Personal data processing agreement

Issued pursuant to the Data Protection Act 2017 (Act No. 20 of 2017) of the Republic of Mauritius

1.  INTRODUCTION AND SCOPE

1.1  This Personal Data Processing Agreement (the "Agreement") governs the collection, use, disclosure, storage and destruction of personal data by Rocket Ventures Invest Ltd, trading as Stanford Realty (the "Controller", "we", "us"), in connection with the websites www.immo.mu and www.stanford-realty.com (together, the "Websites") and with the real estate services provided through them.

1.2  Both Websites are operated by the same legal entity and are governed by this single Agreement. A reference to either domain is a reference to both, and the identity of the Controller does not change according to the domain through which a data subject accesses our services.

1.3  This Agreement is issued in discharge of the Controller's obligations under section 23 of the Data Protection Act 2017 (Act No. 20 of 2017) (the "Act") and constitutes the information required to be given to a data subject at the time of collection of his personal data.

1.4  The Controller conducts its activities within the regulatory framework established by the Act, by the Real Estate Agent Authority Act 2020, under which a real estate agent is required to be registered with the Real Estate Agent Authority, and by the Financial Intelligence and Anti-Money Laundering Act 2002 ("FIAMLA"), under which a real estate agent is a reporting person supervised by the Financial Intelligence Unit. The Controller's registration particulars are published on the Websites and are available on request.

1.5   By accessing the Websites, submitting an enquiry, requesting a viewing, or instructing us in relation to the sale, purchase, letting or management of immovable property, the data subject acknowledges that his personal data will be processed in accordance with this Agreement.

2.  DEFINITIONS

The terms below bear the meanings assigned to them by section 2 of the Act.

2.1  "Personal data" means any information relating to a data subject; "data subject" means an identified or identifiable individual to whom personal data relates.

2.2  "Processing" means any operation performed on personal data, whether or not by automated means, including collection, recording, organisation, storage, retrieval, consultation, use, disclosure, alignment, restriction, erasure or destruction.

2.3  "Controller" means a person who determines the purposes and means of the processing of personal data; "processor" means a person who processes personal data on behalf of a controller.

2.4  "Consent" means any freely given, specific, informed and unambiguous indication of the wishes of a data subject, by a statement or clear affirmative action, by which he signifies agreement to the processing of personal data relating to him.

2.5  "Personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

2.6   "Commissioner" means the Data Protection Commissioner, being the head of the Data Protection Office established under section 4 of the Act.

3.  PRINCIPLES GOVERNING OUR PROCESSING

Pursuant to section 21 of the Act, the Controller ensures that personal data are:

(a) processed lawfully, fairly and in a transparent manner in relation to any data subject;

(b) collected for explicit, specified and legitimate purposes and not further processed in a manner incompatible with those purposes;

(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;

(d) accurate and, where necessary, kept up to date, with every reasonable step being taken to ensure that inaccurate personal data are erased or rectified without delay;

(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed; and

(f) processed in accordance with the rights of data subjects.

3.1   In accordance with section 22(2)(e) of the Act, the Controller has designated an officer responsible for data protection compliance. That officer's contact details appear at clause 15.

4.  CATEGORIES OF PERSONAL DATA COLLECTED

Section 23(2)(d) of the Act requires the Controller to state whether the supply of personal data is voluntary or mandatory. The third column below discharges that requirement. Where data are stated to be mandatory, we are unable to proceed with the relevant service if they are not supplied.

—  Identification data.  Examples: Full name, date of birth, nationality, passport or national identity card number and copy, photograph appearing on identity documents  Supply: Mandatory for any transaction.

—  Contact data.  Examples: Postal address, email address, telephone and messaging numbers, preferred language  Supply: Mandatory.

—  Enquiry data.  Examples: Property references viewed, budget, search criteria, intended use, viewing history, correspondence with our agents  Supply: Voluntary.

—  Transaction data.  Examples: Mandates, offers, reservation contracts, notarial deeds, lease agreements, inventories, keys and access records  Supply: Mandatory once instructed.

—  Financial data.  Examples: Bank details, proof of source of funds, proof of source of wealth, bank references, rental payment history, deposits  Supply: Mandatory (FIAMLA).

—  Due diligence data.  Examples: Beneficial ownership information, politically exposed person status, sanctions and adverse media screening results  Supply: Mandatory (FIAMLA).

