Privacy Policy and Legal Protection Notice of MYCDIC
This policy is written to protect individuals who interact with MYCDIC and to protect MYCDIC by clearly defining how information is handled, what users should not submit, which responsibilities apply to the website, forms, services, applications, external service providers, institutional identity, logo use, non-affiliation, representation authority, and misuse prevention.
1. Scope of this Policy
This Privacy Policy applies to the official website of MYCDIC, including pages, forms, communication channels, membership requests, representation applications, event registrations, partnership requests, president office requests, contact forms, donation forms, media submissions, document requests, newsletters, and any other digital service operated under the MYCDIC name.
This policy also applies when you communicate with MYCDIC by email, social media, event participation, official forms, or other channels connected to MYCDIC activities.
2. Data Controller and Institutional Identity
For the purposes of this policy, the data controller is the Moroccan Youth Council for Diplomatic and International Cooperation, also referred to as “MYCDIC”, “the Council”, “we”, “our”, or “us”.
- Legal organization name: Moroccan Youth Council for Diplomatic and International Cooperation.
- Official acronym: MYCDIC.
- Legal form: International non-profit organization registered as an association in Spain.
- Spanish registration identifier: G75872663.
- Official headquarters: Madrid, Spain.
- Official website: www.mycdic.org.
- Main contact: contact@mycdic.org.
- Privacy contact: privacy@mycdic.org.
- General Secretariat: sg@mycdic.org.
MYCDIC may operate from, cooperate with, or receive data from persons located in multiple countries, including Spain, Morocco, the European Union, and other jurisdictions where MYCDIC activities, partners, representatives, or users are located.
3. Institutional Status, Non-Affiliation, and NGO Independence
MYCDIC is an international non-governmental youth organization registered in Spain and operating through its approved institutional structure. Unless expressly stated in a written agreement signed by the competent MYCDIC body, MYCDIC is not an agency, department, embassy, consulate, ministry, public authority, political party, commercial company, official delegation, royal office, state institution, or official organ of the Kingdom of Morocco or of any other government, state, international organization, university, municipality, association, private entity, or diplomatic mission.
- References to diplomacy, international cooperation, Moroccan youth, public engagement, or international representation describe MYCDIC's mission and activities only. They do not grant governmental, diplomatic, consular, immigration, military, security, public authority, or official state powers.
- No MYCDIC page, publication, event, partnership, representation, certificate, badge, card, email, domain name, logo, or institutional material may be interpreted as granting diplomatic status, official government appointment, royal mandate, public office, visa facilitation, immigration advantage, immunity, preferential administrative treatment, or legal authority to represent the Kingdom of Morocco or any public institution.
- Cooperation, attendance, sponsorship, media coverage, public appearance, correspondence, meeting, photo, or event participation with any third party does not automatically create endorsement, legal affiliation, agency, delegation, joint responsibility, or authority to represent that third party.
- MYCDIC remains responsible only for official statements and decisions issued through its authorized channels, competent internal bodies, and duly appointed representatives acting within their written mandate.
- Any person, page, group, office, representation, partner, member, volunteer, or third party that presents MYCDIC as a governmental body, diplomatic mission, public authority, royal institution, or legally mandated state representative without written authorization acts outside MYCDIC authority.
4. Official Identity, Name, Logo, Emblem, and Brand Assets
The MYCDIC name, acronym, logo, circular emblem, Arabic, Amazigh, and English wording, visual identity, colors, seal-style design, website domain names, email addresses, templates, certificates, cards, badges, documents, publications, photos, videos, designs, graphics, texts, slogans, and institutional materials are protected institutional assets of MYCDIC, whether registered or unregistered. They may also be protected by trademark, copyright, design, unfair competition, passing-off, identity protection, reputation protection, or other applicable laws.
