top of page

MIFAIR · Governance & Trust

Privacy Policy

How the Mauritius Institute for Artificial Intelligence and Robotics (MIFAIR) collects, uses, protects and discloses your personal data, in accordance with the Data Protection Act 2017 of Mauritius.

1. Introduction

This Privacy Policy explains how the Mauritius Institute for Artificial Intelligence and Robotics ("MIFAIR", "we", "us" or "our") obtains, uses, discloses and protects your personal data when you visit our website at mifair.org, register your interest, become a member, attend our events or otherwise interact with us.

As an institute whose mission includes promoting responsible, ethical and trustworthy use of Artificial Intelligence and Robotics, we hold ourselves to the standards we advocate. We are committed to processing your personal data lawfully, fairly and transparently, in full compliance with the Data Protection Act 2017 of Mauritius (Act 20 of 2017) ("the DPA") and any regulations, codes of practice and guidelines issued under it.

2. Who we are

MIFAIR is a non-profit, non-partisan and independent institute operating under the laws of Mauritius, headquartered in Port Louis. Our purpose is to promote, research, train and support the responsible governance of Artificial Intelligence and Robotics for the sustainable and inclusive development of Mauritius and the broader African region.

For the purposes of the DPA, MIFAIR is the controller of the personal data described in this policy, and is registered (or in the process of registration) as a controller with the Data Protection Commissioner in accordance with Part III of the DPA. MIFAIR has designated an officer responsible for data protection compliance, who can be reached using the contact details in section 19.

3. Key definitions

In this policy, terms carry the meaning given to them in the DPA. In particular:

  • Personal data means any information relating to a data subject.

  • Data subject means an identified or identifiable individual — for example, someone identifiable by name, identification number, location data, an online identifier, or factors specific to their physical, economic, cultural or social identity.

  • Processing means any operation performed on personal data, whether or not automated — including collection, recording, storage, use, disclosure, erasure and destruction.

  • Consent means a freely given, specific, informed and unambiguous indication of your wishes, by statement or clear affirmative action, signifying your agreement to the processing of your personal data.

  • Special categories of personal data include data revealing racial or ethnic origin, political opinion, religious or philosophical beliefs, trade union membership, physical or mental health, sexual orientation, genetic or biometric data, and data relating to offences or proceedings.

4. The personal data we collect

We collect only the personal data that is adequate, relevant and limited to what is necessary for the purposes described in this policy. Depending on how you interact with us, this may include:

  • Identity and contact details — your name, email address, telephone number, organisation, job title or institutional affiliation, provided when you register your interest, apply for membership, subscribe to updates or contact us.

  • Membership information — your membership category (founding corporate, corporate, individual, student or other), organisation details where relevant, and records of contributions or payments.

  • Event and programme information — registrations, attendance and participation records for MIFAIR events, working groups, summits, competitions, workshops and training activities.

  • Correspondence — the content of enquiries, messages and feedback you send us.

  • Website usage information — technical data such as your Internet Protocol (IP) address, approximate location, device and browser type, browser language, pages visited, time spent on the site and links clicked, collected through cookies and analytics tools as described in section 11.

 

Where you provide personal data to us, we will indicate which information is required (mandatory) to deliver the relevant service — for example, an email address is required to respond to an enquiry or process a membership — and which information is optional.

5. How we collect your data

We collect personal data primarily directly from you, when you:

  • complete the registration-of-interest or contact form on our website;

  • apply for or renew a MIFAIR membership;

  • subscribe to our mailing list or communications;

  • register for or attend our events, working groups or programmes;

  • correspond with us by email, telephone or otherwise.

 

Where your personal data is provided to us by someone else — for example, where an organisation nominates you as its representative for a corporate membership, or a school registers students for an outreach activity — we will ensure that you are informed of the matters set out in this policy, as required by section 23 of the DPA.

6. Lawful basis for processing

We process personal data only where a lawful basis under section 28 of the DPA applies. Depending on the context, we rely on:

  • Your consent — for example, to send you newsletters and updates about MIFAIR's activities, or to publish photographs from events. You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

  • Performance of a contract — to administer your membership and provide the associated benefits, or to take steps at your request before entering into a membership arrangement.

