Privacy Policy (GDPR)

Last updated: 01 October 2025

1) Who we are (Controller)

This website (“Sitaram Ayurveda Europe”) is operated by:

Authentic Ayurveda d.o.o.
Slavka Krautzeka 51, 51000 Rijeka, Croatia
VAT ID: HR48885563972
Email: info@sitaramayurveda.eu
Authentic Ayurveda d.o.o. is the Controller of all personal data processed in connection with this website and our EU operations. We determine the purposes and means of processing and do not share personal data with Sitaram Ayurveda Pvt. Ltd. (India) or any other non-EEA recipient.

2) What data we collect

We only collect data that is adequate, relevant and limited to what is necessary (data minimization).

  • Identity & contact: name, billing and shipping address, email, phone.

  • Account data: login, role (e.g., practitioner), preferences.

  • Order & payment data: products, prices, payment status, invoice details, delivery information. (We do not store full card numbers - payments are handled by PCI-compliant processors.)

  • Communications: enquiries, support tickets, marketing preferences.

  • Device/usage: IP address, device and browser details, security logs, consent choices, limited analytics events (only if you consent).

  • Regulatory/safety: adverse event or product quality reports you submit; records needed for tax, accounting, and product-safety compliance.

Sources: directly from you; from your device; and, for practitioner accounts, from verification you provide. We do not purchase personal data from brokers.

3) Why we process your data (purposes & legal bases)

Purpose Legal basis
Accepting and fulfilling orders; customer service Art. 6(1)(b) GDPR (contract)
Managing your account; practitioner verification Art. 6(1)(b) (contract) / Art. 6(1)(f) (legitimate interests: platform integrity)
Invoicing, tax & accounting; product-safety obligations Art. 6(1)(c) (legal obligation)
Security & fraud prevention; service resilience Art. 6(1)(f) (legitimate interests)
Analytics & marketing communications Art. 6(1)(a) (consent) - you can withdraw at any time
Responding to legal requests & enforcing rights Art. 6(1)(c) / Art. 6(1)(f)

We do not engage in automated decision-making that produces legal or similarly significant effects (Art. 22 GDPR). We do not sell personal data.

4) Cookies & Consent

We use essential cookies to operate the site (shopping cart, checkout, security). Analytics/marketing cookies are off by default and used only if you give consent via our Cookie banner. You can change preferences at any time. See our Cookie Notice for details.

5) With whom we share data (processors only)

We use vetted service providers acting strictly as processors under Art. 28 GDPR. They may process personal data only on our documented instructions, only for the specified purposes, and only within the EEA (see Section 6).

Typical processors:

  • E-commerce platform & hosting (shop operation, order database)

  • Payment service providers (PCI-DSS compliant; tokenised payments)

  • Fulfilment and carriers (address labels and delivery)

  • Email & helpdesk (customer communications)

  • Analytics (only if you consent)

We maintain a record of current processors and will provide a summary upon request. We require strict confidentiality, security, sub-processor approval, and deletion/return of data at end of service.

6) International transfers - EEA-only policy

We do not transfer personal data outside the European Economic Area (EEA).

  • We do not share personal data with Sitaram Ayurveda Pvt. Ltd. (India) or any other third country entity.

  • We contractually require our processors and their sub-processors to store and process personal data exclusively within the EEA (including backups and disaster recovery).

  • If, in the future, a specific transfer outside the EEA becomes strictly necessary, we will not proceed without implementing a valid transfer mechanism (e.g., EU Standard Contractual Clauses), documenting a transfer impact assessment, updating this Policy, and - where required - obtaining your explicit consent.

7) Retention

  • Orders, invoices, tax records: retained for 10 years (or longer if required by applicable law).

  • Accounts: retained while active and for up to 6 years after last activity, unless you request deletion sooner and no legal retention applies.

  • Marketing: retained until you unsubscribe or withdraw consent.

  • Security logs: retained for a proportionate period to investigate incidents.

When retention periods expire, we securely delete or anonymize data.

8) Security

We implement appropriate technical and organizational measures (TOMs), including encryption in transit, hardened hosting, role-based access control, least-privilege, audit logging, regular vulnerability management, and staff confidentiality. We maintain records of processing and conduct DPIAs where required.

Data breach: If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent authority without undue delay and, where required, inform you promptly (Arts. 33 - 34 GDPR).

9) Your rights (EU-wide)

You have the following rights, exercisable at info@sitaramayurveda.eu:

  • Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18).

  • Portability (Art. 20) for data you provided to us.

  • Object (Art. 21) to processing based on legitimate interests and to direct marketing at any time.

  • Withdraw consent (Art. 7(3)) without affecting prior lawful processing.

  • Complaint to your national supervisory authority and/or the Croatian authority (AZOP). You may lodge a complaint in the EU member state of your habitual residence, place of work, or alleged infringement (Art. 77).

We will respond within one month (extendable by two months for complex requests). We may ask for reasonable verification of identity. We will not discriminate for exercising rights.

10) Country-specific information (EU/EEA)

This Policy is designed to meet the GDPR across all EU/EEA countries. Where national rules impose additional consumer or privacy requirements (e.g., specific retention, language, or ADR notices), we apply them in addition to this Policy for customers in that country. You always retain the right to lodge complaints with your national authority. If you need the contact of your authority, ask us and we will provide it with your response.

11) Children

Our services are intended for persons 18+. We do not knowingly process children’s data.

12) Law-enforcement & government requests

We do not disclose personal data to public authorities unless required by EU or Member-State law. We review every request for lawful basis, scope and necessity, and we challenge requests that are unlawful, extraterritorial or disproportionate. We require due process (e.g., court order) and will notify you where legally permitted.

13) Data ownership & accountability

All personal data collected via this site is processed under the sole control and accountability of Authentic Ayurveda d.o.o. Our processors have no independent rights to use the data. No third party including Sitaram Ayurveda Pvt. Ltd. may demand access to EU customer data from us without a valid EU/Member-State legal basis.

14) Marketing & profiling

We send marketing communications only with your consent (opt-in). You can unsubscribe at any time via the link in our emails or by contacting us. We do not use automated individual decision-making or profiling that produces legal or similarly significant effects.

15) Contact for privacy matters

Data Protection Lead
Email: info@sitaramayurveda.eu
Postal: Authentic Ayurveda d.o.o., Slavka Krautzeka 51, 51000 Rijeka, Croatia

16) Changes to this Policy

We may update this Policy to reflect operational, legal or regulatory changes. Material changes will be highlighted on this page and, where appropriate, notified by email.