Our Privacy Policy
Privacy Notice
2026
1. Introduction
This Privacy Notice explains how Titan Corporate Services Limited (“Titan”, “we”, “us” or “our”) collects, uses, verifies, stores, shares and protects personal data. It also explains the rights available to individuals and how to contact us or the relevant supervisory authority.
This notice applies to prospective and existing clients, beneficial owners, shareholders, directors, officers, trustees, settlors, protectors, beneficiaries, authorised persons, signatories, employees or representatives of clients, introducers, professional advisers, service providers, website users and other individuals whose personal data we process in connection with our business.
Titan is a data controller in respect of personal data for which it determines the purposes and means of processing. We process personal data in accordance with the Mauritius Data Protection Act 2017 and other applicable data-protection requirements. The European Union General Data Protection Regulation applies only where its territorial or other legal requirements apply to the relevant processing.
This notice does not override any applicable law, regulatory obligation, court order, targeted financial sanctions requirement, Financial Intelligence Unit instruction or other competent-authority requirement.
2. Personal data we may collect
Depending on the relationship, service and legal requirements, we may collect and process:
- identity information, including name, former names, date and place of birth, nationality, photograph, signature, passport, national identity card and other identification details;
- contact and residential information, including address, telephone number, email address, country of residence and tax residence;
- family, relationship and connected-person information where relevant to a company, trust, foundation, succession, ownership or control structure;
- professional and corporate information, including occupation, employer, directorships, shareholdings, beneficial ownership, control, authority, powers of attorney and business activities;
- financial information, including bank details, assets, liabilities, income, investments, tax information, expected activity, transactions and payment information;
- source of funds, source of wealth, economic rationale and supporting documents;
- customer due diligence and enhanced due diligence information, including verification results, risk assessments, screening records and ongoing monitoring information;
- information concerning politically exposed person status, sanctions exposure, regulatory matters, litigation, allegations, criminal convictions or alleged offences, where lawful and relevant;
- communications, instructions, meeting notes, correspondence, complaints and records of our relationship with you;
- website and technical information, including Internet Protocol address, browser, device, operating system, access times, pages viewed and cookie or analytics information; and
- any other information required to provide services, comply with law, manage risk or protect our legitimate interests.
Some of this information may constitute special categories of personal data under applicable law. We process such data only where an additional lawful condition applies and appropriate safeguards are in place.
3. How we collect personal data
We may collect personal data:
- directly from you through enquiries, application forms, mandates, service agreements, meetings, correspondence and documents supplied to us;
- from a client, prospective client, connected person, employer, authorised representative, business introducer, professional adviser or other person involved in the relationship;
- from banks, financial institutions, insurers, investment providers, administrators, registrars and other service providers where lawful and relevant;
- from public registers, official records, court records, regulator publications, sanctions lists, professional or corporate profiles, websites, media and other publicly available sources;
- from appropriate third-party identity-verification, fraud-prevention, credit-reference, sanctions, politically exposed person, adverse-media and AML/CFT/CPF screening databases; and
- automatically when you use our website, subject to applicable cookie and consent requirements.
Where you provide us with personal data relating to another individual, you should ensure that you are authorised to do so and, where appropriate, that the individual is informed of this notice.
4. Purposes for which we process personal data
We may process personal data to:
- respond to enquiries and take steps before entering into a contract;
- assess whether we can accept or continue a client relationship or instruction;
- provide, administer, manage and protect our management company, corporate trustee and related services;
- establish and maintain corporate, trust, foundation, banking, investment, insurance or other arrangements requested by or for a client;
- identify and verify clients, beneficial owners, controllers, connected persons and authorised persons;
- assess and manage legal, regulatory, AML/CFT/CPF, sanctions, fraud, credit, operational and reputational risks;
- conduct customer due diligence, enhanced due diligence, screening, ongoing monitoring, transaction or activity review and periodic or event-driven reviews;
- establish and verify source of funds, source of wealth, purpose, intended nature and economic rationale;
- carry out instructions, process payments and transactions, administer fees, maintain accounts and records, and manage claims or disputes;
- comply with legal and regulatory obligations, court orders, regulatory enquiries, inspections, audits, reporting obligations and competent-authority requirements;
- prevent, detect, investigate and respond to fraud, misuse, cyber incidents, unlawful conduct and security threats;
- maintain business continuity, information security, quality control, training, internal governance and record keeping;
- establish, exercise or defend legal rights and claims;
- improve our services, systems, website and business operations through proportionate analysis; and
- send service information or marketing communications where permitted by law.
