Privacy Policy

2026

Privacy Policy for Cystolax

1. Preamble and General Principles of Protection

The present document serves as the definitive Privacy Policy governing the processing of personal data undertaken in relation to the distribution, commercialisation, and support activities surrounding Cystolax, a dietary supplement formulated to support urinary tract wellness and bladder function. This policy has been constructed with strict adherence to the provisions established by Regulation (EU) 2016/679 of the European Parliament and of the Council, known generally as the General Data Protection Regulation (hereinafter referred to as "GDPR"), as well as any subsequent national legislation enacted within the Member States of the European Union that may supplement said Regulation.

It is the firm conviction of the Data Controller that the protection of privacy constitutes a fundamental right of every natural person. Consequently, all activities involving the collection, storage, utilisation, and transmission of personal information are conducted with the utmost respect for the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality. The present policy aims to provide the interested party, hereinafter referred to as the "Data Subject," with clear, comprehensive, and easily accessible information regarding the modalities according to which their personal data shall be managed.

This document applies to all natural persons who interact with the official digital platforms dedicated to Cystolax, including websites and associated applications, as well as to individuals who place orders for the product or subscribe to informational communications within the territory of the European Union and the European Economic Area. By engaging with Cystolax, the Data Subject expressly acknowledges having read, understood, and accepted the terms herein described without reservation.

2. Definitions and Scope of Application

For the purposes of the present Policy, certain terms shall bear the following meanings to ensure clarity and uniform interpretation:

  • Personal Data: Any information relating to an identified or identifiable natural person, such as name, identification number, location data, or online identifier.
  • Processing: Any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, or erasure.
  • Data Controller: The natural or legal person who determines the purposes and means of the processing of personal data.
  • Data Processor: A natural or legal person who processes personal data on behalf of the Controller.

It is to be specified that the present policy does not extend to websites, platforms, or services operated by third parties which may be accessible via hyperlinks present on our official channels. The user is therefore invited to consult with due attention the privacy policies published by such third parties, inasmuch as the present document shall not be considered applicable to processing activities carried out by subjects over whom we do not exercise direct control.

3. Categories of Personal Data Subject to Processing

In the course of the activities aforementioned, Cystolax may collect and process the following categories of personal data, strictly limited to what is necessary for the purposes indicated:

3.1. Identification and Contact Data

This category encompasses information such as surname and given name, residential or delivery address, electronic mail address, telephone number, and any other data necessary for the purpose of identifying the interested party and establishing effective communication channels. Such data are typically provided voluntarily by the user during the compilation of order forms, registration procedures, or requests for assistance.

3.2. Transactional and Commercial Data

Information relating to purchases effected, including details concerning the products acquired, quantities, prices, payment methods utilised, order history, and delivery preferences, shall be processed for the purposes of order fulfilment, invoicing, customer service provision, and management of commercial relationships. It is to be noted that financial data, such as credit card numbers or bank account details, are not directly stored by our systems but are transmitted to authorised payment service providers pursuant to secure encryption protocols.

3.3. Technical and Navigation Data

During the utilisation of our digital platforms, certain information may be automatically collected through standard internet communication protocols. This includes, by way of example, Internet Protocol addresses, browser type and version, time zone setting, operating system, device identifiers, pages visited, duration of visits, and clickstream data. Such information is generally processed in aggregated and anonymised form for statistical purposes, though in specific circumstances it may be considered personal data when it permits the identification of the individual user.

3.4. Data Provided Voluntarily Through Communications

Any information contained in messages, inquiries, feedback, or testimonials submitted by the user through contact forms, electronic mail, or other communication channels shall be processed for the purpose of responding to requests, providing assistance, and improving the quality of our services.

It is expressly affirmed that Cystolax does not solicit, nor does it intend to process, special categories of personal data as defined under Article 9 of the GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a natural person's sex life or sexual orientation, unless explicitly provided by the user for specific support purposes where strictly necessary.