The MYCDIC logo contains elements of Moroccan identity, national colors, cultural symbolism, and a heraldic motif used as part of MYCDIC's own institutional visual identity on the international level. The presence of these elements does not mean that MYCDIC is a governmental body, royal office, public authority, embassy, consulate, ministry, or official state delegation, and it must not be used to suggest such status.
- MYCDIC claims rights over the original composition, arrangement, wording, layout, visual identity, and institutional use of its logo and brand assets. MYCDIC does not claim ownership over official state symbols that legally belong to the Kingdom of Morocco or any competent public authority.
- No person may copy, reproduce, modify, crop, recolor, edit, redesign, imitate, publish, sell, register, upload, distribute, print, stamp, animate, or use the MYCDIC logo, name, acronym, emblem, visual identity, website content, certificates, official documents, or institutional materials without prior written authorization from MYCDIC.
- No person may create social media pages, websites, domain names, email addresses, WhatsApp groups, Telegram channels, forms, stamps, badges, cards, certificates, fundraising campaigns, partnership letters, invitations, event materials, uniforms, banners, or public announcements that suggest official MYCDIC status without written authorization.
- Authorization to use the MYCDIC logo or identity, when granted, is limited, revocable, non-transferable, non-exclusive, and restricted to the exact purpose, duration, format, territory, event, platform, and context approved by MYCDIC.
- The logo must not be used for personal promotion, political campaigning, commercial advertising, unauthorized fundraising, visa or immigration claims, misleading representation, fake certificates, unofficial appointments, hostile internal campaigns, or any activity that may confuse the public, harm MYCDIC's reputation, or expose MYCDIC to legal risk.
- MYCDIC may request immediate removal, correction, deletion, public clarification, account closure, domain transfer, preservation of evidence, compensation, disciplinary measures, or legal action in cases of unauthorized, misleading, defamatory, harmful, or confusing use.
5. Authority to Represent MYCDIC
Only persons expressly appointed or authorized in writing by the competent MYCDIC body may speak, sign, negotiate, publish official statements, collect funds, request documents, open or manage representations, conclude partnerships, issue certificates, organize activities, operate official pages, use official email addresses, or act on behalf of MYCDIC.
- Membership, volunteering, event participation, previous cooperation, social media activity, internal discussion, friendship with officers, possession of logo files, or past access to documents does not grant authority to represent, bind, commit, restructure, or speak for MYCDIC.
- Presidents of representations, coordinators, volunteers, members, committees, advisors, offices, or project teams may act only within the limits of their written appointment, mandate, internal regulations, approved communication channels, and applicable law.
- Any agreement, promise, public statement, donation request, official letter, certificate, appointment, partnership, media declaration, or representation made without proper authority may be treated as unauthorized, non-binding, and contrary to MYCDIC rules.
- Third parties should verify suspicious communications by contacting MYCDIC through the official website or official email addresses before relying on any representation, donation request, invitation, certificate, partnership claim, appointment, or document.
- MYCDIC may revoke access, titles, email accounts, certificates, documents, digital assets, social media permissions, representation status, or internal responsibilities where misuse, conflict, breach of mandate, reputational harm, governance risk, illegality, or security concern is identified.
6. Prohibited Misuse, Defamation, Disruption, and Reporting
To protect MYCDIC, its members, officers, partners, visitors, donors, applicants, representatives, and the public, the following conduct is strictly prohibited on or in connection with MYCDIC services, name, identity, logo, documents, events, communications, representations, offices, social media channels, and public activities:
- Impersonating MYCDIC, a MYCDIC officer, a representation, a partner, a donor, a public authority, or another individual or organization.
- Using MYCDIC's name, logo, certificates, documents, emails, titles, cards, seals, or visual identity to obtain money, favors, access, visas, employment, invitations, partnerships, official treatment, media exposure, or any advantage through misleading or unauthorized means.
- Publishing or spreading false, defamatory, insulting, threatening, misleading, malicious, fabricated, manipulated, or reputation-damaging statements about MYCDIC, its officers, members, representations, partners, donors, activities, or official decisions.
