Skip to content
Relentia

Privacy.

What this site collects, why, and for how long. It is a short list, and all of it is checkable against the site itself.

Status of this page

Last updated

This is a draft. It describes accurately what this website does with the information it receives, written from the application itself rather than from a template, but it has not been reviewed by counsel and it is not the binding notice.

Two questions in it are legal rather than factual and are marked where they arise: the basis for processing data outside the reader's own jurisdiction, and the procedure for acting on a rights request. The binding text will replace this page in full.

Who is responsible

The controller is Relentia S.A.R.L. (Associé Unique), registered at Rue Ouded Aliane N°7, Résidence Zahra, Étage 2, N°10, Tangier, Morocco. The registration is public and can be read at charika.ma.

There is no published contact address for privacy requests yet. Until there is, the partner application form is the route, and a person reads every submission. A dedicated address is to be supplied.

What the form collects

The partner application form asks for six things: your company, your name, a work email address, which side of the market you are on, what you would pay on, and a description of what you run. Only the last of those is free text of any length; what you would pay on is optional.

Each submission is also given a reference, so a reply can refer to an application without quoting a database identifier back at you.

The form carries two fields that are never stored: a decoy input that a person cannot see and a timestamp of when the page was opened. Both exist to tell an automated submission from a typed one, and neither is read for any other purpose.

What is recorded alongside it

Three things are recorded with a submission that you do not type: the network address it was sent from, the browser identification string your browser supplies, and the page you arrived from if your browser sent one.

The address is kept because it is the only thing that makes a flood of submissions attributable after the fact, and because the form's rate limit counts against it - five submissions an hour from one address. The other two are context for whoever reads the application.

These are deleted with the application they belong to, on the schedule below.

Cookies

Two, both strictly necessary, and neither used to identify you across sites.

A session cookie so the server can recognise the same browser between the page loading and the form being submitted. It is marked http-only, so page scripts cannot read it, restricted to same-site navigation, and it expires after two hours.

A cross-site request forgery token, which is what lets the server tell your submission apart from one another site tried to make on your behalf.

There is no consent banner because there is nothing here to consent to. Neither cookie is optional to the site working, and there is no third category.

What this site does not do

There is no analytics of any kind, no advertising pixel, no session recording, no A/B testing tool and no third-party tracking.

No request leaves your browser to another company while you read this site. The typefaces, the stylesheet and the one script are all served from this domain rather than from a font service or a content network, so there is no third party in a position to observe your visit even incidentally.

Nothing collected here is sold, rented, or used to build a profile. The only reason any of it is held is to answer a partnership application.

Who else sees an application

When an application arrives, an email notification is sent to Relentia's own inbox so that a person knows to read it. That message carries the application's contents, and it travels through whichever mail provider Relentia operates - that provider is a processor and is to be named here once confirmed.

The application itself is stored on Relentia's own systems and read by the people who decide whether a partnership is a fit.

The operational log deliberately records less than the application does: a reference, which side of the market the applicant is on, and the domain part of the email address. Never the message, and never the full address. Logs are the one place this kind of data leaks into backups and error tools that nobody scoped for it.

How long it is kept

An application and everything recorded with it are deleted 730 days after it is submitted. A scheduled sweep runs daily and removes anything past that point.

The period is a setting rather than a sentence in a policy, so the software and this page cannot disagree about it.

Where it is processed

Relentia is a Moroccan company and the operation is run from Tangier. An application sent from the United States or the European Union is therefore processed outside the country it was sent from, and that is stated here rather than left to be inferred from the address at the foot of the page.

The lawful basis for that transfer, and the safeguards attached to it, are a legal question rather than a factual one. They are to be settled by counsel and stated here.

Your rights

Subject to the law that applies to you, you can ask what is held about you, ask for it to be corrected, ask for it to be deleted, object to it being held, or ask for a copy of it.

The deletion case is the simplest one here: an application can be removed on request, and everything recorded with it goes at the same time.

The formal procedure and the response times attached to it are pending counsel, along with the contact address noted above. In the meantime a request made through the application form will reach a person.

Changes to this notice

The date at the top of this page is when its content last changed, and it is read from the page itself rather than typed, so it cannot be left behind by an edit.

When the reviewed notice is published it will replace this draft in full.