Legal
Privacy Notice
Updated 4 August 2026
This notice explains how Averquinth Systems handles personal data received through this website.
Scope
It applies to website visits, enquiry forms, public document requests and protected file downloads. It does not replace a customer contract or a product-specific data-processing notice.
Enquiries and tour requests
When you submit a form, we receive the contact and business information you provide. We use it to respond, assess your requirements, maintain a record of the conversation and protect the form from abuse. The lawful bases will generally be steps taken at your request before a contract and our legitimate interests in handling business enquiries securely.
Security and access logs
The server records a timestamp, request identifier, event type, HTTP method, path without query parameters, response status, response time, IP address, requested host, user agent, referrer path, language preference and—when supplied by the hosting network—country and edge-request identifiers. We use these records to operate the service, detect bots and abuse, investigate incidents and establish what happened after a security event.
The application deliberately excludes query strings from its security log, so a protected-file key is not written to the local application log. Upstream hosting or network providers may keep their own request records; protected keys should therefore be rotated after use or suspected disclosure.
Public and protected downloads
Documents in public/files are available to anyone with the URL. Any approved protected archive is mounted outside the public directory and delivered only when the service is explicitly enabled and receives the configured access key. Successful and unsuccessful requests are recorded as minimized security events.
Retention and security
Daily application security logs are kept locally on the server for 90 days by default and then deleted automatically. Enquiry records are stored in a non-public server directory and should be deleted when they are no longer needed for the request or any resulting business relationship. Access to both locations should be limited to authorised operators and protected by server-level permissions and backups appropriate to the deployment.
Your rights
Subject to applicable law, you may request access, correction, erasure, restriction or portability of your personal data, or object to certain processing. You may also complain to Malta’s Office of the Information and Data Protection Commissioner.
Contact
A dedicated privacy contact has not yet been approved for publication.