Privacy Policy

Valletta Software Development Limited. Last updated: 18 September 2026

We keep this policy short and specific. It says what we collect, why, on what legal basis, how long we keep it and what you can ask us to do about it.

Cookies and similar technologies are covered separately, in our Cookie Policy.

1. Who we are

Valletta Software Development Limited is the data controller for the personal data described in this policy.

CompanyValletta Software Development Limited
Company registration numberC88523
Registered address135 La Spinola Court, Paceville, San Giljan, Malta
Contactinfo@vallettasoftware.com
Data Protection OfficerOur processing does not meet the thresholds in Article 37(1) GDPR, so we are not required to appoint a Data Protection Officer and have not appointed one. Data protection questions go to the contact address above and are handled by our management.
Supervisory authorityInformation and Data Protection Commissioner (IDPC), Malta, idpc.org.mt

2. What this policy covers

This policy covers personal data we collect when you visit vallettasoftware.com, contact us, subscribe to our newsletter, apply for a role, or buy one of our services.

It does not cover personal data we process inside client projects. When we build or maintain software for a client, the client decides why and how that data is processed and we act on their documented instructions. That relationship is governed by a Data Processing Agreement between us and the client, not by this policy. If you believe your data is held in a system we built for someone else, contact that organisation, and we will assist them in responding to you.

3. The two roles we act in

As a controller, for the data described in this policy: website visitors, enquiries, newsletter subscribers, job applicants, and our own client and supplier contacts.

As a processor, for personal data inside client systems and client projects. In that role we process only on the client's instructions, under a Data Processing Agreement, and we do not decide the purposes of processing.

4. What we collect

CategoryExamplesWhere it comes from
Identity and contact dataFirst and last name, email address, company, job title, phone number if you give itYou, through forms, email, calls and meetings
Enquiry and project dataThe content of your message, project description, requirements you share with us before a contract existsYou
Newsletter dataEmail address, subscription status, whether an email was opened and which links were clickedYou, plus our email platform
Technical dataIP address, browser type and version, device type, operating system, referring page, pages requestedAutomatically, in our server logs
Usage and analytics dataPages viewed, time on page, links and buttons clicked, the site or search engine you arrived from, and approximate location derived from a truncated IP addressGoogle Analytics cookies, only where you have consented. See our Cookie Policy
Recruitment dataCV, work history, portfolio links, right to work information where relevantYou, or a recruitment partner
Payment dataBilling name, billing address, VAT number, transaction referenceYou and our payment processor. We do not store full card numbers

We do not ask for special category data (health, biometrics, political opinions, religious beliefs, trade union membership, sexual orientation) and we ask you not to send it to us. If you include it in a message to us anyway, we delete it.

5. Why we use it, and the legal basis

PurposeData usedLegal basis (GDPR Article 6)
Responding to your enquiry and preparing a proposalIdentity, contact, enquiry dataSteps at your request prior to entering a contract, Art 6(1)(b)
Delivering services under a signed contractIdentity, contact, project, payment dataPerformance of a contract, Art 6(1)(b)
Sending invoices and keeping accounting recordsIdentity, contact, payment dataLegal obligation, Art 6(1)(c)
Sending our newsletter and marketing emailsNewsletter data, identity, contactConsent, Art 6(1)(a). For existing clients, legitimate interest in marketing similar services, Art 6(1)(f), with an opt out in every message
Measuring how the website performs, so we know which content is worth writingUsage and analytics dataConsent, Art 6(1)(a), given through our cookie banner and withdrawable at any time. The cookies themselves are set under regulation 5 of the Processing of Personal Data (Electronic Communications Sector) Regulations (S.L. 586.01), which implements Article 5(3) of the ePrivacy Directive in Malta
Keeping the website and our systems secureTechnical data, server logsLegitimate interest in the security and integrity of our systems, Art 6(1)(f)
Assessing job applicationsRecruitment dataSteps at your request prior to a contract, Art 6(1)(b), and legitimate interest in building a hiring pipeline, Art 6(1)(f)
Establishing, exercising or defending legal claimsAny of the above, as relevantLegitimate interest in protecting our legal position, Art 6(1)(f)

Where we rely on legitimate interest, we have weighed that interest against your rights and freedoms. You can ask us for the reasoning behind any of these assessments, and you can object to the processing, using the contact details in section 1.

6. AI and your data

We build AI systems for our clients and we use AI tools in our own work, so we state our position plainly rather than leaving you to guess.

We do not use your personal data to train AI models. Personal data you give us through this website is never used to train or fine-tune any machine learning model, whether ours or a third party's. Where we use external AI services, we use them under terms that exclude our inputs from the provider's model training.

Where AI touches your data. We do not process personal data collected through this website with AI systems.

A person is always accountable. Every communication, quote, proposal and hiring decision that reaches you is reviewed by a person who is accountable for it. No AI system sends you a contract, a price or a rejection on its own.

No automated decision-making. We do not take decisions about you that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing, within the meaning of Article 22 GDPR. We do not build profiles of you for that purpose.

Talking to a person, not a bot. This website does not currently use an AI chatbot or virtual assistant. If we introduce one, it will identify itself as AI at the start of the first interaction, as required by Article 50 of Regulation (EU) 2024/1689, and we will update this policy before it goes live.

