IGUAKO Capital is a work of institutional fiction by the Iguako Institute for Applied Unreality. No financial services are offered, no accounts exist and nothing here is an offer, a contract or advice.About this work
George Town · 36 cities · English Domiciles Documents Iguako Network Site Index

Regulatory notice · Mauritius

Mauritius: Data Protection Notice

IGUAKO Capital holds personal data because regulation, contract and prudent underwriting require it, and for no other reason. This notice explains what the firm collects, the basis on which it is held, who else sees it, how long it is kept, and what an individual can require of the firm. It is issued under the group Data Protection and Privacy policy, IGC-DT-001. Four principles of the Ethical Technology Charter govern it. Every dataset has a documented origin and a lawful basis. Nothing is inferred about a person beyond what the mandate needs. A client can see which decisions were model-assisted. Any client may require that a person decide instead.

Jurisdiction
Mauritius
Local entity
IGUAKO Africa Holdings Ltd
Served from
Port Louis
Group policy
IGC-DT-001
Reviewed
June 2026

What is held, and on what basis

The Mauritius entity holds identification documents, ownership and control records, tax residence declarations, settlement instructions, transaction and valuation records, correspondence, meeting notes and the access logs of the client portal. Each processing activity appears in the group processing register with its origin, its lawful basis, its retention period and a named owner. The firm buys no personal data from data brokers, builds no behavioural profile of a client, and draws no inference about an individual that the mandate does not require. Client data is never sold, and it is never used to train a model that serves another client.

What an individual can require

Any individual whose data the firm holds may ask what is held, ask for a copy, ask for a correction, object to a particular use, or ask for deletion where no retention rule requires the record to be kept. Requests go to privacy@iguako.tech and are answered within 30 days, without charge, whatever the size of the relationship. Where a decision has been assisted by a model, the client may require that a person take the decision again, and the office in Port Louis arranges that review within ten business days. A refusal is explained in writing and names the rule relied on.

Where the data goes and how long it stays

Client records sit on group systems and are copied to the regional hub that holds Mauritius records, under the intra-group transfer agreement binding every entity in the network. External processors, principally administrators, custodians and auditors, receive only what their function requires, and each is engaged on written terms carrying the same standard. Data is encrypted at rest and in transit, and access to client records is logged and reviewed monthly. Records are kept for seven years after a relationship ends and are then deleted on a scheduled cycle, not at the discretion of the desk that holds them.

The local regime and the reporting of breaches

Data protection law differs across the 28 domiciles. IGUAKO Africa Holdings Ltd records in the group processing register which regime governs its files, which authority supervises that regime, and what the local rule requires beyond the group minimum.

Mauritius has a national data protection law with a data protection office that registers controllers and processors, and IGUAKO Africa Holdings Ltd is registered as a controller for the personal data it holds on directors, co-investors, borrowers and staff across the platform. The platform holds data on founders and family principals behind African positions, and that data is transferred to Johannesburg, Nairobi, George Town and Luxembourg under written terms that meet the office's conditions for transfers outside Mauritius. Consent is not relied upon as a lawful basis for any client data; contract and legal obligation are used instead. Data subjects in Africa have access, correction and objection rights and receive answers within one month. Breaches are notified to the office without undue delay.

A suspected breach is reported to the Group Data Protection Officer within 24 hours of discovery and assessed within 72 hours wherever in the network it occurs, and the Africa & Indian Ocean regional compliance officer is told at the same time.

Personal data is a liability the firm carries on behalf of the people it belongs to, and it is treated that way. The firm collects the minimum the mandate needs, keeps it only as long as a rule requires, and answers for it through a named officer in every jurisdiction where it holds a file.

Questions about this notice may be raised with the local entity through compliance@iguako.tech, quoting the jurisdiction and the notice title.