Privacy Policy

Last updated on 20th March 2025

Introduction

Welcome to the Malta National Aquarium’s Privacy Policy. Your privacy is important to us, and we are committed to protecting your personal data in compliance with the EU General Data Protection Regulation (GDPR), the ePrivacy Directive (2002/58/EC) as implemented in Maltese law, and Malta’s Data Protection Act (Chapter 586 of the Laws of Malta). This policy explains how we collect, use, share, and protect your information when you use our website (https://www.aquarium.com.mt) or related services. It also describes your rights regarding your personal data and how you can exercise them. By using our site or services, you acknowledge that you have read and understood this Privacy Policy.

Who We Are (Data Controller)

The Malta National Aquarium website and services are operated by Marine Aquatic Limited, a company registered in Malta (Reg. No. C52988). Marine Aquatic Limited’s registered address is Malta National Aquarium, Triq it-Trunciera, Qawra, St. Paul’s Bay, SPB 1500, Malta. In this policy, “we”, “us”, or “our” refer to Marine Aquatic Limited. We are the “data controller” responsible for deciding how and why your personal data is processed via our site. If you have any questions about this policy or wish to exercise your rights, please contact us at [email protected] or by mail at the address above. We may also be contacted by phone at +356 2258 8100 (during normal office hours).

Personal Data We Collect

We collect various categories of personal data from you when you interact with our website or use our services. This includes:

  • Contact Details: Information that identifies you, such as your name, surname, postal address, telephone/mobile number, and email address. For example, if you fill out our contact form or purchase tickets, you may provide your name and contact information.
  • Account and Registration Data: If you register an account on our site or sign up for a membership/loyalty program, we may collect data like a username and password, date of birth, country of residence, and gender.
  • Transaction and Payment Data: If you purchase tickets or merchandise online, we (or our payment processor) collect data needed to process the transaction. This may include your order details and payment information. For instance, we collect your name, surname, and email for billing, and payment details such as your credit/debit card information, which is handled securely via Stripe (our payment provider). Note: Your card details are transmitted directly to Stripe; we do not store full card numbers on our servers for security.
  • Marketing and Communications Data: Your preferences for receiving marketing from us and related information. This includes records of your consent for newsletters or promotions, your communication preferences, and whether you have opted out of marketing. We also keep track of any consent you have given (or withdrawn) for specific data processing activities (e.g. proof that you opted in to our newsletter).
  • Usage and Technical Data: When you visit our website, we automatically collect certain data about your device and how you use the site. This includes your IP address, browser type, device identifiers, pages viewed, dates/times of visits, and referring website. We collect some of this information using cookies and similar tracking technologies (explained in the Cookies section below). This “Tracking Data” helps us understand how visitors navigate our site and improve our services.
  • Social Media Data: If you interact with us via social media or link your social media accounts to our site (for example, by using a “social login” feature or sharing content), we may receive certain information from that social media platform (such as your profile name and any info you have permitted the platform to share with us). This will only happen according to the privacy settings of your social media account and if you choose to engage with such features.

We do not knowingly collect data from children under 18 years of age. Our site and services are intended for adults. If you are under 18, please use our services only with the involvement of a parent or guardian. If we discover we have collected personal data from a minor without appropriate consent, we will delete it.

How We Collect Your Data

Most of the personal data we collect is provided directly by you. For example, you provide your contact and payment details when purchasing tickets or filling in forms, and you provide your email when signing up for our newsletter. We may also collect some data automatically (e.g. through cookies when you browse our site) or, in some cases, from third parties. For instance, we might receive address verification from a postal service or fraud-detection information from a payment processor. If we obtain personal data about you from third-party sources, we will process it in accordance with this Privacy Policy and applicable laws, and we will inform you of the source of the data if required by law.

