How Aimalta Marketplace collects, uses and protects personal data.
Publish on /privacy. Do not publish a Data Protection Officer address unless a DPO is formally appointed and the role is real. Until then use the privacy contact below. Bracketed text below (e.g. [PRIVACY EMAIL]) marks operator details not yet supplied for this build.
[OPERATOR LEGAL NAME], trading as [TRADING NAME], of [REGISTERED BUSINESS ADDRESS], Malta, is the controller of personal data processed for aimaltamarket.mt. Contact: [PRIVACY EMAIL], [TELEPHONE].
For privacy matters, use [PRIVACY EMAIL]. If a Data Protection Officer is formally appointed, this policy will identify the DPO and contact details. A mailbox name alone does not mean a statutory DPO has been appointed.
This policy applies to visitors, registered users, Sellers, Buyers, bidders, business account representatives, support contacts and persons who report content. It covers the website, applications, messages, auctions, Purchased Credits, regular renewals, standard boosts, Meta Sponsored Boost orders and analytics, Business Plans, support, moderation, product safety, tax reporting and related operations.
A Seller is an independent controller for personal data the Seller receives and uses for the Seller's own transaction. We are not responsible for a Seller's separate processing, but we require lawful use through the Terms.
We receive data directly from you, from other users involved in an auction or report, from payment and verification providers, from Meta where a Meta Sponsored Boost is requested, from public business or product safety registers, from devices and consented cookies, and from competent authorities where lawful. We do not purchase hidden personal profiles for advertising.
| Purpose | Legal basis |
|---|---|
| Account, listings, messaging, auctions and support | Performance of a contract and steps requested before a contract, Article 6(1)(b) GDPR. |
| Purchased Credits, Business Plan Bonus Credits, Gift Voucher Bonus Credits, manual and paid automatic renewals, standard boosts, Meta Sponsored Boost, Business Plans and Auction Commissions | Performance of a contract; legal obligation for invoicing, VAT and accounting. Business Plan credit allocations and paid automatic renewal settings are processed to provide the selected service. Meta advertising submission and reporting are performed at the Seller's request under the purchased service terms. |
| Identity, fraud, scam, shill bidding and security controls | Legitimate interests in a safe and lawful marketplace; legal obligations where applicable. We document a balancing test. |
| Illegal content moderation, DSA notices and statements of reasons | Legal obligation and legitimate interests in enforcement of the Terms. |
| Product safety, recalls and authority cooperation | Legal obligation under product safety law and protection of users. |
| DAC7 due diligence and reporting | Legal obligation. Data is not processed on consent where reporting is mandatory. |
| Essential device storage and session security | Necessary to provide the service requested and our legitimate interests. Consent is not used for strictly necessary storage. |
| Analytics and marketing cookies | Consent, Article 6(1)(a) GDPR and applicable ePrivacy rules. No activation before consent. |
| Service analytics without non essential cookies | Legitimate interests using minimised or aggregated data where the method does not require consent. |
| AI assisted listing generation requested by the user | Performance of a contract or requested pre contractual step. |
| AI assisted moderation and search | Legitimate interests in safety, relevance and service operation, with safeguards and the right to object where applicable. |
| Direct electronic marketing | Consent, or a narrow existing customer rule only where law permits and an easy opt out is provided. |
| Legal claims and authority requests | Legal obligation and legitimate interests in establishing, exercising or defending legal claims. |
We disclose only data necessary for the recipient's role. Production providers must be named in the live provider register and reflected in this policy. Categories may include:
We do not sell personal data. We require processors to act on documented instructions, protect confidentiality, support rights and deletion, notify incidents and use approved subprocessors.
Some providers may process data outside the European Economic Area. Where this occurs, we use a European Commission adequacy decision, the European Commission Standard Contractual Clauses with a transfer risk assessment and supplementary safeguards, or another lawful transfer mechanism. Use of the Platform is not treated as consent to an international transfer.