—  Residence scheme data.  Examples: Documents supporting applications under PDS, IRS, RES, Smart City or residence permit procedures, including family composition Supply: Mandatory where instructed.

—  Website data.  Examples: IP address, device and browser type, pages viewed, referring URL, session duration, cookie identifiers  Supply: Partly voluntary (cl. 12).

—  Marketing data.  Examples: Newsletter subscriptions, communication preferences, consent records and withdrawals  Supply: Voluntary.

4.1   We collect personal data directly from the data subject; from a person duly authorised by him; from co-owners, syndics, notaries, developers and property managers in the course of a transaction; and from publicly available registers and screening databases used for anti-money laundering purposes. Where personal data are not collected directly from the data subject, the Controller complies with section 23(4) of the Act.

5.  PURPOSES OF PROCESSING AND LAWFUL BASES

Section 28(1) of the Act prohibits the processing of personal data otherwise than on one of the lawful bases it enumerates. The Controller relies on the following bases:

—  Responding to property enquiries and arranging viewings.  Lawful basis under the act: s. 28(1)(b)(i) — pre-contractual steps taken at the data subject's request.

—  Performance of sale, letting, property management and mandate agreements.  Lawful basis under the act: s. 28(1)(b)(i) — performance of a contract.

—  Customer due diligence, beneficial ownership identification and screening.  Lawful basis under the act: s. 28(1)(b)(ii) — compliance with a legal obligation (FIAMLA, ss. 17C, 17E).

—  Reporting suspicious transactions to the Financial Intelligence Unit.  Lawful basis under the act: s. 28(1)(b)(ii) — legal obligation (FIAMLA, s. 14).

—  Retention of transaction and client records.  Lawful basis under the act: s. 28(1)(b)(ii) — legal obligation (FIAMLA, s. 17F; REAA Act 2020, s. 21).

—  Assistance with residence permit and property acquisition scheme applications. Lawful basis under the act: s. 28(1)(b)(i) — performance of a contract; s. 28(1)(a) — consent where special categories arise.

—  Fraud prevention, site security and protection of our legal position.  Lawful basis under the act: s. 28(1)(b)(vii) — legitimate interests of the Controller.

—  Website operation, measurement and service improvement.  Lawful basis under the act: s. 28(1)(b)(vii) — legitimate interests; s. 28(1)(a) — consent for non-essential cookies.

—  Direct marketing, newsletters and property alerts.  Lawful basis under the act: s. 28(1)(a) — consent, withdrawable at any time.

5.1  Where processing is founded on consent, the Controller bears the burden of proving that consent was given, in accordance with section 24(1) of the Act, and the data subject may withdraw his consent at any time under section 24(2). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, nor does it affect processing founded on a separate lawful basis, in particular a legal obligation.

5.2   We do not make the provision of our services conditional upon consent to processing that is not necessary for the performance of the relevant contract, in accordance with section 24(3) of the Act.

6.  SPECIAL CATEGORIES OF PERSONAL DATA

6.1  "Special categories of personal data" are defined in section 2 of the Act and include data pertaining to racial or ethnic origin, political opinion or adherence, religious or philosophical beliefs, trade union membership, physical or mental health, sexual orientation, genetic or biometric data uniquely identifying a person, and the commission or alleged commission of an offence.

6.2  The Controller does not seek special categories of personal data in the ordinary course of its business. Such data may nevertheless arise incidentally, in particular: (i) health or accessibility information voluntarily disclosed by a client in order that a property may be adapted to his requirements; (ii) information as to alleged offences produced by sanctions, adverse media or politically exposed person screening carried out under FIAMLA; and (iii) documents produced in support of residence permit applications.

6.3  Special categories of personal data are processed only where the conditions in section 29 of the Act are satisfied in addition to a lawful basis under section 28, and access to such data within our organisation is restricted to those officers for whom it is strictly necessary.

6.4   In accordance with section 38(3) of the Act, no automated processing intended to evaluate personal aspects relating to an individual is based on special categories of personal data.

7.  ANTI-MONEY LAUNDERING OBLIGATIONS

7.1  A real estate agent in Mauritius is a reporting person within the meaning of section 2 and the First Schedule of FIAMLA. The Controller is accordingly subject to statutory obligations which override any request by a data subject to limit, restrict or erase the personal data concerned.

