Privacy policy
In short: this site uses no advertising tracker and no third-party audience measurement. We process your data to answer you in writing or on the phone, to serve you if you become a client, to run our clients' assistants, and to improve our assistants from de-identified conversations that no longer allow anyone to recognise you. Call audio is never recorded: only a written transcript is kept. A WhatsApp conversation only ever improves the assistant of the business it belongs to. At any time you can ask to access, correct or delete your data, or object to any contact: a simple "stop" is enough.
1. Who we are
The nolloi.com site and the Nolloi services are provided by Nolloe LLC ("Nolloe", "we"), a Wyoming (United States) limited liability company, filing number 2026-001869334, with its registered office at 30 N Gould St Ste R, Sheridan, WY 82801, USA. Nolloi is the public brand under which Nolloe provides its services. Nolloe is the controller in the situations described below, except when it acts as a processor for its clients (section 8). Under article 2 of Moroccan law 09-08, Nolloe has designated to the CNDP a representative established in Morocco, reachable at the same address. For any question about your data: contact@nolloi.com.
2. What this policy covers
It covers five situations, in which our role differs:
- your visit to nolloi.com (we are the controller);
- your written exchanges with us, on WhatsApp or by email (controller);
- your calls with us, on WhatsApp or on an ordinary phone line, whether you call us or we call your business (controller);
- our file of businesses we approach and our business clients (controller);
- conversations between our clients and their own customers, which the assistant handles on their behalf (we are then a processor, see section 8).
3. On this site
- No advertising cookie, no third-party audience measurement, no advertising tracker, no session recording. The site loads no script from another site.
- Like any site, our server receives technical connection data (IP address, browser, page requested, time). It is used only for security and proper operation, never to follow you.
- Your browser keeps on your device, without sending them to us, your light or dark theme choice and, for the life of the tab, the campaign code in the link that brought you (for example NL-XXXXXX). This code identifies a page or a campaign, never a person; it is only sent if you send it yourself in your WhatsApp message.
- The mirror: the business name and city you type are sent to our server and then to Google Maps Platform to find the business's public information. We do not keep them and we create no file in your name unless you write to us.
- If you fill in one of our advertising contact forms on Facebook or Instagram, we receive what you enter, and we tell Meta that a request was received using a scrambled fingerprint (hash) of your email address or number, never in clear.
4. When you write to us
If you write to us on WhatsApp or by email, we process your number or address, your profile name, your messages and voice notes (transcribed into text so we can answer), and the campaign code of your first message. Purposes: answering you, presenting our offer and, if you wish, preparing your contract; once de-identified, these exchanges also help improve our assistants (section 9). Basis: your request and the pre-contractual steps it calls for, and our legitimate interest in following up a request and improving the service. We never contact you on WhatsApp unless you wrote to us or agreed, and a "stop" ends all contact at once, on every channel.
5. Phone calls
- Our calls, incoming and outgoing, on WhatsApp or on an ordinary phone line, are handled by our advisor, an artificial intelligence assistant. It never pretends to be human: if you ask, it says so.
- The call audio is processed live, only to understand and answer you. It is not recorded or kept anywhere.
- A written transcript of the conversation is kept with your number for follow-up (an agreed callback, sending a document, preparing a contract). It stays linked to you until you ask for deletion or until the retention period ends (section 12); once de-identified, it may help improve our assistants (section 9).
- When we call a business, we call its business number and say on whose behalf we are calling. At any time you can tell the assistant that you no longer wish to be contacted: this applies to all our channels.
- Basis: your calls and requests (pre-contractual steps); for the calls we make to businesses, our legitimate interest in presenting our service to professionals, with your right to object at any time.
6. Our file of businesses
To make Nolloi known, we keep a file of businesses established in Morocco, built from public sources (public maps and directories, business websites): business name, activity, city, published business contact details. It concerns businesses, not private individuals. Basis: our legitimate interest in presenting our service to professionals. You can object at any time, free of charge and without giving a reason, to being in this file or being contacted: write "stop" on WhatsApp or to contact@nolloi.com, or say so during a call, and the objection applies to all our channels.
7. Our clients
For our business clients, we process the data needed for the contract, invoicing, payment by bank transfer and support: identity and role of the signatory, business, contact details, contractual and accounting documents. The contract is signed electronically: the signing platform keeps the signatory's name, role, email or number and a signing log (dates, times, IP addresses, document fingerprint). We never ask for a copy of an identity document. Basis: performance of the contract and our legal obligations.
8. Our clients' customers
When a client's assistant answers that client's own customers, the business client is the controller: it decides what the assistant does and says.
- Roles: the business client is the controller of its customers' data. Nolloe is the processor that handles them only on the client's documented instructions, to run the service sold under the Nolloi brand.
- We use these data to perform the service and, once de-identified, to improve it within the limits of section 9: a client's WhatsApp conversations only improve that same client's assistant. The client remains the owner of its data; they are returned on request in a standard format.
- When the contract ends, they remain readable for 60 days, then identifiable data are deleted within 30 days, unless the law requires us to keep them.
- Health data: in Morocco, a practice or clinic must obtain the CNDP's prior authorisation before going live; the contract provides that the service is activated only with this proof.
- If you are the customer of a business that uses Nolloi, send your requests to that business; we help it answer.
9. Artificial intelligence and service improvement
- Our assistants' written and spoken answers are generated by artificial intelligence models from specialised providers (see section 10).
- An assistant never pretends to be human: if asked, it says so.
