Skip to content Skip to footer

Privacy Policy

Privacy Policy
Last Updated: June 8, 2025
 
GM Pharma Ltd (“we,” “us,” or “our”) is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Maltese Data Protection Act 2018, and other applicable laws. This Privacy Policy explains how we collect, use, share, and protect your personal data when you visit our website at derophanpharmacy.mt or use our services.
 
1. Data Controller
We, GM Pharma Ltd, are the data controller responsible for your personal data. Our details are:
  • Legal Name: GM Pharma Ltd
  • Address: DeRohan Pharmacy, 24 St Anthony Street, Żebbuġ, Malta
  • Email: info@grimapharma.eu 
For data protection inquiries, please contact us at the email address above.
 
2. Personal Data We Collect
We collect the following categories of personal data:
  • Identity and Contact Data: Name, email address, phone number (e.g., when you contact us or make a purchase).
  • Technical Data: IP address, browser type, device information, and browsing behaviour (e.g., pages visited, time spent).
  • Marketing and Analytics Data: Preferences, interactions with ads, and website usage data collected via cookies or similar technologies.
  • Transaction Data: Details of purchases or services you request (e.g., order history, payment information).
We do not process special categories of data (e.g., health data) unless explicitly stated and with your consent. If we process children’s data (under 13 in Malta), we will obtain verifiable parental consent as required by law.
 
3. How We Collect Data
We collect data:
  • Directly from you: When you fill out forms, make purchases, or contact us.
  • Automatically: Via cookies, Google Consent Mode, Meta Pixel, and other tracking technologies when you visit our website.
  • From third parties: From analytics providers (e.g., Google Analytics) or advertising partners (e.g., Meta) for retargeting and statistics.
4. Purposes and Legal Basis for Processing
We process your personal data for the following purposes and legal bases under GDPR Article 6:
Purpose
Data Used
Legal Basis
To
provide
our
services
(e.g.,
process
orders)
Identity,
contact,
transaction
data
Performance
of
a
contract
(Art.
6(1)(b))
To
improve
our
website
and
services
Technical,
analytics
data
Legitimate
interests
(Art.
6(1)(f))
to
enhance
user
experience
To
deliver
personalized
ads
(e.g.,
Meta
retargeting)
Marketing,
technical
data
Consent
(Art.
6(1)(a))
To
analyze
website
usage
(statistics
via
Google
Analytics)
Technical,
analytics
data
Consent
(Art.
6(1)(a))
or
legitimate
interests
(Art.
6(1)(f))
To
send
marketing
communications
Identity,
contact
data
Consent
(Art.
6(1)(a))
 
5. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyse usage, and deliver personalised ads. These include:
  • Strictly Necessary Cookies: Essential for website functionality.
  • Analytics Cookies: To collect statistics on website usage (e.g., via Google Analytics with Google Consent Mode).
  • Advertising Cookies: To deliver personalised ads via Meta Pixel for retargeting and Google Ads.
We use Google Consent Mode v2 to manage consent for analytics (analytics_storage) and advertising (ad_storage). You can manage your cookie preferences through our consent management platform on our website. For more details, see our Cookies Policy .
 
You can opt out of personalised ads via:
6. Sharing Your Data
We share your personal data with:
  • Third-Party Processors: Service providers acting on our instructions, such as payment processors, hosting providers, or analytics tools (e.g., Google Analytics).
  • Advertising Partners: Google (for ads and analytics) and Meta (for retargeting via Meta Pixel).
  • Legal Authorities: If required by law or to protect our rights.
7. International Data Transfers
Your data may be transferred to third countries (e.g., the US for Google and Meta services). We ensure compliance with GDPR Chapter V through:
  • Standard Contractual Clauses (SCCs) with third parties.
  • The EU-US Data Privacy Framework (where applicable).
8. Your GDPR Rights
Under GDPR, you have the following rights:
  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate data.
  • Erasure: Request deletion of your data.
  • Restriction: Limit how we process your data.
  • Data Portability: Receive your data in a structured format.
  • Object: Object to processing based on legitimate interests (e.g., marketing).
  • Withdraw Consent: Withdraw consent at any time (e.g., for cookies or marketing).
To exercise your rights, contact us at info@grimapharma.eu. We will respond within one month, as required by GDPR.
You can also lodge a complaint with the Information and Data Protection Commissioner (IDPC) in Malta:
  • Address: Floor 2, Airways House, High Street, Sliema, SLM 1549, Malta
  • Email: idpc.info@idpc.org.mt (mailto:idpc.info@idpc.org.mt)
9. Data Retention
We retain personal data only as long as necessary:
  • Transaction Data: Kept for 2 years to comply with legal obligations.
  • Analytics Data: Kept for 2 years per Google Analytics settings.
  • Marketing Data: Kept until you withdraw consent or opt out.
Data is securely deleted or anonymised when no longer needed.
 
10. Data Security
We implement technical and organisational measures to protect your data, including:
  • Encryption (e.g., SSL on our website).
  • Access controls to limit data access.
  • Regular security assessments.
In case of a data breach, we will notify the IDPC within 72 hours and affected users as required by GDPR Article 33.
 
11. Policy Updates
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Updates will be posted on our website, and significant changes will be communicated via email or a website notice.
 
12. Contact Us
For questions or concerns about this Privacy Policy, contact us at:
  • Email: info@grimapharma.eu (mailto:info@grimapharma.eu)
  • Address: GM Pharma Ltd, DeRohan Pharmacy, 24 St Anthony Street, Żebbuġ, Malta