

2. Hosting and Infrastructure

This website is hosted on dedicated servers provided by Hetzner Online GmbH. Data is stored exclusively on servers located in Finland (European Union).

This ensures an adequate level of data protection in accordance with EU and UK data protection laws. Hetzner implements appropriate technical and organisational security measures.

We have concluded a Data Processing Agreement (DPA) with Hetzner in accordance with Article 28 UK GDPR / EU GDPR.

3. Content Management and Tools

WordPress

This website uses WordPress as a content management system. Personal data is processed only to the extent necessary to ensure website functionality and security.

Elementor Pro & Crocoblock

We use Elementor Pro and Crocoblock for website design and functionality. These tools are configured to operate without transmitting personal data to third parties.

4. Bookings & Payment Processing

We use WooCommerce and JetBooking to manage bookings and process payments on this website.

When you make a booking, the following personal data is collected and hosted on our servers:

  • Name, location and contact details
  • Billing information

Legal basis: Article 6(1)(b) UK GDPR / EU GDPR (performance of a contract).

Payment Processors

Payments are securely processed through third-party providers:

  • PayPal
  • Stripe

We do not store or have access to your full payment details (such as credit card numbers). These are processed directly by the payment providers.

PayPal and Stripe may process your data in accordance with their own privacy policies and may transfer data outside the UK or European Economic Area (EEA). Appropriate safeguards, such as Standard Contractual Clauses (SCCs), are used to protect your data.

We have concluded Data Processing Agreements (DPAs) with both PayPal and Stripe.

5. Transactional Email Service (Brevo)

We use Brevo (formerly Sendinblue), provided by Brevo SAS, 55 rue d’Amsterdam, 75008 Paris, France, to send transactional emails such as booking confirmations and contact responses.

Brevo acts as a data processor under a Data Processing Agreement in accordance with Article 28 UK GDPR / EU GDPR.

Data processed may include:

  • Name and email address
  • Technical delivery data (e.g. timestamp, delivery status)

Emails are saved as logs for a duration of 1 month and are deleted after 1 month.

Brevo processes data primarily within the European Union. Where data transfers occur outside the EU, appropriate safeguards such as SCCs are applied.

6. Contact & Booking Forms

When you submit a contact form on our website:

  • Your data is transmitted securely via email
  • Your data is securely stored in the website database for as long as necessary to process your requests

Legal basis: Article 6(1)(b) UK GDPR / EU GDPR (pre-contractual communication).

Retention for non-booking inquiries
If your inquiry does not result in a booking or ongoing client relationship, your personal data will be deleted no later than one year after the last communication, unless a longer retention period is required by law.

7. ALTCHA Spam Protection

We use ALTCHA, a self-hosted, open-source spam protection service, to protect our website from automated submissions and spam. ALTCHA operates entirely on our own servers and does not send any personal data to third parties.

ALTCHA works by generating a cryptographic challenge in your browser, which your device solves locally using a proof-of-work algorithm. This process:

  • Does not use cookies or any form of browser fingerprinting
  • Does not track your browsing activity
  • Does not collect or store any personal information
  • Does not share any data with external services

The verification happens in real time and no data is retained on our servers after verification is complete. The cryptographic challenge expires automatically after one hour.

ALTCHA is fully compliant with GDPR, WCAG 2.2 AA accessibility standards, and the European Accessibility Act (EAA). For more information, visit altcha.org.

Cloudflare (Security and Performance Optimisation)

We use the services of Cloudflare Inc. (USA) and Cloudflare Germany GmbH to protect our website against DDoS attacks, bot attacks, and other forms of abuse. Cloudflare acts as our data processor. A Data Processing Agreement (DPA) has been concluded in accordance with Article 28 UK GDPR / EU GDPR.

As part of these security functions, Cloudflare processes the following data:

  • IP addresses (anonymised)
  • HTTP headers (User-Agent, Referrer, etc.)
  • Request timestamps
  • Browser and device information

The processing is based on our legitimate interest in the security and operational reliability of our website (Article 6(1)(f) UK GDPR / EU GDPR). No data is shared with third parties for their own purposes.

Cloudflare stores security‑related log data typically between 7 and 30 days. Data is compared with other Cloudflare services only for security purposes.

International data transfers: Cloudflare is a US‑based company. Data transfers to the USA are based on the EU-U.S. Data Privacy Framework (DPF), for which Cloudflare is certified (DPF certificate). In addition, the EU Standard Contractual Clauses (SCCs) apply.

Further information: Cloudflare Privacy Policy.

