Privacy Policy
This Privacy Policy explains how ExpFinder Limited handles the
information and personal data you provide to us and how we process
such information when you use Boat Finder Malta and our services.
This Policy applies to our websites, products and services that link
to this Policy or that do not have a separate privacy policy.
It is intended to help you understand what personal data we collect,
why we collect it, how we process it, who we may share it with and
the rights available to you under applicable data protection law.
Any personal data you provide to us, or which we already hold about
you, will be processed in accordance with this Privacy Policy.
Information may be provided through our website, by email or through
other communication methods we make available from time to time.
By using our website and services, you acknowledge that your personal
data may be processed as described in this Policy. If you do not agree
with this Privacy Policy, please do not provide us with your personal
data.
Who We Are
References in this Privacy Policy to “The Company”, “we”, “us” or
“our” refer to:
ExpFinder Limited
Company registration number: C 112619
8, Misrah il-Knisja
Birzebbuga, BBG 1512
Malta
ExpFinder Limited determines the purposes and means of processing
personal data and therefore acts as the Data Controller for the
processing activities described in this Privacy Policy.
Our processing of personal data is carried out in accordance with
applicable data protection legislation, including the Maltese Data
Protection Act, Chapter 586 of the Laws of Malta, and Regulation
(EU) 2016/679, the General Data Protection Regulation (“GDPR”).
Interpretation and Definitions
Data Controller
The Data Controller is the natural or legal person, public authority,
agency or other body which, alone or jointly with others, determines
the purposes and means of the processing of personal data.
Data Processor
A Data Processor is a natural or legal person, public authority,
agency or other body which processes personal data on behalf of a
Data Controller.
Personal Data
Personal Data means any information relating to an identified or
identifiable natural person.
Personal Data We May Collect
Depending on how you interact with us, we may collect personal data
including:
- Name and surname
- Email address
- Telephone number
We may also receive personal data from publicly available sources,
such as public company registers or other publicly accessible
information, where it is reasonable and lawful for us to do so.
How and Why We Process Personal Data
We only process personal data where we have an appropriate legal
basis under applicable data protection law.
Legitimate Interests
We may process personal data where we have a legitimate business or
commercial reason for doing so, provided that our interests do not
override your fundamental rights and freedoms.
Where appropriate, we will consider the impact of the processing on
your interests and take measures to ensure that the processing is
fair and proportionate.
Consent
In circumstances where we rely on your consent to process personal
data, that consent will be obtained in a clear manner.
You may withdraw your consent at any time. Withdrawal of consent does
not affect the lawfulness of processing carried out before consent
was withdrawn.
Following withdrawal, we may continue processing personal data where
another lawful basis applies or where we are legally required to do so.
Legal and Contractual Obligations
We may also process personal data where processing is necessary to
comply with a legal obligation or to enter into or perform a contract
with you.
Security and Personal Data Protection
We take appropriate technical and organisational measures designed
to protect personal data against accidental loss, unauthorised use,
access, alteration or disclosure.
Access to personal data is limited to employees, agents, contractors
and service providers who have a legitimate need to access such data
and who are subject to appropriate confidentiality obligations.
We maintain procedures for dealing with suspected personal data
breaches and will notify affected individuals and the relevant
supervisory authority where we are legally required to do so.
Data Retention
We retain personal data only for as long as reasonably necessary for
the purposes for which it was collected, including for the purposes
of satisfying applicable legal, regulatory, accounting, tax or
reporting requirements.
The appropriate retention period depends on the nature of the
personal data, the reason it was collected, our relationship with
you and any legal or contractual obligations that apply.
Certain records may be subject to specific statutory retention
periods under Maltese or European Union law.
Where personal data is no longer required, we will securely delete
it or anonymise it where appropriate.
If You Do Not Provide Personal Data
Where we need personal data in order to comply with a legal
obligation, fulfil a contractual obligation or provide a requested
service, failure to provide the required information may mean that
we are unable to provide some products or services to you.
Cookies and Similar Technologies
When you visit our website, certain information may be collected
automatically through cookies and similar technologies.
Cookies may be necessary for the operation of the website or may,
subject to applicable requirements and your choices, be used for
analytics, functionality, advertising or other purposes.