- Creating confusion about MYCDIC's leadership, legal status, representation structure, internal decisions, appointments, removals, partnerships, documents, or official positions.
- Attempting to create parallel offices, unauthorized representations, hostile internal campaigns, false committees, fake appointments, unauthorized elections, unofficial restructuring, or any action intended to destabilize, capture, replace, obstruct, or damage MYCDIC governance or official activities.
- Submitting forged, altered, false, stolen, confidential, defamatory, discriminatory, threatening, illegal, or misleading content, documents, identity information, payment information, media, or applications.
- Opening unauthorized social media accounts, websites, domains, groups, fundraising pages, events, forms, email addresses, public campaigns, or public statements using MYCDIC's identity or implying MYCDIC authorization.
- Damaging MYCDIC systems, uploading malware, scraping data, bypassing security controls, abusing forms, harassing staff, misusing personal data, leaking confidential information, or attempting unauthorized access.
MYCDIC may preserve relevant logs, emails, messages, submissions, screenshots, metadata, transaction references, documents, recordings, public posts, domain records, and communications as evidence for security review, internal disciplinary measures, account or domain reports, takedown requests, public clarification, civil claims, criminal complaints, or referral to lawyers and competent authorities where appropriate.
7. Personal Data We May Collect
Depending on how you interact with MYCDIC, we may collect the following categories of personal data:
- Identity data: name, surname, title, date of birth where necessary, nationality, country, organization, role, and affiliation.
- Contact data: email address, phone number, postal address, city, country, and preferred language.
- Request data: subject, message, request type, attachments, proposal details, partnership information, support request details, and internal reference number.
- Application data: membership application details, representation application details, motivation letter, CV, academic or professional background, references, country or directorate preferences, eligibility information, and supporting documents where required.
- Participation data: program participation, event registration, attendance, role, representation, volunteer information, and certificates.
- Donation and payment-related data: donor name, contact information, donation amount, purpose, transaction reference, payment status, and payment provider confirmation. MYCDIC does not intentionally collect or store full card numbers.
- Media data: photos, videos, audio, testimonials, interviews, consent records, event images, and public contribution materials when applicable.
- Technical data: IP address, browser type, device type, operating system, page URL, user agent, time of submission, cookies, logs, and security-related metadata.
- Communication data: emails, responses, notes, follow-up history, and administrative correspondence.
- Institutional assistant conversation data: questions, responses, suggested pages, language, session reference, and any name, email address, phone number, or other information voluntarily included in the conversation.
8. Applications to Join MYCDIC, Membership, and Representations
MYCDIC may receive applications from individuals seeking to join the Council, participate in programs, volunteer, represent MYCDIC, join national or international structures, or apply for a role within a directorate, representation, committee, office, student network, project team, or related institutional body.
Application data is used to assess eligibility, suitability, profile alignment, communication ability, institutional discipline, program fit, and the capacity of the applicant to represent MYCDIC responsibly.
- Submitting an application does not create a right to membership, appointment, representation, certificate, office, title, or official role.
- MYCDIC may accept, reject, postpone, archive, or request clarification regarding any application at its discretion and according to internal rules.
- Applicants must provide accurate information and must not misrepresent qualifications, affiliations, identity, experience, or authorization to act on behalf of another institution.
- MYCDIC may verify information provided in an application where necessary and lawful, including by requesting additional documents or references.
- MYCDIC may keep application records for administrative, verification, archive, legal, and future opportunity purposes, unless deletion is required or appropriate.
- Any misuse of the MYCDIC name, logo, email, title, representation, certificate, institutional identity, documents, payment channels, or public status may lead to rejection, suspension, removal, revocation of authorization, public clarification, legal action, or reporting to competent authorities.
9. How We Use Personal Data
MYCDIC may use personal data for the following purposes:
- To respond to contact requests, official messages, president office submissions, partnership proposals, support requests, and general inquiries.
