Privacy and Cookie Policy
Effective Date: 17/12/2025
1. Identification of the Data Controller
Entity: The Mill Adventure Limited - C90719 (hereinafter referred to as "TMA" or "we")
Head office: Level 4, Pendergardens Business Centre 44, St Andrew's Road, STJ 9023, ST Julians, Malta
Email: info@themill.io
Data Protection Officer (DPO): dpo@themill.io
2. Purpose and Scope
This Privacy and Cookie Policy aims to transparently inform users about how we process personal data in connection with their access to and use of our corporate website (www.themill.io) and any interactions carried out through it.
This website is informational and corporate in nature, intended to provide information about our company, services, and activities, and to allow users to contact us or submit enquiries.
We are committed to complying with the General Data Protection Regulation (Regulation (EU) 2016/679 – "GDPR") and applicable data protection laws, ensuring the protection of personal data and the rights of data subjects.
We process only personal data that is adequate, relevant, and limited to what is necessary for the purposes defined in this Policy. This Policy may be updated at any time to reflect legal, technical, or operational changes.
3. Categories of Personal Data and Legal Grounds for Processing
Depending on how you interact with our website, we may process the following categories of personal data:
- Identification and contact data (name, email address, phone number, company, role)
- Communication data (content of messages submitted via contact forms or email)
- Professional information (information provided in business enquiries or partnership requests)
- Technical and usage data (IP address, browser type, operating system, pages visited, timestamps)
- Marketing preferences, where applicable
Personal data is processed for the following purposes and legal bases:
| Legal Base | Purpose |
|---|---|
| Performance of a contract or pre-contractual steps | Responding to enquiries, requests for information or business proposals |
| Legitimate interests | Website security, IT maintenance, analytics, service improvement, fraud and abuse prevention |
| Consent | Marketing communications, newsletters |
4. How We Collect Personal Data
We collect personal data through the following means:
- Directly from you, when you contact us via forms, email, or other communication channels available on the website.
- Automatically, through your use of the website, via cookies and similar technologies, including technical identifiers, session logs and usage data.
- From publicly available sources, where relevant and lawful, in a professional or business context.
All data collection is carried out in accordance with the GDPR principles of lawfulness, fairness and transparency.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or to comply with legal obligations. Indicative retention periods include:
| Contact and enquiry data | Up to 2 years from last interaction |
| Business communications | Duration of the business relationship or up to 3 years |
| Marketing data | Until consent is withdrawn |
| Technical and log data | Up to 12 months |
| Legal purposes | Duration of applicable statutory limitation periods |
After the applicable retention period, data is securely deleted or anonymised, unless further retention is required by law or for the establishment, exercise or defence of legal claims.
6. Data Disclosure and International Transfers
Access to personal data is restricted to authorised employees and service providers who require it to perform their duties and are subject to confidentiality obligations.
We may share personal data with trusted third-party service providers acting as processors, including IT and hosting providers, website analytics services, communication platforms, and professional advisors.
Where personal data is transferred outside the European Economic Area (EEA), such transfers are carried out in accordance with GDPR requirements, including the implementation of appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, pursuant to Article 46 GDPR.
7. Data Subject Rights
As a data subject, you have the right to exercise the rights granted by Chapter III of the GDPR, which include the right to access your personal data; the right to rectify inaccurate or incomplete data; the right to erasure ("right to be forgotten"); the right to restrict the processing of your personal data; the right to object to the processing of data when based on legitimate interests or for direct marketing purposes; and the right to data portability, which allows you to receive your data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
You also have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects you, except where such processing is necessary for the performance of a contract, authorised by Union or Member State law, or based on your explicit consent.
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of your rights, contact our DPO at dpo@themill.io.
9. Security Measures
We adopt appropriate technical and organisational measures to safeguard personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures include encrypted connections (SSL/TLS), robust firewalls, physical access controls, role-based access management, pseudonymisation and encryption of data, logging and monitoring, and regular security training for all staff. While we strive to ensure a high standard of security, it is important to acknowledge that no system is entirely immune to cyber threats.
In the event of a data breach affecting your personal data, we will assess the situation without undue delay and, where legally required, notify the appropriate supervisory authority and data subjects. We maintain robust internal procedures to respond promptly and transparently in such scenarios.
We apply the principles of data minimisation and purpose limitation and ensure that Privacy by Design and Default are embedded into our systems and processes. Where required, we conduct Data Protection Impact Assessments to evaluate and mitigate any risks to data subjects.
10. Supervisory Authority
If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority. You may contact the authority in your country of habitual residence, place of work, or the place of the alleged infringement.
11. Changes to This Policy
We reserve the right to amend this Privacy and Cookie Policy to reflect legal, technical, or operational changes. Any significant modifications will be communicated through the website. The date of the last update will always be displayed at the top of this page.
For any questions about this policy or your data, please contact us at: dpo@themill.io.