- Mellieha Bay Hotel Limited is a data controller under the terms of the General Data Protection Regulation (GDPR).
[Our Data Protection Officer is: The General Manager]
What information do we collect?
- When you register to use our services we may ask you to provide certain personal information (including your full name, email address, contact number and payment details).
What do we use your information for?
We may use your information for the following purposes:
- in the normal course of our business, to allow us to register you to use our services and to provide you with our services on the basis that processing is necessary in order to perform our contract with you to provide our services;
- to allow us to manage your reservation on the basis that processing is necessary in order to perform our contract with you to provide our services;
- to allow us to analyse your personal preferences and personalise our services to you;
- to store your data to pre-populate fields to make it easier for you to provide information when you return to our sites;
- to communicate with you [including sending you information about products and services which we think may be of interest to you. You will be able to opt-out of such communications at any time by [insert opt out mechanism];
- to validate your information (and, in some cases, match it against information that has been collected by a third party) to check that the data we hold about our customers/users is accurate, consistent and up to date on the basis that processing is necessary in order to perform our contract with you to provide our services;
- in pursuit of our legitimate interests, to record CCTV footage to ensure the safety and security of our premises, staff and customers;
- to comply with any legal obligations to which we are subject; and
- We shall periodically check that the personal data we store for you is accurate. If you would like to update the personal data we hold about you, please contact us on email@example.com with your request.
- The provision of certain personal information is mandatory if you are to use our services. If you fail to provide such data we shall be unable to provide our services.
Who do we share your information with?
As part of using our services, you consent to us sharing your personal information with the following parties:
- our agents, other service providers and third party partners, who process and store data on our behalf;
- professional advisors;
- law enforcement agencies;
- [if you select via the [opt-in process], trusted third parties whose products, services and other offers we believe may be of interest to you.
We may also share your personal information with third parties:
- in the event that we, our business, or substantially all of its assets are acquired by a third party (in which case personal information about customers will be one of the transferred assets);
- if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply any contract with you; or to protect our rights, property, or safety of our employees, customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
How long do we store your personal data for?
- We only store your personal information for as long as necessary for the purposes listed in paragraph
What are your rights?
- Access to your personal data: You may request access to a copy of your personal data.
- Right to withdraw: Where you have given your consent for us to use your personal data, you may withdraw your consent at any time. Please contact us using the details located at section 13 of this policy if you would like to withdraw your consent and we will delete your data in line with your right to erasure at 7.4 below.
- Rectification: You may ask us to rectify inaccurate information held about you. If you would like to update the data we hold about you, please contact us using the details below and provide the updated information.
- Erasure: You may ask us to delete your personal data. If you would like us to delete the personal data we hold about you, please contact us using the details below, specifying why you would like us to delete your personal data.
- Portability: You may ask us to provide you with the personal information that we hold about you in a structured, commonly used, machine readable form, or ask for us to send such personal data to another data controller.
- Make a complaint: You may make a complaint about our data processing activities to Office of the Information and Data Protection Commissioner in Malta.
Security and Data Storage
We will treat all of your information in strict confidence and we will endeavour to take all reasonable steps to keep your personal information secure once it has been transferred to our systems. We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction of your personal information, and data stored on the website and associated database.
Please note that the internet is not a secure medium and we cannot guarantee the security of any data you disclose online. You accept the inherent security risks of providing information and dealing online over the Internet and will not hold us liable for any data breach.
A copy of this document can be obtained from our reception.
Sol Beach at Ghadira Bay
9:00am – 7:00pm
Reduced Hours 9:00am – 1:00pm