Privacy policy
Tal-Fanal Village Ltd trading as Fanal Holiday Homes
Last updated: 15 August 2026
At a glance
This notice explains how Fanal Holiday Homes collects and uses personal data across the full guest relationship, including direct enquiries and bookings, bookings received through travel partners, website use, guest communications, payments, stays, complaints, incidents and CCTV.
1. Who we are and who controls your data
Tal-Fanal Village Ltd, trading as Fanal Holiday Homes ("Fanal Holiday Homes", "we", "us" or "our"), provides holiday accommodation and related guest services in Gozo, Malta.
For the purposes of Regulation (EU) 2016/679 (the General Data Protection Regulation or "GDPR"), the Data
Protection Act (Chapter 586 of the Laws of Malta) and other applicable data-protection legislation, Tal-Fanal Village Ltd is the data controller for the personal data described in this Privacy Policy.
Contact details:
• Fanal Holiday Homes, Villagg tal-Fanal, Unit 1, Triq il-Fanal, Għasri, Gozo GSR 1206, Malta
• Telephone: +356 2388 9000
• Email: reservations@fanalholidayhomes.com
• Website: www.fanalholidayhomes.com
For privacy or data-protection requests, please use the above email address and include “Data Protection Request” in the subject line where possible.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data we process about guests, prospective guests, people making or paying for a reservation, persons included in a reservation, website visitors, newsletter subscribers, persons communicating with us, and visitors to areas where CCTV is in operation.
It applies whether you book directly with us or through an online travel agency, travel agent, tour operator, distribution partner, corporate travel provider or another authorised intermediary.
3. Personal data we may collect
3.1 Identification and contact data
• Name and surname
• Postal address, email address and telephone number
• Nationality, country of residence, date of birth or age where required
• Identity-document or registration information where required by law
• Details of other guests included in a reservation where necessary
3.2 Reservation and stay data
• Accommodation booked, arrival and departure dates, number and composition of guests
• Booking reference, booking source, rate, package or promotion
• Special requests and accommodation preferences
• Check-in, check-out and service information
• Changes, cancellations, no-shows, extensions and late check-outs
• Correspondence, guest-service requests, complaints and feedback
• Incident, damage, security and claims records where relevant
3.3 Payment and financial data
• Amounts due and paid, deposits, refunds and outstanding balances
• Payment method, transaction references, invoices and receipts
• Information made available to us by banks, payment processors, booking platforms or payment gateways in connection with a transaction
Payment-card information may be processed by payment providers, booking platforms or systems used to administer your reservation. We limit access to payment information to authorised persons and only process it for legitimate payment, accounting, fraud-prevention and contractual purposes.
3.4 Communications and customer-service data
We may retain communications made by email, telephone, SMS, web forms, online travel agencies, guest
communication systems, digital guidebooks, messaging services or other channels used to administer your enquiry, reservation or stay.
3.5 Website and technical data
• IP address and approximate location derived from technical data
• Browser, device and operating-system information
• Pages viewed, dates and times of access, referring page and website interactions
• Cookie or similar technology identifiers where permitted
Further information is provided in our Cookies Policy.
3.6 Special-category data
Guests may voluntarily provide information about accessibility, health, allergies or other circumstances relevant to their stay. We ask that you provide only what is necessary. Where such information is special-category personal data under the GDPR, we process it only where an appropriate condition under applicable law exists, for example with explicit consent or where otherwise necessary and legally permitted.
4. How we obtain personal data
We may obtain personal data:
• directly from you when you enquire, book, pay, check in, request assistance, complete a form, subscribe, complain
or otherwise communicate with us;
• from the person who makes a reservation on your behalf, such as a family member, group organiser or company;
• from online travel agencies, travel agents, tour operators, accommodation distributors and other booking partners;
• from payment providers, banks and fraud-prevention services in connection with a payment;
• from our website, booking engine and related technical systems; and
• from CCTV systems and operational records where relevant to safety, security, an incident or a claim.
If you provide us with personal data about another person, you should ensure that you are authorised to provide it and, where appropriate, that the person is aware that their information has been provided to us.
