| 3 |
0 |
0 |
3 |
A |
T |
0 |
1208728800 |
0 |
|
0 |
N |
0 |
0 |
activity |
|
en |
Privacy policy |
<p><span style="font-size: 10pt;">Surf Creative Solutions Ltd. (“Surf,” “we,” or “our”) is committed to respecting and protecting your privacy. This Privacy Policy describes how we collect, use, store, and protect personal data when you interact with our platform, whether as a customer, seller, or visitor.</span></p>
<p><span style="font-size: 10pt;">We process your data in compliance with the <a title="General Data Protection Regulation (GDPR)" href="https://gdpr-info.eu/">General Data Protection Regulation (GDPR)</a>, <a title="Malta’s Data Protection Act (Chapter 586)" href="https://legislation.mt/eli/cap/586/eng/pdf">Malta’s Data Protection Act (Chapter 586)</a>, and other applicable Maltese data protection laws, including any specific requirements related to law enforcement data handling and exemptions outlined in the <a title="Restriction of Data Protection (Obligations and Rights) Regulations" href="https://idpc.org.mt/wp-content/uploads/2020/07/SL-586.09.pdf">Restriction of Data Protection (Obligations and Rights) Regulations</a>. Our goal is to ensure all data processing activities are conducted fairly, transparently,and securely.</span></p>
<h3><span style="font-size: 10pt;">1. Who we are</span></h3>
<p><span style="font-size: 10pt;">Surf Creative Solutions Ltd. operates as the data controller, responsible for determining the purpose and means of processing your personal data. We are committed to upholding the highest standards of data protection.</span></p>
<h3><span style="font-size: 10pt;">2. Contact Information</span></h3>
<p><span style="font-size: 10pt;">If you have questions, concerns, or requests regarding your personal data, please contact us at:</span></p>
<ul>
<li><span style="font-size: 10pt;">Email: <a title="info@surf.mt" href="mailto:info@surf.mt">info@surf.mt</a>/<a title="gdpr@surf.mt" href="mailto:gdpr@surf.mt">gdpr@surf.mt</a></span></li>
<li><span style="font-size: 10pt;">Phone: +356 77215267</span></li>
<li><span style="font-size: 10pt;">Address: EOffice 9, Level 3B, Centris Business Gateway II, Triq is-Salib tal-Imriehel, Zone 3, Central Business District, Birkirkara CBD 3020, Malta.</span></li>
</ul>
<p><span style="font-size: 10pt;"><strong>3. Types of Data Collected</strong></span></p>
<p><span style="font-size: 10pt;">Surf collects various types of personal data to provide its services, comply with legal obligations, and improve user experience. This section outlines the categories of data collected based on user interactions with our platform,covering customers, sellers, visitors, influencer applicants, and employees.</span><span style="font-size: 10pt;"></span></p>
<p><span style="font-size: 10pt;"><strong>a. Data Collected from Sellers</strong></span></p>
<p><span style="font-size: 10pt;">Surf collects certain data from sellers to facilitate onboarding, product listings, financial transactions, and legal compliance:</span></p>
<ul>
<li><span style="font-size: 10pt;"><strong>Identity and Business Information:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Business Registration Name: Used to verify the seller’s business entity and for regulatory purposes.</span></li>
<li><span style="font-size: 10pt;">VAT Number: Required for tax compliance and regulatory reporting. </span></li>
<li><span style="font-size: 10pt;">Registered Business Address: For official communication and identity verification.</span></li>
</ul>
</li>
<li><span style="font-size: 10pt;"><strong>Contact Information:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Full Name and Role of Representative: Identifies the individual managing the seller account.</span></li>
<li><span style="font-size: 10pt;">Email Address and WhatsApp Number: Used for account-related communication, support, and notifications.</span><strong style="font-size: 10pt; background-color: var(--tinymce-content-body-bg); color: var(--tinymce-content-body-fg);"> </strong></li>
</ul>
</li>
<li><span style="font-size: 10pt;"><strong>Banking and Financial Details:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Bank Account Information: Required for secure payment processing and payouts.</span><span style="font-size: 10pt;"></span></li>
</ul>
</li>
<li><span style="font-size: 10pt;"><strong>Product Listings and Details:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Product Information: Product descriptions, prices, stock levels, and metadata necessary for managing listings on Surf’s platform.</span><span style="font-size: 10pt;"></span><span style="font-size: 10pt;"></span></li>
</ul>
</li>
<li><span style="font-size: 10pt;"><strong>Usage and Access Information: Login Activity and Session Details: </strong></span>Tracks login times, IP addresses, and session duration for security,platform stability, and usage insights.</li>
</ul>
<p><span style="font-size: 10pt;"><strong>b. Data Collected from Customers</strong></span></p>
<p><span style="font-size: 10pt;">Customer data is essential for managing orders, providing support,and personalizing the experience on Surf’s platform:</span></p>
<ul>
<li><span style="font-size: 10pt;"><strong>Personal Information:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Full Name: Used for personalized interactions and identifying customers.</span></li>
<li><span style="font-size: 10pt;">Email Address and Phone Number: Necessary for order updates, customer service inquiries, and transactional communication. </span></li>
</ul>
</li>
</ul>
<ul>
<li><span style="font-size: 10pt;"><strong>Shipping and Billing Details:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Shipping Address: Needed for order fulfillment, tracking, and delivery.</span></li>
<li><span style="font-size: 10pt;">Billing Address: Required for verifying payment details and legal compliance with invoicing. </span></li>
</ul>
</li>
</ul>
<ul>
<li><span style="font-size: 10pt;"><strong>Order and Transaction Data:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Order History and Purchase DetailsTracks product purchases, order status, and payment methods (processed securely by third parties, such as Stripe). </span></li>
<li><span style="font-size: 10pt;">Refund and Return Information: Necessary for managing returns and refunds in accordance with customer rights and Surf’s policies. </span></li>
</ul>
</li>
</ul>
<ul>
<li><span style="font-size: 10pt;"><strong>Geolocation Data:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Location Information: Collected with consent and used for marketing purposes, such as targeted ads on platforms like Facebook and Google.</span></li>
</ul>
</li>
</ul>
<p><span style="font-size: 10pt;"><strong>c. Data Collected from All Users (Customers, Sellers, and Visitors)</strong></span></p>
<p><span style="font-size: 10pt;">Surf collects technical and browsing data from everyone who visits or interacts with the website. This data helps us optimize services, maintain security, and enhance the user experience. </span></p>
<ul>
<li><span style="font-size: 10pt;"><strong>Browsing and Interaction Data:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Session Information: Tracks pages visited, time spent on each page, and interactions to improve website structure and usability.</span></li>
<li><span style="font-size: 10pt;">Clickstream Data: Collects anonymous data on popular pages and user interactions. </span></li>
</ul>
</li>
</ul>
<ul>
<li><span style="font-size: 10pt;"><strong>Device and Technical Information:</strong></span>
<ul>
<li><span style="font-size: 10pt;">IP Address, Browser Type, and Device Information: Used for security, troubleshooting, and ensuring the website’s compatibility across different devices.</span></li>
</ul>
</li>
</ul>
<ul>
<li><span style="font-size: 10pt;"><strong>Cookies and Tracking Technologies:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Strictly Necessary Cookies:Essential for site functionality (e.g., remembering login sessions and cart items).</span></li>
<li><span style="font-size: 10pt;">Functional Cookies: Enable additional services such as social media sharing. </span></li>
<li><span style="font-size: 10pt;">Marketing Cookies: Used for targeted advertising and analytics, including Facebook Pixel. </span></li>
<li><span style="font-size: 10pt;">Performance Cookies: Collect anonymous data to help analyze website performance and improve user experience. (See our Cookie Policy for details on managing cookies.) </span></li>
</ul>
</li>
</ul>
<p><span style="font-size: 10pt;"><strong>d. Data Collected from Influencer Applicants and Employees</strong></span></p>
<p><span style="font-size: 10pt;">Surf occasionally collects data from individuals interested in joining the platform as influencers or employees. This data is used strictly for reviewing applications, managing employment records, and ensuring compliance with employment regulations. </span></p>
<ul>
<li><span style="font-size: 10pt;"><strong>For Influencer Applicants:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Application Information: Includes Curriculum Vitae (CV) and personal details such as full name, contact information, educational background, professional experience, and social media links.</span></li>
<li><span style="font-size: 10pt;">Communication Details: Used for discussing collaboration opportunities. </span></li>
<li><span style="font-size: 10pt;">Collection Method: Collected via email as noted on Surf’s website. </span><span style="font-size: 10pt;"></span></li>
</ul>
</li>
</ul>
<ul>
<li><span style="font-size: 10pt;"><strong>For Employees:</strong></span>
<ul>
<li><span style="font-size: 10pt;">Employment Records: Includes full name, contact information, national ID, work history, references, and emergency contacts.</span></li>
<li><span style="font-size: 10pt;">Payroll and Benefits Information: Bank account details, tax information, and other financial data necessary for payroll and benefits.</span></li>
<li><span style="font-size: 10pt;">Performance and Evaluation Data: Tracks performance evaluations, role responsibilities, and work-related feedback.</span></li>
<li><span style="font-size: 10pt;">Health and Safety Information: Data related to workplace safety and any required health information, as per legal employment requirements.</span></li>
