Privacy / Personal information
Minimal collection.
Meaningful information.
How the website handles drafts, how business correspondence may be used, and how to exercise your rights.
1. Who is responsible
PAD.Energy Ltd, incorporated in Mauritius under BRN C23196461, is responsible for personal data it receives in connection with its business enquiries and this website. Its registered office is 6th Floor, Carleton Tower, 19 Wall Street, Cybercity Ebene 72201, Mauritius.
For privacy questions or rights requests, email info@pad.energy, marking the subject “Data protection”, or write to the registered office. This is the company’s privacy-enquiry route; it does not represent a named or certified Data Protection Officer appointment.
2. What this website does and does not collect
The website serves locally hosted pages, images, CSS and JavaScript. It contains no analytics tags, advertising pixels, embedded maps, social-media widgets, external fonts, fingerprinting scripts or tracking cookies.
The optional enquiry tool prepares text in your browser. It does not submit a form, upload files, call a server endpoint or write your draft to cookies, local storage or session storage. Use “Clear all” to remove the entered draft from the current page. Your browser or operating system may independently retain autofill, history, clipboard or session-restoration information under your own settings.
Your IP address and technical request information necessarily pass through the network and hosting infrastructure to deliver the website. Hosting, network or security providers may process technical records such as IP address, time, requested resource and browser information. Those service-level records are separate from the enquiry tool.
3. Information, purposes and lawful grounds
| Activity | Information | Purpose and ground |
|---|---|---|
| Business enquiries | Business contact details, organisation, correspondence and the requirement you choose to send. | Assessing and responding to a genuine business enquiry: legitimate interests, subject to the rights and interests of the individual. Pre-contractual steps may apply where the individual is personally a prospective contracting party. |
| Website delivery and security | IP address and technical request or incident information processed by the hosting infrastructure. | Delivering the requested pages, detecting faults and protecting services: legitimate interests with proportionate safeguards. |
| Privacy rights and complaints | Request, contact details and proportionate verification or decision records. | Handling the request and demonstrating compliance with applicable legal duties. |
| Subsequent transaction assessment | Only information justified for the particular engagement, which may include authorised-representative or due-diligence information. | The purpose, legal basis, recipients and retention are to be explained before that information is collected. Legal obligation is relied on only where an obligation actually applies. |
There is no marketing subscription, purchase decision or automated acceptance process on this website. Simply visiting or sending an enquiry is not consent to marketing. Where consent is separately requested, it must be specific and may be withdrawn without affecting earlier lawful processing.
4. Your choices and information from other sources
A business enquiry is voluntary. The local tool requires only a company name and brief requirement to create a useful draft; it does not collect your email address because your email service supplies the sender details when you send. Failure to provide sufficient contact or requirement information may prevent a meaningful response.
Do not send sensitive personal data, identity documents, account credentials, proof of funds or confidential third-party records at first contact. An appropriate channel and separate information notice should be agreed before any justified detailed onboarding.
Where personal data is obtained from an authorised representative, introducer or public source, the applicable information requirements still apply, subject to lawful exceptions. No one should assume that an introduction authorises unrestricted onward disclosure.
5. Who may receive information
Access should be limited to authorised personnel and service providers who need it for the stated purpose. Relevant provider categories include website hosting, network security, business email, IT support and professional advisers. Providers acting as processors require appropriate written terms and safeguards.
DAPIL S.A., a supplier, an independent inspector, a terminal or another transaction participant is not an automatic recipient of information merely because you visit the site or prepare a draft. Before material onward disclosure, the need, relevant recipient, role and lawful basis must be established. Where appropriate, the recipient’s own privacy information will also apply.
Information may be disclosed where required by applicable law, a competent authority or the legitimate handling of legal claims, with the scope limited to what is justified.
6. Processing outside Mauritius
Email, hosting and transaction activity can involve processing outside Mauritius. Potential transaction recipients may be in the Netherlands or the Republic of the Congo; other locations depend on the actual providers and engagement. The website’s draft tool itself does not transfer your draft to any recipient.
