Retour Hahoowa

Document légal

Politique de confidentialité

Privacy Policy

Last updated: August 28, 2026 · Version 2.0 (replaces the version of July 29, 2026) Effective: immediately. Earlier versions are available on request at privacy@hahoowa.app.

Summary (level 1)

  • Who processes your data? Hahoowa Medias Services SARL AU (Casablanca, Morocco) and Hahoowa Medias Services LLC (Wyoming, USA), jointly.
  • Where is it? In the European Union (AWS, Paris region). We keep no copy of it outside the EU.
  • Do we sell it? No. Never.
  • Advertising? Contextual by default. No personalized advertising without your consent, and never any personalized advertising for minors.
  • Do we read your private messages? No — we do not analyze the text of your messages. Only shared images and voice messages are checked against prohibited content.
  • Your rights? Access, rectification, erasure, objection, portability — exercisable in one place: privacy@hahoowa.app or Settings → "Export my data" / "Delete my account".
  • A question? privacy@hahoowa.app · Data Protection Officer: dpo@hahoowa.app.

The full details follow (level 2).


1. Who is responsible for your data

Joint controllers:

  • Hahoowa Medias Services SARL AU — 7, rue Ahmed Touki, Casablanca, Morocco. Operator of the platform. The applicable formalities with the CNDP (Law 09-08) are the responsibility of the operator; references available at privacy@hahoowa.app.
  • Hahoowa Medias Services LLC — 30 N Gould St, Ste R, Sheridan, WY 82801, USA. Contracting entity for paid services.

Both entities jointly determine the purposes and means of the processing described here. A joint-controllership agreement (Art. 26 GDPR) allocates their obligations; you may exercise your rights with either of them, indifferently, via privacy@hahoowa.app.

Representative in the European Union (Art. 27 GDPR): designation in progress — in the meantime, privacy@hahoowa.app is your point of contact and that of the EU authorities; the representative's contact details will be published here as soon as they are designated.

Data Protection Officer (DPO): dpo@hahoowa.app.

Listings between users. When you publish a listing, it may contain personal data (yours, sometimes third parties'). In line with European case law (CJEU, Russmedia, C-492/23, December 2, 2025), we act as joint controller for this data: our prior moderation detects manifestly problematic content, and we offer a fast erasure channel (privacy@hahoowa.app, subject line "Data in a listing"). You remain responsible for what you choose to publish: do not disclose other people's data without a legal basis.

2. What we collect, why, on what basis, and for how long

We process only what the Service needs. The table below cross-references, by purpose: the categories of data, the legal basis (GDPR Art. 6; Moroccan Law 09-08), the retention period, and the recipients (detailed in Section 4).

Purpose Data Legal basis Retention Recipients
Your account email, display name, password hash, phone (optional), language, currency Performance of the contract Life of the account; profile anonymized upon deletion AWS, Cognito
Your publications listings (title, description, photos, price, city), Spots/Drops/posts, profile and cover photos, AI briefs and videos, presenter/voice choices Performance of the contract Removed from public surfaces upon account deletion; otherwise at most 24 months after a listing is archived AWS, Gemini (moderation), AI providers (if you generate)
Messaging messages between users (in-app, WhatsApp bridge where applicable), timestamps, attachments Performance of the contract At most 36 months after the last message; your sent messages emptied upon your deletion AWS, Meta (WhatsApp, if used)
Brand voice (optional) reference voice sample and derived voice model Explicit consent (biometric data) Until you disable the voice or delete the account AWS, WaveSpeed/fal (synthesis)
Payments Stripe customer ID, last 4 digits of card, billing email Performance of the contract + legal obligation (accounting) Billing records: 10 years (law) Stripe
Creator earnings balance, earnings, bank details (last 4 digits of IBAN only) Performance of the contract Life of the account + accounting obligations Stripe, AWS
Professional seller file (KYBC) company or business name, address, city, business phone and email, registration type and number (RC/ICE/auto-entrepreneur/cooperative), time-stamped self-certification Legal obligation (DSA Art. 30; Law 31-08) Life of the account; deleted with it; included in your export AWS; public display (see the box below)
Security, anti-fraud, moderation reports, decisions, moderation logs, IP address, risk signals Legitimate interest (documented balancing test); legal obligation for orders Moderation logs: 5 years AWS, Gemini
Technical operation & reliability device model, OS, app version, language, push token, IP address, crash and performance logs Legitimate interest Device and usage logs: 13 months AWS, Sentry, Expo
Location (city, country) declared city, country estimated from the IP address Performance of the contract (listing relevance) / legitimate interest Life of the account AWS, MaxMind (geo-IP)
Notifications & service emails push token, email address, content of transactional notifications Performance of the contract Life of the account Expo, AWS SES
Marketing emails, logged-out personalization depending on the channel Consent (withdrawable at any time) Until withdrawal; 13 months max for the personalization identifier AWS SES, AWS

