Draft — pending legal review by a Malta-qualified lawyer. Do not rely on this document.
PRIVACY POLICY · DRAFT

Privacy.

How Eywa Solutions handles personal data on this site and across the services we build. Malta-registered company. GDPR-aware by default.

1. Who we are

This site (eywasolutions.net) is operated by [CLIENT-TO-PROVIDE: Registered legal name], a company registered in Malta under company number [CLIENT-TO-PROVIDE: Malta Business Registry (MBR) company number], with registered office at [CLIENT-TO-PROVIDE: Registered office address in Malta].

We act as data controller for personal data collected through this website. For client engagements, the data-controller / data-processor relationship is documented separately in each engagement contract.

2. What we collect on this website

At launch, this site is intentionally minimal in its data handling:

We will update this section the first time we add any tool that processes personal data on the marketing site.

3. Why we collect it

The only personal data we collect via this website is what you actively send us — an email enquiry or a booked discovery call. We use it to:

Lawful basis: Article 6(1)(b) GDPR (steps taken at the request of the data subject prior to entering into a contract) or Article 6(1)(f) GDPR (legitimate interest in responding to inbound enquiries), as applicable.

4. Who else processes your data

When you interact with the site or the services it links to, the following data processors may receive your data:

VERCEL
Hosting (static HTML). EU regions configured (Frankfurt).
CLOUDFLARE
DNS, CDN, edge security. Global, with EU edge presence.
GOOGLE FONTS
Web fonts served from fonts.googleapis.com and fonts.gstatic.com.
CAL.COM
Booking infrastructure when you click "Book a discovery call." Cal.com's own privacy terms apply once you land on their booking page.
GOOGLE WORKSPACE
Email infrastructure for [email protected].

Each of these processors operates under its own privacy terms. We do not sell or share your data with marketing networks, ad networks, or any third party not listed here.

5. International transfers

Where a processor (e.g. Google Fonts, Google Workspace) involves transfer of personal data to a third country, we rely on the relevant adequacy decisions or standard contractual clauses published by the European Commission.

6. How long we keep it

Email correspondence is retained for as long as the relationship is active and for a reasonable period afterwards (typically up to [CLIENT-TO-PROVIDE: retention period — recommended 24 months] for tax, accounting, and contract-history purposes). Booked call records on cal.com are subject to cal.com's retention terms.

7. Your rights

Under the GDPR, you have the right to:

To exercise any of these rights, email [CLIENT-TO-PROVIDE: contact email — currently [email protected]]. We respond within one calendar month, extendable by two further months for complex requests (we will tell you if that applies).

8. Supervisory authority

The supervisory authority for data protection in Malta is the Information and Data Protection Commissioner (IDPC). You have the right to lodge a complaint with the IDPC if you believe we have not handled your personal data correctly.

9. Updates

We update this policy when our data processing changes — for example, when we add a new processor or introduce a contact form. The current version is dated [CLIENT-TO-PROVIDE: last-updated date].

10. Contact

For any privacy-related question: [CLIENT-TO-PROVIDE: contact email — currently [email protected]].