<li><span style="font-size: 10pt;">Collection Method: Typically collected during recruitment, onboarding, and as needed throughout employment.</span></li>
</ul>
</li>
</ul>
<p><span style="font-size: 10pt;"><span style="font-weight: 400;">Surf handles influencer and employee data confidentiality and in accordance with </span><a href="https://gdpr-info.eu/"><span style="font-weight: 400;">GDPR</span></a><span style="font-weight: 400;"> and </span><a href="https://legislation.mt/eli/cap/452/eng/pdf"><strong>Maltese Employment and Industrial Relations Act (EIRA, Chapter 452)</strong></a><span style="font-weight: 400;">, and other relevant labor regulations to ensure compliance with local laws.</span></span></p>
<p><span style="font-size: 10pt;"><strong>4. Additional Data Sources</strong></span></p>
<p><span style="font-size: 10pt;">In certain cases, we may collect data from third-party sources to enhance our services and verify seller information.</span></p>
<ul>
<li><span style="font-size: 10pt;">Third-Party Service Providers:We may receive aggregated data from advertising and analytics partners like Google Analytics to understand user demographics, interests, and improve our marketing strategies.</span></li>
<li><span style="font-size: 10pt;">Publicly Available Sources:To verify seller information and ensure accuracy, Surf consults publicly accessible resources such as:</span>
<ul>
<li><span style="font-size: 10pt;">VATify.eu: Used to verify VAT numbers and ensure compliance with EU VAT regulations.</span></li>
<li><span style="font-size: 10pt;">Malta Business Registry (MBR): For verification of registered businesses in Malta.</span></li>
<li><span style="font-size: 10pt;">Other publicly available databases and resources, consulted as necessary, to support data accuracy and compliance.</span></li>
</ul>
</li>
</ul>
<p><span style="font-size: 10pt;"><strong>5. Purpose, Legal Basis, and Duration of Processing</strong></span></p>
<p><span style="font-size: 10pt;">Surf processes personal data for specific purposes, each with a clear legal basis under GDPR and defined retention periods. Personal data is retained only as long as necessary to fulfill the purposes described below, after which it is securely deleted or anonymized.</span></p>
<p> </p>
<table style="width: 908px; height: 1522px;">
<tbody>
<tr style="height: 100px;">
<td style="width: 208px; height: 100px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Purpose of Processing</strong></span></p>
</td>
<td style="width: 142px; height: 100px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Legal Basis</strong></span></p>
</td>
<td style="width: 204px; height: 100px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Examples of Data Usage</strong></span></p>
</td>
<td style="width: 364px; height: 100px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Data Retention Period</strong></span></p>
</td>
</tr>
<tr style="height: 149px;">
<td style="width: 208px; height: 149px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Account Creation and Management</strong></span></p>
</td>
<td style="width: 142px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Contractual necessity</span></p>
</td>
<td style="width: 204px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Used to create and manage user and seller accounts</span></p>
</td>
<td style="width: 364px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Retained while account remains active; deleted upon closure</span></p>
</td>
</tr>
<tr style="height: 149px;">
<td style="width: 208px; height: 149px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Order Processing and Fulfillment</strong></span></p>
</td>
<td style="width: 142px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Contractual necessity</span></p>
</td>
<td style="width: 204px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Processes shipping and billing information for orders</span></p>
</td>
<td style="width: 364px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">7 years (to comply with tax and legal requirements)</span></p>
</td>
</tr>
<tr style="height: 149px;">
<td style="width: 208px; height: 149px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Marketing and Personalized Advertising</strong></span></p>
</td>
<td style="width: 142px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Consent</span></p>
</td>
<td style="width: 204px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Sends promotional offers and personalized ads</span></p>
</td>
<td style="width: 364px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Until user withdraws consent or as allowed by GDPR</span></p>
</td>
</tr>
<tr style="height: 173px;">
<td style="width: 208px; height: 173px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Customer Support and Service Improvements</strong></span></p>
</td>
<td style="width: 142px; height: 173px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Legitimate interest</span></p>
</td>
<td style="width: 204px; height: 173px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Assists in resolving user queries, includes WhatsApp communication</span></p>
</td>
