HomeLegalPrivacy Policy

Privacy Policy

Effective date: 25 June 2026 · Compliant with Mauritius DPA 2017 & EU GDPR

Effective date: 25 June 2026. This Policy explains how Mauritius AI Network collects, uses, and protects your personal data, and describes your rights under the Mauritius Data Protection Act 2017 and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Who We Are

Mauritius AI Network ("M.A.I.N", "we", "us", "our") is the data controller responsible for personal data processed through this platform. We are an independent, privately operated discovery registry based in the Republic of Mauritius.

Contact: hello@mauritiusai.org

2. Information We Collect

We collect the following categories of personal data:

  • Profile data: Full name, professional title, biography, skills and expertise, industry sector, LinkedIn URL, and profile photograph.
  • Account data: Email address, hashed password, account type (professional, organisation, or ecosystem member), account creation date, and verification status.
  • Verification documents: Identity or supporting professional documents submitted for the verification process. These are processed internally by our review team and are never displayed publicly.
  • Usage data: Basic server-side request logs (pages requested, timestamps) generated by our hosting infrastructure. We do not currently run any dedicated analytics or tracking service — see our Cookie Policy for details.
  • Communication data: The content of contact inquiry messages sent through our mediated inquiry system.
  • Posted content: Job listings, event descriptions, and opportunity posts you submit to the platform.

3. How We Use Your Information

We use your personal data to:

  • Create, operate, and display your public profile (once approved);
  • Process your verification application and communicate the outcome;
  • Send transactional account communications (verification status updates, password resets, security notices);
  • Route contact inquiry messages to your dashboard;
  • Prevent fraud, abuse, and ensure platform security;
  • Generate anonymised aggregate statistics about the Mauritius AI ecosystem (no individual data is published in these reports);
  • Comply with legal obligations under Mauritius law.

5. Your Rights Under the Mauritius Data Protection Act 2017

Under the Mauritius Data Protection Act 2017, you have the following rights in relation to your personal data:

  • Right of access (Section 38 DPA): Request a copy of the personal data we hold about you.
  • Right to rectification (Section 39 DPA): Request correction of inaccurate or incomplete data.
  • Right to erasure (Section 40 DPA): Request deletion of your personal data in certain circumstances (e.g., where it is no longer necessary for the purpose for which it was collected).
  • Right to object (Section 41 DPA): Object to processing on grounds relating to your particular situation.
  • Data portability: Request your data in a structured, machine-readable format where processing is carried out by automated means.

To exercise any of these rights, email hello@mauritiusai.org. We will respond within 28 days. There is no charge for a reasonable request.

You also have the right to lodge a complaint with the Data Protection Commissioner of Mauritius. For further information, visit the official Data Protection Office of Mauritius.

6. Additional Rights for EU/EEA Residents (GDPR)

If you are located in the European Union or European Economic Area, the GDPR applies to our processing of your personal data. In addition to the rights described above, you have:

  • Right to restriction of processing (Art. 18 GDPR): Request that we restrict how we use your data in certain circumstances.
  • Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint: You may contact your local supervisory authority (e.g., CNIL in France, the DPC in Ireland, or the ICO in the United Kingdom).

International transfers: Personal data of EU/EEA residents may be transferred to Firebase infrastructure operated by Google LLC in the United States. Such transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of data protection.

7. Artificial Intelligence & Automated Decision-Making (EU AI Act)

In accordance with Article 22 of the GDPR and the transparency obligations of Regulation (EU) 2024/1689 (the EU AI Act), we confirm the following:

  • The platform does not make solely automated decisions that produce legal or similarly significant effects on individuals.
  • All profile verification decisions are made by human reviewers — no automated system determines your verification status.
  • The platform does not deploy AI systems classified as high-risk under Annex III of the EU AI Act.
  • Should we introduce AI-assisted features in future, we will update this Policy, provide a transparency notice as required by Article 50 EU AI Act, and give users the right to request human review of any AI-influenced decision.

You always have the right to request human intervention, express your point of view, and contest any significant decision affecting your account.

8. How We Share Your Information

Public profile data (name, title, biography, skills, profile photo, and contact form access) is visible to other authenticated, verified members of the platform once your profile is approved.

We use the following data processors to operate the platform:

  • Google LLC / Firebase: Authentication, real-time database, hosting, and analytics.
  • Our email service provider: Transactional email delivery (verification notifications, password resets), sent via our own mailbox over SMTP.

We do not sell, rent, or commercially share your personal data with any third party. We do not work with advertising networks or data brokers.

9. International Data Transfers

Data is stored on Firebase and Google Cloud infrastructure, which may be located outside the Republic of Mauritius. For EU/EEA residents, transfers are protected by Standard Contractual Clauses. For other residents, transfers occur under the legitimate interests basis with appropriate technical and contractual safeguards in place with our processors.

10. How Long We Keep Your Data

  • Active accounts: Retained for the lifetime of the account.
  • Dormant accounts (no login for 24 months): We will send a reminder email. If no response is received within 90 days, the account and associated data will be permanently deleted.
  • Verification documents: Deleted 90 days after the verification decision is communicated.
  • Inquiry messages: Retained for 24 months from the date of submission, then permanently deleted.
  • Posted content (jobs, events, opportunities): Deleted when you remove the listing or close your account.

You may request early deletion of your data at any time by contacting us, or by submitting a deletion request from your account settings — this is reviewed by our team rather than actioned instantly.

11. How We Protect Your Data

  • All data in transit is encrypted using Transport Layer Security (TLS 1.2 or higher).
  • Passwords are hashed using industry-standard algorithms; we cannot read your password.
  • Firebase Security Rules restrict database access to authorised users only.
  • Administrative access to the platform is role-restricted and activity-logged.
  • Verification documents are stored in access-controlled storage and never exposed to other users.

While we apply robust security measures, no system is entirely immune to risk. Please notify us immediately at hello@mauritiusai.org if you believe your account has been compromised.

12. Cookies

We use essential cookies for authentication and session management. We do not currently set any analytics, advertising, or tracking cookies. For full details, please read our Cookie Policy.

13. Changes to This Policy

We will notify registered users by email before any material change to this Privacy Policy takes effect. The effective date at the top of this page reflects the most recent revision. Where changes are significant, we will provide a summary of what has changed.

14. How to Contact Us

For any privacy-related query, data subject access request, or complaint, please contact us at hello@mauritiusai.org. We aim to respond to all requests within 28 days.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Commissioner of Mauritius, Level 2, Maeva Tower, 6 Bank Street, Port Louis, Mauritius. EU/EEA residents may also contact their national data protection supervisory authority.