  • Compliance with a legal obligation — for example, financial record-keeping, regulatory reporting and compliance with the DPA itself.

  • Legitimate interests — for the operation, administration, security and improvement of the Institute and its website, except where such processing would be unwarranted having regard to your rights, freedoms and legitimate interests.

 

In accordance with section 24 of the DPA, where we rely on your consent, MIFAIR bears the burden of proving that consent was given, and we will never make the provision of a service conditional on consent to processing that is not necessary for that service.

7. How we use your data

We use your personal data only for the explicit, specified and legitimate purposes for which it was collected, namely to:

  • respond to your enquiries and registrations of interest;

  • establish, administer and renew memberships, and communicate with members;

  • organise and manage events, working groups, research activities, education programmes and public engagement initiatives;

  • keep you informed of MIFAIR news, activities, research and opportunities, where you have subscribed or consented;

  • maintain the security, performance and integrity of our website;

  • produce aggregated, anonymised statistics on engagement with our work, for internal insight and reporting to partners and stakeholders — such statistics do not identify any individual;

  • comply with our legal and regulatory obligations.

 

We do not sell personal data, and we do not use personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you.

8. Special categories of personal data

MIFAIR does not seek to collect special categories of personal data through its website, membership process or general activities. If a specific programme ever requires such data — for example, dietary or accessibility requirements for an event — we will collect it only with the appropriate safeguards required by section 29 of the DPA, only for that specific purpose, and we will delete it once the purpose has lapsed.

9. Personal data of children

MIFAIR welcomes student participation, including from secondary school students, through free student membership and outreach activities. In accordance with section 30 of the DPA:

If you are under 16 years of age, we will not process your personal data unless consent is given by your parent or guardian. Where a registration involves a child below 16, we will make every reasonable effort, taking into account available technology, to verify that parental or guardian consent has been given.

School-based activities are coordinated through the participating school, and we ask schools to confirm that the necessary consents are in place before sharing student information with us.

10. Disclosure of your data

We do not disclose your personal data to third parties except as described below:

  • Service providers (processors) — providers of website hosting, email delivery, mailing-list management, event registration, payment processing and analytics services who process personal data on our behalf. In accordance with section 31(4) of the DPA, we choose processors that provide sufficient guarantees of security, and we enter into written contracts requiring them to act only on our instructions and to apply the same security obligations that bind MIFAIR.

  • Partners — where you participate in a jointly delivered programme (for example, a co-hosted event or research collaboration), we may share your registration details with the co-organising partner, and we will tell you at the point of collection when this applies.

  • Legal requirements — where we have a duty or right to disclose under the laws of Mauritius, including to the Data Protection Office, or where disclosure is necessary for the establishment, exercise or defence of a legal claim.

 

Any disclosure incompatible with the purposes for which your data was collected is an offence under section 42 of the DPA, and MIFAIR does not make such disclosures.

11. Cookies and analytics

Our website uses cookies — small files placed on your device that generally contain an anonymous unique identifier — to enable core functionality and to collect standard visitor usage information. We may use analytics services (such as Google Analytics) to understand how visitors use our website; the information collected includes your IP address, approximate location, device and browser characteristics, and browsing activity on our site. The analytics provider's own privacy policy applies to its handling of this data.

You can enable, disable or delete cookies at any time through your browser settings. Disabling cookies may limit some website functionality. Engagement metrics shared with partners or stakeholders are aggregated and stripped of personal data before sharing.

12. Security of processing

In accordance with section 31 of the DPA, we implement appropriate security and organisational measures to prevent unauthorised access to, alteration of, disclosure of, accidental loss of, or destruction of personal data in our control, proportionate to the harm that might result and the nature of the data concerned. Our measures include:

  • access controls limiting personal data to those who need it for their role;

  • encryption of data in transit, and pseudonymisation or encryption of stored data where appropriate;

  • measures to ensure the ongoing confidentiality, integrity, availability and resilience of our processing systems;

  • the ability to restore availability and access to personal data in a timely manner after a physical or technical incident;

  • regular testing, assessment and evaluation of the effectiveness of these measures;

  • ensuring that everyone working for or with MIFAIR is aware of, and complies with, our security measures.

