Privacy Policy
1. Introduction
1.1. Purpose
1.1.1. Luramic Ltd (the “Company”, “Luramic”, “we”, “us” or “our”) is committed to protecting the privacy, confidentiality and security of personal data entrusted to us.
1.1.2. This Privacy Policy explains how we collect, use, process, store, share, transfer, retain and otherwise handle personal data obtained in connection with our business activities, products, services, website, trading platforms and business relationships. The Company recognises the importance of safeguarding personal data and is committed to processing such data in a fair, lawful, transparent and secure manner.
1.1.3. This Privacy Policy forms an integral part of and should be read together with the Company’s Client Agreement, Terms and Conditions, Risk Disclosure Notice, Cookie Policy, Order Execution Policy, Anti-Money Laundering and Know Your Customer documentation, account opening forms, consents and any other agreements, notices or disclosures made available by the Company from time to time.
1.1.4. In the event of any inconsistency between this Privacy Policy and any applicable law or regulatory requirement, the applicable law or regulatory requirement shall prevail.
1.2. Application of this Privacy Policy
1.2.1. This Privacy Policy applies to personal data relating to:
- prospective clients and clients;
- directors, shareholders, ultimate beneficial owners ("UBOs"), authorised signatories, authorised representatives, contact persons and employees of corporate clients;
- counterparties, liquidity providers and business partners;
- suppliers, consultants and service providers;
- visitors to our website, trading platforms and mobile applications; and
- any other individuals whose personal data is processed by the Company in connection with its business activities.
1.3. Regulatory Framework
1.3.1. The Company processes personal data in accordance with:
- the Mauritius Data Protection Act 2017;
- any regulations, guidance notes, directives or codes issued by the Mauritius Data Protection Office;
- applicable anti-money laundering and counter-terrorist financing legislation;
- applicable financial services legislation and regulatory requirements; and
- where applicable, other data protection laws and regulations outside of the Republic of Mauritius.
1.4. Data Controller
1.4.1. For the purposes of applicable data protection legislation, Luramic Ltd acts as the data controller in respect of personal data processed in connection with the products and services provided by the Company.
1.4.2. The Company determines the purposes for which and the manner in which personal data is processed.
1.5. Acceptance of this Privacy Policy
1.5.1. By accessing the Company’s website, submitting information to the Company, applying for or using any product or service, opening or maintaining an account, entering into a business relationship with the Company, using any trading platform, communicating with the Company, or otherwise interacting with the Company, you acknowledge that you have read and understood this Privacy Policy and that your personal data may be collected, used, disclosed, transferred, stored and otherwise processed by the Company in accordance with this Privacy Policy and applicable law.
1.5.2. Where required by applicable law, the Company will obtain your consent before processing personal data for specific purposes for which consent is required.
2. Definitions
For the purposes of this Privacy Policy, the following terms shall have the meanings set out below:
Applicable Data Protection Laws means the Mauritius Data Protection Act 2017, any regulations, guidance notes, directives, codes of practice or guidance issued thereunder, and any other applicable data protection, privacy or electronic communications laws and regulations.
Data Controller means the natural or legal person who determines the purposes and means of the processing of Personal Data.
Data Processor means a natural or legal person who processes Personal Data on behalf of a Data Controller.
Personal Data means any information relating to an identified or identifiable natural person, whether directly or indirectly identifiable by reference to an identifier including, without limitation, a name, identification number, location data, online identifier, financial information, or one or more factors specific to that person’s identity.
Processing means any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, alignment, restriction, erasure or destruction.
Client means any existing, prospective or former client of the Company, including any legal entity, institutional client, professional client, eligible counterparty, business partner, liquidity provider or other person receiving products or services from the Company.
3. Categories Of Personal Data We Collect
3.1. The Company may collect, receive, generate, verify and otherwise process various categories of Personal Data in connection with its business activities, regulatory obligations, products and services.
3.2. The categories of Personal Data that we may collect include, without limitation, the following:
- Identification Data, including but not limited to: the name, date of birth, nationality, passport and identification details;
- Contact Information, including but not limited to: residential, business and correspondence details;
- Corporate and Business Information, including company information, ownership and control information, beneficial ownership information and corporate documentation;
- AML, KYC and Due Diligence Information, including due diligence documentation, screening results and risk assessment information;
- Communications Data;
- Technical and Usage Information;
- the Company may also obtain information from publicly available sources where permitted by applicable law.