AI-assisted visual content. Some illustrations on this site are produced with tools that include generative features. We do not publish photorealistic synthetic imagery that could be mistaken for a genuine photograph of a real person, place or event, and we label any image where that distinction could be unclear.

7. Automated decision-making and profiling

We do not carry out automated decision-making producing legal or similarly significant effects, as described in Article 22 GDPR.

We do measure how our marketing emails and web pages perform, including which links are clicked. On the website this happens through Google Analytics, and only if you have consented to analytics cookies. This tells us which content is useful. It is aggregate reporting: it does not produce decisions about you, and we do not use it to build a profile that changes what you are shown or what you are charged.

8. Who we share it with

We share personal data with the categories of recipient below. We do not sell personal data, and we do not share it for third-party advertising.

RecipientWhat they doWhere they are
HubSpotCRM, contact management, sales email trackingUSA / EU
Mailchimp (Intuit)Newsletter delivery and engagement statisticsUSA
StripePayment processingEU / USA
Google Ireland Limited, and Google LLCGoogle Tag Manager and Google Analytics 4, website audience measurementIreland, with onward transfer to the USA
Website hosting providerHosting of vallettasoftware.comEU

We also disclose personal data where we are required to by law, by a court, or by a competent authority, and in connection with a merger, acquisition or sale of assets, in which case we will tell you before your data becomes subject to a different privacy policy.

9. How long we keep your data

We keep personal data only for as long as the purpose it was collected for requires, and then delete or anonymise it.

DataHow long we keep itWhy
Enquiries that do not lead to a contract24 months from our last contact with youSo we can pick up a conversation you return to, and show how an enquiry was handled
Client contracts, project records and related correspondenceFor the life of the contract, then 5 yearsThe general prescriptive period for commercial actions under Maltese law, article 2156 of the Civil Code and article 469 of the Commercial Code
Invoices and accounting records10 years from the end of the financial yearRequired by Maltese company and tax law
Newsletter subscriptionUntil you unsubscribe, then a minimal suppression record kept indefinitelySo that an unsubscribe stays honoured and we do not email you again by mistake
Google Analytics usage data14 months from collectionThe shortest retention Google Analytics 4 allows for event-level data
Server logs and technical data12 monthsSecurity monitoring and investigating incidents
Unsuccessful job applications12 months from the hiring decision, or longer if you ask us to keep you on fileSo we can approach you about a later opening, and answer questions about the decision

Where a retention period is not listed, we keep data for as long as needed for the purpose it was collected for, and then delete or anonymise it.

10. International transfers

Where personal data leaves the EEA, we rely on one of the following:

In practice, transfers to the United States rest on the EU-US Data Privacy Framework, the adequacy decision the European Commission adopted on 10 July 2023, for recipients that are certified under it. Google LLC is certified. Where a recipient is not certified, we use Standard Contractual Clauses instead.

You can ask us for a copy of the safeguards we rely on for any particular transfer, using the contact details in section 1, and we will provide it free of charge as required by Article 15(2) GDPR.

11. Data we receive from other people

Most of the personal data in this policy comes from you. In two situations it reaches us from someone else, and Article 14 GDPR requires us to say so.

We do not buy personal data, and we do not build contact lists by scraping social networks or harvesting addresses from the web.

12. Whether you have to give us your data

You are never obliged to give us personal data, but some of it we cannot do without, and Article 13(2)(e) GDPR requires us to explain the consequences.

13. How we protect your data

We use encryption in transit (TLS) for our website and our systems, access controls limiting personal data to the people who need it, logging of administrative access, and regular patching of the systems we run. Our engineering teams follow secure development practices, and we run security reviews of our own infrastructure.

No method of transmitting or storing data is completely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the IDPC as required by Articles 33 and 34 GDPR.

14. Your rights

Under the GDPR you have the following rights over the personal data we hold about you as a controller. They are not absolute, and where an exemption applies we will tell you which one and why.

To exercise any of these, email info@vallettasoftware.com. We answer within one month, and we do not charge for it. If your request is complex we may extend that by two further months, and we will tell you within the first month if we do. We may ask you for enough information to confirm who you are before we release data.

Complaining. If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to lodge a complaint with the Maltese supervisory authority at any time: the Information and Data Protection Commissioner (IDPC), Floor 2, Airways House, High Street, Sliema SLM 1549, Malta, idpc.org.mt. If you live in another EEA country, you may complain to your local supervisory authority instead.

15. Children

Our services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from a child below the age at which they can consent to information society services, which in Malta is 13 under the Data Protection Act (Chapter 586) and its subsidiary legislation, in line with Article 8 GDPR. If you believe a child has given us personal data, contact us and we will delete it.

16. Links to other sites

Our website links to sites we do not control, including our profiles on Clutch, LinkedIn and code hosting platforms. This policy does not apply to them. We suggest you read their privacy policies before giving them your data.

17. Changes to this policy

We update this policy when our processing changes. The date at the top shows the current version. Where a change materially affects how we use your personal data, we will notify subscribers by email and place a notice on this page before the change takes effect.

18. Contact

Questions about this policy, or about your data:

Valletta Software Development Limited
135 La Spinola Court, Paceville, San Giljan, Malta
Company No. C88523
info@vallettasoftware.com