This website is owned, operated, hosted and maintained by Bloomsbury LLP.
This notice applies to Bloomsbury LLP only. This notice applies where we are acting as a data controller with respect to the personal data of our website visitors, physical site visitors and other data subjects.
We are committed to safeguarding the privacy of data subjects, including our website visitors and physical site visitors. As a result, we would like to inform you regarding the way we would use your personal data, as is required by the European Union General Data Protection Regulation (hereafter the “GDPR”) and the Data Protection Act 2017 (hereafter the “DPA”) where applicable. We recommend you read this Privacy Notice so that you understand our approach towards the use of your personal data.
Our Privacy Notice sets out the types of personal data we collect, how we collect and process that data, who we may share this information with and the rights you have in this respect.
As data controllers, we determine the purposes and means of the processing of that personal data. We also comply with our obligations as a data processor under the DPA and the GDPR.
Bloomsbury LLP (The “firm”) is a firm of Chartered Accountants in Mauritius and is a Member Firm of the Mauritius Institute of Professional Accountants (“MIPA”), providing pioneering audit services.
For more information, please refer to the “About” section on our website at:
http://www.bloomsbury.mu/.
We need to collect personal data to effectively carry out our everyday business functions and activities and to provide the services in connection with our business. Such data is collected from our website visitors, physical site visitors and other data subjects (but is not limited to), name, address, email address, date of birth, identification numbers, private and confidential information, special categories of personal data and bank details.
The principal place of business of the firm is at 1st Floor, Sterling Tower, Office 101-102, 14 Poudrière Street, Port Louis, Mauritius.
Personal data is any data from which you can be identified, and which relates to you.
The type of data we collect will depend on the purpose for which it is collected and used. We will only collect data that we need for that purpose.
We may collect your personal data in the following ways:
The types of personal data that are collected and processed may include:
|
Categories of Personal Data: |
Details: |
|
Contact details |
First name, surname, email address, office phone and cell phone. |
|
IT information |
IP addresses, browser type and version, access time and length of access, page views, user activity and website usage in log files. |
|
Physical security information |
Information recorded in Bloomsbury visitors’ logbook (reason for visit, organisation name, identification measures used, date and time of visit), CCTV footage. |
|
Special categories of personal data |
Body temperature checks (If any) for compliance with COVID-19 and/or health procedures. |
We use cookies on our website. Insofar as those cookies are not strictly necessary for the provision of our website and services, we will ask you to consent to our use of cookies when you first visit our website.
The firmwill only use your personal data for the purposes for which it was collected or agreed with you. We will not use your personal data for any automated individual decision making which will have a significant impact on you.
We have set out below the legal basis of processing for each purpose. Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your personal data.
|
Purpose of processing |
Legal basis |
|
For the purposes of record keeping |
For compliance with a legal obligation to which we are subject to, such as internal/external audit and retention periods |
|
For the purpose of analysing the use of our website |
Consent OR Legitimate interests, namely of monitoring and improving our website and services] |
|
For the purpose of monitoring compliance with our policies and standards |
Legitimate interests, namely of monitoring and improving our website, business and services |
|
For the purposes of ensuring the security of our website and maintaining back-ups of our databases |
Legitimate interests, namely the proper administration of our website and business |
|
For the purposes of confirming and verifying your identity when you request to access, rectify, restrict or delete the information we hold on you |
For compliance with a legal obligation to which we are subject to, that is, to verify the identity of a data subject who makes a subject rights request |
|
For the purposes of replying to any requests, complaints, comment, or enquiries you submit to us regarding our services and notifying you about changes to our service |
Performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract Legitimate interests namely for proper administration of our business and communication with users. |
|
Processing CCTV footage captured on our premises for the purposes of: - protecting our premises and property, - protecting your personal safety when you are on our premises, - identifying any misconduct or disciplinary infringements in our compound, - assisting in providing evidence for such misconduct, |
Legitimate interests of ensuring physical security and proper conduct on our premises. |
|
Purpose of processing |
Legal basis |
|
- for investigating, detecting or preventing crime, and - for apprehending and prosecuting offenders. |
In addition to the above-mentioned specific purposes for which we may process your personal data, we may also process any of your personal data where such processing is necessary for compliance with legal and regulatory requirements which apply to us, or when it is otherwise allowed by law, or when it is in connection with legal proceedings.
In general, we do not share your personal information with third parties (other than service providers acting on our behalf) unless we have a lawful basis for doing so.
We may also make certain personal data available to third party companies that provide us software and tools relevant for our business operations.
We may also be required to disclose your personal data to other third parties such as lawyers, bankers, consultants, insurers, auditors as well as public and government authorities for purposes mentioned in Section 5 or where:
We require our service providers and other third parties to keep your personal data confidential and that they only use the personal data in furtherance of the specific purpose for which it was disclosed. We have written agreements in place with our processors to ensure that they comply with these privacy terms.