- To improve our assistants, we keep conversations as de-identified text: names, phone numbers, email addresses, identifiers (national ID, ICE, RIB, IBAN or others), business names, addresses, cities, dates and links are removed before anything is stored. A passage is kept only if two separate checks confirm it no longer contains anything that could identify someone; when in doubt, it is discarded. This de-identified text is kept without time limit. Basis: our legitimate interest in improving the service.
- The technical link between this text and the original conversation is deleted at the latest 180 days after the person's last message, or as soon as they ask for deletion. A deletion request erases the data about you; the de-identified text, which no longer points to you, is kept.
- WhatsApp conversations: under Meta's WhatsApp Business terms, they only improve the assistant of the business they belong to. Exchanges with Nolloi only improve Nolloi's assistants; exchanges between a client and its own customers only improve that client's assistant. They are never pooled across clients and never used to train our providers' models.
- Conversations from other channels (ordinary phone calls, email, the site), once de-identified, may improve the service as a whole.
- We never send conversations to a provider so that it can train its models. With every AI provider that offers it, we refuse the retention of our exchanges for the provider's own use and their use for training; a provider may still keep technical logs for a limited time under its own terms (for example for security).
- A generated answer can contain a mistake: our clients approve what their assistant may say, and important decisions remain human.
10. Providers
We never sell or rent any data. We use the following providers, each only for what its task requires:
- Supabase, Inc.: the service database, hosted by Amazon Web Services in the Ohio region (United States).
- HostPapa: our server, located in Buffalo (New York State, United States). It hosts the site, the application, our electronic signature tool (DocuSeal) and our WhatsApp gateway (Evolution API), two pieces of software we run ourselves.
- Amazon Web Services: encrypted database backups, stored in Paris (France).
- OpenAI (United States): live understanding and spoken answers during calls, voice note transcription, written answers.
- OpenRouter, Inc. (United States): routing of written requests to the models of Inception Labs and Typesafe, with data collection refused.
- Meta Platforms (WhatsApp Business): delivery of WhatsApp messages and calls.
- Titan: hosting of our contact@nolloi.com mailbox.
- Google (United States): fallback email sending (Gmail), Google Maps Platform for the mirror and businesses' public information, and Google Calendar when a client connects it.
- DIDLogic: phone carrier, only when a call goes through an ordinary phone line (the number and the call audio pass through its network, without being recorded by us).
- Our bank: receiving transfers.
Any change to this list that concerns a client's data is notified to that client in advance, as its contract provides.
11. Transfers outside Morocco
- Where your data are: the database and our server are in the United States; the encrypted backups are in France. Nolloe LLC itself is established in the United States.
- France is on the CNDP's list of countries that ensure a sufficient level of protection (deliberation 236-2015); the United States is not.
- The transfer to the United States therefore relies on article 44 of law 09-08: your express consent where you gave it; its necessity to perform the contract concluded with you or the pre-contractual steps taken at your request, such as a quote (article 44, 1°, d and e); and, for our file of businesses we approach, the CNDP authorisation under article 44, 3°, requested by Nolloe LLC.
- We give each provider only what its task requires, and each is bound by its own contractual data protection and security commitments.
12. How long we keep data
- Call audio: never recorded or kept.
- Written exchanges and call transcripts linked to a person who is not a client: until they ask for deletion or object, and at most 3 years after the last contact, then deleted or de-identified. An objection is kept, so that we can respect it.
- File of businesses: at most 3 years after the last contact, and never after an objection (only the record of the objection is kept).
- Data of clients and of our clients' customers: for the contract, then 60 days of read-only access after it ends, then deletion within 30 days.
- De-identified conversation text: without time limit, with no link to a person (section 9).
- Backups: an encrypted copy of the database is made every day and stored in France (Amazon Web Services, Paris region). Only we can access it, it is used only to restore the service after an incident, and each copy is erased after 14 days.
- Proof that the service was performed (receipts and time-stamped technical logs, without conversation content): 5 years after the contract ends.
- Contractual and accounting documents: 10 years.
13. Security
Exchanges with the site and the service are encrypted (HTTPS), and database backups are encrypted. Access to the client and owner areas requires authentication, and access to data is limited to the people and systems that need it. No measure is infallible: in case of a data breach likely to put your rights at risk, we inform the people concerned and the competent authorities (in Morocco, the CNDP), as the law requires.
14. Your rights
Wherever you are, you can ask to access, correct or delete your data and object to any contact, including prospecting, free of charge and at any time. An objection always wins.
- How: on WhatsApp ("stop" is enough to object), by telling the assistant during a call, by email to contact@nolloi.com, or by registered letter to Nolloe LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.
- Timelines: your data within 20 working days at most; correction and deletion within 7 working days.
- We may ask you to confirm your identity, only to protect your data.
- In Morocco: law 09-08 gives you rights to information, access (article 7), correction (article 8) and objection (article 9), and a right to deletion when the data are no longer needed, and you can complain to the Commission nationale de contrôle de la protection des données à caractère personnel (CNDP), www.cndp.ma.
15. Children
Our services are for businesses. They are not intended for children.
16. Changes
We update this policy when our processing changes. The date at the top shows the latest version. This policy exists in French, Arabic and English; the French version prevails.
17. Contact
Controller: Nolloe LLC, which operates the Nolloi brand, 30 N Gould St Ste R, Sheridan, WY 82801, USA. Email: contact@nolloi.com. Full legal information is in our legal notice (in French).