Privacy Policy
Last updated:
1. Who we are
GG Business Solutions is an accounting and advisory firm based in Mellieħa, Malta. We provide bookkeeping, tax compliance, financial reporting, company formation, payroll, and business advisory services to businesses and individuals in Malta and beyond.
For the purposes of the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Data Protection Act (Chapter 586 of the Laws of Malta), GG Business Solutions acts as the data controller of your personal data.
Data protection contact: [email protected] | +356 9933 7692 | 60, Orchidea, Triq il-Mithna Qadima, Mellieħa, Malta.
2. What personal data we collect
We collect personal data in the following circumstances:
Website enquiries — when you submit our contact form we collect your full name, email address, telephone number, the service you are enquiring about, and any information you include in your message.
Client engagements — when you engage us to provide professional services we may additionally collect financial records, VAT and tax identification numbers, company registration details, payroll data, identity documents, and any other information required to fulfil our obligations to you.
Website usage — we collect anonymised analytics data (page views, session duration, device type, approximate location) through Google Analytics 4, but only after you have given your consent via our cookie banner.
3. How we use your data
We use the personal data we hold to:
• Respond to your enquiry and provide the information or services you have requested • Carry out our contractual obligations where you engage us as a client • Comply with our legal and regulatory obligations, including those under Maltese tax law, the Prevention of Money Laundering Act (Chapter 373), and company law • Manage and improve our website and services • Send you relevant service updates or information where you have given consent or where we have a legitimate interest to do so, and you have not opted out
4. Legal basis for processing
We process your personal data on the following legal bases under Article 6 GDPR:
• Consent (Art. 6(1)(a)) — when you submit our contact form or accept analytics cookies. • Contractual necessity (Art. 6(1)(b)) — when we provide accounting or advisory services to you as a client. • Legal obligation (Art. 6(1)(c)) — where processing is required to comply with applicable laws and regulations, including anti-money laundering and tax reporting obligations. • Legitimate interests (Art. 6(1)(f)) — to manage and improve our services, communicate with prospective clients, and maintain the security of our systems, provided your fundamental rights and interests are not overridden.
Where we rely on consent, you have the right to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. How long we keep your data
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law:
• Website enquiries — up to 12 months from the date of your enquiry, unless you become a client. • Client records — a minimum of 10 years from the end of the engagement, in accordance with Maltese tax and company law requirements. • Anti-money laundering records — 5 years from the end of the business relationship, as required by the Prevention of Money Laundering Act. • Analytics data — aggregated and anonymised; individual session data is retained by Google Analytics for up to 14 months.
When data is no longer required, it is securely deleted or anonymised.
6. Sharing your data
We do not sell, rent, or trade your personal data. We may share your data only in the following circumstances:
• Regulatory and government authorities — where required by law, for example the Malta Tax and Customs Administration (CFR), the Malta Business Registry (MBR), or the Financial Intelligence Analysis Unit (FIAU). • Professional advisers — such as lawyers or auditors engaged by us, under strict confidentiality obligations. • Service providers — third-party providers who assist us in operating our website or delivering our services (for example, our website hosting provider and inbox management platform), subject to appropriate data processing agreements. • Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to equivalent privacy protections.
We do not transfer your personal data outside the European Economic Area (EEA) unless appropriate safeguards are in place in accordance with Chapter V of the GDPR.
7. Cookies and analytics
Our website uses cookies — small text files stored on your device — to improve your browsing experience and to understand how visitors use our site.
Strictly necessary cookies are required for the website to function and cannot be disabled. Analytics cookies (Google Analytics 4) are only placed after you accept our cookie consent banner. You may withdraw your consent at any time by clearing your browser cookies or adjusting your browser settings.
We do not use advertising or tracking cookies, and we do not share analytics data with third parties for marketing purposes.
8. Data security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include secure HTTPS transmission, access controls, and regular review of our data handling practices.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the IDPC within 72 hours and, where required, inform you directly.
9. Your rights
Under the GDPR, you have the following rights regarding your personal data:
• Right of access — to obtain a copy of the personal data we hold about you. • Right to rectification — to have inaccurate or incomplete data corrected. • Right to erasure — to request deletion of your data, subject to our legal retention obligations. • Right to restriction — to request that we limit the processing of your data in certain circumstances. • Right to object — to object to processing based on legitimate interests or for direct marketing purposes. • Right to data portability — to receive your data in a structured, commonly used, machine-readable format. • Right to withdraw consent — at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at [email protected]. We will respond within one month. In complex cases we may extend this by a further two months, and will inform you accordingly.
10. Complaints
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner (IDPC), the supervisory authority in Malta.
IDPC contact details: Office of the Information and Data Protection Commissioner, Second Floor, Airways House, High Street, Sliema SLM 1549, Malta. Website: www.idpc.org.mt | Email: [email protected] | Tel: +356 2328 7100.
We would, however, appreciate the opportunity to address your concerns before you approach the IDPC, so please contact us in the first instance.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The latest version will always be available on this page, with the date of the most recent update shown at the top. Where changes are material, we will take reasonable steps to notify you.