Privacy Policy
Valletta Software Development Limited. Last updated: 18 September 2026
We keep this policy short and specific. It says what we collect, why, on what legal basis, how long we keep it and what you can ask us to do about it.
Cookies and similar technologies are covered separately, in our Cookie Policy.
1. Who we are
Valletta Software Development Limited is the data controller for the personal data described in this policy.
| Company | Valletta Software Development Limited |
|---|---|
| Company registration number | C88523 |
| Registered address | 135 La Spinola Court, Paceville, San Giljan, Malta |
| Contact | info@vallettasoftware.com |
| Data Protection Officer | Our processing does not meet the thresholds in Article 37(1) GDPR, so we are not required to appoint a Data Protection Officer and have not appointed one. Data protection questions go to the contact address above and are handled by our management. |
| Supervisory authority | Information and Data Protection Commissioner (IDPC), Malta, idpc.org.mt |
2. What this policy covers
This policy covers personal data we collect when you visit vallettasoftware.com, contact us, subscribe to our newsletter, apply for a role, or buy one of our services.
It does not cover personal data we process inside client projects. When we build or maintain software for a client, the client decides why and how that data is processed and we act on their documented instructions. That relationship is governed by a Data Processing Agreement between us and the client, not by this policy. If you believe your data is held in a system we built for someone else, contact that organisation, and we will assist them in responding to you.
3. The two roles we act in
As a controller, for the data described in this policy: website visitors, enquiries, newsletter subscribers, job applicants, and our own client and supplier contacts.
As a processor, for personal data inside client systems and client projects. In that role we process only on the client's instructions, under a Data Processing Agreement, and we do not decide the purposes of processing.
4. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact data | First and last name, email address, company, job title, phone number if you give it | You, through forms, email, calls and meetings |
| Enquiry and project data | The content of your message, project description, requirements you share with us before a contract exists | You |
| Newsletter data | Email address, subscription status, whether an email was opened and which links were clicked | You, plus our email platform |
| Technical data | IP address, browser type and version, device type, operating system, referring page, pages requested | Automatically, in our server logs |
| Usage and analytics data | Pages viewed, time on page, links and buttons clicked, the site or search engine you arrived from, and approximate location derived from a truncated IP address | Google Analytics cookies, only where you have consented. See our Cookie Policy |
| Recruitment data | CV, work history, portfolio links, right to work information where relevant | You, or a recruitment partner |
| Payment data | Billing name, billing address, VAT number, transaction reference | You and our payment processor. We do not store full card numbers |
We do not ask for special category data (health, biometrics, political opinions, religious beliefs, trade union membership, sexual orientation) and we ask you not to send it to us. If you include it in a message to us anyway, we delete it.
5. Why we use it, and the legal basis
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Responding to your enquiry and preparing a proposal | Identity, contact, enquiry data | Steps at your request prior to entering a contract, Art 6(1)(b) |
| Delivering services under a signed contract | Identity, contact, project, payment data | Performance of a contract, Art 6(1)(b) |
| Sending invoices and keeping accounting records | Identity, contact, payment data | Legal obligation, Art 6(1)(c) |
| Sending our newsletter and marketing emails | Newsletter data, identity, contact | Consent, Art 6(1)(a). For existing clients, legitimate interest in marketing similar services, Art 6(1)(f), with an opt out in every message |
| Measuring how the website performs, so we know which content is worth writing | Usage and analytics data | Consent, Art 6(1)(a), given through our cookie banner and withdrawable at any time. The cookies themselves are set under regulation 5 of the Processing of Personal Data (Electronic Communications Sector) Regulations (S.L. 586.01), which implements Article 5(3) of the ePrivacy Directive in Malta |
| Keeping the website and our systems secure | Technical data, server logs | Legitimate interest in the security and integrity of our systems, Art 6(1)(f) |
| Assessing job applications | Recruitment data | Steps at your request prior to a contract, Art 6(1)(b), and legitimate interest in building a hiring pipeline, Art 6(1)(f) |
| Establishing, exercising or defending legal claims | Any of the above, as relevant | Legitimate interest in protecting our legal position, Art 6(1)(f) |
Where we rely on legitimate interest, we have weighed that interest against your rights and freedoms. You can ask us for the reasoning behind any of these assessments, and you can object to the processing, using the contact details in section 1.
