PRIVACY POLICY
THE SWEET SPOT
Gzira · Malta
1. About this policy
The Sweet Spot is an indoor golf and entertainment lounge in Gzira, Malta, operated by Adrim TSS Limited. We run golf simulator bays, a putting area, coaching, a bar and food service, private events and a membership programme.
This policy explains what personal data we collect, why, who we share it with, how long we keep it and what control you have. It covers our website, everyone who visits or books with us, Club Card members, corporate accounts, anyone captured on our CCTV, and people who apply to work with us.
It does not cover third-party services you choose to use alongside ours. Where a third party — most importantly Trackman — collects data directly from you under its own terms, we explain that in section 6.
2. Summary
We collect what we need to run the venue
What that means for you: Your booking details, membership record, payments, bar tabs, coaching notes and CCTV footage.
Your golf data mostly belongs to Trackman
What that means for you: Shot data, videos and leaderboards sit in your own Trackman account. Trackman is a separate controller with its own privacy policy.
We do not sell your data
What that means for you: Ever. We share it only with the suppliers and authorities listed in section 10.
Marketing is opt-in
What that means for you: Maltese law requires your written consent before we email or text you marketing. You can withdraw it in one click.
CCTV is for safety and security
What that means for you: Not for monitoring staff breaks or how well you play. Footage is normally deleted after 30 days.
You have real rights
What that means for you: Access, correction, deletion, portability, objection — plus a free complaint route to the Maltese regulator. Sections 14 and 18.
4. What we collect
4.1 Website visitors, enquiries and the waitlist
Contact details you give us — name, email, and phone number where provided.
Your enquiry and our reply.
Consent record — whether you ticked the marketing box, and the date, time and IP address. Maltese law requires us to be able to prove consent.
Technical data — IP address, browser and device type, referring page and pages viewed, collected through cookies (section 9).
4.2 Bookings — bays, the VIP Suite, coaching and the putting area
Name, email and mobile number of whoever makes the booking.
Booking details — date, time, duration, bay booked, number of players, add-ons, and any notes you give us such as a birthday, an accessibility need or a food allergy.
Names of other players in your group, where provided so that scoring and leaderboards work.
Booking history, including cancellations, no-shows and any fee charged.
Service messages we send you and your replies.
4.3 Membership
Identity and contact data — full name, email, mobile, and postal address where given.
Date of birth, where we need it to serve you alcohol lawfully or to place you in a junior category.
Membership record — number, tier, start and renewal dates, price paid, discounts and benefits applied.
Golf profile — handicap, dexterity and similar, where you give it to us or share it from Trackman.
Usage data — bays booked, hours used, Sweet Credit balance and transactions, guests brought in.
Photograph, only if you choose to add one to your profile or card.
4.4 Payments, Sweet Credit and receipts
Transaction data — what you bought, when, where, the amount and the payment method.
Card data — we do not store full card numbers. Our payment provider processes cards on its own systems; we receive a masked number, the card scheme, an authorisation code and the outcome.
Sweet Credit top-ups, bonus credit, spend and expiry.
Invoices and fiscal receipts, including what Maltese tax law requires us to record. For a VAT invoice we also record your name, address and VAT number.
4.5 Bar, food and allergens
Orders and tabs, including tabs linked to a bay or a membership.
Allergen and dietary information you tell us. This is health data under Article 9 GDPR. We collect it only when you volunteer it, use it only to serve you safely, and never put it in a marketing list.
Age verification — staff check identification visually where needed. We do not photograph or record your ID.
4.6 Simulator use
Playing generates golf performance data — ball and club parameters, shot results, scores, video where you choose to save it, leaderboard entries and lifetime statistics. Most of this is collected by Trackman, not by us. See section 6.
4.7 Coaching and juniors
Coaching records — session notes, drills, goals and progress.
Video and swing data captured in lessons, where you consent to it being saved.