- To evaluate applications for membership, representation, volunteering, projects, programs, offices, directorates, student networks, and institutional roles.
- To manage memberships, applications, volunteers, representations, programs, training, certificates, and event participation.
- To organize events, meetings, forums, activities, delegations, media coverage, and institutional communications.
- To review partnership, sponsorship, cooperation, and institutional support proposals.
- To process donations, issue acknowledgements, keep accounting records, and contact donors where necessary.
- To publish news, press releases, event summaries, photos, videos, articles, and public institutional communications where lawful and appropriate.
- To maintain security, prevent spam, detect abuse, protect systems, and preserve website integrity.
- To comply with legal, tax, accounting, reporting, regulatory, and administrative obligations.
- To enforce MYCDIC policies, protect MYCDIC’s rights, resolve disputes, investigate misconduct, and respond to lawful requests.
10. Legal Bases for Processing
Where applicable, MYCDIC may rely on one or more of the following legal bases:
| Legal Basis | Examples |
|---|---|
| Consent | Newsletter subscriptions, optional media permission, voluntary submissions, application consent, or consent checkboxes on forms. |
| Pre-contractual or contractual necessity | Processing partnership proposals, membership applications, representation requests, event participation, training registration, or support arrangements. |
| Legitimate interests | Responding to inquiries, assessing applications, improving services, preventing fraud, securing the website, protecting MYCDIC’s rights, and maintaining records. |
| Legal obligation | Accounting, donation records, compliance, lawful requests, tax requirements, or regulatory obligations. |
| Public or institutional interest where applicable | Institutional communication, public diplomacy activities, event documentation, and public benefit initiatives, subject to applicable law. |
11. Website Forms and Digital Submission Systems
MYCDIC website forms may collect information through authorized digital submission systems used by the Council for receiving, recording, reviewing, and routing official requests.
Form submissions may include contact forms, partnership requests, president office messages, membership applications, representation applications, event registrations, support requests, and document requests. A request ID may be generated to help MYCDIC track and manage the submission internally.
- Form data may be stored in authorized internal records or administrative systems.
- Conversations with the MYCDIC Institutional Assistant may be recorded to provide responses, preserve the conversation record, improve service quality, maintain security, and support appropriate institutional follow-up.
- Authorized MYCDIC personnel may access submissions for review, routing, reply, follow-up, or archiving.
- Anti-spam controls, timestamps, user agents, and page URLs may be used to reduce spam and abuse.
- Attachments may be reviewed for security and relevance. MYCDIC may reject, delete, or ignore unsafe or irrelevant files.
12. Donations, Payments, and Financial Information
MYCDIC may collect limited donor and payment-related information such as full name, email, phone number, donation amount, donation purpose, transaction reference, and payment status.
Payments are processed by authorized third-party payment providers. MYCDIC does not intentionally store full payment card numbers, CVV codes, payment passwords, or online banking credentials.
- Donation records may be retained for accounting, transparency, legal, administrative, and follow-up purposes.
- Donor information may be used to send confirmations, acknowledgements, or necessary follow-up messages.
- Do not send card numbers, passwords, bank credentials, or confidential payment details by email, contact form, or message.
13. Events, Photos, Videos, Testimonials, and Public Content
MYCDIC may document events, meetings, forums, training activities, partnerships, and public programs through photos, videos, audio recordings, articles, press releases, social media posts, and website news.
- When you participate in a public or official MYCDIC event, you may appear in general event photos or videos.
- For interviews, testimonials, individual portraits, or promotional materials, MYCDIC will seek appropriate permission where required.
- Publicly submitted materials may be edited for clarity, length, tone, accuracy, or institutional standards.
- MYCDIC may refuse to publish, edit, archive, restrict, correct, or remove content that is inaccurate, unlawful, harmful, abusive, misleading, politically inappropriate, defamatory, discriminatory, threatening, privacy-invasive, reputationally harmful, or contrary to MYCDIC values and institutional interests.
