NOLITA RENTALS
PRIVACY POLICY
Last updated: 21.11.2025
Effective from: 21.11.2025
Nolita Rentals respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, disclose, store and otherwise process personal data when you visit or use the Nolita Rentals website, create an account, browse or publish properties, subscribe to our services, use an Owner or Agent portfolio, communicate with other users, request a viewing, submit a review or report, contact support, or otherwise interact with our services.
This Privacy Policy should be read together with our Terms of Use, Cookie Policy and other applicable Nolita Rentals policies.
1. Who we are
For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Maltese data-protection law, the data controller is:
NOLITA GROUP Ltd
Company Registration Number: C102490
VAT Number: MT29271128
Registered/Business Address:
4, Last Block P/H 7, Triq il-Habberxa, Marsaskala MSK2242, Malta
Email: nolitagroupltd@gmail.com
Trading platform: Nolita Rentals
Website: nolitarentals.com
In this Privacy Policy, “Nolita Rentals”, “Nolita”, “we”, “us” and “our” refer to NOLITA GROUP Ltd.
NOLITA GROUP Ltd determines the purposes and means of the personal-data processing described in this Privacy Policy and therefore acts as the data controller for those activities. The Malta IDPC explains that an organisation is generally a controller when it determines what personal data is processed and why. IDPC
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed in connection with Nolita Rentals, including:
- Residential Long-Term Rentals
- Residential Short Lets
- Commercial Rentals
- Property Owner accounts and portfolios
- Property Agent accounts and portfolios
- Client accounts
- Client Access subscriptions
- Property listings
- Property enquiries
- Viewing requests
- Messages
- Reviews
- Support tickets
- Listing reports
- Legal and privacy requests
- Subscription and billing administration
- Email communications
- Calendar integrations
- Short-let licensing and registration workflows
- Website and platform analytics
This Policy does not govern an independent third party’s own processing where that third party acts as a separate controller.
3. Data-protection principles
We aim to process personal data in accordance with the principles of:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality; and
- accountability.
These principles are set out in Article 5 GDPR and are also reflected in guidance from Malta’s Information and Data Protection Commissioner. IDPC
4. Personal data we may collect
The personal data we process depends on how you use Nolita Rentals.
4.1 Account and identity information
We may process:
- full name;
- display name;
- email address;
- telephone number;
- login/account identifiers;
- account type;
- authentication information;
- account status;
- language preferences;
- profile photograph;
- account settings.
We do not need access to your password in readable form where authentication is handled securely through the platform’s authentication system.
5. Property Client information
If you use Nolita Rentals to search for property, we may process:
- account information;
- saved properties;
- saved searches;
- property preferences;
- enquiries;
- viewing requests;
- proposed or confirmed appointment dates;
- messages with Owners or Agents;
- contact information you choose to share;
- Client Access subscription status;
- support interactions;
- reviews you submit;
- reports you make;
- browsing and interaction data.
We do not make your complete account profile available to Owners or Agents merely because you browsed their property or portfolio.
Information is shared with the relevant publisher when you deliberately initiate an interaction such as an enquiry, viewing request or permitted contact action.
6. Property Owner information
For Property Owners, we may process:
- full name;
- public display name;
- contact information;
- Owner profile photograph;
- portfolio information;
- Private Owner or Company Owner presentation preference;
- company name and logo where applicable;
- company information;
- property details;
- listing contact details;
- exact property addresses;
- ownership or authority declarations;
- supporting documents where required;
- subscription information;
- enquiry and viewing history;
- listing analytics;
- public reviews;
- account and moderation history.
Choosing Company Owner changes the public presentation of the Owner profile but does not automatically verify a company or alter the underlying account identity.
7. Property Agent information
For Property Agents, we may process:
- full name;
- profile photograph;
- professional title;
- public biography;
- telephone number;
- email address;
- professional areas covered;
- languages;
- residential/commercial specialities;
- agency affiliation where declared;
- professional registration or licence information where applicable;
- supporting evidence;
- Agent Portfolio information;
- listings;
- enquiries;
- viewing requests;
- messages;
- analytics;
- subscription status;
- reviews;
- moderation and compliance records.
