Last updated: 11 July 2026. This page explains, in plain language, how Mauritius AI Network complies with Mauritian data protection law. It is a summary for transparency purposes and does not replace the official legislation or guidance issued by the Data Protection Office of Mauritius.
1. Introduction
Mauritius AI Network ("M.A.I.N", "we", "us", "our") is committed to protecting the personal data of everyone who uses our platform — professionals, organisations, and ecosystem partners alike. This Data Protection page sits alongside our Privacy Policy and focuses specifically on how we meet our obligations under Mauritian data protection law, and what that means for you in practice.
2. Applicable Mauritian Legislation
As a platform operating in and serving the Republic of Mauritius, our processing of personal data is governed primarily by:
- The Data Protection Act 2017 — Mauritius's principal data protection law, in force since 15 January 2018, which sets out the rights of data subjects and the obligations of data controllers and processors.
- The Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 — subsidiary regulations that govern how organisations designate a Data Protection Officer (DPO), the tasks that role must perform, and the position the DPO holds within an organisation.
- Guidance issued by the Data Protection Office of Mauritius — including sector guidance on topics such as artificial intelligence and health data, which we monitor and apply where relevant to our platform.
Where our users are located outside Mauritius — for example in the European Union — we also have regard to frameworks such as the EU GDPR, as described in our Privacy Policy. This page does not reproduce the text of the Act or Regulations; for the authoritative legal text, please refer to the official resources linked at the bottom of this page.
3. Our Commitment to Data Protection
We treat data protection as a governance responsibility, not a checkbox. In practice, this means we:
- Collect only the personal data we genuinely need to operate a verified, mediated professional network;
- Keep verification documents and private contact details out of public view at all times;
- Route every enquiry between members through a mediated inquiry system rather than exposing raw contact details;
- Apply role-based access control so only authorised administrators can view sensitive records;
- Review our data handling practices as the platform and applicable guidance evolve.
4. Personal Data We Collect
Depending on how you use the platform, we may collect:
- Identity and profile data: name, professional title, biography, skills, organisation details, LinkedIn URL, and profile photograph.
- Account data: email address, hashed password, account role, and verification status.
- Verification information: supporting details submitted to confirm you are a genuine professional or organisation. This is reviewed internally and never published.
- Communications: messages sent through our mediated inquiry system, and correspondence with our team.
- Usage data: pages visited, feature usage, and device/browser information, collected via privacy-respecting analytics.
- Content you submit: job listings, event details, and opportunity postings.
5. Why We Process Personal Data
We process personal data to:
- Create and maintain your verified profile once your application is approved;
- Assess and communicate the outcome of verification applications;
- Operate the mediated inquiry and notification systems;
- Detect and prevent fraud, spam, and misuse of the platform;
- Produce anonymised, aggregate insight into the Mauritius AI ecosystem;
- Meet our legal and regulatory obligations under Mauritian law.
6. Lawful Basis for Processing
Under the Data Protection Act 2017, personal data may only be processed where a lawful basis exists. We rely on the following:
- Performance of a contract: to provide the account and directory services you sign up for.
- Consent: for optional communications, and for any optional cookies we may introduce in future, which you can withdraw at any time.
- Legitimate interests: for fraud prevention, platform security, and service improvement, balanced against your rights and freedoms.
- Legal obligation: where processing is required to comply with Mauritian law or a lawful request from a competent authority.
8. Data Sharing
We do not sell, rent, or trade personal data. We share personal data only in the following limited circumstances:
- Published profile data is visible to other signed-in, verified members once your profile is approved and published — this is the core purpose of the directory.
- Service providers who process data on our behalf under contract (see below) — for example our hosting/database provider and our transactional email provider.
- Legal and regulatory disclosure, where required by Mauritian law or a valid request from a competent authority such as the Data Protection Office.
9. International Data Transfers
Our infrastructure providers (Firebase/Google Cloud for hosting and database) may process and store data outside Mauritius. Transactional email is sent directly from our own mailbox over SMTP, not routed through a third-party email API provider. Where personal data is transferred internationally, we require our processors to maintain a level of protection consistent with the Data Protection Act 2017 — including contractual safeguards and, for EU/EEA-related transfers, Standard Contractual Clauses. We do not transfer data to any processor without an appropriate data processing agreement in place.
10. Data Retention
- Active accounts: retained for as long as the account remains active.
- Dormant accounts: after 24 months of inactivity we notify you by email; if there is no response within 90 days, the account and associated personal data are permanently deleted.
- Verification records: deleted 90 days after a decision is communicated.
- Inquiry messages: retained for 24 months, then permanently deleted.
You can request deletion of your account and data at any time from your dashboard, or by contacting us — see Exercising Your Rights below.
11. Data Security Measures
- Encryption in transit using TLS across the entire platform.
- Passwords are hashed and never stored or visible in plain text.
- Database access rules restrict who can read or write which records, enforced server-side.
- Administrative access is role-restricted, and sensitive actions are logged for audit purposes.
- Verification documents are held in access-controlled storage, never exposed publicly.
No system can guarantee absolute security. If you believe your account or data has been compromised, please contact us immediately at hello@mauritiusai.org.
12. Your Rights Under the Data Protection Act
As a data subject under the Data Protection Act 2017, you have rights including the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erasure of your data where it is no longer needed for the purpose it was collected;
- Object to certain processing on grounds relating to your particular situation;
- Data portability, receiving your data in a structured, machine-readable format where processing is automated.
These rights are not absolute and may be subject to exemptions under the Act — for example where fulfilling a request would compromise the rights of another individual. Where a request cannot be fulfilled, we will explain why.
13. Exercising Your Rights
Updating your profile can be done directly from your dashboard. Deleting your account starts as a request submitted from your Account page — a member of our team reviews and actions it, rather than the account being deleted instantly, so we can catch disputes or mistakes first. For anything else, email hello@mauritiusai.org with your request. We aim to respond within 28 days, and there is no charge for a reasonable request. We may ask you to verify your identity before actioning a request that involves personal data.
If you are not satisfied with our response, you have the right to lodge a complaint directly with the Data Protection Office of Mauritius.
14. Contacting the Data Protection Officer
In line with the Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, we maintain a designated point of contact responsible for overseeing our data protection practices, advising on compliance, and acting as the primary contact for data subjects and the Data Protection Office. You can reach our data protection point of contact at hello@mauritiusai.org (please mark your message "For the attention of the Data Protection Officer").
15. Changes to This Policy
We may update this page from time to time to reflect changes in our practices, our platform, or Mauritian data protection law and guidance. Material changes will be communicated to registered users by email in advance. The date at the top of this page always reflects the most recent revision.
16. Official Government Resources
For the authoritative legal text and official guidance, please refer directly to the Data Protection Office of Mauritius:
- Data Protection Office of Mauritius — official website
- Data Protection Act 2017 — full legislative text
- Guidelines on the Data Protection Act 2017 — official guidance documents
- Exercise of Rights — how to make a request as a data subject
- Contact the Data Protection Office — email dpo@govmu.org · tel. 460 0251
