Last Updated: 5 August 2026
Matthew Bartolo ("we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Members Portal ("Service"), in compliance with the General Data Protection Regulation (GDPR) and Maltese data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
Matthew Bartolo
Triq Mikielang Sapiano
Ħaż-Żebbuġ, Malta
Email: matthew@matthewbartolo.com
Website: matthewbartolo.com
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Data protection queries go to the address above.
2. Information We Collect
Information you provide directly:
- Account information: Full name, email address, and password when you create an account
- Profile preferences: Your selected interest areas and notification preferences
- Reflection responses: Any content you submit through guided reflection forms. Because these answers describe how you are doing mentally and emotionally, we treat them as health-related data and give them the additional protection described in Section 3
- Subscription data: Membership tier information and payment history (payment details are processed securely by our third-party payment processor and are not stored on our servers)
Information collected automatically:
- Usage data: Content viewed, pages visited, and interaction patterns within the portal
- Device information: Browser type, operating system, device identifiers, and IP address
- Essential cookies: Required for authentication and session management
- Analytics data: If you accept analytics in our cookie banner, Google Analytics 4 and Vercel Web Analytics collect information about how you use the portal. Neither runs unless you accept. See Section 7 and our Cookie Policy
3. How We Use Your Information
We process your personal data for the following purposes and legal bases under Article 6 of the GDPR:
- Providing the Service (contractual necessity): Account creation, authentication, delivering content based on your subscription tier, and managing your membership
- Personalisation (legitimate interest): Recommending content based on your selected interests and notifying you of new relevant material
- Communication (contractual necessity/consent): Sending password reset emails and account notifications. With your explicit consent, we also send weekly content digest emails and new event notification emails. You can opt in during account setup or at any time via your profile settings, and opt out via the unsubscribe link in any email or your profile settings
- Analytics (consent): Understanding how the portal is used so we can improve it. This processing only happens if you accept analytics in the cookie banner, and you can withdraw that consent at any time
- Legal compliance (legal obligation): Retaining data as required by applicable laws
3.1 Health-Related Data (Special Category Data)
This is a mental health and personal development service. Two kinds of information you give us can reveal something about your health, which Article 9 of the GDPR treats as a special category needing extra protection:
- Reflection responses, which are free-text answers about how you are feeling and coping
- Interest selections, where topics such as Addiction, Relationship Break-Up, or Emotional Regulation may imply something about your circumstances
We process this information on the basis of your explicit consent under Article 9(2)(a). You are asked to confirm that consent before a reflection is saved, and choosing interests is always optional. We record when consent was given so we can demonstrate it.
You may withdraw this consent at any time by emailing us. Withdrawal does not affect processing that already took place, and you can ask us to delete your reflections at the same time. Withdrawing does not cancel your membership or remove your access to content.
We do not use reflection responses for advertising, we do not sell them, and we do not use them to train any artificial intelligence or machine learning model.
5. Data Retention
We keep each category of data only as long as we need it:
| Data | Retention period |
|---|---|
| Account and profile information | While your account is active; deleted within 30 days of an account deletion request |
| Reflection responses and interests | While your account is active; deleted on account closure, or sooner on request |
| Content view history and notifications | While your account is active; deleted on account closure |
| Email delivery records (which emails were sent to you and whether they arrived) | 24 months |
| Subscription, ticket, and payment records | For as long as Maltese tax and accounting law requires us to keep them, even after your account is closed |
| Google Analytics data (only if you accepted analytics) | Up to 14 months, then deleted automatically by Google |
Payment records are the one category we cannot delete on request. Everything else goes when you ask us or when you close your account.
6. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure:Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request that we limit how we use your data
- Right to data portability: Receive your data in a structured, commonly used format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time. Analytics consent can be withdrawn from the Cookie Settings link in the footer, email consent from your profile settings, and consent for reflection responses by emailing us
To exercise any of these rights, please contact us at matthew@matthewbartolo.com. We will respond to your request within 30 days.
How to Submit a Data Request
You may submit the following requests at any time by emailing us:
- Data Subject Access Request (DSAR): Request a full copy of all personal data we hold about you. We will provide this in a structured, machine-readable format (e.g., JSON or CSV) within 30 days.
- Data Deletion Request: Request that we permanently delete all your personal data, including your account, profile information, content interactions, reflections, and notification history. Upon confirmation, deletion is completed within 30 days and is irreversible. Payment records are retained where tax and accounting law requires it, as set out in Section 5.
To submit a request, email matthew@matthewbartolo.com with the subject line "Data Request" and include the email address associated with your account. We may ask you to verify your identity before processing the request.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- Encrypted data transmission (HTTPS/TLS)
- Secure password hashing
- Row-level security policies on database access
- A strict Content Security Policy to limit what code can run in your browser
- Regular security reviews of our infrastructure
While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Maltese supervisory authority within 72 hours and inform you where the law requires it.
9. International Data Transfers
Your account data is stored inside the European Economic Area. Our database is hosted by Supabase in Frankfurt, Germany, and the application itself runs on Vercel's Frankfurt region.
Some processing does take place outside the EEA. Google Analytics, which only runs if you accept analytics, is provided by Google LLC in the United States. Vercel, Sanity, Brevo, and Revolut are also capable of processing limited data outside the EEA in the course of running their services.
Where data leaves the EEA, we rely on Standard Contractual Clauses approved by the European Commission, together with any additional safeguards those providers offer, such as the EU-US Data Privacy Framework where applicable. You can request a copy of the relevant safeguards by contacting us.
10. Children's Privacy
Our Service is not intended for individuals under the age of 16, and you must be 16 or older to create an account. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by email or through a prominent notice on the portal. We encourage you to review this policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Email: matthew@matthewbartolo.com
Website: matthewbartolo.com
This privacy policy is governed by the laws of Malta and the GDPR.
View Terms and Conditions →