Privacy and cookie statement


1. Who is responsible for your data?

Shen Qi Medical Centre is the data controller within the meaning of the GDPR for the processing operations described in this document.


2. Which personal data do we process?

Depending on your use of our webshop, we may process the following data:

  • Identification and contact details: name, (delivery/billing) address, e‐mail, telephone.
  • Account details: login name, password (encrypted), order summary, preferences.
  • Order and transaction data: ordered products/services, order number, payment status, invoice details.
  • Payment details: are processed via payment providers; we do not receive full card details.
  • Communication details: email and customer service contact.
  • Marketing data: newsletter subscription and preferences.
  • Technical/usage data: IP address, device and browser information, cookie IDs, sessions, visited pages, shopping cart.
  • Health-related information (optional): only when you voluntarily provide this yourself for advice and only with your express consent.


3. Purposes and legal bases (GDPR Art. 6)

  1. Ordering and delivery; customer administration, payments, delivery. Basis: performance of contract (Art. 6(1)(b)); statutory obligation for tax administration (Art. 6(1)(c)).
  2. Customer service and communication. Basis: performance of contract; legitimate interest (service quality) (Art. 6(1)(f)).
  3. Account management and security of the webshop. Basis: performance of contract; legitimate interest (fraud prevention/IT security) (Art. 6(1)(f)).
  4. Newsletter/marketing (upon subscription or existing customer relationship for similar products). Basis: consent (Art. 6(1)(a)) or legitimate interest with opt-out (Art. 6(1)(f) Telecommunications Act).
  5. Analysis and improvement of our services and performance. Basis: legitimate interest (Art. 6(1)(f)).
  6. Health data (only if relevant to the advice you have requested). Basis: explicit consent (Art. 9(2)(a)); you can withdraw this consent at any time.


4. Cookies and similar technologies

We use cookies and similar technologies to make our site work, remember preferences, analyze usage, and—if you allow—support marketing.


4.1 Categories

  • Strictly necessary/technical cookies – Essential for basic functions (login, shopping cart, security). No consent required.
  • Preference cookies – Remembering your choices (e.g. language). Consent required.
  • Analytical/statistical cookies – Measuring and improving performance/usage. Consent required, unless fully anonymized in accordance with guidelines.
  • Marketing/advertising cookies – Personalization, advertisements, retargeting, social media. Consent required.


4.2 Consent and management

  • On your first visit, we will show a cookie banner allowing you to give or refuse consent per category.
  • You can always change or withdraw your choices via “Cookie settings” in the footer of our site.
  • We do not place non-essential cookies without your consent.
  • The current, specified list of cookies and (if applicable) vendors is always located in the cookie settings and may change.


4.3 General cookie overviews (non-exhaustive)

CategoryExamplePurposeValidityStrictly necessary session_id , cart Session management, checkout, securitySession – 14 daysPreferred language , locale Remember language/settingsUp to 1 yearAnalytical [analytical_cookie] Anonymized statistics/performance6–24 monthsMarketing [marketing_cookie] Measurement, personalization, retargeting3–13 months


5. Transfer outside the EEA

If data is transferred outside the EEA (e.g. via a service provider), we ensure appropriate safeguards such as EU Standard Contractual Clauses (SCCs) and additional measures where necessary. You can request an explanation via info@shenqimed.nl.


6. Retention periods

We do not retain personal data longer than necessary:

  • Order and invoice details: 7 years (fiscal retention obligation).
  • Account details: as long as your account is active; delete/anonymize 36 months after inactivity.
  • Customer service communication: maximum 24 months after resolution.
  • Newsletter details: until unsubscribe; proof of consent for up to 24 months thereafter.
  • Technical/log data: 12–24 months.
  • Health data with consent: maximum 12 months after the last contact or earlier upon request.


7. Security

We take appropriate technical and organizational measures, including encrypted connections (TLS), password hashing, need-to-know access restrictions, logging, and regular updates/backups.


8. Your rights

You have the right to, among other things, access, rectification, erasure, restriction, portability, objection (including against direct marketing), and withdrawal of consent. Submit your request via info@shenqimed.nl. We will respond within one month (extendable depending on complexity). We may request additional information for verification.


9. Complaints

Do you have a complaint? Please contact us via info@shenqimed.nl. You can also contact the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).


10. Minors

Our webshop is not aimed at persons under the age of 16. We do not process data of minors without the consent of a parent/guardian. Please contact us if you suspect that data has been collected; we will delete it.


11. Automated decision-making

We do not make decisions based solely on automated processing with legal effects for you, without human intervention.


12. Changes to this statement

We may amend this statement. The latest version is always available on our website. In the event of significant changes, we will actively inform you (e.g. via email or a notification on the site) and, if necessary, ask for your consent again in the cookie banner.