Bluefox SAS · Governance & Trust
Privacy Notice
How Bluefox SAS collects, uses, protects and discloses your personal data, in accordance with the Data Protection Act 2017 of Mauritius, the EU General Data Protection Regulation and the Australian Privacy Act 1988. Last updated: August 2026
CONTENTS
1. Introduction
This Privacy Policy explains how Bluefox SAS ("Bluefox", "we", "us" or "our") obtains, uses, discloses and protects your personal data when you visit our website at www.bluefoxsas.com, enquire about our work, book a discovery call, attend one of our programmes, or engage us as a client.
We work with organisations on transformation, change and leadership. That work runs on trust, and a good deal of it involves what people tell us in confidence. We hold ourselves to the same standard with your personal data: processed lawfully, fairly and transparently, in compliance with the data protection law that applies to you.
2. Which law applies to you
Bluefox operates in Mauritius and Australia, and works with clients and programme participants in other countries. Three frameworks are therefore relevant, and which one governs our handling of your data depends on where you are and how we came to hold it.
Framework | When it applies |
|---|---|
Privacy Act 1988 (Cth) of Australia
and the 13 Australian Privacy Principles ("the APPs") | To our Australian activities and to personal information we collect in or from Australia. Where the Privacy Act does not formally bind us, we apply the APP standards to that information as a matter of practice. |
EU General Data Protection Regulation
Regulation (EU) 2016/679 ("the GDPR") | Where we offer services to, or monitor the behaviour of, individuals located in the European Union or European Economic Area. In practice this covers EU-based clients, programme participants, coaching clients and enquirers. |
Data Protection Act 2017 of Mauritius
Act 20 of 2017 ("the DPA") | To all of our processing. Bluefox SAS is established in Mauritius, so the DPA applies to everything described in this policy, together with any regulations, codes of practice and guidelines issued under it. |
The three frameworks are closely aligned in principle and differ in detail. Where they differ, we apply the higher standard of protection, and we do not use a difference between them to give you less than any one of them requires. Section 17 sets out which rights arise under which framework.
3. Who we are
Bluefox SAS is a strategy and transformation consultancy registered in Mauritius, operating in Mauritius and Australia. We deliver organisational transformation, change management, AI transformation roadmaps, leadership coaching, project delivery and strategic advisory work, together with training programmes including The Human Advantage.
Legal Name
BFSAS & Associates Ltd
Business Registration Number
C24214542
Registered office
Les Flamants Lane, Pereybere
Australian entity or ABN
58 927 244 033
Telephone
+(230) 52 51 02 40 / +(61) 481 839 286
Bluefox SAS is the controller of the personal data described in this policy, under the DPA and, where it applies, the GDPR. Under the Privacy Act we are the APP entity responsible for the personal information we hold.
​
We are registered as a controller with the Data Protection Commissioner of Mauritius in accordance with Part III of the DPA. Registration number: C23750.
​
In accordance with section 22(2)(e) of the DPA, we have designated an officer responsible for data protection compliance: Farhanaaz Jhumka. They can be reached using the contact details in section 20.
4. Key definitions
The three frameworks use slightly different vocabulary for the same ideas. The DPA and the GDPR say personal data, data subject, controller and processor; the Privacy Act says personal information, individual and APP entity. We use the DPA terms throughout this policy, and they should be read as covering their Australian equivalents.
​
-
Personal data means any information relating to a data subject. Under the Privacy Act, personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
-
Data subject means an identified or identifiable individual, for example someone identifiable by name, identification number, location data, an online identifier, or factors specific to their physical, economic, cultural or social identity.
-
Processing means any operation performed on personal data, whether or not automated, including collection, recording, storage, use, disclosure, erasure and destruction.
-
Consent means a freely given, specific, informed and unambiguous indication of your wishes, by statement or clear affirmative action, signifying your agreement to the processing of your personal data.
-
Special categories of personal data (called sensitive information under the Privacy Act) include data revealing racial or ethnic origin, political opinion, religious or philosophical beliefs, trade union membership, physical or mental health, sexual orientation, genetic or biometric data, and data relating to offences or proceedings.
5. The personal data we collect
We collect only the personal data that is adequate, relevant and limited to what is necessary for the purposes described in this policy, in accordance with section 21(c) of the DPA, Article 5(1)(c) of the GDPR and APP 3.