6. AI and your data
We build AI systems for our clients and we use AI tools in our own work, so we state our position plainly rather than leaving you to guess.
We do not use your personal data to train AI models. Personal data you give us through this website is never used to train or fine-tune any machine learning model, whether ours or a third party's. Where we use external AI services, we use them under terms that exclude our inputs from the provider's model training.
Where AI touches your data. We do not process personal data collected through this website with AI systems.
A person is always accountable. Every communication, quote, proposal and hiring decision that reaches you is reviewed by a person who is accountable for it. No AI system sends you a contract, a price or a rejection on its own.
No automated decision-making. We do not take decisions about you that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing, within the meaning of Article 22 GDPR. We do not build profiles of you for that purpose.
Talking to a person, not a bot. This website does not currently use an AI chatbot or virtual assistant. If we introduce one, it will identify itself as AI at the start of the first interaction, as required by Article 50 of Regulation (EU) 2024/1689, and we will update this policy before it goes live.
AI-assisted visual content. Some illustrations on this site are produced with tools that include generative features. We do not publish photorealistic synthetic imagery that could be mistaken for a genuine photograph of a real person, place or event, and we label any image where that distinction could be unclear.
7. Automated decision-making and profiling
We do not carry out automated decision-making producing legal or similarly significant effects, as described in Article 22 GDPR.
We do measure how our marketing emails and web pages perform, including which links are clicked. On the website this happens through Google Analytics, and only if you have consented to analytics cookies. This tells us which content is useful. It is aggregate reporting: it does not produce decisions about you, and we do not use it to build a profile that changes what you are shown or what you are charged.
8. Who we share it with
We share personal data with the categories of recipient below. We do not sell personal data, and we do not share it for third-party advertising.
| Recipient | What they do | Where they are |
|---|---|---|
| HubSpot | CRM, contact management, sales email tracking | USA / EU |
| Mailchimp (Intuit) | Newsletter delivery and engagement statistics | USA |
| Stripe | Payment processing | EU / USA |
| Google Ireland Limited, and Google LLC | Google Tag Manager and Google Analytics 4, website audience measurement | Ireland, with onward transfer to the USA |
| Website hosting provider | Hosting of vallettasoftware.com | EU |
We also disclose personal data where we are required to by law, by a court, or by a competent authority, and in connection with a merger, acquisition or sale of assets, in which case we will tell you before your data becomes subject to a different privacy policy.
9. How long we keep your data
We keep personal data only for as long as the purpose it was collected for requires, and then delete or anonymise it.
| Data | How long we keep it | Why |
|---|---|---|
| Enquiries that do not lead to a contract | 24 months from our last contact with you | So we can pick up a conversation you return to, and show how an enquiry was handled |
| Client contracts, project records and related correspondence | For the life of the contract, then 5 years | The general prescriptive period for commercial actions under Maltese law, article 2156 of the Civil Code and article 469 of the Commercial Code |
| Invoices and accounting records | 10 years from the end of the financial year | Required by Maltese company and tax law |
| Newsletter subscription | Until you unsubscribe, then a minimal suppression record kept indefinitely | So that an unsubscribe stays honoured and we do not email you again by mistake |
| Google Analytics usage data | 14 months from collection | The shortest retention Google Analytics 4 allows for event-level data |
| Server logs and technical data | 12 months | Security monitoring and investigating incidents |
| Unsuccessful job applications | 12 months from the hiring decision, or longer if you ask us to keep you on file | So we can approach you about a later opening, and answer questions about the decision |
Where a retention period is not listed, we keep data for as long as needed for the purpose it was collected for, and then delete or anonymise it.
10. International transfers
Where personal data leaves the EEA, we rely on one of the following:
an adequacy decision of the European Commission covering the destination country;
Standard Contractual Clauses approved by the European Commission, combined with a transfer impact assessment and, where needed, supplementary technical measures such as encryption in transit and at rest.
In practice, transfers to the United States rest on the EU-US Data Privacy Framework, the adequacy decision the European Commission adopted on 10 July 2023, for recipients that are certified under it. Google LLC is certified. Where a recipient is not certified, we use Standard Contractual Clauses instead.
