Privacy Policy
1. Controller
The controller responsible for data processing on this website is:
HealthEncounters
2. General information
We process personal data only where necessary to provide this website, process orders, communicate with customers, process payments or comply with legal obligations. Relevant legal bases include Art. 6(1)(b), (c) and (f) GDPR and, where consent is required, Art. 6(1)(a) GDPR.
3. Server logs
When the website is accessed, technically necessary information such as IP address, access time, requested page, browser type, operating system and referrer may be processed. This is done to provide the website securely and reliably and to diagnose errors on the basis of Art. 6(1)(f) GDPR.
4. Cookies and session data
The website uses technically necessary session information and cookies, for example for the cart, login and language preference. These are required to provide the functions requested by you.
5. Customer accounts
If you create an account, we process data including your email address, password hash and any name or address information you provide. The data is used to manage your account and simplify order processing under Art. 6(1)(b) GDPR.
6. Orders and delivery
When you place an order, we process the data necessary to perform the contract, including name, email address, delivery address, ordered items, order value, payment status and any order notes. Processing is based on Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(c) GDPR for statutory retention requirements.
Where shipping service providers are used, the data required for delivery is transmitted to the respective provider.
7. Bitcoin payments and BTCPay Server
Bitcoin payments are processed through a self-hosted BTCPay Server. Payment-related data may include invoice ID, Bitcoin payment address, amount and payment status. Bitcoin transactions are also recorded publicly on the Bitcoin blockchain, and we cannot control the permanent storage of blockchain data.
The legal basis for processing in connection with contract performance is Art. 6(1)(b) GDPR.
8. Email communication
When you contact us or receive automated order, verification or password emails, the contact data required for that communication is processed. External email service providers may be involved as processors where applicable.
9. Usage data
Simple usage events such as page views, product views and cart actions may be stored on our own systems for technical and business analysis and to improve the website, where permitted on the basis of Art. 6(1)(f) GDPR.
10. Retention
Personal data is retained only for as long as necessary for the relevant purpose or as required by law. Uncompleted orders may be deleted after the applicable reservation period. Statutory retention obligations remain unaffected.
11. Recipients and service providers
Personal data is shared only where necessary for website operation, communications, payment, delivery or legal obligations. Recipients may include hosting, DNS, email and shipping providers.
12. Your rights
Subject to the legal requirements, you have rights including access, rectification, erasure, restriction of processing, data portability and objection. You may also withdraw consent with future effect where processing is based on consent.
You also have the right to lodge a complaint with a competent data protection supervisory authority.
13. Security
We use appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. Absolute security during internet transmission cannot be guaranteed.
14. Last updated
Last updated: August 2026.
