Privacy Policy Malta

Effective date: 19th day of August 2026
Last reviewed: 19th day of August 2026

 

  1. Who we are

 

1.1 CapServices Limited is a company registered in Malta with company registration number C 84084 and registered office at The Hub Annex, Triq Sant’ Andrija, San Ġwann, SGN 1612, Malta (“CapServices”, “we”, “us” or “our”).

1.2 CapServices is a Class C company service provider. CapServices is authorised to provide the company services falling within the scope of its authorisation. Authorised to act as a Company Service Provider by the Malta Financial Services Authority.

1.3 For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Data Protection Act, Chapter 586 of the Laws of Malta, CapServices is the controller of the personal data described in this Privacy Notice, except where this Notice expressly states otherwise.

1.4 References on our website to Capricorn Group, CapConnect or any other affiliated business do not mean that all such businesses form a single legal entity or act as a single controller. Each company is a separate legal entity. Where another group company collects or uses personal data as a controller, it is responsible for providing the relevant privacy information.

1.5 Questions about this Privacy Notice or the use of personal data may be sent to:

Privacy contact:
Email: info@capservicesmalta.com
Postal address: The Hub Annex, Triq Sant’ Andrija, San Ġwann, SGN 1612, Malta
Telephone: +356 27374531

CapServices should not describe a person as its “Data Protection Officer” unless a Data Protection Officer (DPO) has been formally appointed.

 

  1. Scope of this Privacy Notice

 

2.1 This Privacy Notice explains how we collect and use personal data relating to:

(a) visitors to www.capservicesmalta.com and any replacement or related website operated by CapServices;

(b) persons who contact us or submit an enquiry;

(c) prospective, current and former clients;

(d) directors, company secretaries, shareholders, beneficial owners, officers, authorised representatives and employees of clients or prospective clients;

(e) suppliers, professional advisers, business contacts, introducers and other persons with whom we interact; and

(f) any other individual whose personal data we process in connection with our business or legal and regulatory obligations.

2.2 “Personal data” means information relating to an identified or identifiable natural person. Information relating to a company or other legal entity may also constitute personal data where it identifies, or can be linked to, an individual connected with that entity.

2.3 This Privacy Notice applies to CapServices’ processing as a controller. If we process personal data solely on documented instructions from a client and as that client’s processor, the client remains responsible for providing the relevant privacy information to the individuals concerned.

2.4 Our website and services are not directed at children. We do not knowingly collect children’s personal data through the website. We may nevertheless process information concerning minors where this is necessary in connection with a client structure, ownership, inheritance, family relationship or legal or regulatory requirement.

 

  1. Personal data we collect

 

Depending on the nature of our relationship with you, we may collect the following categories of personal data.

3.1 Identification and contact information, including name, previous names, signature, date and place of birth, nationality, citizenship, residential and correspondence address, email address, telephone number, government-issued identification details and copies, photographs and proof of address.

3.2 Professional and relationship information, including occupation, employer, job title, curriculum vitae, professional qualifications, business activities, directorships, company secretarial appointments, shareholdings, authorised signatory status and your relationship with a client or prospective client.

3.3 Company and ownership information, including details of shareholders, members, directors, company secretaries, beneficial owners, controllers, protectors, settlors, trustees, beneficiaries, authorised representatives and other persons associated with a company, partnership, trust, foundation or other structure.

3.4 Financial and tax information, including bank account details, payment information, tax identification numbers, tax residence, financial statements, source of wealth, source of funds, income, assets and transaction information where this is required for the proposed or existing relationship.

3.5 Due diligence and compliance information, including information obtained for customer due diligence, sanctions screening, politically exposed person screening, adverse-media screening, fraud prevention, risk assessment and ongoing monitoring.

3.6 Where permitted or required by law, compliance information may include information concerning alleged or actual criminal offences, convictions, regulatory investigations, sanctions, disqualifications, insolvency, litigation or other matters relevant to our legal and regulatory obligations.

3.7 Service and engagement information, including requested services, letters of engagement, instructions, corporate and statutory records, filings, minutes, resolutions, correspondence, invoices, complaints and records of services provided.

3.8 Communications information, including emails, letters, meeting notes, telephone records and other communications with us. We will notify you if a call is to be recorded.

3.9 Website and technical information, including Internet Protocol address, browser type and version, device information, operating system, time zone, referral source, pages visited, dates and times of access, cookie identifiers and website interaction information.

3.10 Marketing information, including your communication preferences, event participation and records of whether you have opened or interacted with a communication, where such tracking is lawfully used.

3.11 Any other personal data that you voluntarily give us or that is reasonably necessary for the purpose for which it is collected.

 

  1. How we obtain personal data

 

4.1 We may obtain personal data:

(a) directly from you;

(b) from a client, prospective client, your employer, a company or structure with which you are associated, or another person acting on your behalf;

(c) from group companies, introducers, professional advisers, financial institutions, auditors and service providers;

(d) from the Malta Business Registry, courts, regulators, government authorities, tax authorities and other official registers or sources;

(e) from identity-verification, sanctions-screening, politically exposed person screening, adverse-media and other compliance service providers;

(f) from publicly available sources, including company websites, professional directories, news media and online sources; and

(g) automatically when you use our website, including through cookies and similar technologies.

4.2 Where another person gives us your personal data, we expect that person to be authorised to do so and, where required, to have made this Privacy Notice available to you.

 

  1. Why we use personal data and our legal bases

 

5.1 Enquiries and pre-contractual steps

We use personal data to respond to enquiries, assess whether we can provide a requested service, prepare a proposal and take steps requested before entering into an engagement.

Where you are the proposed contracting party, the legal basis is Article 6(1)(b) GDPR. Where you act for a company or another person, the legal basis is our legitimate interest under Article 6(1)(f) GDPR in communicating with representatives and developing our business.

5.2 Client onboarding and acceptance

We use personal data to:

(a) identify and verify clients, beneficial owners, directors, officers and other relevant persons;

(b) conduct conflict checks;

(c) assess the nature, purpose and risk of a proposed relationship;

(d) carry out sanctions, politically exposed person and adverse-media screening;

(e) establish source of funds and source of wealth where required; and

(f) decide whether we may establish or continue a business relationship.

This processing is necessary to comply with legal and regulatory obligations under Article 6(1)(c) GDPR and for our legitimate interests under Article 6(1)(f) GDPR in protecting our business and accepting clients responsibly.

5.3 Provision and administration of services

We use personal data to establish, administer and provide company services and any separately agreed ancillary services; communicate with clients and their representatives; maintain corporate and statutory records; make authorised filings; issue invoices; receive payments; manage instructions; and administer our relationship with a client.

The applicable legal bases are performance of a contract or pre-contractual steps under Article 6(1)(b) GDPR, compliance with legal obligations under Article 6(1)(c) GDPR and our legitimate interests under Article 6(1)(f) GDPR in administering our business and communicating with representatives of corporate clients.

5.4 Legal and regulatory compliance

We use personal data to comply with obligations arising under applicable company-service-provider, company, beneficial-ownership, anti-money-laundering, counter-terrorist-financing, sanctions, tax, accounting and other laws, regulations, rules and binding requirements. This includes obligations under the Company Service Providers Act, the MFSA Company Service Providers Rulebook, the Prevention of Money Laundering Act, the Prevention of Money Laundering and Funding of Terrorism Regulations and applicable FIAU Implementing Procedures.

The legal basis is Article 6(1)(c) GDPR. Where special-category personal data are processed, we will rely on an additional condition permitted by Article 9 GDPR and applicable Maltese law. Information concerning criminal offences or convictions will be processed only where permitted by Article 10 GDPR and applicable law.

5.5 Security, fraud prevention and protection of rights

We use personal data to maintain the security of our systems, premises and records; authenticate communications and instructions; prevent or investigate fraud, misuse and security incidents; establish, exercise or defend legal claims; obtain legal advice; and protect our rights, property and interests or those of our clients and other persons.

The legal bases are compliance with legal obligations and our legitimate interests in operating securely, preventing fraud and protecting or enforcing legal rights.

5.6 Complaints, quality assurance and regulatory enquiries

We use personal data to investigate and respond to complaints, improve our services, maintain complaint records, cooperate with regulatory authorities and demonstrate compliance.

The legal bases are compliance with legal and regulatory obligations and our legitimate interests in resolving complaints and improving our services.

5.7 Website operation and analytics

We use technical information to operate, secure and troubleshoot the website. Strictly necessary cookies and comparable technologies are used where required for the website to function or remain secure.

We use optional analytics, preference, advertising or similar technologies only after obtaining consent where consent is required. Further details are provided in our Cookie Policy.

5.8 Marketing and business communications

We may send information about CapServices’ services, events or developments where you have asked to receive it, consented to receive it, or where applicable electronic-marketing law otherwise permits us to do so.

Where consent is required, the legal basis is Article 6(1)(a) GDPR. In limited business-contact situations where marketing is legally permitted without consent, we may rely on our legitimate interest in developing our business. You may object to direct marketing or withdraw consent at any time.

5.9 Consent

Where we rely on consent, the consent request will identify the relevant purpose. Consent may be withdrawn at any time. Withdrawal does not affect processing carried out lawfully before consent was withdrawn.

5.10 Automated decision-making

CapServices does not currently make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect individuals. If this changes, we will provide the information and safeguards required by law before carrying out such processing.

 

  1. Information we require from you

 

6.1 Some personal data are required by law, by our regulatory obligations or in order for us to consider or perform an engagement.

6.2 If requested information is not provided, or cannot be verified to our satisfaction, we may be unable to commence or continue an engagement, provide a requested service, accept an instruction or complete a transaction. We may also be required to suspend or terminate a relationship or take other action required by law.

6.3 You must ensure that information provided to us is accurate, complete and current and notify us promptly of relevant changes.

 

  1. Who we disclose personal data to

 

7.1 Where necessary for the purposes described in this Privacy Notice, we may disclose personal data to:

(a) the Malta Financial Services Authority, Financial Intelligence Analysis Unit, Malta Business Registry, Commissioner for Revenue, courts, law-enforcement bodies and other competent authorities;

(b) banks, payment service providers, insurers and financial institutions;

(c) auditors, lawyers, tax advisers, accountants, notaries and other professional advisers;

(d) information-technology, website-hosting, cloud-storage, communications, document-management, security, archiving and business-continuity providers;

(e) identity-verification, screening, fraud-prevention, compliance and due-diligence providers;

(f) couriers, registered-office facility providers and other suppliers involved in delivering an agreed service;

(g) another group company where that company is involved in an enquiry, referral or service and the disclosure is lawful and necessary;

(h) a purchaser, investor, successor or adviser in connection with a proposed or completed sale, merger, reorganisation or transfer of all or part of our business, subject to appropriate confidentiality safeguards;

(i) a person to whom disclosure is authorised by the relevant client or individual; and

(j) any other person where disclosure is required or permitted by law.

7.2 We disclose only the personal data reasonably necessary for the relevant purpose. Service providers acting as processors are required to process personal data only on appropriate instructions, maintain confidentiality and apply suitable security measures.

7.3 We will not sell personal data.

7.4 An introducer will not automatically receive information concerning your relationship with us. We will disclose information to an introducer only where this is authorised, legally permitted and necessary for an identified purpose.

 

  1. International transfers

 

8.1 We will seek to keep personal data within the European Economic Area (“EEA”) where reasonably practicable. Some suppliers, professional advisers, counterparties or authorities may nevertheless be located outside the EEA or may access information from outside the EEA.

8.2 Where personal data are transferred outside the EEA, we will ensure that an appropriate transfer mechanism is used where required. This may include:

(a) a European Commission adequacy decision;

(b) European Commission standard contractual clauses, together with any necessary supplementary measures;

(c) a legally permitted derogation for a specific situation; or

(d) another transfer mechanism permitted by applicable data-protection law.

8.3 You may contact us for further information about the safeguards applicable to a relevant transfer. Some details may be withheld where necessary to protect confidentiality, security or legal privilege.

 

  1. How long we retain personal data

 

9.1 We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to satisfy applicable legal, regulatory, accounting, reporting and claims requirements.

9.2 The criteria used to determine a retention period include the nature and sensitivity of the information, the purposes of processing, the duration of the relationship, regulatory and limitation periods, legal-preservation requirements and the risk of harm arising from unauthorised use or disclosure.

9.3 Subject to any longer or shorter period required by law or a competent authority, the following principles apply:

(a) client, customer-due-diligence and service records are generally retained for at least five years after the end of the relevant business relationship or the completion of the relevant transaction, and may be retained longer where required or permitted by law or by a competent authority;

(b) corporate and statutory records may need to be retained for the life of the relevant entity and for an additional legally required period;

(c) accounting, tax, contractual and payment records are retained for the applicable statutory, regulatory and limitation periods;

(d) complaint and legal-claim records are retained for the period necessary to handle the matter and protect legal rights;

(e) unsuccessful enquiries and onboarding records are retained for a period of five (5) years, unless a longer period is required for compliance, fraud prevention or legal claims;

(f) marketing information is retained until you opt out or the information is no longer needed. A minimal suppression record may be retained so that an opt-out can continue to be respected; and

(g) website logs and cookie information are retained for the periods disclosed in our Cookie Policy or cookie settings facility.

9.4 Personal data may be retained for longer where litigation, an investigation, a regulatory direction, a legal hold or another lawful reason requires this.

9.5 At the end of the applicable period, information will be securely deleted, anonymised or placed beyond ordinary use in accordance with our retention procedures.

 

  1. Security

 

10.1 We use appropriate technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

10.2 These measures may include access controls, authentication, encryption or secure transmission where appropriate, system monitoring, backups, staff confidentiality obligations, supplier controls and incident-response procedures.

10.3 No Internet transmission or information-storage system can be guaranteed to be completely secure. You should avoid sending sensitive information through an insecure channel and should promptly tell us if you suspect that a communication, account or instruction has been compromised.

 

  1. Your data-protection rights

 

11.1 Subject to the conditions, exceptions and restrictions in applicable law, you may have the right to:

(a) obtain confirmation as to whether we process your personal data and request access to that data and associated information;

(b) have inaccurate personal data corrected and incomplete data completed;

(c) request deletion of personal data where there is no continuing lawful reason to retain it;

(d) request restriction of processing in the circumstances provided by law;

(e) receive personal data you provided to us in a structured, commonly used and machine-readable format, and request its transmission to another controller, where processing is based on consent or contract and carried out by automated means;

(f) object to processing based on legitimate interests, including profiling based on those interests;

(g) object at any time to processing for direct-marketing purposes;

(h) withdraw consent at any time where processing is based on consent;

(i) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where legally permitted and accompanied by appropriate safeguards; and

(j) lodge a complaint with a competent data-protection supervisory authority.

11.2 The right to erasure is not absolute. We may retain information where processing remains necessary for compliance with a legal obligation, the establishment, exercise or defence of legal claims or another lawful reason.

11.3 An objection based on your particular situation is also not absolute, except in relation to direct marketing. We may continue processing if we demonstrate compelling legitimate grounds which override your interests, rights and freedoms or if processing is required for legal claims.

 

  1. Exercising your rights

 

12.1 Requests may be submitted using the contact details in Clause 1.5.

12.2 We may request information needed to verify your identity and clarify the request. This is intended to prevent unauthorised disclosure or alteration of personal data.

12.3 We will normally respond within one month of receiving a valid request. Where a request is complex or numerous requests have been made, the period may be extended by up to two further months. If an extension is required, we will inform you within the initial one-month period.

12.4 Rights requests are normally handled without charge. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable fee or refuse to act, as permitted by law.

12.5 Certain rights may be restricted where this is necessary and permitted by law, including for anti-money-laundering, prevention or detection of crime, regulatory, confidentiality, legal-privilege or legal-claims purposes. We may also be legally restricted from informing you about certain reports, investigations or disclosures.

 

  1. Complaints to the data-protection authority

 

13.1 Please contact us first if you have a concern about our use of personal data so that we can try to resolve it.

13.2 You also have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta:

Office of the Information and Data Protection Commissioner
Floor 2, Airways House
Triq Il-Kbira
Tas-Sliema SLM 1549
Malta

Telephone: +356 2328 7100
Email: idpc.info@idpc.org.mt
Website: https://idpc.org.mt/

The Commissioner’s contact details may change, and the current details should be checked on the Commissioner’s website before publication.

 

  1. Cookies

 

14.1 Our website uses cookies and similar technologies. Strictly necessary technologies may be used without consent where they are required to provide a service requested by the user or to maintain essential operation and security.

14.2 Optional analytics, preference, advertising or similar technologies will not be activated until the required consent has been obtained.

14.3 Further information, including the cookies in use, their providers, purposes and durations, is available in our Cookie Policy. Choices may be reviewed or withdrawn at any time through cookie settings.

 

  1. Changes to this Privacy Notice

 

15.1 We may update this Privacy Notice to reflect legal, regulatory, technical or business developments.

15.2 The current version will be published on our website with its effective date. Where a change materially affects individuals, we will take reasonable steps to bring the change to the attention of affected persons.

15.3 Previous versions may be obtained by contacting us.

* * *