Privacy Policy

version 1 - effective date 15/11/2023

 

At Iftaħ Qalbek, we take data privacy seriously. Please read this privacy notice to ensure that you are fully informed. If you have any questions or concerns, please contact us using the contact details.

1.     Definitions

 

In this privacy notice, these terms have the following meanings:

 

Data Subject” means any person to whom Personal Data relates. Persons utilising our services or contacting us from Our website are generally Data Subjects. Persons browsing the Website without contacting us are unlikely to be Data Subjects.

 

Personal Data” means any information that identifies or can be used to identify a Data Subject, directly or indirectly. Examples of Personal Data include, but are not limited to, first and last name, date of birth, and e-mail address. Personal Data does not include data where the identity has been removed (“Anonymous Data”)

 

Services” means our therapeutic services and/or communication through our website.

 

You” and “Your” means, depending on the context, you as a Data Subject.

 

Us and “Our” means Iftaħ Qalbek.

 

 

2.     The Purpose of this Privacy Notice

 

This privacy notice explains who we are, what Personal Data we collect and how we collect it, share and use Personal Data, as well as how you can exercise your privacy rights. It also explains how Iftaħ Qalbek collects and processes your Personal Data when using our services or utilising our website.

 

 

3.     Personal Data We Collect

 

The Personal Data that we may collect broadly falls into the following categories:

 

(i)             Data you provide to us: In the course of engaging with our Services, you may provide Personal Data about you. Personal Data is often, but not exclusively, provided to us when you use Our Services or provide to us in the course of contacting us through the Website or in any way. By giving this Personal Data, you agree to this Personal Data being collected, used and processed and stored in accordance with our terms of services and/or this privacy policy. This information may include, but not limited to:

 

a.     Identification and communication data: During the receipt of our Services and communication with Us, through the website or otherwise, you will be asked to provide certain basic information such as your first name, last name, e-mail address, along with other information required to communicate with you and supply our Services appropriately.

b.     Historical and family data: During the provision of our Services, we may collect historical data about you such as education history, employment history, civil status and changes to such, family composition, relationship history, and similar.

c.     Special Categories of data: our Services generally requires knowledge of other information which may be considered as a special category. This in order to be in a position to provide our Services in the best manner taking into account the full context of Your circumstances. Special Categories of data may include, health situation and history, race and ethnicity, sexual preferences, criminal history, political opinions, religious or philosophical beliefs, and similar.

 

 

(ii)           Data we collect automatically: When you use our Website, we may collect certain data about your device and usage of the Website. We use cookies and other tracking technologies to collect some of this data. Our use of cookies and tracking technologies is discussed more below.

 

(iii)         Third party or publicly available sources: From time to time, we may obtain data from third-party sources, such as public databases, social media platforms, and third-party data providers. Examples of the information we receive from other sources include device information such as IP addresses, location, and online behavioural data.

 

 

4.     Use of Personal Data and Legal Basis for Collection and Processing

 

We may use the Personal Data we collect through the Website and the Services or other sources for a range of reasons, as per the below table:

 

 

Data Category

 

 

Purpose

 

Legal Basis

Data we collect automatically and data collected from third-party or publicly available sources

 

To provide, support and improve the Website and the Services

Legitimate Interest

Data You provide to US, namely Communication Data, including first name, last name, e-mail address, message, comments and other Personal Data submitted by you in communicating with Iftaħ Qalbek, whether through the Website or other means, including but not limited to e-mail.

 

For you to communicate with us and for us to communicate with you.

Consent given by you; and to fulfil contractual obligations as the case may be.

Historical Data and Special Categories of Data, as defined above.

As a therapeutic service, in order to provide You with the best tailor-made Service, we would need to understand, and you might disclose, such types of data.

 

To provide our Services as requested by yourself (ie. to fulfil our contractual obligations)

 

Please note that in addition to the above, we may use the Personal Data we collect through the Services or other sources (whether you provide such Personal Data to us or whether it is automatically collected or acquired from third-parties) for a range of reasons, including:

 

a.     To meet legal requirements;

b.     To provide information to representatives and advisors, including attorneys and accountants;

c.     To use in legal proceedings;

d.     To fulfil ethical and legal obligations, including where information disclosed is likely to indicate a threat or risk to You or others, or in cases of knowledge or strong suspicions of child maltreatement.

e.     To respond to lawful requests by public authorities;

f.      For data analytics purposes;

g.     For other purposes to carry out legitimate business purposes

 

When we rely on a legal basis of legitimate interests, we have carried out a Legitimate Interests Assessments to ensure that we have weighed your interests and any risks posed to you and to ensure that our processing is proportional and appropriate. Typically, our legitimate interests include improving, maintaining, providing, and enhancing our technology, products, and services; ensuring the security of the Website and the Services

 

In some cases, we may also have a legal obligation to collect Personal Data from you, in which case that would apply as the legal basis for collecting and processing such Personal Data.

