Back to home

Privacy Policy

Last updated: Effective date:

Learn how Property Decision Support collects, uses, stores and protects your personal information.

This Privacy Policy explains how Property Decision Support t/a Hartmut Goldau collects, uses, stores and protects personal data when visitors use this website, contact the provider, book a service, make a payment or receive a property-related service.

1. Data controller

The controller responsible for this website and the related services is:

Property Decision Support t/a Hartmut Goldau


Address: Triq L-Imgarr, IX-Xewkija, XWK 9017, Gozo, Malta
Email: info@propertydecisionsupport.com

For privacy questions or data protection requests, please contact:

info@propertydecisionsupport.com

Unless stated otherwise, no data protection officer has been appointed.

2. Personal data

The provider may collect and process the following types of personal data:

  • name;
  • email address;
  • phone number;
  • booking reference;
  • payment reference and payment status;
  • selected service and price paid;
  • appointment details;
  • property address, property link and property information;
  • property access details where needed for the booked service;
  • customer notes, concerns and supplied details;
  • refund or cancellation request details;
  • property-focused photos, videos, notes or audio notes where needed for service delivery;
  • information included in customer-supplied property documents or property-related communication;
  • email delivery and communication metadata;
  • technical website data;
  • cookie and consent preferences;
  • security and anti-spam verification data.

Personal data may also include information about other persons where such information is included in customer-supplied property materials, communications or media. For example, this may include names, contact details, visible persons, neighbours, tenants, agents, sellers, buyers or other third parties if such information is provided by the customer or appears in property-related material.

The provider does not intentionally collect full payment card details through the website. Card details are handled by the payment provider Stripe.

3. Third-party data supplied by customers

Customers should only provide personal data relating to other persons where this is necessary for the requested service and where they are entitled to share that information.

Customers should avoid sending unnecessary personal data, sensitive information, private family information, unrelated documents, images of people, children, neighbours, vehicle registration plates or personal belongings unless reasonably required for the booked service.

Where a customer provides information about another person, the customer is responsible for ensuring that the information has been provided lawfully.

4. Special category data

The provider does not intentionally request special category personal data, such as health data, biometric data, religious beliefs, political opinions or similar sensitive information.

Customers should not provide such information unless it is strictly necessary for the service or specifically requested. If such information is provided incidentally, it will be handled only where necessary and in accordance with applicable data-protection law.

5. Why personal data is used

Personal data may be used to:

  • provide and maintain the website;
  • respond to enquiries;
  • process payments;
  • send service and booking communication;
  • schedule and manage appointments;
  • prepare and deliver the booked service;
  • prepare notes, action lists, reports or other service materials;
  • review property-related information provided by the customer;
  • process refund and cancellation requests;
  • prevent spam, fraud and abuse;
  • keep accounting, tax and business records;
  • comply with legal obligations;
  • protect legal rights;
  • improve the website and booking flow where analytics is enabled and consent is required and given.

7. Contact and enquiry data

Contact form submissions may include name, email address, phone number, topic, message content and technical or security information.

This information is used to respond to the enquiry, manage customer communication and protect against spam or abuse.

8. Payment data

Payments are processed by Stripe.

The provider may store limited payment-related information such as customer email, booking reference, selected service, amount paid, payment status, payment date and payment references.

This information is used to confirm payment, manage bookings, provide support, process refunds and keep business records.

Full payment card details are processed by Stripe and are not intentionally collected or stored by the provider through the website.

9. Booking and appointment data

Appointment scheduling may be handled through Cal.eu, Cal.com or another scheduling provider.

Booking and appointment data may include name, email address, phone number, appointment time, selected service, property access details and other information needed to provide the service.

This information is used to schedule, confirm, manage, reschedule or cancel appointments and to prepare the booked service.

10. Service information and property media

Customers may provide property information before, during or after the service.

During an on-site visit, the provider may collect property-focused photos, short videos, notes or audio notes where reasonably needed to provide the booked service.

Property media is collected for service-related purposes, such as documenting visible conditions, preparing service notes, preparing reports, supporting customer communication and protecting legal rights.

The provider does not intentionally collect private household information that is unrelated to the service. Customers should remove or avoid unnecessary personal items, personal documents, images of people or other private information where possible.

Further details are explained in the Documentation & Media Consent page.

11. Refund and cancellation data

Refund or cancellation requests may include booking reference, checkout email, message content, request reason and related communication.

