Privacy Policy
Last updated: April 2026
At Ta' Pinu Pharmacy, we are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR) and Maltese data protection legislation. This policy explains what personal information we collect, how we use it, and your rights regarding your data.
Data Controller
Ta' Pinu Pharmacy is the data controller responsible for your personal data. If you have any questions about this privacy policy or how we handle your data, you can contact us using the details at the bottom of this page.
What Information We Collect
When you book an appointment through our online booking system or contact us, we collect the following personal information:
Personal details:
- Full Name — to identify you for your appointment
- Email Address — to send you a booking confirmation and any updates regarding your appointment
- Phone Number — to contact you if we need to reach you about your appointment
- Notes — any additional information you choose to provide to help us prepare for your visit
Appointment details:
We also collect non-personal booking information such as your preferred date, time, service, and provider. This information is used solely for scheduling purposes.
Legal Basis for Processing
We process your personal data on the following legal grounds:
Consent — when you submit a booking through our online system, you provide explicit consent for us to process your personal data for appointment management. You may withdraw your consent at any time.
Legitimate interest — we may process your data where it is necessary for our legitimate interests, such as improving our services, provided these interests do not override your fundamental rights.
Legal obligation — we may process your data where required by law, such as maintaining pharmacy records as required by Maltese regulations.
How We Use Your Information
Your personal information is used exclusively to:
Manage your appointments — scheduling, confirming, and following up on your bookings.
Communicate with you — sending confirmation emails, appointment reminders, and contacting you if any changes are needed.
Improve our services — understanding booking patterns to better serve our patients.
We do not sell, share, or disclose your personal information to any third parties for marketing purposes.
Third-Party Service Providers
We use the following third-party service providers to operate our booking system. These providers process your data on our behalf and are contractually obligated to protect your information:
Brevo (Sendinblue) — used to send transactional emails such as booking confirmations and appointment reminders. Your name and email address are shared with Brevo for this purpose.
Vercel — our website hosting provider. Vercel may process technical data such as IP addresses as part of delivering the website to you.
Data Storage & Retention
Your booking information is securely stored using cloud infrastructure. Access to this data is restricted to authorised pharmacy staff only.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Booking records are retained for a reasonable period to support ongoing patient care and comply with applicable legal requirements. You may request deletion of your data at any time.
Cookies
Our website uses essential cookies that are necessary for the website to function properly. We do not use any analytics or marketing cookies. For more details, please see our Cookie Policy.
Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
Right of access — you can request a copy of the personal data we hold about you.
Right to rectification — you can request correction of any inaccurate or incomplete information.
Right to erasure — you can request deletion of your personal data where there is no compelling reason for us to continue processing it.
Right to restrict processing — you can request that we limit how we use your data.
Right to data portability — you can request your data in a structured, commonly used format.
Right to object — you can object to processing of your personal data in certain circumstances.
Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us and we will respond within 30 days.
Right to Complain
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC), Malta's supervisory authority for data protection:
Office of the Information and Data Protection Commissioner
Website: idpc.org.mt
Contact Us
If you have any questions about this privacy policy or how we handle your data, please don't hesitate to reach out:
