- Introduction & General Terms
- About Us
Engage People Limited (C-90119) and AX Group p.l.c. (C-12271) form part of the AX Group of companies (“AX Group”), a diversified conglomerate operating across four key business sectors: Construction, Development, Healthcare, and Hospitality.
For the purposes of this Privacy Policy, references to “we”, “us”, or “our” refer to Engage People Limited, AX Group p.l.c., and any other entity falling within the AX Group. We respect your privacy and are committed to protecting your personal data. Whether you are browsing our website/s or contacting us with enquiries, we ensure that processing of your personal data is done in an appropriate, lawful and transparent manner, and in accordance with the Data Protection Act (Chapter 586 of the Laws of Malta) (the “Act”) and the General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”).
- Scope
The purpose of this Privacy Policy (the “Policy”), which should be read in conjunction with our Cookie Policy, is to provide you with information in terms of article 13 of the GDPR.
This Policy sets out the basis on which your personal data is processed by us,and is intended to inform you about how we will handle and safeguard your personal data, particularly when you visit the website and other AX Group websites (the “Website” or the “Site”) and make use of our online facilities. It also outlines:
- our obligations in processing your personal data responsibly, lawfully and transparently;
- your rights as a data subject; and
- the legal protections afforded to you.
This Policy also provides clear information on how we collect and process your personal data when you interact with us online, including when you browse our website, subscribe to our newsletter, use our Contact Form,
You are encouraged to read this Policy together with any other privacy or fair processing notices we may provide on specific occasions when collecting or processing your personal data. This Policy is designed to supplement those notices, not to override them, ensuring you are fully informed about how and why your data is used.
This Policy is provided in a layered format so you can click through to the specific areas set out below:
- Who we are
- Your Personal Data: What We Collect, How We Collect it and Why;
- Our Use of Your Personal Data
- Disclosures of Your Personal Data;
- International Transfers of Personal Data;
- Cookies and Tracking Tools
- Data Security;
- Data Retention;
- Your Legal Rights;
- Updates to This Privacy Policy.
- The Website
Please note that the Website is not intended for persons under the age of 18, and that we do not knowingly collect data relating to minors, Provided that such shall not apply to persons having attained the age of 16 where the intention is to seek lawful employment with us through the
To give you a better service, our Website may contain links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. When connecting to such other websites you will no longer be subject to this Policy, but to the privacy statements and practices of the third-party site.
Please note that we do not control these third-party websites and are not responsible for their privacy statements or practices. We strongly encourage you to review the applicable privacy policies of any website you visit, as these will govern the use of any personal information you submit or that may be collected. We do not accept any liability for the content, security, or data practices of such third-party websites, and your use of them is entirely at your own risk.
- General Terms
- all headings are for ease of reference only and shall not affect the construction or interpretation of this Policy;
- unless the context otherwise requires, references to the singular include the plural and vice versa and references to any gender include every gender;
- unless the context otherwise requires, references to any statute or statutory provision will include any subordinate legislation made under it and will be construed as reference to such statute, statutory provision and/or subordinate legislation as modified, amended, extended, re-enacted and/or replaced and in force from time to time following the date of this Policy;
Terms used in this Policy shall have the same meaning as those defined under the GDPR, unless otherwise specified.
- Who We Are
- Controller
For the purposes of this Policy, the Data Controller (as such term is defined in the GDPR) shall be Engage People Ltd and/or an alternative AX Group company, the identity of which is dependent on the nature of your interaction or the specific service being requested and provided. Any company forming part of the AX Group may act as the Data Controller, the Data Processor, or both. The relevant AX Group entity responsible for your personal data will be identified based on the specific circumstances in which your data is collected and processed. Regardless of the entity involved, your data will be handled in accordance with this Policy and the overarching standards of data protection applied throughout the AX Group and in strict compliance with the GDPR.
- Data Protection Contact Point
We have appointed a Data Protection Contact Point who is responsible for overseeing matters relating to this Policy. Any queries relating to this Privacy Policy or our data processing practices, including any requests to exercise Your Legal Rights, should be directed to our Data Protection Contact Point using the contact details provided below.
| Email address: | dp@axgroup.mt |
| Postal address: | AX Group, AX Business Centre, Triq Id-Difiza Civili, Mosta MST 1741, Malta, Europe |
Should you feel dissatisfied with the manner in which your personal data has been handled, you have the right to file a complaint at any time with the Information and Data Protection Commissioner (“IDPC”) as the supervisory authority for data protection matters in Malta (https://idpc.org.mt/en/Pages/Home.aspx) or your local supervisory authority. We would, however, welcome and appreciate the opportunity to address your concerns directly before you approach the IDPC and we encourage you to reach out to us in the first instance.
