MAÎTRE
Privacy Policy
Effective date: 29 July 2026
MAÎTRE | PRIVACY POLICY
1. Scope and purpose
This Privacy Policy explains how K.I.A.B Investment Management Consulting Ltd (“KIAB”, “we”, “us” or “our”), operating under the MAÎTRE trading name, collects and uses personal data in connection with maitre.world, enquiries, communications and services.
It applies to website visitors, prospective clients, clients, authorised representatives, household or family contacts, suppliers, professional advisers and other individuals whose personal data we process.
This Policy should be read together with any service-specific privacy information provided at the point of collection.
2. Data controller and contact details
The data controller is K.I.A.B Investment Management Consulting Ltd, incorporated in the Republic of Cyprus.
Contact email for privacy matters: info@maitre.world
We have not appointed a Data Protection Officer unless and until the law requires us to do so. Privacy enquiries are handled through the email address above.
3. Our confidentiality principle
Confidentiality comes first. We do not publicly disclose client identities, personal information or the details of client requests.
Where information is required to assess or perform a request, it is disclosed only to authorised persons who need it for that purpose and only to the extent reasonably necessary.
This confidentiality principle does not prevent disclosures required by law, court order, regulatory obligation, fraud prevention, sanctions compliance, protection of vital interests, or the establishment, exercise or defence of legal claims.
4. Personal data we may collect
4.1 Information you provide directly
- identity and contact details, such as name, title, email address, telephone number, messaging username, country and preferred language;
- enquiry and request information, including objectives, dates, locations, preferences, budget parameters and relevant background;
- communications, correspondence, call notes, instructions, feedback and complaint information;
- billing and transaction information, such as billing address, invoice details, payment status and limited payment references;
- identity, authority and compliance information where reasonably required, including identification documents, proof of authority, beneficial ownership information, sanctions-screening results or source-of-funds information;
- travel and logistics information, such as passport details, nationality, date of birth, itinerary, loyalty programme details, accessibility needs and emergency contacts;
- property, household, family or guest information relevant to an accepted request;
- professional or business information, such as company, role, business contact details and authorised representative status; and
- any other information you choose to provide.
4.2 Information collected automatically
- IP address and approximate location derived from it;
- browser, device, operating system and language information;
- website pages viewed, date and time, referral source and interaction data;
- security, diagnostic and server-log information; and
- cookie identifiers and consent preferences, as described in our Cookie Policy.
4.3 Information received from other sources
- a client, family member, assistant, employer, family office or authorised representative;
- Third-Party Providers involved in a request;
- professional advisers, public registers and lawful compliance databases;
- payment providers and financial institutions, limited to information relevant to payment or fraud prevention; and
- publicly available sources where necessary and proportionate for a request or compliance check.
5. Special-category and highly sensitive data
Some concierge requests may incidentally require data concerning health, dietary or accessibility requirements, religious observance, biometric identifiers, criminal allegations, or other information treated as sensitive under applicable law.
We request and use such data only where necessary, proportionate and supported by an appropriate legal condition, which may include explicit consent, vital interests, legal claims or another condition permitted by law.
Please do not provide sensitive data unless it is genuinely necessary. We may ask you to use a more secure transmission method for passports, identification documents, medical information or financial records.
6. Why we use personal data and our legal bases
| Purpose | Examples | Legal basis |
|---|---|---|
| Responding to enquiries | Reviewing a request, communicating, assessing scope and availability | Steps requested before a contract; legitimate interests |
| Providing accepted services | Research, coordination, bookings, introductions, administration and client support | Performance of a contract; legitimate interests |
| Managing payments and records | Quotations, invoices, expense records, reconciliation and debt recovery | Contract; legal obligations; legitimate interests |
| Compliance and risk management | Identity, authority, fraud, sanctions, source-of-funds and legal checks | Legal obligations; legitimate interests |
| Confidential operations | Access control, record management, supplier coordination and internal quality control | Legitimate interests; contract |
| Website operation and security | Hosting, logs, diagnostics, cybersecurity and consent records | Legitimate interests; legal obligations; consent where required |
| Marketing | Sending updates or invitations where permitted | Consent, or legitimate interests where law permits |
| Legal protection | Complaints, disputes, insurance, investigations and legal claims | Legal obligations; legitimate interests; legal claims |
Where we rely on legitimate interests, those interests may include operating and protecting our business, responding to enquiries, delivering a discreet service, preventing fraud, maintaining records, improving operations and establishing or defending legal rights. We consider the impact on individuals and do not rely on legitimate interests where those interests are overridden by fundamental rights and freedoms.
Where processing is based on consent, consent may be withdrawn at any time without affecting processing that occurred before withdrawal.
7. When we share personal data
We do not sell or rent personal data.
