Privacy Notice
Policy version: 2.0
Effective Date: 10th September 2026
1. Introduction
At SWAN, comprising the entities listed in Annex 1 (hereafter “we”, “us”, “our”), safeguarding your personal data is one of our fundamental responsibilities. We take your privacy seriously and strive to ensure that your personal data is processed in a lawful, fair and transparent manner.
Our core principles:
- We only collect personal data that is relevant and necessary for us to provide you with our products and services.
- We process your personal data in accordance with applicable legal and regulatory requirements.
- We will not disclose your personal data to any third parties except where necessary, where required or permitted by law, or where we have obtained your consent.
- We aim to keep your personal data accurate and up to date.
- We maintain appropriate technical and organisational measures to ensure that your personal data is protected.
This Privacy Notice explains what personal data we collect and how we obtain it, the purposes and lawful bases for processing, with whom we may share your personal data, your rights, how long we keep your data and the security measures we have in place.
This Privacy Notice has been prepared in compliance with the Data Protection Act 2017 (DPA).
2. Scope
This Privacy Notice applies to:
- Individual clients, including policyholders, applicants and beneficiaries, and individuals representing, authorised by, or otherwise connected with corporate clients;
- Directors, shareholders, authorised signatories and ultimate beneficial owners;
- Employees and job candidates;
- Suppliers and business partners;
- Insurance agents, salespersons and brokers;
- Visitors to our website and offices/branches;
- Users of our mySWAN mobile application; and
- Third parties whose personal information is provided to us in connection with our services (e.g., dependents, employees or family members)
3. Definitions
We have aimed to use clear and simple language in this Privacy Notice. However, data protection is a complex subject, some technical terms are unavoidable. Below, we have provided definitions for the technical terms used in this Privacy Notice:
- “Children” mean any individual under 16 years old.
- “Consent” means any freely given, specific, informed and unambiguous indication of the wishes of a data subject, either by a statement or a clear affirmative action, by which he signifies his agreement to personal data relating to him being processed.
- “Controller” means a person who or public body which, alone or jointly with others, determines the purposes and means of the processing of personal data and has decision making power with respect to the processing.
- “Data subject” means an identified or identifiable individual, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.
- “Direct marketing” means the communication of any advertising or marketing material which is directed to any particular individual.
- “Personal data” means any information relating to a data subject.
- “Processor” means any person who, or public body which, processes personal data on behalf of the Controller.
- “Processing” means an operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- “Special categories of personal data”, in relation to a data subject, means personal data pertaining to: (a) his racial or ethnic origin; (b) his political opinion or adherence; (c) his religious or philosophical beliefs; (d) his membership of a trade union; (e) his physical or mental health or condition; (f) his sexual orientation, practices or preferences; (g) his genetic data or biometric data uniquely identifying him; (h) the commission or alleged commission of an offence by him; (I) any proceedings for an offence committed or alleged to have been committed by him, the disposal of such proceedings or the sentence of any Court in the proceedings; or (j) such other personal data as the Commissioner may determine to be sensitive personal data;
4. Children’s Personal Data
We may process the personal data of children where they are insured persons, dependents, or beneficiaries under a policy. In line with the DPA, consent from a parent or legal guardian is required and is captured at the time of application. We take reasonable steps to verify that such consent has been validly given.
5. Special Categories of Personal Data
Where we process special categories of personal data, including health data or criminal conviction information, we will only do so where permitted under the DPA and where appropriate safeguards are in place.
6. How We Collect Your Data
We may collect your personal data in the following ways:
- Directly from you (e.g., applications, claims, service requests, online forms, branch visits, etc.).
- From intermediaries (e.g., financial advisors, insurance agents, salespersons, brokers, etc.).
- From corporate clients (e.g., group insurance, pension schemes, etc.).
- From publicly available sources (e.g., public registers, etc.).
- From third parties (e.g., employers, insurance companies, credit organisations, motor vehicle and driver licensing authorities, financial institutions, medical professionals, etc.).
- From Non-Governmental Organisations under our Corporate Social Responsibility programme.
- Automatically via cookies via SWAN website. For more information on the cookies we use and how to manage them, please see our Cookie Notice.
- From mySWAN app and other SWAN platforms.
- From third parties to whom you have authorised disclosure.
- Through artificial intelligence-enabled tools and digital solutions used by SWAN, where applicable.
7. Mandatory and Voluntary Information
In certain cases, providing your personal data is mandatory because it is required by law or regulation (for e.g., to comply with employment, tax, AML/CFT/CPF, or corporate governance obligations) or because it is necessary for us to perform a contract with you (such as underwriting an insurance policy or processing a claim).
