Legal

Privacy Policy

How iLeap collects, uses, protects and shares personal data, in accordance with the Data Protection Act 2017 of Mauritius.
Last updated: 25 July 2026

01Who we are

iLeap is a training administration platform built for training institutions in Mauritius. It supports the full training lifecycle — training registration, client bookings, attendee management, attendance tracking, compliance documentation and certificate generation.

The website ileap.app and the iLeap platform are operated by Red Peach Ltd, a company registered in Mauritius under business registration number C25229658, with its registered office at No 98, Royal Road, Morc Ashviva, Trou aux Biches, Mauritius ("iLeap", "we", "us", "our").

We are registered with the Data Protection Office of Mauritius as a controller and processor under the Data Protection Act 2017 (the "Act")

Our designated officer responsible for data protection compliance can be reached at contact@ileap.app.

02Scope of this policy

This policy explains how we handle personal data when you:

  • Visit ileap.app or join our launch waitlist;
  • Contact us by email or through the website;
  • Use the iLeap platform as a training institution administrator, trainer, or client HR user; or
  • Are a training participant whose details are entered on the platform by a training institution or your employer.

It applies to processing of personal data wholly or partly by automated means, and to non-automated processing forming part of a filing system, as provided under section 3 of the Act.

03Our role: controller and processor

Under the Act, our responsibilities depend on the context in which your data is processed.

Where iLeap is the controller

We determine the purposes and means of processing — and are the controller — for:

  • The ileap.app website, waitlist and marketing communications;
  • Account registration and authentication for all platform users;
  • Platform usage, security and audit data.

Where iLeap is the processor

When a training institution or a client organisation enters personal data about trainers, contact persons or training participants into the platform, that organisation is the controller of the data and iLeap processes it on the organisation's behalf and on its instructions, under a written agreement as required by section 31(4) of the Act.

If you are a training participant: your details were provided to iLeap by your employer or a training institution. Requests to access, correct or erase your data should be directed to that organisation in the first instance. We will assist them in responding, and you may also contact us at contact@ileap.app.

04Personal data we collect

ContextPersonal dataSupply
Website & waitlist Name and email address you submit to join the waitlist or contact us Voluntary
Platform accounts Name, email address, phone number, role, organisation, login credentials Mandatory to use the platform
Training institution & client profiles Contact person name, business email and phone number, organisation details Mandatory for bookings and compliance
Trainer profiles Name, contact details, CV, qualifications, references, identity document Mandatory for trainer registration
Training participants First name, last name, national identity number, email address, phone number, attendance records, certificates issued Provided by the booking organisation; required for compliance documentation
Training feedback Questionnaire responses linked to a training session; anonymised where required Voluntary
Technical data IP address, browser and device information, log and audit trail data Collected automatically

We do not collect personal data beyond what is adequate, relevant and necessary for the purposes described in this policy, in line with section 21 of the Act.

05Why we process personal data

We process personal data only where a lawful basis under section 28 of the Act applies:

PurposeLawful basis
Managing the launch waitlist and sending you updates about iLeap Your consent, which you may withdraw at any time
Creating and administering platform accounts; delivering the platform's features (bookings, attendance, certificates, documentation) Performance of a contract
Generating compliance and refund documentation required by Mauritian training authorities on behalf of training institutions and their clients Performance of a contract; compliance with legal obligations of the controller organisation
Sending service notifications (booking confirmations, expiry reminders, feedback forms) Performance of a contract; legitimate interests
Securing the platform, maintaining audit trails, preventing fraud and misuse Legitimate interests; compliance with legal obligations
Improving the platform through aggregated, anonymised usage analysis Legitimate interests

We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

We do not sell personal data, and we do not use personal data for direct marketing without your consent. Where data is processed for direct marketing, you have the right to object at any time and we will stop.

06Special categories of data

We do not intentionally collect special categories of personal data as defined in the Act — such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual orientation, or genetic and biometric data.

Identity documents and CVs uploaded by trainers should not contain such data beyond what appears on standard identity documents. Where any special category data is incidentally processed, we apply the safeguards required by section 29 of the Act and restrict access to authorised personnel only.

07Children's data

iLeap is a professional platform and is not directed at children. We do not knowingly process the personal data of a child below the age of 16 without the consent of the child's parent or guardian, as required by section 30 of the Act. Organisations entering participant data on the platform are responsible for ensuring this consent exists where a participant is under 16. If you believe a child's data has been provided to us without proper consent, contact us and we will take appropriate action.

