How we handle requests for your data.
Our policy for law-enforcement requests, by Maximinds Ltd, the data controller. Effective 11 September 2026.
1. Our stance
Attesta (Maximinds Ltd) is built to protect the people who use it. We disclose personal data to law enforcement only where we are lawfully required or permitted to, and only the minimum necessary. We do not give any authority open or bulk access to our systems. Every request is reviewed by our Data Protection Officer.
2. What we may hold
Because verification documents (ID, payslips, bank statements, ownership papers) are deleted automatically after review, they are usually no longer available. What we may still hold and that is relevant to an investigation is limited to: a user's selfie / facial image (retained on a lawful basis to help prevent and investigate fraud, then erased after a bounded period), fraud-case records, account and consent records, and audit logs. See our Privacy Notice.
3. Valid requests
We act on requests from Jamaican law-enforcement authorities that carry lawful authority — for example a court order, warrant, production order, or a specific statutory power — and that identify the account and the data sought. We verify the requester and the legal basis before doing anything. We will decline or seek clarification on requests that are overly broad, vague, or that lack a proper legal basis.
4. How we respond
Our DPO assesses each valid request for necessity and proportionality and discloses only the specific data lawfully required, never more. Where the law allows us to narrow, delay, or challenge a request, we will. We may seek independent legal advice before responding.
5. Logging and notice to you
We keep a record of every request we receive and every disclosure we make. Where we are legally permitted to do so, we will notify the affected user — unless a court order, statute, or a genuine risk to an investigation, to safety, or to life prevents it, in which case we notify as soon as that restriction lifts.
6. Emergencies
In a genuine emergency involving an imminent risk of serious harm to a person, we may disclose the limited information needed to help prevent that harm, and we log and review every such disclosure afterwards.
7. How to make a request
Authorities should send requests to our Data Protection Officer, Micah Brown, at dpo@attestajm.com, on official letterhead, identifying the requesting agency and officer, the legal basis, the specific account(s) and data sought, and the time period. We aim to acknowledge lawful requests promptly.
Data Protection Officer: Micah Brown · dpo@attestajm.com · See also the Privacy Notice and sub-processor list.