Privacy Notice
CS & Partner Consulting Ltd.
1. Introduction
CS & Partner Consulting Ltd. (“we”, “us”, “the Company”) takes the protection of your personal data very seriously.
This Privacy Notice explains which personal data we process when you visit our website www.cspc.mu, for what purposes we process this data, and which rights you have under the Mauritius Data Protection Act 2017 (DPA 2017).
By using this website, you consent to the processing of your personal data in accordance with this Privacy Notice.
2. Data Controller
CS & Partner Consulting Ltd.
24 AVE des Hirondelles Sodanc
72249 Quatre Bornes
Republic of Mauritius
E-mail: privacy-notice (at) cspc.mu
We are not legally required to appoint a Data Protection Officer. However, you may contact us regarding any data protection matters using the e-mail address above.
3. Personal Data We Process
3.1 Automatically collected data (server and technical data)
When you visit our website, the following information is automatically collected:
- IP address
- Date and time of access
- Browser type and version
- Operating system
- Referrer URL
- Pages visited
- General geolocation data (e.g., country)
This data is necessary for the technical operation, security, and optimization of our website.
3.2 Data you voluntarily provide
When you use our contact form, we process the following information:
- Name
- E-mail address
- Telephone number (optional)
- Company name (optional)
- Message content
- Uploaded documents (if applicable)
4. Purposes of Data Processing
We process your personal data for the following purposes:
- Operation and technical provision of the website
- Responding to contact and business inquiries
- Improving the stability, security, and functionality of the website
- Analysing user behaviour (anonymised or based on consent)
- Compliance with legal obligations
We do not use your personal data for automated decision-making.
5. Legal Basis for Processing
We process your data based on:
- Your consent (e.g., when submitting a contact form)
- Our legitimate interest in providing a secure and functioning website
- Legal obligations, where applicable
6. Cookies and Analytics Tools
6.1 Cookies
Our website uses cookies to:
- ensure basic functions (technically necessary cookies)
- improve website performance
- analyse usage behaviour (only with your consent)
If required, a cookie banner will appear allowing you to grant or refuse consent.
6.2 Analytics tools
If we use tools such as Google Analytics, Matomo, or similar, analytics data is processed only with your consent. Any international transfer of analytics data is carried out in accordance with the safeguards required under Section 36 of the Mauritius DPA 2017.
7. Disclosure of Your Data
Your personal data is disclosed only to:
- technical service providers (hosting, security, analytics)
- authorised internal employees
- companies within the Brüderlinpartner Group, where required for business communication
We do not sell your data or disclose it to unauthorised third parties.
8. International Data Transfers
If data is processed outside Mauritius (e.g., in Switzerland, Germany, or the EU), such transfers occur:
- only where required for business communication
- exclusively to trusted partners and service providers
- in compliance with the safeguards defined in Section 36 of the DPA 2017
- only to the extent necessary
9. Data Retention
- Server log files are generally stored for 30–90 days.
- Contact inquiries are stored for up to 12 months, unless longer retention is necessary for business communication.
- Upon request, we will erase your data earlier, provided no legal obligations prevent deletion.
10. Your Rights Under the Data Protection Act 2017
You have the following rights at any time:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to object
- Right to withdraw consent
- Right to data portability
- Right to lodge a complaint with the Data Protection Office Mauritius
For all requests, please contact:
privacy-notice (at) cspc.mu
11. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- SSL-encrypted data transmission
- Access restrictions
- Secure hosting environment
- Regular internal security controls
- Data minimisation
12. Updates to This Privacy Notice
We may update this Privacy Notice when necessary.
The most current version will always be available on our website.