Privacy Policy
Who We Are
Minimum Viable Compliance Ltd. (‘we’ or ‘us’ or ‘our’) gather and process your personal information in accordance with this privacy notice and in compliance with the relevant data protection Regulation and laws. This notice provides you with the necessary information regarding your rights and our obligations, and explains how, why and when we process your personal data.
Minimum Viable Compliance Ltd.’s registered office is at 230 Triq Il-Kungress Ewkaristiku, Mosta MST 9039, Malta. We are a company registered in Malta under company number C 114370. Our designated Appointed Person for the organisation is Daniel Thompson-Yvetot, who can be contacted in writing at the company’s registered address or via email at privacy@mvc.eu.
Information That We Collect
Minimum Viable Compliance Ltd. processes your personal information to meet our legal, statutory and contractual obligations and to provide you with our products and services. We will never collect any unnecessary personal data from you and do not process your information in any way, other than as specified in this notice.
The personal data that we may collect from you can include:
- Name
- Business Email
- Personal Email
- Company or Organisation Name
- Job Title
- Telephone Number
We collect information in the below ways:
- Online contact and enquiry forms
- Newsletter registration form
- Employment CV submissions
Third-party services that we use that also have access to your personal information:
HubSpot
We use HubSpot as our primary platform for contact management and marketing communications. When you submit a form on our website or book a meeting, your data is processed by HubSpot’s platform. This allows us to respond to your enquiries, manage our communications, and send you relevant updates where you have consented to receive them.
The provider is HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA. The data processed by HubSpot may include your name, email address, company name, IP address, and the contents of your communications with us.
HubSpot is certified in accordance with the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Our HubSpot instance is hosted on the EU data centre to ensure your data remains within the European Union wherever possible.
The legal basis for this processing is your consent under Art. 6(1)(a) GDPR for marketing communications, and the performance of our contract with you under Art. 6(1)(b) GDPR for service-related communications.
Details can be found in HubSpot’s Privacy Policy.
Resolve247
We use Resolve247 to power the chat widget on our website. When you interact with the chat, your messages and any information you provide are processed by Resolve247’s platform so we can respond to your enquiries. The data processed may include the contents of your chat messages, your IP address, and any contact details you choose to share during the conversation.
The legal basis for this processing is the performance of our contract with you under Art. 6(1)(b) GDPR, where chat is used for support, and your consent under Art. 6(1)(a) GDPR for any optional information you provide.
Details can be found at resolve247.ai.
YouTube
We embed videos on our website using YouTube, a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. When you play an embedded video, YouTube may set cookies on your device and collect data including your IP address and browsing behaviour in accordance with their own privacy policy.
We use YouTube’s standard embed functionality. By playing a video on our website, you acknowledge that data may be transferred to and processed by Google in accordance with their terms.
You can learn more about the cookies used by Google at https://policies.google.com/technologies/cookies.
The legal basis for this processing is your consent under Art. 6(1)(a) GDPR.
Fathom Analytics
We use Fathom Analytics to understand how visitors use our website in aggregate. Fathom is a privacy-focused, cookie-free analytics service: it does not set cookies or use persistent identifiers, and does not track visitors across sites.
The provider is Conva Ventures Inc. (trading as Fathom Analytics), 517 Fort Street, Victoria, BC V8W 1E7, Canada. Canada is recognised by the European Commission as providing an adequate level of data protection under Article 45 GDPR, so no additional transfer safeguards are required.
The data processed by Fathom may include your IP address (used only at the point of collection to derive anonymised, aggregated information such as approximate country and is not stored), user agent, referring URL, and the page URL visited. Fathom does not retain personal data.
The legal basis for this processing is our legitimate interest under Art. 6(1)(f) GDPR in understanding how our website is used so we can improve it. Because Fathom does not store information on your device or process personal identifiers, no consent is required.
Details can be found in Fathom’s Privacy Policy.
Netlify
The site https://mvc.eu is hosted on the Netlify platform, which collects some data for each request in their access logs, including the IP addresses of visitors. This means if you visit any page of this site, each page visit results in your IP address being stored in Netlify’s access logs. This information is stored for less than 30 days. See Netlify’s privacy policy for more details.
Processing of Customer and Contract Data
We collect, process, and use personal customer and contract data for the establishment, content arrangement and modification of our contractual relationships. Data with personal references to the use of this website (usage data) will be collected, processed, and used only if this is necessary to enable the user to use our services or required for billing purposes. The legal basis for these processes is Art. 6(1)(b) GDPR.