<td style="width: 364px; height: 173px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Retained until support issues are fully resolved</span></p>
</td>
</tr>
<tr style="height: 149px;">
<td style="width: 208px; height: 149px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Fraud Detection and Security</strong></span></p>
</td>
<td style="width: 142px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Legitimate interest</span></p>
</td>
<td style="width: 204px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Monitors suspicious activity to protect user accounts</span></p>
</td>
<td style="width: 364px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Retained throughout the business relationship</span></p>
</td>
</tr>
<tr style="height: 149px;">
<td style="width: 208px; height: 149px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Regulatory Compliance and Reporting</strong></span></p>
</td>
<td style="width: 142px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Legal obligation</span></p>
</td>
<td style="width: 204px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Maintains records for tax compliance and regulatory audits</span></p>
</td>
<td style="width: 364px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">As mandated by Maltese law and GDPR</span></p>
</td>
</tr>
<tr style="height: 149px;">
<td style="width: 208px; height: 149px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Employee and Payroll Management</strong></span></p>
</td>
<td style="width: 142px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Contractual necessity and legal obligation</span></p>
</td>
<td style="width: 204px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Manages payroll, benefits, and performance tracking</span></p>
</td>
<td style="width: 364px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Duration of employment plus additional statutory requirements</span></p>
</td>
</tr>
<tr style="height: 149px;">
<td style="width: 208px; height: 149px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Influencer Applications</strong></span></p>
</td>
<td style="width: 142px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Consent</span></p>
</td>
<td style="width: 204px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Reviews applications from prospective influencers</span></p>
</td>
<td style="width: 364px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Retained for 6 year post-application if not engaged</span></p>
</td>
</tr>
<tr style="height: 149px;">
<td style="width: 208px; height: 149px; text-align: center;">
<p><span style="font-size: 10pt;"><strong>Analytics and Website Performance</strong></span></p>
</td>
<td style="width: 142px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Legitimate interest</span></p>
</td>
<td style="width: 204px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Tracks browsing behavior to improve user experience</span></p>
</td>
<td style="width: 364px; height: 149px; text-align: center;">
<p><span style="font-weight: 400; font-size: 10pt;">Retained for 2 years in aggregated, anonymized format</span></p>
</td>
</tr>
</tbody>
</table>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Contractual Necessity<span style="font-weight: 400;">: Processing is required to fulfill a contract with the user or seller. For example, Surf needs user details to complete orders and facilitate payment processing.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Legitimate Interest<span style="font-weight: 400;">: Processing supports Surf’s business interests, including </span>WhatsApp as a preferred communication channel<span style="font-weight: 400;"> with users and sellers for updates, support, and inquiries, without overriding data subject rights.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Legal Obligation<span style="font-weight: 400;">: Surf retains certain data to comply with legal requirements, such as tax documentation.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Consent: Certain processing, such as marketing communications or influencer applications, requires explicit user consent. Users can withdraw this consent at any time, ending the processing for that purpose.</span></li>
</ul>
<h3><span style="font-size: 10pt;"><strong>6. Disclosure of Personal Data</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">We may disclose your personal data in the following circumstances:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400; font-size: 10pt;">To comply with legal obligations or respond to lawful requests by public authorities, including to meet national security or law enforcement requirements.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400; font-size: 10pt;">To protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or others.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400; font-size: 10pt;">In connection with a sale, merger, or other business reorganization, your data may be disclosed to potential buyers or joint venture partners under appropriate confidentiality measures.</span></li>
</ul>
