- The Maltese Data Protection Act (hereafter referred to as the “DPA” – Chapter 586 of the Laws of Malta) as well as any other subsidiary legislation issued under the DPA as may be amended from time to time; and
- Regulation (EU) 2016/679 of The European Parliament And of The Council of 27 April 2016 On The Protection of Natural Persons With Regard to The Processing of Personal Data And On The Free Movement of Such Data, And Repealing Directive 95/46/EC (General Data Protection Regulation)” (hereinafter referred to as “the Regulation” or “GDPR”).
The DPA and the GDPR shall hereafter be collectively referred to as the “Data Protection Laws”.
Casacollection determines the means and purposes of the processing of Personal Data and therefore acts as the “Data Controller” in terms of the applicable Data Protection Laws.
The Data Controller
“The Data Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law. The Data Processor
“The Data Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. Personal Data
“Personal Data” means any information that identifies You individually or relates to an identified or identifiable natural person.
Casacollection stores Your Personal Data digitally on encrypted hard drives.
Personal Data Protection
Personal Data held by Us is protected using the highest industry standard security processes and systems. Our commitment to protect personal data is not merely through quality and high standards but also through the best and most efficient application of the law. We are bound to only process personal data if such processing is based on a genuine and legitimate reason to do so on the basis of one of the legal grounds established in the GDPR.
Processing on the Basis of our Legitimate Interests
A legitimate interest exists when We have a business or commercial reason upon which personal data will be processed. In such a case We undertake to protect any and all of Your personal data and the manner in which such data is processed and to ensure that such processing would not be unfair to You or Your interest. If and when We decide to process Your personal data on the basis of legitimate interest, We will inform You of such, what said legitimate interest are and provide a process whereby You will be able to raise any questions and/or objections which You way have in relation to such processing. It is important to note that Casacollection is not obliged to stop processing if the grounds for processing over-ride Your right to object.
Processing on the Basis of Your Consent
Consent is not the only ground we may be permitted or obliged to rely on to process Your personal data. We will only process personal data on the basis of Your consent where we cannot or otherwise choose not to rely on any ulterior legal ground (such as compliance with a legal obligation or legitimate interest). Where we process Your personal data on the basis of Your consent, you shall have the right to withdraw your consent at any time and in the same manner as it had been previously provided by Yourself. In the case that You exercise Your right to withdraw consent, we would then determine whether we are able (or obliged) to process Your personal data on the basis of any other legal ground other than consent. If this is the case We will notify You accordingly. Any such withdrawal of Your consent will not invalidate any processing operations carried out prior to You having withdrawn Your consent.
Processing on the Basis of Consent
For the avoidance of all doubt, We would like to point out that in those limited cases where We cannot or choose not to rely on another legal ground (for example, Our legitimate interests), We will process Your Personal Data on the basis of Your consent.
In those cases where We process on the basis of Your consent (which We will never presume but which We shall have obtained in a clear and manifest manner from You), you have the right to withdraw your consent at any time and this, in the same manner as You shall have provided it to Us.
Should You exercise Your right to withdraw Your consent at any time (by writing to Us at the physical or email address below), We will determine whether at that stage an alternative legal basis exists for processing Your Personal Data (for example, on the basis of a legal obligation to which We are subject) where We would be legally authorised (or even obliged) to process Your Personal Data without needing Your consent and if so, notify You accordingly.
When We ask for such Personal Data, You may always decline, however should You decline to provide Us with necessary data that We require to provide requested services, We may not necessarily be able to provide You with such services (especially if consent is the only legal ground that is available to Us).
Just to clarify, consent is not the only ground that permits Us to process Your Personal Data. In the last preceding section above We pointed out the various grounds that We rely on when processing Your Personal Data for specific purposes.
We may be required to use and retain personal information for; loss prevention; and to protect Our rights, privacy, safety, or property, or those of other persons in accordance with Our legitimate interests.
We retain data for limited periods when it needs to be kept for legitimate business or legal purposes. We try to ensure that our services protect information from accidental or malicious deletion. Because of this, there may be delays between when you delete something and when copies are deleted from our active and backup systems. Should you need further information please contact us on firstname.lastname@example.org.
Authorised Disclosures of Personal Data to Third Parties
Sharing of Personal Data with Other Categories of Recipients
You will be aware that data sent via the Internet may be transmitted across international borders even where sender and receiver of information are located in the same country. We cannot be held responsible for anything done or omitted to be done by You or any third party in connection with any Personal Data prior to Our receiving it including but not limited to any transfers of Personal Data from You to Us via a country having a lower level of data protection than that in place in the European Union, and this, by any technological means whatsoever (for example, WhatsApp, Skype, Dropbox etc.). Moreover, We shall accept no responsibility or liability whatsoever for the security of Your data while in transit through the internet unless Our responsibility results explicitly from a law having effect in Malta.
Accuracy of Personal Data
All reasonable efforts are made to keep any Personal Data We may hold about You up-to-date and as accurate as possible. You can check the information that We hold about You at any time by contacting Us in the manner explained below. If You find any inaccuracies, We will correct them and where required, delete them as necessary. Please see below for a detailed list of Your legal rights in terms of any applicable data protection law.