7.2  Pursuant to section 17C of FIAMLA, the Controller undertakes customer due diligence measures when establishing a business relationship, where a transaction equals or exceeds 500,000 rupees (or the equivalent in foreign currency) whether as a single transaction or several linked transactions, where doubts exist as to previously obtained identification information, and wherever there is a suspicion of money laundering or terrorism financing. Where the customer is not physically present, identification is undertaken by means of a reliable and independent digital identification system in accordance with section 17C(1A).

7.3  Pursuant to section 14(1) of FIAMLA, the Controller is required to report a suspicious transaction to the Financial Intelligence Unit promptly and not later than 5 working days after the suspicion arose. The Controller is prohibited by law from informing the data subject that such a report has been made, or is contemplated, or of the content of that report.

7.4   The Controller has appointed a Money Laundering Reporting Officer, whose appointment is approved by the Real Estate Agent Authority pursuant to section 5 of the Real Estate Agent Authority Act 2020.

EFFECT ON DATA SUBJECT RIGHTS — Where personal data are held in discharge of an obligation under FIAMLA, the Controller is entitled to refuse erasure by virtue of section 39(4)(c) of the Act, which excepts processing necessary for compliance with a legal obligation to which the controller is subject. The Controller will state this reason expressly when responding to such a request.

8.  RECIPIENTS AND DISCLOSURE

In discharge of section 23(2)(c) of the Act, the intended recipients of personal data are:

—  Notaries and attorneys.  Purpose of disclosure: Preparation and execution of deeds of sale, leases and related instruments.

—  Financial Intelligence Unit.  Purpose of disclosure: Suspicious transaction reports and currency transaction reports under FIAMLA.

—  Real Estate Agent Authority.  Purpose of disclosure: Regulatory supervision, complaints and inspections under the REAA Act 2020.

—  Data Protection Office.  Purpose of disclosure: Statutory notifications, investigations and enquiries under the Act.

—  Mauritius Revenue Authority and Registrar-General.  Purpose of disclosure: Registration duty, land transfer tax and tax compliance.

—  Economic Development Board.  Purpose of disclosure: Applications under property acquisition schemes and residence permit procedures.

—  Banks and financial institutions.  Purpose of disclosure: Payment processing, escrow and client account operations.

—  Vendors, purchasers, landlords, tenants and their advisers.  Purpose of disclosure: Conduct and completion of the transaction to which the data subject is a party.

—  Syndics, property managers and contractors.  Purpose of disclosure: Property management, maintenance, access and inventories.

—  Knight Frank network and referral partners.  Purpose of disclosure: Marketing of a property with the client's instruction, and qualified buyer referrals.

—  IT and communications providers.  Purpose of disclosure: Hosting, email, customer relationship management, analytics and archiving.

8.1  The Controller does not sell personal data. Personal data are not disclosed to any third party for that third party's own marketing purposes.

8.2   Every processor engaged by the Controller acts on documented instructions under a written contract imposing obligations of confidentiality, security and assistance, and is itself required to be registered under section 14 of the Act where it operates in Mauritius.

9.  TRANSFER OF PERSONAL DATA OUTSIDE MAURITIUS

9.1  The Act contains no adequacy mechanism. Section 36(1) prescribes an exhaustive list of gateways, and the Controller transfers personal data to another country only where one of them is satisfied.

9.2  The gateways relied upon by the Controller are:

(a) section 36(1)(a) — where proof of appropriate safeguards with respect to the protection of the personal data has been provided to the Commissioner;

(b) section 36(1)(b) — where the data subject has given explicit consent to the proposed transfer, after having been informed of the possible risks of the transfer owing to the absence of appropriate safeguards; and

(c) section 36(1)(c)(i) and (ii) — where the transfer is necessary for the performance of a contract between the data subject and the Controller, for the implementation of pre-contractual measures taken at the data subject's request, or for the conclusion or performance of a contract concluded in the interest of the data subject.

9.3  Transfers occur principally where a client is resident abroad and his file must be communicated to his own bank, notary, adviser or family office; where a property is marketed through an international network at the owner's instruction; and where the Controller uses information technology services hosted outside Mauritius.

9.4   The Controller notes that, under section 36(4) of the Act, the Commissioner may require it to demonstrate the effectiveness of the safeguards relied upon and may prohibit, suspend or impose conditions upon any transfer.

