Privacy policy
We process personal data only as far as necessary to deliver your order and answer your questions. We never sell or rent your data to third parties.
Last updated: 4 September 2026
This notice explains what we do with your personal data when you visit therapiummed.com, buy from us, write to us, or subscribe to our emails. It is written to be read, not filed. If anything in it is unclear, email us and ask.
The short version
- Who holds your data: Therapium Ltd, London, United Kingdom.
- How to reach us about it: office@therapiummed.com.
- How to get a copy of your data, correct it, or have it deleted: email that address, say what you want, and we answer within one month. There is no form to fill in and it costs nothing. Section 10 sets out every right you have and exactly how to use it.
- How to stop our marketing emails: click unsubscribe in any of them, or email us. It takes effect immediately and we never ask why.
- What we do not do: we do not sell your data, we do not make automated decisions about you, and we do not use your data to profile you.
1. Who is responsible for your data
Therapium Ltd is the controller of your personal data. That means we decide why it is held and what happens to it, and we are the ones answerable to you for it.
| Controller | Therapium Ltd, registered in England and Wales under company number 16471805 |
|---|---|
| Registered and trading address | 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom |
| Email for all data protection matters | office@therapiummed.com |
| Data protection officer | We have not appointed one. We are not required to: we do not carry out large-scale monitoring and we do not process special categories of data on a large scale. Your point of contact is the email address above. |
| Representative in the European Union (Article 27 GDPR) | [TO BE COMPLETED — name and full postal address of the appointed EU representative] |
We do not operate a customer telephone line. Email is the address we monitor, and you can also write to us at the postal address above.
2. Which data protection law applies to us
- We are established in the United Kingdom, so the UK GDPR and the Data Protection Act 2018 apply to everything we do.
- We also offer goods to people living in the European Union and the European Economic Area. Under Article 3(2) of the EU GDPR, that brings us within the EU GDPR as well, for the data of people in those countries.
- Both regimes therefore apply to us at the same time. Where they differ, we apply whichever gives you more protection.
- Because the EU GDPR applies to us and we are not established in the EU, Article 27 requires us to appoint a representative in the Union and to publish its name and address here. The line for it in section 1 is empty because no representative has yet been appointed. This is a gap we are aware of and it is being dealt with. It does not reduce any of your rights: everything in this notice applies to you now, and you can exercise all of it by writing to the email address in section 1.
- Cookies and anything else stored on or read from your device are also governed by the ePrivacy Directive (2002/58/EC) as implemented in your country, and by the UK Privacy and Electronic Communications Regulations. Our Cookie policy covers that.
3. What data we collect, and where it comes from
Almost everything we hold, you gave us yourself. Nothing here is bought from a data broker and nothing is scraped from social media.
| Category | What is in it | Where it comes from |
|---|---|---|
| Order and delivery data | Your name, email address, delivery address, billing address, telephone number if you give one, what you ordered, the price, the currency, the order number and the date. | You, at checkout. |
| Payment data | Confirmation that the payment succeeded, the method used, and a partial identifier such as the last four digits of a card. We never receive or store your full card number, expiry date or security code. Those go directly from you to the payment provider. | The payment provider, after you pay. |
| Account data | Your email address, your name, your saved addresses and your order history. Only if you choose to create an account — an account is optional and you can buy from us as a guest. | You, when you create the account. |
| Marketing data | Your email address, the fact that you consented, and the date and place you consented. If you unsubscribe, the fact and date of that. | You, when you subscribe. |
| Correspondence | Your messages to us and our replies, including anything you attach or type into the contact form: your name, your email address, your subject line and the body of your message. | You, when you write to us. |
| Returns, refunds and guarantee claims | The order the claim relates to, what you told us, what we decided, and the date and amount of any refund. | You and us, during the claim. |
| Technical and usage data | Your IP address, the type of browser and device you use, the pages you looked at, the site you arrived from, your approximate location at country level, and the language and country you are browsing in. | Collected automatically by the site as you use it. Section 4 and our Cookie policy explain how much of this depends on your consent. |
| Health information you volunteer | Anything you choose to tell us about a condition, a medicine, an allergy or a pregnancy when you ask us a question about a product. | You, and only you. We never ask for it. Section 6 explains what happens to it. |
4. What the website collects on its own
- The site is hosted and run on Shopify. Serving you a page necessarily involves your IP address and your browser's request, and Shopify records that in its server logs. This is unavoidable in the way that a postal address is unavoidable if you want a parcel.