Purpose and Legal Bases for Processing

We only use your personal data when we have a valid legal reason (lawful basis) under the GDPR to do so. Under the GDPR, we rely on one or more of the following legal bases when processing your data:

  • To Perform a Contract: We process personal data as necessary to provide you with services that you request, such as purchasing tickets online, booking an event, or registering an account. This includes processing payments through Stripe, emailing order confirmations, and providing customer support. We cannot provide these services without processing your data, so this use is based on “contractual necessity.” If you refuse to provide necessary information (like payment details or contact info), we may not be able to fulfill your purchase or request.
  • With Your Consent: We will ask for your consent before using your data for certain purposes, when required. For example, we rely on your consent to send you promotional emails (newsletters or special offers) or to place non-essential cookies (analytics or advertising cookies) on your device. Where we rely on consent, you have the right to withdraw it at any time (see “Your Rights” below). Withdrawing consent will not affect the lawfulness of any processing we already carried out, but it will stop that specific processing going forward.
  • Legitimate Interests: In some cases, we process your data to pursue our legitimate interests in a way that does not override your rights and freedoms. For instance, it is in our interest to understand how our website is used so we can improve its layout and content – we may use aggregated analytics data for this (with your consent for cookies, as required). We may also process data to prevent fraud and secure our website, or to communicate with you about our services. Whenever we rely on this basis, we carefully consider and balance our interests against your privacy rights. Example: We may use your past purchase history to personalize content on our site or recommend attractions that might interest you, but you have the right to object to such profiling (see “Your Rights”).
  • Legal Obligation: We will process personal data if needed to comply with a legal or regulatory obligation. For example, under Maltese law we must retain certain transaction records for accounting/tax purposes for a set period (such as keeping invoice information for 10 years). We may also need to disclose data to authorities if required by law or to comply with lawful requests (such as court orders or law enforcement inquiries).
  • Vital Interests/Public Interest: In rare cases, we might process personal data to protect someone’s life or for a task in the public interest. These bases are unlikely to apply in the context of a public aquarium website, but if they do, we will only process the minimum data necessary and in accordance with the law.

We will always clearly indicate the purpose for which we are collecting your data at the time of collection. If we intend to use your data for a new purpose that is incompatible with the original reasons, we will seek your consent or inform you of the legal basis for that new use.

How We Use Your Data (Summary of Purposes)

In practical terms, we use the personal data we collect for the following purposes:

  • Providing and Managing Services: To process your ticket purchases, reservations, or membership applications; to manage your user account; and to deliver any products or services you request. For example, we use your contact and payment details to complete transactions and provide access to the aquarium or related events.
  • Communications: To communicate with you about your orders, respond to inquiries or support requests, and send service-related announcements. These communications are not promotional in nature; they are necessary for customer service or administrative purposes (e.g. sending you an e-ticket or notifying you of changes to our terms). You cannot opt out of receiving essential service communications, as they are part of the services you request.
  • Marketing and Newsletters: With your permission, we use your email or other contact details to send you newsletters, promotions, or updates about the Aquarium, such as upcoming events or special offers. We will only send you marketing communications if you have opted in to receive them, or if you are an existing customer and we have a lawful basis to contact you under applicable law. You can always opt out of marketing (see “Marketing Communications and Opt-Out” below).
  • Analytics and Improvement: To analyze website traffic and usage patterns in order to improve our site’s functionality, content, and user experience. We use tools like Google Analytics to collect information about how visitors interact with our site (pages visited, time spent, etc.). These analytics help us understand what content is popular or where users encounter issues, so we can enhance our offerings. Wherever possible, we use this information in an aggregated form that does not directly identify you. Non-essential analytics tools (like Google Analytics) are only activated if you have given consent via our cookie consent banner.
  • Advertising and Social Media Features: If you consent, we use tracking technologies (like the Meta Pixel by Facebook/Meta) to help us with advertising and social media outreach. The Meta Pixel allows us to show you relevant ads on Facebook/Instagram or measure the effectiveness of our ads by understanding what actions you took on our website. For example, if you consent to marketing cookies, the Meta Pixel may track that you visited our ticket page, which enables us to later show you an Aquarium promotion on Facebook. This involves sharing certain technical data (like your IP, device ID, or page visited) with Meta Platforms. Similarly, if our site uses social media plug-ins (such as a Facebook “Like” button), those may set cookies to facilitate social sharing. All such marketing/tracking activities are only done with your consent, and you can disable these cookies at any time (see “Cookies and Tracking Technologies”).
  • Fraud Prevention and Security: To keep our website, visitors, and business secure. We monitor and may process personal data (like IP addresses or order information) to detect and prevent fraudulent transactions, hacking attempts, or other malicious activities. This helps protect both you and us. Our legitimate interest in protecting our business and users is the legal basis for this type of processing.
  • Compliance and Legal Claims: To fulfill our legal obligations (for example, maintaining transaction records for financial audits or tax compliance) and to establish, exercise, or defend legal claims. If we are involved in any dispute or legal process, we may process and preserve relevant personal data as needed for those proceedings. We may also disclose information if required by law or authoritative order (see “Data Sharing and Third Parties” below for details on authorized disclosures).