<h3><span style="font-size: 10pt;"><strong>a. Third-Party Sharing and Compliance Measures</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">Surf shares personal data with third parties only to the extent necessary to operate and enhance our services. We have strict agreements in place with third parties to ensure your data is processed in compliance with GDPR and other applicable regulations. These partners include:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Service providers<span style="font-weight: 400;"> for payment processing, marketing, and analytics.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Logistics and fulfillment providers<span style="font-weight: 400;"> to manage order deliveries.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Advertising platforms<span style="font-weight: 400;"> to reach our audience with relevant content and offers.</span></span></li>
</ul>
<h3><span style="font-size: 10pt;"><strong>b. Data Processing Agreements</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">All third parties handling your data on our behalf are subject to Data Processing Agreements (DPAs) that enforce compliance with GDPR standards. These agreements include provisions to:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400; font-size: 10pt;">Limit data processing to only necessary and approved activities.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400; font-size: 10pt;">Require appropriate technical and organizational security measures.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400; font-size: 10pt;">Ensure data is processed confidentially and securely.</span></li>
</ul>
<h3><span style="font-size: 10pt;"><strong>7. International Data Transfers</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">When Surf transfers data outside the European Economic Area (EEA), we adhere to GDPR requirements for data protection. Transfers are only made when necessary and with adequate protection measures in place.</span></p>
<h3><span style="font-size: 10pt;"><strong>a. Safeguards for Cross-Border Data Transfers</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">For cross-border data transfers, Surf implements the following safeguards:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Standard Contractual Clauses<span style="font-weight: 400;">: When transferring data outside the EEA, we employ Standard Contractual Clauses approved by the European Commission to ensure the security and legality of the transfer.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Binding Corporate Rules<span style="font-weight: 400;">: For transfers within our organization, we follow strict internal policies that align with GDPR principles.</span></span></li>
</ul>
<p><span style="font-size: 10pt;"><strong>b. Standard Contractual Clauses </strong></span></p>
<p><span style="font-weight: 400; font-size: 10pt;">Our agreements with third-party service providers outside the EEA incorporate Standard Contractual Clauses (SCCs) where required. These clauses provide specific guarantees around data security, privacy, and compliance with GDPR requirements.</span></p>
<h3><span style="font-size: 10pt;"><strong>8. Cookies and Tracking Technologies</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">Surf uses cookies and similar tracking technologies to enhance your experience on our platform. Cookies help us understand user preferences, optimize site performance, and deliver targeted advertisements.</span></p>
<h3><span style="font-size: 10pt;"><strong>a. Types of Cookies Used</strong></span></h3>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Strictly Necessary Cookies<span style="font-weight: 400;">: Essential for site functionality, like maintaining your login session.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Functional Cookies<span style="font-weight: 400;">: Enable extra features, such as saving your preferences.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Performance Cookies<span style="font-weight: 400;">: Collect anonymous data to analyze website performance and improve user experience.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;">Marketing Cookies<span style="font-weight: 400;">: Used to personalize advertising and measure ad effectiveness.</span></span></li>
</ul>
<h3><span style="font-size: 10pt;"><strong>b. Managing Cookie Preferences</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">You can manage or disable cookies through your browser settings or via our cookie preference tool on the site. For more details, please refer to our Cookie Policy.</span></p>
<h3><span style="font-size: 10pt;"><strong>c. Link to Detailed Cookie Policy</strong></span></h3>
<p><span style="font-size: 10pt;"><span style="font-weight: 400;">For a more detailed overview of the cookies we use and their purposes, please review our </span><a href="https://docs.google.com/document/u/0/d/1e0oFW32lXnPjhzVc7w4O3lAQCPP6WzXCJy_noP6Q7zY/edit"><span style="font-weight: 400;">Cookie Policy.</span></a></span></p>
<h3><span style="font-size: 10pt;"><strong>9. Changes to the Privacy Policy</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">We may update our Privacy Policy to reflect changes in our practices or relevant laws. We encourage you to review this page periodically for any updates.</span></p>
