Back to site
Legal

Privacy Policy

Effective from 1 January 2026 · Aphelion Ltd.

This Privacy Policy explains how Aphelion Ltd. collects, uses, discloses and safeguards personal data when delivering our cloud, AI, cybersecurity and managed services, and when you interact with our website. We are committed to protecting your privacy and complying with the Mauritius Data Protection Act 2017, the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Data controller

Aphelion Ltd. (“Aphelion”, “we”, “us”) is the data controller for personal data collected through this website and during the delivery of our services. Our registered address is 2nd Floor, KL House, M3 Motorway, Riche Terre, Pamplemousses, Mauritius. You can contact our Data Protection Officer at dpo@aphelion-group.com.

2. Personal data we collect

We collect the following categories of personal data:

  • Contact data — name, job title, company, work email and phone number submitted via our contact, lead-magnet or newsletter forms.
  • Account data — credentials and profile information for client portals and service-management tools.
  • Service data — technical data processed on your behalf when delivering managed cloud, security (including Broadsword MDR) and AI services, which may include logs, configurations and user activity you provide to us.
  • Usage data — anonymised analytics data such as pages visited, scroll depth and conversion events, collected via our analytics tooling.

3. Lawful basis for processing

Under the GDPR and the Mauritius Data Protection Act 2017, we process personal data on the following lawful bases:

  • Contract — to deliver services under our client agreements and to respond to your requests for proposals, assessments and support.
  • Consent — for marketing communications (such as our newsletter) and for non-essential analytics. You may withdraw consent at any time.
  • Legal obligation — to comply with regulatory, tax, accounting and legal requirements.
  • Legitimate interests — for network and information security, fraud prevention, and internal operations, balanced against your rights and expectations.

4. How we use your data

We use personal data to:

  • Respond to enquiries, deliver assessments and provide contracted services;
  • Operate, monitor and secure the infrastructure and platforms we manage for you;
  • Send service-related communications, alerts and reports;
  • Send marketing and thought-leadership content where you have consented;
  • Comply with legal, regulatory and contractual obligations.

5. Data sharing and sub-processors

We do not sell personal data. We share it only with sub-processors who support our service delivery (for example cloud and hosting providers, security tooling, and email/CRM platforms), each under written agreement imposing equivalent data-protection obligations. A current list of sub-processors is available on request. We may also disclose data where required by law.

6. International data transfers

As we serve clients across Africa, Europe and the Indian Ocean, personal data may be processed outside Mauritius. Where data leaves Mauritius or the European Economic Area, we rely on applicable safeguards including adequacy decisions, Standard Contractual Clauses or other lawful transfer mechanisms, and we document the transfer in our records.

7. Data retention

We retain personal data only for as long as necessary to fulfil the purposes set out above, to meet legal and contractual obligations, and to establish, exercise or defend legal claims. Service-related data is retained for the duration of the engagement plus a defined wind-down period agreed in your contract. Marketing data is retained until you withdraw consent or a defined inactivity period elapses.

8. Data security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, multi-factor authentication, network segmentation, 24/7 security monitoring (Broadsword MDR), regular penetration testing and staff security-awareness training. Despite these measures, no system can be guaranteed to be completely secure.

9. Your rights

Subject to applicable law, you have the right to:

  • Access, rectify or erase your personal data;
  • Restrict or object to processing;
  • Data portability;
  • Withdraw consent at any time (without affecting processing already carried out);
  • Lodge a complaint with the supervisory authority (the Mauritius Data Protection Office or your local EU data-protection authority).

To exercise any of these rights, email dpo@aphelion-group.com. We will respond within one month, or as required by applicable law.

10. Cookies

Our website uses a minimal set of cookies and local-storage items for analytics and preference persistence. We do not use cookies for intrusive cross-site advertising tracking. Where consent is required, it is requested before the relevant cookie is set and can be withdrawn at any time.

11. Changes to this policy

We may update this Privacy Policy from time to time. The effective date above indicates when the current version took effect. Material changes will be communicated through our website or directly to affected clients.

Aphelion Ltd.
2nd Floor, KL House
M3 Motorway, Riche Terre
Pamplemousses, Mauritius
Email: info@aphelion-group.com · Phone: +230 248 3744