01Controller
- Controller
- Gambridge Technologies Ltd, Eria, P. Byrdone Street, Naxxar NXR 2320, Malta
- Privacy contact
- privacy@gamb-tech.com
This notice explains how we handle personal data when you visit this website, contact us, or work with us as a client, supplier or applicant. It follows Regulation (EU) 2016/679 (GDPR) and the Maltese Data Protection Act (Cap. 586).
02What we process, why, and on what basis
| Activity | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Visiting this website | IP address, request time, URL requested, status code, user agent, referrer | Delivering the site, security, troubleshooting | Legitimate interests, Art. 6(1)(f) | Up to 30 days |
| Project enquiry form and email | Name, work email, subject selected, message content, anything you choose to add | Replying to your enquiry, assessing a possible engagement | Steps prior to a contract, Art. 6(1)(b); otherwise legitimate interests, Art. 6(1)(f) | 24 months after the last contact, unless a contract follows |
| Client and supplier relationships | Contact details of the people we work with, correspondence, contractual and billing data | Performing the contract, invoicing, support and account management | Art. 6(1)(b) and Art. 6(1)(c) for statutory records | Statutory retention periods under Maltese commercial and tax law |
| Job applications | Application documents and interview notes | Assessing your application | Art. 6(1)(b) and Art. 6(1)(f) | 6 months after the process closes, longer only with your consent |
Providing data is voluntary. If you do not send us contact details we cannot reply to an enquiry; that is the only consequence.
03No tracking, no profiling
This website uses no analytics services, no advertising or social media pixels, no third-party fonts and no content delivery networks that would expose your IP address to others. Nothing on the site is loaded from an external domain. We do not carry out profiling or automated decision-making with legal effect within the meaning of Art. 22 GDPR.
Cookie details are set out in our cookie policy.
04When we act as processor for our clients
In development and managed-operations projects we may process personal data on behalf of a client — for example when working on production-like data, investigating an incident, or operating a platform under an SLA. In those cases the client is the controller and we act as processor under a data processing agreement pursuant to Art. 28 GDPR that covers scope, instructions, confidentiality, security measures, sub-processors, assistance and deletion.
Our standing position is that production personal data is not used for development or testing. Where analysis cannot be done otherwise, access is granted on a named, time-limited basis and logged. If you are an end user of a platform we operate for a client, please direct data subject requests to that client as controller; we will support them in responding.
05Recipients and sub-processors
We share personal data only where necessary, and only with recipients bound by a contract and by confidentiality obligations. Our current categories of recipients are:
| Recipient | Role | Location |
|---|---|---|
| Hosting provider | Website hosting and server logs | EU |
| Email and office provider | Business email and document storage | EU |
| Accounting and audit advisers | Bookkeeping, statutory accounts, audit | Malta |
| Legal advisers | Advice and dispute handling where needed | Malta / EU |
We do not sell personal data and we do not disclose it to third parties for their own marketing purposes.
Complete this table with the actual providers before publishing, and keep a sub-processor register alongside it. The register is the document clients ask for during due diligence.
06Transfers outside the EEA
We prefer providers that operate in the EU or EEA. Where a transfer to a third country cannot be avoided, it takes place on the basis of an adequacy decision under Art. 45 GDPR or the European Commission's standard contractual clauses under Art. 46 GDPR, combined with a transfer impact assessment and, where appropriate, technical measures such as encryption and pseudonymisation. You can request a copy of the safeguards in place.
07Security
We apply the technical and organisational measures required by Art. 32 GDPR, calibrated to the payment systems we work on. These include encryption in transit and at rest, role-based access with least privilege, multi-factor authentication, hardware-backed credentials for administrative access, segregated environments, code review and automated security testing in CI, centralised logging with alerting, dependency and vulnerability management, documented incident response, and staff confidentiality undertakings with regular training.
08Your rights
Under the GDPR you have the right to request access to your personal data, rectification of inaccurate data, erasure, restriction of processing, and portability of data you provided to us. You may object to processing based on legitimate interests, and you may withdraw any consent at any time with effect for the future.
Send requests to privacy@gamb-tech.com. We reply within one month and will tell you if we need to extend that period, as permitted by Art. 12(3) GDPR. We may ask for information to confirm your identity, and we use that information for no other purpose.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Information and Data Protection Commissioner in Malta (idpc.org.mt). You may alternatively complain to the authority in your country of residence or place of work.
09Changes to this notice
We update this notice when our processing changes or when guidance from the supervisory authorities makes clarification useful. The current version is always published on this page with the date at the top. Material changes affecting existing clients are communicated directly.