​
-
Identity and contact details — your name, email address, telephone number, organisation, job title and the reason you got in touch, provided when you enquire, book a discovery call, subscribe to updates or contact us.
-
Engagement information — contact details for the people we work with on your side, information about your organisation, the material you share with us during an engagement, and our notes, correspondence, invoices and payment records.
-
Programme information — your name, employer, job title, contact details, attendance records, and any assessment or exercise responses that form part of a programme. For HRDC-eligible programmes we also collect the information the Human Resource Development Council requires in order to process a grant or refund, as required by the HRDC
-
Coaching records — what you tell us in sessions, and the notes we keep so that the next session is useful.
-
Correspondence — the content of enquiries, messages and feedback you send us.
-
Website usage information — technical data such as your IP address, approximate location, device and browser type, pages visited, time on the site and links clicked, collected through cookies and analytics tools as described in section 12.
-
Application information — where you apply to work with us or alongside us, your CV, work history, qualifications and references.
-
​
Where you provide personal data to us, we will indicate which information is required to deliver the relevant service and which is optional.
6. How we collect your data
We collect personal data primarily directly from you, when you:
​
-
complete a contact or enquiry form on our website;
-
book a discovery call through our scheduling tool;
-
subscribe to our mailing list or communications;
-
register for or attend a training programme or coaching engagement;
-
engage us as a client and work with us on a project;
-
correspond with us by email, telephone, LinkedIn or otherwise.
Where your personal data is provided to us by someone else, for example where your employer enrols you on a programme or nominates you as its contact for an engagement, we will ensure that you are informed of the matters set out in this policy, as required by section 23 of the DPA, Article 14 of the GDPR and APP 5.
7. Lawful basis for processing
We process personal data only where a lawful basis under section 28 of the DPA and, where applicable, Article 6 of the GDPR applies. Under the Privacy Act, collection is governed by APP 3 and use and disclosure by APP 6: we collect only what is reasonably necessary for our functions, and we use or disclose it only for the purpose we collected it for, for a directly related purpose you would reasonably expect, or with your consent.
What we do | Lawful basis |
|---|---|
Operate, secure and improve the website; keep records of engagements in case of a legal claim | Legitimate interests, except where the processing would be unwarranted having regard to your rights and freedoms (s.28(1)(b)(vii) DPA; Art. 6(1)(f) GDPR; APP 6.2(a)) |
Send you information about our work | Your consent (s.28(1)(a) DPA; Art. 6(1)(a) GDPR; APP 7) |
Submit training records to the HRDC; invoice, take payment and keep accounts | Compliance with a legal obligation (s.28(1)(b)(ii) DPA; Art. 6(1)(c) GDPR; APP 6.2(b)) |
Deliver consultancy, training and coaching | Performance of a contract (s.28(1)(b)(i) DPA; Art. 6(1)(b) GDPR; APP 6.1) |
Respond to enquiries and hold discovery calls | Steps taken at your request before entering into a contract (s.28(1)(b)(i) DPA; Art. 6(1)(b) GDPR; APP 3.2 and APP 6.1) |
In accordance with section 24 of the DPA and Article 7 of the GDPR, where we rely on your consent, Bluefox bears the burden of proving that consent was given. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal. We will never make a service conditional on consent to processing that is not necessary for that service.
8. How we use your data
We use your personal data only for the explicit, specified and legitimate purposes for which it was collected, namely to:
​
-
respond to your enquiry and work out whether we can help;
-
schedule and hold discovery calls;
-
scope, deliver and administer consultancy, transformation and change engagements;
-
run training programmes, including registration, attendance and completion records, and HRDC administration where the programme is eligible;
-
deliver coaching, and keep the records that make it continuous and useful;
-
keep you informed of our work where you have subscribed or consented;
-
maintain the security, performance and integrity of our website;
-
produce aggregated, anonymised statistics on engagement with our work, which do not identify any individual;
-
meet our legal, tax and regulatory obligations.
We do not sell personal data, we do not trade it, and we do not pass it to advertisers. We do not use personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you.
​
In accordance with APP 7, we use personal information for direct marketing only where you would reasonably expect it or where you have consented, every marketing message contains a simple means of opting out, and we act on an opt-out request promptly. We do not use or disclose sensitive information for direct marketing.
