OUR PRIVACY POLICY
In this privacy policy (the “Policy”), we explain how we collect and use your personal information. This Policy applies to all personal data we process about you when you use our services, visit our websites or otherwise interact with us.
The Policy applies to both Axía Advisory Services (“Axia”).
In this Policy, “Axía”, “we”, “our” or “us” may refer to Axía or any of Axía subsidiaries and affiliates (and their respective successors in title).
1. Who we are
Axía is registered as Data Controller (defined below) with the Data Protection Office in Mauritius and as such is bound to comply with the EU General Data Protection Regulation (“GDPR”) and the Mauritius Data Protection Act 2017 (“DPA”). The Policy forms part of Axía’s obligation to be fair and transparent with each and every data subject whose personal data we process and to provide full information on how we process such personal data and what we do with it.
2. What is personal data?
Personal data relates to any information about a natural person that makes you identifiable.
We may process your personal data under the following situations:
3. What personal data we collect about you
We collect and process a series of data about people we deal with and those related to our clients and other counterparties. Such data might include (but is not limited to):
(i) Your personal details such as your:
(ii) Information about entities/ organisations or institution with which you are related such as:
(iii) Identification documents such as passport, ID card, driving licence or any other documents required by the laws of the Republic of Mauritius.
(iv) Address verification documents such as utility bill, bank statement, credit card statement, bank reference letter or professional reference letter or any other Information required by the laws of the Republic of Mauritius or provided through our recruitment process such as CVs.
(v) Contact details of people with whom you are connected, including your immediate family or next of kin.
(vi) Your marketing preferences.
(vii) Information which you provide to us in the course of corresponding with us.
4. What are sensitive/ special categories of personal data?
Sensitive or special categories personal data refer to the above but includes genetic data and biometric data. For example:
We may also collect and process “special categories” of personal data in certain circumstances where we are required to for the purposes of our legal and/ or regulatory obligations including, but not limited to, legislation and regulatory obligations relating to Anti- Money Laundering and Combating the Financing of Terrorism and any other related legislation. This may include information regarding your racial or ethnic origins, political opinion and affiliations or information relating to criminal records.
5. What is a Data Controller?
For the purposes of GDPR and the DPA, the “Data Controller” means the person or organisation, alone or jointly with others, determines the purposes and means of the processing of personal data and has decision making power with respect to the processing.
The identity of the Data Controller for data protection purposes will vary depending on the company with which you are interacting with.
The data controller for Axía is data protection officer is Alexandre Yeung Chin Shing, who can be contacted at the above address or by calling 464-0889.
6. What is a Data Processor?
A “Data Processor” is a person or organisation which processes personal data on behalf of the Data Controller.
7. What information do we collect about you and how?
We principally collect your personal data from the following sources:
(i) From information which you or your authorised representative give to us, including but not limited to:
(ii) Personal data we receive from you or any third party sources which may include:
We may also collect and process your personal data in the course of dealing with advisors, regulators, official authorities and service providers by whom you are employed or engaged or for whom you act.
8. What is Lawful Processing?
For the processing of data to be lawful under the GDPR and the DPA, there are certain conditions that need to be met before we can process personal data.
Under the DPA, we are allowed to hold and process your personal data on the following six legal bases:
(i) You consent to the processing for one or more specified purposes;
(ii) The processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request before entering into a contract;
(iii) For compliance with any legal and regulatory obligations to which we are subject;
(iv) In order to protect your vital interests or another person;
(v) For the performance of a task carried out in the public interest; and
(vi) For the legitimate interests pursued by us or by a third party to whom data is disclosed, except if the processing is unwarranted in any particular case having regard to the harm and prejudice your rights and freedoms or legitimate interests.
Some of the above mentioned grounds for processing might overlap and there might be more than ground substantiating our use of your personal data.
9. What are the purposes for processing your data?
Pursuant to paragraph 8 of the Policy, we may process your personal data for the following purposes:
Your personal data will only be used for the purposes for which we collected it (as listed above) except in circumstances where we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. In case we might need to use your personal information for an unrelated purpose, we shall notify you and explain the legal basis which allows us to do so.
10. To whom we may disclose your personal data?
We may disclose your personal data:
However, the authorised third parties may process your personal data abroad and may have to disclose it to foreign authorities for examples for anti money laundering and combating financing of terrorism.
In cases where such third parties act as data processors, we shall ensure that there is an appropriate agreement in place and that your personal data is processed according to applicable laws.
11. How long do we keep hold of your data for?
Your personal data will be retained as long as required:
12. Limitation of Liability
We respect your privacy and your personal data is always treated diligently and cautiously by our organisation. We aim to store and process your personal data in accordance with accepted market standards.
Whilst we have taken every reasonable care to ensure the implementation of appropriate technical and security measures, we cannot guarantee the security of your personal data over the internet, via email or via our website nor do we accept, to the fullest extent permitted by law, any liability for any errors in data transmission, machine, software or operating error or any other cause.
13. Keeping in mind Your Rights as Data Subject
The DPA introduces greater rights for you as data subject so as to be aligned with the enhanced rights afforded under the GDPR. These are:
(i) Right of Access;
(ii) Right of Rectification;
(iii) Right of Erasure;
(iv) Right of Restriction; and
(v) Right to Object.
What is Right of Access?
It is your right to request a copy of the information that we hold about you. If you would like a copy of some or all of your processed personal data, please email or write to us at the address mentioned in paragraph 15.8. We will respond to your request within one month of receipt of the request.
What is Right of Rectification?
We want to make sure your personal information is accurate and up to date. You may ask us to correct data you think is inaccurate by emailing or writing to us.
What is Right of Erasure?
You have the right to ask us to delete your personal data in the following course of events:
Right of restriction
In some situations, this right gives an individual an alternative to requiring data to be erased; in others, it allows the individual to require data to be held in limbo whilst other challenges are resolved.
If personal data is ‘restricted’, then we may only store the data, and not process it by any means. You may ask us to restrict the processing of your personal data under the following circumstances:
Right to object
You have a specific right to object. It is not an absolute right and it applies only in the following circumstances:
However, if we have processed your personal data under lawful processing conditions mentioned in paragraph 10, and you choose to object, we might no longer be in a position in that case to continue providing our services to you.
You have a right at any time to stop us sending you newsletters, newsflash, important notices/ communiqué and general updates on the Mauritius and Global International Financial Services industry.
To opt out please email us at: compliance@axia.mu
If you would like to exercise your rights in relation to the processing of your personal data, you may contact us on:
E-mail: compliance@axia.mu
In Writing to: the Data Protection Officer,
Axía Advisory Services Ltd, Level 5,
Maeva Tower, Bank Street,
Cybercity, Ebène,
Republic of Mauritius
Right to make a complaint
If you feel that your personal data has been processed in a way that does not meet the GDPR or DPA, you have a specific right to lodge a complaint with the relevant supervisory authority. The supervisory authority will then guide you of the progress and outcome of your complaint.
The supervisory authority in the Republic of Mauritius is the Data Protection Office, whose contact details are as follows:
The Data Protection Office,
5th floor, SICOM Tower,
Wall Street, Cybercity, Ebène,
Republic of Mauritius
E-mail: dpo@govmu.org
Web address: http://dataprotection.govmu.org
This Privacy Policy was most recently amended on 17 September 2021 and replaces earlier versions. We may further amend this Privacy Policy from time to time and will notify you of any changes prior to these changes taking effect.