08Who we share data with

We disclose personal data only to the following categories of recipients, and only to the extent necessary:

  • Within the platform: access is role-based and organisation-scoped. Training institutions, trainers and client HR users see only the data relevant to their own trainings and organisation. Cross-organisation visibility is not permitted.
  • Compliance documentation: the platform generates documents (registration forms, attendance sheets, certificates and refund documentation) containing participant and trainer data, which the training institution or client organisation submits to the relevant Mauritian authorities.
  • Service providers: trusted providers who process data on our behalf under written contracts consistent with section 31(4) of the Act — including our hosting provider and our email service provider (MailerLite, which manages our waitlist and email communications).
  • Legal requirements: where disclosure is required by law, by a court order, or by a lawful request of the Data Protection Commissioner or another competent authority.

We never disclose personal data in a manner incompatible with the purposes for which it was collected.

09Transfers outside Mauritius

Some of our service providers store data on servers located outside Mauritius. In particular, waitlist and email communication data is processed by MailerLite on servers located in the European Union.

Where personal data is transferred outside Mauritius, we do so in accordance with section 36 of the Act — ensuring appropriate safeguards are in place with respect to the protection of the data, or relying on your explicit consent or another condition permitted by the Act. You may contact us for information on the safeguards applied to any transfer.

10How we protect data

In accordance with section 31 of the Act, we implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, accidental loss and destruction, including:

  • Encryption of data in transit and at rest;
  • Role-based access control, so users see only the data their role requires;
  • Authentication controls on all platform accounts;
  • Audit trails recording changes to critical records, which are read-only;
  • Regular testing and evaluation of the effectiveness of our security measures;
  • Staff awareness of, and contractual commitment to, our security obligations.

For processing likely to present a high risk to the rights and freedoms of data subjects, we carry out data protection impact assessments and consult the Data Protection Office where required by sections 34 and 35 of the Act.

11How long we keep data

We keep personal data only in a form that permits your identification for as long as necessary for the purposes for which it was collected:

  • Waitlist data is kept until launch communications conclude or you unsubscribe, whichever is earlier;
  • Account data is kept for the duration of your account and deleted or anonymised following closure, subject to any legal retention obligation;
  • Training and compliance records are retained for the periods required by the controller organisation's regulatory obligations, after which they are destroyed or anonymised;
  • Audit and security logs are retained for as long as needed to secure the platform and demonstrate compliance.

Where the purpose for keeping personal data has lapsed, we destroy the data as soon as reasonably practicable and notify any processor holding it, as required by section 27 of the Act.

12Data breach notification

In the event of a personal data breach, we will notify the Data Protection Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by section 25 of the Act. Where the breach is likely to result in a high risk to your rights and freedoms, we will also communicate it to you without undue delay, describing the nature of the breach and the measures taken, in accordance with section 26 of the Act.

Where we act as processor, we will notify the controller organisation without undue delay upon becoming aware of a breach.

13Your rights

Under Part VII of the Act, you have the right to:

  • Access — obtain confirmation of whether we process your personal data, and receive a copy of it, free of charge at reasonable intervals (section 37);
  • Rectification — have inaccurate data corrected and incomplete data completed without undue delay (section 39);
  • Erasure — have your data erased where it is no longer necessary, where you withdraw consent, where you object and no overriding grounds exist, or where it was unlawfully processed (section 39);
  • Restriction of processing — in the circumstances set out in section 39(5) of the Act;
  • Objection — object in writing at any time to processing of your data, including for direct marketing (section 40);
  • Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal (section 24);
  • Not be subject to solely automated decisions producing legal or similarly significant effects (section 38).

To exercise any of these rights, write to us at contact@ileap.app. We will respond within one month of receiving your request; this may be extended by a further month for complex or numerous requests, in which case we will inform you. If we refuse a request, we will give you our reasons in writing and inform you of your right to complain.

If you are a minor, or physically or mentally unfit, your rights may be exercised on your behalf by a person with parental authority, a guardian, or a person you have duly authorised in writing.

Right to complain: if you are not satisfied with how we handle your data or your request, you have the right to lodge a complaint with the Data Protection Office of Mauritius and, if aggrieved by a decision of the Commissioner, to appeal to the ICT Appeal Tribunal within 21 days.

14Cookies and analytics

ileap.app uses a limited number of cookies and similar technologies that are necessary for the website to function, and may use analytics to understand how visitors use the site in aggregate. Where cookies are not strictly necessary, we will ask for your consent before setting them. You can control cookies through your browser settings; disabling necessary cookies may affect how the site works.

15Changes to this policy

We may update this policy from time to time to reflect changes to the platform, our practices or the law. The "Last updated" date at the top of this page shows when it was last revised. Where changes are material, we will notify registered users by email or through the platform before they take effect. We encourage you to review this page periodically.

16Contact us

For any question about this policy or how we handle personal data, or to exercise your rights:

  • Email: contact@ileap.app
  • Post: Data Protection Compliance Officer, Red Peach Ltd, No 98, Royal Road, Morc Ashviva, Trou aux Biches, Mauritius