<h3><span style="font-size: 10pt;"><strong>a. Notification of Policy Updates</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">When we make significant changes to our Privacy Policy, we will notify you via email or through prominent notices on our website to keep you informed.</span></p>
<h3><span style="font-size: 10pt;"><strong>b. Effective Date of Last Update</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">This Privacy Policy was last updated on 07/11/2024.</span></p>
<h3><span style="font-size: 10pt;"><strong>10. Contact Information for GDPR Queries</strong></span></h3>
<p><span style="font-weight: 400; font-size: 10pt;">If you have any questions, concerns, or requests regarding the processing of your personal data, or if you would like to exercise your rights under the General Data Protection Regulation (GDPR), please contact our data protection team.</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;"><strong>Data Protection Officer (DPO)</strong><span style="font-weight: 400;">: Ashwini Kumar</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;"><strong>Email</strong><span style="font-weight: 400;">: gdpr@surf.mt</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;"><strong>Phone</strong><span style="font-weight: 400;">: +356 77215267</span></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-size: 10pt;"><strong>Postal Address</strong><span style="font-weight: 400;">:</span><span style="font-weight: 400;"><br /></span><span style="font-weight: 400;">Surf Creative Solutions Ltd.</span><span style="font-weight: 400;"><br /></span><span style="font-weight: 400;">Attn: Ashwini Kumar - Data Protection Officer</span><span style="font-weight: 400;"><br /></span><span style="font-weight: 400;">Office 9, Level 3B, Centris Business Gateway II, Triq is-Salib tal-Imriehel, Zone 3,</span><span style="font-weight: 400;"><br /></span><span style="font-weight: 400;">Central Business District, Birkirkara CBD 3020, Malta.</span></span></li>
</ul>
<p><span style="font-weight: 400; font-size: 10pt;">Our team is committed to addressing your queries promptly and transparently. We aim to respond to GDPR-related inquiries within one month, as required under GDPR regulations.</span></p>
<h3><span style="font-size: 10pt;"><strong>11. Definition of main terms</strong></span></h3>
<table style="width: 911px;">
<tbody>
<tr>
<td style="width: 911px;" colspan="2">
<p><span style="font-size: 10pt;"><strong>Glossary</strong></span></p>
</td>
</tr>
<tr>
<td style="width: 120px;">
<p><span style="font-size: 10pt;"><strong>GDPR</strong></span></p>
</td>
<td style="width: 791px;">
<p><span style="font-weight: 400; font-size: 10pt;">Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural person with regard to the processing of personal and on the free movement of such data and repealing Directive 95/46/EEC (General Data Protection Regulation)</span></p>
</td>
</tr>
<tr>
<td style="width: 120px;">
<p><span style="font-size: 10pt;"><strong>Processing</strong></span></p>
<p><span style="font-weight: 400; font-size: 10pt;"> </span></p>
</td>
<td style="width: 791px;">
<p><span style="font-weight: 400; font-size: 10pt;">Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction</span></p>
</td>
</tr>
<tr>
<td style="width: 120px;">
<p><span style="font-size: 10pt;"><strong>Controller</strong></span></p>
</td>
<td style="width: 791px;">
<p><span style="font-weight: 400; font-size: 10pt;">The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data</span></p>
</td>
</tr>
<tr>
<td style="width: 120px;">
<p><span style="font-size: 10pt;"><strong>Data Protection Officer – DPO</strong></span></p>
</td>
<td style="width: 791px;">
<p><span style="font-weight: 400; font-size: 10pt;">For the purposes of this privacy policy the Controller (Surf Creative Solutions LTD) appointed a DPO to carry out the following tasks:</span></p>
<p><span style="font-weight: 400; font-size: 10pt;">To review the compliance with GDPR and other applicable EU or national legislation in relation to the protection of personal data.</span></p>
<p><span style="font-weight: 400; font-size: 10pt;">To advise Surf Creative Solutions LTD about legislative developments and methods of compliance with its obligations under GDPR and other applicable law.</span></p>
<p><span style="font-weight: 400; font-size: 10pt;">To cooperate with the supervisory authority.</span></p>
</td>
</tr>
<tr>
<td style="width: 120px;">
<p><span style="font-size: 10pt;"><strong>Personal data</strong></span></p>
</td>
<td style="width: 791px;">
<p><span style="font-weight: 400; font-size: 10pt;">Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.</span></p>
</td>
</tr>
</tbody>
</table>
<p><strong>Version:</strong><span> 1.1</span><br /><strong>Effective Date:</strong><span> 31/03/2025</span></p> |
privacy policy, data protection, personal data security, user privacy rights, cookie usage, data collection practices, legal compliance, secure data handling |
Read our detailed Privacy Policy to understand how we collect, use, and protect your personal data when you use our services at Surf. |
Comprehensive Privacy Policy - Protecting Your Data | Surf |
|
privacy-policy |
|