9. Special categories and sensitive information
We do not seek special categories of personal data through our website, our enquiry process or our general activities.
​
Coaching and leadership work can nonetheless surface things about a person's health, beliefs or circumstances. Where that happens, we process such data only with the explicit consent of the person concerned and with the safeguards required by section 29 of the DPA, Article 9(2)(a) of the GDPR and APP 3.3. We keep it separate from general client records, and we do not disclose it to your employer or anyone else without your specific agreement.
​
Where you tell us about a dietary requirement or an accessibility need for a training session, we collect it only for that purpose and delete it once the purpose has lapsed.
10. Personal data of children
Our services are directed at organisations and working professionals, and we do not knowingly process the personal data of anyone under 16.
​
In accordance with section 30 of the DPA, we will not process the personal data of a child below 16 unless consent is given by the child's parent or guardian, and we will make every reasonable effort, taking into account available technology, to verify that such consent has been given. This is consistent with Article 8 of the GDPR, under which parental consent is likewise required for children below 16, or a lower age not below 13 set by an individual EU member state.
​
The Privacy Act does not set a fixed age of consent and instead asks whether an individual has the capacity to consent, assessed case by case. We apply the age of 16 uniformly, which meets or exceeds the requirement in every jurisdiction where we operate. If you believe we hold data about a child, write to us and we will delete it.
11. Disclosure of your data
We do not disclose your personal data to third parties except as described below:
​
-
Service providers (processors) — our website and form host (Wix), our scheduling tool (Calendly), our email and document platform (Microsoft 365), and our payment provider (MCB Bank). In accordance with section 31(4) of the DPA and Article 28 of the GDPR, we choose processors that provide sufficient guarantees of security, and we enter into written contracts requiring them to act only on our instructions and to apply the security obligations that bind us.
-
The Human Resource Development Council — participant records for HRDC-eligible programmes.
-
Your employer — where your employer has commissioned the programme or engagement, we report attendance and completion. We do not report what you said in a coaching session or a confidential exercise.
-
Associates and subcontractors — who are bound by written confidentiality and data protection terms before they are given access to anything.
-
Professional advisers and regulators — where we have a duty or right to disclose under applicable law, including to the Data Protection Office of Mauritius or the Office of the Australian Information Commissioner, or where disclosure is necessary for the establishment, exercise or defence of a legal claim.
Any disclosure incompatible with the purposes for which your data was collected is an offence under section 42 of the DPA, and we do not make such disclosures.
12. Cookies and analytics
Our website uses cookies, small files placed on your device that generally contain an anonymous unique identifier, to enable core functionality, keep the site secure and collect standard visitor usage information. The site is built on Wix, which sets cookies for these purposes, and we use analytics to understand which pages people read.
​
You can refuse non-essential cookies through the banner on the site, and you can enable, disable or delete cookies at any time through your browser settings. Refusing analytics cookies does not stop you using the site, though disabling all cookies may limit some functionality. Where the GDPR applies, non-essential cookies are set only after you consent, and you may withdraw that consent at any time.
​
Refer here for cookies list, provider and duration
13. Security of processing
In accordance with section 31 of the DPA, Article 32 of the GDPR and APP 11, we implement appropriate security and organisational measures to protect personal data from misuse, interference and loss, and from unauthorised access, alteration, disclosure or destruction, proportionate to the harm that might result and the nature of the data concerned. Our measures include:
​
-
access controls limiting personal data to those who need it for their role;
-
multi-factor authentication on systems that hold personal data;
-
encryption of data in transit, and encryption of stored data on devices;
-
measures to ensure the ongoing confidentiality, integrity, availability and resilience of our processing systems;
-
the ability to restore availability and access to personal data in a timely manner after a physical or technical incident;
-
periodic review of who has access to what, and of whether these measures still work;
-
confidentiality and data protection terms in every associate and subcontractor agreement.
No system is beyond compromise. Section 16 sets out what we do if something goes wrong.
14. Retention and destruction
In accordance with section 21(e) of the DPA, Article 5(1)(e) of the GDPR and APP 11.2, we keep personal data in a form that permits your identification for no longer than is necessary for the purposes for which it was collected.