This information is used to verify and review the request, respond to the customer, process any approved refund and keep records where required.

12. Transactional emails

Transactional emails may be sent through Resend or another email service provider.

These may include payment, booking, appointment, service, refund, cancellation and support communication.

Transactional emails are used to provide the service and manage customer requests. They are not marketing emails.

13. Website security and anti-spam

Cloudflare Turnstile or similar tools may be used to protect forms and website flows from spam, bots and abuse.

These tools may process technical information about the browser, device and interaction to check whether a request is legitimate.

This processing is used to protect the website, the provider and visitors from abuse, automated attacks, spam and fraud.

14. Hosting and content management

The website may be hosted by Vercel or another hosting provider.

Website content may be managed through Sanity or another content management provider.

These providers may process technical, hosting, infrastructure or content-related data as needed to operate, maintain and secure the website.

16. AI-assisted processing

The provider may use digital tools, including transcription, summarisation or AI-assisted drafting tools, to organise customer notes, property information, photos, videos, audio notes or service materials.

These tools are used to support service delivery, internal organisation and report preparation. They do not replace the provider’s professional judgement.

Where possible, the provider avoids sending unnecessary personal data, payment data, private documents or unrelated personal information to such tools.

The provider does not use customer property materials for public marketing, model training or unrelated purposes without consent or another lawful basis.

17. Service providers

The provider may share personal data with service providers only where needed for the purposes described in this Privacy Policy.

  • Current or planned providers may include:
  • Stripe for payment processing and refunds;
  • Cal.eu / Cal.com for appointment scheduling;
  • Resend for transactional email delivery;
  • Cloudflare Turnstile for spam and bot protection;
  • Vercel for hosting and infrastructure;
  • Sanity for content management;
  • c15t for consent management;
  • PostHog for analytics where enabled;
  • transcription, productivity, storage or AI-assisted tools where needed for service delivery, internal organisation or report preparation.

The provider does not sell personal data.

18. International transfers

Some service providers listed above may process, store or access personal data outside Malta or the European Economic Area.

This can happen because online tools may use servers, support teams, subprocessors or group companies in other countries.

Where personal data is transferred outside the EEA, the provider relies on appropriate safeguards where required by law. These may include an adequacy decision, EU standard contractual clauses, provider data-processing terms or another lawful transfer mechanism.

Customers may contact the provider to request further information about the transfer safeguards used for relevant service providers.

19. Retention

Personal data is kept only for as long as needed for the purposes described in this Privacy Policy.

Retention depends on the type of data and the reason it is held:

  • enquiry and support messages are kept for as long as needed to respond and manage the relationship;
  • booking, payment, refund and accounting records are kept for the period required by tax, accounting and legal obligations;
  • service information, notes and property media are kept for as long as needed to deliver the service, handle follow-up, support quality control and protect legal rights;
  • cookie and consent records are kept for as long as needed to manage and prove consent choices;
  • technical security records are kept only for as long as needed to protect the website and investigate abuse.

Where exact retention periods cannot be stated in advance, retention is determined by the nature of the data, the service relationship, legal obligations, limitation periods, dispute risk and the need to protect legal rights.

Data may be kept longer where required by law, an active dispute, fraud prevention, accounting obligations or legal protection.

20. Customer rights

Subject to applicable law, customers and website visitors may have the right to:

  • access their personal data;
  • correct inaccurate personal data;
  • request deletion;
  • restrict processing;
  • object to processing;
  • request data portability;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta.

To make a privacy request, contact:

info@propertydecisionsupport.com

The provider may need to verify identity before responding.

Some rights may be limited where the provider has legal obligations, accounting obligations, contractual obligations, dispute-related reasons or other lawful grounds to keep or process the relevant data.

21. No solely automated decisions

The provider does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning the customer or similarly significantly affect the customer.

Any service output, note, checklist, report or recommendation is prepared or reviewed with human involvement.

22. Security

The provider uses appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or disclosure.

Access to personal data is limited to authorised persons and service providers where necessary.

While reasonable steps are taken to protect personal data, no method of internet transmission, email communication or electronic storage can be guaranteed to be completely secure.

23. Updates

This Privacy Policy may be updated from time to time.

The latest version will be published on this website with the updated date shown above.

Where changes are material and legally required, the provider may take additional steps to inform affected customers or visitors.