Last updated: 8 July 2026.
This policy explains how Dermagic Europe collects, uses and protects any personal information you provide when using this website. We are committed to keeping your privacy protected and to being clear about what we do with your data.
Who is the data controller?
The data controller for the personal information collected on this website is:
Dermagic Europe
IDA Industrial Estate
Eurobase House, 312 Cork Rd
Waterford X91 EH5N
Ireland
customerservice@dermagic.eu · +44 7425 388643
If you have any question about how your data is used, or want to exercise any of the rights below, please email us at the address above.
What information we collect
Depending on how you use the site, we may collect:
- Name and contact details (email address, phone number, postal address).
- Order information (items purchased, prices paid, delivery address, order status).
- Payment status (approved / declined / refunded). We never see or store your full card number — Stripe handles the card details on our behalf.
- Account information if you register (login email, password hash, addresses, saved pet profiles you optionally add).
- Content of live-chat conversations with Sophie, our chat assistant (see the section below).
- Cart contents when you leave without completing checkout, for our abandoned-cart recovery emails (see the section below).
- Technical information collected automatically: browser type, device type, IP address, and cookies (see the cookie table at the bottom of this page).
Why we use it, and our lawful basis
Under the UK and EU General Data Protection Regulation (GDPR) we must tell you the lawful basis on which we process your data. In practice we rely on the following:
- To fulfil your order (name, address, order contents, payment status, shipping data shared with DHL) — lawful basis: performance of a contract (GDPR Art 6(1)(b)).
- To handle returns, refunds and warranty claims — performance of a contract and compliance with legal obligation (Art 6(1)(b)/(c)).
- To keep tax and accounting records — legal obligation (Art 6(1)(c)).
- To send transactional emails (order confirmations, dispatch notifications, password resets, replies to enquiries) — performance of a contract.
- To send abandoned-cart recovery emails — legitimate interest in offering existing / prospective customers the chance to complete their purchase (Art 6(1)(f); soft opt-in under UK PECR / EU e-Privacy). You can opt out at any time using the one-click unsubscribe link in every recovery email.
- To answer questions you send to our live chat, contact form, or trade application — legitimate interest in supporting customers and reviewing trade enquiries.
- To measure how the site is used (Google Analytics 4, Google Ads conversion measurement) — consent given through our cookie banner (Art 6(1)(a)). Not loaded until you accept.
- For product safety monitoring — where a customer or chat conversation reports an adverse reaction in a pet, we retain the record as required by cosmetic-product safety obligations — legal obligation / vital interests.
- To detect and prevent abuse (fraud attempts, chat abuse, spam) — legitimate interest.
Who we share your data with
We only share your data with the third parties we need to run the service, and only for the purpose each one serves. Each of them is contractually bound to process your data on our behalf and not for their own purposes.
- Stripe — processes card, Apple Pay and Google Pay payments. Card data goes to Stripe directly and never reaches our servers.
- PayPal — processes PayPal payments if you choose that method.
- DHL Express — receives your name, address, phone number and email so it can deliver your order and let you track it.
- SendGrid (Twilio) — sends our transactional emails (order confirmation, cart-recovery, password reset, chat handoff, etc.). Receives only the email address and the message content.
- Anthropic — powers our live-chat assistant Sophie. Only used if you open the chat and accept chat consent. See the Sophie section below.
- Google — receives usage-analytics events (Google Analytics 4 + Google Ads conversion measurement) only if you consent through the cookie banner. Data goes to Google Ireland Ltd.
- Hetzner Online GmbH — hosts our servers in the European Union (Germany + Finland). All customer data at rest lives there.
Except for the above, we do not sell, rent or share your personal information with third parties for their own marketing purposes.
International transfers
Most of our processing happens inside the EU. Two providers involve transfers outside the EU/UK:
- Stripe and SendGrid are US-headquartered but certified under the EU-US Data Privacy Framework, providing an adequate level of protection.