- Some data is stored in your browser so the site can work at all — your basket, your session, and the language and country you are browsing in. That is what our Cookie policy calls strictly necessary, and it does not need your consent.
- Shopify's own commerce analytics measure how the shop is used in aggregate: which pages are visited, where visitors arrive from, where the checkout is abandoned. This is not strictly necessary and it depends on your consent. Please read the Cookie policy, which is honest about the fact that the mechanism for collecting that consent is not yet in place on this site.
- We use no third-party advertising network, no advertising pixels, no session-recording or heatmap tool, and no analytics product other than Shopify's own.
- The "What suits me?" quiz runs entirely in your browser. Your answers are not sent to us, not stored anywhere, and not attached to you. Its output is a product suggestion, not a decision about you, and not medical advice — see clause 10.10 of our Terms and conditions.
5. Why we use your data, and our lawful basis for each use
Data protection law requires us to have a specific legal reason for every use of your data, and to tell you what it is. Here they all are.
| What we do | Data used | Our lawful basis |
|---|---|---|
| Take your order, take payment, dispatch it, deliver it, and deal with a return or a refund | Order and delivery data, payment confirmation, returns data | Performance of a contract (Article 6(1)(b)). We cannot sell you anything without this, which is why these fields are required at checkout. |
| Send you order emails — confirmation, dispatch, delivery, refund | Email address, order data | Performance of a contract (Article 6(1)(b)). These are not marketing and you cannot unsubscribe from them while an order is live. |
| Give you an account, if you asked for one | Account data | Performance of a contract (Article 6(1)(b)) — the contract being the account itself, which you asked us to provide. |
| Issue invoices and keep accounting and tax records | Order data, invoice data | Legal obligation (Article 6(1)(c)). Tax law requires a seller to keep records of what it sold, to whom, and for how much. |
| Keep the records a food business has to keep, and act on a product safety problem | Order reference, product and batch, what you reported | Legal obligation (Article 6(1)(c)). As a food business operator we must be able to trace a batch one step back and one step forward, under Article 18 of Regulation (EC) No 178/2002, and we must act on a safety issue under product safety law. This duty is mostly about batches rather than about you, but where a report is tied to a specific order we keep it with that order. |
| Answer your questions and handle complaints | Correspondence, order data | Performance of a contract (Article 6(1)(b)) where your message is about an order. Legitimate interests (Article 6(1)(f)) where it is not — our interest being to run a shop that answers the people who write to it, which is also what you want when you write. |
| Send you marketing emails | Email address, name | Consent (Article 6(1)(a)). Only if you opted in, only until you withdraw, and withdrawing is one click. |
| Prevent fraud and keep the shop secure | Order data, technical data | Legitimate interests (Article 6(1)(f)). Our interest is not being defrauded and not having the site attacked. We have weighed it against your interests: the data used is what we already hold for the order, it is not combined with anything else, and it is not used to score or rank you. |
| Apply the conditions of our 60-day guarantee, including the limit of one claim per customer per product | Order data, guarantee claim records | Legitimate interests (Article 6(1)(f)). The condition is published in clause 11.1 of our Returns and refunds page, and we cannot apply it without keeping a record of claims already made. |
| Establish, exercise or defend a legal claim | Whatever is relevant to the claim | Legitimate interests (Article 6(1)(f)), and where a court or a law requires it, legal obligation (Article 6(1)(c)). |
| Understand how the shop is used, in aggregate | Technical and usage data | Consent (Article 6(1)(a)) for the part that involves storing or reading anything on your device, because the ePrivacy rules require consent for that. See the Cookie policy. |
| Respond to a lawful request from a public authority, a regulator or a court | Whatever the request validly covers | Legal obligation (Article 6(1)(c)). |
Do you have to give us this data?
