1. Purpose and scope
This notice explains how individuals may exercise rights relating to personal data for which Ali Geren, operating through the professional presence Geren Corporate, acts as data controller.
It should be read together with POL-001 — Privacy Notice.
This notice applies only to processing activities for which Ali Geren is responsible as controller under applicable data-protection law. It does not transfer to Ali Geren responsibility for independent processing carried out by third-party websites, platforms or service providers. Where applicable law nevertheless treats Ali Geren as controller or joint controller for a particular processing activity, the corresponding statutory obligations remain unaffected.
2. Data controller
Data Controller: Ali Geren
Professional presence: Geren Corporate
Contact address
Signature – Portomaso Business Centre
Portomaso
St Julian’s
PTM 01
Malta
Contact email
support@gerencorporate.mt
3. Your responsibilities when providing information
You are responsible for taking reasonable care to ensure that information you provide is accurate, complete, relevant and, where appropriate, kept up to date.
You should provide only information reasonably necessary for your enquiry, request or engagement.
You should not send special-category, highly sensitive, confidential, excessive or unrelated personal information through ordinary website or email channels unless specifically requested or reasonably necessary.
Where you provide personal data concerning another individual, you are responsible for ensuring that you are lawfully entitled to provide that information and, where applicable, that the individual has been appropriately informed.
You are also responsible for the security of your own devices, email accounts, internet connections and other communication channels used to communicate with us.
These responsibilities do not remove any obligation imposed on the controller by applicable data-protection law.
4. Your GDPR rights
Depending on the circumstances and subject to applicable conditions and exemptions, you may have rights relating to access, rectification, erasure, restriction, objection, portability, withdrawal of consent and certain automated decision-making.
These rights apply only to the extent provided by applicable law and should not be interpreted as creating broader contractual rights against Ali Geren or Geren Corporate.
5. GDPR rights are subject to legal limits
Data-protection rights are important statutory rights, but many are not absolute.
A request does not automatically require us to delete information, cease processing, disclose every document, provide information in any requested format or accept the interpretation advanced by the requester.
Processing or retention may continue where permitted or required by law, including where necessary for:
- compliance with statutory or regulatory requirements;
- Company Service Provider obligations;
- anti-money laundering, due-diligence or record-keeping requirements;
- establishment, exercise or defence of legal claims;
- compliance with requests or obligations imposed by competent authorities;
- protection of the rights and freedoms of other persons;
- confidentiality, professional secrecy or legally protected information; or
- another lawful basis recognised by applicable legislation.
6. Making a request
For efficient and secure handling, GDPR-related requests should be sent to support@gerencorporate.mt.
You should provide sufficient information to allow the request and relevant records to be identified, including your name, appropriate contact information, the right being exercised and enough information to locate the relevant processing activity.
You are responsible for ensuring that the information supplied in support of your request is accurate.
If a request is unclear, incomplete or exceptionally broad, we may request reasonable clarification where permitted by law. Applicable statutory response obligations will continue to be observed.
7. Identity verification
Protecting personal data against unauthorised disclosure is itself a data-protection obligation.
Where there are reasonable doubts concerning the identity of a person exercising GDPR rights, we may request additional information necessary to confirm that person's identity.
Only information reasonably required for verification will be requested.
You should not send identity documents unless requested.
We may refuse to disclose personal data where we cannot reasonably verify that disclosure would be made to the correct person, subject to applicable law.
8. Requests made for another person
Anyone making a request on behalf of another individual is responsible for demonstrating appropriate authority to act.
We may request evidence of that authority.
Personal data will not be disclosed to a representative unless we are reasonably satisfied that doing so is lawful and appropriately authorised.
9. Response periods
Requests will be handled without undue delay and normally within one month of receipt, as required by applicable data-protection law.
Where permitted because of the complexity or number of requests, the response period may be extended by up to a further two months. Where an extension is used, the individual will be informed within the original one-month period together with the reason for the delay.
10. Fees, abusive, manifestly unfounded or excessive requests
GDPR requests are normally handled free of charge.
However, where a request is manifestly unfounded or excessive, applicable data-protection law may permit the controller, subject to the relevant legal requirements, either to charge a reasonable fee reflecting administrative costs or to refuse to act on the request.
The controller bears the burden of establishing that the applicable threshold is met.