We may share only the information reasonably required with:
- our personnel and contractors who are authorised and subject to confidentiality obligations;
- hotels, airlines, transport providers, venues, retailers, property professionals, couriers and other Third-Party Providers needed to assess or perform a request;
- lawyers, accountants, auditors, insurers, consultants and other professional advisers;
- website hosting, email, communications, cloud storage, customer-management, cybersecurity, analytics and payment-service providers;
- banks, payment processors and fraud-prevention providers;
- government, regulatory, law-enforcement, court or tax authorities where required or permitted by law;
- a purchaser, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality; and
- other recipients authorised by the relevant individual.
Third-Party Providers may act as independent controllers and provide their own privacy notices. Their processing is not always controlled by us.
8. International transfers
The nature of international concierge work may require personal data to be sent to recipients outside Cyprus and outside the European Economic Area (“EEA”), including in countries that may not provide an equivalent level of data protection.
Where GDPR transfer restrictions apply, we use an available lawful mechanism, such as an adequacy decision, standard contractual clauses, a permitted derogation for a contract or request made in the individual’s interest, explicit consent where appropriate, or another mechanism recognised by law.
International travel or cross-border requests may make certain transfers objectively necessary. We limit the data shared to what is reasonably required for the relevant arrangement.
9. Data security
We use reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures may include access restrictions, confidentiality commitments, authentication, secure hosting, encryption where appropriate, backups, vendor assessment and incident-response procedures.
No transmission or storage system is completely secure. You are responsible for using appropriate care when sending sensitive information and for keeping your own accounts, devices and communications secure.
10. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including legal, accounting, tax, compliance, insurance and dispute requirements.
| Category | Indicative retention approach |
|---|---|
| Unsuccessful or unaccepted enquiries | Normally up to 24 months after the last meaningful contact, unless a longer period is needed for legal, security or compliance reasons. |
| Client and service records | For the relationship and normally up to 6 years after completion or termination, subject to applicable legal requirements and limitation periods. |
| Invoices and accounting records | For the period required by applicable tax and accounting law. |
| Compliance and verification records | For the period required or justified by applicable anti-fraud, sanctions, legal and risk obligations. |
| Website security logs | Normally retained for a limited period appropriate to security and diagnostics. |
| Marketing preferences | Until consent is withdrawn, an objection is made, or the data is no longer required; suppression records may be retained to respect opt-out choices. |
Retention periods may be extended where records are relevant to a complaint, investigation, litigation, legal hold or outstanding obligation. Data may be anonymised and retained in a form that no longer identifies an individual.
11. Your data-protection rights
Subject to legal conditions and exceptions, you may have the right to:
- request access to your personal data and information about its use;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time where consent is the legal basis; and
- complain to a competent data-protection authority.
To exercise a right, email info@maitre.world. We may request information necessary to verify identity and authority. We normally respond within the period required by law.
Rights are not absolute. We may retain or continue processing information where permitted or required by law, including for legal claims, compliance, security and the rights of others.
12. Complaints
We encourage you to contact us first so that we can address any concern.
You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus or, where applicable, another competent supervisory authority in the EEA.
13. Marketing communications
We may send marketing communications only where permitted by law. You may unsubscribe at any time by using the unsubscribe method in the communication or contacting us.
Service communications relating to an enquiry, arrangement, security issue, payment or legal matter are not marketing and may still be sent where necessary.
14. Children
The Website is not directed to children and individuals under 18 should not submit enquiries directly.
A client may provide information about a child where necessary for a family request and where the client is authorised to do so. We process such data only for the relevant purpose and with heightened care.
15. Automated decision-making
We do not currently make decisions producing legal or similarly significant effects based solely on automated processing. If this changes, we will provide the information required by law.
16. Third-party links and platforms
The Website may contain links to third-party websites and communication platforms, including WhatsApp and Telegram. Following such a link may allow the relevant platform to process information under its own privacy terms. A simple external link does not by itself mean that MAÎTRE receives access to the user’s account or private communications on that platform.
Information submitted through the enquiry form is delivered to and handled by KIAB for the purpose of reviewing and responding to the request. The exact technical delivery method may change, but any service provider used for hosting, email delivery, form processing or storage is selected and managed as part of our business operations and is subject to appropriate data-protection arrangements where required.
17. Enquiry form
18. Cookies
Information about cookies and similar technologies, including Google Analytics, is set out in the MAÎTRE Cookie Policy. Non-essential analytics, advertising, map or other optional technologies are activated only after consent where consent is required.
19. Changes to this Policy
We may update this Policy to reflect legal, technical or operational changes. The current version will be published on the Website with its effective date. Material changes may also be communicated by another appropriate method.
20. Contact
Privacy enquiries and rights requests: info@maitre.world