Privacy Policy — Pulse Social Wellness Club
Your privacy matters
We are committed to protecting your personal data and being fully transparent about how we collect, use, and safeguard it — in line with the GDPR and Maltese law.
Last Updated: 25 June 2026Contents
Section 01
Introduction
Carisma Wellness Group Ltd. (“Pulse”, “we”, “us”, or “our”) operates Pulse Social Wellness Club, a members’ social wellness club based at Grand Hotel Excelsior, Valletta, Malta. We provide members with access to an open gym (Technogym equipment and a self-access yoga & stretch studio for self-guided training), a spa and recovery suite — including sauna, indoor pool, jacuzzi, steam room and recovery zones — and amenities such as locker rooms, showers, a fuel bar and a co-working lounge. This Privacy Policy explains what personal data we collect about you, why and how we use it, who we share it with, how long we keep it, and the rights you have over it.
We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the Maltese Data Protection Act (Chapter 586 of the Laws of Malta) and its subsidiary legislation, and guidance issued by the Information and Data Protection Commissioner (IDPC) of Malta.
By using our website, enquiring about membership, or becoming a member of Pulse, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not provide us with your personal data.
Section 02
Who we are (data controller)
The data controller responsible for your personal data is:
Carisma Wellness Group Ltd.
Company Registration Number: C 106006
VAT Number: MT30347620
Registered Address: Grand Hotel Excelsior, Great Siege Road, Valletta, Malta
Club Location: Grand Hotel Excelsior, Valletta, Malta
Email: hello@pulsewellness.com
Phone: +356 27802062
For all privacy-related queries, requests, or complaints, please contact us using the email address above, marking your message for the attention of “Data Protection”.
Section 03
Personal data we collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
Identity & contact data
- Full name, date of birth, and gender
- Email address and telephone/mobile number
- Emergency contact details, where you provide them
Membership, access & financial data
- Membership type, check-in and facility-access records, and tour or appointment history
- Billing name and address, amounts paid, and payment references (we do not store full card numbers — these are handled by our payment provider)
- Records of correspondence and enquiries (email, phone, WhatsApp, social media, and contact-form messages)
Health & wellness data
- Health questionnaire responses, including any medical conditions, injuries, or physical limitations relevant to using our gym, spa and recovery facilities
- Information about your wellness goals, activity levels, and any special requirements disclosed to our team
Technical & website data
- IP address, device, browser, and operating-system information
- Pages visited, referring URLs, and interactions on our website
- Cookie and similar tracking-technology data (see Section 7)
- Email open and click data, for subscribers to our communications
Where we ask you to provide personal data to meet a legal or contractual requirement (for example, a health questionnaire before using our facilities), failure to provide it may mean we are unable to safely accommodate your use of the club.
Section 04
Health & wellness data
Some of the data we collect — in particular, information about your health conditions, injuries, or physical limitations — may constitute “special-category” data under Article 9 of the GDPR. We collect this information solely to ensure your safe use of our gym, spa and recovery facilities, and we treat it with additional care.
We rely on the following conditions to process this data:
- Article 9(2)(a) GDPR — your explicit consent, provided when you complete our health questionnaire or disclose relevant information before participating.
- Article 9(2)(c) GDPR — where necessary to protect your vital interests in an emergency situation where you are unable to consent.
You may withdraw your consent at any time by contacting us, though this may affect our ability to safely accommodate your use of certain facilities. We do not use health information you share with us for any purpose other than managing your safety and access.
Section 05
Legal bases for processing
We process your personal data on one or more of the following legal bases under Article 6 of the GDPR:
- Consent (Art. 6(1)(a)) — for marketing communications, non-essential cookies, and optional uses of your data such as testimonials or promotional content.
- Contract (Art. 6(1)(b)) — to fulfil your membership, manage your access to the club, and provide the services you have signed up for.
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, consumer-protection, and other legal duties.
- Vital interests (Art. 6(1)(d)) — to protect someone’s life or health in an emergency.
- Legitimate interests (Art. 6(1)(f)) — to run, secure, and improve our club and website, prevent fraud, and respond to enquiries, where these interests are not overridden by your rights.
For health and special-category data, we additionally rely on the Article 9 conditions set out in Section 4.
