1. Data controller and contact
Bramston & Associates Ltd is the controller of personal data processed through the FinEng website, unless a separate notice or engagement document states otherwise.
Controller contact: info@bramston.co
Carleton Tower, 19 Wall Street
Cybercity, Ebène 72201
Mauritius
Business Registration Number: C10044944
2. Scope of this policy
This policy covers personal data collected through the public website, contact enquiries, ordinary business communications and technical operation of the site. Client, employee, recruitment, due-diligence or regulated records may be governed by additional notices and contractual terms.
3. Information collected
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, organisation, business email, telephone, location | Provided by the individual or an authorised representative |
| Mandate information | Enquiry type, decision context, timetable and jurisdictions | Contact form, email, telephone or meeting |
| Communication records | Messages, responses, meeting notes and scheduling information | Business correspondence |
| Technical data | IP address, timestamps, user agent, requested page, security events | Server, network and security logs |
| Compliance information | Conflict, sanctions, identity or authority information where required | The individual, organisation or reliable sources |
Visitors should not submit special-category data, credentials, financial account details or identity documents through the public form unless specifically requested through an agreed secure channel.
4. Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Assess and respond to an enquiry | Consent; steps requested before entering a contract; legitimate interests |
| Evaluate conflicts, authority, risk and engagement suitability | Legitimate interests; legal or professional obligations |
| Operate, secure and improve the website | Legitimate interests in security, resilience and administration |
| Maintain legal, audit and decision records | Legal obligation; legitimate interests in establishing or defending rights |
| Send requested communications | Consent or legitimate interests, subject to direct-marketing rules |
Where processing relies on consent, consent may be withdrawn prospectively.
6. International transfers
Because FinEng’s service field is cross-border and technology providers may operate internationally, information may be processed outside Mauritius. Where required, reasonable contractual, organisational and technical safeguards should be used.
7. Retention
| Record | Indicative retention approach |
|---|---|
| Preliminary enquiries | Normally up to 24 months after the last meaningful contact, unless a different period is justified |
| Client and mandate records | For the engagement and applicable contractual, professional, legal, tax, audit and limitation periods |
| Security and server logs | For a proportionate period needed for security, diagnosis, abuse prevention and legal obligations |
| Suppression or objection records | As necessary to respect the request and demonstrate compliance |
8. Security
Reasonable technical and organisational measures are intended to protect confidentiality, integrity and availability. No public internet transmission is risk-free. Highly sensitive information should be exchanged only through an agreed secure channel.
9. Individual rights
Subject to the Mauritius Data Protection Act 2017 and applicable exceptions, an individual may have rights to obtain information, access data, request rectification or erasure, restrict or object to processing, receive portable data where applicable, and withdraw consent.
10. Questions and complaints
Privacy questions or rights requests may be sent to info@bramston.co with the subject “Data protection request”. An individual may also have the right to complain to the Data Protection Office of Mauritius.
11. Children and unsolicited information
The website is directed to business and institutional users and is not intended for children. Where a person provides personal data about another individual, the provider should have lawful authority.
12. Changes to this policy
This policy may be updated to reflect changes in services, technology, law or processing. The effective date and version will be revised.