Physical information relevant to your swing — height, injury or mobility limitations, where you choose to tell your coach. Where this is health data we rely on your explicit consent and share it only with your coach.
Junior records — see section 15.
4.8 Corporate accounts, private hire and events
Account and organiser details — company name, registration and VAT numbers, billing address, and the contact's name, title, email and phone.
Nominated user data — names, emails and usage of staff enrolled on a corporate account. We report usage back to the account holder; we do not report what you ate, drank or scored.
Attendee lists and any dietary or accessibility requirements provided for an event.
4.9 CCTV
We operate CCTV at the premises. Section 7 covers this in full.
4.10 Photography and social media
Photographs and video taken by us for marketing. Where someone is clearly identifiable and is the subject of the shot, we ask for consent. For general atmosphere shots we rely on legitimate interests, display notices, and remove any image on request.
Content you post or send us — tags, mentions, reviews, competition entries and messages. The platform also processes these under its own policy.
4.11 Incidents, complaints and job applications
Accident and incident reports, which may include health data, kept to meet our health and safety obligations and to handle claims.
Complaints and their outcome; damage and loss records; records of refused service or exclusion and the reason.
Job applications — CV, work history, qualifications, coaching certifications, references, right-to-work evidence, interview and trial notes, and the outcome.
5. Why we use it, and our legal basis
Under the GDPR we need a lawful basis for every use of your data. Ours are:
Taking and managing your booking, running your membership, serving you at the bar, and charging you
Legal basis: Contract — Art. 6(1)(b)
Serving you safely given an allergy you have told us about
Legal basis: Explicit consent — Art. 9(2)(a), with Art. 6(1)(b)
Delivering coaching and tracking your progress
Legal basis: Contract — Art. 6(1)(b); explicit consent — Art. 9(2)(a) for health information
Protecting our staff, customers and property; preventing and investigating crime, damage and safety incidents
Legal basis: Legitimate interests — Art. 6(1)(f)
Establishing, exercising or defending a legal claim, and dealing with insurers
Legal basis: Legitimate interests — Art. 6(1)(f); Art. 9(2)(f) for special category data
Fiscal receipts, VAT invoices, accounting and tax records, alcohol licensing, health and safety, and lawful requests from public authorities
Legal basis: Legal obligation — Art. 6(1)(c)
Service messages — confirmations, reminders, session-end notices, renewals, changes to opening hours
Legal basis: Contract — Art. 6(1)(b). Not marketing; you cannot opt out while you hold a booking or membership.
Marketing by email or SMS
Legal basis: Consent — Art. 6(1)(a), in writing as Maltese law requires; or the limited existing-customer exemption in S.L. 586.01, always with an easy opt-out
Advertising on social platforms and website analytics
Legal basis: Consent — Art. 6(1)(a), through our cookie banner
Tailoring offers to how you actually use the venue
Legal basis: Legitimate interests — Art. 6(1)(f), and you can object at any time
Leaderboards, competitions and tournaments
Legal basis: Contract or consent, depending on how you entered
Managing a corporate account and reporting usage to the account holder
Legal basis: Legitimate interests — Art. 6(1)(f)
Recruiting staff and coaches
Legal basis: Steps prior to a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) for right-to-work checks
Where we rely on legitimate interests we have carried out a balancing exercise. You can ask us for a summary of it.
6. Trackman and your golf data
Our bays run on Trackman technology supplied by Trackman A/S (Denmark). Much of the data generated while you play goes into your own Trackman account under Trackman's privacy policy, not ours.
Your Trackman account — name, email, username and any optional details you add
Controlled by: Trackman
Notes: You manage and can delete it there.
Shot and performance data, session and round scores, lifetime statistics, achievements
Controlled by: Trackman
Notes: We see the data generated in our bays in order to run the session, support you and coach you.
Video recordings of your swing
Controlled by: Trackman
Notes: Not saved unless you choose to save them. In tournament play, recordings may be kept where needed to verify play.
Leaderboards and tournament results
Controlled by: Trackman and us
Notes: Your name or player name may appear in the venue and online. Tell us if you would rather use an alias.
Simulator and system data — unit identifiers, usage times, user ID, IP address
Controlled by: Trackman
Notes: Used to operate and support the equipment.
Your booking, payment and membership record
Controlled by: Us
Notes: Held in our own systems.
You do not need a Trackman account to hire a bay. Without one, less data about you is created — but you lose your saved stats and history.
Trackman asks for your consent before sharing your contact details and shot data with a venue. If you give it, we receive that data and use it as described here. If not, we still see the session in the bay but not your player profile.
Trackman stores data on cloud infrastructure in the EU and the United States, and keeps it while you hold an account and for a defined period afterwards.
Where our online booking runs on Trackman's platform, Trackman acts as our processor for that booking data. Where you use your own player account, Trackman is its own controller.
Status note: our agreement with Trackman was still being finalised when this policy was drafted. This section will be updated to name the exact platform components in use before publication.
7. CCTV
We use CCTV to protect the safety of customers and staff, deter and investigate theft and damage, protect simulator equipment, meet licensing and health and safety obligations, and resolve disputes and claims. Our legal basis is legitimate interests under Article 6(1)(f).
Where cameras are: the entrance and reception, the bar and till points, the bay and putting areas, circulation areas, and external approaches under our control.
Where they are not: there are no cameras in bathrooms, showers or changing areas. Cameras are never concealed and we do not use covert surveillance.
No audio, no recognition. Our CCTV does not record audio [confirm against the final system specification], and we do not use facial recognition, biometrics or automated analytics on footage.
Not for monitoring. CCTV is not used to assess employee productivity or how you play, and is not watched continuously. Footage is reviewed only where there is a specific reason.
Signage is displayed at every entrance and in each monitored area, naming Adrim TSS Limited and giving the privacy contact.
Retention: footage is automatically overwritten after 30 days. Footage extracted for an incident, claim or police request is kept only for as long as that matter requires.
Access is restricted to named managers. Every viewing and export is logged with the date, the person and the reason.
Disclosure outside the company only to the Malta Police Force or another authority acting within its powers, to our insurers or lawyers for a claim, or to you on a valid request.
You can ask for a copy of footage in which you appear. We need the date, approximate time, location and a description of what you were wearing, plus proof of identity. Where other people appear we will mask them, or where masking is not technically possible we may have to refuse the copy while still confirming what was recorded.
8. Marketing and your choices
Malta applies a stricter standard than most of the EU. Under S.L. 586.01 we generally need your prior consent in writingbefore sending marketing by email, SMS or automated call. A box you actively tick counts; a pre-ticked box or silence does not. A narrow exemption lets us market our own similar products and services to existing customers, provided we gave you a clear, free opportunity to object when we took your details and in every message since.
Service messages — confirmations, reminders, renewals, changes to opening hours. Part of providing the service; you cannot opt out while you hold a live booking or membership.
Marketing messages — offers, events, league nights, new food and drink. Opt-in, and you can stop them at any time.
To stop marketing: click unsubscribe in any email, reply STOP to an SMS, email privacy@thesweetspotgolf.mt, or tell any member of staff. Withdrawing consent does not affect what we lawfully did beforehand and does not cancel your membership or bookings.
We also advertise on social platforms. That can involve a tracking pixel on our website, or uploading a hashed email list so a platform can match it to its users in order to show or exclude ads. We only do this with the consent you give through our cookie banner, and you can withdraw it at any time.
9. Cookies
Under S.L. 586.01 we may only store or read information on your device with your prior informed consent, unless it is strictly necessary for a service you asked for. Our banner lets you reject as easily as accept — non-essential cookies are not set until you accept, and you can change your choice any time through "Cookie settings" in the site footer.
Strictly necessary
What it does: Keeps your session alive, secures forms, remembers your cookie choice.
