No deposit required— with our zero-excess waiver at €10 a day

Car Rentals Ltd

GDPR privacy policy

What personal data we collect, why we hold it, how long we keep it, and the rights you have over it under the General Data Protection Regulation.

Introduction

Car Rentals Ltd. takes data protection seriously and invests in the processes needed to keep personal data safe by design. Where processing personal data is necessary and there is no statutory basis for it, we obtain the data subject's consent.

Any processing of personal data — such as a name, address, email address or telephone number — is carried out in line with the General Data Protection Regulation (GDPR). This declaration explains the nature, scope and purpose of the personal data we collect and process, and sets out the rights you are entitled to.

Data controller

The controller for the purposes of the GDPR, other data protection laws applicable in EU member states, and other provisions related to data protection, is:

The CEO
Car Rentals Ltd.
Fliegu Street, Qawra
Malta SPB 1400

As controller, we have implemented technical and organisational measures intended to give the personal data we process the fullest practical protection.

What data we collect, and why

When you become a customer — whether in person at our premises or through another channel — we generally collect your name and surname, address, telephone and mobile numbers, and email address where required. This is stored securely, either on a centralised server or on a company computer.

When you use this website we may collect the same details. In addition, our web hosting provider records standard server log data, which may include:

  • browser type and version;
  • the operating system of the accessing system;
  • the referring website;
  • the date and time of access;
  • the IP address;
  • the internet service provider of the accessing system;
  • similar data that may be relevant in the event of an attack on our IT systems.

We never use this data to draw conclusions about you as an individual. We need it to deliver the standard of service we want our clients to have — to contact you as part of a transaction, and, where you have given separate consent, to tell you about new services and offers by email or by post.

Anonymised data is analysed statistically, with the aim of improving our data protection and data security. Anonymous server log data is stored separately from any personal data you provide.

Where we are obliged to process your data to meet a legal requirement, or to perform a contract we have with you, and that data is not provided, we may be unable to perform the services as agreed.

How we collect it

  • through our representatives, in person;
  • through this website and our social media pages;
  • through emails received and actioned by our representatives;
  • through telephone calls;
  • through postal mail.

Retention period

We normally retain a client's personal data for as long as they are considered a client. As a matter of policy, we retain personal data for two years from the date of last contact. After that, the data subject is no longer considered a client and the data is erased — unless the data subject asks us to do otherwise.

For marketing communications we ask for specific permission to retain an email address and/or phone number indefinitely. Every mailing reminds recipients that they may opt out at any time.

Who we share your data with

We may use third-party partners to help process data for marketing or other purposes, such as ICT, logistics, and accounting and audit firms. We satisfy ourselves that these partners handle personal data under strict controls, and we deliberately share only the data required for the task rather than everything we hold.

We may disclose personal data where a public authority — law enforcement, tax or customs — requests it in accordance with a legal obligation, where that data is necessary for an inquiry in the general interest under EU or member state law. We may also disclose data where we are under a legal obligation to do so, in pursuance of a judgment or court order, or to enforce our terms of use or protect our rights.

Transfers outside the European Union

Transferring data outside the EU — particularly to countries that may not have appropriate data protection safeguards — is very unlikely, and in any case would be based on your consent.

Subscription to our newsletter

You may be given the opportunity to subscribe to our newsletter, which we use to inform customers and business partners about our offers. The newsletter is only sent where the data subject has a valid email address, has registered for it, and — as a client — has opted in.

We operate a double opt-in procedure: a confirmation email is sent to the address given, to establish that the owner of that address is genuinely authorised to receive the newsletter. At registration we also store the IP address assigned by your internet service provider along with the date and time. That is collected so that any later misuse of an email address can be understood, and serves the legal protection of the controller. Data collected for the newsletter is used only to send the newsletter.

Cookies

This website uses cookies — small text files stored on your device — to help the site function properly and to show content that is more relevant to you. The site will ask for your acceptance of these cookies. We do not use data acquired through cookies to draw conclusions about individual visitors.

CCTV at our premises

Where CCTV cameras are installed, their purpose is security alone — protecting company assets and the physical safety of clients while they are on our premises — and not monitoring the movements of clients or employees. Footage is disclosed to third parties such as law enforcement agencies only in the event of a security incident. Recordings are stored on a rotating basis and are overwritten roughly every 30 days.

Data security

Your data is processed in accordance with the provisions of the GDPR, and we take appropriate technical and organisational precautions to protect it against loss, misuse and unauthorised access.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you;
  • Rectify data that is inaccurate or incomplete;
  • Erasure of your data where there is no overriding reason for us to keep it;
  • Restrict or object to processing in certain circumstances;
  • Data portability — to receive your data in a portable format;
  • Withdraw consent at any time, where processing is based on consent;
  • Lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta.

Contacting us about your data

To exercise any of the rights above, or to ask anything about this policy, write to the CEO at Car Rentals Ltd., Fliegu Street, Qawra, Malta SPB 1400, or email [email protected].


This policy describes our data protection practices. It should be read together with our terms & conditions.

Call us