If you do not provide this mandatory information, we may not be able to proceed with or continue our relationship with you, or we may be prevented from complying with our legal obligations.
8. Types of Personal Data We Process
Depending on your relationship with SWAN and the products, services or facilities you use, request or interact with, we may process different categories of personal data.
The categories of personal data and examples listed below are provided for illustrative purposes only and are not exhaustive. SWAN may process other types of personal data where this is necessary, relevant and lawful, or where required or permitted under applicable laws and regulatory requirements.
| Categories of Personal Data | Examples |
| Identification and contact details | Name, surname, date of birth, National Identity Card number, telephone number, etc. |
| Policy, product and service information | Details relating to insurance policies, investment products, pension schemes, etc. |
| Financial and transactional information | Bank account details, payment details, salary, etc. |
| Health, medical and lifestyle information | Health declarations, medical reports, medical history, etc. |
| Family, beneficiary and dependent information | Details of spouse, children, dependents, beneficiaries, etc. |
| KYC/CDD, AML/CFT/CPF and compliance information | Proof of identity, proof of address, beneficial ownership information, etc. |
| Recruitment and employment-related information | CVs, qualifications, employment history, etc. |
| Corporate, shareholder and governance information | Directorship details, shareholding details, beneficial ownership details, etc. |
| Supplier, insurance agent, salesperson, broker and partner information | Contact details, contractual information, due diligence records, etc. |
| Communications and correspondence | Emails, letters, calls, etc. |
| Premises access and security information | Visitor logs, identification details, CCTV footage, etc. |
9. Purposes and Legal Basis for Processing Personal Data
We may process your personal data for a range of purposes connected with our products, services, operations and legal obligations, for example to provide quotations, process applications, underwrite insurance policies, perform customer due diligence, process claims, collect and process payments, comply with our legal and regulatory obligations, etc.
Depending on the purpose and the circumstances, we rely on one or more of the following lawful bases under the DPA:
- Performance of a contract with you, or taking steps at your request before entering into a contract.
- Compliance with our legal and regulatory obligations.
- Our legitimate interests or those of a third party, provided these are not overridden by your interests, rights and freedoms.
- Your consent, which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal.
- Protection of your vital interests or those of another person.
- Performance of a task carried out in the public interest or in the exercise of official authority.
- Historical, statistical or research purposes, where permitted by law and subject to appropriate safeguards.
Change of Purpose:
- Where we need to process your personal data for a purpose other than the purpose for which it was originally collected, we will only do so where the new purpose is compatible with the original purpose, where we have a valid legal basis under the DPA, or where we have obtained your consent, where required.
- Where necessary, we will provide you with further information before processing your personal data for a new purpose.
10. Automated Decision Making
We may use automated systems to assist us in decision-making processes. You have the right not to be subject to a decision based solely on automated processing.
11. Sharing of Your Personal Data
We may share your personal data with:
- SWAN entities, as listed in Annex 1;
- Reinsurers, insurance agents, salespersons and brokers;
- Medical service providers, opticians, hospitals and clinics;
- Business partners (for e.g., credit financing institutions, fraud reporting agencies, our advisers such as loss adjusters, and others involved in the claims handling process);
- Banks and payment providers;
- Third-party administrators and service providers;
- Corporate advisory partners and professional service providers;
- Regulators and public authorities (for e.g., FSC, FIU, BoM, MRA, DPO);
- Professional advisors (for e.g., auditors, accountants, actuaries, tax advisors, lawyers, consultants);
- Emergency assistance providers (for e.g., travel, medical emergencies);
Service Provider Safeguards:
Where we engage service providers (acting as processors), they are contractually bound to confidentiality and to use the personal data only for the purposes specified by SWAN.
Where we share personal data with controllers (such as regulators, banks, hospitals, or clinics), those parties are responsible for their own compliance with DPA. We only disclose the personal data that is necessary and proportionate for the relevant purpose.
12. International Data Transfers
Your personal data may be transferred outside Mauritius to a range of locations, including by our service providers and business partners. Where such transfers take place, we take appropriate steps to protect your personal data and to ensure that the transfer is carried out in accordance with the DPA.
We also use cloud service providers to host and process personal data. In doing so, we put in place appropriate contractual and organisational measures to protect your information and to comply with the requirements of the DPA.
All transfers are limited to the personal data strictly necessary for the relevant purpose, and we take steps to ensure that your information remains protected wherever it is processed.