You may request information about the applicable safeguard from [PRIVACY EMAIL], subject to protection of confidential security information.
| Data set | Retention rule |
|---|---|
| Account profile | While the account is active. After closure, remove public profile promptly and delete or anonymise ordinary account data within 30 days, subject to the exceptions below. |
| Deleted content and backups | Remove from active systems promptly. Encrypted backups expire on a rolling basis no later than 90 days unless preservation is legally required. |
| Messages | While needed for the active conversation and account. After account closure, retain up to 24 months where necessary for fraud, safety or disputes, then delete or anonymise unless a legal claim is active. |
| Bids and auction outcomes | Six years from the end of the relevant year, or longer where a tax, DAC7 or legal claim period requires it. |
| Credits, renewals, boosts, subscriptions, Auction Commissions, invoices and VAT records | At least six years from the end of the year to which the records relate, and longer where a corrected return, payment dispute or other tax rule requires. |
| DAC7 data and reports | For the statutory due diligence and reporting period advised by the Malta tax adviser, with access restricted to authorised compliance personnel. |
| Product safety and recalls | For the period necessary to comply with authority orders, notify affected users and establish legal compliance. Set the category schedule after the product safety adviser confirms it. |
| Moderation, fraud and appeals | Normally 24 months after closure of the case; longer only for repeated abuse, legal claims or authority requirements. |
| Security and server logs | Normally 12 months, shortened where a log is not needed and extended only for an active security investigation. |
| Cookie consent evidence | For the life of the consent plus the period needed to demonstrate compliance, normally up to five years. |
| Marketing consent | Until withdrawal, then retain a minimal suppression record so the opt out is respected. |
| Meta Sponsored Boost campaign and audit data | For the period needed to provide reporting, resolve refunds or disputes, meet tax and advertising transparency duties and defend legal claims. Exact operational periods must be set with the accountant and privacy adviser. |
Retention is reviewed annually. Data is anonymised where the purpose can be achieved without identification. A legal hold suspends routine deletion only for the relevant records and period.
Subject to the GDPR and applicable conditions, you may request access, rectification, erasure, restriction, portability and information about processing. You may object to processing based on legitimate interests and at any time to direct marketing. You may withdraw consent without affecting processing before withdrawal.
Submit a request through Account Settings or [PRIVACY EMAIL]. We may verify identity proportionately. We normally respond within one month and explain any lawful extension or refusal. Closing an account and erasure are not the same: records required for tax, DAC7, product safety, legal claims or recovery of a valid amount may be retained while unrelated data is erased.
You may complain to the Information and Data Protection Commissioner in Malta or another competent supervisory authority.
AI may help draft listing text requested by a user, improve search, identify duplicates, detect scams or unsafe content and prioritise material for review. AI generated listing text is presented as an editable draft. The Seller remains responsible for checking accuracy, legality, safety information and intellectual property rights before publication.
Where a person interacts directly with an AI system, the interface discloses that fact unless it is obvious from the context. Public content generated or materially edited by our AI is labelled where required by law and technically feasible.
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects for a user. A restriction based on an automated flag is subject to meaningful human review and appeal. Users may object to legitimate interest profiling as described above.
We use proportionate technical and organisational measures, including encryption in transit, secure password hashing, least privilege access, multifactor authentication for privileged users, logging, backups, vulnerability management, incident response and processor controls. No service can guarantee absolute security.
Internal access to messages, identity, billing, tax and product safety data is role-based, logged and limited to a defined purpose. Impersonation sessions must be visibly marked, audited and prevented from financial, bidding or messaging actions.
The Platform is for adults aged 18 or older. We do not knowingly create accounts for children. If we learn that a child has provided personal data, we restrict the account and delete data that is not legally required. Contact [PRIVACY EMAIL] to report a concern.
The Cookies Policy explains cookies and similar technologies. Non essential analytics and marketing technologies operate only after consent. Service and transaction messages are sent because they are necessary for the account, auction, payment, safety or legal process and are not marketing merely because they use email or push notifications.
Marketing messages include an easy unsubscribe method. Withdrawing marketing consent does not stop essential service messages.
We update this policy when processing, providers or law changes. Material changes are notified through the Platform or email before taking effect where appropriate. The current effective date is [EFFECTIVE DATE]. Contact [PRIVACY EMAIL] with questions.