- Your Personal Data: What We Collect, How We Collect it and Why
- What personal data do we collect
‘Personal Data’, or personal information, refers to any information that relates to an individual from which that individual can directly or indirectly be identified. Information that does not identify an individual, such as anonymised data, is not considered personal data.
We may collect, use, store and transfer various categories of personal data about you which we have grouped together as follows:
- Identity Data – which includes your first name, last name, title, nationality, date of birth and gender;
- Contact Data – which includes your email address and telephone or mobile number(s);
- Correspondence Data – which includes information, material and documentation which you may provide when filling in forms on the Website and corresponding with us;
- Compliance Data –
- includes your credit card or payment details;
- Technical Data – which includes your internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the device(s) you use to access our website;
- Profile Data – which includes your username and password, purchase history, your interests, preferences, feedback and survey responses;
- Usage Data – which includes information about how you interact with and use our website and Services;
- Marketing and Communications Data – which includes your preferences in receiving marketing communications from us and our business partners, as well as your communication preferences.
We also collect, use and share Aggregated Data such as statistical or demographic information, for various purposes. Aggregated Data may be derived from your personal data but is not considered personal data at law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data in a way that could directly or indirectly identify you, we treat the resulting combined data as personal data, and handle it in accordance with this Policy.
- How and why we collect your personal data
- When visiting our Website
Our Website is designed to allow you to browse without necessarily identifying yourself or revealing any personal information. However, once you choose to provide us with your personal data, we will protect such information and process it in accordance with this Policy.
While it is possible to visit our Website without actively submitting any personal data, to ensure optimal functionality and provide you with the best experience when browsing our Website, we may be required to process certain data which can identify you and which would therefore be considered to be personal data.
In particular, we may collect the following types of information about you whenever you access and interact with our Website:
- Technical information: this includes details such as the IP address used to connect your computer to the Internet, your login information, browser type and version, the full Uniform Resource Locators (URL), clickstream to, through and from our Website (including date and time) as well as other information regarding your experience on our Website such as page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs) and methods used to browse away from the page.
- Location Information: We may receive and collect information about your approximate or precise location. We may determine your location through your IP address and, when accessing the Website through a mobile device, by using the data that we collect from this device. This includes precise location information from GPS or information about the wireless networks or cell towers near your mobile device at the time of access.
For further details on how we use cookies or similar technologies to collect certain information about your visit to our Website, please refer to our Cookie Policy .
- When using the ‘Contact Us’ Form
Our Website allows you to submit an enquiry through our ‘Contact Us’ Form and get in touch with our team for assistance.. In order for us to be able to reply to your query accurately and efficiently, we shall require certain basic contact information, such as your name, surname and email address, as well as information relating to your query.
Based upon the information which you provide, one of our representatives will contact you directly to be able to provide assistance as per your request.
- When using the “Apply Now” Form
The “axcareers” website allows you to apply for advertised vacancies and to submit information, documentation and data in pursuance thereto
In order for us to be able to process any application, we shall require certain basic contact information, such as your name, surname and email address, as well as your curriculum vitae and any other data requested, and we would be required to process personal data.
The personal data which we request from you shall generally be restricted to the data which is necessary for us to be process any applications.
We do not collect any Special Categories of Personal Data about you, such as data relating to your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data.
- Your obligations in providing personal data
In certain circumstances, we are required by law or by the terms of a contract we have with you, to collect specific personal data. If you fail to provide the requested data when required, we may be unable to perform our obligations emanating therefrom.
This may ultimately result in our being unable to provide the services you have requested or fulfilling legal or regulatory obligations.
- Our Use of Your Personal Data
- How we use your personal data
We shall only process and use your personal data when permitted by law. Most commonly, we shall process and use your personal data in the following circumstances:
- Contractual necessity – where the processing is required for the performance of a contract to which you are a party, or to take steps at your request prior to entering into such a contract;
- Legitimate interests – where the processing is necessary for our legitimate interests (or those of a third party), except where such interests are overridden by your fundamental rights and freedoms; and
- Legal obligation – where we are required to process your personal data in order to comply with a legal or regulatory obligation.