If we need to process your personal data for any purpose that is not outlined in this policy, we will inform you and, if necessary, obtain your consent or ensure another valid legal basis applies.

Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to provide functionality and to enhance your user experience. Cookies are small text files placed on your device that can remember your preferences and track your activity on our site. We categorize cookies as follows:

  • Essential Cookies: These are cookies that are strictly necessary for the website to function or to provide a service you requested. For example, cookies that keep you logged in during your session, remember items in your shopping cart, or facilitate secure payment processing are essential. We do not need your consent to use essential cookies. Without them, certain features of the site (like ticket purchasing or login) may not work properly.
  • Non-Essential Cookies: These cookies are not strictly required for the core functionality of the site, but they help us improve your experience and our services. We only use non-essential cookies with your consent, in line with the ePrivacy Directive’s requirements. Non-essential cookies on our site may include:
    • Preferences Cookies: These remember your choices and preferences (such as language or text size) to provide a more personalized experience. For instance, a preferences cookie may save you from re-entering your location each time you visit the site.
    • Analytics/Statistics Cookies: These help us collect information about how visitors use our site, such as which pages are visited most often, whether visitors are new or returning, and how they found our site (via search engine, link, etc.). We use this data to compile reports and improve the site. We currently use Google Analytics, which sets cookies like _ga and _gid to generate anonymous statistics. The information generated by these cookies (including your IP address, which Google may anonymize) will be transmitted to and stored by Google on servers that may be outside the EU. We have configured Google Analytics in compliance with data protection guidelines and Google will only use this information on our behalf to analyze your site use and provide us with aggregated reports. These cookies are only placed if you consent via the cookie banner.
    • Marketing/Advertising Cookies: These cookies track your browsing habits to tailor marketing content and advertisements to your interests. On our site, marketing cookies include those set by third parties like Meta (Facebook) Pixel. With your consent, the Meta Pixel is activated to collect data about your actions on our site (e.g. visiting certain pages or completing a purchase). This allows us to re-market to you on platforms like Facebook or Instagram, showing ads we think may interest you. It also helps us measure the effectiveness of our ads and content. The data collected (such as page URLs, your user ID if you are logged into Facebook, or other online identifiers) may be combined with your profile by Meta and used according to Meta’s privacy policies. We do not receive personal data like your Facebook credentials; we only receive aggregated ad performance reports. Marketing cookies will only be set if you explicitly allow the “Marketing” category in our cookie consent pop-up.

Cookie Consent: When you first visit our website, you will see a cookie consent banner or pop-up. We will not set any non-essential cookies (preferences, analytics, marketing) unless you choose to allow them. You can manage your cookie preferences at any time by using our cookie settings tool (available via the banner or a link like “Cookie Settings” on our site) to withdraw or change your consent. You also have the option to disable cookies entirely through your browser settings. Most web browsers allow you to block or delete cookies – see your browser’s help section for instructions or visit the All About Cookies website for guidance. Please note that if you disable all cookies (including essential ones) via your browser, some features of our site may not function properly.

For more detailed information on the cookies we use, their purpose, and how to manage them, please see our Cookie Policy (available on our website). Our Cookie Policy is incorporated into this Privacy Policy by reference. It explains in an easy-to-read format what cookies are and the difference between essential and non-essential cookies.

Data Sharing and Third-Party Recipients

We treat your personal data with care and confidentiality. We do not sell your personal information to third parties. However, we do share your data with certain trusted third parties in order to run our operations, provide our services, and comply with legal requirements. We only share the minimum information necessary for the relevant purpose, and any third party that processes data on our behalf must adhere to strict data protection obligations.

