GDPR Compliance
Effective from 1 January 2026 · Aphelion Ltd.
Aphelion Ltd. is committed to protecting the personal data of our clients, their end users and our website visitors. This page summarises how we comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Mauritius Data Protection Act 2017 (“DPA”) — two frameworks that are closely aligned in their principles and in the rights they confer on individuals.
1. Our roles
When delivering managed cloud, security and AI services on behalf of a client, Aphelion acts as a data processor, processing personal data only on the client’s documented instructions under a Data Processing Agreement (DPA). When operating our website, marketing and direct client relationships, we act as a data controller. Our Privacy Policy explains our controller activities in detail.
2. Lawful basis and purpose limitation
We process personal data only where a lawful basis exists (contract, legal obligation, consent or legitimate interests) and only for the specified, explicit purposes communicated to data subjects. We do not reuse personal data for incompatible purposes without a fresh lawful basis or consent.
3. Data minimisation and accuracy
We collect only the personal data necessary for the stated purpose and keep it accurate and up to date. Where we process data on a client’s behalf, we rely on the client to define and provide the data sets required, and we flag obviously inaccurate data back to the client for correction.
4. Storage limitation and retention
Personal data is retained only for as long as necessary for the purpose for which it was collected, to meet legal or contractual obligations, or to establish, exercise or defend legal claims. Our retention schedule is documented per data category and reviewed annually. Service-related data is retained for the engagement term plus the agreed wind-down period defined in the client contract.
5. Integrity and confidentiality (security)
We implement appropriate technical and organisational measures, including:
- Encryption in transit (TLS) and at rest;
- Role-based access control and least-privilege principles;
- Multi-factor authentication for all administrative and privileged access;
- 24/7 security monitoring and managed detection & response via our Broadsword platform;
- Network segmentation and private connectivity between services by default;
- Regular penetration testing and continuous vulnerability scanning;
- Staff security-awareness training and phishing simulations;
- Documented incident-response and breach-notification runbooks.
6. International data transfers
Personal data may be processed outside Mauritius and outside the European Economic Area as part of delivering Services across Africa, Europe and the Indian Ocean. Where this occurs, we rely on applicable safeguards — adequacy decisions, Standard Contractual Clauses (SCCs) approved by the European Commission, binding corporate rules (where relevant) or other lawful transfer mechanisms — and we document each transfer in our records of processing activities.
7. Sub-processors
We engage sub-processors only under written agreements that impose data-protection obligations no less protective than those we owe our clients. A current list of sub-processors is maintained and made available to clients on request, and we provide advance notice of any proposed addition or replacement of a sub-processor.
8. Data subject rights
We support our controller clients in fulfilling data-subject requests (access, rectification, erasure, restriction, objection, portability and rights related to automated decision-making). As a processor, we action requests only on the client’s documented instructions, except where an individual contacts us directly — in which case we forward the request to the relevant controller without delay.
9. Personal data breach management
We maintain a documented incident-response process. In the event of a personal data breach affecting client data, we notify the affected client without undue delay (and in any case within the timeframe required by the applicable DPA or our agreement), provide the information reasonably required for the client to assess and meet its own notification obligations, and cooperate in remediation and investigation. Breaches are logged internally for regulatory accountability.
10. Records of processing and accountability
We maintain records of processing activities as required by Article 30 of the GDPR and the equivalent DPA provision, conduct data protection impact assessments (DPIAs) for high-risk processing, and appoint a Data Protection Officer who can be reached at dpo@aphelion-group.com.
11. Audits and certifications
We support reasonable client audits of our data-protection controls subject to the terms of the applicable agreement, and we maintain alignment with recognised frameworks including ISO 27001 controls and GDPR/DPA requirements. Information on current certifications is available on request.
12. Supervisory authority
Individuals have the right to lodge a complaint with the supervisory authority in their jurisdiction. In Mauritius this is the Data Protection Office (dataprotection.govmu.org); in the EU, the local data-protection authority of the individual’s habitual residence or place of the alleged infringement. We encourage individuals to contact us first so we can address concerns directly.