For more information about the cookies we use and how you can manage
your preferences, please read our
Cookie Policy.
Other Purposes
Where permitted by law, we may use and retain personal data where
necessary for fraud or loss prevention and for the protection of our
rights, privacy, safety or property, or those of other persons.
Sharing Personal Data With Third Parties
Personal data may be shared with authorised third parties where such
disclosure is permitted or required under applicable data protection
or other legislation.
Such recipients may include, where appropriate:
- Service providers and technology providers
- Professional advisers, accountants and auditors
- Payment or booking-related service providers where applicable
- Digital marketing and analytics providers
- Regulators and competent public authorities
- Law-enforcement authorities where legally required
- Business partners and authorised subcontractors
-
Other parties where you have asked or authorised us to share your
information
We require processors acting on our behalf to process personal data
only in accordance with our instructions, applicable data protection
laws and appropriate confidentiality and security obligations.
We do not share your personal data with third parties for their own
direct marketing purposes unless you have provided the necessary
consent or another lawful basis applies.
International Transfers
Some of our service providers or business partners may process
personal data outside the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, we take
appropriate steps to ensure that the transfer complies with
applicable data protection law.
Depending on the destination and recipient, safeguards may include
an adequacy decision adopted by the European Commission, approved
Standard Contractual Clauses or another transfer mechanism permitted
under the GDPR.
In relation to transfers to the United States, an adequacy decision
may apply where the recipient organisation participates in the
EU-U.S. Data Privacy Framework. Where this is not applicable, another
valid GDPR transfer mechanism may be used where required.
Internet Communications
Information transmitted over the internet may travel across
international networks and borders even where the sender and
recipient are located in the same country.
Although we take appropriate steps to protect information under our
control, no method of internet transmission can be guaranteed to be
completely secure.
You should therefore take appropriate care when transmitting
personal information through email, messaging services or other
internet-based communication methods.
Accuracy of Personal Data
We take reasonable steps to ensure that personal data we hold is
accurate and, where necessary, kept up to date.
If you believe that any information we hold about you is inaccurate
or incomplete, please contact us so that we can review and, where
appropriate, correct it.
Links to Third-Party Websites
Our website may contain links to websites, booking platforms or
services operated by third parties.
We are not responsible for the privacy practices, content or data
processing activities of third-party websites. We recommend that
you review the privacy information provided by those third parties
before providing them with personal data.
Your Data Protection Rights
Subject to applicable data protection law and any relevant
conditions or exceptions, you may have the following rights in
relation to your personal data.
Right of Access
You may ask us whether we process personal data about you and request
access to that data together with information about how it is
processed.
Right to Rectification
You may ask us to correct personal data that is inaccurate or to
complete information that is incomplete.
Right to Erasure
In certain circumstances you may request deletion of your personal
data, including where the data is no longer necessary for the purpose
for which it was collected or where processing was unlawful.
The right to erasure is not absolute. We may retain information where
processing remains necessary to comply with a legal obligation or
where another lawful exception applies.
Right to Restriction of Processing
You may have the right to ask us to restrict processing in certain
circumstances, including while the accuracy of personal data or the
lawfulness of processing is being considered.
Right to Data Portability
Where the applicable legal requirements are met, you may request
personal data you have provided to us in a structured, commonly used
and machine-readable format and, where technically feasible, request
that it be transmitted to another controller.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that
consent at any time. Withdrawal does not affect the lawfulness of
processing carried out before consent was withdrawn.
Right to Object
You may have the right to object to processing based on our
legitimate interests or the performance of a task in the public
interest, subject to the conditions established by applicable law.
Where personal data is processed for direct marketing purposes, you
may object to such processing at any time.
Right to Lodge a Complaint
If you believe that your data protection rights have been infringed,
you have the right to lodge a complaint with a competent data
protection supervisory authority.
In Malta, the competent supervisory authority is the Office of the
Information and Data Protection Commissioner (IDPC).
We would appreciate the opportunity to address any concern directly
before you approach the supervisory authority, although this does
not affect your right to lodge a complaint.
Privacy enquiries
Contact Us About Your Personal Data
If you have any questions about this Privacy Policy, would like more
information about how we process your personal data, or wish to
exercise any of your data protection rights, please contact: