GOZOLT Back to website
PRIVACY & DATA PROTECTION

Privacy, clearly explained.

This notice explains how the current GOZOLT public website preview handles information. Live accounts, bookings, payments and app services will use service-specific privacy notices before personal data is collected.

Last updated: 29 September 2026

The current preview is data-minimised

The website does not intentionally set analytics or advertising cookies, create user accounts, transmit details entered in preview booking forms, or request payment-card information. Preview form details remain in the browser tab and are cleared when the dialog closes or the page is left.

Who is responsible

Primooo Global Ltd operates GOZOLT and is the controller for personal data it decides to process.

No 270, Carmel Street, Opp to Lidl, 270, Luqa LQA 1311, Malta
Telephone: +356 9957 5559

Information processed now

  • Technical security logs: the hosting provider may record IP address, browser information, request time and requested page to operate and protect the service.
  • Direct enquiries: if you call or choose an email link, information you provide is processed to answer your request.
  • External maps: Google Maps loads only after you choose the external link; it is not embedded automatically.

Purposes and legal bases

  • Operating, securing and troubleshooting the website: legitimate interests in service security and availability.
  • Responding to an enquiry: steps requested by you, legitimate interests, or contract-related communication as applicable.
  • Meeting legal, regulatory and fraud-prevention duties: compliance with legal obligations.

Cookies and similar technology

The current GOZOLT website code does not intentionally use analytics, advertising or profiling cookies. If non-essential technologies are introduced, they must remain disabled until an appropriate consent choice is made.

Live services and payment information

Before a live service collects personal information, GOZOLT must provide a clear notice covering the exact purpose, lawful basis, recipients and retention period. Data collection should be limited to what the selected service needs.

Raw card numbers, expiry dates and CVV codes must not be collected by this static website or sent by email. Production card entry must be supplied by a PCI DSS-compliant payment provider using a provider-hosted payment page or equivalent tokenised solution. GOZOLT systems should receive only the minimum payment token and transaction status needed to manage an order.

Sharing and international transfers

Personal data should be shared only with service providers and partners that need it for the stated purpose, under appropriate contracts and security obligations. Data is not sold. Transfers outside the EEA must use an applicable adequacy decision or recognised safeguards such as Standard Contractual Clauses.

Retention and security

Personal data should be kept only for documented service, legal, accounting, dispute and security needs, then securely deleted or anonymised. Appropriate technical and organisational measures must be reviewed according to risk, including encryption, access control, logging, backups, incident response and supplier oversight.

Your GDPR rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where consent is the legal basis. Identity may need to be verified before a request is fulfilled.

Questions and complaints

Use the GOZOLT contact details above for a privacy request. You may also complain to Malta’s Information and Data Protection Commissioner.

Changes to this notice

This notice will be updated when live accounts, bookings, rewards, location services, support tools or payments are introduced. Material changes should be communicated clearly before they apply.