Professional information supplied by an Agent is not automatically considered independently verified.
Where Nolita performs a review, the review status is stored separately.
8. Property and listing information
We may process property-related information including:
- listing title;
- description;
- category;
- property type;
- rental price;
- deposits and charges;
- general locality;
- exact street address;
- unit/floor information;
- geographical coordinates;
- photographs;
- floor plans;
- amenities;
- availability;
- Last Availability Confirmed information;
- listing history;
- commercial property information;
- publisher information;
- listing review/moderation information.
Some of this information is public, while other information, such as exact addresses, precise coordinates and protected publisher contacts, is restricted.
9. Short-let information
For Residential Short-Let listings, we may process information required to operate the relevant listing and compliance workflow, including:
- MTA licence number;
- STR or other applicable short-term rental registration number;
- licence holder/operator information;
- accommodation details;
- registration/licence status;
- validity or expiry information;
- date and source of validation or review;
- supporting documents;
- regulatory reporting information where legally required.
Submission of licensing information does not automatically mean it has been validated.
Where applicable law requires certain registration information to be publicly displayed, that information may be shown publicly even where ordinary property contact information is protected.
10. Commercial property information
Commercial listings may contain:
- property-use declarations;
- fit-out information;
- floor areas;
- service charges;
- extraction/ventilation information;
- equipment details;
- loading/access information;
- power information;
- parking information;
- supporting documents;
- document-review records.
Where information is labelled Declared by publisher, it originates from the publisher.
A Supporting document reviewed status does not necessarily mean that Nolita has confirmed legal suitability for a particular business.
11. Subscription and payment information
Where you purchase a Nolita subscription, we may process:
- selected plan;
- subscription status;
- billing period;
- payment-provider customer/subscription identifiers;
- payment status;
- paid-through date;
- cancellation status;
- transaction references;
- invoices/payment records where applicable;
- refund/dispute status.
Nolita should not receive or store complete payment-card details where payment is processed by an external payment provider such as Stripe.
Payment-card information is generally processed directly by the payment provider under its own privacy arrangements.
12. Messages, enquiries and viewings
We may process communications made through Nolita, including:
- sender and recipient;
- message content;
- timestamps;
- property reference;
- conversation reference;
- enquiry status;
- viewing-request status;
- proposed viewing dates/times;
- shared contact information;
- email replies routed into a Nolita conversation.
Messages are not public.
They are available only to authorised participants and authorised Nolita personnel where access is reasonably necessary for support, safety, legal or platform-integrity purposes.
13. Email communications
Nolita may use email to send:
- property-enquiry notifications;
- viewing notifications;
- viewing confirmations;
- rescheduling notices;
- listing approval/review information;
- subscription communications;
- account communications;
- availability reminders;
- support replies;
- legal notices;
- security notifications.
Operational emails may be sent using Nolita’s configured email services.
Incoming replies may be matched to the appropriate Nolita conversation or support ticket using secure thread/reference information.
If an incoming email cannot be matched confidently, it may be retained in a restricted administrative inbox for manual review.
14. Calendar information
Where an Agent or other authorised user voluntarily connects an external calendar such as Google Calendar or Outlook, we may process limited calendar information necessary to:
- check availability;
- prevent scheduling conflicts;
- create confirmed viewing appointments;
- update or cancel synchronised appointments.
Nolita’s internal viewing record remains separate from external calendar data.
We aim to minimise the information shared with external calendar providers.
Connecting an external calendar is optional unless clearly stated otherwise.
15. Reviews
When reviews are enabled, we may process:
- reviewer account;
- person or publisher reviewed;
- rating;
- review text;
- related Nolita interaction;
- timestamps;
- moderation status;
- reports relating to the review.
We may verify whether the reviewer had an eligible platform interaction before accepting a review.
Public reviews will normally display only the information configured for public display, not the reviewer’s private account information.
16. Support, complaints and reports
We may process information submitted through:
- Help & Contact;
- support tickets;
- formal complaints;
- Listing Quality reports;
- Illegal Content Notices;
- privacy requests;
- safety reports;
- review reports.
This may include:
- name;
- contact information;
- message;
- related listing;
- evidence;
- attachments;
- correspondence;
- resolution;
- audit history.
