SAAS · STARTUPS · NUMBERIC PRODUCTS

Build the product.
Earn customer trust.

A startup can pass in a few months from a prototype without real data to a product used by several European customers. At this rate, the choices of architecture, analyticals, authentication, support, d

PRIVACY BY DESIGNDPASUBTRACTORSEU CLIENTS

Your activity,
its real flows.

Prospects then request a DPA, the list of processors, accommodation locations, security measures, durations, incident procedure and transfer mechanisms. Responding with generic documents weakens the sale if the answers do not correspond to the product.

RCM installs a proportionate base: product mapping, privacy by design, contracts, supplier register, rights procedure, documentary security file and responses to questionnaires. Code audits, penetration testing, certifications and general AI Act compliance remain the responsibility of the appropriate specialists.

Scoping starts with the facts: systems, teams, people involved, data, customers, suppliers and countries. The obligations are then qualified separately with regard to the GDPR and Moroccan law 09-08. This method avoids applying a generic response to processing activities that have neither the same purpose nor the same level of risk.

WHEN TO COME

Triggers
most common.

A mission may begin before a launch, during a negotiation or after a gap appears.

01

First European customer

DPA, safety questionnaire, SCC and proof requested during the sale.

02

New feature

AI, analytics, profiling, integration, data import or change of hosting.

03

Scaling up

Multiplication of accounts, support teams, suppliers and deployment regions.

FROM THE FIELD TO EVIDENCE

A journey
in four stages.

Decisions and limits are made visible at each stage.

01

Describe the product

Users, data, features, architecture, clients, teams and countries.

02

Qualify the roles

Controller, processor, sub-processors and own processing.

03

Build the base

DPA, notices, records, procedures, controls and transfer documentation.

04

Integrate into the product cycle

Launch questionnaire, change review and decision evidence.

SECTORAL RISKS

What the documents
Don't always show.

These situations are points of analysis, not automatic conclusions.

01

Roles combined

The SaaS can be a processor for customer data and responsible for its accounts or marketing.

02

Moving processors

Cloud, email, support, logs, analytics and AI are changing the channel and the countries.

03

Data in logs

Identifiers, queries, or content may persist outside of primary storage.

04

Incomplete deletion

Production, backups, support, exports and processors follow different cycles.

05

Commercial promises

Too absolute a response to the questionnaire may become an impossible commitment.

06

Integrated AI

Inputs, outputs, retention, reuse and suppliers require dedicated analysis.

OPERATIONAL CONTROLS

Measures that
teams can apply.

Each check must have a responsible person, frequency and proportionate proof.

01

Product card

Flows by feature, role, system, vendor, country and duration.

02

Pre-launch review

Privacy checklist in the product process with decisions and actions.

03

Processor register

Use, data, location, CCA, security and notification of changes.

04

Rights management

Search by tenant, identity, export, deletion, restriction and proof.

05

End of contract

Review meeting, deletion, backups, deadlines and confirmation to the customer.

06

Reliable business record

Responses, policies and evidence aligned with the product actually delivered.

DELIVERY

What RCM
Leave it to your teams.

The final scope depends on maturity, risks and elements already available.

01

Product mapping

Features, data, roles, systems, providers and transfers.

02

SaaS DPA

Annex article 28, instructions, assistance, security and processors.

03

Privacy pack

Notices, register, durations, rights, incidents and end of contract.

04

Vendor register

Cloud, support, email, logs, analytics, payment and AI.

05

Customer questionnaire

Library of validated evidence-based answers.

06

Product process

Screening, DPIA criteria, notification, corrections and launch validation.

TWO FRAMES

GDPR and law 09-08,
I didn't confuse them.

The same activity may fall within both frameworks for different reasons.

EU

GDPR

Roles, responsibilities, information, rights, security, subcontracting and transfers outside EEA.

MA

Law 09-08

Treatment in Morocco, rights, security and formalities of declaration or authorization.

International flows

Access, hosting, recipients, mechanism, context and additional measures.

Evidence

Contracts, registers, decisions, controls, training, incidents and actions followed.

INTERVENTION FORMATS

Start small.
Maintain if necessary.

The amounts are confirmed after scoping; no fictitious pricing is published.

DIAGNOSIS

Starting point

Targeted interviews, review of available elements, major risks and sectoral roadmap.

Fixed price · after scoping
TARGETED MISSION

Priority base

Agreed deliverables, corrections, review meeting and operational transfer to internal managers.

From — on estimate
ACCOMPANYING

Continuous management

Volume, deadlines, meetings, controls, new projects and contract overruns.

Subscription · on quote
RESPONSIBILITIES AND LIMITS

Advise, structure
and advance.

RCM provides GDPR advice, law 09-08 and operational assistance. The client organization retains its decisions, responsibilities, budgets, validations and technical actions. No mission guarantees absolute compliance, absence of sanction or a favorable decision from an authority.

  • Penetration tests, forensic investigations and certifications are carried out by competent experts.
  • Reserved legal consultations and litigation are directed to a lawyer.
  • Sectoral regulations excluding data protection remain outside the scope unless expressly stated.
FREQUENTLY ASKED QUESTIONS

Specific responses.
Contextualized decisions.

These answers present general principles. Processing, roles, countries and contracts should be reviewed before any conclusion.

Should a Moroccan SaaS apply GDPR to sell in Europe?

The scope of application depends in particular on the establishment, the activities and the people concerned. Regardless of this analysis, a European client will often impose contractual obligations on its processor. RCM separately qualifies legal obligations, customer requirements and transfers related to access from Morocco.

Are we responsible for processing or subcontracting? +

A SaaS can combine several roles depending on the purpose. It often acts on instructions for data imported by the customer, while determining its own uses for account management, security, billing or marketing. Mapping must distinguish these operations rather than choose a single role for the entire enterprise.

Can we use a DPA template found online? +

A model can serve as a starting point but must correspond to the actual service, data, processors, transfers, measures, deadlines and assistance capabilities. A clause promising immediate deletion or unlimited audit becomes problematic if the product cannot execute it.

How to answer security questionnaires without ISO certification? +

Answer with precision and evidence: controls present, responsible, frequency, perimeter and correction plans. Do not present partial alignment as certification. RCM structure the privacy and documentary response; the technical or ISO assessments are entrusted to the competent professionals.

Does AI API integration require DPIA? +

An initial evaluation should examine data, purposes, people, decisions, scope, suppliers, reuse and consequences. An DPIA may become necessary when treatment is likely to create a high risk. RCM covers data protection, not general compliance with IA Regulation.

What happens when a customer cancels? +

The contract and product must define export, review meeting, deletion, backups, deadlines and justified exceptions. Support accounts, local copies and processors must be included. Proof of closure protects both the customer and the supplier.

Your sector deserves A concrete scoping.

Present your tools, data, customers, suppliers, countries and deadlines. RCM will indicate the first useful perimeter.

Scoping the mission →
Talk to a DPO