8. Sharing Data with Third Parties (Travel Service Providers)

To deliver your travel services, we may share your personal data with trusted third-party partners, including:

  • Hotels, riads, and desert camps
  • Transport providers and drivers
  • Local guides and activity providers
  • Restaurants and service partners

This data is shared solely for the purpose of fulfilling your booking and delivering the agreed services.

Legal basis: Article 6(1)(b) UK GDPR / EU GDPR (performance of a contract).

International transfers to Morocco

Where your booking requires services to be provided in Morocco, your data may be transferred to partners located in Morocco. Morocco is not the subject of an adequacy decision by the EU or UK.

Such transfers are made on the basis of Article 49(1)(b) GDPR (transfer necessary for the performance of a contract between you and us, or for pre-contractual measures taken at your request).

We ensure that appropriate safeguards (such as confidentiality agreements) are in place with our local partners.

9. Cookies and Consent Management

We use cookies to ensure proper website functionality and, where applicable, to analyse website usage.

Cookie consent is managed through Complianz.

  • Essential cookies are active by default. These are processed on the basis of our legitimate interest in providing a functional and secure website (Article 6(1)(f) UK GDPR / EU GDPR).
  • Analytics cookies are only activated with your explicit consent (Article 6(1)(a) UK GDPR / EU GDPR).

You may withdraw or modify your consent at any time via our cookie banner.

10. Google Analytics

This website uses Google Analytics, provided by Google Ireland Ltd.

  • IP anonymisation is enabled
  • Data is used only for internal analysis
  • Tracking is activated only after user consent (Article 6(1)(a))

Google may transfer data to the United States. Such transfers are protected using:

  • Standard Contractual Clauses (SCCs)
  • Google is also certified under the EU-U.S. Data Privacy Framework (DPF)

We have concluded a Data Processing Agreement with Google for Google Analytics.

11. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy.

Type of dataRetention period
Booking-related dataUp to 10 years to comply with legal and tax obligations (e.g. invoices, contracts)
Contact form submissions (no booking)1 year after last communication
Email correspondenceManually deleted – no fixed retention but subject to your right to erasure
Transactional email logs (Brevo)1 month

12. Security Measures

We implement appropriate technical and organisational measures, including:

  • SSL/TLS encryption
  • Firewall protection
  • Secure authentication systems
  • Regular backups

13. Your Rights

Under UK GDPR and EU GDPR, you have the following rights:

RightDescription
Access (Art. 15)Obtain confirmation whether your data is processed and request a copy
Rectification (Art. 16)Correct inaccurate or incomplete data
Erasure (Art. 17)Request deletion of your data (“right to be forgotten”)
Restriction (Art. 18)Limit processing in certain circumstances
Data portability (Art. 20)Receive your data in a structured, machine-readable format
Object (Art. 21)Object to processing based on legitimate interests
Withdraw consent (Art. 7)Withdraw any consent you have given at any time

To exercise any of these rights, please contact us at contact@mementomorocco.com.

You also have the right to lodge a complaint with a supervisory authority, in particular:

  • In the UK: Information Commissioner’s Office (ICO)https://ico.org.uk
  • In the EU: The supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.

14. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or significant effects concerning you.

15. International Data Transfers – General Statement

Where personal data is transferred outside the UK or European Economic Area (EEA) to a country that has not received an adequacy decision, we rely on one or more of the following safeguards:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission
  • The EU-U.S. Data Privacy Framework (for certified US recipients)
  • Derogations for specific situations, such as the performance of a contract with you (Art. 49)

16. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. The “Last updated” date at the top of this page indicates when the latest changes were made. Continued use of the website after changes are posted constitutes acceptance of the revised policy.

17. Contact

If you have any questions or wish to exercise your rights, please contact:

Memento Universe Ltd
Email: contact@mementomorocco.com

© 2026 Memento Universe Ltd — Data protection compliant with UK & EU GDPR

Your Trip, You Take The Lead!

40% of the global bookings we receive are tailor made by our beloved travelers. People more often prefer to take full advantage of this opportunity and have full control over their trips. We are so happy to support your future memorable trip and make it a lifetime experience for you!

Your Trip, You Take The Lead!

40% of the global bookings we receive are tailor made by our beloved travelers. People more often prefer to take full advantage of this opportunity and have full control over their trips. We are so happy to support your future memorable trip and make it a lifetime experience for you!

Personal Information
First Name*
Last Name*
Email*
Phone
Nationality
correspondence country
Trip Preferences
From*
To*
Adults*
Children
Infant
Desired Itinerary