Privacy Policy
· Version 2026-08-13-v1
Who we are
- Trading name
- Giatrikonmas Pharmacy
- Registered address
- 12 1st April Avenue, Liopetri 5350, Cyprus
- antri@giatrikonmas.com
- Telephone
- +357 23 741 200
1. Who we are
The controller of your personal data is the company whose full details are set out in the "Who we are" box at the top of this page.
We have not appointed a Data Protection Officer. We do not meet the Article 37 GDPR threshold: processing special category data is neither our core activity nor carried out on a large scale. That assessment is documented. For any data protection matter, contact: «FILL IN: name of the responsible pharmacist and email».
2. What data we collect
- Account details — name, email address, password (stored hashed), telephone.
- Order details — shipping and billing address, order contents, order history, invoicing details (for business customers: company name and VAT number).
- Payment details — we never store card numbers. Card payments go directly to our provider Stripe; we receive only a confirmation and the last four digits.
- Correspondence — messages you send through the support form or by email, and our replies.
- Product reviews — the display name you choose and the review text.
- Saved favourites — the list of products you save, where you have given the separate explicit consent for it.
- Technical data — IP address, device and browser type, and the cookies described in the Cookie Policy.
3. Purposes and legal bases
We process your data for the following purposes, on the legal basis shown:
- Fulfilling your order, delivery, returns — Article 6(1)(b) — performance of a contract
- Creating and managing your account — Article 6(1)(b) — performance of a contract
- Processing health-related data — Article 9(2)(a) — explicit consent (see section 4)
- Saved favourites list — Article 9(2)(a) — separate explicit consent
- Invoicing, tax and accounting records — Article 6(1)(c) — legal obligation
- Answering support requests — Articles 6(1)(b) and 6(1)(f)
- Fraud prevention at payment — Article 6(1)(f) — legitimate interests
- Grouping customers on commercial signals — Article 6(1)(f) — legitimate interests (see section 8)
- Analytics or marketing cookies — Articles 6(1)(a) and 9(2)(a) — consent
4. Health-related data
Our store does not sell medicines. It sells food supplements, cosmetics, baby products and medical equipment.
Even so, we treat data linking you to specific products as special category data under Article 9 GDPR across the whole store. The reason: part of our catalogue — blood pressure monitors and glucose meters, wound care, iron supplements, breastfeeding and infant health products — permits, with reasonable probability, inferences about your state of health. Because a browsing session or a basket cannot be technically separated into "sensitive" and "non-sensitive" products, we apply the higher standard to all of it.
In practice this means we ask for separate, explicit consent at checkout before your order is completed, distinct from accepting the Terms and from cookie consent. You may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before it.
5. Who receives your data
We never sell personal data. We share it only with the following recipients, and only so far as necessary:
- Stripe Payments Europe Ltd (Ireland) and Stripe Inc. (USA) — payment provider; receives payment details, amount and contact details.
- Google Ireland Ltd — Google sign-in, only if you choose it; receives email, name and profile picture reference.
- Brevo (Sendinblue SAS, France) — transactional email delivery; receives email, name and order details.
- Courier companies — «FILL IN: names»; receive name, address and telephone.
- Hetzner Online GmbH (Germany) — server hosting, as infrastructure provider.
- Competent authorities — only where required by law.
Every provider is bound by a data processing agreement (Article 28 GDPR).
The site also loads flag icons for the language selector from the cdn.jsdelivr.net content delivery network, which receives your IP address. It is the only third-party request the site makes.
6. Transfers outside the EEA
Stripe transfers data to the United States. The transfer is covered by the European Commission's Standard Contractual Clauses (Article 46 GDPR), as set out in Stripe's Data Processing Addendum. Google transfers data to Google LLC (USA) under the EU–US Data Privacy Framework together with supplementary Standard Contractual Clauses.
7. How long we keep your data
- Orders, invoices, tax records — 6 years «FILL IN/CONFIRM: statutory tax retention period»
- Account details — while the account is active; deleted on your request.
- Cookie consent records — 24 months from the record.
- Support messages — 24 months.
- Product reviews — removed from public display with your account; retained in archive so it can be established what was removed.
- Saved favourites — permanently deleted on withdrawal of consent or account deletion.
- Customer grouping data — only orders from the last 24 months are considered.
8. Customer grouping and automated decisions
We group registered customers on commercial signals only: number of orders, total spend, and how recently they last ordered. No signal about which products or categories you bought or saved is used. The grouping produces no legal effects and does not significantly affect you within the meaning of Article 22 GDPR.
You have the right to object (Article 21(2) GDPR). If you exercise it, you are permanently removed from every group.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of any consent you have given.
Withdrawal is as easy as giving it: cookie consent is withdrawn from the "Cookie settings" link in the footer, and favourites consent from your account.
We respond within one month. To exercise any right, contact us using the details in section 1.
10. Complaints
If you believe the processing of your data infringes the GDPR, you may complain to the Office of the Commissioner for Personal Data Protection, 1 Iasonos Street, 1082 Nicosia, tel. +357 22 818 456.
commissioner@dataprotection.gov.cy · www.dataprotection.gov.cy
11. Security
The site runs exclusively over an encrypted connection (TLS). Passwords are stored hashed. We never store card numbers: they are processed entirely by Stripe, which limits our PCI-DSS compliance scope to SAQ A.
12. Changes to this policy
Every substantive change carries a new version and date, shown at the top of the page. Where the change concerns processing based on your consent, you will be asked again.
See also the Cookie Policy and the Terms and Conditions.