13. Retention and destruction

We keep personal data in a form that permits your identification for no longer than is necessary for the purposes for which it was collected. Indicatively:

  • membership records are retained for the duration of membership and for a limited period thereafter as required for legal, accounting and audit purposes;

  • enquiry correspondence is retained only as long as needed to handle and follow up the enquiry;

  • mailing-list data is retained until you unsubscribe or withdraw consent;

  • event records are retained for the administration and reporting of the relevant activity.

 

In accordance with section 27 of the DPA, once the purpose for keeping personal data has lapsed, we destroy the data as soon as is reasonably practicable and notify any processor holding the data to do the same.

14. Transfers of personal data outside Mauritius

Some of our service providers (for example, email or analytics platforms) may store or process data on servers located outside Mauritius. Where personal data is transferred outside Mauritius, we do so only in accordance with section 36 of the DPA — that is, where appropriate safeguards for the protection of the data are in place, where you have given explicit consent to the transfer after being informed of the possible risks, or where another condition under section 36 applies (for example, the transfer is necessary for the performance of a contract with you). The Data Protection Commissioner may request proof of the effectiveness of these safeguards at any time.

15. Personal data breaches

In the event of a personal data breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data — MIFAIR will:

  • notify the Data Protection Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with section 25 of the DPA; and

  • where the breach is likely to result in a high risk to your rights and freedoms, communicate the breach to you without undue delay, in clear language, together with recommended measures to mitigate its possible adverse effects, in accordance with section 26 of the DPA.

16. Your rights as a data subject

Under Part VII of the DPA, you have the following rights in relation to your personal data. All requests can be made using the contact details in section 19.

Right
What it means
Withdraw consent
Where processing is based on your consent, you may withdraw it at any time — for example, by using the unsubscribe link in any newsletter — without affecting processing carried out before withdrawal.
Automated decisions
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or significantly affects you. MIFAIR does not carry out such processing.
Objection
You may object in writing at any time to the processing of your personal data. Where you object to processing for direct marketing (including any related profiling), we will stop that processing — this right is absolute.
Restriction
You may ask us to restrict processing — for example, while the accuracy of your data is being verified, or where you require the data for a legal claim after we no longer need it.
Erasure
You may ask us to erase your personal data where it is no longer necessary for the purpose collected, where you withdraw consent and no other legal ground applies, where you object and no overriding legitimate ground exists, or where the data has been unlawfully processed.
Rectification
You may ask us to correct inaccurate personal data, or complete incomplete data, without undue delay.
Access
You may request, free of charge, confirmation of whether we process personal data relating to you and a copy of that data, together with information about the purposes, categories, recipients, retention period and safeguards involved. We will respond within one month of your request (extendable by a further month for complex requests, in which case we will tell you).

To protect your data, we may ask for proof of identity before acting on a request. If we refuse to act on a request, we will tell you in writing within one month of receiving it, with the reason for the refusal and your right to lodge a complaint with the Data Protection Commissioner. Rights may also be exercised on your behalf by a parent or guardian (for minors), a court-appointed guardian or administrator, or a person you have duly authorised in writing.

17. Complaints

If you believe that we have processed your personal data in contravention of the DPA, we encourage you to contact us first so that we can try to resolve the matter directly. You also have the right at any time to lodge a complaint with the:

Data Protection Office
Data Protection Commissioner
Port Louis, Republic of Mauritius
dataprotection.govmu.org

18. Changes to this policy

We may revise this Privacy Policy from time to time, for example to reflect changes in our activities, in the law or in guidance issued by the Data Protection Office. The current version will always be published on this page with its "last updated" date, and we will highlight material changes through our website and, where appropriate, our mailing list.

19. How to contact us

For any question about this policy, our privacy practices, or to exercise any of your rights, please contact:

MIFAIR — Mauritius Institute for Artificial Intelligence and Robotics
Attention: Data Protection Compliance Officer
Chemin La Coline Nirvanna Villa Pointe Aux Canonniers, Republic of Mauritius
Email: contact@mifair.org
Website: www.mifair.org

This Privacy Policy is issued pursuant to the Data Protection Act 2017 of Mauritius. Nothing in this policy limits any right you have under the DPA or any other applicable law.

bottom of page