Privacy, clearly explained.
This notice explains how the current GOZOLT public website preview handles information. Live accounts, bookings, payments and app services will use service-specific privacy notices before personal data is collected.
Last updated: 29 September 2026The current preview is data-minimised
The website does not intentionally set analytics or advertising cookies, create user accounts, transmit details entered in preview booking forms, or request payment-card information. Preview form details remain in the browser tab and are cleared when the dialog closes or the page is left.
Who is responsible
Primooo Global Ltd operates GOZOLT and is the controller for personal data it decides to process.
No 270, Carmel Street, Opp to Lidl, 270, Luqa LQA 1311, Malta
Telephone: +356 9957 5559
Information processed now
- Technical security logs: the hosting provider may record IP address, browser information, request time and requested page to operate and protect the service.
- Direct enquiries: if you call or choose an email link, information you provide is processed to answer your request.
- External maps: Google Maps loads only after you choose the external link; it is not embedded automatically.
Purposes and legal bases
- Operating, securing and troubleshooting the website: legitimate interests in service security and availability.
- Responding to an enquiry: steps requested by you, legitimate interests, or contract-related communication as applicable.
- Meeting legal, regulatory and fraud-prevention duties: compliance with legal obligations.
Cookies and similar technology
The current GOZOLT website code does not intentionally use analytics, advertising or profiling cookies. If non-essential technologies are introduced, they must remain disabled until an appropriate consent choice is made.
Live services and payment information
Before a live service collects personal information, GOZOLT must provide a clear notice covering the exact purpose, lawful basis, recipients and retention period. Data collection should be limited to what the selected service needs.
Raw card numbers, expiry dates and CVV codes must not be collected by this static website or sent by email. Production card entry must be supplied by a PCI DSS-compliant payment provider using a provider-hosted payment page or equivalent tokenised solution. GOZOLT systems should receive only the minimum payment token and transaction status needed to manage an order.
Sharing and international transfers
Personal data should be shared only with service providers and partners that need it for the stated purpose, under appropriate contracts and security obligations. Data is not sold. Transfers outside the EEA must use an applicable adequacy decision or recognised safeguards such as Standard Contractual Clauses.
Retention and security
Personal data should be kept only for documented service, legal, accounting, dispute and security needs, then securely deleted or anonymised. Appropriate technical and organisational measures must be reviewed according to risk, including encryption, access control, logging, backups, incident response and supplier oversight.
Your GDPR rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where consent is the legal basis. Identity may need to be verified before a request is fulfilled.
Questions and complaints
Use the GOZOLT contact details above for a privacy request. You may also complain to Malta’s Information and Data Protection Commissioner.
Changes to this notice
This notice will be updated when live accounts, bookings, rewards, location services, support tools or payments are introduced. Material changes should be communicated clearly before they apply.
Back to website