The collected customer data shall be deleted upon completion of the order or termination of the business relationship and upon expiration of any existing statutory archiving periods.
How We Use Your Personal Data (Legal Basis for Processing)
Minimum Viable Compliance Ltd. takes your privacy very seriously and will never disclose, share or sell your data without your consent; unless required to do so by law. We only retain your data for as long as is necessary and for the purpose(s) specified in this notice. Where you have consented to us providing you with promotional offers and marketing, you are free to withdraw this consent at any time.
The purposes and reasons for processing your personal data are detailed below:
- We collect your personal data in the performance of a contract or to provide a service.
- We collect and store your personal data as part of our legal obligation for business accounting and tax purposes.
- Where you have provided consent, we use your contact details to send you newsletters, updates, and relevant information about EU product compliance.
Your Rights
You have the right to access any personal information that Minimum Viable Compliance Ltd. processes about you and to request information about:
- What personal data we hold about you
- The purposes of the processing
- The categories of personal data concerned
- The recipients to whom the personal data has or will be disclosed
- How long we intend to store your personal data for
- If we did not collect the data directly from you, information about the source
If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information and we will strive to correct it as quickly as possible; unless there is a valid reason for not doing so, at which point you will be notified.
You also have the right to request erasure of your personal data or to restrict processing (where applicable) in accordance with the data protection laws; as well as to object to any direct marketing from us; to exercise your data portability rights, and to be informed about any automated decision-making we may use.
If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request; this is to ensure that your data is protected and kept secure.
Sharing and Disclosing Your Personal Information
We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement. All processors acting on our behalf only process your data in accordance with instructions from us and comply fully with this privacy notice, the data protection laws and any other appropriate confidentiality and security measures.
Safeguarding Measures
Minimum Viable Compliance Ltd. takes your privacy seriously and takes every reasonable measure and precaution to protect and secure your personal data. We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place, including SSL and TLS encryption for all communications. We operate under the principle of least privilege, restricting access to personal data to only those who require it.
Transfers Outside the EU
While we primarily seek to use services that process data within the European Union (EU), some of our essential third-party service providers are based in other countries, most notably the United States. Personal data in the EU is protected by the General Data Protection Regulation (GDPR), but some other countries may not necessarily have the same high standard of protection.
When your personal data is transferred outside the European Economic Area (EEA), we take steps to ensure it is protected with the same level of security and in accordance with this privacy notice. We achieve this by relying on lawful data transfer mechanisms, including:
- Decisions from the EU Commission that a specific country provides an adequate level of data protection (e.g., the EU-US Data Privacy Framework).
- Legal contracts approved by the European Commission that impose data protection obligations on the importer.
Specific details on the data transfer mechanisms for each relevant provider are listed in the Information That We Collect section of this policy.
Consequences of Not Providing Your Data
You are not obligated to provide your personal information to Minimum Viable Compliance Ltd., however, as this information is required for us to provide you with our services, we will not be able to offer some or all of our services without it.
How Long We Keep Your Data
Minimum Viable Compliance Ltd. only ever retains personal information for as long as is necessary and we have strict review and retention policies in place to meet these obligations. We are required under Maltese tax law to keep your basic personal data (name, address, contact details) for a minimum of 10 years after which time it will be destroyed.
Where you have consented to us using your details for direct marketing, we will keep such data until you notify us otherwise and/or withdraw your consent.
Marketing
Occasionally, Minimum Viable Compliance Ltd. would like to contact you (likely via email) with company updates, regulatory news, and other content we think might be useful for you. If you consent to us using your contact details for these purposes, you have the right to modify or withdraw your consent at any time by using the opt-out/unsubscribe options or by contacting us directly.
Lodging A Complaint
Minimum Viable Compliance Ltd. only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however, you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to lodge a complaint with the supervisory authority.
Minimum Viable Compliance Ltd. Daniel Thompson-Yvetot 230 Triq Il-Kungress Ewkaristiku, Mosta MST 9039, Malta privacy@mvc.eu
Office of the Information and Data Protection Commissioner (IDPC) Floor 2, Airways House, Triq il-Kbira, Sliema SLM 1549, Malta +356 2328 7100 idpc.info@idpc.org.mt
Last modified: April 2026