Privacy policy
Last updated: August 2026
At React Box we take the protection of your personal data very seriously. This policy explains what data we collect, on what basis, how we use it, where it is hosted, and what your rights are under Moroccan Law 09-08 on the protection of personal data.
Data controller and DPO
The data controller is React Consulting SARL AU, ICE 003399449000060, with registered office at Boulevard My Hassan 1er, Imm Siam Block A, 3rd floor N°10, Marrakech, Morocco. You can contact our Data Protection Officer (DPO) at dpo@react-box.com.
Our role: data controller and processor
React Box acts in two distinct capacities. (1) Data controller for the data needed to operate the service: user accounts, organisations, security logs, notifications, usage statistics. (2) Data processor under article 21 of Law 09-08 for the documents you upload: those documents remain under your responsibility or that of your accounting firm. We host them in strictly private access and do not consult their content. The one exception, triggered by you: when you request a scan (OCR) or share a document with the Atlas assistant, that file is sent to our artificial intelligence subprocessor to extract its data, and the result is returned to you for review. No automatic analysis takes place on documents you have not submitted to those features.
Data we collect
We collect the information you provide when you sign up (first name, last name, email address, profile picture), the information about your organisation (legal name, ICE, IF, RC, TP, address, logo), the documents you upload to your vault (the content remains private and is analysed only for the documents you submit to scanning or to the Atlas assistant), and activity logs (actions performed in the application, IP address, user agent).
Purposes and legal bases
Your data is used to provide the service (performance of the contract), to ensure security and traceability (legal obligation and legitimate interest), to send you transactional notifications by email and push (performance of the contract), and to improve the product through audience measurement (consent). Audience measurement is operated by PostHog: it records the pages you visit, your interactions with the interface, the errors you run into and — on signed-in surfaces only (dashboard, account, authentication) — a recording of your browsing session. These processing activities are enabled only after your consent, collected in the cookie banner on the web and in the app settings on mobile, and can be withdrawn at any time.
Hosting and transfers
Our primary servers are located in the European Union (Frankfurt, Germany) — Neon database (eu-central-1, AWS), application and realtime on Cloudflare Workers, files on Cloudflare R2 (EU jurisdiction), email through Cloudflare Email Sending. Artificial intelligence processing (scanning, the Atlas assistant and the web searches triggered from Atlas) is operated by Mistral AI, a French company, on infrastructure located in the European Union. Audience measurement is hosted on PostHog’s European infrastructure. Three processing activities do, however, leave the European Union. (1) Push notifications for the mobile app travel through Expo’s delivery service (650 Industries, Inc., United States) and then through the Apple (APNs) and Google (FCM) gateways: your device token together with the title and body of the notification are transmitted to them — and that body may contain the name of the person behind an action, the name of their organisation and the title of a document or a conversation. This is the most sensitive transfer and it is structural: Expo is the mandatory relay to the Apple and Google gateways. (2) If you choose to sign in with Google, Apple or Microsoft, those companies (United States) receive the sign-in request and return your identity to us (email address, name, profile picture). (3) Cloudflare, Inc. and Neon Inc. are companies incorporated in the United States and may as such receive access requests from their own authorities, even though the data itself stays hosted in the European Union. These transfers are framed by the European Commission’s standard contractual clauses and by each subprocessor’s confidentiality commitments. You are informed of these transfers when you sign up and when you create your organisation; you can avoid the push-notification transfer by turning push notifications off in the app settings, and the social sign-in transfer by creating your account with an email address and a password.
Technical subprocessors
We rely on the following subprocessors, all contractually committed to GDPR and Law 09-08 compliance. (1) Cloudflare, Inc. — US company, hosting in the European Union: running the application and realtime channels (Workers, Durable Objects), storing vault files (R2, EU jurisdiction), sending transactional email (Email Sending) and bot verification on public forms (Turnstile). Receives all service data, including the content of the files you upload. (2) Neon Inc. — US company, database hosted in Frankfurt (eu-central-1, AWS): accounts, organisations, document metadata, logs. Does not receive file content. (3) Mistral AI SAS — France, European Union: document scanning (OCR), the Atlas assistant and the assistant’s web search, run by its own built-in engine. Only receives the files, messages and search queries you explicitly submit to those features; that content is not used to train any model, and search conversations are not retained on its side. (4) PostHog — audience measurement and session recording on the vendor’s European infrastructure, only after your consent: pages visited, interactions, errors, account and organisation identifiers. Does not receive the content of your files. (5) 650 Industries, Inc. (Expo) — United States: delivery of push notifications to your mobile device. Receives your device token together with the title and body of the notification. (6) Apple Inc. and Google LLC — United States: push delivery gateways (APNs and FCM), recipients of the same items. (7) Google LLC, Apple Inc. and Microsoft Corporation — United States: social sign-in, only if you choose that authentication method. They receive the sign-in request and return your identity to us (email address, name, profile picture). Email-and-password authentication is handled in-house by React Box, with no third-party subprocessor. This list is kept up to date; any change is published on this page.
Retention
Account data is retained as long as your account is active, then deleted within 30 days after closure. The documents you upload are retained under your responsibility — you decide when to delete them. Security audit logs are kept for 5 years, activity logs for 2 years, read notifications for 6 months. Data exports are kept for 30 days.
Your rights
Under Law 09-08 you have the right to access, rectify, object, delete, restrict and port your personal data. To exercise these rights, write to dpo@react-box.com or use our online form available from the footer ("Exercise my rights"). For the data contained in your documents, your direct counterpart is your accounting firm or your business (data controller). You also have the right to file a complaint with the CNDP (www.cndp.ma).
Cookies
Our site uses cookies that are essential to operation (session, language, consent preferences) and, subject to your explicit consent, audience measurement cookies. You can adjust your preferences at any time via the "Cookie preferences" link in the footer. See our cookie policy for details.
Security
We implement appropriate technical and organisational measures: end-to-end TLS encryption, AES-256 encryption at rest on Cloudflare R2, access control with two-factor authentication (2FA) available, short-lived signed URLs (5 minutes for downloads, 15 minutes for uploads), logging of the actions performed on your documents, and least-privilege principle — our operational teams never access the content of your documents.
Programmatic access: API keys, OAuth and the MCP server
An organisation can open its data to applications and automated agents in two ways: by creating an API key from its settings, or by authorising a third-party application through the OAuth flow, which grants access to our MCP server. Both mechanisms are restricted to organisation administrators. A key or an authorisation can only cover the data of the organisation that issued it, within a fixed allow-list of operations, and its use is logged like that of a user. An agent authorised this way can read the organisation’s management data and its vault metadata. A key can be revoked at any time from the organisation settings; an authorisation granted to a third-party application is withdrawn the same way. It is up to the organisation issuing the key to satisfy itself that the recipient is trustworthy.
Sharing a document through a public link
A user with the necessary rights can create a public link pointing to a document in their vault, in order to pass it on to a recipient who has no React Box account. Until it expires or is revoked, that link makes the document accessible to anyone holding it: it is a disclosure of data decided by the organisation, under its sole responsibility. Each link can carry an expiry date and a password, and the public page requires a bot check. For every opening we retain the date, an irreversible fingerprint of the IP address, the country and the visitor’s user agent, so that the organisation can trace accesses and detect unwanted sharing. A link can be revoked at any time, with immediate effect.
CNDP reference
The processing described in this policy has been declared to the National Commission for the Protection of Personal Data (CNDP). The receipt number will be published here as soon as we receive it.