We will ensure that your personal data is processed lawfully, fairly, and transparently, in accordance with Article 6 of the GDPR and other applicable provisions.
- Purposes for which we will use your personal data
We have set out below, in a table format, the purposes for which we may process your personal data, along with the applicable legal bases under the GDPR. Where relevant, we have also indicated our legitimate interests.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose and context for which we are using your personal data. Should you require further information about the specific legal ground we are relying on to process your personal data, where more than one ground has been set out in the table below, please contact us using the details provided in this Privacy Policy.
| Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
| To be able to take steps to enter into a contract with you, or perform the contract which we enter into with you, or to provide you with a Service | § Identity Data
§ Contact Data § Financial Data § Compliance Data |
Article 6(1)(b) – Performance of a contract
Article 6(1)(c) – Compliance with a legal obligation |
| To assess and process payments for services, including verifying payment methods and generating invoices. | § Financial Data
§ Contact Data |
Article 6(1)(b) – Performance of a contract
Article 6(1)(f) – Legitimate interests (fraud prevention and operational efficiency) |
| To respond to service-related queries and special requests from residents or their representatives, and provide customer support. | § Identity Data
§ Contact Data § Information relating to your query |
Article 6(1)(b) – Performance of a contract
Article 6(1)(f) – Legitimate interests (customer support) |
| To manage our relationship with you, including notifying you of changes to our terms or privacy policy, requesting feedback, and conducting satisfaction surveys. | § Identity Data
§ Contact Data § Profile Data § Marketing and Communications Data |
Article 6(1)(b) – Performance of a contract
Article 6(1)(c) – Compliance with a legal obligation Article 6(1)(f) – Legitimate interests (to keep our records updated and to study how customers use our products/services and for overall service improvement) |
| To ensure the safety and security of our residents, guests, visitors, staff and premises, through the operation of CCTV and digital infrastructure. | § CCTV Image Data
§ Location Data § Technical Data |
Article 6(1)(d) – Vital interests (safety of personnel and property)
Article 6(1)(f) – Legitimate interests (security of premises) |
| To administer and protect our business and this Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | § Identity Data
§ Contact Data § Technical Data |
Article 6(1)(c) – Compliance with a legal obligation
Article 6(1)(f) – Legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) |
| Professional or Employment-Related Information | § Current Job Title
§ Employer § Resume and documents attached in pursuance |
Article 6(1)(f) – Legitimate interests (to communicate with you and to screen and assess applications and requests by you) |
| To personalise services based on recorded preferences and prior interactions. | § Profile Data
§ Contact Data |
Article 6(1)(f) – Legitimate interests (personalised care and service) |
| To make suggestions and recommendations to you about goods or services that may be of interest to you | § Identity Data
§ Contact Data § Technical Data § Marketing and Communications Data § Profile Data |
Article 6(1)(a) – Consent (where required)
Article 6(1)(f) – Legitimate interests (to develop our products/services and grow our business) |
| To comply with legal and regulatory obligations applicable to our operations. | § Identity Data
§ Compliance Data |
Article 6(1)(c) – Compliance with a legal obligation |
- Marketing and Promotional Offers
- Direct Marketing
We are committed to giving you control over how your personal data is used, particularly in relation to marketing and promotional communications. We will only send you marketing communications such as emails, notifications, or promotional messages, where we have obtained your prior express consent.
We may use your Identity, Contact, Technical, Usage and Profile Data to better understand your preferences and determine which of our products, services, or offers may be relevant and of interest to you (‘Direct Marketing’).
You will receive marketing communications from us if you have:
- subscribed to our newsletter;
- joined our Loyalty Scheme (AX Plus); or
- maintain an ongoing relationship with us such as in the event you are a bondholder or a party to a time-share contract with us.
In these cases, we rely on our legitimate interest in strengthening and maintaining our existing relationship with you and inform you of any offers which may be of interest to you. In all other instances, we will only send you marketing communications and promotional messages where we have obtained your prior express consent.
- Third-party marketing
We will never share your personal data with any company outside the AX Group for marketing purposes without first obtaining your explicit, informed, and freely given consent. This means you will be clearly informed about who we intend to share your data with, the specific marketing purposes involved, and your rights regarding such sharing before any transfer occurs. Your consent will be recorded and can be withdrawn at any time without affecting your other interactions with us.