14. Cookies, Analytics, Logs, and Similar Technologies
The MYCDIC website may use cookies, server logs, analytics functions, embedded content, social media links, fonts, icons, security controls, and similar technologies to improve performance, maintain security, understand usage, and provide website functionality.
- Essential cookies: used for website functionality, security, forms, sessions, and navigation.
- Analytics or performance cookies: used to understand how visitors interact with the website, where enabled.
- Third-party cookies: may be set by external services used for payments, maps, videos, social platforms, fonts, icons, security, or website functionality.
You can control cookies through your browser settings. Blocking cookies may affect website functionality, forms, videos, maps, payment pages, or other services.
15. How We Share Personal Data
MYCDIC does not sell personal data. We may share personal data only where necessary and appropriate, including with:
- Authorized MYCDIC officers, departments, representatives, committees, or staff members who need access for official purposes.
- Service providers that support hosting, email, form processing, storage, analytics, cybersecurity, payment processing, or administrative operations.
- Event partners, institutional partners, or co-organizers when necessary for a specific program and where lawful.
- Legal, accounting, tax, compliance, or professional advisers where necessary.
- Public authorities, regulators, courts, law enforcement, or government bodies where required by law or necessary to protect rights, safety, or security.
MYCDIC may also share aggregated or anonymized information that does not directly identify individuals.
16. International Data Transfers
Because MYCDIC works internationally, personal data may be processed or accessed from Spain, Morocco, the European Union, and other countries where MYCDIC personnel, representatives, service providers, or partners operate.
Where required, MYCDIC will seek to use appropriate safeguards for international data transfers, including contractual safeguards, service provider terms, access controls, necessity-based transfer, or other lawful mechanisms available under applicable data protection rules.
17. Data Retention
MYCDIC keeps personal data only for as long as reasonably necessary for the purposes described in this policy. Membership, representation and advisory application files are normally retained for up to five years after the final closure of the application process. Limited evidence, decision records, consent evidence, security logs, duplicate-prevention records and records relevant to safeguarding, audit, fraud prevention, legal claims or institutional archives may be retained for a longer period where required or permitted by applicable law and subject to appropriate access restrictions.
| Data Type | Typical Retention Approach |
|---|---|
| Contact and inquiry messages | Retained while the request is active and for a reasonable administrative period after closure. |
| Membership and representation applications | Retained for evaluation, eligibility review, appointment records, verification, future opportunities, and institutional archive purposes. |
| Partnership and sponsorship proposals | Retained for evaluation, future cooperation, recordkeeping, or institutional follow-up. |
| Donation and payment records | Retained as necessary for accounting, tax, compliance, audit, and donor follow-up. |
| Membership, event, and certificate records | Retained as needed to verify participation, issue certificates, manage membership, and maintain institutional archives. |
| Website logs and security data | Retained for a limited period necessary for security, troubleshooting, abuse prevention, or legal protection. |
| Published news, media, and public records | May be retained as part of MYCDIC’s public institutional archive unless removal is required or approved. |
MYCDIC may keep limited records where necessary to establish, exercise, or defend legal claims, prevent repeated abuse, maintain institutional archives, verify status or participation, or comply with legal obligations.
18. Data Security and Protection Measures
MYCDIC uses reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
- Access to personal data is limited to authorized persons who need it for official purposes.
- Forms may use anti-spam controls, request IDs, timestamps, user agent recording, and internal routing controls.
- Files and submissions may be reviewed, restricted, deleted, or quarantined if they are unsafe or irrelevant.
- MYCDIC may archive, restrict, or delete records to reduce unnecessary exposure.
- MYCDIC may suspend access, block abusive submissions, or report unlawful activity when necessary.
19. Your European Data Protection Rights
MYCDIC recognizes European data protection rights where applicable. Depending on the applicable law and your location, you may have rights in relation to your personal data, including:
- Right to be informed: to receive clear information about how your data is processed.