- Anthropic (chat) is US-based; the transfer is covered by Standard Contractual Clauses (SCCs) as approved by the European Commission. Anthropic does not use conversation data to train its models.
How long we keep your data
- Customer accounts: for as long as the account is active. You can request deletion at any time.
- Order records: retained for at least six years after the transaction, to comply with tax and accounting obligations.
- Contact-form / trade-application enquiries: up to two years after last contact, then deleted or anonymised.
- Marketing email list: until you unsubscribe, then removed within 30 days (a suppression record of the email address is kept indefinitely so we don't email you again by accident).
- Cart-recovery data: abandoned cart contents are aged out with the rest of inactive cart data (typically within 90 days of the cart being abandoned).
- Chat conversations: anonymised 90 days after the last message. Conversations flagged as reporting an adverse reaction in a pet are kept for at least five years (see below).
- Site analytics (Google Analytics 4): Google retains event data for 14 months by default.
Live chat (Sophie)
The site offers an optional live-chat assistant called Sophie, which can help with product questions, condition guidance, and your own orders if you are signed in. Sophie only loads after you grant chat consent through our cookie banner; you can revoke that consent at any time from the preferences manager linked in the footer.
What is collected when you chat:
- The messages you type into the chat panel.
- Sophie's replies (including any product or condition information looked up to answer you).
- A salted, daily-rotating hash of your IP address (used only to detect abuse).
- Your browser's user agent string.
- If you are signed in, your customer id is linked to the conversation so Sophie can look up your own orders and addresses when you ask.
How conversations are handled:
- Chat messages are sent securely to Anthropic, our chat-AI processor, which generates Sophie's replies. Anthropic processes the messages to produce the response and may retain them briefly for abuse prevention; they do not use Store conversations to train their models.
- Conversations are stored on our own servers in the European Union.
- If you ask to speak to a human, or Sophie detects a question best handled by a person (returns, refunds, suspected adverse reactions, medical guidance), the conversation is flagged for our customer-care team and answered by email within one business day.
- Routine conversations are anonymised 90 days after the last message — the message content is replaced, and IP hashes and user-agent details are deleted.
- Conversations flagged as reporting an adverse reaction in a pet are kept for product-safety review for at least five years, in line with cosmetic-product safety obligations, and are exempt from automatic erasure.
Your rights:
- You can ask us for a copy of your own chat transcript at any time (GDPR Article 20 export).
- You can ask us to erase a conversation; we will honour the request unless it relates to an adverse-event report, in which case we will explain why and offer to anonymise instead.
- Sophie is an automated assistant. You always have the option to escalate to a human; use the "Talk to a human" link inside the chat panel or write to the email address in our Contact Us page.
Abandoned-cart recovery emails
If you start a cart on the site and leave before completing the order, we may send you up to three follow-up emails to the email address you typed in checkout, on the basis of soft opt-in — a recognised lawful basis under the UK Privacy and Electronic Communications Regulations and the EU e-Privacy Directive for existing or prospective customer relationships of similar products.
The schedule is:
- About 24 hours after you left the cart: a friendly reminder with the items still in your basket.
- About 3 days later: a second reminder with a small one-time discount code.
- About 7 days later: a final reminder with a slightly larger one-time discount code; no further emails about this cart after that point.
Each email contains a one-click unsubscribe link at the bottom. Clicking it stops all future cart-recovery emails to you, both for the cart it referred to and for any future carts under the same customer account. The opt-out takes effect immediately and we honour it on subsequent visits.
What we collect for this purpose:
- The email address you typed in checkout.
- The items in your cart at the moment you left it.
- Whether you have clicked a restore-link in an earlier email (so we credit which email brought you back, and so the conversion attribution feeds our internal analytics).
- Whether you have used a recovery discount code (so we don't issue another one for the same cart).
What we do NOT do:
- We do not share your email or cart contents with third parties beyond our email delivery provider (SendGrid, which transmits the message and is contractually bound to use it only for that purpose).
