Last updated: 1 September 2026  |  Controller: Tama Surf Morocco SARL, Tamraght Oufella, Morocco  |  Contact: privacy@tamasurf.com

Tama Surf Morocco is committed to protecting your personal data. This policy explains what we collect through tamasurf.com, why we collect it, how long we keep it, and your rights under the GDPR.

1. Who We Are

Tama Surf Morocco SARL (“Tama Surf”, “we”, “us”) operates tamasurf.com and provides surf coaching, accommodation, and retreat services from our riad in Tamraght Oufella, Taghazout Bay, Morocco. We are the data controller for personal information collected through this website and our booking communications.

2. Information We Collect

Information you give us directly

Information collected automatically

Information we do NOT collect

3. How We Use Your Data

4. Data Sharing

We never sell or rent your data. We share it only with: activity partners at the riad (e.g. yoga instructors, surf guides) where necessary for your booking; email service providers for newsletter delivery (under GDPR-compliant Data Processing Agreements); regulatory authorities where required by applicable law.

5. International Data Transfers

Our operations are based in Morocco. Where personal data is transferred to or processed by service providers based in the EEA, we use Standard Contractual Clauses (SCCs) or rely on adequacy decisions to ensure appropriate safeguards are in place.

6. Data Retention

7. Your GDPR Rights

Under the GDPR you have the following rights regarding your personal data. Email privacy@tamasurf.com to exercise any of them — we respond within 30 days.

👁️
Access (Art. 15)

Request a copy of all data we hold about you.

✏️
Rectification (Art. 16)

Correct any inaccurate or incomplete data.

🗑️
Erasure (Art. 17)

Request deletion of your personal data.

⏸️
Restriction (Art. 18)

Restrict how we process your data.

📦
Portability (Art. 20)

Receive your data in a machine-readable format.

🚫
Object (Art. 21)

Object to processing based on legitimate interests.

🔕
Withdraw Consent (Art. 7)

Withdraw consent at any time without penalty.

⚖️
Complain

Lodge a complaint with your national data protection authority.

8. Cookies

We use a minimal cookie approach. For full details and management options, see our Cookie Preferences page.

9. Security

All data in transit is protected by TLS encryption. In the event of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.

10. Changes to This Policy

We may update this policy periodically. The “Last updated” date at the top reflects any changes. Material changes will be communicated via a notice on our homepage or by email to newsletter subscribers.

11. Contact & Supervisory Authorities

If you are based in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority (e.g. ICO — UK, CNIL — France, BfDI — Germany, Datatilsynet — Scandinavia).

Notification message