Links to Third Party Sites
Links that We provide to third-party websites are clearly marked and We are not in any way whatsoever responsible for (nor can We be deemed to endorse in any way) the content of such websites (including any applicable privacy policies or data processing operations of any kind). We suggest that You should read the privacy policies of any such third-party websites.
Transfer of Data Outside of the EEA
Your personal data will only be transferred outside of the EEA or any other non-EEA country which has been deemed by the European Commission to offer an adequate level of protection (in the following circumstances: When You have expressly consented Us to do so; when it is necessary to constitute or execute a contract entered between You and Casacollection; or to be compliant and in line with any and all legal obligations or duties. In the event that personal data is transferred outside of the EEA, within Casacollection or to any of Casacollection’s business partners, We ensure to implement all appropriate safeguards to ensure that the same protection is afforded and the same standards are applied as would be within the EEA. You are entitled to receive a copy of such safeguards by contacting Us at the address below.
Contracts containing the EU Standard Contractual clauses (EU Model Clauses) will be used which require the entity receiving the personal data to use the same standards as they would be subject to within the EEA. Should any data be transferred to the USA and the entity receiving the data is registered with Privacy Shield (a framework that ensures personal data protection) it will be taken that the same level of protection as approved by the European Commission.
Data Subject Rights
Casacollection undertakes to assist You in the best way possible should You choose to exercise any of Your rights with respect to Your personal data. In certain cases We might need to verify Your identity prior to acceding to Your request to exercise any relevant right.
Right of Access
You have a right to ask Us whether We are processing any personal data which concerns You and if this is the case, You shall have the right to access that personal data as well as the following information:
- What Personal Data We have,
- Why We process them,
- Who We disclose them to,
- How long We intend on keeping them for (where possible),
- Whether We transfer them abroad and the safeguards We take to protect them,
- What Your rights are,
- How You can make a complaint,
- Where We got Your Personal Data from and – Whether We have carried out any automated decision-making (including profiling) as well as related information.
Right to Rectification
You have a right to ask us to have any inaccurate or incomplete personal data relating to You rectified and/or completed.
Right of Erasure (the “right to be forgotten”)
You have the right to ask Us to delete Your Personal Data and We shall comply without undue delay but only where:
- The Personal Data are no longer necessary for the purposes for which they were collected; or
- You have withdrawn Your consent (in those instances where We process on the basis of Your consent) and We have no other legal ground to process Your Personal Data; or
- You shall have successfully exercised Your right to object (as explained below); or
- Your Personal Data shall have been processed unlawfully; or
- There exists a legal obligation to which We are subject; or
- Special circumstances exist in connection with certain children’s rights.
In any case, We shall not be legally bound to comply with Your erasure request if the processing of Your Personal Data is necessary to comply with a legal obligation imposed on Us.
Right to Restriction of Processing
You have the right to ask Us to restrict the processing of Your personal data. However, You are only able to exercise this right where:
- The accuracy of Your Personal Data is contested (see the right to data rectification above), for a period enabling Us to verify the accuracy of the Personal Data; or
- The processing is unlawful and You oppose the erasure of Your Personal Data; or
- We no longer need the Personal Data for the purposes for which they were collected but You need the Personal Data for the establishment, exercise or defence of legal claims; or
- You exercised Your right to object and verification of Our legitimate grounds to override Your objection is pending.
Should You successfully exercise this right, We would only be in a position to process Your personal data:
- Where We have Your consent; or
- For the establishment, exercise or defence of legal claims; or
- For the protection of the rights of another natural or legal person; or
- For reasons of important public interest.
Right to Data Portability
You have the right to ask Us to provide You with Your personal data which You would have previously provided to Us. We will provide You such data in a structured, commonly used, machine readable format, or (where technically feasible) We may have the data sent directly to another Data Controller, provided this does not adversely affect the rights and freedoms of others. You may only exercise this right where:
- The processing is based on Your consent or on the performance of a contract with You; and
- The processing is carried out by automated means.
Right to Withdraw Consent
For detailed information on this right, refer to “Processing on the Basis of Consent” section, above.
Right to Object to Processing
In certain instances, You have the right to object to the processing of Your personal data. Where we are only processing Your personal data on the basis of one of the following purposes:
- The processing is necessary for the performance of a task carried out in the public interest; or
- When processing is necessary for the purposes of the legitimate interests pursued by Us or by a third party.
The processing shall only cease where the Data Controller has not provided compelling and legitimate grounds which outweigh the objections raised by You in such a request and which require the processing to continue.
Where Your data is being processed for direct marketing purposes, You have the right to object to the processing of Your personal data at any time.
In all other instances apart from those listed above, this general right to object shall not subsist.
Right to Lodge a Complaint
As a Data subject You may at any time lodge a complaint with any relevant Data Protection Supervisory Authority should You feel that any of Your rights have been impinged by Casacollection. The Competent Supervisory Authority in Malta is the Office of the Information and Data Protection Commissioner (‘IDPC’).
Notwithstanding this right, We kindly ask You to please attempt to resolve any issues You may have with Us prior lodging a complaint with the IDPC.
It is important to note that notwithstanding such rights, Casacollection may still refuse such request if it can reasonably justify such decision. Such refusal does not prohibit You from lodging a complaint with the relevant data protection authority.
If You have any questions/ comments about privacy or should You wish to exercise any of Your individual rights, please contact our DPO at: email@example.com or by writing to the address above.