5. Why we use personal data and our lawful bases
| Purpose | What this covers | Principal lawful basis |
| Enquiries, quotations and reservations | Responding to enquiries; taking steps before a contract; creating, amending and administering bookings; providing accommodation and requested services. |
Contract / pre-contractual steps |
| Guest communications | Booking confirmations, payment notices, arrival information, check-in instructions, property information, service messages and other communications necessary for the stay. |
Contract; legitimate interests in effective guest service |
| Payments and accounting | Taking and reconciling payments, deposits and refunds; invoicing; accounting; financial controls; fraud prevention. |
Contract; legal obligation; legitimate interests |
| Legal and regulatory compliance | Guest-registration requirements, taxation, tourism or environmental charges, lawful authority requests and statutory record keeping. |
Legal obligation |
| Customer service, complaints and claims | Responding to complaints, investigating incidents, dealing with insurers and advisers, establishing facts and defending legal rights. |
Contract; legal obligation; legitimate interests; legal claims where applicable |
| Safety, security and property protection | CCTV, incident investigation, access control, fraud prevention, protection of guests, staff and property. |
Legitimate interests; legal obligation where applicable |
| Service and business improvement | Operational analysis, service quality, website performance, demand analysis and internal management. |
Legitimate interests, using aggregated or anonymised data where practical |
| Marketing | Sending promotional communications where consent has been given or where the limited soft-opt-in rules lawfully apply. |
Consent and/or legitimate interests, subject to electronic-marketing rules |
| Website cookies and similar technologies | Providing essential website functions and, with consent, functional, analytics or marketing technologies. |
Strict necessity for exempt cookies; consent for non-essential cookies |
Where we rely on legitimate interests, those interests include operating and improving our accommodation business, delivering effective guest support, preventing fraud and misuse, protecting people and property, maintaining security, and establishing or defending legal rights. We consider whether those interests are overridden by your rights and freedoms before relying on this basis.
6. Service communications and direct marketing
6.1 Service communications
Messages needed to administer a reservation or provide requested accommodation are service communications. These may include confirmations, payment information, arrival and check-in instructions, directions, property notices, guest guidebook information, service updates and communications needed during or after a stay. They are not treated as marketing merely because they are sent by email or SMS.
6.2 Marketing communications
We may send offers, promotions or information about Fanal Holiday Homes where permitted by law. Where prior consent is required, marketing will only be sent after valid consent has been obtained. In limited circumstances, electronic marketing about our own similar accommodation or services may be sent to an existing customer under the applicable “soft opt-in” rules, provided the legal conditions are met.
You can object to direct marketing at any time, free of charge, by using the unsubscribe mechanism in the message or contacting us. Opting out of marketing will not stop service communications required for an existing reservation or requested service.
7. CCTV
CCTV may operate at entrances, common areas, exterior areas and other appropriate locations at or around our properties for safety, security, prevention and investigation of theft or damage, protection of people and property, investigation of accidents or complaints, and the establishment, exercise or defence of legal claims.
CCTV processing is generally based on our legitimate interests in maintaining safety and security and protecting people and property. Appropriate signage is displayed where CCTV is in use, and access to recordings is restricted to authorised persons.
| CCTV retention CCTV footage is normally retained for a maximum of 14 days and is then automatically overwritten or deleted. If footage relates to a specific accident, complaint, suspected offence, damage, insurance matter, legal claim or other incident, the relevant footage may be extracted and retained for longer where reasonably necessary to investigate the matter, comply with law, establish facts or protect legal rights. |
8. Who we may share personal data with
We do not sell personal data. Where necessary for the purposes described in this Policy, personal data may be shared with:
• property-management, reservation, booking-engine and website technology providers;
• payment processors, banks and financial-service providers;
• IT, hosting, cybersecurity, cloud, communications, analytics, website-performance, user-experience and advertising
service providers;
• digital guidebook and guest-service providers;
• online travel agencies, travel agents, tour operators and distribution partners where necessary to administer a
booking;
• accountants, auditors, insurers, insurance advisers, lawyers and other professional advisers;
• cleaning, maintenance and operational service providers only where access to limited guest information is
genuinely necessary;
• public authorities, courts, regulators or law-enforcement bodies where disclosure is required or permitted by law;
and
• a purchaser, successor or adviser in connection with a genuine corporate transaction, subject to appropriate
confidentiality and data-protection safeguards.
Some organisations act as processors on our instructions. Others, such as certain booking platforms, payment providers or travel partners, may act as independent data controllers and process personal data under their own privacy notices.
9. International transfers
Some technology, booking, payment, communications, cloud or other service providers may process personal data outside Malta or outside the European Economic Area (EEA). Where personal data is transferred to a country not covered by an applicable European Commission adequacy decision, we use or require appropriate safeguards where necessary, such as approved Standard Contractual Clauses or another lawful transfer mechanism under the GDPR.
You may contact us for further information about safeguards relevant to a particular transfer of your personal data.
10. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected and for any related legal, accounting, taxation, insurance, security or claims requirements.