Categories of third-party recipients include:

  • Service Providers and Processors: We use external companies to help us operate the website and provide our services. These include:
    • Website Hosting and IT Providers: Companies that host our website or provide technical infrastructure, development, and support. They may process personal data (e.g., in stored databases or backups) only to ensure our site runs smoothly and securely. For example, our web administrators and IT maintenance contractors have access to data as needed to perform their tasks.
    • Payment Processors: We partner with Stripe to handle online payments securely. When you make a purchase, your payment details (like card number, expiration date, CVV) are transmitted directly to Stripe. Stripe processes your payment on our behalf and is contractually obligated to protect your data and use it only for payment processing and fraud prevention. We share with Stripe the information required to charge your card and verify the transaction (such as the purchase amount, your name, billing address, and email). Stripe may also run anti-fraud checks and is PCI-DSS compliant (a strict security standard for payments). Stripe is a data processor for us, and in some cases a separate controller for certain data it collects to comply with its own legal obligations (e.g., financial regulations). You can refer to Stripe’s Privacy Policy for more details on how they handle your data.
    • Analytics and Advertising Partners: As noted, we use Google Analytics for site analytics and the Meta Pixel for advertising. These partners receive certain data via cookies or similar technologies on our site. Google and Meta process data as independent controllers for their own purposes as well (e.g., improving their services or, in Meta’s case, targeted advertising beyond our ads). We have agreements in place (such as Google’s data processing terms) to ensure compliance with EU data protection standards. Google Analytics data is shared with Google LLC, and Meta Pixel data is shared with Meta Platforms, Inc. (Facebook). These companies may process the data on servers outside the EU (see “International Data Transfers” below for how we safeguard such transfers).
    • Email and Marketing Service Providers: If we use a third-party platform to send out our newsletters or marketing emails (for example, a service like MailChimp or similar), we will share your name and email address with that provider to distribute the communications you signed up for. Such providers act under our instructions and cannot use your email for their own purposes.
    • Ticketing and Reservation Systems: In some cases, we might use third-party systems for ticket bookings or event reservations. If so, the information you provide (like name, contact, and booking details) will be processed by that system provider on our behalf. They are bound by contract to protect your data.
  • Business Partners: We may share data with affiliated organizations or partners as needed to provide a service you requested. For example, if you purchase a combined ticket for the Aquarium and another attraction offered in partnership, we would share the relevant details with that partner to honor the ticket. We will inform you at the time of data collection if a partner is involved in processing your data. All our partners are also required to comply with data protection laws. We do not share your data with third parties for their own marketing purposes unless you have explicitly consented to such sharing.
  • Legal and Regulatory: We might disclose personal information to third parties if required by law or legal process, or to protect our rights or the rights of others. This includes situations such as:
    • Complying with a subpoena, court order, or other legal obligation.
    • Sharing information with law enforcement or government authorities when we believe in good faith that such disclosure is necessary to meet national security or law enforcement requirements, or to report suspected illegal activity.
    • Disclosing data to enforce our terms and conditions, or to protect the safety, rights, or property of our customers, the public, or Marine Aquatic Limited (for example, providing information to fraud prevention agencies or to credit card companies to handle chargebacks).
    • In connection with potential business transactions: if Marine Aquatic Limited ever considers a merger, acquisition, restructuring, or transfer of assets, personal data may be shared with involved parties (e.g., auditors, advisers) as part of due diligence, under strict confidentiality, and only if necessary for the transaction. If a change in ownership actually occurs, we will ensure your data remains protected and inform you of any significant changes to how your data is used.

All third parties processing personal data on our behalf (our “data processors”) are subject to contractual agreements under Article 28 of the GDPR to ensure they only process data for our specified purposes and with adequate security. We require these parties to implement appropriate technical and organizational measures to safeguard personal data, and they are not permitted to use your data for any unrelated purposes. We remain responsible for the protection of your data when it is processed by such partners.

Importantly, we will never share or sell your personal data to third parties for their own marketing purposes unless you have given us your explicit consent to do so. For example, we won’t hand over your email list to another company so they can market to you, unless you specifically agree to that.

