Privacy Policy

Last Updated : 05/08/2026
​
1. Introduction and Scope
This Privacy Policy applies to the website and all services operated by Synerf (referred to as "I," "Me," or "My"). I am committed to protecting your privacy and personal data. I process your data in compliance with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the Maltese Data Protection Act (Cap. 586). For the purposes of this Policy, I am the Data Controller of the personal data collected through this Website.
2. Data I Collect and How I Use It
I collect and use personal data for specific purposes, based on your interaction with the website:
A. Website Visit Data (Cookies and Analytics)
-
Data Collected: When you visit the website, I automatically collect Technical Data (such as your Internet Protocol (IP) address, browser type, operating system) and Usage Data (information about how you use my website, pages viewed, and visit duration).
-
Purpose of Processing: This data is used solely to understand how visitors use the site, improve the website's performance, and enhance the overall user experience.
-
Legal Basis: This processing is based on my legitimate interest in monitoring and improving the website. For non-essential analytics cookies, the legal basis is your explicit consent, managed via the cookie banner.
B. Query Form Data (Contact & Marketing)
-
Data Collected: When you use the query form, I collect your Identity Data (Name) and Contact Data (Email Address).
-
Purpose of Processing:
-
To respond to your specific inquiry or question.
-
To use your Name and Email Address for marketing purposes, including sending you newsletters, updates, and service information.
-
-
Legal Basis: I process your name, email address and enquiry because it is necessary to respond to your request and, where applicable, to take steps at your request before entering into a contract. I may also process correspondence on the basis of my legitimate interest in maintaining appropriate business records and responding to enquiries. I will use your information for newsletters or other promotional communications only where there is an appropriate lawful basis and, where consent is required, you have voluntarily provided separate marketing consent. Marketing consent is not a condition of submitting an enquiry, and you may withdraw it or unsubscribe at any time.
-
Retention: Query data will be retained for as long as necessary to address your query and for subsequent marketing communications until you exercise your right to erasure or objection.
​
C. Masterclass and Workshop Booking Data
When you book or pay for a masterclass, workshop, seminar or other event organised by Synerf, I collect and process personal data necessary to administer your booking and attendance.
Data Collected: This may include your name, email address, telephone number, organisation or professional information where requested, the event booked, the amount paid, payment status, transaction reference, correspondence relating to your booking, and your attendance or check-in status.
I may also collect accessibility, dietary or other requirements that you voluntarily provide where these are necessary to make appropriate arrangements for your participation. Please provide only information that is relevant and necessary for this purpose.
Purpose of Processing: I use this information to:
-
process and administer your booking;
-
confirm your registration and payment;
-
communicate essential information about the event, including changes to the date, time, venue or programme;
-
manage event capacity, attendance and check-in;
-
respond to enquiries, cancellation requests, refund requests or payment disputes;
-
make reasonable accessibility or dietary arrangements where requested;
-
maintain financial, tax and accounting records; and
-
establish, exercise or defend legal claims where necessary.
Legal Basis: Booking information is processed because it is necessary to take steps at your request before entering into a contract and to perform the contract relating to your booking.
​
Certain information may also be processed to comply with my legal obligations, including applicable tax, accounting and record-keeping requirements. Where necessary, I may process information on the basis of my legitimate interests in administering the event, maintaining security, preventing fraud and handling disputes, provided that those interests do not override your rights and freedoms.
Where you voluntarily provide health, disability, allergy or other special-category information, I will process it only to the extent necessary to accommodate your requirements and where an appropriate legal basis and condition under data-protection law applies.
Payment Processing: Online payments are processed securely by Stripe. When you proceed to Stripe’s checkout, Stripe may collect your name, contact information, billing information, payment-method details, transaction information, device information and fraud-prevention information.
Your complete payment-card number and card security code are submitted directly to Stripe. I do not receive or store your complete card number or card security code.