- Opting out
If you have consented to receive marketing material, you can withdraw your consent at any time. You can also request that we or any third parties stop sending you marketing messages by either following the ‘unsubscribe’ links included in any marketing communication sent to you or by contacting us directly using the details provided in this Privacy Policy.
Please note that opting out of receiving these marketing communications, will not affect our processing of personal data provided to us as a result of the Services which we provide to you or any personal data which we are obliged to retain as a result of our legal obligations.
- Additional Processing Activities
- Use of CCTV for Safety and Security
In order to ensure the safety and security of our residents, guests, visitors, staff and property, please note that we have installed CCTV surveillance in order to be able to detect and prevent illegal or otherwise illicit activity on our premises. As a result, we may collect personal data relating to your appearance as well as your location at a given point in time. This is carried out in order to protect your vital interests as well as in furtherance of our legitimate interest to protect our premises. All CCTV footage is deleted after thirty (30) days unless there is an overriding interest requiring longer retention of such personal data, such as in cases where there is a legal claim or an ongoing investigation. Access to CCTV data is strictly limited to authorised personnel and, where required, regulatory or law enforcement authorities.
- Customer Feedback and Review Monitoring
We may collect and process customer feedback through surveys, review platforms, or direct communication for quality assurance and service improvement. This may include follow-up communication based on the feedback provided.
- Event Participation or Promotions
If you participate in any events, contests, or promotions we organise, we may collect and process your data for administration of the event, communication, and fulfilment of any prizes or benefits. Additional notices may apply in such instances.
- Access Logs and Entry Monitoring
For security, operational integrity, and internal audit purposes, we may monitor and record access to certain areas within our premises, such as private, restricted, or staff-only zones, using key cards, digital access systems, or physical sign-in registers.
These access logs may capture personal data such as names, ID numbers, timestamps, and location data related to entry and exit activity. This processing is carried out on the basis of our legitimate interest in maintaining a secure and well-managed environment for all individuals on site, including residents, staff, contractors, and visitors.
Access data is retained only for as long as necessary to fulfil security and audit purposes, unless longer retention is required due to a legal obligation or investigation.
- Social Media Interaction
If you engage with us via social media platforms (e.g., comments, messages, tags), we may process this data for customer support or brand engagement purposes, in accordance with the privacy settings of the platform and your preferences.
- Internal Reporting and Analytics
We may anonymise or pseudonymise your data for internal reporting, statistical analysis, and operational improvements. Where data is anonymised, it no longer constitutes personal data and is excluded from the scope of this Policy.
You have the right to object at any time to such processing of your personal data as further explained under Section (9).
- Change of purpose
We will only use your personal data for the purposes for which it was originally collected, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. Should you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
Should we need to use your personal data for a purpose unrelated to the original purpose, we will notify you in advance and we will explain the legal basis permitting such use.
Please note that in certain circumstances, we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
- Disclosures Of Your Personal Data
We may have to share your personal data with the parties set out below for the purposes set out in Section (3) of this Policy.
- Affiliated Entities: we may disclose, transfer or otherwise provide access to your personal data to our Affiliated Entities for any of the reasons indicated in Section (3) of this Policy.;
- External Third-Party Service Providers: to effectively deliver our Services, we may also transfer your personal data to trusted external third parties, namely our service providers. In particular, we may transfer your personal data to our IT and software support service providers, our insurers and external legal counsel. We contractually require all such third parties to maintain the confidentiality and respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions;
- Regulatory and Government Authorities: We may also disclose your personal data to governmental, regulatory, executive, or judicial authorities which may have jurisdiction over our operations. Any such disclosures will be strictly limited to what is legally necessary to comply with our legal obligations.
- International Transfers of Personal Data
In certain circumstances, we may need to transfer your personal data to countries outside the European Economic Area (‘EEA’). Such transfers will only occur where one of the following legal bases applies:
- the transfer is necessary for the performance of a contract between you of one part and the AX Group of the other part, or for the implementation of pre-contractual measures taken at your request;
- the transfer is necessary for the conclusion or performance of a contract concluded in your interest between us and another natural or legal person;
- the transfer is necessary for important reasons of public interest; or
- the transfer is necessary for the establishment, exercise or defence of legal claims.
