P-HOLD

MAXIMUS INSTITUTIONAL ECOSYSTEM

Privacy implementation draft

This is a private-review control page, not the final public privacy notice. Publication is blocked until the text is reconciled against the systems, providers, transfers and retention rules actually used in production.

PUBLICATION HOLD · DO NOT INDEX OR RELEASE

KNOWN CONTROLLER DETAILS

Identity can be stated; operations still need verification

ANTICIPATED PROCESSING MAP

Draft only — every row needs operational confirmation

The following is an implementation map for review. It is not a statement that every activity or data category is currently active.

ActivityPossible dataProposed purposePublication gate
Written enquiriesName, work contact details, organisation, role, message and material deliberately supplied by the sender.Assess and respond to the stated enquiry; maintain necessary correspondence and institutional records.Lawful basis, mailbox provider, access roles, transfer locations and retention must be approved.
Site delivery and securityPotentially IP address, request time, device or browser data, URL and security events generated by infrastructure.Deliver, secure, diagnose and protect the website.Actual host, logs, recipients, locations, retention and user-facing disclosure must be verified.
Controlled information requestsIdentity, professional role, purpose of request, diligence details, release decision and disclosed-material record where necessary.Verify the requester, protect rights and make a documented disclosure decision.Minimum fields, identity checks, secure-transfer route, access controls and retention must be approved.
Future programme participationNot activated through this website preview.No application, payment, membership, health-data or child-data collection should be launched through this site without a separate approved workflow.Programme-specific notice, legal basis, necessity assessment, safeguarding, processors, retention and DPIA review where applicable.

UNRESOLVED OPERATING FIELDS

Ten facts and controls required before release

Each item must have a named owner, evidence and approval date. “Not provided” is safer than an invented provider, location or retention period.

  1. 01

    Named privacy lead or Data Protection Officer, the decision on whether a DPO is legally required, and the monitored rights-request channel.

  2. 02

    Complete record of processing activities, data categories, data subjects, purposes and lawful bases for each live workflow.

  3. 03

    Website host, content-delivery, security and log providers; the exact technical data each receives; and the applicable contract terms.

  4. 04

    Email, document-storage, CRM, form, analytics, consent-management and other processors actually used in production.

  5. 05

    Countries in which data is stored or accessed, all international-transfer mechanisms and any supplementary safeguards.

  6. 06

    A system-by-system retention and deletion schedule, including backups, security logs, enquiries, rejected proposals and evidence records.

  7. 07

    Cookie and similar-technology inventory, consent requirements and proof that non-essential tools remain disabled before valid consent.

  8. 08

    Rights-request, complaint, correction, breach-response, access-control and processor-governance procedures tested in operation.

  9. 09

    Whether any programme will involve children, vulnerable people, health-related information, systematic monitoring or other high-risk processing, and the required assessment route.

  10. 10

    Publication approval confirming that the final notice matches production systems on the date it becomes effective.

FINAL NOTICE REQUIREMENTS

What the approved public version must explain

Collection and lawful use

What is collected, directly or automatically; why it is necessary; the applicable lawful basis; whether provision is required; and the consequences of not providing it.

Recipients, locations and time

Actual processors and recipient categories, international transfers and safeguards, security-log use, and clear retention criteria or periods.

Individual rights and escalation

How to request access, correction, erasure, restriction, objection or portability where applicable; how identity is verified; and how to complain to the DIFC Commissioner of Data Protection.

Cookies and technology

A complete, current inventory of essential and non-essential technologies, purpose, provider, duration, consent controls and withdrawal route.

High-risk and vulnerable groups

Programme-specific safeguards for children, vulnerable people, sensitive data, automated evaluation or systematic monitoring, including DPIA findings where required.

Change and evidence control

Effective date, version owner, approval evidence, material-change notification, archived versions and routine comparison with the live production stack.

CURRENT SAFE CONTACT RULE

Use the written channel carefully

Until the final notice and secure workflows are approved, use info@maximus.ltd for a minimal written enquiry only. Do not send identification documents, health information, bank details, children’s information, government identifiers or confidential source files unless an authorised contact provides a suitable route in writing.

No fixed response deadline is promised on this draft page. Requests will need to be handled under the applicable law, verified procedures and the facts of the request.

Controlled information protocol →