Data | Retention Period |
|---|---|
Unsuccessful applications | 7 years, unless you ask us to destroy your data |
Mailing list data | Until you unsubscribe or withdraw consent |
Training and HRDC records | As required by the HRDC and by tax law |
Coaching session notes | 7 years from the end of the engagement |
Client engagement records | 7 years from the end of the engagement, for accounting and limitation purposes |
Enquiries that do not become engagements | 12 months from last contact |
Website analytics | 26 months |
In accordance with section 27 of the DPA, once the purpose for keeping personal data has lapsed, we destroy the data as soon as is reasonably practicable and notify any processor holding it to do the same. APP 11.2 requires the same of us for personal information collected in Australia: where we no longer need it for any permitted purpose and are not required by law to keep it, we destroy it or de-identify it. Where we retain data for statistical purposes, we anonymise it so that it can no longer identify you.
15. Cross-border transfers
Bluefox SAS operates in Mauritius and Australia, and some of our service providers store or process data on servers located outside those countries, including in the United States and the European Union.
​
Out of Mauritius
Where personal data is transferred outside Mauritius, we do so only in accordance with section 36 of the DPA: where appropriate safeguards for the protection of the data are in place, where you have given explicit consent to the transfer after being informed of the possible risks, or where another condition under section 36 applies, such as the transfer being necessary for the performance of a contract with you. We rely principally on written contractual safeguards with each provider, and the Data Protection Commissioner may request proof of the effectiveness of those safeguards at any time.
​
Out of the EU or EEA
Where personal data of individuals in the EU or EEA is transferred to Mauritius, Australia or another country outside the EEA, we rely on the transfer mechanisms in Chapter V of the GDPR. Neither Mauritius nor Australia is currently the subject of an EU adequacy decision, so such transfers are made under appropriate safeguards, principally the European Commission's Standard Contractual Clauses entered into with the relevant recipient, or, where no safeguard is available, under a specific derogation in Article 49 such as your explicit consent or the necessity of the transfer for a contract with you.
​
Out of Australia
Before we disclose personal information collected in Australia to an overseas recipient, APP 8 requires us to take reasonable steps to ensure that the recipient does not breach the APPs in relation to that information. We do this through the written contracts described in section 11. You should be aware that, under section 16C of the Privacy Act, we generally remain accountable to you for an overseas recipient's handling of your information as if we had done it ourselves.
16. Personal data breaches
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. If one occurs, Bluefox SAS will:
​
-
notify the Data Protection Commissioner of Mauritius without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with section 25 of the DPA, and, where the breach concerns individuals in the EU or EEA, notify the competent EU supervisory authority within the same 72-hour period under Article 33 of the GDPR;
-
where the breach is likely to result in a high risk to your rights and freedoms, communicate the breach to you without undue delay, in clear language, together with recommended measures to mitigate its possible adverse effects, in accordance with section 26 of the DPA and Article 34 of the GDPR; and
-
where the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act applies, assess any suspected eligible data breach within 30 days and, where the breach is likely to result in serious harm to any individual affected, notify the Office of the Australian Information Commissioner and the individuals at risk as soon as practicable, with a statement setting out what happened, what information was involved and what we recommend you do.
Where a processor acting on our behalf becomes aware of a breach, it is required to notify us without undue delay.
17. Your rights as a data subject
Your rights depend on which framework applies to you, as set out in section 2. The table below sets out each right, what it means, and where it comes from. All of them are free to exercise, and all requests can be made using the contact details in section 20.
Right
What it means
Applies under
Access
You may request confirmation of whether we process personal data relating to you and a copy of that data, together with information about the purposes, categories, recipients, retention period, source and safeguards involved.
DPA s.37
GDPR Art. 15
APP 12
Correction
You may ask us to correct inaccurate, out-of-date, incomplete, irrelevant or misleading personal data without undue delay. Where we have disclosed the data to someone else, you may ask us to tell them of the correction.
DPA s.39
GDPR Art. 16
APP 13
Erasure
You may ask us to erase your personal data where it is no longer necessary for the purpose collected, where you withdraw consent and no other legal ground applies, where you object and no overriding legitimate ground exists, or where the data has been unlawfully processed.
DPA s.39
GDPR Art. 17
No equivalent standalone right under the Privacy Act, though APP 11.2 requires us to destroy or de-identify information we no longer need
Restriction
You may ask us to restrict processing, for example while the accuracy of your data is being verified, or where you require the data for a legal claim after we no longer need it.
