Your information. Clear choices.
This notice explains our public website and enquiry handling, the information involved, and how to exercise your rights. It includes specific provisions for South Africa, the EEA and UK, Australia, California and Mauritius.
For a privacy request, contact us directly. You do not need to open an account.
Who we are and how to contact us
Maubex Capital operates internationally. For this website and enquiries addressed to it, Maverick Trading 1388 CC, trading as Maubex Capital, is the organisation responsible for deciding how personal information is used (the “controller” or, under POPIA, the “responsible party”).
Maverick Trading 1388 CC, trading as Maubex Capital63 Chelsea Drive, Durban, KwaZulu-Natal, South Africa
jeanluc@maubex.com · +27 83 232 9448
Use these contact details for privacy questions, complaints or requests, and mark your message “Privacy / Information Officer”. You can request an accessible copy of this policy through the same contact.
This policy covers visitors to our public Maubex Capital websites, including maubexcapital.com and maubexcapital.co.za and their www subdomains, prospective clients, business contacts and people whose information is included in their communications. It explains our website and enquiry handling. Client onboarding, identity verification, trading, custody, employment and other services require the relevant additional privacy information at the point of collection. Where another group entity is responsible, its identity and contact details must be identified in that notice or your service documentation.
The jurisdiction sections below supplement this policy when those laws apply to the individual, organisation or processing involved. A global presence does not mean that every law applies to every interaction. Mandatory local protections take priority over any conflicting wording here.
Information we collect
The following describes the categories collected through this website and related enquiries, their sources and purposes, and the recipients involved in ordinary handling.
- Identifiers and contact information
- Your name, email address and optional telephone number, provided by you or a person contacting us on your behalf. Used to identify and answer your enquiry and keep related correspondence. Recipients: staff handling the enquiry and email, communications and IT providers supporting that work.
- Professional or business information
- Your optional company name and any role or business details you include. Used to understand your organisation and route the enquiry. Sources: you, your organisation or your representative. Recipients: relevant staff and the same communications and IT providers.
- Enquiry and correspondence information
- Your selected enquiry type, message and subsequent communications, including information about an intended service or transaction if you choose to include it. Used to respond, assess next steps and maintain an appropriate record. Sources: you and people you authorise. Recipients: relevant staff, communications providers and advisers where needed to address a legal or compliance issue.
- Internet, device and connection information
- When your browser requests a page or video, it sends information such as its IP address, browser details, requested URL and request time to the serving infrastructure. Hosting and content-delivery providers may log this information for delivery, security and troubleshooting. The homepage video is delivered through Amazon CloudFront. Recipients: the relevant hosting, content-delivery and security providers, and authorised technical staff where logs are available to them.
The enquiry form requires a name, email address and message to prepare a useful reply. Company and telephone details are optional. Providing an enquiry is voluntary; without sufficient contact information or a description of your request, we may be unable to respond. There is no statutory requirement to submit this website form.
Please do not include passwords, wallet private keys, seed phrases, payment-card details, identity documents, health information or other sensitive information in an initial enquiry. This website has no identity-document upload or account-verification facility. If verification is necessary later, we will explain the required information, purpose and appropriate submission channel separately.
If you provide another person’s information, do so lawfully, provide only what is needed, and make this policy available to them. We provide any additional notice required when information comes from someone other than the individual concerned.
Purposes and lawful grounds
- Responding and taking requested steps: we use contact, professional and enquiry information to reply and discuss services. Where you are a prospective contracting individual, this can be necessary to take steps at your request before a contract. For general enquiries or representatives of organisations, we rely on the legitimate interest in handling relevant business communications, where local law permits and your interests do not override it.
- Operating and protecting the website: connection information supports page and video delivery, fault diagnosis and security. Our legitimate interests are maintaining a usable site and preventing misuse, subject to the applicable balancing and necessity requirements.