Consent needed?: No
Functional
What it does: Remembers preferences such as language or a previously used bay.
Consent needed?: Yes
Analytics
What it does: Tells us which pages are visited and where people drop out of a booking.
Consent needed?: Yes
Advertising
What it does: Lets us show ads to past visitors and measure whether ads led to bookings.
Consent needed?: Yes
Third-party embeds
What it does: Maps, videos, social feeds and booking widgets, which may set their own cookies.
Consent needed?: Yes
A current list of the individual cookies we set, with provider, purpose and lifetime, is kept on the cookie settings page of our website, because it changes more often than this policy does. You can also block or delete cookies in your browser, though blocking strictly necessary ones will break booking.
10. Who we share your data with
We do not sell your data and do not share it for anyone else's marketing.
Trackman A/S (Denmark)
Why: Simulator technology, player accounts, shot data, booking software where used
Role: Separate controller for player data; our processor for booking data
Our point-of-sale and fiscalisation provider
Why: Tills, orders, tabs, invoicing and EXO-compliant receipts
Role: Processor
Our payment provider and acquiring bank
Why: Card payments, refunds and disputes
Role: Independent controller for card data
Our CCTV provider
Why: Installation, maintenance and support
Role: Processor
Our email and SMS platform, website host and form providers
Why: Campaigns, subscriptions, running the site
Role: Processor
Analytics and advertising platforms
Why: Website measurement and advertising, where you consented
Role: Joint controller for audience matching; own controller thereafter
Our accountants, auditors and tax advisers
Why: Statutory accounts, audit and tax compliance
Role: Processor or independent controller
Coaches engaged at the venue
Why: Delivering your lessons
Role: Processor where engaged by us; independent controller where they contract with you directly
Malta Golf Association
Why: Squad training administration, squad members only
Role: Independent controller
Public authorities, including MTCA and the Malta Police Force
Why: Tax, fiscal, licensing, health and safety and law enforcement obligations
Role: Independent controller
Insurers, loss adjusters and lawyers
Why: Claims and legal advice
Role: Independent controller
A buyer or investor
Why: If the business is sold, restructured or refinanced, subject to confidentiality
Role: Independent controller from completion
Every processor is bound by a written contract meeting Article 28 GDPR: they act only on our documented instructions, keep the data secure, help us answer your requests, and delete or return it at the end of the engagement.
Named suppliers are being finalised. The published version will name each provider and its country of establishment.
11. Sending data outside the EEA
We prefer suppliers that keep data inside the EEA. Some — particularly analytics, advertising and cloud providers — process it in the United States or elsewhere. Where data leaves the EEA we rely on an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified), the European Commission's Standard Contractual Clauses supported by a transfer impact assessment, or a derogation under Article 49. Ask us and we will tell you which applies to a specific transfer.
12. How long we keep it
Booking records
Retention period: 24 months from the booking
Club Card membership record
Retention period: Duration of membership plus 24 months
Sweet Credit balances and transactions
Retention period: Duration of the balance plus 6 years
Accounting, invoice and fiscal records
Retention period: Minimum 6 years; up to 10 where company law requires
CCTV footage
Retention period: 30 days, then automatically overwritten
CCTV extracted for an incident
Retention period: For the duration of the matter, then deleted
Coaching records and swing video
Retention period: Duration of the coaching relationship plus 24 months, or until you ask us to delete them
Allergen and dietary information
Retention period: Held against your membership profile while you are a member; otherwise deleted after the visit
Marketing list and consent records
Retention period: Until you unsubscribe; a suppression record is kept indefinitely so we do not contact you again
Enquiries and correspondence
Retention period: 24 months
Complaints and incident reports
Retention period: 6 years from resolution; 10 years where an injury was involved
Records of refused service or exclusion
Retention period: 3 years
Unsuccessful job applications
Retention period: 6 months, unless you agree to longer
Website analytics
Retention period: 14 months at most
At the end of a period we delete the data or irreversibly anonymise it. Anonymised data — such as how many bays were occupied at 8pm on a Friday — is not personal data and we keep it for planning.
