Medasia Hotel & Spa

Privacy Policy

Last updated: 24 September 2026

1. Introduction

MedAsia Hotel & Spa respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, store and protect your personal information when you:

  • visit our website;
  • make or enquire about a reservation;
  • stay at MedAsia Hotel & Spa;
  • use our facilities or services;
  • contact us by telephone, email, social media or another communication channel;
  • subscribe to our marketing communications; or
  • interact with us in any other way.

This policy is intended to comply with the General Data Protection Regulation, Regulation (EU) 2016/679, the Data Protection Act, Chapter 586 of the Laws of Malta, and other applicable data-protection legislation.

2. Who We Are

For the purposes of data-protection law, the data controller is:

Legal entity: Modo Hospitality Trading name: MedAsia Hotel & Spa

Any reference in this policy to “MedAsia Hotel & Spa”, “the Hotel”, “we”, “us” or “our” refers to the legal entity identified above.

3. Personal Data We Collect

Depending on how you interact with us, we may collect:

Identification and contact information

This may include your name, surname, date of birth, nationality, residential address, telephone number, email address, signature, identification document or passport details.

Reservation and stay information

This may include:

  • arrival and departure dates;
  • room type and rate;
  • number and names of guests;
  • special requests;
  • booking history;
  • preferred language;
  • loyalty or promotional information;
  • vehicle registration details;
  • complaints, feedback and service requests.

Payment information

We may process information relating to payments, billing addresses, transaction references, deposits and card pre-authorisations.

Full payment-card information may be processed directly by our authorised payment provider and may not be stored by the Hotel.

Special-request information

Where voluntarily provided and necessary to accommodate your stay, we may process information concerning:

  • accessibility requirements;
  • allergies;
  • dietary requirements;
  • medical or emergency-related needs.

Some of this information may constitute special-category personal data. We will only process it where there is an appropriate legal basis and where it is necessary to provide the requested service.

Website and technical information

When you use our website, we may collect:

  • IP address;
  • browser and device information;
  • operating system;
  • pages visited;
  • booking activity;
  • referral source;
  • cookie identifiers;
  • website interaction and analytics information.

CCTV and security information

CCTV may operate in public and security-sensitive areas of the Hotel for the purposes of safety, security, incident investigation and the protection of guests, employees and property.

Appropriate signage will be displayed in monitored areas. CCTV will not be used in areas where individuals would reasonably expect complete privacy.

Communications

We may retain emails, messages, telephone notes, social-media communications, reviews, enquiries and other correspondence exchanged with you.

4. How We Collect Your Information

We may collect personal data:

  • directly from you;
  • through our website and booking system;
  • during check-in, check-out or your stay;
  • from another guest making a reservation on your behalf;
  • from travel agents, tour operators and online booking platforms;
  • from corporate clients or event organisers;
  • from payment providers;
  • from affiliated MedAsia businesses where legally permitted;
  • through CCTV, security systems and website technologies;
  • from publicly available sources where appropriate.

Where you provide personal information relating to another guest, you are responsible for ensuring that you are permitted to provide it and that the person has been informed about this Privacy Policy.

5. Why We Use Your Personal Data

We may process your data for the following purposes:

To provide accommodation and services

This includes:

  • managing enquiries and reservations;
  • confirming, amending or cancelling bookings;
  • processing payments and deposits;
  • completing guest registration;
  • providing rooms, facilities and requested services;
  • managing check-in and check-out;
  • communicating important information about your stay.

The legal basis is generally the performance of a contract or taking steps at your request before entering into a contract.

To comply with legal obligations

We may process or retain information where required for:

  • tourism and accommodation obligations;
  • guest registration requirements;
  • accounting, taxation and financial records;
  • health and safety;
  • fraud prevention;
  • cooperation with competent authorities;
  • legal claims or regulatory investigations.

To protect guests, employees and property

We may process personal information for security, access control, CCTV monitoring, emergency management, fraud prevention and incident investigation.

The legal basis may be our legitimate interests, compliance with legal obligations or the protection of vital interests.