- Legal obligations and disputes: we may retain or disclose relevant records to comply with a binding legal duty or to establish, exercise or defend legal claims. A legal-obligation basis is used only where the obligation qualifies under the law governing the processing; otherwise another valid ground must apply.
- Optional communications: if we ask to use information for a separate purpose that requires consent, we will explain it and request a separate choice. A general enquiry does not subscribe you to a marketing list.
These grounds apply only to the extent recognised by the relevant law. Where consent is required, including for sensitive information or certain marketing, we obtain it before that processing unless a lawful exception applies. We do not treat reading this policy, browsing the website or accepting website terms as consent to unrelated processing.
You may withdraw consent at any time through the contact above, without affecting earlier lawful processing. You may object to direct marketing at any time, free of charge, by contacting us or using an unsubscribe facility in the communication. Withdrawing optional consent does not prevent an ordinary enquiry.
Disclosures and international transfers
We limit disclosure to the purpose concerned. In addition to the recipients described above, information may be disclosed to a group entity where needed to handle a request directed to it; to professional advisers, courts or regulators where legally justified; or to parties involved in a proposed business transfer with appropriate confidentiality and data-protection safeguards. Public access to this website does not authorise unrestricted sharing within the group.
Providers processing information on our instructions must be subject to appropriate confidentiality, security and processing terms. An independent provider or regulator may instead be responsible for its own processing. We do not authorise enquiry recipients to use your details for unrelated advertising.
Our published group locations include South Africa and Mauritius. Enquiries sent to our South African contact are handled in South Africa; a request involving our Mauritius presence may involve that location. Hosting, email and global video-delivery infrastructure can involve other countries. Contact us for the destinations and protections relevant to your enquiry; a service-specific notice must identify additional overseas recipients and destinations where required.
A cross-border transfer needs the protections required by the law governing it. For EEA or UK data, this may require a recognised adequacy decision or appropriate contractual safeguards, such as European Commission Standard Contractual Clauses and the applicable UK transfer instrument, with a transfer assessment and additional safeguards where necessary. POPIA section 72 and Mauritius Data Protection Act section 36 have their own transfer requirements. Australian overseas disclosures are subject to APP 8 where it applies.
These are legal mechanisms that may be required, not a statement that every destination is adequate or that a particular contract is in place for every provider. We must establish the applicable transfer basis before a restricted transfer. You may request information about, and a copy of applicable safeguards, with necessary confidential details removed. Merely contacting us does not waive transfer protections or amount to consent to an otherwise unlawful transfer.
Retention and security
Information should be kept only for as long as needed for its disclosed purpose or a valid legal requirement. Because the nature of an enquiry and any resulting relationship vary, we use the following retention criteria rather than a single period for all visitors:
- Contact and professional details: for handling the enquiry and relevant follow-up, then only while needed for an ongoing relationship, a required record or a specific dispute.
- Messages and correspondence: for resolving the matter, documenting the outcome and satisfying applicable record-keeping or claim requirements. Enquiries that lead to a regulated service become subject to that service’s retention notice.
- Connection and delivery records: for the operational or security window needed to deliver the site, diagnose an issue or investigate abuse, subject to the provider’s applicable logging and deletion arrangements.
- Privacy requests and communication preferences: to administer the request, demonstrate how it was handled and retain the minimum information needed to respect an objection or opt-out.
Legal holds may require relevant records to be preserved until the matter is resolved. When there is no remaining lawful need, records should be deleted or irreversibly anonymised; backup copies are subject to the applicable backup replacement and deletion process. Ask us about the retention period applying to your particular record.
Security measures must be proportionate to the information and risk, including restricted access, appropriate protection in transmission and storage, and oversight of providers. No website or email channel can guarantee absolute security. Report a suspected privacy incident using the contact above; please do not send a private key or password as evidence. Where a breach triggers a legal notification duty, we will notify the relevant authority and affected people within the applicable time limits.
