OUR PRIVACY POLICY
At Harley Street Fertility Centre (Mauritius) Ltd (“HSFC”, “the Clinic”), we are committed to protecting the privacy and confidentiality of your personal data. This Privacy Policy explains how we collect, use, store, share and protect your information, as required under the Data Protection Act 2017 of Mauritius.
1. SCOPE
This policy applies to all personal data processed by the clinic, whether in electronic or paper form, and covers all individuals interacting with us, including patients, visitors, employees, contractors, suppliers, and website users.
“Personal data” means any information relating to an identifiable individual (“data subject”).
2. WHAT PERSONAL DATA WE COLLECT
We may collect and process the following categories of personal data:
- Identification and Contact Data: name, address, ID / Passport, telephone number, email, emergency contacts
- Medical Data: medical history, symptoms, diagnoses, treatment records, laboratory results, imaging, prescriptions
- Administrative Data: billing details, insurance information, payment records
- Employment Data (for staff): CV, qualifications, work history, character certificate
- Other Data: CCTV images, appointment records, communications with the clinic
3. HOW WE COLLECT YOUR DATA
We collect data:
- Directly from you (in person, phone, website, forms)
- From healthcare professionals, laboratories, or insurers with your consent or where legally required
- Automatically when you interact with our website (cookies, IP address – where applicable)
4. PURPOSE OF PROCESSING
We use your personal data for the following purposes:
- To provide safe, effective, and continuous medical care
- To maintain accurate patient records and comply with professional standards
- To manage appointments, billing, and insurance claims
- To meet legal, regulatory, and public health reporting obligations
- To improve the quality of our healthcare services
- For internal management, training, and audit purposes
5. LEGAL BASIS FOR PROCESSING
We process your personal data based on one or more of the following legal basis:
- Consent (where you have given permission)
- Performance of a contract (providing medical services to you)
- Legal obligation (complying with health, tax, or regulatory requirements)
- Vital interests (protecting your life in case of emergencies)
- Legitimate interests (ensuring quality and security of services)
6. SHARING OF DATA
We may share your personal data with:
- Other healthcare professionals involved in your care
- Laboratories, pharmacies, insurance companies, and payment providers
- Regulatory and public health authorities, when legally required
- IT service providers, subject to confidentiality and security safeguards
We do not sell or share your data with third parties for marketing purposes.
International Transfers
In some cases, your personal data may be transferred and stored outside Mauritius (for example, when using international laboratories, insurance providers, or cloud-based IT systems).
When such transfers are necessary:
- They will only be made to countries that ensure an adequate level of data protection as recognised under the Data Protection Act 2017, or
- Appropriate safeguards (such as data transfer agreements or standard contractual clauses) will be put in place to protect your data.
You will be informed whenever an international transfer of your medical or personal information is required, unless this is not possible due to legal or medical obligations.
7. DATA RETENTION
Your personal data will be kept only as long as necessary for the purposes stated and in accordance with:
- Legal and regulatory requirements (at least 7 years)
- Professional medical guidelines
- Our internal retention schedule
After this period, your data will be securely deleted or anonymised.
8. DATA SECURITY
We use appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or loss. These include:
- Secure physical storage of records
- Restricted access for authorised staff only
- Encrypted IT systems and secure backups
- Staff training on confidentiality and data protection
9. THIRD PARTY LINKS
Our website may contain links to other websites of interest. However, once such links are used to leave the site, we do not have any control over other websites. Therefore, HSFC cannot be held responsible for the protection and privacy of any information provided whilst visiting such sites and such sites are not governed by this privacy policy.
10. DATA BREACH MANAGEMENT
If a personal data breach occurs:
Immediate steps will be taken to contain the breach
We will investigate the cause and take corrective measures
If required by law, we will notify the Data Protection Commissioner
If the breach poses a high risk to you, we will inform you promptly
11. YOUR RIGHTS
Under the Mauritius Data Protection Act 2017, you have the following rights:
- To access your personal data
- To request correction of inaccurate or incomplete data
- To request deletion of your data, where applicable
- To withdraw consent, where processing is based on consent
- To restrict or object to certain processing activities
- To lodge a complaint with the Data Protection Commissioner
12. CONTACT DETAILS
If you have any questions or wish to exercise your rights, please contact our Data Protection Officer:
Name: SmarTree Consulting Ltd – Aurelie Sevene Email: [email protected] Phone: +230 5252 7501 Address: 3B, 3rd floor, Henessy Court Building, Pope Henessy Street, Port Louis
13. COMPLIANCE WITH DATA PROTECTION ACT 2017
All processing of personal data by HSFC shall be done in compliance with the Data Protection Act 2017. Non-adherence to this privacy policy by employees may lead to disciplinary actions by the Management.
14. OWNERSHIP
The privacy policy shall be maintained by the Data Protection Officer (“DPO”). All questions or comments related to this policy should be directed to our DPO.