International Data Transfers

The personal data we collect is primarily stored and processed within the European Union (EU)/European Economic Area (EEA). However, some of our third-party service providers are based outside the EEA, or may store data on servers outside the EEA (for example, in the United States). Whenever we transfer your data to a country that is not deemed to provide an adequate level of data protection by the European Commission, we take steps to ensure your data remains protected.

For transfers outside the EEA, we implement appropriate safeguards in accordance with GDPR Chapter V. These may include:

  • EU Commission Adequacy Decisions: If the data is transferred to a country that the European Commission has recognized as providing adequate data protection (a “white-listed” country), we rely on that decision. (For example, transfers to countries like Switzerland or Canada might fall under this if deemed adequate.)
  • Standard Contractual Clauses (SCCs): For transfers to the United States or other countries without an adequacy decision, we use the European Commission’s approved Standard Contractual Clauses. These are contractual commitments between us and the recipient, obligating them to protect your data to EU privacy standards. For instance, our contracts with Google, Meta, and Stripe include standard data protection clauses to safeguard any personal data that may be stored or accessed in the U.S. or elsewhere.
  • Additional Technical Measures: In some cases, we may apply encryption or pseudonymization to data before it is transferred overseas, so that the data cannot be easily linked back to you by any unauthorized parties. Services like Google Analytics also offer IP anonymization features, which we utilize to truncate your IP address within the EU before transferring it to Google’s servers (adding an extra layer of privacy).
  • EU–US Data Privacy Framework: We also consider whether our U.S.-based service providers are certified under frameworks like the new EU–US Data Privacy Framework (DPF), which, as of 2023, is intended to facilitate compliant data transfer to participating U.S. companies. For example, Meta Platforms and Google may be certified under the DPF. Participation in such a framework means the company must comply with specific privacy commitments. (Regardless of certification, we still use SCCs or other measures as needed, until we are satisfied your data is adequately protected.)

You are entitled to request more information about the safeguards we have in place for international transfers of your personal data, or a copy of the relevant contractual clauses. To do so, please contact us using the details in the “Who We Are” section. We will not transfer your personal data to third countries unless it is permitted by EU and Maltese data protection laws and we have done what is necessary to ensure the same level of protection for your data as within Malta.

Data Retention – How Long We Keep Your Data

We will retain your personal data only for as long as necessary to fulfill the purposes we collected it for, including for satisfying any legal, accounting, or reporting requirements. In determining how long to keep data, we consider factors such as the nature and sensitivity of the data, the purpose for processing, and the applicable legal requirements that mandate certain retention periods.

In practice:

  • User Account Data: If you create an account or membership with us, we will retain your account information while your account is active and for a reasonable period after if you stop using the account (in case you return, or to comply with any request to delete it). If you ask us to delete your account, we will do so, except for any information we must retain by law or legitimate interests (see below).
  • Transaction Records: Purchase and payment information is kept for the duration needed to complete the transaction and then as required by financial and tax regulations. For example, Maltese tax laws require us to keep records of financial transactions (invoices, receipts, etc.) for 10 years. Even if you request erasure of your data, we may retain invoice information until this 10-year period expires, to comply with legal obligations.
  • Marketing Data: We retain your contact details for marketing purposes until you unsubscribe or withdraw your consent. If you opt out of marketing, we will stop sending you messages, but may retain your contact info on a suppression list (to ensure we honor your no-contact request in the future). We also keep a record of when and how you gave consent for marketing, as proof of compliance, for as long as we send you marketing and a short period after (generally up to 5 years, aligned with statute of limitations for claims, in case of disputes about lawful marketing).
  • Analytics Data: Data collected via Google Analytics or similar tools may be stored in aggregated form indefinitely (as it no longer identifies individuals). Raw analytics data that is potentially identifiable (like full IP addresses) is either not stored at all (due to anonymization) or retained only for a short period and then deleted or anonymized. Google Analytics, for instance, allows us to set a retention period for user-level data; we configure this in line with best practices (typically 14 months, unless you revisit which resets the clock, as per Google’s default settings).
  • General Correspondence: If you contact us (e.g., via email or contact form), we may retain those communications for a period of time to effectively manage our relationship, handle any follow-up, and improve our services. Typically, inquiry data is kept for up to 2 years, unless needed longer (for example, a complaint that resulted in legal action would be kept through the resolution of the case).
  • Legal Hold: If any personal data is needed for legal claims or proceedings, we will retain it for as long as necessary for that purpose. For instance, if we believe a customer might file a lawsuit, or if we are investigating potential fraud, we will preserve relevant data until the issue is resolved, even if this extends beyond normal retention periods. In Malta, the general prescriptive period for legal claims is 5 years, so we may keep certain data up to 5 years from our last interaction with you to protect ourselves against legal disputes.