4. Sources Of Personal Data
4.1. The Company may collect Personal Data directly from the individual concerned, indirectly through third parties, or from publicly available sources, as further described below.
4.2. The Company may collect Personal Data directly from you when you:
- apply for, open or maintain an account with the Company;
- request information regarding the Company's products or services;
- complete application forms, questionnaires, declarations or other documentation;
- communicate with the Company by email, telephone, electronic messaging systems, website forms or other means;
- use the Company's website, trading platforms, client portals or other electronic systems;
- interact with the Company in connection with its products, services or business activities.
4.3. The Company may receive Personal Data from:
- corporate clients;
- authorised representatives;
- authorised signatories;
- directors, shareholders and Ultimate Beneficial Owners;
- counterparties and liquidity providers;
- introducers, professional advisers and consultants;
- payment service providers and banking institutions;
- service providers acting on behalf of the Company, and other third parties authorised to provide such information;
- publicly available sources, regulatory databases and sanctions screening providers;
- information generated during the course of the business relationship.
4.4. Where Personal Data relating to directors, shareholders, Ultimate Beneficial Owners, authorised signatories, authorised representatives, employees, contact persons or other associated individuals is provided to the Company by a Corporate Client, applicant, authorised representative or other third party, the person providing such Personal Data represents and warrants that it is authorised to do so and has provided all required notices and obtained all necessary consents, authorisations or other lawful grounds required under applicable law to enable the Company to collect, use, disclose, transfer, store and otherwise process such Personal Data in accordance with this Privacy Policy and applicable law.
4.5. The Company may rely upon such representations unless it becomes aware of circumstances indicating otherwise.
5. Purposes And Legal Bases For Processing
5.1. The Company processes Personal Data only where it has a lawful basis to do so under applicable data protection legislation. Depending on the circumstances, the Company may process Personal Data on the basis of contractual necessity, legal and regulatory obligations, legitimate interests, consent, or other lawful grounds recognised under applicable law.
5.2. The Company may process Personal Data for the following purposes:
| Purpose of Processing | Categories of Personal Data | Legal Basis |
|---|---|---|
| Establishing and maintaining a business relationship | Identification, contact, corporate and due diligence information | Performance of a contract; pre-contractual steps |
| Providing products and services | Identification, account, transaction and communication information | Performance of a contract |
| Customer due diligence, AML, sanctions screening, source of funds/source of wealth verification and ongoing monitoring | Identification, financial, due diligence, screening and transaction information | Compliance with legal and regulatory obligations |
| Processing payments and financial transactions | Financial, account and transaction information | Performance of a contract; legal obligations |
| Risk management, fraud prevention, cybersecurity and business continuity | Identification, technical, transaction and communication information | Legitimate interests; legal obligations |
| Regulatory reporting and responding to requests from regulators, courts and authorities | Identification, financial, transaction and compliance information | Compliance with legal obligations |
| Record keeping, audit and internal controls | Any relevant Personal Data | Compliance with legal obligations; legitimate interests |
| Investigation and resolution of complaints, disputes and legal proceedings | Identification, transaction and communication information | Legitimate interests; legal claims |
| Marketing communications and relationship management | Contact information and communication preferences | Consent where required; otherwise legitimate interests |
| Protection of the Company’s rights, interests and assets | Any relevant Personal Data | Legitimate interests; legal claims |
5.3. The Company processes Personal Data only where it has a lawful basis to do so under applicable law, including the performance of a contract, compliance with legal and regulatory obligations, the Company’s legitimate interests, consent where required, and the establishment, exercise or defence of legal claims. Failure to provide Personal Data required by law, regulation or contractual arrangements may prevent the Company from establishing or continuing a business relationship or providing products and services.
6. AML/KYC and Regulatory Processing
6.1. The Company processes Personal Data for anti-money laundering, counter-terrorist financing, sanctions compliance, fraud prevention, customer due diligence, beneficial ownership verification, transaction monitoring, source of funds and source of wealth verification, regulatory reporting and other legal and regulatory obligations.
6.2. The Company may conduct screening against sanctions, politically exposed persons (“PEPs”), adverse media and other compliance databases and may request additional information or documentation where required.
6.3. The Company may disclose Personal Data to regulators, supervisory authorities, financial intelligence units, law enforcement agencies, courts and other competent authorities where required by law.
6.4. Failure to provide information required for compliance purposes may result in the refusal, restriction or termination of services.