You can ask us for a copy of the safeguards we rely on for any particular transfer, using the contact details in section 1, and we will provide it free of charge as required by Article 15(2) GDPR.
11. Data we receive from other people
Most of the personal data in this policy comes from you. In two situations it reaches us from someone else, and Article 14 GDPR requires us to say so.
Recruitment partners and job boards. Where an agency or platform puts your CV in front of us, we receive your name, contact details and work history from them. We tell you within one month of receiving it, or at our first contact with you if that comes sooner.
Your colleagues. Where someone at a client or prospective client gives us your name and work email as the right person to talk to, we receive those details from them. We use publicly available business contact information in the same way.
We do not buy personal data, and we do not build contact lists by scraping social networks or harvesting addresses from the web.
12. Whether you have to give us your data
You are never obliged to give us personal data, but some of it we cannot do without, and Article 13(2)(e) GDPR requires us to explain the consequences.
Contact forms and enquiries. Your name and email are needed for us to reply at all. This is a contractual necessity in the sense of Article 6(1)(b), not a statutory one. Without them, we cannot answer you.
Contracts and invoicing. Billing details are a statutory requirement. Maltese VAT and company law obliges us to issue and keep compliant invoices, so we cannot deliver paid services without them.
Newsletter. Your email address is needed to send it. Nothing follows from declining except that you do not receive it.
Analytics cookies. Entirely optional. Refusing them changes nothing about how the site works for you.
13. How we protect your data
We use encryption in transit (TLS) for our website and our systems, access controls limiting personal data to the people who need it, logging of administrative access, and regular patching of the systems we run. Our engineering teams follow secure development practices, and we run security reviews of our own infrastructure.
No method of transmitting or storing data is completely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the IDPC as required by Articles 33 and 34 GDPR.
14. Your rights
Under the GDPR you have the following rights over the personal data we hold about you as a controller. They are not absolute, and where an exemption applies we will tell you which one and why.
Access (Art 15). Ask whether we hold personal data about you, and get a copy of it along with an explanation of how we use it.
Rectification (Art 16). Have inaccurate data corrected and incomplete data completed.
Erasure (Art 17). Ask us to delete your data where we no longer need it, where you withdraw consent we relied on, or where you successfully object. We may refuse where we still need the data to meet a legal obligation or to defend a legal claim.
Restriction (Art 18). Ask us to pause processing while we check an accuracy dispute or an objection.
Portability (Art 20). Receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible. This applies to data we process by consent or under a contract.
Objection (Art 21). Object to processing we base on legitimate interest, including the reasoning behind our balancing test. Where you object to direct marketing, we stop, with no exceptions.
Not being subject to automated decisions (Art 22). Not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. As section 7 explains, we do not take decisions of that kind, so in practice there is nothing here for you to contest.
Withdrawing consent (Art 7(3)). Where we rely on consent, withdraw it at any time. This does not affect processing already carried out. Every marketing email has an unsubscribe link.
To exercise any of these, email info@vallettasoftware.com. We answer within one month, and we do not charge for it. If your request is complex we may extend that by two further months, and we will tell you within the first month if we do. We may ask you for enough information to confirm who you are before we release data.
Complaining. If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to lodge a complaint with the Maltese supervisory authority at any time: the Information and Data Protection Commissioner (IDPC), Floor 2, Airways House, High Street, Sliema SLM 1549, Malta, idpc.org.mt. If you live in another EEA country, you may complain to your local supervisory authority instead.
15. Children
Our services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from a child below the age at which they can consent to information society services, which in Malta is 13 under the Data Protection Act (Chapter 586) and its subsidiary legislation, in line with Article 8 GDPR. If you believe a child has given us personal data, contact us and we will delete it.
16. Links to other sites
Our website links to sites we do not control, including our profiles on Clutch, LinkedIn and code hosting platforms. This policy does not apply to them. We suggest you read their privacy policies before giving them your data.
17. Changes to this policy
We update this policy when our processing changes. The date at the top shows the current version. Where a change materially affects how we use your personal data, we will notify subscribers by email and place a notice on this page before the change takes effect.
18. Contact
Questions about this policy, or about your data:
Valletta Software Development Limited
135 La Spinola Court, Paceville, San Giljan, Malta
Company No. C88523
info@vallettasoftware.com