1. Scope and controller
This notice applies to personal data processed when a person visits the website, corresponds with Tamam Shud Ltd, or is recorded in connection with a legitimate corporate enquiry. For those activities, Tamam Shud Ltd acts as controller under the Mauritius Data Protection Act 2017.
The public site is intentionally data-light. It has no contact form, public account, newsletter, advertising network or behavioural analytics tool.
2. Data that may be processed
Depending on the interaction, the company may process:
- name, role, organisation and professional contact details;
- the content, metadata and attachments of correspondence;
- corporate, authority or relationship information supplied to support an enquiry;
- technical logs generated by hosting or security services, which may include an IP address, browser or device information, requested page, date and time; and
- records required to respond, protect systems, administer a corporate relationship or comply with law.
The website should not be used to send unnecessary identity documents, bank records, ownership records or other sensitive material. A secure channel should first be agreed where such information is legitimately required.
3. Purposes and legal bases
| Purpose | Typical basis |
|---|---|
| Responding to a relevant enquiry and taking requested corporate or pre-contractual steps | Legitimate interests, requested steps or performance of an arrangement, as applicable |
| Corporate administration, recordkeeping and relationship management | Legitimate interests and legal obligations |
| Website security, abuse prevention and technical availability | Legitimate interests and legal obligations |
| Regulatory, legal, tax, audit or authority correspondence | Legal obligations, public-interest requirements or legitimate interests, as applicable |
Consent is used only where it is the appropriate basis and is expressly sought.
4. Recipients and processors
Personal data may be disclosed, on a need-to-know basis, to hosting, email, cybersecurity and IT providers; professional advisers; relevant corporate administration personnel; banks or counterparties involved in a legitimate process; and public authorities where disclosure is required or properly justified.
The company does not sell personal data and does not provide it to advertising brokers.
5. International processing
Website hosting, email delivery or professional support may involve processing outside Mauritius. The actual locations and contractual safeguards of production providers must be documented. Where applicable law requires a transfer safeguard, the company should use an appropriate mechanism and retain evidence of it.
6. Retention
Personal data is retained only for as long as reasonably required for the purpose, a legitimate corporate record, a legal or regulatory obligation, the defence of a claim, or information-security needs. Production server-log retention depends on the selected hosting and security configuration.
7. Security
Proportionate technical and organisational measures are intended to protect data against unauthorised access, alteration, loss or disclosure. The website reduces exposure through a small data surface, local assets, restrictive security headers, limited browser-side code and no public form. No internet or email system can be guaranteed completely secure.
8. Individual rights
Subject to the conditions and exceptions in Mauritius law, a data subject may request access, correction of inaccurate data, erasure or restriction where applicable, object to certain processing, and exercise other statutory rights relevant to the processing. A request may require proportionate identity verification.
The website does not make solely automated decisions producing legal or similarly significant effects.
9. Data-protection contact
Data-protection correspondence, including correspondence addressed to any person formally designated by the company as data protection officer, may be sent to office@tamamshud.xyz.
The Mauritius Data Protection Act 2017 requires a controller to designate an officer responsible for data protection. The Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026 come into operation on 1 January 2027 and add requirements concerning designation, notification, qualifications, tasks, independence, support and publication of contact details. Formal designation, notification and internal reporting arrangements are corporate obligations and are not established by website code alone.
10. Complaints and updates
A person may contact the company first so that the matter can be considered. A data subject may also lodge a complaint with the Mauritius Data Protection Commissioner where entitled to do so.
This notice may change when the law, provider configuration or processing activity changes. The version date appears above.