Open Sundays/Holidays: 21 Sept · 6 Dec

Privacy Policy

Last updated: August 2026

At Ta' Pinu Pharmacy, we are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR) and Maltese data protection legislation. This policy explains what personal information we collect, how we use it, and your rights regarding your data.

Data Controller

The data controller responsible for your personal data is Maria Erica Farrugia, trading as Ta' Pinu Pharmacy, of Triq Franġisk Portelli, L-Għarb, Gozo GRB 1141, Malta (VAT MT 2258 0230). Full details are on our Legal Notice page.

We have not appointed a Data Protection Officer. We are not required to have one, because we are a small practice and processing health data is not our core activity. Questions about your data go to the contact details at the bottom of this page.

The visiting healthcare professionals who hold clinics with us are responsible in their own right for the clinical records they create about you.

What Information We Collect

When you book an appointment through our online booking system or contact us, we collect the following personal information:

Personal details:

  • Full name. To identify you for your appointment.
  • Email address. To send you a booking confirmation and any updates regarding your appointment.
  • Phone number. To contact you about your appointment, and to send you SMS reminders before it.
  • ID card number. Required in order to book. It lets us identify you correctly at the clinic and keep your record separate from other patients with a similar name. If you do not have a Maltese ID card, please call us and we will book you by phone instead.
  • Notes. Anything you choose to tell us to help the clinic prepare for your visit. Please keep this to what is needed for the appointment.

Appointment details:

We also record the date and time you choose, the service you book, the healthcare professional you are booked with and, for ultrasound appointments, the type of scan you request. Because all of this is linked to your name and ID card number, it is personal data, and some of it is health data. See Health Data below.

After your appointment:

The healthcare professional you saw may record clinical notes and a fee against your booking. These notes are visible to that professional and to authorised pharmacy administrators.

Health Data

Some of the information you give us is data concerning health under Article 9 of the GDPR. This includes the clinic or specialty you book, the healthcare professional you are booked with, the type of scan you request, anything you write in the Notes field, and any clinical notes recorded by that professional after your appointment.

We process this data under Article 9(2)(h) of the GDPR, because it is necessary for the provision of health care and the management of health care services. As Article 9(3) requires, it is processed by or under the responsibility of professionals who are bound by an obligation of professional secrecy under Maltese law.

We do not rely on your consent to process health data, we do not use it for marketing, and we do not share it with anyone outside your care and the service providers listed below.

Legal Basis for Processing

We process your personal data on the following legal grounds:

Performance of a contract (Article 6(1)(b)). We use your name, contact details, ID card number and appointment details to arrange, confirm and manage the appointment you asked us for.

Provision of health care (Article 9(2)(h)). Where the information is health data, this is the condition we rely on, as explained above.

Legitimate interests (Article 6(1)(f)). We keep our booking and contact forms secure and available, and we keep a record of the messages we send you so we can tell whether a confirmation or reminder reached you.

The tick box on the booking form confirms that you have seen this notice. It is not the legal basis for the processing, so unticking it later would not undo a booking already made. If you want your data removed, see Your Rights below.

How We Use Your Information

We use your personal information to:

Manage your appointment. Scheduling it, confirming it, and handling any reschedule or cancellation.

Communicate with you. Sending your confirmation by email, sending email and SMS reminders before your appointment, and contacting you if anything changes.

Keep you on a waiting list, if you ask us to. If your preferred time is unavailable you can join a waiting list or ask to be told when new dates open. We keep your details for that purpose until we contact you, you ask us to stop, or you use the unsubscribe link in one of those emails.

Notify our own staff. When a booking is made, an internal notification is sent to the pharmacy so the clinic can prepare for your visit.

Keep a record of your care. Your booking history, and any notes recorded by the healthcare professional you saw, are kept so that the pharmacy and that professional can support your ongoing care.

We do not sell your personal information, and we do not share or disclose it to any third party for marketing purposes.

Third-Party Service Providers

We use the following providers to run our booking system. Each processes your data on our behalf, under a contract that limits what they may do with it:

ProviderWhat they doWhat they receive
Brevo
France
Privacy policy
Sends our booking emails and SMS remindersYour name, email address, phone number, ID card number, appointment details, requested scan and anything you wrote in Notes
Neon
US company, data stored in Frankfurt, Germany
Privacy policy
Hosts the database holding all booking recordsAll booking data, including health data
Vercel
US company, our site runs in Frankfurt, Germany
Privacy policy
Hosts and serves the websiteYour IP address, browser details, and the contents of any form you submit as it passes through

Google

Google is involved in two separate ways, and in neither case is it acting only on our instructions:

Our staff mailbox. The internal notification we send ourselves when you book is delivered to a mailbox hosted by Google. That notification contains your booking details.

The map.The map on our home and contact pages is provided by Google. It does not load until you press "Show map". If you do, Google receives your IP address and the page you are viewing, and uses that for its own purposes as an independent controller. You can see the pharmacy's location without loading it by using the "open in Google Maps" link instead. See Google's privacy policy.