- The order and delivery data is necessary to form and perform a contract of sale. If you do not give it, we cannot take your order. There is no other consequence.
- Everything else is optional. You do not have to create an account, you do not have to subscribe to anything, and refusing marketing has no effect whatsoever on your order, your price, your delivery or your rights.
6. Health information — please read this one
We sell food supplements. People who buy food supplements often have a reason, and sometimes they tell us. This section is about what happens then.
- Information about your health, your medication, a diagnosis, an allergy or a pregnancy is a special category of personal data under Article 9 of the GDPR. It has stronger protection than an address or an order number, and processing it is prohibited unless a specific condition in Article 9(2) applies.
- We never ask for it. There is no health question at checkout, no health field on the contact form, and no health question in the quiz. Our contact form asks for a name, an email address, a subject and a message, and nothing else.
- If you volunteer it in a message — "I take warfarin, can I use this?", "I am pregnant, is this suitable?" — we treat that as you asking us to use that information for the single purpose of answering your question, and nothing else. Article 9(2)(a) allows us to act on it on that basis, and that basis lasts exactly as long as the question does.
- Our honest answer to most such questions is that we cannot answer them. We are a shop, not a clinic. As clause 10 of our Terms and conditions says, only a qualified professional who knows your circumstances can tell you whether a supplement is suitable for you. We will tell you what is in the product, and we will tell you to ask your doctor or pharmacist.
- What happens to the message. Once we have answered you, we delete the health details from our records. In practice that means we delete the message thread, or where the thread also contains order information we have to keep, we remove the health content from it. We do this as soon as the exchange is closed and in any event within 30 days of our last reply.
- We never copy it into your customer record. We never use it to decide what to show you, what to recommend to you, or what to email you. We never share it with anyone.
- One exception, and we will tell you when it applies. If what you report is an adverse reaction to a product, product safety law requires us to record it and to be able to act on it. In that case we will ask for your explicit consent to keep the report with your details. If you would rather we did not, we will keep the report of the reaction with the product and the batch and remove everything that identifies you. Either way, the report itself has to exist — that is how unsafe batches get found.
- If you have already sent us something you would rather we did not hold, email office@therapiummed.com and say so. We will delete it and confirm that we have.
7. Who else sees your data
We share personal data only where it is needed to do something you have asked for, or where the law requires it. Everyone in the first group acts as our processor: they act on our instructions under a written data processing agreement and they may not use your data for their own purposes.
| Recipient | What they do | What they see |
|---|---|---|
| Shopify | Runs the shop. Hosting, the storefront, the checkout, the order records, the customer accounts, the transactional emails and the shop's own analytics all sit on Shopify's platform. | Everything held in the shop: order, delivery, account, marketing, correspondence and technical data. |
| Our payment provider | Takes your payment. Card details go from you to them directly and never pass through us. | Your payment details, your name and your billing address. The providers we use are listed at checkout and in clause 5.5 of our Terms and conditions. |
| Brands on Demand UG, Muthesiusstraße 6, 12163 Berlin, Germany | Manufactures the supplements we sell and fulfils orders. Connected to the shop through its Chance2Brand app, which reads orders so they can be packed and dispatched. | Your name, your delivery address and what you ordered. |
| Selfnamed | Manufactures and fulfils the private-label cosmetics part of the range, through an app connected to the shop. | The delivery details of the orders it fulfils: your name, your delivery address and what you ordered. |
| Delivery carriers | Deliver your parcel and, where they offer it, keep you updated about it. | Your name, your delivery address, and your email address or telephone number if you gave one for delivery notifications. Our carriers are named in clause 4.1 of Shipping and delivery. |
| The Shopify Claude Connector | An assistant provided by Shopify inside our admin, which we use to run the shop by asking it questions in ordinary language. It has access to the shop's records, which includes order and customer records, because that is the data the shop is made of. | Order and customer records when we use it on a task that involves them. We do not use it to analyse you or to make decisions about you. |
| Our accountant and professional advisers | Prepare and audit our accounts and advise us. | Invoice and accounting records. |
| Public authorities, regulators and courts | Only where a valid legal obligation requires disclosure — for example a tax authority, a food safety authority, or a court order. | Only what the obligation covers. |
- If our business is ever sold or transferred, customer records may transfer with it. If that happens we will tell you, and the buyer will be bound by this notice until it publishes its own.
- We do not sell your personal data, and we do not share it with anyone for their own advertising. If you are in the United States, your state's law may use "sell" and "share" more broadly than that; our Your privacy choices page deals with those rights specifically.
8. Sending data outside the United Kingdom and the EEA
This section matters, and we would rather explain the mechanics than reassure you vaguely.
- Our shop runs on Shopify. Shopify is a Canadian group with infrastructure in several countries, including the United States. That means your order data does leave the United Kingdom and the European Economic Area in the ordinary course of us selling you something. There is no version of using this shop in which it does not.
- Both the UK GDPR and the EU GDPR allow a transfer like that only if one of a defined set of safeguards is in place. The ones that are capable of applying here are these:
- An adequacy decision. Canada has been recognised as providing an adequate level of protection for data transferred to commercial organisations, by the European Commission and, separately, by the United Kingdom. Where a transfer is to a Canadian entity covered by that recognition, no further mechanism is needed.
- The EU–US Data Privacy Framework, and its UK extension. These allow transfers to organisations in the United States that have certified to the framework and remain on the list. They cover only certified organisations, so they apply to a given recipient or they do not.
- Standard contractual clauses. Where neither of the above covers a transfer, the standard contractual clauses approved by the European Commission are used, together with the United Kingdom's International Data Transfer Addendum for the UK side, backed by an assessment of the destination country.
- What we can tell you honestly: transfers connected with this shop are made under one or more of those mechanisms, as set out in Shopify's data processing addendum, which forms part of our contract with Shopify. What we are not going to do is tell you which specific mechanism covers which specific transfer as though we had verified it. That depends on Shopify's current corporate arrangements and its current certifications, and it can change. If you want to know exactly which safeguard applies to your data today, email office@therapiummed.com and we will confirm it with Shopify and tell you what they say, including how to obtain a copy of the relevant clauses.
- The other recipients in section 7 sit closer to home. Brands on Demand UG is in Germany, inside the EEA. Our payment provider, our carriers and our advisers are named or identified in the documents cross-referenced above; where any of them processes data outside the UK and the EEA, the same set of mechanisms applies.
- Whatever the mechanism, it does not reduce your rights. Everything in section 10 applies to data held anywhere, and we remain answerable to you for it.
9. How long we keep things
We do not keep data "just in case". Each category below has a period and a reason for that period.
| Category | How long | Why that long |
|---|---|---|
| Order, invoice and payment records | Six years from the end of the financial year the order falls in. Longer where the tax law of the country of sale requires it — several EU states require up to ten years for accounting records. [TO BE COMPLETED — the longest national retention period that applies to our sales, confirmed with our accountant] | UK tax law requires a company to keep its business records for six years. We cannot delete an invoice on request, because keeping it is a legal obligation rather than a choice. |
| Account data | Until you close your account. Deleted within 30 days of closure, except anything inside the invoice records above. | The account exists to serve you. When you no longer want it, its reason for existing has gone. |
| Correspondence and complaints | Three years from the end of the exchange. | We are liable for a lack of conformity that appears within two years of delivery, under clause 9 of our Terms and conditions. Three years covers that period plus time for a claim made near the end of it. |
| Returns, refunds and guarantee claims | With the order record it belongs to. | A refund is part of the accounting record of the sale. It is also how we apply the one-claim-per-customer-per-product condition in clause 11.1 of Returns and refunds. |
| Marketing consent | Until you withdraw it. After that we keep a minimal record — your email address and the fact and date you unsubscribed — indefinitely. | We have to be able to show that we had your consent while we were using it, and the suppression record is what stops you being added back to the list by accident later. It is the smallest amount of data that achieves that, and it is never used to contact you. |
| Health information you volunteered | Deleted as soon as we have answered you, and in any event within 30 days of our last reply. | Our only basis for holding it is to answer your question. When the question is answered, the basis is gone. See section 6. |
| Adverse reaction and product safety reports | [TO BE COMPLETED — retention period, confirmed with our food safety adviser, based on product shelf life and the applicable national rules] | Product safety and food traceability law requires these records to outlive the batch they concern. The exact period depends on shelf life and on national rules, and we would rather leave this blank than state a number we have not checked. |
| Server and security logs | Held by Shopify on our behalf, for the period Shopify sets. We do not control it. [TO BE CONFIRMED — Shopify's log retention period] | These logs are created by the hosting platform, not by us. We are telling you they exist rather than pretending they do not. |
| Cookies and anything stored on your device | See the Cookie policy, which gives the duration for each category. | Different mechanism, different rules, its own page. |
When a period ends we delete the data or anonymise it so that it can no longer be connected to you. Where we are holding something only because the law requires it, we hold it for that purpose alone and use it for nothing else.