Section 06
How we use your data
- Managing your membership, arranging tours and appointments, and sending confirmations and reminders
- Ensuring your safe use of our gym, spa and recovery facilities by retaining relevant health and wellness information
- Processing payments and managing your membership account
- Responding to your enquiries, requests, and complaints
- Sending you service messages such as opening-hours or facility updates
- Sending marketing communications where you have consented (see Section 13)
- Operating, securing, and improving our website and services
- Meeting our legal, regulatory, accounting, and insurance obligations
- Establishing, exercising, or defending legal claims
Section 08
Sharing & processors
We do not sell your personal data. We share it only where necessary and with appropriate safeguards, including with:
- Our authorised staff, who are bound by confidentiality obligations, to manage your membership and your use of the club
- Trusted service providers (data processors) acting on our instructions — for example, CRM systems (GoHighLevel), IT and hosting providers, payment processors, email and communications platforms, and analytics providers
- Professional advisers such as accountants, insurers, and lawyers, where necessary
- Public authorities, regulators, or courts where we are legally required to disclose data
- A successor entity in the event of a business sale or reorganisation, subject to this Policy
All processors are bound by written contracts that require them to keep your data secure and to process it only on our documented instructions, as required by Article 28 of the GDPR. We do not sell your personal data to any third party.
Section 09
International transfers
We aim to keep your personal data within the European Economic Area (EEA). Some of our service providers may process data outside the EEA. Where this happens, we ensure an adequate level of protection by relying on a European Commission adequacy decision, or on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with any additional measures required. You may request a copy of the relevant safeguards using the contact details in Section 17.
Section 10
Data retention
We keep your personal data only for as long as necessary for the purposes set out in this Policy and to meet our legal obligations.
- Active member data is retained for the duration of your membership and for two years thereafter, to allow us to respond to any queries or claims.
- Membership, check-in and access records are retained for seven years for tax and legal purposes.
- Financial and accounting records are retained as required by Maltese tax and company law (generally a minimum of ten years).
- Marketing data is retained until you unsubscribe or withdraw consent, after which we keep a suppression record so we do not contact you again.
- Website and analytics data is retained for limited periods in line with the relevant cookie or tool settings.
When data is no longer needed, we securely delete or anonymise it. Specific retention periods are available on request.
Section 11
Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, disclosure, or destruction. These include access controls, staff confidentiality obligations and training, secure storage of member records, encryption in transit where appropriate, and the use of reputable, security-conscious service providers. No method of transmission or storage is completely secure, but we work continually to protect your data.
Section 12
Your rights
Under the GDPR and Maltese data-protection law, you have the right to:
- Be informed about how we use your data (this Policy)
- Access a copy of the personal data we hold about you
- Have inaccurate or incomplete data corrected (rectification)
- Have your data erased in certain circumstances (the 'right to be forgotten')
- Restrict our processing of your data in certain circumstances
- Object to processing based on our legitimate interests, and to direct marketing at any time
- Data portability — to receive certain data in a structured, machine-readable format
- Withdraw consent at any time, where we rely on consent (without affecting prior processing)
To exercise any right, contact us at hello@pulsewellness.com, marking your message for the attention of “Data Protection”. We will respond within one month, as required by law. We do not charge a fee unless your request is manifestly unfounded or excessive.
Section 13
Marketing communications
We will only send you marketing communications (such as offers, events, and club news) where you have given consent, or where otherwise permitted by law. Every marketing email contains an easy way to unsubscribe, and you can opt out at any time by contacting us. Opting out of marketing does not stop essential service messages relating to your membership.
Section 14
Children's data
Our services and website are intended for adults aged 16 and over. We do not knowingly market to or collect data from children under 16 without appropriate parental or guardian consent. If you believe a child has provided us with personal data without appropriate consent, please contact us and we will take appropriate steps to delete it.
Section 15
Data breaches
We have procedures to detect, report, and investigate personal-data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Information and Data Protection Commissioner (IDPC) without undue delay and, where required, within 72 hours. Where the breach is likely to result in a high risk to you, we will also notify you directly.
Section 16
Changes to this policy
We may update this Policy from time to time to reflect changes in our practices or the law. The “Last Updated” date at the top of this page shows when it was last revised. Where changes are significant, we will take reasonable steps to bring them to your attention — for example by email or a notice on our website. We encourage you to review this page periodically.
Section 17
Contact & complaints
If you have any questions about this Policy, wish to exercise your rights, or want to make a complaint about how we handle your data, please contact us:
Get in touch
Carisma Wellness Group Ltd.
Grand Hotel Excelsior, Valletta, Malta
Email: hello@pulsewellness.com
Phone: +356 27802062
You also have the right to lodge a complaint with the supervisory authority in Malta — the Information and Data Protection Commissioner (IDPC), Floriana, Malta — idpc.org.mt. We would, however, appreciate the chance to address your concerns first.