13. Data Security
We prioritise the security of your personal data and maintain appropriate technical and organisational measures to protect confidentiality, integrity and availability, ensure business continuity, and minimise the impact of security incidents. We have procedures to handle personal data breaches and will notify you and the Data Protection Office where legally required.
Where artificial intelligence-enabled tools are used, SWAN applies appropriate access controls, monitoring, logging, confidentiality obligations, vendor due diligence and other relevant technical and organisational measures to protect personal data processed through such technologies.
14. Data Retention
We collect and process personal data for specific purposes and retain it only as long as necessary for those purposes and in line with statutory requirements.
As a general rule, personal data is retained for up to seven (7) years after the end of the business relationship, in accordance with legislation such as the Financial Services Act and the Companies Act.
Personal data that have reached the retention period will be deleted, while the remaining records will be retained until the retention period of 7 years has expired. Where required, we may retain personal data longer to comply with regulatory or legal obligations, or to establish, exercise or defend legal claims.
15. Your Rights
As a data subject, you have certain rights regarding your personal data as detailed below and we are committed to facilitating the exercise of these rights:
- Right to Access: You have the right to request access to the personal data we hold about you. This includes the right to obtain confirmation of whether we process your personal data and to receive a copy of that information.
- Right to Rectification: If you believe that the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or update it.
- Right to Erasure: In certain circumstances, you may have the right to request the erasure of your personal data. This includes situations where your personal information is no longer necessary for the purposes for which it was collected, or you withdraw your consent and there is no other legal basis for processing.
- Right to Restriction of Processing: You have the right to request the restriction of the processing of your personal data under certain conditions. This means we will temporarily suspend the processing of your personal data, such as when you contest its accuracy or when you object to the processing.
- Right to Object: You have the right to object to the processing of your personal data for certain reasons, such as direct marketing or legitimate interests. If you exercise this right, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
- Right to Withdraw Consent: If we rely on your consent as the legal basis for processing your personal data, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data, or to exercise any of your other rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask for further information in relation to your request to help us respond more quickly.
To exercise your rights, please contact our Data Protection Officer and include the type of request, such as access, deletion or modification.
You also have a right to lodge a complaint with the Mauritius Data Protection Office (http://dataprotection.govmu.org)
Time limit to respond
We aim to respond to all legitimate requests within one month. Where a request is particularly complex, or where multiple requests have been submitted, additional time may be required. In such circumstances, we will inform you accordingly and keep you updated on the progress of your request.
16. Your Responsibilities
You are responsible for ensuring that the personal data you provide is true, accurate and not misleading.
Where you provide information about another person (for e.g., dependents), you are responsible for obtaining any consent necessary for us to collect and use that data as described in this Notice.
17. Contact Us
For inquiries or to exercise your data protection rights, please contact our Data Protection Officer as follows:
Email: dataprotection@swanforlife.com
Address: Swan Centre, 10 Intendance Street, Port Louis, Mauritius
18. Changes to this Notice
We may update this Notice from time to time to reflect best practices in data management, security and control, and to ensure compliance with any changes or amendments to the DPA and any related laws or regulations. We encourage you to check our website periodically so that you remain aware of our latest privacy practices. This Notice was last updated on 10th September 2026.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
ANNEX 1
| LIST OF SWAN ENTITIES REGISTERED AS CONTROLLERS AND PROCESSORS OF PERSONAL DATA WITH THE DATA PROTECTION OFFICE | |
| DATA CONTROLLERS | DATA PROCESSORS |
|
SWAN GENERAL LTD SWAN LIFE LTD SWAN PENSIONS LTD SOCIETE DE LA CROIX SOCIETE DE LA MONTAGNE SOCIETE DE LA RIVIERE SWAN ACTUARIAL SERVICES LTD SWAN CORPORATE ADVISORS LTD SWAN CORPORATE AFFAIRS LTD SWAN FOREX LTD SWAN FOUNDATION SWAN REINSURANCE PCC SWAN GLOBAL FUNDS LTD SWAN CMB SECURITIES LTD SWAN BONDS LTD (FORMERLY KNOWN AS SWAN SMART ACHIEVER NOTES LTD) SWAN SPECIAL RISKS COMPANY LTD SWAN WEALTH MANAGERS LTD SWAN LENDING SOLUTIONS LTD (FORMERLY KNOWN AS SWAN WEALTH STRUCTURED PRODUCTS LTD) |
SWAN GENERAL LTD SWAN LIFE LTD SWAN PENSIONS LTD SWAN ACTUARIAL SERVICES LTD |


SWAN Centre
10 Intendance Street
Port Louis
Clotilde Domingue
Data Protection Officer