Last Updated: December 2025
This privacy policy describes how Mela collects, uses, stores, and protects the personal data of its users, in accordance with the EU General Data Protection Regulation (GDPR) and Maltese law.
For the purposes of the GDPR and applicable data protection laws, the Data Controller responsible for your personal information and the operation of the Mela platform is:
Any reference to "Mela", "we", "us", or "our" in this policy refers to Stefan Penchev acting as the data controller.
Mela is committed to processing personal data lawfully, fairly, and transparently. Our Privacy Policy is designed to be clear and concise, avoiding legal jargon. We regularly update this policy to reflect any changes in our data processing practices or GDPR regulations.
We ensure that our technical infrastructure (e.g., user registration, payment processing, analytics) is built with data protection in mind ("Privacy by Design"). This includes data minimization (only collecting necessary data), robust security measures (encryption, access controls), and mechanisms for users to easily exercise their rights.
We collect specific types of data such as names, email addresses, IP addresses, payment information, and shipping addresses. The purposes include order processing, account management, transaction facilitation, customer service, marketing, and security.
We process data based on the following lawful grounds:
Data Minimization is a key principle, ensuring that processing is adequate, relevant, and limited to what is necessary.
Your consent must be explicit, informed, and unambiguous. We do not use pre-ticked checkboxes; you must actively opt-in. If data is collected for multiple purposes (e.g., marketing and analytics), granular consent is required for each. You have the ability to withdraw your consent easily at any time.
GDPR grants extensive rights to you, the user. Mela has implemented mechanisms for efficiently tracking and managing data access requests. Your specific rights include:
To exercise any of these rights, please contact us at Info@melaapps.com.
Mela implements appropriate security measures, including encryption, access controls, and secure payment gateways. In the unlikely event of a data breach that poses a high risk to your rights and freedoms, Mela will notify the relevant supervisory authority (the Information and Data Protection Commissioner - IDPC in Malta) within 72 hours and inform affected customers without undue delay.
| Personal Data Category | Specific Data Points | Purpose of Processing | Legal Basis | Data Recipients | Retention Period |
|---|---|---|---|---|---|
| Identity Data | Name, Surname, Username | Account creation, Identity verification | Contractual necessity | Authentication providers | While account is active + legal obligation period |
| Contact Data | Email, Phone, Address | Order management, Notifications | Contractual necessity | Shipping carriers, Email providers | While account is active + legal obligation period |
| Financial Data | Payment card details | Payment processing, Refunds | Contractual necessity | Payment processors, Banks | As per legal/financial requirements |
| Transaction Data | Order history, Purchases | Order fulfillment, Support | Contractual necessity | Sellers, Delivery personnel | While account is active + legal obligation period |
| Technical Data | IP address, Cookies | Security, UX improvement | Legitimate interest | Analytics providers | As per cookie policy |
| Marketing Data | Preferences | Personalizing offers | Consent | Marketing platforms | Until consent is withdrawn |
If you have any questions about this policy or your data, please contact Stefan Penchev at Info@melaapps.com.