Your privacy rights and requests
Depending on applicable law, you can ask to know whether we hold your information, access or obtain a copy, correct it, delete it, restrict its use, object to processing, withdraw consent or receive a portable copy. Some laws also provide opt-outs from sale, sharing, targeted advertising or certain profiling, and a right to appeal a refusal. These rights are subject to the conditions and exceptions in the relevant law.
Maverick Trading 1388 CC, trading as Maubex Capital63 Chelsea Drive, Durban, KwaZulu-Natal, South Africa
jeanluc@maubex.com · +27 83 232 9448
Email, telephone or write to us with the right you want to exercise, enough detail to locate the record, and a reply address. Mention your country or state if useful for identifying the applicable rules. You do not need an account or a particular legal phrase. The contact page also offers an enquiry form; choose “Privacy or personal information request”.
We may ask for proportionate information to verify your identity or an agent’s authority, using existing contact details where possible. We do not require unnecessary identity documents. An authorised representative may make a request, subject to any legally permitted proof of authority or direct confirmation. An opt-out must not be subjected to identity verification where the law prohibits it.
We will respond within the applicable deadline. If a lawful extension, fee or refusal applies, we will explain the reason and available complaint or appeal route. Requests are ordinarily free; any charge must be specifically permitted by law and explained in advance. Exercising a right will not result in unlawful discrimination or retaliation. Some records may need to be retained for legal obligations or other lawful exceptions even if you request deletion.
If you disagree with our response, reply with “Privacy appeal” and explain why you wish it to be reconsidered. This does not replace or restrict any right to complain to a regulator or seek a judicial remedy. You do not have to complete an internal appeal first where the law permits direct escalation.
South Africa — POPIA
Where the Protection of Personal Information Act 4 of 2013 (POPIA) applies, the responsible party is identified above. POPIA can also protect information about an existing juristic person, such as a company. The collection details, purposes, voluntary and required fields, consequences, recipients and transfer considerations are set out in this policy.
You may request confirmation and access under section 23, correction or deletion under section 24, and object to processing under section 11 where applicable. Direct marketing by electronic communication must meet section 69, including the consent or qualifying existing-customer requirements and a way to object. We do not use the enquiry form to obtain blanket marketing consent.
Requests for records may also involve the Promotion of Access to Information Act (PAIA) and its procedures. Ask the contact above for assistance and the applicable PAIA manual or request process. Prescribed forms are available from the Information Regulator.
You may complain to the Information Regulator of South Africa, including through its eServices portal. The regulator’s published general contact is enquiries@inforegulator.org.za, telephone +27 10 023 5200. Access requests are handled within applicable POPIA and PAIA time limits; other rights are addressed as required by POPIA.
EEA and United Kingdom — GDPR
Where the EU General Data Protection Regulation or UK GDPR applies, our purposes and corresponding legal grounds appear above. You have the applicable rights of access, rectification, erasure, restriction, portability and objection. In particular, you may object to processing based on legitimate interests for reasons relating to your situation, and to direct marketing at any time.
We normally respond without undue delay and within one month. Where legally justified by complexity or number of requests, this can be extended by up to two additional months, with notice and reasons within the initial month. Any lawful identity-verification or clarification rules will be explained where relevant.
This public website does not make decisions about you solely by automated means that produce legal or similarly significant effects. If a later service involves such processing, its notice must explain the logic, significance, consequences and applicable safeguards and rights before it is used.
You may complain to a supervisory authority in the EEA, particularly where you live or work or where an alleged infringement occurred; see the EDPB’s authority directory. In the UK, contact the Information Commissioner’s Office. Applicable representative or Data Protection Officer details must be supplied in the relevant processing notice where such an appointment is required.
Australia — Privacy Act and APPs
Where the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs) apply, you may request access to and correction of your personal information. We respond within a reasonable period, ordinarily within 30 days. If access or correction is refused, we provide reasons and complaint options unless the law allows otherwise. You may also request association of a statement of disagreement with a record where required.
We collect sensitive information only with consent where required or under a lawful exception. Where lawful and practicable, you may make a general enquiry anonymously or using a pseudonym, including by contacting us directly; verification may be necessary for a specific account or regulated service.
