Privacy policy
Last updated: 13 September 2026
1. Who processes your data
Catalogue DZ is published by AGYN TECH SARL, a limited liability company with a share capital of DZD 1,000,000, 12 rue Didouche Mourad, 16000 Algiers, Algeria, Trade register 16/00-1092847 B 24 · Tax ID 002416109284712. Contact: contact@dz-catalogue.com.
Two roles coexist. For our merchant customers' own data (account, subscription) we are the controller. For the end-customer data a merchant collects through its catalogue — reservations — the merchant is the controller and we act as its processor, on its instructions alone.
This document covers Regulation (EU) 2016/679 (GDPR) for visitors and customers in the European Union, and Algerian law no. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data.
2. What we process
Merchant account: name, e-mail, password (hashed, never readable), organisation name, and the identity Google passes us if you sign in with Google.
Sign-in log: date, IP address and browser for each sign-in and failed attempt. This is a security measure against account takeover.
Venue: name, address, city, phone, e-mail, map coordinates, and the photos and catalogues you publish.
Reservations (your customers' data): name, phone, optional e-mail, date, time, party size and any notes.
Payments: amount, date, method, reference, period covered. We never see or store a card number — entry happens at Stripe or Chargily.
Messaging: the content of your exchanges with our team and any attachments.
Menu visitors: an anonymous identifier is created only if you favourite a product or tap Like. Reading a catalogue creates none. A visit counter is recorded with no identifier.
3. Why, and on what basis
Providing the service (building your catalogue, publishing it, receiving your reservations) — performance of the contract.
Billing, collection, accounting and the referral programme — performance of the contract and legal obligation.
Securing the platform: sign-in log, attempt limits, abuse detection — legitimate interest.
Writing to you about your licence, its expiry or an incident — performance of the contract.
Visitor favourites and likes — your explicit request, at the moment you tap.
We use no data for advertising and sell none.
4. For how long
Account and shops: as long as the account exists.
Reservations and end-customer contact details: twenty-four months, then automatic deletion.
Sign-in log: twelve months. E-mail delivery log: twelve months.
Password reset tokens: thirty days. Visit counters: twenty-four months.
Accounting records (payments, commissions): kept for the period required by applicable accounting and tax law, even after the account is deleted, in a form that no longer identifies anyone.
These periods are applied automatically by a task running on the server, not merely written here.
5. Who else has access
We share data only with the providers the service needs, each for the stated purpose alone:
Stripe (card payment outside Algeria) — Stripe Payments Europe, Ireland. Card details are entered with them, never with us.
Chargily (EDAHABIA / CIB card payment in Algeria) — a provider established in Algeria.
Google — Google Maps if you open the map, Google Fonts for display, and Google Calendar if you choose to connect your calendar.
Our hosting provider and our transactional e-mail provider.
None of this data is sold, rented or handed to a third party for commercial purposes.
6. Where your data lives
The platform's servers are located in the European Union.
Some of the providers above may process data outside the country where the person concerned lives. Those transfers rely on the European Commission's standard contractual clauses or an equivalent mechanism.
For people located in Algeria, transfer outside the national territory is governed by law 18-07; we will tell you on request which providers are involved for your account.
7. Your rights
You may at any time access your data, correct it, ask for its erasure, restrict or object to its processing, and receive a usable copy.
Two of these work straight from your dashboard, without writing to us: “Export my data” downloads everything we hold as JSON, and “Delete my account” erases the account, the shops, the catalogues and every reservation.
For anything else, write to contact@dz-catalogue.com; we answer within one month.
If one of your merchant's customers sends you a request about their reservation, you answer it: you are its controller, and the export above gives you the content.
You may lodge a complaint with the competent authority: in Algeria the Autorité nationale de protection des données à caractère personnel (ANPDP); in the European Union, your country's supervisory authority (in France, the CNIL).
8. Cookies and trackers
Strictly necessary, set without consent because the service cannot work without them: your sign-in session, the chosen language, the billing country, and a short-lived anti-fraud token during a Google sign-in.
At your request: the anonymous identifier behind favourites and likes, created at the moment you tap one, and never before.
Subject to your consent: the Google map, which sends your IP address to Google. Until you accept, the map does not load and the rest of the site works normally.
We use no advertising cookies and no third-party analytics.
9. Security
End-to-end HTTPS, passwords hashed with bcrypt, calendar tokens encrypted at rest, tenant isolation verified automatically on every release so one merchant can never reach another's data, a sign-in log and attempt limiting.
No system is infallible. In the event of a breach likely to create a risk to your rights, we will inform you and the competent authority within the periods the regulation sets.
10. Changes
Any substantial change to this policy is announced by e-mail at least thirty days before it takes effect.