Data Storage & Retention

Your booking information is stored in the database described above. It can be seen by authorised pharmacy administrators, and by the healthcare professional you are booked with, who sees the patients booked into their own clinic.

Our staff system also groups your bookings together into a single patient record, so that when you contact us we can see your history with us rather than one appointment at a time. Staff can look you up by name, email, phone number or ID card number. This record is only used to run your care and your bookings. It is not used for marketing, it is not shared, and no automated decision is made about you from it.

We keep different information for different lengths of time, depending on why we hold it:

WhatHow longWhy
Records of appointments you attended, including your notes and any notes the healthcare professional made10 years from the appointmentSo that your care can be followed up, and because a claim about treatment can be brought for up to this long
The same records, where the patient was under 18 at the timeUntil the patient's 25th birthday, or 10 years from the appointment, whichever is laterTime limits for claims brought on behalf of a child run from when the child turns 18, not from the appointment
Fees charged9 years from the end of the yearRequired by Maltese tax law
Appointments you cancelled or did not attend2 yearsNo treatment took place, so we only keep them long enough to resolve any dispute about the booking itself
Waiting-list entries and requests to be told about new dates12 months, or 6 months after the date you were waiting for has passedOnce we can no longer offer you the slot, there is no reason to keep your details
Our record of the emails and texts we sent you2 yearsSo we can show a confirmation or reminder was sent if that is ever in question

You can ask us to delete your data at any time, and we will unless we are required to keep it. Where an appointment has taken place, we usually cannot delete the clinical record before the period above has run, because keeping it is both part of your care and something we may need if a claim is made. If we cannot delete something, we will tell you why.

Where Your Data Is Kept

Your booking data is stored and processed inside the European Economic Area. Our database is hosted in Frankfurt, Germany, and the servers that run this website are in the same region.

Two of our providers, Neon and Vercel, are companies registered in the United States, even though the data itself stays in Germany. That means their staff may be able to access it from outside the EEA for support and maintenance. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, which is the safeguard required by Articles 44 to 49 of the GDPR. Brevo, which sends our emails and SMS messages, is established in France.

If you press "Show map", Google will receive your IP address, and Google may process that outside the EEA under its own safeguards. Nothing about your booking is sent to Google when you do this.

Children's Information

Some of our clinics are for children, including paediatric hip scans for babies. Appointments for anyone under 18 must be booked by a parent or legal guardian, who gives us the child's details and agrees to our terms on the child's behalf.

We handle a child's information the same way we handle an adult's, and on the same legal grounds. We never use it for marketing, and we never use it to build a profile. Because we do not rely on consent to process booking data, the separate GDPR rule about the age at which a child can consent online does not decide anything here.

A parent or guardian can exercise a young child's data protection rights for them. From the age of 14, Maltese law lets a young person consent to their own healthcare where the professional treating them judges that they understand it. Where that applies, what the young person tells the clinician is theirs, and we may not be able to release all of it to a parent. If that situation comes up we will explain it at the time.

If you believe we hold information about a child that we should not, please contact us and we will look into it.

Security

We take the following measures to protect your information:

Encryption in transit. The whole website, including the booking form, is served over HTTPS, so what you send us is encrypted on the way.

Restricted access. The pharmacy area of this site requires a username and password. Passwords are stored only as a cryptographic hash, never in a readable form. Healthcare professionals can see the patients booked into their own clinics, not the whole database.

Links in your emails. The link that lets you manage, reschedule or cancel your appointment contains a long random code unique to that booking. Anyone with that link can view and change that one appointment, so please do not forward your confirmation email to anyone you would not want to see it.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information and Data Protection Commissioner within 72 hours, and tell you directly where the law requires it.

Cookies & Browser Storage

Browsing this website as a patient does not set any cookies. We do store a small number of preferences in your own browser, such as whether you have dismissed a notice. Cookies are used only on the staff login area. We do not use analytics, advertising or marketing cookies, and we do not track you across other websites. For the full list, please see our Cookie Policy.

Your Rights Under GDPR

Under the General Data Protection Regulation, you have the following rights regarding your personal data:

Right of access — you can request a copy of the personal data we hold about you.

Right to rectification — you can request correction of any inaccurate or incomplete information.

Right to erasure — you can request deletion of your personal data where there is no compelling reason for us to continue processing it.

Right to restrict processing — you can request that we limit how we use your data.

Right to data portability — you can request your data in a structured, commonly used format.

Right to object — you can object to processing of your personal data in certain circumstances.

Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us and we will respond within 30 days.

Right to Complain

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC), Malta's supervisory authority for data protection:

Office of the Information and Data Protection Commissioner

Website: idpc.org.mt

Contact Us

If you have any questions about this privacy policy or how we handle your data, please don't hesitate to reach out:

Ta' Pinu Pharmacy

Email: info@tapinupharmacy.com

Phone: +356 2788 8128 or +356 9953 9112

Or visit our contact page.