Privacy and cookie statement


1. Who is responsible for your data?

Shen Qi Medical Centre is the controller within the meaning of the GDPR for the processing operations described in this document.


2. What personal data do we process?

Depending on your use of our webshop, we may process the following data:

  • Identification and contact details: name, (delivery/billing) address, email, telephone.
  • Account details: login name, password (encrypted), order overview, preferences.
  • Order and transaction data: ordered products/services, order number, payment status, invoice information.
  • Payment details: processed via payment providers; we do not receive full card details.
  • Communication data: email and customer service contact.
  • Marketing data: newsletter registration and preferences.
  • Technical/usage data: IP address, device and browser information, cookie IDs, sessions, pages visited, shopping cart.
  • Health-related information (optional): only when you provide this voluntarily for advice and only with your explicit consent.


3. Purposes and legal bases (GDPR Art. 6)

  1. Orders and delivery; customer administration, payments, delivery. Basis: performance of agreement (Article 6(1)(b)); statutory obligation for tax administration (Article 6(1)(c)).
  2. Customer service and communication. Basis: performance of contract; legitimate interest (quality of service) (Art. 6(1)(f)).
  3. Account management and security of the webshop. Basis: performance of contract; legitimate interest (fraud prevention/IT security) (Art. 6(1)(f)).
  4. Newsletter/marketing (upon registration or existing customer relationship for similar products). Basis: consent (Article 6(1)(a)) or legitimate interest with opt-out (Article 6(1)(f)   Telecommunications Act).
  5. Analysis and improvement of our services and performance. Basis: legitimate interest (Art. 6(1)(f)).
  6. Health data (only if relevant to the advice you request). Basis: explicit consent (Article 9(2)(a)); you can withdraw this consent at any time.


4. Cookies and similar technologies

We use cookies and similar technologies to make our site work, remember preferences, analyze usage, and—if you allow—support marketing.


4.1 Categories

  • Strictly necessary/technical cookies – Essential for basic functions (login, shopping cart, security). No consent required.
  • Preference cookies – Remember your choices (e.g., language). Consent required.
  • Analytical/statistical cookies – Measure and improve performance/usage. Consent required unless fully anonymized in accordance with guidelines.
  • Marketing/advertising cookies – Personalization, ads, retargeting, social media. Consent required.


4.2 Consent and management

  • On your first visit, we will show you a cookie banner where you can give or refuse consent per category.
  • You can always change or withdraw your choices via “Cookie Settings” in the footer of our site.
  • We do not place non-essential cookies without your consent.
  • The current, specified list of cookies and (if applicable) suppliers is always in the cookie settings and is subject to change.


4.3 General cookie overviews (non-exhaustive)

CategoryExamplePurposeValidityStrictly necessary session_id , cart Session management, checkout, securitySession – 14 daysPreferred language , locale Remember language/settingsUp to 1 yearAnalytical [analytical_cookie] Anonymized statistics/performance6–24 monthsMarketing [marketing_cookie] Measurement, personalization, retargeting3–13 months


5. Transfer outside the EEA

If data is transferred outside the EEA (e.g., via a service provider), we ensure appropriate safeguards such as EU Standard Contractual Clauses (SCCs) and additional measures where necessary. You can request an explanation via info@shenqimed.nl.


6. Retention periods

We do not store personal data longer than necessary:

  • Order and invoice data: 7 years (tax retention obligation).
  • Account data: As long as your account is active; delete/anonymize after 36 months of inactivity.
  • Customer service communications: up to 24 months after completion.
  • Newsletter data: until unsubscribe; proof of consent for up to 24 months thereafter.
  • Technical/Log data: 12–24 months.
  • Health data with consent: maximum 12 months after last contact or sooner upon request.


7. Security

We take appropriate technical and organizational measures, including encrypted connections (TLS), password hashing, limited access rights (need to know), logging and regular updates/backups.


8. Your rights

You have the right to access, rectify, erase, restrict, port, object (including to direct marketing), and withdraw consent. Submit your request to info@shenqimed.nl. We will respond within one month (extendable depending on complexity). We may request additional information for verification purposes.


9. Complaints

 Do you have a complaint? Please contact us at info@shenqimed.nl. You can also contact the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).


10. Minors

Our webshop is not intended for individuals under the age of 16. We do not process data from minors without the consent of a parent/guardian. If you suspect that data has been collected, please contact us; we will delete it.


11. Automated decision-making

We do not make decisions based solely on automated processing that have legal effects for you, without human intervention.


12. Changes to this statement

We may amend this statement. The latest version is always available on our website. In the event of significant changes, we will actively inform you (e.g., by email or a notification on the website) and, if necessary, request your consent again in the cookie banner.