Privacy Policy

This privacy policy explains how AS Surgitech ("we") processes personal data in connection with the use of this website (the "website").

Last updated: 22 April 2026

1. Data controller

The data controller is AS Surgitech.

  • AS Surgitech
  • Pärnu mnt 148, 11317 Tallinn, Estonia
  • Phone: +372 6460660
  • Email: tellimused@surgitech.ee

2. What data we process

The website collects only the minimum information necessary for the service to operate and for us to understand its use:

  • Server logs — our hosting provider (Vercel Inc.) records standard server logs including IP address, user agent (browser and operating system type) and request timestamp.
  • Aggregated usage statistics — we use Cloudflare Web Analytics, which does not set cookies and does not use fingerprinting. Only aggregate, non-identifying data is collected: page views, referrer domains, countries, device types and browsers.

We do not collect or process personal data via contact forms, user accounts or purchase transactions on this website — purchases take place directly with pharmacy partners.

3. Legal basis

Processing is carried out on the basis of our legitimate interest (GDPR Article 6(1)(f)) in ensuring the secure operation of the website, preventing abuse, and understanding overall website usage.

4. Retention periods

  • Server logs (Vercel): up to 30 days.
  • Cloudflare Web Analytics aggregate statistics: indefinite, as they contain no personal data.

5. Recipients and data processors

We have entered into data processing agreements with the following service providers, who act as processors on our behalf:

  • Vercel Inc. (United States) — website hosting. Legal basis for transfer: EU–U.S. Data Privacy Framework (DPF, 2023).
  • Cloudflare, Inc. (United States) — cookieless usage statistics. Legal basis for transfer: EU–U.S. Data Privacy Framework (DPF, 2023).

We do not sell or rent your data to third parties.

6. Cookies

This website does NOT use tracking cookies, advertising cookies or third-party profiling cookies. The chosen analytics solution (Cloudflare Web Analytics) is fully cookieless. For this reason, no cookie consent banner is displayed.

7. Your rights

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • right of access to personal data concerning you;
  • right to rectification of inaccurate data;
  • right to erasure ("right to be forgotten");
  • right to restriction of processing;
  • right to data portability;
  • right to object to processing;
  • right to lodge a complaint with the supervisory authority — the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).

8. Contact for data protection matters

To exercise your rights or for any other data protection queries, please contact us:

  • Email: tellimused@surgitech.ee
  • Phone: +372 6460660
  • Post: AS Surgitech, Pärnu mnt 148, 11317 Tallinn, Estonia

9. Children

This website is not directed at children under 16. We do not knowingly collect personal data from children under 16.

10. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. The updated version will be published on this page with a revised "last updated" date. For material changes, we will notify visitors with a prominent notice on the website.

Attention: this website contains information about an over-the-counter medicine. Before use, read the package leaflet carefully.

Back to home