- Home
- Platform Privacy Policy
Platform Privacy Policy
Last updated: August 2026 · v1.0
This Platform Privacy Policy explains how the Bookify Malta platform (“Bookify Malta”, “we”, “us”) collects, uses and protects personal data when you use Bookify Malta as a business owner or staff member. We are committed to protecting your privacy in line with the EU General Data Protection Regulation (GDPR) and the Maltese Data Protection Act (Chapter 586 of the Laws of Malta).
This policy covers the platform itself. The data you submit through our marketing site forms is covered by our Privacy Policy.
1. Who we are
Bookify Malta is operated by Christian Azzopardi, trading as Bookify Malta (VAT MT30087118, Gcoe, Triq il-Mithna, Qala, Gozo, Malta), a Malta-based service founded in 2024. Your data is hosted in the EU. Questions about this policy can be sent to legal@bookify.mt.
2. Our role and yours
Data protection roles depend on the data in question:
- Your account and business data: we act as the controller. This includes your name, email, business name and profile.
- Your clients’ data: when you record client names, phone numbers or booking history in Bookify Malta, you act as the data controller and we act as your processor. Our Data Processing Agreement governs that relationship.
3. Data we collect
- Account data: name, email address, password (stored securely hashed), and staff accounts you create.
- Business data: business name, services, categories, opening hours, settings and preferences.
- Client data you record: client names, phone numbers and booking history, entered by you or by your clients through self-booking.
- Usage data: bookings, logs of activity within the platform, and billing records for invoices we issue.
4. How we use your data
- To operate, maintain and improve the platform;
- To authenticate you and manage staff access;
- To send SMS reminders to your clients (where you enable this feature);
- To invoice you and manage your subscription;
- To provide support and communicate with you about your account;
- To meet our legal and security obligations.
5. Legal basis for processing (GDPR Article 6)
We rely on the following lawful bases:
| Activity | Lawful basis |
|---|---|
| Creating and operating your account; processing bookings and subscription payments | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional communications (invoices, password resets, account notifications) | Performance of a contract (Art. 6(1)(b)) |
| Security monitoring, fraud detection, and product improvement | Legitimate interests (Art. 6(1)(f)) |
| Retaining invoicing and accounting records | Legal obligation (Art. 6(1)(c)) — Maltese tax and accounting law |
Where we process client data as your processor, the legal basis is yours: you must have a valid lawful basis for processing the client’s telephone number and sending each message. Strictly transactional appointment reminders (confirmations, reschedule notices and the 24-hour reminder) will normally rely on performance of the booking relationship (Art. 6(1)(b)) or your documented legitimate interests (Art. 6(1)(f)), subject to your assessment. Any promotional or mixed promotional message requires compliance with the applicable direct-marketing consent and opt-out requirements. We do not sell your data or your clients’ data, ever.
6. Where your data goes
Your data is hosted in the EU. To run the platform we rely on a small number of processors, including Google (Firebase for authentication and storage, Cloud Functions for backend logic, and Cloud Tasks for scheduling SMS reminders), Epic Communications Ltd (Epic Malta) for SMS delivery, DigitalOcean, LLC (which hosts the Bookify-operated SMS messaging relay in Frankfurt, Germany), and SiteGround Hosting Ltd for email delivery. A full, current list with the purpose, region, privacy policy and transfer mechanism of each is on our Subprocessor List.
We keep data within the EU/EEA wherever possible. Where a processor operates outside the EU, we rely on appropriate safeguards such as EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), an applicable adequacy decision, or other safeguards permitted under Chapter V GDPR. A copy of the relevant safeguards is available on request from legal@bookify.mt.
7. SMS reminders
SMS reminders are sent to the phone numbers you hold for your clients, 24 hours before an appointment, via Epic Communications Ltd (Epic Malta), a Maltese mobile network operator. Messages pass through a Bookify-operated messaging relay hosted on DigitalOcean in Germany before reaching Epic for final delivery. Bookify Malta acts as your processor for these messages. Strictly transactional reminders (confirmations, reschedule notices and appointment reminders) will normally rely on performance of the booking relationship (Art. 6(1)(b)) or your documented legitimate interests (Art. 6(1)(f)), subject to your assessment, and do not require separate marketing consent. Any promotional or mixed promotional message requires compliance with the applicable direct-marketing consent and opt-out requirements \u2014 do not add promotional content to reminders. Each reminder we send identifies your business.
8. Data retention
We keep data only as long as needed:
| Data category | Retention period |
|---|---|
| Account profile data (name, email, business profile) | While account is active. Deleted within 30 days of account deletion. |
| Salon-client profiles and appointment records | Controlled by the salon and retained until deleted by the salon or until account deletion, subject to backup expiry. |
| Bookify invoices, subscription records and accounting evidence | Retained for the applicable statutory accounting period (currently 7 years under Maltese tax and VAT law), then deleted; pseudonymised after account deletion. |
| Security and rate-limit logs | 7 days |
See our Account Deletion Policy for details of what is deleted and what is kept, and why.
9. Security
We take reasonable technical and organisational measures to protect your data: encrypted transmission over HTTPS, encryption of data at rest, secure authentication via Firebase, access controls on staff accounts, rate limiting on sensitive endpoints, and EU-hosted infrastructure. No method of transmission over the internet is fully secure, however.
10. Data breach notification
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information and Data Protection Commissioner of Malta within 72 hours as required by Article 33 GDPR, and where the risk is high we will notify affected individuals without undue delay (Article 34 GDPR). Where the breach affects your clients’ data processed under our DPA, we will notify you without undue delay so you can meet your own obligations.
11. Children’s privacy
The platform is intended for business use and is not directed at children under 16. We do not knowingly collect personal data from children under 16. If a child’s booking is legitimately recorded (for example, a parent booking their child’s haircut), the parent or guardian provides the information. If you believe a child’s data has been recorded in error, contact us at legal@bookify.mt and we will help you delete it.
12. Automated decision-making
We do not engage in automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR. Auto-accept of bookings and automated reminders are simple, transparent rules you configure yourself and do not constitute automated decision-making under Article 22.
13. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you;
- Have inaccurate data corrected;
- Request erasure of your data;
- Restrict or object to our processing;
- Data portability; and
- Withdraw your consent at any time.
To exercise any of these rights, or if you receive a request from one of your clients about their data, email us at legal@bookify.mt. We respond within 30 days as required by the GDPR. You also have the right to lodge a complaint with the supervisory authority: the Information and Data Protection Commissioner of Malta, Level 2, Airways House, Triq il-Kbira, HMR 1100, Floriana, Malta (idpc.org.mt).
14. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above and notified by email where practical.