 

Change of Purpose

 

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

 

 

5.     Cookies and Tracking Technologies

 

We and our partners may use technologies to collect and store information when you use our Website, and this may include using cookies and similar tracking technologies to collect Personal Data such as:

 

a.   Device information: Our Website service provider may collect information about the device and applications you use to access the Website and the Services, such as your IP address, your operating system, your browser ID, and other information about your system and connection

 

b.   Product usage data: We collect usage data about you whenever you interact with our Website which may include the dates and times you access the Website and your browsing activities (such as what portions of the Services are used). We also collect data regarding the performance of the Website. This information allows us to improve the content and operation of the Website, and facilitate research and analysis of the Website.

 

6.     Other Data Protection Rights

 

You have the following data protection rights:

 

1.     To access, correct, update or request deletion of Personal Data.

2.     To object to the processing of your Personal Data.

3.     To request restriction of processing of your Personal Data.

4.     To request Personal Data portability.

5.     If Personal Data is collected or processed on the basis of consent, to withdraw such consent. Withdrawing your consent will not affect the lawfulness of any processing conducted prior to withdrawal, nor will it affect processing of Personal Data conducted in reliance on lawful processing grounds other than consent. 

6.     To complain to a data protection authority about the collection and use of Personal Data.

 

If you wish to exercise any of the rights set out above, please get in touch with us. We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

 

Consequences of Refusal to Provide Personal Data 

 

While you may refuse to provide us with the herein Personal Data, kindly note that such non-disclosure might hinder the accuracy of, or even render impractical, our Services to you. We therefore reserve the right to refuse or withdraw from the provision of Services in such event.

 

 

7.     How We Share Information

 

We do not share or disclose any of your Personal Data without your consent, other than for purposes specified in this notice or where there is a legal requirement. We may use third party providers to provide our services – in particular in maintaining the website.

 

In pursuit of the above, we may share and disclose your Personal Data to the following types of third parties for the purposes described in this privacy notice:

 

a.   Our Service Providers: Sometimes, we share your information with third-party service providers, who help us provide and support our Website and other business-related functions.

 

b.   Advertising partners: kindly note Clause 9 below in this respect.

 

c.   Any competent law enforcement body, regulatory body, authority, court or other third party where we believe disclosure is necessary on account of any applicable law, or to exercise, establish, or defend our legal rights.

 

d.   A potential new joint venture member or acquirer in the event that the joint venture is reorganised or restructured, or in the case of a sale, merger, consolidation, liquidation, reorganisation or acquisition of any of the joint venture’s members, the new member. In such case, the new member or acquirer will be subject to our obligations under this privacy policy, including your rights to access and choice. 

 

e.   Any other person with your consent.

 

 

8.     Your Choices and Opt-Outs

 

If you opted in our marketing e-mails and communications, you can opt out of receiving such communication. You may do so by clicking the ‘unsubscribe’ link at the bottom of the marketing message received. Also, opt-out requests can be made by messaging us directly.

 

 

9.     Security & Data Transfers

 

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your Personal Data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

 

 

International Data Transfers

 

Personal Data in the European Union is protected by the General Data Protection Regulation (GDPR) but some other countries may not necessarily have the same high standard of protection for your Personal Data. Sometimes we may have to share your Personal Data with third party processors which are based outside of the EU, however when we do so we will ensure that this is done under an adequacy decision or under standard contractual clauses approved by the EU Commission.

 

 

10.  Retention of Data

 

We will only retain your Personal Data for as long as necessary to fulfil its collection purposes including any legal, contractual, regulatory or accounting requirements. We will hold on to your Personal Data for as long as our relationship subsists or to prove that we provided our services, for a period of 5 years after the relationship ends, or where the right subsists, up until the Personal Data is deleted in pursuit of a request from your end.

 

 

11.  Changes to this Privacy Notice

 

We may change this privacy notice at any time and from time to time. The most recent version of the privacy notice is reflected by the version date located at the top of this privacy notice. All updates and amendments are effective immediately upon notice, which may be given by any means, including, but not limited to, by posting a revised version of this privacy notice or other notice on the Website.

 

We encourage you to review this privacy notice often and to stay informed of changes that may affect you. 

 

 

12.  Questions and Concerns

 

If you have any questions, comments, or if you have a concern about the way in which we handled any privacy matter, or if you would like to send us a communication or message in pursuit of any of your rights in accordance with this privacy notice, please use our contact page on www.iftahqalbek.mt or e-mail us on [email protected]

 

 

13.  Conclusion

 

Iftaħ Qalbek is controller and responsible for your Personal Data. You have the right to make a complaint at any time to the Office of the Information and Data Protection Commissioner (IDPC), the Maltese supervisory authority for data protection issues (www.idpc.org.mt). We would, however, appreciate the chance to deal with your concerns before you approach the IDPC so please contact us in the first instance.