Our overseas handling is described in the international-transfers section, including South Africa and potential handling in Mauritius. APP 8 may require reasonable steps to ensure an overseas recipient handles information consistently with the APPs, and we may remain accountable. This policy does not seek consent to waive that protection.
Raise a privacy complaint with us using the contact above. We will investigate and communicate an outcome, ordinarily within 30 days. If unresolved, you may complain to the Office of the Australian Information Commissioner; its guidance ordinarily asks you to complain to the organisation first and allow a response.
California — CCPA / CPRA
Where Maubex is a covered business and the information is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA / CPRA), California residents have rights to know and access, correct and delete personal information, subject to statutory exceptions. You may also opt out of sale or sharing for cross-context behavioural advertising and limit certain uses or disclosures of sensitive personal information where those activities occur.
The collection section identifies this website’s identifiers, professional or business information, enquiry or commercial information and internet activity, including sources, purposes and recipient categories. The retention section explains the criteria for each category. The website does not request sensitive personal information, infer sensitive characteristics, operate targeted advertising or offer a financial incentive for providing personal information. Its current features do not sell personal information or share it for cross-context behavioural advertising, including information about people under 16.
Use the email, postal contact or enquiry form in Your privacy rights for a request, including through an authorised agent. Know, correction and deletion requests may require verification. Where the CCPA applies, we acknowledge these requests within 10 business days and normally respond within 45 calendar days of receipt; a permitted extension of up to a further 45 days will be explained within the initial period. Sale/sharing opt-outs and applicable sensitive-information limits are handled as soon as feasible and within 15 business days, without a verifiable consumer request requirement.
See the browser-signals section for GPC and Do Not Track. The absence of a current sale or sharing feature does not waive your rights. If practices change, the required notices and controls must be provided before that processing begins. We do not discriminate against you for exercising CCPA rights.
Some financial information may be subject to statutory exemptions; an exemption must be assessed for the information and activity involved and is not a blanket exemption for all website visitors. For guidance and complaints, visit the California Privacy Protection Agency or the California Attorney General’s CCPA page.
Mauritius — Data Protection Act
Where the Mauritius Data Protection Act 2017 applies, you may exercise rights of access, rectification, erasure or restriction, and objection, subject to the Act’s conditions. Protections also apply to automated individual decisions and to the lawful processing of special categories of personal data. You can withdraw consent where processing relies on it.
For access requests under section 37, we inform you of the action taken within one month. Where necessary because of complexity or the number of requests, a further month is permitted under the Act. We explain any applicable extension or refusal and the available complaint route.
Transfers outside Mauritius must satisfy section 36 and any applicable authorisation or consultation requirements. A group relationship alone is not a transfer safeguard. You may complain to the Mauritius Data Protection Office, whose published contact is dpo@govmu.org or +230 460 0251.
Other jurisdictions and children
Visitors elsewhere can use the same contact and request process. Where another applicable law provides additional notice, consent, access, correction, deletion, portability, appeal, localisation or transfer protections, those requirements continue to apply. This includes relevant US state privacy laws and applicable protections in other countries; this policy does not claim that one jurisdiction’s law replaces them.
If a local privacy law gives you an appeal right, send a “Privacy appeal” to the contact above. We will explain the result and applicable regulator route within that law’s deadline. You may also contact your local privacy or consumer-protection authority.
Our website and services are directed to adults and business representatives, not children. We do not knowingly solicit children’s personal information through this website. If you believe a child has supplied information, contact us so we can investigate and remove it or handle it as the applicable law requires. Regulated service eligibility is governed by the relevant service terms.
Changes to this policy
We update this policy when relevant practices or requirements change and show the revision date at the top. Material changes will be brought to your attention in an appropriate way, and further notice or consent will be provided before a new use where required. A policy update cannot retrospectively authorise processing that requires a separate legal basis or consent.
For the rules governing this public website, read our Terms & Conditions.