Privacy Policy

This privacy policy explains how personal data is processed when you visit farmaciacanfora.com (Canfora Medicine Guide) and when you contact us, and which rights you have under the EU and UK General Data Protection Regulation (GDPR).

Who is responsible

The controller responsible for this website is Dr. Ema Hudson, operator of farmaciacanfora.com. You can reach us about data protection through the contact page; please mark your message “Privacy”.

Hosting and server log files

The website is hosted on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. When you open a page, the web server automatically records technical information in log files: your IP address, the date and time of the request, the page requested, the HTTP status code, the amount of data transferred, the referring page and your browser and operating system (user agent).

This data is needed to deliver the website, to keep it secure and stable (for example to detect attacks) and to fix errors. The legal basis is our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR). The server log files are rotated weekly and the last five are kept, so log entries are normally deleted after about five to six weeks, unless they are needed to investigate a specific security incident.

Content delivery and security (Cloudflare)

Requests to this website pass through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, which delivers the site quickly and protects it against attacks and abuse. Cloudflare processes connection data such as your IP address, the requested URL, the time, and browser information, and may set technically necessary security cookies. The legal basis is our legitimate interest in a fast and secure website (Art. 6(1)(f) GDPR). Data may be processed in the USA; Cloudflare is certified under the EU-US Data Privacy Framework and also uses the European Commission’s standard contractual clauses. More information: Cloudflare’s privacy policy at cloudflare.com/privacypolicy.

Contact form

If you use the contact form, we process the name, email address and message you enter, plus the time of submission. We use this data only to answer your enquiry. The legal basis is our legitimate interest in answering messages sent to us (Art. 6(1)(f) GDPR) and, where your message concerns a contract or a request you are making, Art. 6(1)(b) GDPR. Submissions are stored in the website’s database on our hosting server. We keep them for as long as needed to deal with your enquiry and any follow-up, unless legal obligations require longer storage.

Please don’t send health information. We can’t give personal medical advice, so there is no need to tell us about your health. If you include health details anyway, we use them only to reply to you.

If you use the search box, your search term is sent to our server to display matching articles. Search terms are not stored in a separate database; like every page request, the search address can appear in the server log files described above.

Fonts

The fonts used on this website are stored on our own server. No connection to an external font service is made to display them.

Cookies set by the content management system

The site is built with WordPress. WordPress sets cookies when an administrator logs in, to keep the login session. These cookies are technically necessary for operating the site (§ 25(2) TDDDG, Art. 6(1)(f) GDPR) and are not used for visitors who don’t log in.

Articles link to external sources such as health services, regulators and scientific journals. Their privacy policies apply once you follow a link.

Your rights

Under the GDPR you have the right to:

  • request access to the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have your data erased (Art. 17) or its processing restricted (Art. 18);
  • receive your data in a portable format, where processing is based on consent or a contract (Art. 20);
  • withdraw any consent you have given, with effect for the future (Art. 7(3));
  • lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live or work or where an alleged infringement occurred (Art. 77).

Right to object (Art. 21 GDPR): where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

To exercise your rights, use the contact page.

Security

This website uses TLS encryption (recognisable by “https://” and the padlock in your browser), so data you send to us cannot be read by third parties in transit.

Changes to this policy

We update this policy when the website or the law changes. Last updated: October 2026.