We may transfer, or store, your personal data outside Mauritius as may be necessary for the purposes mentioned above.
These transfers would always be made in compliance with the GDPR and/or the DPA. Data transfers do not change any of our commitments to safeguard your privacy and your personal data remains subject to existing confidentiality obligations.
If we transfer your personal data to other countries which provide a lower level of protection, we will ensure that there are appropriate safeguards in place with regard to the protection of your personal data, such as by using:
If you would like further details on the transfer of your personal data outside Mauritius, please contact our Data Protection Officer/ Privacy Champion (hereafter “DPO”).
We are legally obliged to provide adequate protection for the personal data we hold. We have put in place appropriate security measures to prevent your personal data from being subject to any accidental or unlawful destruction, loss, alteration, and any unauthorised disclosure or access.
We have also put in place procedures to deal with any suspected data security breach and will notify you and the Data Protection Office of a suspected breach where we are legally required to do so.
We will, on an on-going basis, continue to review our security controls and related processes to ensure that your personal data is secure.
Our security policies and procedures cover:
When we contract with third parties, we impose appropriate security, privacy and confidentiality obligations on them to ensure that personal data that we remain responsible for is kept secure.
We will ensure that anyone to whom we pass your personal data agrees to treat your data with the same level of protection as we are obliged to.
Under the GDPR and the DPA, you have rights we need to make you aware of. The rights available to you depend on our reason for processing your information.
You have the right to ask us to delete your personal data in certain circumstances:
Where we collect personal data for a specific purpose, we will not keep it for longer than is necessary to fulfil that purpose, unless we have to keep it for legitimate business or legal reasons. Upon the determined expiry date, we will securely destroy your personal data. Retention periods are indicated in Annex A’s Records Retention and Disposal Schedule. When we delete data from our servers, no residual copies remain on our servers. Data from our backup tapes are also deleted depending on the next scheduled backup overwrite which may be on a weekly, monthly or yearly basis in accordance with its configuration.
You have the right to request a copy of the personal data we hold about you. To do this, simply contact our DPO (refer to Section 11.1) and specify what data you would like. We will take all reasonable steps to confirm your identity before providing details of your personal data.
You will not have to pay a fee to access your personal data (or to exercise any of your other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
You have the right to ask us to update or correct your personal data if you think it is inaccurate or incomplete. We will take all reasonable steps to confirm your identity before making changes to personal data we may hold about you. We would appreciate it if you would take the necessary steps to keep your personal data accurate and up-to-date by notifying us of any changes we need to be aware of.
You have the right to ask us to limit how we use your data. If necessary, you may also stop us from deleting your data. To exercise your right to restriction, simply contact our DPO (refer to Section 11.1), say what data you want restricted and state your reasons. You may request us to restrict processing of your personal data in the following circumstances:
You also have the right to object to us processing your personal data where your data is being used:
We currently process personal data for our legitimate interests. You should contact our DPO (refer to Section 11.1) to inform that you are objecting to any more processing of your personal data and state in your objection why you believe we should stop using your data in this way. Unless we believe we have strong legitimate reasons to continue using your data in spite of your objections, we will stop processing your data as per the objection raised.
The right to data portability allows you to ask for transfer of your personal data from one organisation to another, or to you. The right only applies if we are processing information based on your consent or performance of a contract with you, and the processing is automated. You can exercise this right with respect to information you have given us by contacting our DPO (refer to Section 11.1). We will ensure that your data is provided in a way that is accessible and machine-readable.
To the extent that the legal basis for our processing of your personal information is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.
If you wish to exercise any of the rights set out above, please contact our DPO (refer to Section 11.1).
We keep our privacy notice under regular review. We reserve the right to change our privacy notice at any time thus we encourage you to periodically review this notice to be informed of how we are using and protecting your personal data. We will notify you of significant changes by a pop-up on the website. This version was last updated on the 14 March 2025.
The primary point of contact for questions relating to this privacy notice, including any requests to exercise your legal rights, is our DPO who can be contacted by email at:
If you believe we have not handled your request in an appropriate manner, you have the right to complain to the Data Protection Office.
The procedure to file a complaint with the Data Protection Office is available on https://dataprotection.govmu.org/Pages/Home%20-%20Pages/Take%20Action/To-report-your-Complaint.aspx
The table below sets specific retention requirements:
|
Categories of Personal Data |
Purpose of processing |
Retention period |
|
Contact details |
The firm’s visitors’ logbook records, complaints handling |
7 years |
|
IT information |
Website Management |
7 years |
|
Physical security information |
Security/ Identifying disciplinary infringement/ Investigation, detection & prevention of crime |
7 years |
|
Special categories of personal data |
The firm’s visitors’ logbook records |
3 months |