Retention periods are determined by factors including the duration of the guest relationship, statutory record-keeping duties, applicable limitation periods, accounting and tax requirements, insurance requirements, the possibility of complaints or claims, and the sensitivity and security risk of the information.
| Data category | Retention approach |
| Reservation and guest records | For the period needed to administer the booking and thereafter for applicable accounting, tax, legal, operational and claims- management requirements. |
| Financial records | For the period required by applicable accounting, taxation and other legal obligations. |
| Unsuccessful enquiries | For a reasonable period after the enquiry unless a legitimate reason requires longer retention. |
| Marketing records | For as long as we have a lawful basis; a limited suppression record may be kept after opt-out so that the preference continues to be respected. |
| CCTV | Normally up to 14 days, unless relevant footage is preserved for a specific incident, complaint, investigation, insurance matter or legal claim. |
When information is no longer required, we delete, destroy or anonymise it as appropriate.
11. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful access, disclosure, alteration, loss or destruction. Measures may include access controls, authentication controls, restricted staff permissions, secure systems and networks, backups, confidentiality requirements, contractual safeguards with service providers, staff awareness and security procedures.
No electronic system can provide an absolute guarantee of security. We therefore review security measures in light of the nature of the personal data and the risks presented by the processing.
12. Children and minors
We do not knowingly collect personal data directly from children for marketing purposes. Information about children may be processed where they are included in an accommodation reservation and the information is necessary to administer the booking, determine occupancy, provide appropriate accommodation, comply with legal obligations or address safety or guest-service needs.
Where appropriate, information relating to a minor should be provided by a parent, legal guardian or another person authorised to provide it.
13. Is providing personal data mandatory?
Certain information is required so that we can respond to a booking request, enter into or perform an accommodation contract, process payment, identify the person responsible for a booking, comply with legal obligations or provide a requested service. If required information is not provided, we may be unable to accept or administer the reservation or provide the relevant service.
14. Your data-protection rights
Subject to the conditions and limitations in applicable law, you may have the following rights:
| Right | What it means |
| Access | To ask whether we process your personal data and obtain access to that data and related information. |
| Rectification | To correct inaccurate personal data or complete incomplete information. |
| Erasure | To request deletion in circumstances where the GDPR provides a right to erasure. This right is not absolute. |
| Restriction | To request restriction of processing in circumstances specified by the GDPR. |
| Data portability | Where applicable, to receive personal data you provided in a structured, commonly used and machine-readable format and have it transmitted to another controller where technically feasible. |
| Object | To object to processing based on legitimate interests for reasons relating to your particular situation, and to object at any time to direct marketing. |
| Withdraw consent | Where processing is based on consent, to withdraw it at any time without affecting processing already lawfully carried out. |
| Automated decisions | Rights in relation to solely automated decisions producing legal or similarly significant effects, where such processing applies. |
To exercise a right, contact reservations@fanalholidayhomes.com. We may request information reasonably necessary to verify your identity. We normally respond within one month of receiving a valid request, subject to any extension permitted by the GDPR for complex or multiple requests.
Data-protection requests are normally free of charge. The GDPR allows a reasonable fee or refusal in limited cases where a request is manifestly unfounded or excessive, particularly where it is repetitive.
15. Complaints to the supervisory authority
If you believe your personal data has been processed in breach of applicable data-protection law, you have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner (IDPC) in Malta:
• Office of the Information and Data Protection Commissioner
• Floor 2, Airways House, Triq Il-Kbira, Tas-Sliema SLM 1549, Malta
• Telephone: +356 2328 7100
• Website: idpc.org.mt
Where applicable, you may also have the right to complain to another competent EU or EEA supervisory authority. We encourage you to contact us first so that we can address your concern directly.
16. Cookies and similar technologies
Our website uses necessary, functional, analytics and marketing cookies and similar technologies. These support website functionality, analytics, user-experience analysis, advertising measurement and customer communications.
Non-essential technologies are used only after the relevant consent has been given through our cookie-management tool, where consent is required.
See our separate Cookies Policy for the cookies and technologies currently used, their providers, purposes and retention periods. You can use the website cookie settings to manage or withdraw your preferences.
17. Third-party websites and booking platforms
Our website and guest communications may contain links to websites or services operated by third parties. We are not responsible for the privacy practices of independently operated services. Where you book through an online travel agency, travel agent, tour operator or other third party, that organisation may independently collect and process your personal data under its own privacy notice.
18. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our services, systems, service providers, legal obligations or privacy practices. The current version will be published on our website and will show the date of the latest update.
Material changes will be communicated by additional means where required by law.
19. Contact us
Questions about this Privacy Policy or requests concerning your personal data should be addressed to:
Fanal Holiday Homes - Tal-Fanal Village Ltd
Villagg tal-Fanal, Unit 1, Triq il-Fanal, Għasri, Gozo GSR 1206, Malta | Telephone: +356 2388 9000 | Email:
reservations@fanalholidayhomes.com | Website: www.fanalholidayhomes.com