Data controller: GREX Strategies (sole proprietor)
Address: 18 Triq Sant' Elija, Ix-Xgħajra , XJR 1010, Malta
Privacy enquiries / data requests: privacy@grex-strategies.com
General enquiries: office@grex-strategies.com
2. Scope
This policy explains how GREX Strategies processes personal data in connection with this website, enquiries, prospective client discussions and advisory engagements. Personal data may be received directly from you, from clients or other parties involved in an engagement, or from public and professional sources where relevant to our work.
Depending on the circumstances, we may process:
Contact and professional information, including name, email address, telephone number, job title and organization.
Correspondence and enquiry information provided when you contact us.
Client and engagement information, including contractual documents, engagement records and professional correspondence.
Billing and administrative information, including invoices and information required for accounting and tax purposes.
Information obtained or provided in connection with advisory, research, review or investigative work.
We do not intentionally collect special categories of personal data through this website. Such data may, where necessary and lawful, arise in connection with a particular professional engagement.
We may collect personal data:
Directly from you when you contact or engage us;
From clients, counterparties, professional advisers or other persons involved in an engagement;
From publicly available sources, professional databases or other legitimate information sources where relevant to an assignment; and
Through technical information processed in connection with the operation and security of this website.
We process personal data where necessary:
to respond to enquiries and take steps before entering into an engagement, on the basis of contractual necessity or our legitimate interests;
to provide and administer professional services, on the basis of contractual necessity and, where appropriate, our legitimate interests;
to maintain business, accounting and tax records and comply with legal requirements, on the basis of legal obligations;
to protect our business, systems and legal interests, on the basis of our legitimate interests; and
where consent is specifically requested, on the basis of that consent.
Where we rely on legitimate interests, we consider those interests against the rights and interests of the individuals concerned.
This website is hosted using Google Sites. Google may process technical information, including device, log and cookie information, in connection with the provision and security of its services.
GREX Strategies does not currently use Google Analytics, advertising trackers, or a public website contact form.
If you contact us by email, we process the information contained in your correspondence for the purposes of responding to your enquiry and, where applicable, taking steps towards or administering an engagement.
Some service providers used by GREX Strategies may process personal data outside the European Economic Area (EEA).
Where personal data is transferred outside the EEA, we rely, where required, on safeguards permitted under the GDPR, including European Commission adequacy decisions, standard contractual clauses, or other appropriate transfer mechanisms.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, contractual and professional requirements.
As a general rule:
General enquiries that do not result in an engagement: up to 2 years after the last substantive contact.
Proposals and prospective client records: normally up to 3 years after the matter is closed.
Client and engagement records: retained for an appropriate period following completion of the engagement, taking account of contractual, legal and potential claims requirements; and
Accounting, invoice and tax records: retained for the periods required under Maltese law.
Information may be retained for longer where required by law, necessary for the establishment, exercise or defense of legal claims, or otherwise justified by the circumstances. When information is no longer required, it will be securely deleted or anonymized.
9. Sharing personal data
We do not sell personal data.
Where necessary for the purposes described in this policy, personal data may be shared with:
Professional advisers, including lawyers and accountants;
Specialist experts or contractors engaged in connection with a particular assignment;
IT, hosting and other service providers;
Clients or other parties where necessary for the performance of an engagement; and
Courts, regulators, public authorities or law enforcement bodies where disclosure is required or permitted by law.
Where a service provider acts as a processor on our behalf, appropriate data protection arrangements are put in place.
You may have the right to: access your personal data; request its correction or erasure; request restriction of processing; object to certain processing; receive certain personal data in a portable format; withdraw consent where processing is based on consent; and lodge a complaint with a competent supervisory authority, subject to the conditions and limitations established by the GDPR. To exercise your rights, contact privacy@grex-strategies.com. We may request information necessary to verify your identity and will respond within the applicable statutory timeframe.
We use reasonable technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, loss or destruction. Where particularly sensitive information needs to be exchanged in connection with an engagement, we may arrange an appropriate secure transfer method.
This website and our professional services are not directed at children, and we do not knowingly collect personal data from children through the website.
We may update this Privacy Policy from time to time to reflect changes in our activities, services or legal obligations. The version of this Privacy Policy displayed on this website is the current version.
GREX Strategies is established in Malta. The Maltese supervisory authority for data protection is the Office of the Information and Data Protection Commissioner (IDPC).
You have the right to lodge a compliant with the IDPC if you consider that the processing of your personal data infringes applicable data protection law. You may also have the right to lodge a complaint with another competent EU or EEA supervisory authority.