To improve our services

We may analyse feedback, complaints, booking patterns and website usage to improve the Hotel, our services and the guest experience.

Where we rely on legitimate interests, we consider whether our interests are proportionate and whether your rights and freedoms could be affected.

Marketing

With your consent, or where otherwise permitted by law, we may send you news, offers, event information and promotional communications.

You may unsubscribe at any time by using the unsubscribe option in the communication or by contacting us.

Withdrawing consent will not affect the lawfulness of any processing carried out before your consent was withdrawn.

6. Sharing Your Personal Data

We may share information where necessary with:

  • hotel-management and reservation-system providers;
  • online travel agencies and booking platforms;
  • payment processors and financial institutions;
  • IT, website, hosting, cloud and cybersecurity providers;
  • email, customer-management and marketing providers;
  • security companies and emergency-service providers;
  • accountants, auditors, insurers and professional advisers;
  • housekeeping, maintenance, transport or other service providers;
  • other MedAsia facilities or businesses where included in your booking or requested by you;
  • government departments, regulatory authorities, law-enforcement agencies or courts where required by law.

Service providers are only permitted to process personal data for authorised purposes and must protect it appropriately.

We do not sell your personal data to third parties.

7. International Transfers

Some service providers may process personal data outside Malta or outside the European Economic Area.

Where personal data is transferred outside the EEA, we will take appropriate steps to ensure that it receives an adequate level of protection. These measures may include an adequacy decision, approved contractual safeguards or another lawful transfer mechanism.

8. Data Retention

We retain personal data only for as long as reasonably necessary to:

  • provide the requested services;
  • maintain appropriate booking and operational records;
  • comply with tax, accounting, tourism and legal obligations;
  • manage complaints;
  • establish, exercise or defend legal claims;
  • protect the Hotel, its guests and employees.

Different categories of information may be kept for different periods.

9. Data Security

We use reasonable organisational, physical and technical measures to protect personal data against:

  • unauthorised access;
  • accidental loss;
  • alteration;
  • disclosure;
  • destruction;
  • misuse.

Access to personal data is restricted to authorised individuals who require it for legitimate business or legal purposes.

Although we take appropriate security precautions, no internet transmission or electronic storage system can be guaranteed to be completely secure.

10. Your Rights

Subject to the conditions and limitations established by law, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of your personal data;
  • request restriction of processing;
  • object to certain processing;
  • request the transfer of certain data in a portable format;
  • withdraw your consent;
  • object to direct marketing;
  • lodge a complaint with the relevant supervisory authority.

These rights arise under the GDPR and are subject to exceptions, including where information must be retained to meet a legal obligation or defend a legal claim.

Requests may be sent to:

Email: info@medasiahotelmalta.com
 Postal address: The Strand, 90 Triq ix-Xatt, Sliema, Malta

We may request proof of identity before responding.

You also have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta.

11. Children’s Personal Data

Reservations must be made by an adult with legal capacity to enter into the booking agreement.

We may process information relating to children where necessary to manage a family reservation, comply with guest-registration requirements, protect the child’s safety or provide an appropriate service.

Parents and legal guardians should avoid providing information about children unless it is necessary for the booking or stay.

12. Cookies

Our website may use essential, functional, analytics and marketing cookies.

Non-essential cookies will be used only where permitted and, where required, after consent has been obtained.

On this website, essential storage is used only to remember your cookie choice. Third-party content such as the embedded Google Map on our Contact page is loaded only after you accept cookies. You can change your choice at any time using “Cookie Settings” in the footer of every page.

13. Third-Party Websites

Our website may contain links to third-party websites, booking platforms or services.

We are not responsible for the privacy practices or content of third-party websites. Guests should review the privacy policy of the relevant third party before submitting personal information.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our services, systems or legal obligations.

The latest version will be published on our website with the date of the most recent update.

15. Contact Us

Questions concerning this Privacy Policy or the use of your personal data may be sent to:

MedAsia Hotel & Spa
 Modo Hospitality
 The Strand, 90 Triq ix-Xatt, Sliema, Malta
 Email: info@medasiahotelmalta.com
 Telephone: +356 2010 2222