These records are not public.
17. Technical and usage information
When you use Nolita Rentals, we may automatically process certain technical information such as:
- IP address;
- device/browser information;
- operating system;
- session identifiers;
- login timestamps;
- security logs;
- page interactions;
- referral information;
- cookie preferences;
- error/debug information;
- analytics events where permitted.
We use this information only in accordance with the purposes and legal bases described in this Policy.
18. How we obtain your personal data
We may obtain personal data:
Directly from you
For example when you:
- create an account;
- create a listing;
- submit a profile;
- purchase a subscription;
- send an enquiry;
- request a viewing;
- send a message;
- submit a review;
- contact support;
- submit documentation.
From another Nolita user
For example where an Owner or Agent sends information relevant to a shared viewing or conversation.
From connected services
For example:
- payment providers;
- connected email systems;
- Google/Outlook calendars;
- authentication providers.
From public or official sources
Where appropriate and lawful, we may use public registers or official sources to check submitted business, professional or regulatory information.
Where GDPR Article 14 applies because information was obtained from another source, we will provide the required information within the legally applicable timeframe unless an exemption applies. Malta’s IDPC identifies Articles 13 and 14 as the core GDPR transparency requirements. IDPC
19. Why we process your personal data
We process personal data only where an appropriate lawful basis applies.
Article 6 GDPR provides the principal lawful bases, including consent, performance of a contract, legal obligation and legitimate interests. Malta’s IDPC stresses that controllers must identify the basis that genuinely fits each processing activity rather than treating consent as the default. IDPC
Our main processing purposes are described below.
20. Performance of a contract
We may process personal data because it is necessary to provide services you request or to take steps at your request before entering into a contract.
This may include:
- account creation;
- subscription administration;
- Client Access;
- Owner/Agent membership;
- property publishing;
- Owner/Agent portfolios;
- enquiries;
- messages;
- viewing requests;
- customer support;
- account management;
- payment/subscription administration.
21. Legal obligations
We may process personal data where necessary to comply with a legal obligation.
This may include:
- accounting and tax records;
- responding to lawful authority requests;
- consumer-protection obligations;
- regulatory records;
- data-protection obligations;
- short-let regulatory requirements;
- legally required content/report handling.
We will not claim a legal-obligation basis where no relevant legal obligation applies.
22. Legitimate interests
Where appropriate, we may process personal data based on our legitimate interests or those of another party, provided those interests are not overridden by your rights and freedoms.
Possible legitimate interests include:
- preventing fraud;
- securing accounts;
- detecting abuse;
- investigating suspicious listings;
- protecting platform integrity;
- maintaining audit records;
- improving services using proportionate analytics;
- handling legal claims and disputes;
- preventing duplicate or malicious activity.
Where required, we undertake an appropriate balancing assessment.
23. Consent
We rely on consent where consent is the appropriate lawful basis.
Examples may include:
- non-essential cookies;
- certain analytics technologies;
- optional marketing communications;
- optional third-party integrations.
Consent must be freely given, specific, informed and unambiguous, and may be withdrawn. Pre-ticked boxes or inactivity do not constitute valid consent. IDPC
Withdrawal does not affect processing lawfully carried out before withdrawal.
24. Marketing communications
We do not treat acceptance of our Terms as consent to marketing.
Where required, promotional email or electronic marketing will be sent only where we have a lawful basis.
You may opt out using the unsubscribe method provided in the communication or through your account/preferences where available.
Malta’s IDPC explains that electronic direct marketing generally requires prior consent, subject to certain conditions such as the existing-customer “soft opt-in”, and that recipients must be given an easy and free way to object. IDPC
Operational messages relating to your account, subscription, property, viewing, security or support are not treated as optional marketing simply because they are delivered by email.
25. Cookies and similar technologies
Nolita may use cookies and similar technologies.
Our Cookie Policy and Cookie Settings provide details of the technologies actually used.
We distinguish between:
- Strictly Necessary;
- Preferences;
- Analytics;
- Marketing.
Where consent is legally required, non-essential cookies and similar storage/access technologies are not activated before valid affirmative consent.