5. Lawful bases for processing
Depending on the circumstances, we process personal data where the processing is necessary:
- to take steps at your request before entering into a contract or to perform a contract;
- to comply with a legal or regulatory obligation to which Titan is subject;
- for Titan’s or a third party’s legitimate interests, where those interests are not overridden by the rights and interests of the individual;
- to establish, exercise or defend a legal claim;
- to protect the vital interests of an individual; or
- on the basis of valid consent where consent is the appropriate lawful basis.
Where we rely on consent, consent may be withdrawn at any time. Withdrawal does not affect processing carried out lawfully before withdrawal and does not affect processing supported by another lawful basis.
Consent is not the lawful basis for processing that Titan must undertake to comply with its AML/CFT/CPF, targeted financial sanctions, regulatory, reporting or record-keeping obligations.
6. Data Protection and AML/CFT/CPF Compliance
Titan processes and independently verifies personal information for the provision and administration of services and for compliance with applicable Anti-Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing requirements. This may include customer due diligence, beneficial ownership verification, risk assessment, screening, source of funds and source of wealth verification, ongoing monitoring, transaction or activity review, record keeping, targeted financial sanctions controls and suspicious transaction reporting.
For these purposes, Titan may verify information supplied by a client, prospective client or connected person through reliable and independent documents, data or information. Verification may include appropriate third-party databases, public registers, official records, publicly available information, professional or corporate sources and other lawful sources.
Relevant information may be disclosed, where necessary, required or permitted by law, to banks and other financial institutions, the Financial Services Commission, the Financial Intelligence Unit, law-enforcement bodies, courts, registrars, tax authorities, other regulators and competent authorities, professional advisers, auditors and service providers. Such disclosures are subject to applicable confidentiality, data-protection, security, cross-border transfer and record-keeping requirements.
Where a specific applicable AML/CFT/CPF, targeted financial sanctions, court, regulator, Financial Intelligence Unit or competent-authority requirement conflicts with this notice or with a request made by an individual, Titan will comply with that legal or official requirement to the extent required or permitted by law. Data-protection obligations and safeguards continue to apply in all other respects.
Titan may be prohibited from informing an individual that a suspicious transaction report has been or may be made, that related information has been requested or supplied, or that certain Financial Intelligence Unit, law-enforcement, sanctions or regulatory action is being considered or taken.
Where personal data or supporting documents are required by law or are necessary for Titan to meet its regulatory obligations, failure to provide them may prevent Titan from accepting an instruction, establishing or continuing a business relationship, processing a transaction or providing a service.
7. Sharing personal data
Access to personal data within Titan is restricted to directors, officers, employees and authorised persons who require it for their duties.
Where necessary, required or permitted, we may share relevant personal data with:
- banks, financial institutions, insurers, investment providers, administrators, custodians, payment providers, registrars and other organisations involved in providing or administering services;
- the Financial Services Commission, the Financial Intelligence Unit, law-enforcement bodies, courts, tax authorities, registrars and other regulators or competent authorities;
- lawyers, accountants, auditors, tax advisers, consultants and other professional advisers;
- technology, hosting, cloud, communications, document-management, identity-verification, screening, data, security and other operational service providers;
- business introducers, authorised representatives and counterparties where necessary for the relevant relationship or instruction; and
- any other recipient where you have consented to the disclosure or the disclosure is otherwise lawful.
Service providers that process personal data on our behalf are required to act only on appropriate instructions and to apply suitable confidentiality, security and data-protection safeguards. Titan remains responsible for its own statutory obligations and does not transfer its AML/CFT/CPF responsibilities or final compliance decisions to a third party.
Titan does not sell personal data.
8. International transfers
The nature of our services may require personal data to be accessed, stored or processed outside Mauritius, including where we deal with overseas clients, banks, professional advisers, regulators, counterparties or service providers.
Where personal data is transferred outside Mauritius, we will rely on an applicable lawful transfer ground and implement appropriate safeguards where required. These may include contractual safeguards, confidentiality and security requirements, risk assessment, explicit consent where appropriate, or another transfer basis permitted by law.
Where the European Union General Data Protection Regulation applies, we will also use an applicable transfer mechanism and supplementary safeguards where required.
9. Security and confidentiality
Titan applies appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures are selected according to the nature, volume, context and risk of the processing and may include access controls, authentication, secure storage, backup, monitoring, staff confidentiality, supplier controls, incident-response procedures and secure disposal.
No method of transmission or storage can be guaranteed to be completely secure. We review our safeguards and respond to personal data breaches in accordance with applicable legal requirements.