After the applicable retention period ends, or if the data is no longer needed, we will either securely delete or anonymize your personal data. Anonymization is an irreversible process that strips personal data of identifying elements so that it can no longer be linked to any individual; we may use anonymized data for statistical analysis or business planning without further notice, since it no longer constitutes personal data.

How We Protect Your Data (Security Measures)

We take the security of your personal information seriously and have implemented a variety of measures to prevent unauthorized access, misuse, alteration, or disclosure of your data. These measures include:

  • Technical Safeguards: Our website and databases are secured with industry-standard security technologies. This includes the use of firewalls, encryption of data in transit (e.g., HTTPS secure connections on our website), and encryption of sensitive data at rest where appropriate. For example, when you enter payment information, it is protected by SSL/TLS encryption. We ensure that any stored passwords are salted and hashed. We regularly update and patch our systems to address security vulnerabilities.
  • Organizational & Physical Security: Personal data is stored in secure facilities. We limit access to your personal data to employees and service providers who need to know it for the purposes described in this policy. These persons are subject to confidentiality obligations. Our internal policies and training emphasize the importance of privacy and security. We also maintain physical security measures at our offices and servers to prevent unauthorized access (such as secure entry controls, surveillance in sensitive areas, etc.).
  • Access Controls: We have implemented access control measures such as role-based access – meaning staff and contractors can only access the data necessary for their role. For example, our customer service team may see your contact information to assist you, but they will not have access to your full payment card details. Only authorized personnel with special clearance (e.g., our IT admin or finance team) can access more sensitive data, and even then, direct access to payment card information is restricted since we use a payment processor.
  • Monitoring and Testing: We monitor our systems for potential vulnerabilities and attacks. We use anti-malware protection and intrusion detection systems. Periodically, we conduct security audits and penetration testing to assess the strength of our protections. Any third-party processor handling data on our behalf must also implement adequate security measures and, where applicable, comply with recognized security standards (such as PCI-DSS for payment processors like Stripe).
  • Data Minimization: Wherever possible, we minimize the amount of personal data we collect and store. If we don’t need certain information, we don’t ask for it. If we can delete information that is no longer needed, we do so. By holding less data, we reduce the risk of something sensitive being exposed in the event of a breach.
  • Incident Response: In spite of all precautions, no system can be guaranteed 100% secure. We have a data breach response plan in place. This means if we suspect any personal data has been compromised, we will act quickly to contain the issue, investigate, and mitigate any harm. Where required by law, we will also notify you and relevant authorities (such as the Malta Information and Data Protection Commissioner) of certain data breaches.

While we strive to protect your information, it’s important to understand that no method of transmission over the internet, or method of electronic storage, is completely secure. You can also play a part in protecting your data by using strong passwords, not sharing your account credentials, and logging out after using shared devices. If you have any reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please contact us immediately.

Your Rights Under GDPR

Under European and Maltese data protection laws, you have a number of rights regarding your personal data. We respect these rights and have processes in place to enable you to exercise them. Your principal rights are:

  • Right to Access: You have the right to ask us whether we are processing your personal data, and if so, to request a copy of the data we hold about you. This is often called a “Data Subject Access Request.” We will also provide you with information about how we use your data, who we share it with, how long we keep it, and the safeguards in place if we transfer it abroad. The first copy will be provided free of charge, but we may charge a reasonable fee for additional copies or manifestly unfounded/repetitive requests. We will respond within one month of receiving your request, unless the request is complex (in which case we may extend by an additional two months, but we will inform you of the need for extension).
  • Right to Rectification: If any of your personal data we hold is incorrect or incomplete, you have the right to have it corrected or updated without undue delay. Upon your request, we will rectify inaccurate data and (taking into account the purposes of processing) complete any incomplete data. In some cases, we may need to verify the new information you provide to ensure accuracy before making the change.
  • Right to Erasure (Right to be Forgotten): You have the right to request that we delete your personal data in certain circumstances. This right is not absolute, but we will comply if for example: the data is no longer necessary for the purposes collected; you withdraw consent and we have no other legal basis to continue processing; you object to processing based on legitimate interests and we have no overriding grounds to continue; or we unlawfully processed your data. If we have made your data public (e.g., posted a testimonial you provided) and you request erasure, we will take reasonable steps to inform other controllers processing the data to fulfill your request. Please note: We might not delete data if an exemption applies – for instance, we cannot erase data that we must keep to comply with a legal obligation or to establish or defend legal claims. If you request deletion, we will inform you if any such exemptions apply.
  • Right to Restrict Processing: You have the right to ask us to limit the processing of your data (essentially to keep but not use it) in certain situations. This can apply if: you contest the accuracy of the data (for a period enabling us to verify it); the processing is unlawful but you prefer restriction over deletion; we no longer need the data but you need it for a legal claim; or you have objected to processing and verification of our legitimate grounds is pending. When processing is restricted, we will store your data securely and not actively process it, except to: with your consent, or as needed for legal claims, to protect others’ rights, or for important public interests. We will inform you before lifting a restriction.
  • Right to Data Portability: For data that you provided to us and which we process by automated means on the basis of your consent or to perform a contract, you have the right to request a copy in a structured, commonly used, machine-readable format (for example, CSV or JSON). You also have the right to ask that we transmit this data directly to another data controller (for example, another service provider), where technically feasible. This right facilitates moving your business or switching providers. Note that it applies only to data you provided, not data we generated, and only when processing is based on consent or contract.
  • Right to Withdraw Consent: If we are processing your personal data based on your consent, you have the right to withdraw that consent at any time. For example, you may withdraw your consent to receive our newsletter, or to cookies by adjusting your preferences. Withdrawing consent will not affect the lawfulness of processing that happened before your withdrawal. If you withdraw consent for a particular purpose, we will stop the processing for that purpose and, if there’s no other lawful basis that applies, we will delete your data (subject to any legal retention requirements). We make it as easy to withdraw consent as it was to give it – for instance, you can unsubscribe from marketing emails by clicking the “unsubscribe” link in any email, or toggle off certain cookie categories in our preference center.
  • Right to Object: You have the right to object to our processing of your personal data in certain circumstances. (1) If we are processing your data based on legitimate interests (or performing a task in the public interest), you can object on grounds relating to your particular situation. If you do so, we will stop processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless we need to continue processing for the establishment, exercise, or defense of legal claims. (2) Additionally, you have an absolute right to object to direct marketing at any time. This includes profiling to the extent it is related to direct marketing. If you object to marketing, we will stop using your data for that purpose immediately with no exceptions. For example, if you tell us you no longer wish to receive promotional emails or calls, we will remove you from our marketing lists.
  • Right Not to Be Subject to Automated Decisions: We do not make any fully automated decisions (with no human involvement) that produce legal or similarly significant effects on individuals using personal data. Should we in the future use automated decision-making or profiling in a way that significantly affects you, we will ensure we comply with GDPR Article 22, including informing you and providing an option to request human intervention or to contest the decision. (For instance, if we ever implemented automated risk scoring for transactions, you would have the right to know and object.)
  • Right to Lodge a Complaint: If you believe your data protection rights have been violated, you have the right to file a complaint with a supervisory authority. In Malta, the supervisory authority is the Office of the Information and Data Protection Commissioner (IDPC). You can find details on how to contact the IDPC on their official website. The IDPC’s office can be reached at Floor 2, Airways House, High Street, Sliema SLM1549, Malta, or via email ( [email protected]) and phone (+356 2328 7100). We encourage you to contact us first to try resolving any issue directly, but you are free to contact the IDPC at any time.

Exercising Your Rights: You can exercise any of your rights by contacting us via email at [email protected] or by mail/phone using the contact details provided in the “Who We Are” section. Please clearly state what right you wish to exercise and provide us with enough information to identify you (we may need to verify your identity for security reasons before fulfilling your request). This is to ensure that we do not disclose data to someone who is not entitled to receive it. For example, we might ask you to confirm some details we already have on file, or require a copy of a legitimate identification document, before releasing data in an access request.

