Legal
Privacy Policy
Updated: 11 August 2026
⚠️ Draft pending client data. Sections marked
[PENDING]need to be completed with Phoenix Hub Solutions’ real registration details before this page is published. Seedocs/todos.md.
Last updated: 11 August 2026
1. Who is responsible for your data
Phoenix Hub Solutions (“we”, “us”), registered in Malta at 39, Il-Bajja ta’ Spinola, St Julians, STJ 3021, Malta, company registration number [PENDING], VAT number [PENDING], is the data controller for the personal data described in this policy.
Contact: [email protected] · Data protection contact: [PENDING — name a DPO or privacy contact if one is appointed]
2. What data we collect
- Contact form / lead submissions: name, email, phone number, company, and any information you choose to provide about your project or budget.
- Newsletter sign-up: email address.
- Website analytics: aggregated, privacy-respecting analytics (see our Cookie Policy).
- Client and lead data processed on behalf of our customers: see How We Handle Lead Data for the specific case of leads generated for our clients.
3. Why we process your data (legal basis)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Responding to your enquiry | Legitimate interest / pre-contractual steps |
| Delivering a contracted service | Performance of a contract |
| Sending the newsletter | Consent |
| Basic website analytics | Legitimate interest |
| Legal and accounting obligations | Legal obligation |
4. How long we keep your data
We keep enquiry and lead data for as long as necessary to fulfil the purpose it was collected for, and no longer than [PENDING — define retention period, e.g. 24 months of inactivity], unless a longer period is required by law.
5. Who we share data with
We do not sell personal data. We share data only with:
- Service providers strictly necessary to deliver our services (hosting, email delivery, CRM) under data processing agreements.
- Authorities, where required by law.
[PENDING — list actual subprocessors once selected: hosting provider, email provider, CRM, analytics.]
6. International transfers
[PENDING — state whether any subprocessor is outside the EEA and which safeguard applies, e.g. Standard Contractual Clauses.]
7. Your rights (GDPR Articles 15–22)
As a data subject you have the right to: access your data, rectify it, request erasure, restrict processing, object to processing, and data portability. You can exercise these rights by writing to [email protected].
If you are not satisfied with our response, you may lodge a complaint with the Maltese Information and Data Protection Commissioner (IDPC) or, if you are in Spain, with the Agencia Española de Protección de Datos (AEPD).
8. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or alteration.
9. Changes to this policy
We may update this policy from time to time. The date at the top reflects the latest revision.