Before an international transfer of personal data, PAD.Energy must establish a lawful route under section 36 of the Mauritius Data Protection Act 2017. This may require providing the Commissioner with proof of appropriate safeguards, or satisfying a specific statutory exception. The existence of a commercial contract or an overseas business relationship does not automatically make every transfer lawful.
Where relevant information is to be collected or shared for an engagement, the recipient categories, destination countries, applicable safeguards and the means of obtaining further information are to be communicated. You may ask the privacy contact about the safeguards applicable to your information. This notice is not a blanket consent to transfers.
7. Retention and deletion
Personal data should be retained only for its stated purpose or an identified legal need. The following are the retention commitments proposed for this website’s deployment and enquiry workflow; they require the company and its providers to implement the corresponding operational settings.
- Unsent website drafts
- No application-side persistent storage. Clear the form to remove its contents from the current page. Browser-managed restoration, clipboard and email-app copies are controlled separately by you.
- Routine unsuccessful or inactive enquiries
- Delete or anonymise within 12 months after the last substantive contact, unless the matter becomes an active engagement or a documented legal hold applies.
- Routine technical security logs, where enabled
- A maximum of 30 days, unless particular records are isolated for investigation or a documented legal requirement. Routine access logging is disabled in the supplied reference-server configuration.
- Privacy-request accountability records
- Retain only the minimum decision and correspondence record for up to 24 months after closure, subject to a justified legal hold. Do not retain identity-verification copies longer than needed for verification.
- Transaction and statutory records
- A separate purpose-specific schedule must be communicated when that processing is introduced. No universal “keep everything” period is created by this website.
These are policy periods, not a statement that Mauritius law prescribes 12, 30 or 24 months for these activities. Where a legal hold applies, its reason, scope and review date should be recorded. At the end of the justified period, deletion or anonymisation should cover relevant providers and scheduled backup expiry.
8. Your rights and the response process
Subject to applicable conditions and exceptions, you may request access, correction, erasure or restriction of personal data, object to relevant processing and challenge a decision based solely on automated processing with significant effects. The website does not make such automated decisions. Consent may be withdrawn where consent is the ground relied on.
Send a plain-language request to info@pad.energy or the registered office. Identify the relevant correspondence or processing where possible. A passport or identity-document copy is not routinely required; proportionate additional information may be requested where there is reasonable doubt about identity or authority.
Under section 37, the company should inform you in writing of the action taken within one month of receiving the request. Where justified by complexity or the number of requests, the period may be extended by one further month, with notice and reasons within the initial month. Any lawful refusal should explain the reason and complaint route. Applicable rules govern manifestly unfounded or excessive requests; rights are not subject to an automatic fee.
You may complain to the Mauritius Data Protection Office without first completing a company complaint process. Consult its official website (opens a new tab) for current contact details and complaint procedures.
9. Security, incidents and links
The supplied website avoids a web-submission endpoint and does not accept files. Security also depends on the live hosting configuration, protected email accounts, access management, provider arrangements and staff procedures. Ordinary email is not represented as a secure document vault.
Personal-data breaches must be assessed and handled under the Act. Section 25 requires notification to the Commissioner without undue delay and, where feasible, within 72 hours of awareness; a delayed notification must explain the delay. Section 26 addresses notification to affected individuals where a breach is likely to result in a high risk, subject to its specified exceptions.
Optional external links are not embedded services. Following a WhatsApp or other external link takes you to a third party whose privacy arrangements apply. Contact the company promptly if you believe personal data has been mishandled; do not publish the data in a public report.
10. Children, changes and legal framework
This is a business-to-business website intended for adults. It does not solicit children’s personal data. Where information concerning a child is received unexpectedly, its necessity and applicable legal requirements must be assessed.
This notice is prepared against the Mauritius Data Protection Act 2017 and the enacted Data Protection (Designation, Tasks and Position of Data Protection Officers) Regulations 2026, which commence on 1 January 2027. The regulations create organisational duties that cannot be completed by publishing a notice alone.
Material changes to purposes, collection methods, providers or legal requirements require review of the notice before the changed processing begins. The date above identifies this version. Mandatory statutory rights prevail over conflicting website wording.