Privacy policy

Last updated

This policy explains what personal data we collect, why, what we do with it, how long we keep it, and what you can tell us to do about it. It is written to the General Data Protection Regulation and the Irish Data Protection Act 2018.

Cookies and similar technologies have their own page, the cookie policy, because they are governed by a different set of rules.

1Who is responsible for your data

The data controller is NEEDS: registered company name, a private company limited by shares registered in Ireland, company number NEEDS: CRO number, registered office NEEDS: registered office address, trading as Aesthetic Medicine.

Data protection requests and questions go to NEEDS: data protection contact address. We answer within one month.

We are not required to appoint a Data Protection Officer and we have not appointed one. Requests are handled by the address above.

2What we collect, and why

WhatWhy we need itLawful basis
Name, business name, email, phone, delivery and billing addressTo take an order, deliver it, invoice it, and talk to you about itPerformance of a contract
Professional registration details, for example a professional body, registration number, qualification or clinic details, and any document you send to evidence themTo check that a buyer is entitled to buy products restricted to practitioners, and to keep a record that we checkedLegal obligation and our legitimate interest in supplying restricted goods responsibly
VAT number, where you give oneTo apply the correct VAT treatment on a cross-border business saleLegal obligation
Order history, invoices, credit notes, delivery recordsTo run the account, handle returns and complaints, and meet our tax and traceability dutiesContract and legal obligation
Batch and traceability records against an orderSo that if a manufacturer recalls a batch we can tell the people who received itLegal obligation
Emails, calls and messages between usTo answer you and to keep a record of what was agreedLegitimate interest
Payment detailsHandled by our payment provider, not stored by us. We see the last four digits and the resultContract
Technical data: IP address, browser, pages viewedTo keep the site working and secure. See the cookie policy for what is set and whenLegitimate interest, and consent where a cookie is not strictly necessary
Marketing preferencesTo send you what you asked for, and nothing elseConsent

A note on professional verification. Checking that somebody is a registered practitioner means holding information about that person's professional status and qualifications. We collect only what is needed to make the check, we record the outcome rather than keeping copies of documents longer than we need them, and we do not use any of it for marketing.

3What we do not do

  • We do not sell your personal data. Not to anyone, ever.
  • We do not share it with advertising networks or data brokers.
  • We do not build profiles of you, and no decision about you is made by automated means alone.
  • We do not ask for or want health data about your patients, and you should not send it to us. If you need to describe a clinical situation, please do it without identifying anybody.

4Who else sees it

Only where they need it to do a job for us, and only under a contract that binds them to protect it.

  • Our hosting and website providers, who keep the site running.
  • Our payment provider, who takes the payment. They are a controller in their own right for fraud prevention.
  • Couriers, who need a name, an address and a phone number to deliver.
  • Our accountants and auditors, for the financial records the law requires us to keep.
  • A manufacturer or the relevant authority, where a product safety issue or a recall means we have to say who received a batch.
  • Professional advisers, insurers and, where we are legally required, the authorities.

The named list of processors is published here once the shop's payment and delivery providers are appointed, and this page will name them rather than describing them in general terms.

5Sending data outside the EU

We keep data inside the European Economic Area wherever we can. If a provider we use processes data outside it, we rely on the safeguards the GDPR allows, normally an adequacy decision by the European Commission or the European Commission's standard contractual clauses.

You can ask us which providers those are and what safeguard applies to each, and we will tell you.

6How long we keep it

Order and invoice records
Six years after the end of the tax year they relate to, which is what Irish tax law requires.
Batch and traceability records
Kept for as long as product traceability requires, which can be longer than six years for some medical devices.
Professional verification records
For as long as the account is open, and six years after it closes.
Correspondence
Three years, unless it relates to a complaint or a claim, in which case until that is resolved and the limitation period has run.
Marketing consent
Until you withdraw it. We also stop sending if you have not opened anything in two years.
An account you ask us to close
Deleted, except for the records above that we are legally required to keep.

7Marketing

We only send marketing to somebody who asked for it, or to an existing customer about products similar to what they already bought, which is what the ePrivacy rules allow. Every message carries an unsubscribe link, it works immediately, and using it costs you nothing else. You will still get the emails we have to send about an order you placed.

8Your rights

You can ask us to:

  • show you the personal data we hold about you, and give you a copy;
  • correct anything that is wrong or incomplete;
  • delete it, where we do not have a legal reason to keep it;
  • restrict what we do with it while a dispute about it is sorted out;
  • hand it over to you or to somebody else in a machine-readable form, where we hold it on the basis of consent or a contract;
  • stop, where we are relying on legitimate interests, or where it is marketing. For marketing there is no argument: we stop.

Where we rely on your consent, you can withdraw it at any time. That does not undo anything done before you withdrew it.

Ask at NEEDS: data protection contact address. We answer within one month, and we tell you if we need longer and why. There is no charge, unless a request is clearly excessive or repetitive.

9Keeping it safe

The site runs over HTTPS. Access to customer records is limited to people who need it. Payment card details never reach our servers. We review access when somebody joins or leaves.

No system is perfect. If a breach happens that is likely to put your rights at risk, we will tell the Data Protection Commission within 72 hours and, where the risk to you is high, we will tell you directly.

10Complaining about how we handle your data

Tell us first if you can, at NEEDS: data protection contact address. You do not have to.

You have the right to complain to the Data Protection Commission, the Irish supervisory authority, at any time. Their website is dataprotection.ie and they publish a complaint form and a phone number.

If you live in another EU country you can complain to your own national supervisory authority instead.

11Changes to this policy

When this policy changes, the date at the top changes with it. If a change materially affects how we use data we already hold, we will tell account holders directly rather than relying on you noticing this page.

The short version

  • We collect what we need to take your order, get it to you, and prove who you are where the law requires it.
  • We do not sell your data and we do not share it with advertisers.
  • Marketing only ever goes out if you asked for it, and every message has an unsubscribe link that works.
  • You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Tell us and we will do it inside one month.

A summary of everything above, not the policy itself. The numbered sections are the ones that count.

Questions about this page

Data protection questions, and requests to see, correct or delete your data.

info@irishmediaagency.ie +353 1 443 4433

This page was last updated on 22 August 2026. We keep older versions on file and will tell account holders before any change that affects an order already placed.

Trade only
Accounts verified against your professional registration
Irish based
Priced in euro, shipping across Ireland and the EU
CE marked
Medical devices CE marked, cosmetics EU notified
341 brands
From the injectable lines clinics know to Korean skincare

Your Shopping cart

Close