13. How we protect it
Access restricted to staff who need it, under individual named accounts, with multi-factor authentication on administrative systems and email.
Encryption in transit across the website and booking flows, and at rest with our cloud providers.
No full card numbers stored on our systems; card processing is handled by a PCI DSS compliant provider.
Physical security on server, recorder and back-office areas.
Data protection training for all staff before they start on the floor, and confidentiality clauses in employment and coaching contracts.
Written processing agreements with every supplier handling personal data for us.
A documented breach procedure, including notification to the Information and Data Protection Commissioner within 72 hours where required, and to you where the risk is high.
No system is perfectly secure. If something goes wrong we will tell you honestly and quickly, and tell you what we are doing about it.
14. Your rights
These are free to exercise.
Access
What it means: Get a copy of the data we hold about you and an explanation of how we use it.
Rectification
What it means: Have inaccurate data corrected and incomplete data completed.
Erasure
What it means: Have your data deleted where we no longer need it or where you withdraw the consent it rested on. Not absolute — we cannot delete a fiscal record we are legally required to keep.
Restriction
What it means: Have us pause using your data while we check its accuracy or consider your objection.
Portability
What it means: Receive data you gave us in a machine-readable format, or have it sent to another provider where feasible.
Objection
What it means: Object to processing based on legitimate interests. Where you object to direct marketing we must stop immediately.
Withdraw consent
What it means: At any time, as easily as you gave it, without affecting what we lawfully did before.
Complain
What it means: Lodge a complaint with the Information and Data Protection Commissioner. See section 18.
Email admin@thesweetspotgolf.mt or write to our trading address. Tell us which right you are exercising and, if you can, narrow down what you are looking for.
We will verify your identity first, asking for no more than we need.
We respond within one month, extendable by up to two further months for complex or repeated requests — we will tell you within the first month if we extend.
No charge, unless a request is manifestly unfounded or excessive, and we will explain why.
If we refuse in whole or in part, we will give the reason and how to challenge it.
15. Automated decisions and profiling
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Nothing automated decides whether you may join or what you are charged. We do group members by how often they play or what they tend to buy so that offers are relevant. That rests on legitimate interests, and you can object at any time without affecting your membership.
16. Children and young people
Where a player is under 16, a parent or guardian must make the booking or complete the enrolment and is our primary contact.
We collect only what a junior programme needs: name, age, the parent's contact details, an emergency contact, and any medical or accessibility information the parent chooses to give.
We do not send marketing to anyone under 18.
We do not publish a junior's photograph or full name without the written consent of a parent or guardian, which can be withdrawn at any time. On leaderboards we use a first name and initial, or an alias, unless a parent agrees otherwise.
Coaches working with juniors are subject to our safeguarding requirements and are asked for a police conduct certificate.
In Malta a child can consent on their own behalf to an online service from age 13 (S.L. 586.11). Below that we rely on parental consent. Because our services also involve alcohol licensing, we apply higher thresholds where safety requires it. If you believe we hold data about a child without the necessary consent, contact us and we will delete it.
17. Changes to this policy
We will update this policy as the business changes. The version and date at the top show which version you are reading. If a change materially affects how we use your data we will tell members and subscribers by email and post a notice on the website and at reception before it takes effect. Where a change needs your consent, we will ask for it.
18. Questions and complaints
Talk to us first — most issues are a misunderstanding we would rather fix quickly.
Post
admin@thesweetspotgolf.mt: The Sweet Spot, 14 Triq Sir Frederick C. Ponsonby, Gzira GZR 1075, Malta
In person
admin@thesweetspotgolf.mt: Ask for the duty manager at reception
If you are not satisfied, you have the right to complain to the Maltese supervisory authority. Complaints are free, and you also have the right to a judicial remedy before the Maltese courts.