Malta IDPC guidance states that consent-required tracking cookies should be installed only after prior informed affirmative consent. IDPC
You may withdraw consent through Cookie Settings.
26. Who we may share personal data with
We do not sell personal data to advertisers.
We may share personal information only where appropriate with categories of recipients such as:
Other Nolita users
Only where required for a legitimate platform interaction.
For example, an Agent may receive the information a Client deliberately submits with a viewing request.
Payment providers
To process subscriptions and transactions.
Hosting and infrastructure providers
To operate and secure Nolita Rentals.
Email providers
For sending and receiving operational email.
Calendar providers
Where the user chooses to connect an external calendar.
Analytics and technology providers
Where enabled and lawful.
Professional advisers
Such as lawyers, accountants or auditors where reasonably necessary.
Regulators and public authorities
Where disclosure is required or authorised by law.
Buyers or successors
In connection with a genuine corporate transaction, subject to appropriate safeguards.
Service providers processing information on our behalf are expected to process data under appropriate contractual and security obligations.
27. Owner and Agent disclosures
Public Owner and Agent profiles may display information that the publisher has chosen or is required to make public.
This may include:
- display name;
- company name;
- profile photo/logo;
- professional title;
- service areas;
- specialties;
- portfolio listings;
- reviews;
- required business/regulatory information.
Protected telephone numbers, direct emails and exact property addresses remain subject to the Platform’s applicable access rules unless disclosure is legally required.
Mandatory legal disclosure is not hidden behind Client Access.
28. International data transfers
Some technology providers may process personal data outside Malta or the European Economic Area.
Where personal data is transferred to a country outside the EEA, we will use an applicable lawful transfer mechanism where required, such as:
- an adequacy decision issued by the European Commission;
- Standard Contractual Clauses;
- another transfer mechanism permitted under Chapter V GDPR.
Where required, additional safeguards may be applied.
[TO CONFIRM BEFORE PUBLICATION: identify the actual providers, countries and transfer mechanisms used by Base44, Stripe, Gmail/Google, Microsoft and any analytics provider.]
This point should not remain vague in the final policy: a Malta IDPC enforcement decision has specifically criticised privacy policies that merely state data “may” go outside the EEA without explaining the relevant safeguards required by Article 13(1)(f). IDPC
29. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including applicable legal, regulatory, accounting, security and dispute requirements.
Different categories require different periods.
Our retention schedule covers categories including:
- account information;
- subscriptions and invoices;
- property listings;
- messages;
- enquiries;
- viewing requests;
- support tickets;
- complaints;
- reports;
- reviews;
- legal/moderation records;
- audit records;
- short-let regulatory information;
- uploaded documents.
[TO CONFIRM BEFORE PUBLICATION: insert or configure the approved retention periods/criteria for each category.]
We do not keep personal data indefinitely merely because storage is technically available.
The GDPR storage-limitation principle requires identifiable data not to be kept longer than necessary for its purpose. IDPC
When the applicable retention period ends, data will be securely deleted or irreversibly anonymised unless further retention is required or permitted by law.
30. Account deletion
Closing or deleting an account does not necessarily mean that all associated personal data can immediately be erased.
We may need to retain certain records for:
- legal obligations;
- accounting;
- fraud prevention;
- disputes;
- legal claims;
- safety;
- platform integrity;
- regulatory purposes.
Messages already legitimately shared with another participant may also remain in that participant’s conversation history where appropriate.
Where data can lawfully be erased, we will process eligible deletion requests in accordance with GDPR.
31. Security
We use appropriate technical and organisational measures intended to protect personal data against:
- unauthorised access;
- unlawful processing;
- accidental loss;
- alteration;
- disclosure;
- destruction.
Measures may include, depending on the system:
- authentication controls;
- role-based permissions;
- private data separation;
- secure transmission;
- restricted administrative access;
- audit logging;
- secure private file access;
- security monitoring;
- provider access controls.
No online service can guarantee absolute security.
Users are also responsible for maintaining the confidentiality of their own login credentials.
32. Data breaches
Where a personal-data breach occurs, we will assess and respond to it in accordance with applicable GDPR obligations.
Where required, we will notify the competent supervisory authority and affected individuals within the applicable legal framework.