10. Your rights
These rights are yours by law. Using them is free, and using them never affects how we treat you as a customer.
- Access (Article 15). You can ask us to confirm whether we hold data about you, and to give you a copy of it together with an explanation of what we do with it, who we share it with and how long we keep it.
- Rectification (Article 16). If something we hold is wrong or incomplete, you can have it corrected or completed. You can also change your own details in your account at any time.
- Erasure (Article 17). You can ask us to delete your data. We will, unless we have to keep something — an invoice we are required to retain, or a record needed for a live claim. If that happens, we will tell you exactly what we are keeping and why, and we will delete everything else.
- Restriction (Article 18). You can ask us to stop using your data while something is being sorted out — for example while we check whether data you say is wrong really is wrong, or while we consider an objection you have made.
- Portability (Article 20). For the data you gave us that we process on the basis of consent or of a contract, you can ask for a copy in a structured, commonly used, machine-readable format, and you can ask us to send it to another controller where that is technically feasible.
- Objection (Article 21). You can object to any processing we carry out on the basis of legitimate interests, and we must stop unless we can show compelling grounds that override your interests. Where you object to direct marketing there is nothing to weigh: we stop, immediately and permanently.
- Automated decisions (Article 22). You have the right not to be subject to a decision made solely by automated means that produces legal effects or similarly significantly affects you. As section 12 says, we do not make any such decisions, so in practice there is nothing here for you to exercise.
- Withdrawing consent (Article 7(3)). Where we rely on your consent, you can withdraw it at any time and as easily as you gave it. Withdrawing does not make what we did before unlawful, and it has no other consequences. Section 11 explains how.
- Complaining to a regulator (Articles 77 and 79). Section 13.
How to use any of them
- Email office@therapiummed.com. Put "Data request" in the subject line, tell us which right you want to use, and tell us the email address you used when you ordered so we can find your records.
- You do not need to fill in a form, quote an article number, give a reason, or use particular words. "Please delete my data" is a valid request and we will treat it as one.
- You can also write to us at Therapium Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
- We answer within one month of receiving your request. If a request is genuinely complex, or if you have made several, the law lets us take up to two further months — and if we need them, we will tell you within the first month, and tell you why.
- It is free. We may only charge a reasonable fee, or refuse, if a request is manifestly unfounded or excessive, and if we ever do that we will explain the decision and tell you how to challenge it.
- We may ask you to confirm who you are before we hand over personal data. That is a protection for you, not an obstacle: we will not send someone else's order history to whoever asks for it. We will ask for the least that will do the job.
11. Withdrawing consent
- Marketing emails. Click the unsubscribe link at the bottom of any of them, or email office@therapiummed.com and say "unsubscribe". Either way it takes effect at once, and we do not ask you to confirm, log in, or explain.
- Cookies and anything stored on your device. See the Cookie policy, which sets out how to change or withdraw a choice and is candid about the current state of the mechanism for making one.
- Health information you told us about. Email us and we will delete it, as section 6.8 says.
