1. Who is responsible
For WELCOME Maritime, Elcome International Holdings Ltd is the controller of the personal data described in this policy. Our contact address is The Core, Valley Road, Msida MSD 9021, Malta.
Email help@elcome.com with a privacy question or request. If another WELCOME edition identifies a different seller or controller when you buy, that entity's notice will apply to that purchase.
2. The data we use
| Data | Examples | Why and legal basis |
|---|---|---|
| Website technical data | IP address, request time, browser and device information, requested page, and security logs created by our hosting systems. | Keep the website available and secure. Legitimate interests in operating and protecting the service. |
| Account and contact data | Name, email address, phone number if provided, language, account identifier, authentication records, and organisation where relevant. | Create and protect your account, remember your plans, and communicate about the service. Performance of our contract and legitimate interests in account security. |
| Purchase and entitlement data | Plan or access code, price, currency, tax, order and receipt identifiers, payment status, activation, allowance, and expiry. The payment provider, not WELCOME, handles full card or wallet credentials. | Take payment, activate the plan, issue receipts, prevent fraud, and keep required financial records. Contract, legal obligations, and legitimate interests. |
| Wi-Fi and device data | Device MAC and assigned IP address, device name or type when supplied, site or vessel, session start and end, data volume, plan speed, disconnection reason, and network diagnostics. | Connect the correct device, meter the plan, share capacity fairly, troubleshoot faults, and protect the network. Contract, legitimate interests, and legal obligations that apply to an internet provider. |
| Service location | The WELCOME site, vessel, or Starlink terminal serving the session and its general location. | Confirm service availability, apply territorial rules, support a vessel, and investigate faults. Contract and legal obligations. Connecting to Wi-Fi does not by itself give us your phone's continuous GPS location. |
| Support and complaint data | Your messages, attachments, contact details, order or session reference, and the steps taken to resolve a request. | Answer you, fix problems, handle refunds or complaints, and demonstrate the outcome. Contract, legitimate interests, and legal obligations. |
We normally collect data from you, your device, the WELCOME gateway, a person who gives you an access code, and our identity, payment, hosting, and connectivity providers.
3. How we use the data
- show available plans, accept an order, activate access, meter usage, and display what remains;
- authenticate accounts and devices, prevent duplicate or unauthorised use, and recover access;
- process payments, refunds, access codes, tax records, and receipts;
- monitor service health, diagnose faults, enforce plan limits, manage shared capacity, and secure the network;
- answer support, privacy, accessibility, and regulatory requests;
- detect fraud, abuse, malware, and breaches of the acceptable use rules;
- comply with lawful requests, sanctions, accounting, communications, and data protection duties; and
- produce aggregated statistics that do not identify a person.
We do not use the content of your calls, messages, browsing, or other internet communications for advertising. Delivering and securing internet access can require processing traffic metadata and limited technical indicators. We may restrict traffic only where reasonably necessary for law, security, network integrity, congestion management, or enforcement of the plan you bought.
WELCOME does not make decisions based solely on automated processing that produce legal or similarly significant effects. A payment or identity provider may make its own automated fraud or security decision under its published notice. You can ask support to review a WELCOME access decision.
4. Who receives data
We disclose only what is needed for the purpose:
- Service providers. Identity, payment, cloud hosting, communications, monitoring, fraud prevention, and customer-support providers process data under contract or their own published terms.
- Starlink. Starlink carries the underlying satellite traffic and receives terminal, account, location, performance, and diagnostic data for its service. Starlink acts as a separate controller for data it determines how to use. Its privacy policy explains that processing.
- Vessel or site operators. Authorised staff may receive site status, aggregated usage, access-code records, and limited account or session details when needed to issue access or solve a problem. They do not receive your payment credentials or the content of your internet communications from WELCOME.
- Elcome group companies and advisers. Only where needed to operate, support, audit, insure, finance, or reorganise the service, with appropriate confidentiality safeguards.
- Authorities and affected parties. Where disclosure is required by law or reasonably necessary to protect users, the network, legal rights, or public safety.
We do not sell or rent personal data.
5. International transfers
WELCOME serves vessels that move between countries and uses global providers. Data may therefore be processed outside Malta or the European Economic Area. Where the destination does not benefit from an EU adequacy decision, we use an approved safeguard such as the European Commission's standard contractual clauses, together with supplementary measures where needed. You may ask us for information about the safeguard relevant to your data.
6. How long we keep data
We keep data only for as long as the purpose requires:
- account and entitlement data while the account or plan is active, then for the period needed to answer disputes, prevent fraud, and meet legal duties;
- orders, payments, tax, and refund records for the applicable statutory accounting and tax period;
- session, device, security, and diagnostic records for the shortest operational period that supports metering, troubleshooting, network security, and legal obligations; and
- support and complaint records until the issue and any reasonable appeal or limitation period have ended.
We then delete or irreversibly anonymise the data unless it must be preserved for a legal claim, investigation, or binding request. Backups expire on their normal protected rotation.
7. Your data protection rights
Under the GDPR, you may have the right to:
- receive a copy of your personal data and information about its use;
- correct inaccurate or incomplete data;
- ask for deletion or restriction where the legal conditions apply;
- receive data you provided in a portable format;
- object to processing based on legitimate interests or to direct marketing; and
- withdraw consent at any time where consent is the legal basis.
Email help@elcome.com. We may ask for information needed to verify your identity and protect the account. We normally respond within one month, subject to the extensions and exceptions allowed by law.
You may also complain to Malta's Information and Data Protection Commissioner, or to the data protection authority where you live or work. Please contact us first if you can, so we have a chance to resolve the concern.
8. Cookies and the marketing website
The current welcome.online marketing site does not set non-essential cookies, use advertising trackers, or run third-party analytics. It reads your device's colour-scheme preference to display the site, but does not store that preference. Our hosting provider may keep ordinary request and security logs.
If we add optional analytics, marketing technology, a support chat, or another feature that stores information on your device, we will update this policy and request consent where the ePrivacy rules require it.
9. Children and security
WELCOME is not designed for a child to buy independently where local law requires an adult to contract. A parent, guardian, vessel operator, or other authorised adult should arrange access for a child who cannot contract on their own. Contact us if you believe a child provided account data without proper authority.
We use administrative, technical, and physical controls designed to protect personal data, including access controls, encryption in transit, logging, and incident response. No internet service can promise absolute security. Protect your device, use encrypted websites and apps, and do not share passwords or full access codes.
10. Changes and contact
We will update the effective date when this policy changes. If a change materially affects how we use existing data, we will provide a prominent notice or contact affected account holders where reasonably possible.