10.  RETENTION AND DESTRUCTION

Section 23(2)(h) of the Act requires the period of storage to be stated. Section 27(1) further imposes an affirmative duty: where the purpose for keeping personal data has lapsed, the Controller shall destroy the data as soon as is reasonably practicable and notify any processor holding them, and the processor shall likewise destroy them.

—  Customer due diligence records, account files, business correspondence and identity documents.  Retention period: Not less than 7 years after the business relationship has ended  Basis: FIAMLA, s. 17F(2)(a).

—  Transaction records sufficient to permit reconstruction of each transaction.  Retention period: 7 years after completion of the transaction  Basis: FIAMLA, s. 17F(2)(b).

—  Suspicious transaction reports and accompanying documentation.  Retention period: At least 7 years from the date the report was made  Basis: FIAMLA, s. 17F(2)(c).

—  Books of account and records of transactions conducted as agent.  Retention period: 7 years Basis: REAA Act 2020, s. 21.

—  Unconverted enquiries and viewing records.  Retention period: 24 months from last contact  Basis: Legitimate interests; s. 27 of the Act.

—  Marketing consents and preference records.  Retention period: Until consent is withdrawn, and 12 months thereafter as proof of withdrawal  Basis: s. 24(1) of the Act.

—  Website analytics and cookie data.  Retention period: As stated in clause 12, and not exceeding 14 months  Basis: Consent; legitimate interests.

10.1   Where a statutory retention period applies, the purpose for keeping the personal data has not lapsed within the meaning of section 27 of the Act until that period expires. Upon expiry, the records are destroyed or irreversibly anonymised.

11.  RIGHTS OF THE DATA SUBJECT

Part VII of the Act confers the following rights, which the Controller brings expressly to the attention of data subjects as required by section 40(4):

—  Access. Provision: s. 37 Substance: On written request: confirmation of processing, a copy of the data, and the information listed in s. 37(2).

—  Rectification and completion.  Provision: s. 39(1)  Substance: Inaccurate data rectified, and incomplete data completed, without undue delay.

—  Erasure. Provision: s. 39(2) Substance: Erasure without undue delay on the grounds stated, subject to the exceptions in s. 39(4).

—  Restriction of processing.  Provision: s. 39(5)  Substance: Processing restricted while accuracy is contested or an objection is verified.

—  Objection.  Provision: s. 40(1)  Substance: Written objection at any time, unless compelling legitimate grounds are demonstrated.

—  Objection to direct marketing.  Provision: s. 40(2)–(3)  Substance: Absolute: on objection, the data shall no longer be processed for that purpose.

—  Automated decision-making.  Provision: s. 38  Substance: Right not to be subject to a decision based solely on automated processing producing legal effects.

—  Complaint.  Provision: s. 6  Substance: Right to lodge a complaint with the Data Protection Commissioner.

EXERCISE OF RIGHTS AND TIME LIMITS

11.1  A request for access must be made in writing. The Controller shall, within one month of receipt of a request, inform the data subject in writing whether or not action has been taken, in accordance with section 37(5)(a). That period may be extended by one further month where necessary, taking into account the complexity and the number of requests, under section 37(5)(b).

11.2  Where the Controller refuses to take action, it shall, within one month of receipt of the request, inform the data subject in writing of the reason for the refusal and of the possibility of lodging a complaint with the Commissioner, in accordance with section 37(6).

11.3  No fee is charged. Where a request is manifestly excessive, the Controller may charge a fee or decline to act under section 37(7), in which case it bears the burden of proving the manifestly excessive character of the request.

11.4  Where the Controller has reasonable doubt as to the identity of the person making a request, it may require additional information to confirm identity, in accordance with section 37(1)(b).

11.5  Under section 41 of the Act, rights may be exercised on behalf of a minor by a person having parental authority or an appointed guardian; on behalf of a person physically or mentally unfit, by a guardian or legal administrator appointed by a Court; and in any other case by a person duly authorised in writing by the data subject.

11.6   The Act does not confer a right to data portability. Any request of that nature will be treated as a request for access under section 37.

12.  COOKIES AND WEBSITE DATA

12.1  Both Websites use cookies and similar technologies. Strictly necessary cookies are set without consent, being indispensable to the delivery of the service requested. All other categories are set only where the data subject has given consent through the cookie banner.

—  Strictly necessary.  Purpose: Session management, security, load balancing, language selection  Basis: Legitimate interests — no consent sought  Duration: Session to 12 months.