- Withdrawing consent never affects your order, your delivery, your refund rights, your statutory rights or our 60-day guarantee. Those do not depend on consent and cannot be taken away by withdrawing it.
12. Automated decision-making and profiling
- We do not make decisions about you by automated means, and we do not profile you. There is no automated scoring, no automated refusal of orders, no personalised pricing, no behavioural advertising and no automated risk rating.
- The checkout runs automated fraud checks that Shopify and our payment provider operate as part of taking a payment. If one of those flags an order, a human at Therapium looks at it and decides. An order is never cancelled by a machine on its own.
- The "What suits me?" quiz is not automated decision-making. It runs in your browser, it produces a suggestion from the answers you clicked, we never see the answers, and nothing about you changes as a result.
- If that ever changes, we will say so here before it starts, and we will explain the logic involved and what it means for you.
13. Complaining to a supervisory authority
- Please tell us first. Most problems are quickest to fix directly, and if we have got something wrong we would rather know. Email office@therapiummed.com.
- You do not have to come to us first, and nothing here requires you to. You may go straight to a regulator.
- In the United Kingdom the supervisory authority is the Information Commissioner's Office (ICO). It handles complaints about how organisations use personal data, and it is free to complain to.
- If you live in the European Union or the EEA, you may complain to the data protection authority of the country where you live, where you work, or where you think the problem happened. You do not have to complain in the United Kingdom and you do not have to complain in English.
- In Romania, that authority is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP). Please note that this is a different body from ANPC, which is named in clause 15 of our Terms and conditions: ANPC handles consumer complaints about a purchase, ANSPDCP handles complaints about personal data.
- Every EU and EEA country has its own equivalent authority. If you are not sure which one is yours, ask us and we will point you to it.
- You also have the right to an effective judicial remedy against us or against a supervisory authority, and to bring proceedings in the courts of the country where you live.
14. Children
- Our shop is not for children and our products are not for children. You must be at least 18 to place an order, as clause 3 of our Terms and conditions says.
- We do not knowingly collect personal data from anyone under 18, we do not market to children, and nothing on this site is designed to appeal to them.
- If we discover that we hold data about a child, we delete it. If you are a parent or guardian and you believe your child has given us data, email office@therapiummed.com and we will delete it and confirm that we have.
15. Keeping your data safe
- The site runs over an encrypted connection, and the platform, the payment provider and the fulfilment partners in section 7 all hold your data on their own secured infrastructure.
- Access to customer records inside our admin is limited to the people who need it to run the shop.
- We never receive full card numbers, so we cannot lose them.
- No system is perfectly secure and we are not going to claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will report it to the supervisory authority within 72 hours of becoming aware of it, and where the risk to you is high, we will tell you directly and without undue delay.
16. If you are in the United States
- Some US state privacy laws give residents a right to opt out of the "sale" or "sharing" of personal information, or of targeted advertising, using definitions that are broader than the ordinary meaning of those words.
- Those rights, and how to use them, are set out on our Your privacy choices page.
- We do not currently ship to the United States. That page is there so the right exists if you are browsing from a state that grants it.
17. Changes to this notice
- We will update this notice when what we do with data changes — a new processor, a new purpose, a new retention period, or a change in the law.
- The date at the top of this page always tells you when it was last changed. The version on this page is the current one.
- If a change materially affects you — a new purpose, a new category of recipient, or anything that would change a decision you have already made — we will not rely on you noticing the date. We will tell you by email if we have your address, before the change takes effect, and where the change needs your consent we will ask for it rather than assume it.
18. Language
- This notice is published in English, Romanian, German, French, Italian and Spanish.
- The translations are provided so you can read it in your own language, and we intend them to say the same thing. If a translation and the English version conflict, we will apply whichever is more favourable to you.
19. How to contact us about your data
- Email office@therapiummed.com. This is the address for every data protection question, request and complaint, and it is the one we monitor.
- By post: Therapium Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
- We do not operate a customer telephone line.
- If you are in the European Union you may also contact our Article 27 representative once one is appointed — see section 1. Until then, and regardless of it, the email address above reaches us and works.