Last Updated: 27.06.25
At Tilfreds, your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website or use our services, including when you complete a medical questionnaire or order hair loss products.
Tilfreds is fully compliant with the General Data Protection Regulation (GDPR) and relevant EU and national data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
VitaPlus Group B.V.
HERENGRACHT 449-A
1017 AMSTERDAM
Email: info@Tilfreds.eu
2. What Personal Data We Collect
Depending on how you interact with our website, we may collect the following types of data:
a) Identification Data
- Name
- Date of birth
- Country of residence
- Contact information (email, phone number)
b) Health Information
- Medical history and symptoms (submitted via the Medical Questionnaire)
- Photographs (if required for assessment)
Note: Health data is classified as “special category” data under GDPR and is handled with the highest level of protection.
c) Order & Transaction Data
- Billing and shipping address
- Purchase history
- Payment method (we do not store card data directly)
d) Technical Data
- IP address
- Browser type
- Device information
- Website usage patterns (cookies, analytics)
3. Legal Basis for Processing
We process your personal data only where permitted by law, including:
- Consent: For processing your medical questionnaire and sending marketing emails (if opted-in).
- Contractual necessity: For order processing and delivery.
- Legal obligation: For tax, compliance, and healthcare regulations.
- Legitimate interest: For fraud prevention, security, and customer support.
4. How We Use Your Data
- To evaluate your medical eligibility for prescription treatments
- To fulfill and ship non-prescription orders
- To coordinate prescriptions with licensed doctors and pharmacies
- To communicate order updates and health information securely
- To respond to your inquiries and provide customer support
- To comply with applicable legal requirements
5. Sharing Your Data
We only share your data when necessary and in compliance with GDPR:
- With licensed doctors for reviewing your medical questionnaire
- With licensed EU pharmacies to dispense prescribed medications
- With payment processors (PCI-DSS compliant) to handle secure payments
- With service providers (e.g., email platforms, IT support) under strict data processing agreements
- With legal or regulatory authorities when required by law
We never sell your personal data.
6. International Data Transfers
Tilfreds is hosted on WordPress.com, which may store or process personal data in the United States. WordPress.com adheres to the European Commission’s Standard Contractual Clauses and offers a Data Processing Agreement to ensure an adequate level of data protection as required under the GDPR.
If we transfer your data outside the EEA, we ensure appropriate safeguards such as: – EU Standard Contractual Clauses – Data Protection Agreements
7. Data Retention
- Medical data: Retained for 5 years to comply with EU medical standards.
- Order and invoice data: Retained for 7 years for tax compliance.
- User account data: Retained as long as your account is active.
- Cookies and analytics: Retention periods vary based on cookie type (see Cookie Policy).
8. Your Rights
Under GDPR, you have the right to: – Access your data – Rectify inaccurate data – Request deletion (“right to be forgotten”) – Restrict or object to processing – Data portability – Withdraw consent at any time
To exercise your rights, contact: [support@Tilfreds.eu]
You also have the right to lodge a complaint with your national data protection authority.
9. Cookies and Tracking
We use cookies and similar technologies to improve user experience and analyze traffic. For more information, please refer to our Cookie Policy.
10. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- End-to-end encryption of medical questionnaire data
- Secure (HTTPS) data transfer – Access control and authentication for internal systems
- Regular security audits
11. Updates to This Policy
We may update this Privacy Policy from time to time. All changes will be posted here with the updated date. Significant changes will be notified by email if you have an account with us.
12. Contact Us
If you have any questions about this policy or how we handle your data:
VitaPlus Group B.V.
Email: info@tilfreds.eu