We therefore reserve every right available under applicable data-protection law where there is sufficient lawful basis to use it.
11. Access requests do not provide unlimited document access
The right of access concerns personal data and the information required by applicable data-protection law.
It does not automatically create a right to unrestricted disclosure of every email, document, file, internal note, business record or other material in which personal data may appear.
Where applicable law requires copies, extracts or contextual material to make personal data intelligible, these will be provided as required.
Disclosure may be appropriately restricted, redacted or otherwise protected where necessary to safeguard the rights and freedoms of others, confidentiality, legally privileged information, regulatory restrictions or other interests recognised by law.
12. Additional copies
Where the right of access applies, the first required copy of personal data is provided in accordance with applicable data-protection law.
For additional copies requested by a data subject, a reasonable fee based on administrative costs may be charged where permitted by law.
13. Erasure requests and mandatory retention
The right to erasure does not provide an unconditional right to have all information deleted.
Personal data may continue to be retained where retention is required or permitted by law.
This is particularly important for regulated Company Services. Records relating to the provision of Company Services may be subject to statutory and regulatory retention requirements, including requirements under the applicable MFSA Company Service Provider framework.
Accordingly, a request for deletion cannot require us to destroy records that must lawfully be retained.
Other statutory, regulatory, anti-money-laundering, evidential or legal-claim requirements may also justify continued retention.
14. Rectification
Where you believe personal data is inaccurate or incomplete, you should identify the information concerned, explain the correction requested and, where reasonably available, provide supporting information.
We are not required to replace accurate records merely because a person disagrees with a documented fact, professional assessment, historical record or other information that is lawfully and accurately recorded.
15. Data portability
The right to data portability applies only in the circumstances provided by applicable data-protection law, principally where processing is automated and based on consent or contract and concerns data provided by the data subject.
Direct transmission to another controller applies only where technically feasible.
The portability right does not require us to create systems, formats or technical capabilities beyond what applicable law requires.
16. Objection and withdrawal of consent
Where processing is based on legitimate interests, a right to object may apply subject to the conditions provided by applicable data-protection law.
Processing may continue where applicable law permits it, including where compelling legitimate grounds override the relevant interests or where processing is required for the establishment, exercise or defence of legal claims.
Where processing is based on consent, consent may be withdrawn. Withdrawal does not retrospectively make processing carried out before withdrawal unlawful.
If personal data is ever processed for direct marketing, an applicable objection to that direct marketing will be respected in accordance with applicable data-protection law.
17. Security of communications
Electronic communication carries inherent risks.
You are responsible for exercising reasonable care regarding what you transmit, the device and account you use, the security of your connection and the accuracy of the destination address.
You should not transmit unnecessary confidential, sensitive or identification material through ordinary email.
Where we reasonably consider a more secure communication method appropriate, we may request that an alternative method be used.
Nothing in this provision limits our own statutory data-security obligations.
18. Automated decision-making
The Geren Corporate website does not currently use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
If this changes materially, the relevant information will be updated as required by law.
19. Complaints and supervisory authority
Questions or concerns may be sent to support@gerencorporate.mt.
You are not required by this notice to contact us before exercising any statutory right to complain directly to the supervisory authority.
Individuals may lodge a complaint with the Information and Data Protection Commissioner (IDPC), Malta where they consider that their personal data has been processed contrary to applicable data-protection legislation.
Information and Data Protection Commissioner
Floor 2, Airways House
Triq Il-Kbira
Tas-Sliema SLM 1549
Malta
20. No waiver and no additional assumption of liability
Nothing in this notice excludes or restricts any obligation or individual right that cannot lawfully be excluded under the GDPR, Malta’s Data Protection Act or other applicable legislation.
Subject to those mandatory requirements, nothing in this notice creates any additional contractual duty, warranty, representation or assumption of liability by Ali Geren or Geren Corporate beyond that imposed by applicable law or expressly agreed in a separate professional engagement; expands any statutory data-subject right beyond its lawful scope; or constitutes a waiver of any defence, exemption, limitation, retention right or other protection available under applicable law.
21. Changes
This notice may be updated where necessary to reflect changes in law, regulation, regulatory guidance, technology, website functionality or professional activities.
The version published on the website will identify its last-updated date.