Stripe may process personal data as a data processor acting on my instructions and, for certain payment, fraud-prevention and regulatory activities, as an independent data controller. Stripe’s handling of your information is also governed by Stripe’s own privacy documentation, which is available through the Stripe checkout page.
Required Information: Your name, email address and the payment information requested by Stripe are necessary to complete and administer your booking. If you do not provide the required information, I may be unable to accept the booking or provide admission to the event.
Event Communications: I may use your contact details to send communications that are necessary for the administration of the event. These may include payment confirmation, joining instructions, venue information, reminders, programme changes, cancellation notices and post-event administrative communications.
​
These operational communications are part of the booking service and are not marketing communications.
Marketing: Booking an event does not automatically subscribe you to newsletters or promotional communications. I will use your booking information to promote future events or services only where there is an appropriate lawful basis and, where required, you have provided separate consent.
Where consent is requested, it will be optional and will not be a condition of completing the booking. You may withdraw your consent or unsubscribe from marketing communications at any time.
Retention: Operational attendee and check-in lists will normally be retained only for the period reasonably necessary to administer and conclude the event.
Booking, payment, refund, invoice and accounting records may be retained for a longer period where this is required by Maltese tax, accounting or other legal obligations. Relevant information may also be retained for as long as necessary to manage a complaint, payment dispute or legal claim.
Information concerning accessibility, dietary or similar requirements will be deleted when it is no longer necessary for the event, unless there is a legal reason to retain it.
​​​
3. How and Why I Share Your Data
I may share your data only with trusted third parties necessary for running the business, and I ensure they are compliant with GDPR:
-
Service Providers: I use trusted third-party providers for services including website hosting, website administration, analytics, email communications, cloud storage, event administration and payment processing. These providers may include Wix, Google and Stripe. Depending on the service and processing activity, a provider may act as a Data Processor acting on my instructions or as an independent Data Controller with its own legal and regulatory obligations.
-
Legal Compliance: I will disclose your data if required to do so by Maltese or EU law, or in response to a court order or other legal process.
International Transfers
I aim to store and process personal data within Malta or the European Economic Area where reasonably possible. Some service providers may, however, process or permit access to personal data from countries outside the European Economic Area.
Where a transfer is subject to the GDPR’s international-transfer requirements, I will rely on an appropriate legal mechanism, such as an adequacy decision issued by the European Commission, approved Standard Contractual Clauses, or another safeguard recognised under applicable data-protection law.
4. Data Security and Retention
-
Data Security: I have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way.
-
Data Retention: I retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including the purposes described in Section 2. Different retention periods may apply depending on whether the information concerns a website enquiry, marketing communication, client service, event booking, payment, accounting record, complaint or legal claim. Where Maltese financial, tax, commercial or other laws require information to be retained for a specified period, I will retain it for that period.
5. Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data. You can exercise these rights at any time by contacting me directly (see Section 6):
-
Right to Access: You can request a copy of the personal data I hold about you.
-
Right to Rectification: You can ask me to correct any inaccurate or incomplete data.
-
Right to Erasure ('Right to be Forgotten'): You can request the deletion of your personal data where there is no good reason for me to continue processing it, particularly if you withdraw your consent.
-
Right to Restrict Processing: You can ask me to temporarily stop processing your personal data in certain scenarios.
-
Right to Data Portability: You can request that I transfer your personal data to another party.
-
Right to Object: You can object to the processing of your personal data, especially for marketing purposes (you can simply click the 'unsubscribe' link in any email).
-
Right to Withdraw Consent: Where I rely on your consent to process your data, you have the right to withdraw that consent at any time.
6. Contact Information and Complaints
-
Data Protection Contact Person:
-
Name: Karl Cini
-
Email: karl@synerf.com
-
Address: 2A, Hill Valley, Triq il-Gardell, Kappara, San Gwann.
-
-
Supervisory Authority: If you have a complaint about how I handle your data, you have the right to lodge a complaint with the relevant supervisory authority in Malta: The Information and Data Protection Commissioner (IDPC).