- We do not send recovery emails for trade customers by default.
- We do not retain recovery-related data beyond what is necessary — anonymous cart rows whose contents are no longer commercially relevant are aged out alongside other inactive cart data.
You also have the GDPR Article 21 right to object to direct marketing at any time. The one-click unsubscribe link is the simplest way to exercise this; you may also write to us via the Contact Us page and we will action the request manually.
Security
We are committed to keeping your information secure. Traffic between your browser and our servers is encrypted with TLS. Passwords are stored only as salted hashes — we never hold your password in a form we could read. Card data never reaches our servers; Stripe handles it end-to-end. Backups of our databases are encrypted (GPG) before leaving the primary server and are stored in an EU-hosted offsite location.
Your rights under UK / EU GDPR
You have the right to:
- Access a copy of the personal data we hold about you (subject-access request). This is free of charge unless the request is manifestly unfounded or excessive.
- Correct any information you believe is inaccurate or incomplete.
- Erase your personal data ("right to be forgotten"), subject to our need to keep records for tax, warranty and product-safety obligations.
- Restrict or object to our processing of your data.
- Data portability — receive your data in a machine-readable format.
- Withdraw consent at any time where we relied on consent (for example, marketing emails or analytics cookies).
To exercise any of these rights, email customerservice@dermagic.eu. We will respond within one month.
If you are not happy with our response, you have the right to lodge a complaint with your data-protection authority. In Ireland this is the Data Protection Commission; in the UK it is the Information Commissioner's Office; other EU residents can complain to their national supervisory authority.
Children
This site is not directed at children. We do not knowingly collect personal data from anyone under 16 without parental consent. If you believe a child has provided data to us, please contact us and we will remove it.
Links to other websites
Our site may contain links to other websites of interest. Once you leave this site, we are not responsible for the protection or privacy of any information you provide to those sites. You should read their own privacy notices.
Changes to this policy
We may update this policy from time to time to reflect changes in the way we operate. The "Last updated" date at the top will change when we do. For material changes, we will do our best to give affected customers advance notice by email.
Cookies we use
A cookie is a small file stored on your device. Some cookies are strictly necessary for the site to work; others we only set once you consent through our cookie banner.
Strictly necessary (always set)
| Cookie | Purpose | Retention |
|---|---|---|
_medusa_jwt | Keeps you signed in to your customer account. HttpOnly, secure. | Session / until sign-out |
_medusa_cart_id | Associates your basket with your browser so items persist between visits. | 7 days |
_medusa_cache_id | Cache invalidation flag used when your cart changes. | Session |
_medusa_locale | Remembers your language choice (English / German / French / Polish). | 1 year |
_dermagic_currency | Remembers your chosen currency (EUR / GBP / PLN). | 1 year |
_dermagic_geo_country | Country detected from your IP address (via Cloudflare), used to preselect the correct shipping region. | 1 hour |
_dermagic_consent | Remembers your choices in the cookie banner (analytics on / off, chat on / off). | 1 year |
_dermagic_chat | Links your browser to your Sophie chat session so the conversation persists across page loads. HttpOnly. Only set once you accept chat consent. | 30 days |
Analytics (set only if you accept "Analytics" in the cookie banner)
| Cookie | Purpose | Retention |
|---|---|---|
_ga, _ga_<id> | Google Analytics 4 — anonymous visitor and session identifiers so we can measure how people find and use the site. | Up to 2 years |
_gid | Google Analytics 4 — identifies unique visits within a 24-hour window. | 24 hours |
_gcl_au | Google Ads conversion linker — measures whether an ad click led to a purchase. | 90 days |
You can change your cookie preferences at any time from the "Cookie preferences" link in the site footer. You can also block or delete cookies through your browser settings. Blocking strictly-necessary cookies will prevent some parts of the site (sign-in, cart, checkout) from working.
