Our approach
Art. 32 GDPR — security of processing · Art. 23 Loi 09-08 (Moroccan personal data protection act)
The security of a platform that handles payments, geographic positions and the contact details of students cannot rest on the good conduct of the interface alone. We therefore apply a simple principle: every control is enforced at the lowest possible layer, the one that no manipulation of the client can circumvent.
In practice, access rules, price calculation and the validation of order steps are executed server-side and systematically redo the work rather than trusting what the device sends.