Privacy Policy
Last updated: 29 July 2026
This policy explains what personal data SmartOne collects, why, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Maltese Data Protection Act (Cap. 586).
1. Who we are
This website is operated by SmartOne POS Europe Limited (company registration no. C 115037), a private limited liability company registered in Malta, with registered office at Level 6, Room 2, Tagliaferro Business Centre, Sqaq Gaiety, Sliema SLM 1551, Malta. We are the controller of the personal data described here.
For any privacy question, or to exercise your rights, write to info@smartoneglobal.com.
2. Scope
This policy covers this website and the enquiries you send us through it. It does not cover the payment services themselves: those are provided by our regulated partner, which handles the related data under its own terms and its own regulatory obligations.
3. What we collect
When you contact us or request a terminal, we collect the details you provide: your name, business name, email address, phone number, country, the type and size of your business, your current card processor and how you heard about us (all of these except name, email and country are optional), and the message you send.
If you accept the cookie notice, we store in your browser's local storage which campaign tag or referring site brought you here (so_first_touch). If you later send us an enquiry, it is submitted with the form so we know which channel it came from. It contains no name or contact details and is not shared with advertising networks. Decline the notice and nothing is stored.
When you browse the site, we store three functional cookies: your country, your language, and the fact that you have seen the cookie notice. We do not run advertising, analytics or cross-site tracking.
Our servers keep short-lived technical logs (IP address, request time, page requested, browser type) to keep the site running and secure.
4. Why we use it and our legal basis
To respond to your enquiry and to set up your account and device — processing necessary to take steps at your request and to perform a contract (GDPR Art. 6(1)(b)). This covers your name, business name, email, phone and message.
To qualify and price our offer to you — your business type, monthly card-sales band and current processor, all optional — on the basis of our legitimate interest in preparing a suitable commercial proposal (GDPR Art. 6(1)(f)). You can object to this at any time.
To understand which channels our enquiries come from — your consent, given by accepting the cookie notice (GDPR Art. 6(1)(a)). You can withdraw it at any time by clearing your browser storage for this site, and nothing is stored unless you accept.
To run the functional cookies that remember your country, language and that you have answered the cookie notice — our legitimate interest in a working site (GDPR Art. 6(1)(f)).
To keep the site available and secure and to meet our legal, tax and accounting obligations — our legitimate interest in the security of our systems (GDPR Art. 6(1)(f)) and compliance with a legal obligation (GDPR Art. 6(1)(c)).
5. Who we share it with
Payment, electronic-money and card-acquiring services are provided by Paynetics AD, an authorised electronic-money institution regulated by the Bulgarian National Bank and passported into the European Union. Where those services apply to you we share only what is needed to provide them, and that partner is the party responsible for payment-related regulatory checks, including AML and KYC.
We use processors who act only on our instructions under a data-processing agreement: our website host, the service that receives and routes the contact form, and our email and CRM providers.
We may share your details with other companies in the SmartOne group in Malta, Spain, Cyprus, Slovakia and the United Kingdom where that is needed to serve you in your market.
We do not sell your personal data, and we do not share it with advertising networks or data brokers.
6. International transfers
This website, and the enquiries you send through it, are hosted on servers located in the United States. Your personal data is therefore transferred outside the European Economic Area.
For that transfer, and for any other processor outside the EEA, we rely on either an adequacy decision of the European Commission, where the provider is certified under the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses under GDPR Art. 46, together with a transfer impact assessment and any additional technical and organisational measures required.
You can ask us which safeguard applies to a specific provider by writing to info@smartoneglobal.com.
7. Automated decision-making
We do not make decisions about you based solely on automated processing, and we do not profile you. Your enquiry is read and priced by a person; the volume band you select on the site only helps us prepare the conversation.
8. How long we keep it
We keep data only as long as needed for the purpose it was collected, then delete or anonymise it.
Sales enquiries that do not become customers: up to 12 months from your last contact with us.
Customer and transaction records: for the duration of the relationship, and afterwards for the statutory retention periods that apply under Maltese law — including approximately 6 years for VAT records (VAT Act, Cap. 406) and up to 9–10 years for tax and accounting records (Income Tax Management Act, Cap. 372; Companies Act, Cap. 386).
Technical server logs: a short period, normally no more than a few weeks.
9. Your rights
Under the GDPR you can ask us to give you access to your data, correct it, delete it, or send it to another provider; you can object to processing based on our legitimate interest, ask us to restrict processing, and where we rely on consent you can withdraw it at any time without affecting what we did before.
To exercise any of these, write to info@smartoneglobal.com. We respond within one month.
You also have the right to lodge a complaint with a data protection authority. Our lead authority is the Office of the Information and Data Protection Commissioner (IDPC), Floor 2, Airways House, High Street, Sliema SLM 1549, Malta, tel +356 2328 7100, idpc.info@gov.mt. You can also complain to the authority in the country where you live or work.
10. Children
This site and our products are aimed at businesses, not at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us their details, write to us and we will delete them.
11. Changes
We may update this policy as our services change; the date at the top shows the current version. If a change materially affects how we use your data, we will make that clear on this page.