Privacy Policy
This Privacy Policy explains how Aphelion Ltd(“Foundation One”, “we”, “us”, “our”) collects, uses, discloses and protects personal data when you visit our website at f1.aphelion.cloudor use the Foundation One platform (the “Service”). We operate as both a data controller (for our website and direct marketing) and a data processor (for personal data our customers process through the Service).
This Privacy Policy is governed by the Data Protection Act 2017 of Mauritius(the “DPA 2017”), which is the primary law applicable to Aphelion Ltd as a Mauritius-incorporated entity. It is also drafted to meet the equivalent requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR, given the cross-border nature of our Service. Where both regimes apply, the higher standard prevails.
Foundation One is operated under the regulatory framework of the Financial Services Commission (FSC) of Mauritius and the Bank of Mauritius, and processes personal data under the supervision of the Data Protection Commission (DPC) of Mauritius. Foundation One launches on 1 October 2026; this policy takes effect from that date.
1. Who we are
Foundation One is operated by Aphelion Ltd, a company incorporated in the Republic of Mauritius under the Companies Act 2001, with its registered office at 2nd Floor, KL House, M2 Motorway, Riche Terre, 21813 Mauritius. We act as a financial services intermediary authorised and supervised by the Financial Services Commission, Mauritius. For data protection enquiries, contact our Data Protection Officer at dpo@aphelion-group.com.
2. Personal data we collect
2.1 Data you provide directly
- Marketing & demo requests: name, work email, company, role, firm type, assets administered, and any message submitted via our demo-request form.
- Account & identity: name, email, role and authentication data when a customer provisions a Foundation One account.
- Customer support: correspondence and any data you share when contacting support.
2.2 Data collected automatically
- Usage data: IP address, browser type, device, pages visited, referring URLs and timestamps. See our Cookie Policy.
- Service telemetry: audit logs, error logs and performance metrics needed to operate and secure the Service.
2.3 Customer-processed data
When you use Foundation One to administer trusts, companies, portfolios and compliance, you may upload personal data of your clients, beneficial owners, directors and beneficiaries (“Client Personal Data”). We process this data only as your processor under the terms of our Data Processing Addendum.
3. How we use personal data
Under section 21 of the Mauritius Data Protection Act 2017, processing is lawful only where a valid condition is met. The table below sets out each purpose alongside the DPA 2017 basis and, where applicable, the equivalent GDPR article for customers operating in the EU/EEA or UK.
| Purpose | Lawful basis — Mauritius DPA 2017 | GDPR equivalent |
|---|---|---|
| Responding to demo requests and enquiries | s.21(2)(c) — legitimate interests | Art. 6(1)(f) |
| Providing, maintaining and securing the Service | s.21(2)(b) — performance of a contract | Art. 6(1)(b) |
| Billing and account administration | s.21(2)(b) — performance of a contract | Art. 6(1)(b) |
| Product analytics and improvement | s.21(2)(c) — legitimate interests | Art. 6(1)(f) |
| Security, fraud prevention and audit | s.21(2)(a) & (d) — consent and legal obligation | Art. 6(1)(a) & (c) |
| Direct marketing (only where opted in) | s.21(2)(a) — consent | Art. 6(1)(a) |
| Compliance with legal & regulatory obligations (incl. FSC, FIU, MRA) | s.21(2)(d) — legal obligation | Art. 6(1)(c) |
4. Sharing and disclosure
We share personal data only as necessary to deliver the Service or where required by law:
- Sub-processors hosting, infrastructure and tooling providers — listed in the DPA and bound by written terms no less protective than this policy.
- Professional advisers (lawyers, auditors) where needed for advice or compliance.
- Mauritius regulators and authorities where we are legally compelled — including the Financial Services Commission (FSC), the Financial Intelligence Unit (FIU) for AML/CFT matters, the Mauritius Revenue Authority (MRA) for tax, and the Data Protection Commission (DPC) for data-protection investigations.
- Foreign regulators and tax authorities where bilateral or multilateral cooperation agreements (such as FATCA, CRS/AEOI or MLATs) require disclosure.
- Corporate transactions — a successor in connection with a merger, acquisition or sale of assets, subject to confidentiality.
We never sell personal data.
5. International transfers
Foundation One is hosted on cloud infrastructure that may process data outside Mauritius. Under section 41 of the DPA 2017, personal data may be transferred outside Mauritius only where the destination jurisdiction ensures an adequate level of protection, or where appropriate safeguards are in place. We rely on:
- The Mauritius DPC’s recognition of jurisdictions with adequate data-protection standards;
- Standard Contractual Clauses (SCCs) adopted under the EU GDPR or the UK GDPR;
- Binding Corporate Rules (where applicable); or
- Another lawful transfer mechanism under DPA 2017 section 41 and Article 46 GDPR.
A list of hosting regions is available to customers under NDA.
6. Retention
| Data category | Retention period |
|---|---|
| Demo / marketing enquiries | 24 months from last contact, or until you opt out |
| Customer account data | Duration of the contract + 90 days, then deleted on request |
| Client Personal Data (in-Service) | Per customer instructions; deleted within 90 days of contract end unless law requires otherwise |
| Audit & security logs | 12 months (extended where a legal hold applies) |
| Billing records | 7 years (tax / accounting law) |
7. Security
We protect personal data with AES-256 encryption at rest, TLS 1.3 in transit, role-based access control down to the field, multi-factor authentication, and continuous monitoring. Customer tenants are logically isolated with row-level security. See our security overview for the full control set.
8. Your rights
Under Part IV of the Mauritius DPA 2017 (sections 23–30) and, where applicable, the GDPR, you have the right to:
- Access (s.23 / Art. 15) — the personal data we hold about you;
- Rectification (s.24 / Art. 16) — of inaccurate or incomplete data;
- Eradication (s.25 / Art. 17) — the “right to be forgotten” where no lawful ground remains;
- Restriction (s.26 / Art. 18) — of processing in defined circumstances;
- Objection (s.29 / Art. 21) — to processing based on legitimate interests;
- Portability (Art. 20 GDPR / s.27 DPA 2017 where applicable) — receive your data in a structured, machine-readable format;
- Withdraw consent (s.22) — for marketing or consent-based processing at any time;
- Not be subject to automated decision-making (s.30 / Art. 22) producing legal or similarly significant effects;
- Complain to the Data Protection Commission, Mauritius (the supervisory authority) or, for EU/EEA/UK data subjects, your local supervisory authority.
To exercise any right, email dpo@aphelion-group.com or write to us at the address in section 11. We respond within 30 days (extended by 60 days where requests are complex, with notice), in accordance with s.31 of the DPA 2017.
9. Children’s data
The Service is intended for professional use by financial services firms. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
10. Changes to this policy
We may update this policy to reflect operational, legal or regulatory changes. Material changes will be notified to customers by email and posted on this page with a new “Last updated” date.
11. Contact
For any privacy question or request, contact our Data Protection Officer:
Aphelion Ltd — Foundation One
Attn: Data Protection Officer
2nd Floor, KL House, M2 Motorway, Riche Terre, 21813 Mauritius
dpo@aphelion-group.com
You may also lodge a complaint with the Data Protection Commission of Mauritius:
Data Protection Commission
1st Floor, The Cyberati Lounge, Côte d’Or Street, Cybercity, Ebene 72201, Mauritius
dataprotection.govmu.org