Privacy Notice
Purpose and legal basis: We collect and process personal data you provide to deliver services, perform contracts, comply with legal obligations, respond to inquiries, and where necessary for our legitimate business interests (e.g., fraud prevention, administration, and improving services). Where required, we will obtain your consent; you may withdraw consent at any time without affecting processing based on a prior lawful basis.
Categories of data: Typical categories include identification and contact data (name, address, email, phone), billing and payment data, professional and contractual information, and any other information you provide.
Recipients and international transfers: We may disclose personal data to service providers (e.g., payment processors, IT hosts, accountants, legal advisors) who act as processors under contract requiring appropriate safeguards. Transfers outside the EEA (including to countries without an adequacy decision) will be made only with appropriate safeguards such as Standard Contractual Clauses, binding corporate rules, or other measures permitted under applicable law.
Retention: We retain personal data only as long as necessary for the purposes stated, to fulfil contractual or legal obligations, or to establish, exercise or defend legal claims. Retention periods depend on the data category and applicable statutory limits (e.g., tax and accounting laws).
Security: We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, in accordance with applicable Maltese and EU law.
Your rights: Under Maltese and EU data protection law (including the General Data Protection Regulation), you have the right to:
- access your personal data;
- request rectification of inaccurate data;
- request erasure (“right to be forgotten”) where applicable;
- request restriction of processing;
- object to processing based on our legitimate interests or direct marketing;
- request portability of data you have provided in a structured, commonly used, machine-readable format;
- withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise these rights, or for questions about processing, contact our Data Protection Contact at info@kaiengleradvisory.com. You may be asked to provide proof of identity to protect your data.
Complaints: You have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner (IDPC) in Malta or another competent supervisory authority.
Automated decision‑making: Where we use any automated decision-making, including profiling, we will inform you and, where required, implement appropriate safeguards to protect your rights and freedoms.
Updates: This notice may be updated from time to time. The effective date will be shown on the website; material changes will be notified where required.
Controller contact for data protection matters:
Kai Engler Advisory Ltd,
Centris Business Gateway, Level 4M
Triq Is-Salib Tal-Imriehel
Central Business District, Zone 3
CBD 3020
Malta