- Right of access: to request access to personal data held about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data where legally applicable.
- Right to restriction: to request limits on certain processing activities.
- Right to data portability: to receive certain personal data in a structured format where applicable.
- Right to object: to object to certain processing based on legitimate interests or direct communications.
- Right to withdraw consent: where processing is based on consent, without affecting prior lawful processing.
- Rights related to automated decision-making: where applicable under data protection law.
- Right to lodge a complaint: with a competent data protection authority.
To exercise these rights, contact privacy@mycdic.org. MYCDIC may need to verify your identity before responding. Some requests may be refused or limited where MYCDIC must retain data for legal, security, contractual, accounting, public archive, membership verification, or legitimate institutional reasons.
20. Minors and Youth Participation
MYCDIC works with youth and may organize activities involving young people. The website is not intended to collect personal data from children without appropriate consent or lawful authorization.
- Persons under the age required by applicable law should obtain parental or guardian consent before submitting personal data.
- Where MYCDIC becomes aware that data from a minor has been collected without appropriate consent, it may delete or restrict the data.
- For youth programs, events, or media involving minors, MYCDIC may request additional consent forms or authorization.
- Applicants below the required age for specific roles may be rejected, redirected, or asked to provide guardian consent where lawful.
21. Third-Party Services, Links, and External Platforms
The MYCDIC website may include links or integrations with external services used for hosting, email, payments, forms, social media, maps, videos, fonts, icons, analytics, security, and other website or administrative functions.
These third parties may process data according to their own privacy policies and terms. MYCDIC is not responsible for the privacy practices, security standards, or content of third-party websites or services. Users should review the relevant third-party policies before submitting information or making payments.
22. User Responsibilities, Legal Limits, and Institutional Protection
By using the MYCDIC website, submitting an application, communicating with MYCDIC, or using any MYCDIC-related service, you agree that:
- You will provide accurate information and will not impersonate another person, organization, public authority, officer, representation, partner, donor, or MYCDIC body.
- You will not falsely claim membership, representation, office, title, authorization, certificate, partnership, mandate, diplomatic status, government status, or official authority with MYCDIC.
- You will not use MYCDIC's name, logo, emblem, colors, templates, documents, certificates, pages, emails, or identity to mislead the public, obtain money or benefits, create confusion, or harm MYCDIC.
- You will not publish, submit, or distribute illegal, abusive, defamatory, discriminatory, threatening, hateful, fraudulent, misleading, forged, confidential, or malicious content about MYCDIC or any person connected to MYCDIC.
- You will not attempt to create unauthorized parallel structures, representations, committees, offices, leadership claims, fundraising initiatives, pages, groups, or campaigns under the MYCDIC name.
- You will not upload malware, unsafe files, scripts, unauthorized confidential information, identity documents, payment details, or personal data of third parties without a lawful basis.
- You understand that ordinary contact forms and email are not appropriate for highly sensitive information, confidential state information, bank credentials, passwords, or payment card details.
- MYCDIC may ignore, reject, delete, block, archive, correct, preserve, publicly clarify, or report submissions, pages, messages, documents, accounts, or conduct that violate this policy, MYCDIC rules, or applicable law.
- MYCDIC may take internal, administrative, civil, criminal, platform, domain, or legal measures against misuse of its name, identity, logo, institutional materials, emails, titles, documents, certificates, reputation, or representation structures.
23. Updates to this Privacy Policy
MYCDIC may update this Privacy Policy from time to time to reflect changes in website features, forms, services, legal requirements, operational practices, or institutional structure.
The updated version will be posted on this page with a revised “Last updated” date. Continued use of the website after publication of updates means that you acknowledge the revised policy.
24. Privacy Contact and Requests
For questions, privacy requests, correction requests, deletion requests, media removal requests, application data requests, or data protection concerns, contact MYCDIC using the channels below.