Privacy Policy

Privacy Policy

Information pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”)

This policy describes how the personal data of users visiting the website https://alchemyspa.online/ (hereinafter, “Data Controller” or “Company”) is processed and how they interact with the services offered.

  1. DATA CONTROLLER

The Data Controller is Alchemy, by Jaminka Mujdzic.

Headquarters:

  • Alchemy Birgu at 84 Lawrenze Street, Birgu BRG 1010, Malta
  • Alchemy Valletta: Old Mint Street 39, Valletta, Malta

Phone :

  • Alchemy Birgu: +356 9980 9920
  • Alchemy Valletta: +356 99045740

Email :

VAT: —

The Data Controller has not appointed a Data Protection Officer (DPO), as it has been assessed that, given the type of processing carried out, there is no obligation or need for such a position.

  1. DATA COLLECTED AND PURPOSE OF PROCESSING

The Data Controller collects and processes the following personal data:

  • Data provided voluntarily by the user: Name, surname, email, phone number, and other information entered by the user in contact forms, registration, or newsletter.
  • Data provided for information requests, quotes, or to finalize contracts.
  • Navigation data: IP addresses, browser type, login data, pages visited, connection times, device identifiers. These data are collected automatically for statistical, security, and proper website functioning purposes.

Purpose of Processing and Legal Bases

Purpose Legal Basis
Providing requested services (quotes, assistance, orders) Performance of a contract (Art. 6.1.b GDPR)
Legal, fiscal, and accounting obligations Legal obligation (Art. 6.1.c GDPR)
Direct marketing (newsletters, promotions) Explicit consent (Art. 6.1.a GDPR)
Statistical analysis and service improvement Legitimate interest (Art. 6.1.f GDPR)
Cybersecurity and fraud prevention Legitimate interest (Art. 6.1.f GDPR)

  1. DATA STORAGE

Personal data will be stored in a form that allows identification of the user only for as long as necessary to achieve the purposes for which the data were originally collected and, in any case, within legal limits. Specific security measures are in place to prevent data loss, unlawful or improper use, and unauthorized access, in accordance with GDPR. The Data Controller has adopted adequate security measures to protect your data from loss, abuse, or alteration. The Data Controller will not transfer your personal data to a third country or an international organization.

To ensure that personal data is always accurate, updated, complete, and relevant, data subjects are encouraged to report any changes to the email address provided above in Section 1.

  1. COOKIE POLICY

Types of cookies used: Technical cookies: necessary for the website to function and to manage online bookings.
Analytics cookies: help us understand how the site is used (in anonymous form).
Profiling cookies: used to show you personalized content and offers (only with your consent).
Managing cookies: You can accept, refuse, or customize your cookie preferences at any time via the banner on the website or by changing your browser settings.

  1. DATA RECIPIENTS

Personal data may be communicated to:

  • IT service providers (hosting, email, management software).
  • Legal, fiscal, and administrative consultants for legal obligations.
  • Judicial or regulatory authorities, if required by law.

The data will not be transferred to third parties for marketing purposes without the explicit consent of the user.

  1. TRANSFER OF DATA OUTSIDE THE EU

If the website uses third-party services with servers outside the European Union (e.g., Google, Meta, Mailchimp), data may be transferred in accordance with the adequacy decisions of the EU Commission or through Standard Contractual Clauses (SCC).

  1. USER RIGHTS

The user has the right to:

✅ Access their data (Art. 15 GDPR).
✅ Request rectification or updates (Art. 16 GDPR).
✅ Request data deletion (“right to be forgotten”) (Art. 17 GDPR).
✅ Limit processing (Art. 18 GDPR).
✅ Receive data in a structured format (portability, Art. 20 GDPR).
✅ Object to processing, including for marketing purposes (Art. 21 GDPR).
✅ Withdraw consent at any time.

CHANGES TO THE PRIVACY POLICY

This policy may be updated for regulatory adjustments or technological advancements. 

  1. PURPOSE OF PROCESSING

The processing of personal data is aimed at:

  • Primarily the correct and complete execution of the contract and other assignments, including the formulation of quotes, granted by the data subject.
  • Within the limits and for the sole purpose of providing the services accessible through the company’s website, to allow users to learn about or deepen the company’s activities and other initiatives.
  • The fulfillment, by the Data Controller, of obligations in the fiscal and accounting area.
  • Compliance with obligations incumbent on the Data Controller in accordance with other binding regulations (e.g., security matters).
  • With the explicit consent of the data subject, for sending communications containing information about the Data Controller and activities organized by them (such as invitations to conferences and events, including managing participation in these events), as well as updates and/or legal and/or promotional material, such as newsletters, presentations, and insights related to the Data Controller’s activities, including profiling the data subject for these purposes to improve or personalize initiatives based on their specific needs or interests.

  1. CONSEQUENCES OF NOT PROVIDING PERSONAL DATA

Providing personal data for the above purposes is optional, and failure to provide it will only result in the inability of the Data Controller to manage and process the data subject’s requests or send the communications mentioned above.

Policy version as of 05-02-2026

Scroll to Top