Last updated: 19 August 2026
This policy is a working draft prepared as a starting point. Please have it reviewed by a qualified data protection or legal adviser, and replace every bracketed placeholder, before the site goes live.
1. Who is responsible for your data
The Mayfair Practice (BRN 116010958), of 3 Closel Road, Vacoas-Phoenix, Plaines Wilhems, 73417, Mauritius, is the data controller for the personal data described in this policy. You can reach us at mdeonaran@mayfair-practice.com. Our data protection contact is [DPO / RESPONSIBLE PERSON].
We handle personal data in accordance with the Data Protection Act 2017.
2. What we collect
When you use this website
- Information you give us in an enquiry form or by email — typically your name, contact details and whatever you choose to tell us about your reason for getting in touch.
- Technical data collected automatically by our hosting provider, such as IP address, browser type and the pages you visited, used to keep the site secure and working.
When you become a client
- Contact and identity details, and where relevant those of your GP, next of kin or referrer.
- Clinical records: assessment notes, session notes, formulations, correspondence, outcome measures and any reports prepared.
- Health information, which is "special category" data and is given particular protection.
- Appointment and payment records.
3. Why we use it, and our lawful basis
- To respond to your enquiry — because it is in our legitimate interests to answer people who contact us, or because we are taking steps at your request before entering a contract.
- To provide clinical services and keep records — performance of our contract with you, and, for health data, because processing is necessary for the provision of health care by a professional bound by an obligation of confidentiality.
- To meet our professional, regulatory, insurance and legal obligations — compliance with a legal obligation, and our legitimate interests in defending claims.
- To take payment and keep accounting records — performance of our contract and compliance with a legal obligation.
- To keep the website secure — our legitimate interests in protecting the site and its users.
Where we rely on your consent — for example to write to your GP, or to send you occasional practice updates — you can withdraw it at any time without affecting anything done before you withdrew it.
4. Who we share it with
We do not sell your data and we do not share it for marketing. We may share it with:
- Clinical supervisors, in line with our professional obligations, using the minimum identifying detail necessary.
- Service providers who process data on our behalf under contract — for example our website host, email provider, [PRACTICE MANAGEMENT SYSTEM] and [ACCOUNTING PROVIDER].
- Your GP or another healthcare professional, where you have asked us to or where disclosure is necessary to protect someone from serious harm.
- Regulators, insurers, legal advisers or courts, where we are required or entitled to do so by law.
5. Where your data is held
Your data is stored [WHERE — e.g. on servers located in the EU]. Where a provider transfers data outside Mauritius, we take steps to ensure an equivalent standard of protection through [SAFEGUARD — e.g. standard contractual clauses].
6. How long we keep it
- Enquiries that do not become clients: 12 months.
- Adult clinical records: 7 years from the end of contact.
- Records concerning children and young people: until the client's 25th birthday, or their 26th birthday if they were 17 when treatment ended.
- Financial records: 5 years, as required by tax law.
At the end of the retention period, records are securely deleted or destroyed.
7. How we keep it safe
Written clinical notes are stored securely in a locked cabinet, with access restricted to authorised persons who require the information for legitimate professional purposes. Electronic clinical records are stored on a secure online platform and protected by appropriate access controls and security measures. We regularly review how information is stored and protected. However, no storage or communication system can be guaranteed to be completely secure. As standard email may not provide adequate protection for sensitive information, clients should not send detailed clinical information by email unless a secure method has been agreed in advance.
8. Your rights
Subject to certain conditions, you have the right to:
- Ask for a copy of the personal data we hold about you.
- Ask us to correct data that is inaccurate or incomplete.
- Ask us to delete data, or to restrict how we use it.
- Object to processing we carry out on the basis of legitimate interests.
- Ask us to transfer certain data to another provider.
- Withdraw consent where our processing relies on it.
These rights are not absolute — for example, we may need to keep clinical records for a defined period even if you ask us to delete them. To exercise a right, write to mdeonaran@mayfair-practice.com. We will respond within one month.
9. Cookies
This website does not set analytics or advertising cookies. It loads fonts from Google Fonts, which means your browser makes a request to Google's servers and Google may log your IP address for that purpose. If we add analytics or embedded content in future, we will update this policy and, where required, ask for your consent first.
10. Complaints
If you are concerned about how we have handled your data, please tell us first at mdeonaran@mayfair-practice.com. You also have the right to complain to a supervisory authority:
- Data Protection Office (Mauritius) — 5th Floor, SICOM Tower, Wall Street, Ebène, Republic of Mauritius. Telephone +230 460 0251. Email dpo@govmu.org. Website dataprotection.govmu.org.
- Information Commissioner's Office (United Kingdom) — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. Website ico.org.uk.
11. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it was last changed, and material changes affecting current clients will be communicated directly.