4. Purposes and Legal Basis of Processing

The processing of personal data shall be carried out exclusively for the following purposes, each supported by an appropriate legal basis pursuant to Article 6 of the GDPR:

4.1. Execution of Pre-Contractual and Contractual Measures

Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract. This includes order processing, payment verification, product delivery, management of returns or refunds, and provision of customer support services. Without the provision of such data, it would not be possible to conclude the contract of sale.

4.2. Compliance with Legal Obligations

Processing is necessary for compliance with a legal obligation to which the controller is subject, including but not limited to fiscal and accounting requirements, obligations relating to product safety and traceability, and duties concerning the prevention of fraudulent activities within the commercial sector.

4.3. Legitimate Interests Pursued by the Controller

Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Such legitimate interests may include: improvement of website functionality and user experience, prevention of security incidents, management of IT systems, and conduct of internal analyses for business development purposes.

4.4. Consent of the Data Subject

Processing is based on the freely given, specific, informed, and unambiguous consent of the data subject, particularly with regard to: sending of promotional communications, participation in marketing initiatives, collection of testimonials, and processing of special categories of data where applicable. Consent may be withdrawn at any moment, without prejudice to the lawfulness of processing based on consent before its withdrawal.

5. Modalities of Processing and Data Retention

Personal data shall be processed by means of automated and/or manual instruments, with organisational and technical measures designed to ensure an appropriate level of security. Access to data shall be restricted to authorised personnel who require such access for the performance of their duties, and who are bound by appropriate confidentiality obligations.

With regard to retention periods, personal data shall be kept for no longer than is necessary for the purposes for which they are processed. Specifically:

  • Identification and transactional data shall be retained for the duration of the contractual relationship and, thereafter, for the period prescribed by applicable legislation concerning fiscal, accounting, and consumer protection obligations;
  • Technical and navigation data shall be retained for a period not exceeding twenty-four months from the date of collection, unless a longer retention is required for security purposes or legal proceedings;
  • Data processed on the basis of consent for marketing purposes shall be retained until such consent is withdrawn or until the purpose for which consent was given has been fulfilled, whichever occurs first.

Upon expiration of the relevant retention period, personal data shall be securely deleted or anonymised in such a manner as to prevent re-identification. It is our procedure to review retention schedules periodically to ensure compliance with the principle of storage limitation.

6. Communication and Transfer of Data to Third Parties

Personal data may be communicated to third parties only in the following circumstances and subject to appropriate safeguards:

6.1. Service Providers and Data Processors

Data may be shared with external subjects who provide services on our behalf, such as logistics operators, payment processors, IT maintenance providers, and customer service platforms. Such subjects shall act exclusively as data processors pursuant to Article 28 of the GDPR, under written instructions and with contractual obligations ensuring compliance with data protection standards.

6.2. Competent Authorities

Data may be disclosed to public authorities, regulatory bodies, or judicial institutions when such disclosure is required by applicable law or necessary for the establishment, exercise, or defence of legal claims.

6.3. Corporate Transactions

In the event of a merger, acquisition, or transfer of business assets, personal data may be transferred to the successor entity, provided that such entity undertakes to respect the terms of the present Privacy Policy and applicable data protection legislation.

It is hereby affirmed that personal data shall not be sold, rented, or otherwise commercialised for purposes unrelated to those explicitly described herein. The confidentiality of our customers is of paramount importance to the integrity of our brand.

7. International Transfers of Personal Data

Where personal data are transferred to recipients located outside the European Economic Area, such transfers shall be carried out only in compliance with Chapter V of the GDPR. Appropriate safeguards, such as Standard Contractual Clauses adopted by the European Commission or adequacy decisions issued by the European Commission, shall be implemented to ensure that the level of protection afforded to personal data is not undermined.

The Data Subject retains the right to request information regarding the specific safeguards applied to any international transfer of their personal data by contacting the Data Controller through the designated channels. We ensure that any transfer is conducted with the same level of care and protection as would be applied within the European Union.