7. Disclosure of Personal Data
7.1. The Company may disclose Personal Data to:
- affiliated entities;
- service providers and outsourced service providers;
- banks, payment service providers and financial institutions;
- liquidity providers, counterparties and business partners;
- professional advisers, auditors and consultants;
- regulators, courts, law enforcement agencies and competent authorities;
- prospective purchasers, successors or other parties in connection with a merger, acquisition, restructuring or other corporate transaction.
7.2. The Company shall take reasonable steps to ensure that recipients process Personal Data only for legitimate purposes and in accordance with applicable law.
8. International Transfers
8.1. The Company may transfer, store or process Personal Data in jurisdictions outside Mauritius where necessary for the provision of services, compliance with legal and regulatory obligations, operational requirements, or the engagement of service providers, affiliates, counterparties or business partners.
8.2. Where Personal Data is transferred internationally, the Company shall take reasonable steps to ensure that appropriate safeguards are implemented in accordance with applicable data protection laws and that Personal Data continues to receive an adequate level of protection.
9. Data Retention
9.1. The Company retains Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory, tax, accounting, audit, anti-money laundering, contractual and operational requirements.
9.2. Retention periods may vary depending on the nature of the Personal Data, the purpose of processing and applicable legal or regulatory obligations. Upon expiry of the applicable retention period, the Company shall securely delete, anonymise or otherwise dispose of the Personal Data unless further retention is required or permitted by law.
10. Data Security
10.1. The Company implements appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access or other unlawful forms of processing.
10.2. Such measures may include access controls, authentication procedures, encryption, monitoring systems, physical security controls, staff training, confidentiality obligations and information security policies.
10.3. While the Company seeks to protect Personal Data, no method of transmission over the Internet or method of electronic storage can be guaranteed to be completely secure.
11. Cookies And Tracking Technologies
11.1. The Company may use cookies, web beacons, analytics tools and similar technologies to improve the functionality, performance and security of its website and electronic services.
11.2. These technologies may collect information relating to device characteristics, browser settings, usage patterns, preferences, IP addresses and other technical information.
11.3. Further information regarding the Company’s use of cookies is available in the Company’s Cookie Policy.
12. Marketing Communications
12.1. The Company may use Personal Data to provide information regarding its products, services, events, updates and other information that may be relevant to existing or prospective clients.
12.2. Where required by applicable law, marketing communications will only be sent with the individual’s consent. Individuals may withdraw consent or opt out of receiving marketing communications at any time by following the unsubscribe instructions provided in such communications or by contacting the Company.
12.3. The withdrawal of consent shall not affect the lawfulness of any processing carried out prior to such withdrawal.
13. Data Subject Rights
13.1. Subject to applicable law and any relevant limitations or exemptions, individuals may have the right to:
- request access to their Personal Data;
- request correction of inaccurate or incomplete Personal Data;
- request the erasure of Personal Data;
- request restriction of processing;
- object to certain processing activities;
- request the transfer of Personal Data to another organisation where applicable;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent supervisory authority.
13.2. The exercise of these rights may be subject to legal, regulatory, anti-money laundering, confidentiality, privilege, record-keeping or other restrictions permitted under applicable law.
13.3. Requests relating to Personal Data may be submitted using the contact details set out in this Privacy Policy.
14. Automated Decision-Making and Profiling
14.1. The Company may use automated systems, screening tools, risk assessment methodologies and profiling techniques for compliance, fraud prevention, anti-money laundering, sanctions screening, security and risk management purposes.
14.2. Where required by applicable law, individuals may request additional information regarding such processing and may exercise any rights available to them under applicable data protection legislation.
15. Complaints
15.1. Individuals who have concerns regarding the Company’s processing of Personal Data or who believe that their privacy rights have been infringed may submit a complaint to the Company using the contact details provided below.
15.2. The Company shall endeavour to investigate and respond to complaints within a reasonable timeframe and in accordance with applicable legal and regulatory requirements.
15.3. Individuals may also have the right to lodge a complaint with the Mauritius Data Protection Office or another competent supervisory authority.
16. Contact Details Of The Data Protection Officer
Questions, requests or complaints relating to this Privacy Policy or the processing of Personal Data may be directed to the Company’s Data Protection Officer or designated privacy contact using the details below:
Luramic Ltd
Registered Address: 18 Bank Street, Ground Floor, Silver Bank Tower, Cybercity, Ebene 72201
Email: support@luramic.com
Privacy Contact: support@luramic.com
The Company may request additional information to verify the identity of any individual submitting a request relating to Personal Data.