Privacy Policy

1.  Introduction

The Cloud Factory EMEA Ltd ("The Cloud Factory", "we", "us" or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard your personal data when you visit our website www.tcf.cloud(opens in new tab) (the "Website"), contact us, or use our services, and it sets out your rights under applicable data protection law.

This policy is designed to comply with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

Please read this policy carefully to understand our practices regarding your personal data.

2.  Who We Are (Data Controller)

For the purposes of applicable data protection law, the data controller is:

The Cloud Factory EMEA Ltd 1, The Factory Building, Vivéa Business Park, Moka, Mauritius Also operating as: TCF EMEA Ltd, [UK registered address] Email: [privacy@tcf.cloud](opens in new tab)
Telephone: +230 433 7629 (Mauritius) / +44 20 8078 7251 (UK)

[If applicable: Our UK/EU representative for data protection matters is [name and contact details].]

3.  The Personal Data We Collect

We may collect and process the following categories of personal data:

· Contact and enquiry data — name, email address, telephone number, company name, job title, and the content of any message you send us via our contact form, booking form, or email.

· Booking data — information you provide when booking a consultation or registering for an event or workshop.

· Technical data — IP address, browser type and version, device information, operating system, and other technology on the devices you use to access the Website.

· Usage data — information about how you use our Website, including pages visited, time spent, and referral sources.

· Marketing and communications data — your preferences in receiving marketing from us and your communication preferences.

We do not intentionally collect any special categories of personal data (such as health, race, religion, or biometric data) through the Website.

4.  How We Collect Your Personal Data We collect personal data:

· Directly from you — when you complete a contact or booking form, subscribe to our communications, register for an event, or contact us by email or phone.

· Automatically — as you navigate the Website, through cookies and similar technologies (see our Cookie Policy).

· From third parties — such as analytics providers and, where relevant, publicly available business sources.

5.  How We Use Your Personal Data and Our Legal Basis

Under the UK and EU GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases:

Purpose

Lawful basis

To respond to your enquiries and provide requested information

Legitimate interests / Steps to enter into a contract

To arrange and deliver consultations, events and services

Performance of a contract / Legitimate interests

To manage our relationship with you and our clients

Legitimate interests / Performance of a contract

To send marketing communications (where permitted)

Consent / Legitimate interests

To improve and secure our Website

Legitimate interests

To comply with legal and regulatory obligations

Legal obligation

Where we rely on legitimate interests, these are to operate, promote and grow our

business, respond to enquiries, and provide relevant services — balanced against your rights and freedoms. Where we rely on consent, you may withdraw it at any time.

6.  Marketing Communications

We may send you marketing communications about our services, insights and events where you have consented, or where we have a legitimate interest (for example, to existing business contacts about similar services). You can opt out at any time by clicking "unsubscribe" in any email or by contacting us at [privacy@tcf.cloud](opens in new tab). We will not sell your personal data to third parties for their own marketing.

7.  Cookies and Similar Technologies

Our Website uses cookies and similar technologies to function correctly, analyse traffic, and improve your experience. Non-essential cookies are only set with your consent. For full details, please see our [Cookie Policy].

8.  How We Share Your Personal Data We may share your personal data with:

· Service providers and processors — such as website hosting, IT, CRM, email, analytics and scheduling providers (e.g. Microsoft) who process data on our behalf under appropriate contractual safeguards.

· Professional advisers — including lawyers, accountants and auditors.

· Regulators and authorities — where required by law.

· Business transfers — in connection with any merger, acquisition or sale of assets.

All third-party processors are required to respect the security of your personal data and to process it only in accordance with our instructions and applicable law.

9.  International Transfers

As we operate in Mauritius, the UK and Europe, your personal data may be transferred to and processed in countries outside the UK and the European Economic Area (EEA), including Mauritius.

Where we transfer personal data internationally, we ensure an appropriate level of protection through legally recognised safeguards, such as:

· UK/EU adequacy decisions, where available; or

· Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) or Addendum; together with additional safeguards where required.

You may contact us for more information about the safeguards in place.

10.  Data Retention

We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting

requirements. Enquiry and marketing data is typically retained for [e.g. 24–36 months] from your last interaction with us, unless a longer period is required by law. When no longer required, data is securely deleted or anonymised.

11.  Data Security

We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, loss or

destruction. These include access controls, encryption, secure Microsoft cloud infrastructure, and staff confidentiality obligations. However, no method of

transmission over the internet is completely secure, and we cannot guarantee absolute security.

12.  Your Data Protection Rights

Under the UK and EU GDPR, you have the following rights:

· Right to be informed — about how your data is used (this policy).

· Right of access — to request a copy of the personal data we hold about you.

· Right to rectification — to have inaccurate or incomplete data corrected.

· Right to erasure — to request deletion of your data in certain circumstances ("right to be forgotten").

· Right to restrict processing — to limit how we use your data.

· Right to data portability — to receive your data in a structured, commonly used format.

· Right to object — to processing based on legitimate interests or for direct marketing.

·  Rights related to automated decision-making — we do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

To exercise any of these rights, please contact us at [privacy@tcf.cloud](opens in new tab). We will respond within one month, as required by law. You will not usually have to pay a fee.

13.  Your Right to Complain

If you have concerns about how we handle your personal data, please contact us first and we will do our best to resolve them.

You also have the right to lodge a complaint with a supervisory authority:

· UK: the Information Commissioner's Office (ICO) — www.ico.org.uk(opens in new tab)

· EU: the data protection authority in your country of residence.

· Mauritius: the Data Protection Office — dataprotection.govmu.org(opens in new tab)

14.  Third-Party Links

Our Website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review their privacy policies.

15.  Children's Privacy

Our Website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from anyone under the age of 16.

16.  Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review it periodically.

17.  Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:

The Cloud Factory EMEA Ltd Email: [privacy@tcf.cloud](opens in new tab) Telephone: +230 433 7629 (Mauritius) / +44 20 8078 7251 (UK) Address: 1, The Factory Building, Vivéa Business Park, Moka, Mauritius