DPA s.39
GDPR Art. 18
Portability
Where processing is based on your consent or a contract and carried out by automated means, you may receive the personal data you provided in a structured, commonly used and machine-readable format, and have it transmitted to another controller where technically feasible.
GDPR Art. 20
Objection
You may object in writing at any time to the processing of your personal data. We must stop unless we can demonstrate compelling legitimate grounds that override your interests, or unless we need the data for a legal claim.
DPA s.40
GDPR Art. 21
Direct marketing
You may object to direct marketing at any time, including any related profiling, and we will stop. This right is absolute. You may also ask us to tell you where we obtained your details.
DPA s.40
GDPR Art. 21(2)
APP 7.6
Anonymity or pseudonymity
You may deal with us without identifying yourself, or using a pseudonym, where that is lawful and practicable, for example when making a general enquiry.
APP 2
Automated decisions
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or significantly affects you. We do not carry out such processing: assessments used in our programmes inform a human judgement, they do not replace one.
DPA s.38
GDPR Art. 22
Withdraw consent
Where processing is based on your consent, you may withdraw it at any time, for example by using the unsubscribe link in any email, without affecting processing carried out before withdrawal.
DPA s.24
GDPR Art. 7(3)
We will tell you in writing within one month of your request what we have done. Where a request is complex we may take one further month, and we will tell you why. If we refuse to act on a request, we will tell you in writing within one month, with the reason and your right to lodge a complaint (s.37(5) and (6) DPA; Art. 12(3) and (4) GDPR). Under APP 12 and APP 13 we respond to access and correction requests within a reasonable period, and in practice we apply the same one-month standard.
​
To protect your data, we may ask for proof of identity before acting on a request. Under section 41 of the DPA, rights may also be exercised on your behalf by a parent or guardian where the data subject is a minor, by a court-appointed guardian or administrator, or by a person you have duly authorised in writing.
18. Complaints
If you believe that we have handled your personal data in contravention of the law that applies to you, contact us first so that we can try to resolve it directly. You also have the right at any time to complain to the relevant regulator.
Mauritius — Data Protection Office
5th Floor, SICOM Tower, Wall Street, Ebène, Republic of Mauritius
Telephone: +230 460 0251
Email: dpo@govmu.org
Website: dataprotection.govmu.org
If you are dissatisfied with a decision of the Commissioner, section 51 of the DPA allows you to appeal to the ICT Appeal Tribunal within 21 days of the decision being made known to you.
Australia — Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001, Australia
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au
Website: oaic.gov.au
The OAIC will normally expect you to have raised the matter with us first and given us a reasonable opportunity to respond, ordinarily 30 days.
European Union and EEA — your national supervisory authority
Where the GDPR applies to our processing of your personal data, you may lodge a complaint with the supervisory authority of the member state in which you habitually reside, in which you work, or in which the alleged infringement took place (Art. 77 GDPR). A list of supervisory authorities is published by the European Data Protection Board at edpb.europa.eu.
19. Changes to this policy
​We may revise this Privacy Policy from time to time, for example to reflect changes in our activities, in the law, or in guidance issued by the regulators named above. Australian privacy law in particular is under active reform, and we will update this policy as those reforms take effect. The current version will always be published on this page with its "last updated" date, and we will highlight material changes through our website and, where appropriate, our mailing list.
20. How to contact us
For any question about this policy, our privacy practices, or to exercise any of your rights, please contact:
Bluefox SAS
Attention: Farhanaaz Jhumka, Data Protection Compliance
Les Flamants Lane, Pereybere
Email: contact@bluefoxsas.com
Telephone: (230) 52 51 02 40 / (61) 481 839 286
Website: www.bluefoxsas.com
This Privacy Policy is issued pursuant to the Data Protection Act 2017 of Mauritius and aligned with Regulation (EU) 2016/679 (GDPR) and the Privacy Act 1988 (Cth) of Australia. Nothing in this policy limits any right you have under the DPA, the GDPR, the Privacy Act or any other applicable law.
Bluefox Strategic Advisory Services
Strategy and transformation across Mauritius and Australia.
​
© 2026 Bluefox SAS · bluefoxsas.com