—  Functional.  Purpose: Saved searches, shortlisted properties, currency and unit preferences  Basis: Consent  Duration: Up to 12 months.

—  Analytics.  Purpose: Aggregated measurement of pages viewed, traffic sources and site performance  Basis: Consent  Duration: Up to 14 months.

—  Marketing.  Purpose: Measurement of advertising campaigns and retargeting Basis: Consent Duration: Up to 13 months.

12.2  Consent may be withdrawn at any time through the cookie preference centre on either Website, or by deleting cookies in the browser. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

12.3   Consent given on one domain does not extend to the other. A data subject accessing both immo.mu and stanford-realty.com will be asked for his cookie preferences separately on each.

13.  SECURITY AND PERSONAL DATA BREACH

13.1  In accordance with section 31 of the Act, the Controller implements appropriate technical and organisational measures having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of processing. These include access control on a need-to-know basis, encryption of identity and financial documents at rest and in transit, segregation of due diligence files, logging of access, contractual confidentiality obligations binding all staff and processors, and periodic review of those measures.

13.2  In the case of a personal data breach, the Controller shall, without undue delay and where feasible not later than 72 hours after having become aware of it, notify the breach to the Commissioner in accordance with section 25(1)(a) of the Act. Where notification is not made within that period, the reasons for the delay shall be provided to the Commissioner under section 25(1)(b). It is to be noted that the Act imposes no risk threshold: every personal data breach is notifiable to the Commissioner.

13.3  Where a personal data breach is likely to result in a high risk to the rights and freedoms of a data subject, the Controller shall communicate the breach to that data subject without undue delay in accordance with section 26(1), save where one of the exceptions in section 26(3) applies.

13.4   Any processor engaged by the Controller is required, under section 25(2) of the Act and by contract, to notify the Controller of a personal data breach without undue delay.

14.  MINORS

14.1  The Websites are not directed at minors and we do not knowingly collect personal data from minors through them.

14.2   Personal data relating to minors may nevertheless be processed where they form part of a family file in a transaction or a residence permit application. Such data are supplied by the person having parental authority, are limited to what is necessary for that purpose, and are never used for marketing.

15.  CONTACT, COMPLAINTS AND AMENDMENT

DATA PROTECTION CONTACT

15.1  Requests under Part VII of the Act, questions concerning this Agreement and withdrawals of consent are to be addressed in writing to the officer designated under section 22(2)(e) of the Act:

Data Protection Officer — Rocket Ventures Invest Ltd (Stanford Realty)

1st Floor, The Prestinct, Grand Baie, Republic of Mauritius

hello@immo.mu  ·  +230 5738 65-62

COMPLAINT TO THE COMMISSIONER

15.2  A data subject who considers that the Act has been, is being, or is about to be contravened may lodge a complaint with the Data Protection Commissioner, who shall investigate it in accordance with section 6 of the Act. A person aggrieved by a decision of the Commissioner may appeal to the ICT Appeal Tribunal within 21 days under section 51.

Data Protection Office, SICOM Tower, Wall Street, Ebene, Republic of Mauritius ·  +230 460 0251  ·  dataprotection.govmu.org

AMENDMENT AND GOVERNING LAW

15.3  The Controller may amend this Agreement to reflect changes in law, regulatory guidance or its processing operations. The version number and effective date appear on the first page, and the current version is published on both Websites. Where an amendment materially affects the data subject's rights, notice will be given by email to those data subjects with whom we are in an active business relationship.

15.4  This Agreement is governed by the laws of the Republic of Mauritius. The Courts of the Republic of Mauritius shall have exclusive jurisdiction, without prejudice to the statutory jurisdiction of the Data Protection Commissioner and of the ICT Appeal Tribunal.

15.5   Where any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions continue in full force and effect.

 

WEBSITES COVERED   www.immo.mu  ·  www.stanford-realty.com

CONTROLLER   Rocket Ventures Invest Ltd, trading as Stanford Realty

BUSINESS REG. NO.   C21184689

VAT REG. NO.   27998090

REGISTERED OFFICE   1st Floor, The Prestinct, Grand Baie, Republic of Mauritius

CONTACT   hello@immo.mu  ·  +230 5738 65-62

VERSION / EFFECTIVE   Version 1.0  ·  16 September 2026