Professional seller file: public display. DSA Art. 30(2) requires us to display professional sellers' information on the platform. Once your file is approved, the following fields are public, on each of your listings and on your storefront: company name, address, city, business phone and email, registration type and number, self-certification date. The form informs you of this before submission. Use business contact details — that is what they are for. Any change to the file suspends the display until re-validation; deleting the account deletes the file.

We do not collect full card numbers, full IBANs, or sensitive data (health, religion, opinions, orientation) — unless you voluntarily publish them yourself, in which case you are responsible for it. The periods above are maxima that we commit to respecting: when they expire, the data is deleted or irreversibly anonymized.

3. Deleting your account

When you delete your account (Settings → Account → Delete my account), deletion takes effect immediately:

  1. Active systems: your profile is anonymized; your listings, Spots, Drops, posts and comments are removed from public surfaces; your sent messages are emptied of their content; your social graph (follows, blocks, favorites, reactions), your professional seller file, your notification tokens and your personal telemetry are physically deleted; your media files are erased from our servers; your authentication account is deleted.
  2. Backups: technical backup copies permanently expire within 90 days at most.

The right to erasure is offered to all users, not only in the EU. The following survive deletion, in a limited and justified way: financial records (credits, earnings — accounting obligation, GDPR Art. 17(3)); moderation logs (5 years — establishment and defense of legal claims); the order and listing records necessary for the integrity of other users' transactions and for disputes, with your profile anonymized in them. On request, we provide you with a time-stamped proof of erasure. Merchant accounts: deletion is deferred as long as orders, disputes, earnings or paying subscribers remain open (see the Terms of Service, Art. 12.4) — your obligations towards buyers come first.

4. Who we share with — our processors and joint controllers

We do not sell your data and share it only with the providers necessary for the Service, all bound by contract (Art. 28 GDPR). The up-to-date list is maintained in this policy:

Recipient What it receives Why Where Transfer safeguard
Amazon Web Services all platform data (database, media, cache) Hosting (RDS, S3, CloudFront, ElastiCache) EU (Paris, eu-west-3) Storage in the EU; admin access from Morocco safeguarded (Section 5)
Stripe billing email, payment identifiers Payments; joint controller for payment data EU / USA 2021 SCCs
Google (Gemini) published content (text, images, videos, audio, streams) Automated moderation and writing assistance USA 2021 SCCs
Higgsfield brief, product photo, presenter choice AI video generation USA 2021 SCCs
WaveSpeed / fal script, and voice sample if brand voice is enabled Speech synthesis and rendering USA / other 2021 SCCs
Mux live video streams Live broadcasting and replays USA / EU 2021 SCCs
Meta (WhatsApp Business) phone number and message content, only if you use the WhatsApp bridge Order confirmations you request USA / EU 2021 SCCs
Expo push notification token, notification content Push notification delivery USA 2021 SCCs
Amazon SES email address, content of service emails and (with consent) marketing emails Sending emails EU / USA 2021 SCCs
Sentry crash and performance logs, technical identifiers Incident detection and resolution EU / USA 2021 SCCs
MaxMind IP address (for country estimation) Approximate location USA 2021 SCCs
Authorities what is legally required Court decision, audit, DSA/e-Evidence notification Legal basis

A provider removed from the product no longer receives any data (HeyGen, removed in July 2026, is one example).

5. Where your data resides, and international transfers

Storage. Database, media and caches are hosted with AWS in the European Union (Paris). We keep no second copy of this database outside the EU.

Two flows leave the EU, both safeguarded:

  1. Administration from Morocco. The platform is operated from Casablanca; its operator administers the systems from there. Morocco does not benefit from an EU adequacy decision → this flow is covered by the Commission's Standard Contractual Clauses (2021 version), supplemented by a transfer impact assessment (encryption at rest and in transit, least-privilege access).
  2. Processors. Those in Section 4 located outside the EU receive only the data described, under the 2021 SCCs.

Morocco → abroad direction. Moroccan Law 09-08 subjects transfers of data out of Morocco to prior authorization by the CNDP; the corresponding formalities are the responsibility of the operator. You can obtain a copy of the applicable safeguards at privacy@hahoowa.app.

