Privacy Policy
Privacy Policy
Last updated: 09/07/2026
This Privacy Policy explains how The Bridge – The Third Millennium Teaching Ltd collects, uses, and protects your personal data when you visit or make a purchase on shop.thebridgecart.com (the “Site”). It is provided in accordance with Regulation (EU) 2016/679 (“GDPR”) and the Data Protection Act (Chapter 586 of the Laws of Malta).
1. Data Controller
The Bridge – The Third Millennium Teaching Ltd
Registered office: CMS House, Third Floor, St. Peter’s Street, San Gwann SGN 2310, Malta
Company registration number: C116263
VAT: MT 3292-4705
Privacy contact: privacy@thebridgettmt.com
General contact: info@thebridgettmt.com
We have not appointed a Data Protection Officer (DPO), as we are not legally required to do so. For any privacy matter you may contact us at privacy@thebridgettmt.com.
2. What data we collect
Depending on how you interact with us, we may process:
- Identification and contact data: first and last name, email address, telephone number, postal/billing address.
- Account data: username, password (stored in encrypted form), order history, preferences.
- Order and transaction data: products/services purchased, amounts, invoicing data, VAT number where applicable.
- Payment data: processed directly by our payment providers (Stripe, PayPal). We do not store your full card details on our servers.
- Communications data: messages you send us, support requests, and email interactions.
- Navigation and usage data: IP address, browser type, device, pages visited, and similar data collected through cookies and similar technologies (see our Cookie Policy).
- Marketing data: consent status, interactions with our emails and advertisements.
3. Why we process your data, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
| Processing your orders, providing the purchased services, managing your account | Performance of a contract (Art. 6(1)(b)) |
| Customer support and responding to your requests | Performance of a contract / legitimate interest (Art. 6(1)(b)/(f)) |
| Issuing invoices and meeting tax and accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Sending order confirmations and service-related communications | Performance of a contract / legal obligation (Art. 6(1)(b)/(c)) |
| Sending our newsletter and commercial communications | Consent (Art. 6(1)(a)) — or the “soft opt-in” for similar products to existing customers, where permitted |
| Publishing photos/videos of events in which you are identifiable | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, and exercising or defending legal claims | Legitimate interest / legal obligation (Art. 6(1)(f)/(c)) |
Where processing is based on consent, you may withdraw it at any time (see Section 8), without affecting the lawfulness of processing carried out before withdrawal.
4. Who we share your data with (processors and third parties)
We share personal data only with providers who act as our data processors or independent controllers, strictly for the purposes above. Our main providers are:
- HubSpot, Inc. (USA) — CRM, contact management, and sending order and service confirmation emails.
- Make.com (Celonis Inc. / Make) — workflow automation that transmits form data from the Site to HubSpot.
- Stripe and PayPal — payment processing.
- SiteGround — web hosting of the Site (WordPress, self-hosted).
We may also disclose data to consultants, accountants, and lawyers bound by confidentiality, and to public authorities where required by law. We do not sell your personal data.
5. International transfers (outside the EU/EEA)
Some of our providers are based in the United States (HubSpot, Make.com, and in part Stripe/PayPal). When your data is transferred outside the EU/EEA, we ensure an adequate level of protection through:
- the EU-US Data Privacy Framework, to which HubSpot and Stripe are certified; and/or
- the European Commission’s Standard Contractual Clauses (SCCs), used among others by Make.com and PayPal, together with supplementary measures where appropriate.
You may request a copy of these safeguards by writing to privacy@thebridgettmt.com.
6. How long we keep your data
We keep your data only for as long as necessary for the purposes for which it was collected:
- Account and order data: for the duration of the account, and afterwards for the applicable limitation period.
- Invoicing, tax, and accounting data: for the period required by Maltese law (generally up to [10] years).
- Marketing data: until you withdraw consent or object, and in any case reviewed periodically.
- Navigation/cookie data: for the periods set out in the Cookie Policy.
When data is no longer needed, it is deleted or irreversibly anonymised.
7. Cookies and tracking technologies
The Site uses only technical cookies strictly necessary for its operation (for example, session management, shopping cart, security, and storing your cookie preferences). The Site does not use profiling, analytics, or advertising cookies from third parties such as Meta, Google, or TikTok. Payment providers (Stripe, PayPal) may set cookies strictly necessary for fraud prevention and to process your payment. Because these cookies are strictly necessary, they do not require prior consent; full details are set out in our [Cookie Policy].
8. Your rights
Under the GDPR you have the right to: access your data; request rectification; request erasure (“right to be forgotten”); restrict processing; object to processing (including for direct marketing); data portability; and to withdraw consent at any time.
To exercise these rights, write to privacy@thebridgettmt.com. We will respond without undue delay and in any case within one month.
You also have the right to lodge a complaint with the Maltese supervisory authority:
Information and Data Protection Commissioner (IDPC)
Level 2, Airways House, High Street, Sliema SLM 1549, Malta — idpc.org.mt
or with the supervisory authority of your country of residence (for example, the Garante per la protezione dei dati personali in Italy, or the Agencia Española de Protección de Datos in Spain).
9. Minors
Our programmes may be aimed at participants aged 10–17. Purchases and account registration must be completed by an adult (a parent or legal guardian). In accordance with the Data Protection Act (Chapter 586), where processing is based on consent in relation to information society services offered directly to a child, such consent is lawful from the age of 13; below that age, we require the consent of a parent or legal guardian. We do not knowingly collect data from children below this age without such consent; if you believe we have, please contact privacy@thebridgettmt.com and we will delete it.
10. Data security
We adopt appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse, including encryption of credentials, access controls, and vetted providers. No system is completely secure, but we work to protect your data on an ongoing basis.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified on the Site and, where appropriate, by email. The “last updated” date at the top always indicates the current version.
12. Contact
For any question about this Policy or your personal data:
privacy@thebridgettmt.com — The Bridge – The Third Millennium Teaching Ltd, CMS House, Third Floor, St. Peter’s Street, San Gwann SGN 2310, Malta.