Privacy policy.
This policy explains what information KMFINCO receives through this website, why we use it and the choices available to you.
Effective
Information we collect
When you submit an enquiry or meeting request, we receive the name, email address and any organisation or context you provide. Meeting requests also include the preferred time, duration and browser timezone. Enquiry records may include the submission time, reference and browser user-agent information.
Recovery records include a request reference, a hash used to check that repeated requests have the same details, and the submission status. Meeting records also include the reserved interval, host calendar identifier and any returned calendar event or joining links.
Cloudflare processes technical request information, which can include your IP address, to deliver and protect the website. If optional analytics is enabled and you accept it, Google Analytics receives website interaction and technical information such as device, browser and approximate location. We do not send enquiry text or email addresses as analytics events.
Required fields are marked in the forms; organisation and meeting context are optional. Please do not include identity documents, payment details, health information or other sensitive material in an initial enquiry.
How we use information
The form asks for your permission to use your details to respond to your enquiry or arrange the meeting you request. We record your affirmative choice, the checkbox statement, the privacy notice version and the time your request is first accepted. This is not a marketing subscription. You can withdraw that permission through our contact page, by phone or WhatsApp, quoting your request reference where available. We record withdrawals and stop further processing that relies on that permission; withdrawal does not undo processing already carried out lawfully.
Limited security and recovery records support our legitimate interests in preventing misuse, preserving accepted enquiries and avoiding duplicate invitations. Optional analytics relies on your separate choice to accept it. You can decline without losing access to the website or its forms.
A subsequent professional engagement has its own written terms and applicable privacy information. We do not make solely automated decisions about your eligibility for professional services through these forms.
Retention and security
Retention is reviewed by purpose rather than applying one period to every record:
- Enquiry details are kept while answering the enquiry and completing agreed follow-up. Once that work is closed, identifying details are removed unless a documented legal obligation, dispute or subsequent engagement requires them.
- Meeting details are kept while arranging, reconciling and completing the meeting and its agreed follow-up. An uncertain booking outcome must be reconciled before its recovery record is cleared. Calendar copies are reviewed separately.
- Minimal request references and matching hashes are kept while needed for duplicate prevention. They can still be personal information when linked to a person or request.
- Your analytics choice is kept until you change it or clear browser storage. Withdrawal stops future analytics and removes accessible analytics cookies; it does not automatically erase events already held by the provider. You can contact us about those records.
These criteria require a manual review of open work, any legal retention requirement and provider copies; they are not a universal automatic deletion timer. Access to submission records must be restricted to the people handling the request. No online service can guarantee absolute security.
Your choices and rights
Subject to applicable conditions, you may request access, correction, deletion, restriction or portability, object to processing based on legitimate interests, or withdraw consent. Use our contact page and include your request reference where available. We may need to verify your identity; please do not send identity documents unless requested through an appropriate channel.
You may complain to Malta's Information and Data Protection Commissioner, or the supervisory authority where you live or work.
Contact and updates
For privacy questions or rights requests, use our contact page. Professional engagements may provide additional privacy information. The effective date above identifies this website notice's latest revision.
