Last updated
This policy explains what personal data we collect, why, what we do with it, how long we keep it, and what you can tell us to do about it. It is written to the General Data Protection Regulation and the Irish Data Protection Act 2018.
Cookies and similar technologies have their own page, the cookie policy, because they are governed by a different set of rules.
The data controller is NEEDS: registered company name, a private company limited by shares registered in Ireland, company number NEEDS: CRO number, registered office NEEDS: registered office address, trading as Aesthetic Medicine.
Data protection requests and questions go to NEEDS: data protection contact address. We answer within one month.
We are not required to appoint a Data Protection Officer and we have not appointed one. Requests are handled by the address above.
| What | Why we need it | Lawful basis |
|---|---|---|
| Name, business name, email, phone, delivery and billing address | To take an order, deliver it, invoice it, and talk to you about it | Performance of a contract |
| Professional registration details, for example a professional body, registration number, qualification or clinic details, and any document you send to evidence them | To check that a buyer is entitled to buy products restricted to practitioners, and to keep a record that we checked | Legal obligation and our legitimate interest in supplying restricted goods responsibly |
| VAT number, where you give one | To apply the correct VAT treatment on a cross-border business sale | Legal obligation |
| Order history, invoices, credit notes, delivery records | To run the account, handle returns and complaints, and meet our tax and traceability duties | Contract and legal obligation |
| Batch and traceability records against an order | So that if a manufacturer recalls a batch we can tell the people who received it | Legal obligation |
| Emails, calls and messages between us | To answer you and to keep a record of what was agreed | Legitimate interest |
| Payment details | Handled by our payment provider, not stored by us. We see the last four digits and the result | Contract |
| Technical data: IP address, browser, pages viewed | To keep the site working and secure. See the cookie policy for what is set and when | Legitimate interest, and consent where a cookie is not strictly necessary |
| Marketing preferences | To send you what you asked for, and nothing else | Consent |
A note on professional verification. Checking that somebody is a registered practitioner means holding information about that person's professional status and qualifications. We collect only what is needed to make the check, we record the outcome rather than keeping copies of documents longer than we need them, and we do not use any of it for marketing.
Only where they need it to do a job for us, and only under a contract that binds them to protect it.
The named list of processors is published here once the shop's payment and delivery providers are appointed, and this page will name them rather than describing them in general terms.
We keep data inside the European Economic Area wherever we can. If a provider we use processes data outside it, we rely on the safeguards the GDPR allows, normally an adequacy decision by the European Commission or the European Commission's standard contractual clauses.
You can ask us which providers those are and what safeguard applies to each, and we will tell you.
We only send marketing to somebody who asked for it, or to an existing customer about products similar to what they already bought, which is what the ePrivacy rules allow. Every message carries an unsubscribe link, it works immediately, and using it costs you nothing else. You will still get the emails we have to send about an order you placed.
You can ask us to:
Where we rely on your consent, you can withdraw it at any time. That does not undo anything done before you withdrew it.
Ask at NEEDS: data protection contact address. We answer within one month, and we tell you if we need longer and why. There is no charge, unless a request is clearly excessive or repetitive.
The site runs over HTTPS. Access to customer records is limited to people who need it. Payment card details never reach our servers. We review access when somebody joins or leaves.
No system is perfect. If a breach happens that is likely to put your rights at risk, we will tell the Data Protection Commission within 72 hours and, where the risk to you is high, we will tell you directly.
Tell us first if you can, at NEEDS: data protection contact address. You do not have to.
You have the right to complain to the Data Protection Commission, the Irish supervisory authority, at any time. Their website is dataprotection.ie and they publish a complaint form and a phone number.
If you live in another EU country you can complain to your own national supervisory authority instead.
When this policy changes, the date at the top changes with it. If a change materially affects how we use data we already hold, we will tell account holders directly rather than relying on you noticing this page.
A summary of everything above, not the policy itself. The numbered sections are the ones that count.
We supply dermal fillers, biostimulators, threads, mesotherapy and related products intended for use by qualified practitioners. They are not for sale to the general public.
By continuing you confirm that you are a healthcare or aesthetic professional, that you hold the qualifications required to use these products, or that you operate a business in the field.
Product information on this site is intended for professional reference and is not medical advice.