In addition, where necessary to support our operations and service delivery, we may transfer your personal data to our third-party suppliers, such as IT and system support providers and cloud service providers, which may be located outside of the EEA. In such cases we take all necessary steps to ensure that your personal data is handled responsibly to a standard that is essentially equivalent to that guaranteed within the EEA and in line with applicable data protection laws. This includes:
- Ensuring the recipient country has been recognised by the European Commission as providing an adequate level of data protection; or
- Implementing appropriate safeguards, such as Standard Contractual Clauses (‘SCCs’) approved by the European Commission, binding corporate rules, or other lawful mechanisms.
- Cookies and Tracking Tools
We use cookies and similar tracking technologies to improve the functionality of our Website, enhance user experience, analyse traffic, and support our digital marketing efforts. Cookies are small text files stored on your device when you visit a website. Some cookies are necessary for the website to function, while others help us personalise content and advertising or collect analytical data.
You can manage your cookie preferences at any time by adjusting your browser settings or using the cookie banner or preference management tool available on our Website. Please note that by disabling or refuting cookies, some parts of this Website may become inaccessible or not function properly.
For more detailed information about the cookies we use, the purposes for which we use them, and how to manage your cookie preferences, please refer to our Cookie Policy.
- Data security
We have put in place appropriate technical and security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Additionally, access to your personal data is strictly limited to those employees, agents, contractors, or authorised third parties who have a legitimate business need to know. Such persons are bound by confidentiality obligations and are required to process personal data only in accordance with our instructions and applicable data protection laws.
We have also established procedures to identify, investigate, and respond to any suspected personal data breaches. In the event of a breach involving your personal data, we will notify you and the relevant supervisory authority where we are legally required to do so.
- Data retention
We will only retain your personal data for as long as necessary to fulfil the purposes for which such data collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
When determining the appropriate retention period for personal data, we take into account:
- the amount, nature, scope and sensitivity of the personal data;
- the potential risk of harm from unauthorised use or disclosure;
- the purposes for which we process your personal data and whether we can achieve those purposes through other means; and
- the applicable legal requirements.
In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) and use it for research or statistical purposes. Anonymised data is no longer considered personal data and may be retained indefinitely without further notice.
- Your legal rights
Under applicable data protection laws, including the GDPR, you have several rights in relation to your personal data. These rights are subject to certain conditions and limitations and may vary depending on the lawful basis for processing.
10.1. Your data protection rights
You have the right to:
10.1.1. Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it;
10.1.2. Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us;
10.1.3 Request erasure of your personal data. This enables you to request the deletion or removal of your personal data where there is no lawful reason for us to continue processing it. This right also applies:
- where you have successfully exercised your right to object to processing (as per below);
- where we may have processed your information unlawfully; or
- where erase of your personal data is required to comply with a legal obligation.
Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request;
10.1.4. Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which compels you to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to continue processing your information which grounds override your rights and freedoms;
10.1.5. Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
- if you want us to establish the data’s accuracy;
- where our use of the data is unlawful, but you do not want us to erase it;
- where you need us to retain the data, even if we no longer require it, as you need it to establish, exercise or defend legal claims; or
- you have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it;
10.1.6. Object to profiling – where we conduct limited profiling for service personalisation or operational improvement, you have the right to object at any time to profiling and analysis of your preferences;
10.1.7. Request the transfer of your personal data to you or to a third party (data portability). You may request that your personal data be transferred to you or to a third party of your choosing, in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you;
10.1.8. Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before such withdrawal of your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
If you wish to exercise any of the rights set out above, please contact our Data Protection Contact Point.
10.2. No fee usually required
You will not be charged a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. In such cases, we may refuse to comply with your request, where permitted by law.
10.3. Verification of identity
To protect your personal data, we may need to request specific information from you to help us confirm your identity before fulfilling your request. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to request further information in relation to your request to expedite our response.
10.4. Time limit to respond
We aim to respond to all legitimate requests within one (1) month. In some cases, such as when your request is complex or you have submitted multiple requests, it may take us longer than a month to accommodate your request(s). In this case, we will notify you and keep you informed of the progress.
- Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, legal obligations, or the services we offer. The date of the most recent revisions will appear on this page. Where appropriate, we will also notify you of any material changes through our Website or other communication channels.
We encourage you to review this Policy periodically to remain informed about how we collect, use, and protect your personal data.


