Collection and lawful use
What is collected, directly or automatically; why it is necessary; the applicable lawful basis; whether provision is required; and the consequences of not providing it.
MAXIMUS INSTITUTIONAL ECOSYSTEM
This is a private-review control page, not the final public privacy notice. Publication is blocked until the text is reconciled against the systems, providers, transfers and retention rules actually used in production.
KNOWN CONTROLLER DETAILS
The legal role of each ecosystem entity must be decided for each processing activity. A commercial operator, licensed provider or programme partner may be a separate controller or processor; the NPIO should not be named for data it does not control.
ANTICIPATED PROCESSING MAP
The following is an implementation map for review. It is not a statement that every activity or data category is currently active.
| Activity | Possible data | Proposed purpose | Publication gate |
|---|---|---|---|
| Written enquiries | Name, work contact details, organisation, role, message and material deliberately supplied by the sender. | Assess and respond to the stated enquiry; maintain necessary correspondence and institutional records. | Lawful basis, mailbox provider, access roles, transfer locations and retention must be approved. |
| Site delivery and security | Potentially IP address, request time, device or browser data, URL and security events generated by infrastructure. | Deliver, secure, diagnose and protect the website. | Actual host, logs, recipients, locations, retention and user-facing disclosure must be verified. |
| Controlled information requests | Identity, professional role, purpose of request, diligence details, release decision and disclosed-material record where necessary. | Verify the requester, protect rights and make a documented disclosure decision. | Minimum fields, identity checks, secure-transfer route, access controls and retention must be approved. |
| Future programme participation | Not activated through this website preview. | No application, payment, membership, health-data or child-data collection should be launched through this site without a separate approved workflow. | Programme-specific notice, legal basis, necessity assessment, safeguarding, processors, retention and DPIA review where applicable. |
UNRESOLVED OPERATING FIELDS
Each item must have a named owner, evidence and approval date. “Not provided” is safer than an invented provider, location or retention period.
Named privacy lead or Data Protection Officer, the decision on whether a DPO is legally required, and the monitored rights-request channel.
Complete record of processing activities, data categories, data subjects, purposes and lawful bases for each live workflow.
Website host, content-delivery, security and log providers; the exact technical data each receives; and the applicable contract terms.
Email, document-storage, CRM, form, analytics, consent-management and other processors actually used in production.
Countries in which data is stored or accessed, all international-transfer mechanisms and any supplementary safeguards.
A system-by-system retention and deletion schedule, including backups, security logs, enquiries, rejected proposals and evidence records.
Cookie and similar-technology inventory, consent requirements and proof that non-essential tools remain disabled before valid consent.
Rights-request, complaint, correction, breach-response, access-control and processor-governance procedures tested in operation.
Whether any programme will involve children, vulnerable people, health-related information, systematic monitoring or other high-risk processing, and the required assessment route.
Publication approval confirming that the final notice matches production systems on the date it becomes effective.
FINAL NOTICE REQUIREMENTS
What is collected, directly or automatically; why it is necessary; the applicable lawful basis; whether provision is required; and the consequences of not providing it.
Actual processors and recipient categories, international transfers and safeguards, security-log use, and clear retention criteria or periods.
How to request access, correction, erasure, restriction, objection or portability where applicable; how identity is verified; and how to complain to the DIFC Commissioner of Data Protection.
A complete, current inventory of essential and non-essential technologies, purpose, provider, duration, consent controls and withdrawal route.
Programme-specific safeguards for children, vulnerable people, sensitive data, automated evaluation or systematic monitoring, including DPIA findings where required.
Effective date, version owner, approval evidence, material-change notification, archived versions and routine comparison with the live production stack.
CURRENT SAFE CONTACT RULE
Until the final notice and secure workflows are approved, use info@maximus.ltd for a minimal written enquiry only. Do not send identification documents, health information, bank details, children’s information, government identifiers or confidential source files unless an authorised contact provides a suitable route in writing.
No fixed response deadline is promised on this draft page. Requests will need to be handled under the applicable law, verified procedures and the facts of the request.
Controlled information protocol →