6. Automated analysis of content (moderation) and of messages

Public content. Every piece of content you publish — including your display name, your bio, your profile and cover photos, and your storefront images — is automatically analyzed (by Google Gemini and our systems) to detect what is prohibited (see the Community Guidelines). This analysis rests on our legitimate interest in offering a safe and lawful service. No decision producing significant legal effects is taken in a fully automated way without the possibility of human recourse: sensitive cases (defamation, impersonation, dangerous false information, political advertising) are always decided by a human, and you can challenge any decision (Terms of Service, Art. 9; DSA Arts. 20-22; GDPR Art. 22).

Private messages. We do not analyze the text of your private messages, and we never use them for advertising or profiling purposes. Images and voice messages shared in private messages are automatically checked against the prohibited categories (protection of users and minors, legitimate interest); only the verdict is kept in the moderation logs.

7. Recommender systems

The "For You" feed, search and suggestions are ranked by automated systems whose main parameters are described in the Terms of Service (Art. 7). You can influence this ranking and disable personalization when logged out (see Section 9, hahoowa_did identifier). We never base a recommendation on sensitive data.

8. Advertising

By default, advertising is contextual (tied to the content displayed, the language, the country). Any personalized advertising would require your consent, withdrawable at any time. We practice no targeting based on the profiling of sensitive data, and no personalized advertising for minor users (DSA Arts. 26(3) and 28(2)). Every ad is labeled "Sponsored". Paid political advertising is prohibited (Terms of Service, Art. 6.2).

9. Cookies and storage on your device (web)

Hahoowa loads no third-party tracker: no advertising pixel, no audience-analytics suite, no session recorder. What we store:

What Purpose Consent
Session and security cookies keep you signed in, protect forms Strictly necessary — none required
NEXT_LOCALE remember your language Strictly necessary — none required
hahoowa_did first-party identifier personalizing your feed when logged out Consent — requested on your 1st visit
hahoowa_consent_v1 remember your answer above Strictly necessary — none required

We ask for your consent before creating the personalization identifier. "Decline" is as simple and visible as "Accept" (no dark patterns). If you decline, the identifier is not created — and any existing identifier is deleted. The question is asked again at least every 13 months. You can change your choice at any time via the "Cookies" link in the footer.

10. Your rights

You may at any time: access your data, rectify it, erase it (subject to the legal retentions of Section 3), object to a processing operation (e.g. marketing), restrict its processing, exercise portability (machine-readable export — Settings → "Export my data"), and withdraw any consent.

These rights are open to you whether you are in the EU (GDPR), in Morocco (Law 09-08), in California (CCPA) or elsewhere. Contact: privacy@hahoowa.app from your account's address, or directly in the Settings. We respond within 30 days (rectifications within 10 business days for Moroccan residents, in line with CNDP practice). A penalized account keeps access to its rights: the "Account Status" page, export and deletion remain accessible.

You can lodge a complaint with your authority: CNDP (Morocco), CNIL (France) or the authority of your Member State, your State Attorney General (USA), etc.

11. Minors

The Service is reserved for people 18 or over (see the Terms of Service, Art. 4). We do not knowingly collect the data of minors; if we discover the account of a person under the required age, we delete it. No personalized advertising is served — to anyone (advertising is contextual, § 8).

12. Provenance of AI-generated content

The videos and images produced by Hahoowa's AI studios carry a visible "AI-generated" label and are recorded in an internal provenance registry that allows them to be identified on all the surfaces where they circulate — this is our implementation of synthetic-content transparency (AI Act, Art. 50). This marking is not personal data about you; it identifies the synthetic origin of the content.

13. Security

TLS encryption in transit; encryption at rest for databases and media (AWS); passwords stored only as hashes; least-privilege role-based access control; logging of sensitive administrative actions. No system is perfectly secure: use a strong, unique password, and notify us at privacy@hahoowa.app of any suspected incident.

14. Changes

Substantial changes are notified in the app and by email at least 30 days before they take effect. Earlier versions are available on request at privacy@hahoowa.app.

15. Contact

  • Data protection: privacy@hahoowa.app
  • Data Protection Officer (DPO): dpo@hahoowa.app
  • EU representative (Art. 27 GDPR): designation in progress — interim contact privacy@hahoowa.app
  • Supervisory authorities: CNDP (Morocco), CNIL (France) or your national authority
  • Postal address: see Art. 20 of the Terms of Service