8. Rights of the Data Subject

Pursuant to Articles 15 to 22 of the GDPR, the interested party enjoys the following rights with regard to their personal data, which may be exercised at any time:

8.1. Right of Access

The data subject has the right to obtain confirmation as to whether or not personal data concerning them are being processed, and, where that is the case, access to such data and relevant information regarding the purposes of processing, the categories of data concerned, and the recipients to whom the data has been disclosed.

8.2. Right to Rectification

The data subject has the right to obtain the correction of inaccurate personal data and the completion of incomplete data without undue delay. It is requested that the user verifies the accuracy of the data provided during the order process to facilitate this right.

8.3. Right to Erasure ("Right to be Forgotten")

The data subject has the right to obtain the deletion of personal data when certain conditions are met, such as when the data are no longer necessary in relation to the purposes for which they were collected or when consent is withdrawn.

8.4. Right to Restriction of Processing

The data subject has the right to obtain limitation of processing under specific circumstances, such as when the accuracy of the data is contested or when the processing is unlawful but the data subject opposes erasure.

8.5. Right to Data Portability

The data subject has the right to receive personal data in a structured, commonly used, and machine-readable format, and to transmit such data to another controller where the processing is based on consent or contract and carried out by automated means.

8.6. Right to Object

The data subject has the right to object, on grounds relating to their particular situation, to processing based on legitimate interests or for direct marketing purposes. In the event of an objection to direct marketing, the processing shall cease immediately.

Furthermore, the interested party has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if they consider that the processing of personal data relating to them infringes the GDPR. We are committed to cooperating fully with any such authority.

9. Cookies and Similar Technologies

Our digital platforms may utilise cookies and similar tracking technologies to enhance user experience, analyse navigation patterns, and personalise content. Cookies are small text files stored on the user's device which allow recognition of the browser during subsequent visits.

We utilise the following categories of cookies:

  • Essential Cookies: Strictly necessary for the operation of our platforms, enabling basic functions such as page navigation and access to secure areas of the website. These cannot be disabled.
  • Analytical Cookies: Allow us to recognise and count the number of visitors and to see how visitors move around our platforms. This information is used to improve the way our platforms work and is always processed in an anonymised manner.
  • Functional Cookies: Enable our platforms to remember choices made by the user and to provide enhanced, more personal features.

Users may manage cookie preferences through their browser settings or via the consent management tool provided on our website. It is to be noted that disabling certain categories of cookies may affect the functionality of specific features of the platform.

10. Security Measures and Data Protection

We adopt appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Such measures include, inter alia: encryption of data in transit and at rest, regular security assessments, access controls, staff training on data protection, and incident response procedures.

Notwithstanding the efforts undertaken, it is to be acknowledged that no method of transmission over the Internet or electronic storage is absolutely secure. Therefore, whilst we strive to utilise commercially acceptable means to protect personal data, we cannot guarantee absolute security. However, in the event of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, we shall notify the competent supervisory authority and, where necessary, the affected data subjects without undue delay.

11. Modifications to the Present Policy

The present Privacy Policy may be subject to modifications or updates in response to changes in applicable legislation, technological developments, or evolution of our processing activities. Any substantial changes shall be communicated to users through appropriate channels, and the updated policy shall be published on our official digital platforms with indication of the date of last revision.

It is recommended that users consult this document periodically to remain informed regarding the modalities according to which their personal data are protected and processed. Continued use of the services following any modifications constitutes acceptance of the updated Policy.

12. Final Provisions and Governing Law

The present Privacy Policy is governed by the laws of the European Union and, where applicable, by the national legislation of the Member State wherein the user resides. Any dispute arising in connection with the interpretation or application of this policy shall be subject to the exclusive jurisdiction of the competent courts, without prejudice to the right of the data subject to bring proceedings before the courts of their habitual residence.

For any clarification, request, or exercise of rights pursuant to the present policy, the interested party may contact the data controller through the dedicated channels made available on our official digital platforms. We express our gratitude for the trust placed in Cystolax and reaffirm our commitment to protecting the privacy and personal data of all individuals who choose to utilise our products and services.

This document has been prepared with the utmost care to ensure compliance with European standards for data protection and reflects the principles of accountability and transparency.