10. Retention of personal data
Titan retains personal data for as long as necessary for the purposes for which it was collected and in accordance with applicable legal, regulatory, contractual and professional requirements.
Records obtained through customer due diligence, including client files, business correspondence, identity documents and the results of relevant analysis, are generally retained for at least seven years after the business relationship has ended.
Transaction records are generally retained for seven years after completion of the relevant transaction.
Copies of suspicious transaction reports and related reports or supporting documents are retained for at least seven years from the date of the report.
Personal data may be retained for a longer period where required by law, a court, a regulator, the Financial Intelligence Unit or another competent authority, or where necessary for an investigation, legal proceedings, the establishment or defence of legal rights, audit, complaint handling, remediation or another continuing lawful purpose.
When no continuing lawful purpose or retention requirement applies, personal data will be securely destroyed or irreversibly anonymised.
11. Your rights
Subject to applicable law, you may have the right to:
- ask whether we process your personal data and request access to it;
- request correction of inaccurate personal data or completion of incomplete personal data;
- request erasure of personal data where no continuing lawful ground or retention obligation applies;
- request restriction of processing in specified circumstances;
- object to processing based on particular lawful grounds, including direct marketing;
- withdraw consent where processing is based on consent;
- receive information about applicable automated decision making; and
- lodge a complaint with the Data Protection Commissioner through the Data Protection Office of Mauritius.
These rights are not absolute. Titan may retain or continue to process personal data, or may limit information supplied in response to a request, where this is required or permitted by law. This may include statutory record keeping, prevention or investigation of offences, legal proceedings, targeted financial sanctions, regulatory enquiries, suspicious transaction reporting, Financial Intelligence Unit communications and restrictions intended to prevent tipping off.
To exercise a right, contact the Data Protection Officer using the details in section 18. We may request sufficient information to verify identity and authority before acting on a request.
12. Screening, profiling and automated tools
Titan may use screening, identity-verification, monitoring and risk-assessment tools to support compliance and risk-management decisions.
A database result or similar-name result is not treated as conclusive by itself. Potential matches should be reviewed using additional identifiers and relevant supporting information.
Titan will not make a decision producing legal or similarly significant effects based solely on automated processing unless the processing is permitted by law and appropriate safeguards apply. Where applicable, an individual may request human review or query the decision.
13. Monitoring of electronic communications
Where lawful and proportionate, Titan may record or monitor telephone calls, emails, online communications and other electronic communications for evidence of instructions, service quality, training, security, fraud prevention, dispute resolution, business continuity and compliance with legal, regulatory and internal requirements.
14. Direct marketing
Titan may send information about its services where it has valid consent or another lawful basis expressly permitted by applicable law.
Marketing consent is optional and is separate from personal data required to provide services or meet legal obligations.
You may object to direct marketing or withdraw marketing consent at any time by using the unsubscribe method in the communication or by contacting us.
We will stop using your personal data for direct marketing after processing the request, although we may keep a minimal suppression record to ensure that the preference is respected.
15. Cookies and website analytics
Our website may use cookies and similar technologies. Some cookies are necessary for the website to function. Other cookies may support preferences, security, performance or analytics and will be used subject to applicable consent requirements.
Where Google Analytics or another analytics service is enabled, the provider may process information such as Internet Protocol address, browser type, device information, pages visited, approximate location and use of the website.
Analytics information may be processed outside Mauritius in accordance with the provider’s arrangements and the international-transfer requirements described above.
Where required, you can accept, reject or manage non-essential cookies through the website’s cookie controls. You may also adjust browser settings to block or delete cookies. Blocking certain cookies may affect website functionality.
Use of the website does not by itself constitute consent to non-essential cookies where applicable law requires an affirmative choice.
16. Third-party websites
Our website may contain links to websites or services operated by third parties. Their processing is governed by their own privacy notices and practices.
Titan is not responsible for the content or privacy practices of third-party websites.
17. Changes to this Privacy Notice
We may amend this Privacy Notice to reflect changes in law, regulation, guidance, our services, technology or processing practices.
The current version will be published on our website and will state its effective date and last-updated date.
Material changes may also be communicated by another appropriate method.
18. Contact, queries and complaints
For questions, requests or complaints concerning personal data, email info@titan-corp.net and mark the communication “For the attention of the Data Protection Officer”.
We will review the matter and respond in accordance with applicable requirements.
You may also lodge a complaint directly with the Data Protection Commissioner through the Data Protection Office of Mauritius.