We will respond to your request as soon as possible and no later than one month from receipt of a valid request. If your request is particularly complex or if you have made multiple requests, we may extend this period by up to two further months, but we will inform you of any extension within the first month and explain the reasons. In general, we will not charge a fee for handling your rights requests. However, if a request is manifestly unfounded or excessive (for example, repetitive), we may either charge a reasonable fee or refuse to act on the request (providing justification in that case).

Marketing Communications and Opt-Out

We want to ensure you are in control of how you hear from us. If you subscribe to our newsletter or consent to receive promotional communications, we may send you information about aquarium news, upcoming events, special offers, or related services. These communications will be sent via the channels you consented to (e.g., email or SMS).

Consent for Marketing: We rely on your consent (opt-in) to send marketing emails or texts, unless you are an existing customer who purchased a similar service from us and we are allowed by law to send you marketing under a “soft opt-in” exception. In all cases, we will honor your marketing preferences. If you opt in, you have the choice at any time to opt out again.

How to Opt Out: If you no longer want to receive marketing emails from us, you can opt out easily. Every marketing email we send includes an “unsubscribe” link at the bottom. Simply click that link, and you will be able to stop further emails. You can also opt out or change your preferences by contacting us at [email protected] and letting us know which communications you want to stop. If we send SMS messages, you can reply with an opt-out keyword (e.g., “STOP”) as instructed in the message, or contact us to remove your number.

Once you opt out of a particular type of marketing, we will cease using your data for that purpose and will update our records immediately, or in any event within a few days at most (to allow for email processing times). Please note that opting out of marketing communications does not affect service communications. You will still receive transactional messages (as noted earlier) such as confirmations, important notices, or responses to customer service queries, as those are not marketing. If you have multiple distinct interactions with us (e.g., you signed up with multiple email addresses), you will need to opt out of each if you wish to stop all marketing.

We do not share your personal data with other companies for their own independent marketing without your consent. If you ever do consent to such third-party marketing (for example, if you agree to receive info from a partner organization during a promo event), you can opt out later by contacting that third party directly, as they would be responsible for those communications. We will assist you if possible by directing your request appropriately.

For online advertising (e.g., the Meta Pixel-based ads or Google remarketing), you can control these through the cookie settings as described in the Cookies section. Not consenting or withdrawing consent for marketing cookies will stop us from tracking for targeted ads on our site. Additionally, platforms like Facebook and Google allow you to adjust ad preferences within your user account (for example, you can use Facebook’s ad settings to hide certain ads or opt out of interest-based ads from specific advertisers).

Links to Other Websites

Our website may contain links to third-party websites or social media platforms, such as Facebook, Instagram, or ticketing partners. If you follow these links, please be aware that those external sites are not governed by this Privacy Policy. We have no control over, and take no responsibility for, the content or privacy practices of third-party sites. We encourage you to read the privacy policies of every website you visit, especially if you provide personal information to them. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about external links (for example, if a link is broken or the third-party site appears suspicious).

Updates to This Privacy Policy

We may update or revise this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. If we make significant changes, we will notify you by appropriate means – for example, by posting a prominent notice on our website or, if the changes materially affect your rights or the way we use your data, by emailing you (if we have your email).

We archive former versions of this Privacy Policy and indicate the effective date of each version for your reference. We encourage you to review this page periodically to stay informed about how we are protecting your information. Your continued use of our website after any changes to this Privacy Policy constitute acceptance of those changes, to the extent permitted by law.

This policy was last updated on [Insert Date] and is effective as of that date. (Last updated date is also noted at the top of this policy for clarity.)

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please do not hesitate to contact us:

Marine Aquatic Limited (Malta National Aquarium)
Address: Malta National Aquarium, Triq it-Trunciera, Qawra, St Paul’s Bay, SPB 1500, Malta
Email: [email protected]
Telephone: (+356) 2258 8100 (Monday–Friday, business hours)

We will be grateful for the opportunity to address your questions and resolve any issues directly. Your privacy is our priority, and we welcome feedback on how we can improve our policies and practices to better protect your information.