🔒 Data Protection Act 2017
Your data and that of your employees remains yours. Klytic applies the Data Protection Act 2017 of the Republic of Mauritius and all applicable personal data protection regulations, and helps you comply with them in your own operations.
Depending on the data concerned, Klytic acts as a processor or as a controller.
Emails, files, contacts, CRM records, calls and logs: for this data, we act as a processor and you act as the controller, in accordance with the Data Protection Act 2017. We process it only on your documented instructions and to the extent necessary to deliver, secure, maintain and support the services, unless otherwise required by law. This processing is governed by a Data Processing Agreement (DPA), which forms an integral part of the contract.
Contact details of your contact persons, contracts, billing and exchanges with support: we act as the controller for this data. This data is used only to perform the contract and manage our relationship with you.
We do not sell, rent, transfer or exploit your data for our own commercial purposes. No advertising, no profiling, no enrichment of our own databases.
Your data is hosted in the geographic zone you have chosen. We do not transfer it outside that zone without your prior written consent, unless required by a legal or regulatory obligation, in which case we inform you to the extent permitted by law.
Appropriate technical and organisational measures to ensure the confidentiality, integrity, availability and security of data: access control, authentication, encryption (TLS 1.3, AES-256), encrypted daily backups, logging and protection against unauthorised access.
We inform you as soon as possible of any personal data breach we become aware of, with the information you need to meet your own legal and regulatory obligations.
Persons authorised to process your data are bound by confidentiality and access it only to the extent necessary for their duties. Each party preserves the confidentiality of the other party’s information and uses it only to perform the contract.
At the end of the services, in accordance with your instructions and subject to our legal retention obligations, we return or delete your personal data and any copies, as provided for in the DPA.
For the duration of the contract, then 30 days to allow you to retrieve it. Backups are retained on a rolling 30-day basis.
Not retained under normal operation. A message is kept, encrypted and temporarily, only if the recipient server is unavailable or if it is quarantined.
Used only within the contractual framework. Data unused for three years is deleted during an annual review, subject to legal obligations (accounting records: 10 years).
Stored internally and destroyed no later than 30 days after the call. See our Service quality page.
In accordance with the Data Protection Act 2017 of the Republic of Mauritius, you have the following rights regarding your personal data.
✓ Access
✓ Rectification
✓ Erasure
✓ Restriction of processing
✓ Objection
✓ Right not to be subject to automated decisions
To exercise them, write to us via the contact form or at [email protected]. We will respond within one month. For your users’ data hosted in our services, we handle the request with you, as the controller.
You may also lodge a complaint with the Data Protection Office, the Mauritian supervisory authority (dataprotection.govmu.org).
Dedicace Software (Mauritius) LTD, a company registered under number C21178866, with its registered office at SHIVALAH ROAD MON GOUT PAMPLEMOUSSES MAURITIUS. Phone: +230 460 26 10. See also our legal notice and the Hosting & Sovereignty page.
We will provide you with the Data Processing Agreement and respond to your compliance questionnaires.
Contact us