33. Automated decision-making and profiling
Nolita may use automated technical rules for purposes such as:
- spam detection;
- fraud prevention;
- listing validation;
- security;
- matching/filtering;
- search ranking;
- notification logic.
Unless clearly stated otherwise, Nolita does not currently intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects on an individual within the meaning of Article 22 GDPR.
If such processing is introduced, this Privacy Policy will be updated and the required information and safeguards will be provided.
34. Your data-protection rights
Subject to the conditions and exceptions provided by law, you may have the following rights:
Right to be informed
To receive clear information about how your data is used.
Right of access
To request confirmation of whether we process your personal data and obtain a copy.
Right to rectification
To correct inaccurate or incomplete personal data.
Right to erasure
To request deletion in applicable circumstances.
Right to restriction
To request restriction of processing in applicable circumstances.
Right to data portability
To receive certain personal data in a structured, commonly used and machine-readable format and request transfer where legally applicable.
Right to object
To object to processing based on legitimate interests and to direct marketing.
Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time.
Rights concerning automated decisions
Where Article 22 GDPR applies, you may have rights in relation to decisions based solely on automated processing.
Malta’s IDPC provides further explanations of these rights. IDPC
35. How to exercise your rights
You may submit a privacy request through Nolita’s Help & Contact Centre or by emailing:
nolitagroupltd@gmail.com
Please state the nature of your request.
We may ask for reasonable information necessary to verify your identity before disclosing, changing, exporting or deleting personal data.
We will not request excessive identification merely because you have exercised a privacy right.
Requests will be handled within the time limits required by applicable data-protection law.
36. Complaints to the supervisory authority
You have the right to lodge a complaint with the competent data-protection supervisory authority.
In Malta, this is:
Office of the Information and Data Protection Commissioner (IDPC)
You may find current contact information and complaint procedures on the IDPC’s official website.
Our internal complaint or privacy-request process does not prevent you from contacting the IDPC directly. IDPC
37. Children
Nolita Rentals is intended for persons capable of entering into the relevant property, account and subscription arrangements.
The Platform is not designed as a service directed at young children.
We do not knowingly seek to collect children’s personal data for property publishing or paid membership purposes.
[LEGAL REVIEW REQUIRED: confirm the minimum account age and any Malta-specific consent/contract-capacity rules before final publication.]
38. Public information
Certain information you intentionally publish may become publicly available.
This can include:
- Owner/Agent public profiles;
- public property listings;
- property photos;
- public reviews;
- public portfolio URLs;
- QR-linked portfolio pages;
- regulatory/business information required to be public.
Public information may be indexed by search engines, shared by third parties or remain temporarily available in external caches even after it is removed from Nolita.
Do not include private information in a public property description or image unless you intend it to be public.
39. Property photographs and metadata
Publishers are responsible for ensuring that photographs and other media do not unintentionally reveal private information.
Where technically feasible, Nolita may remove metadata from public property images and may moderate media containing visible contact or sensitive address information.
This does not guarantee that photographs cannot reveal or allow others to infer a property’s location.
40. Links to external websites
Nolita may contain links to external websites or third-party services.
We are not responsible for the independent privacy practices of third-party websites.
You should review their privacy information before submitting personal data to them.
41. Changes to this Privacy Policy
We may update this Privacy Policy where our services, technology, providers or legal obligations change.
Each published version will show its publication/effective information.
Where a material change requires additional notice or renewed consent under applicable law, we will provide that notice or request separately.
We will not treat a draft or unapproved policy as publicly effective.
Previous versions may be retained for legal and audit purposes.
42. Contact us
For questions about this Privacy Policy or our processing of personal data, contact:
NOLITA GROUP Ltd
Company Registration Number: C102490
VAT Number: MT29271128
4, Last Block P/H 7
Triq il-Habberxa
Marsaskala MSK2242
Malta
Email: nolitagroupltd@gmail.com
If Nolita later appoints a Data Protection Officer where legally required, the DPO’s contact information will be published here and communicated to the competent authority where required. Not every organisation is legally required to appoint a DPO; the obligation depends on the circumstances set out in GDPR. IDPC
