Your Data
PRIVACY POLICY
What we collect, why we collect it, and the rights you have over it
1. Who We Are
Aqua-Fly, operating from the Aqua-Fly Dock, Bahar ic-Caghaq, Naxxar, Malta, is the data controller for the personal data described in this policy. For anything privacy-related, contact us at info@aqua-fly.com or on +356 9937 4612.
2. What We Collect
We only collect the data we need to run our sessions and answer you:
- Contact form — the subject you choose, your first name, email address, contact number and your message.
- Online waiver — your first name, surname, email address, contact number, a photo of you, your signature, and the date and time you signed.
- Bookings — when you book a session, the details needed to manage that booking (participant names, contact details and the agreed slot).
- Technical data — standard web-server logs (such as IP address and the pages requested) kept for security, and the cookies described below.
3. Why We Use It
- To answer your enquiries and manage your bookings (steps taken at your request).
- To keep a record of signed waivers — this is a safety and legal record: we use it to confirm who has accepted the activity risks, to email you your signed copy, and to establish or defend legal claims if we ever need to.
- To protect the website and our inbox from abuse and spam.
We do not sell your data, we do not send marketing without asking you first, and we make no automated decisions about you.
4. Who We Share It With
We use a small number of service providers to run the site:
- Amazon Web Services (SES) delivers our email — your signed waiver copy, booking confirmations and contact-form notifications pass through AWS mail servers located in the United States. That transfer is protected by recognised safeguards, including the EU–U.S. Data Privacy Framework and standard contractual clauses.
- Google reCAPTCHA protects the contact form from bots. When you use that form, Google processes device and interaction data under the Google Privacy Policy and Terms of Service.
- Google Maps shows our location on the Contact page; loading the map involves Google in the same way.
- Google Analytics measures how the site is used (pages visited, how you found us) — but only if you choose “Accept All” in the cookie banner. If you choose “Accept Required Only”, Google Analytics is never loaded and no usage data is sent to Google.
- Stripe processes card payments if and when we take payments online; card details go directly to Stripe and never touch our servers.
5. Cookies
This site keeps cookies to a minimum:
-
Required cookies — a security (anti-forgery) cookie that protects
the forms, and
af_cookie_consent, which remembers the choice you make in the cookie banner for 12 months. These are needed for the site to work. -
Analytics cookies — set only if you choose “Accept All”
in the cookie banner. We use Google Analytics, whose cookies (named
_gaand_ga_…, kept for up to 2 years) help us understand how the site is used so we can improve it. - Third-party cookies — Google may set cookies when a page embeds reCAPTCHA or Google Maps.
You can change or withdraw your choice at any time by clearing this site's cookies in your browser — the banner will ask you again on your next visit.
6. How Long We Keep It
- Contact messages — for as long as we need to handle your enquiry and for a reasonable period afterwards.
- Signed waivers (including photo and signature) — for as long as legal claims connected to a session could be brought, after which they are deleted.
7. Your Rights
Under the GDPR you can ask us at any time to:
- access the personal data we hold about you;
- correct it if it is wrong;
- delete it, where we no longer have a valid reason to keep it;
- restrict or object to how we use it;
- receive a copy of the data you gave us in a portable format.
Write to info@aqua-fly.com and we will respond. You also have the right to complain to the Maltese supervisory authority, the Information and Data Protection Commissioner (idpc.org.mt).
8. How We Protect It
The site runs over HTTPS, access to stored data is restricted, and the verification codes on waiver PDFs are encrypted so they cannot be forged or read by anyone else.
9. Children
Participants under 18 need the consent of a parent or guardian, as set out in the activity waiver. We do not knowingly collect a child's data online without a parent or guardian being involved.
10. Changes to This Policy
If we change how we handle personal data, we will update this page and its effective date.