1. Controller and scope
The website and the Dialogue are administered by Bramston & Associates Ltd (BRN C10044944) as the ATFCD Secretariat. For website enquiries and event administration, Bramston & Associates Ltd is the data controller.
This notice covers public website visitors, people who contact the Secretariat and prospective or confirmed participants. Any securities, regulatory, KYC or investment due-diligence process relating to Canopus will be subject to separate documentation and a separate privacy notice.
2. Data protection contact
ATFCD Secretariat, 44E, Cyprus Lane, Leclezio Street, Curepipe, Mauritius.
Email: info@atfcd.org. Please use the subject line ‘Data protection request’.
3. Personal data we may process
Professional contact and enquiry data, including name, title, institution, country, email address and the content of correspondence.
Event administration data supplied by an invitee or institution, such as protocol contact details, attendance status, dietary or accessibility requirements and travel information where necessary.
Limited technical data in server security logs, such as IP address, browser type, requested page, timestamp and security events.
The public website does not request passports, payment-card information, source-of-funds information or other investment due-diligence material. Please do not send sensitive documents through the public website.
The briefing-request form operates in the visitor’s browser and opens the visitor’s email application; it does not itself submit the form contents to an ATFCD database.
4. Purposes and lawful grounds
To respond to enquiries, assess interest, manage invitations and administer the Dialogue, relying on legitimate interests and, where relevant, steps requested before an arrangement is made.
To maintain website and information security, prevent abuse and investigate incidents, relying on legitimate interests and legal obligations.
To comply with law, regulatory requests, sanctions, anti-corruption, accounting or dispute requirements where applicable.
To send optional updates only where consent has been given or another lawful basis applies. Consent may be withdrawn at any time.
7. International transfers
The Dialogue involves institutions in several countries and event arrangements in the United Arab Emirates. Where personal data are transferred outside Mauritius, the Secretariat will use an applicable lawful basis and appropriate safeguards required by section 36 of the Mauritius Data Protection Act 2017.
Hosting-provider identity, hosting location and any material cross-border safeguards must be recorded in the production data-processing register before the website goes live.
8. Retention
Technical security logs should ordinarily be retained for no longer than 30 days unless a security incident requires longer preservation.
General enquiries should ordinarily be retained for up to 24 months after the last substantive contact.
Event administration records should ordinarily be retained for up to 36 months after the Dialogue, unless law, audit, security, protocol or dispute requirements justify a different period.
Data are deleted, anonymised or restricted when no longer needed. Investment and regulatory records follow separate retention schedules.
9. Security
The site is designed for encrypted transmission, restrictive security headers, data minimisation, controlled administrative access and limited logging. Organisational measures should include role-based access, confidentiality duties, incident handling and processor oversight.
No internet transmission or storage system can be guaranteed absolutely secure. Please use an agreed secure channel for sensitive documents.
10. Your rights
Subject to the Act and applicable exceptions, individuals may request access, rectification, erasure or restriction, object to processing, and withdraw consent where consent is relied upon.
A request may require proportionate identity verification. Individuals may also lodge a complaint with the Mauritius Data Protection Commissioner.
11. Personal-data breaches
The Secretariat will maintain an incident process. Where required, a personal-data breach will be notified to the Commissioner without undue delay and, where feasible, within 72 hours after awareness. Affected individuals will be informed without undue delay where the breach is likely to create a high risk to their rights and freedoms.
12. Children
The website and Dialogue are intended for senior professional and public-sector audiences and are not directed to children. The Secretariat does not knowingly collect children’s data through the public site.
13. Changes and official information
This notice may be updated as the event, hosting and processing arrangements are finalised. The version date will be changed when material updates are made.
Official information about Mauritius data-protection law and data-subject rights is available from the Mauritius Data Protection Office.
Mauritius Data Protection Office
Where a translated version differs from the English version, the English version prevails to the extent permitted by law.