GlowUp Ltd. — Malta
Last updated: August 2026
GlowUp Ltd. takes the protection of your personal data seriously. This Privacy Policy explains how we collect, use, store and protect personal data when you visit our website or use our services. The processing of personal data is carried out in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Data Protection Act (Chapter 586 of the Laws of Malta) and other applicable Maltese and European data protection legislation.
The data controller responsible for the processing of personal data on this website is:
GlowUp Ltd. [FULL REGISTERED BUSINESS ADDRESS] Mosta, Malta Email: glowupmalta@gmail.com Website: www.glowup.com
Please replace the placeholder above with the full registered address of GlowUp Ltd. before publishing this Privacy Policy.
No Data Protection Officer has been appointed based on the information currently available.
We process personal data only where necessary to operate our website, respond to enquiries, arrange appointments, provide our services, analyse the use of our website or comply with applicable legal obligations.
“Personal data” means any information relating to an identified or identifiable natural person.
Depending on the specific processing activity, personal data may be processed on the basis of consent, contractual necessity, a legal obligation or our legitimate interests.
Our website is hosted by STRATO.
When you access our website, certain technical information may be processed automatically in order to provide and secure the website. This may include:
The processing of this information is necessary to ensure the reliable, secure and technically functional operation of our website.
The legal basis for this processing is Article 6(1)(f) GDPR, based on our legitimate interest in maintaining a secure and functional website.
Where the hosting provider processes personal data on our behalf, such processing is carried out in accordance with the applicable requirements governing processors under the GDPR.
You may contact us by email or through the contact form available on our website.
When you contact us, we may process the personal data you voluntarily provide, including:
We use this information solely to process and respond to your enquiry.
Where your enquiry relates to entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR.
For general enquiries, processing may be based on our legitimate interest in responding to communications under Article 6(1)(f) GDPR.
Your information will generally be retained only for as long as necessary to deal with your enquiry, unless longer retention is required by law.
We use Calendly to enable users to schedule appointments with us.
When you book an appointment, personal information required for organising the appointment may be processed. This may include:
The purpose of this processing is to organise, administer and conduct appointments.
Where the appointment relates to the preparation or performance of a contractual relationship, processing is based on Article 6(1)(b) GDPR.
In other cases, processing may be based on our legitimate interest in efficiently managing appointments pursuant to Article 6(1)(f) GDPR.
Calendly LLC is based in the United States. Personal data relating to users in the European Economic Area may be transferred to and processed in the United States and other jurisdictions. Such transfers are subject to the applicable safeguards required under data protection law, which may include the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
Data is retained only for as long as necessary for the relevant appointment and associated purposes, subject to any applicable legal retention obligations.
We use Google Analytics to analyse how visitors use our website.
Google Analytics helps us understand, for example:
For businesses in Europe, the standard Google Analytics service is generally provided under terms with Google Ireland Limited.
Where Google Analytics involves the use of cookies, identifiers or similar tracking technologies requiring consent, Google Analytics is only activated after you have provided your consent.
The legal basis for such processing is Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future through the cookie or privacy settings provided on our website.
Google may process information on servers located outside the country in which the user is located. Where required, recognised legal mechanisms are used for international data transfers.
The retention period for information processed through Google Analytics depends on the configuration used for our Google Analytics account and the relevant settings.
Our website may use cookies and similar technologies.
Cookies are small data files which may be stored on a user’s device when visiting a website.
Some cookies may be technically necessary to provide and secure the website. Other cookies or similar technologies may be used for analytics or other optional purposes.
Where cookies or similar technologies are not strictly necessary and require consent under applicable law, they will only be used after you have provided your consent.
You may withdraw or modify your consent at any time through the cookie settings available on our website.
We do not sell personal data to third parties.
Personal data may, however, be disclosed to service providers where this is necessary for the operation of our website or provision of our services. These service providers may include, in particular:
Service providers receive personal data only where necessary for the relevant service and subject to applicable data protection requirements.
Personal data may also be disclosed where we are legally required to do so.
We aim to process personal data within the European Economic Area where reasonably possible.
However, some of the service providers we use may process personal data in countries outside the European Economic Area. In particular, international transfers may occur when services such as Calendly or Google services are used.
Where personal data is transferred outside the EEA, we take appropriate measures to ensure that such transfers comply with Articles 44 to 49 GDPR.
Depending on the destination country and service provider, these safeguards may include:
International transfers by our service providers are subject to the safeguards applicable to the respective provider and processing activity.
We retain personal data only for as long as necessary for the purposes for which it was collected.
Once the relevant purpose no longer applies, personal data will normally be deleted unless we are required or permitted to retain the information for a longer period due to:
Personal data provided through contact enquiries will generally be deleted once the enquiry has been fully dealt with, unless continued retention is necessary.
Retention periods relating to third-party services may additionally depend on the settings and retention policies applicable to those services.
Depending on the specific processing activity, we rely on the following legal bases under the GDPR:
Article 6(1)(a) GDPR – ConsentWhere you have voluntarily consented to the processing of your personal data.
Article 6(1)(b) GDPR – Contractual NecessityWhere processing is necessary to enter into or perform a contract with you.
Article 6(1)(c) GDPR – Legal ObligationWhere processing is necessary to comply with a legal obligation.
Article 6(1)(f) GDPR – Legitimate InterestsWhere processing is necessary for our legitimate interests or those of a third party and your fundamental rights and interests do not override those interests.
Under the GDPR, you have various rights regarding your personal data. Depending on the circumstances, these include:
To exercise any of your data protection rights, please contact: glowupmalta@gmail.com
We may need to request additional information to confirm your identity before responding to a request.
If you believe that the processing of your personal data infringes applicable data protection legislation, you have the right to lodge a complaint with the competent supervisory authority.
For organisations established in Malta, the relevant national supervisory authority is:
Office of the Information and Data Protection Commissioner (IDPC) Floor 2, Airways House Triq Il-Kbira Tas-Sliema SLM 1549 Malta
The IDPC is Malta’s national supervisory authority responsible for monitoring and enforcing the GDPR and the Maltese Data Protection Act.
Based on the services currently used on this website, we do not carry out solely automated decision-making, including profiling, which produces legal effects concerning users or similarly significantly affects them within the meaning of Article 22 GDPR.
We use appropriate technical and organisational measures to protect personal data against:
Our security measures are reviewed and adapted where appropriate to reflect technical developments and the nature of the personal data being processed.
We may update this Privacy Policy from time to time, for example where our website, services, processing activities or applicable legal requirements change.
The most recent version of this Privacy Policy will be made available on our website.