Privacy policy
Personal data protection
The website mm-medic.com is operated by two legal entities: ТОВ "ММ МЕДІК" (sale of physical products) and ПО "ІПРМ" (provision of services). Each is a separate controller of personal data and has its own Privacy Policy. Select the appropriate tab below.
1. General provisions
1.1
This Privacy Policy (hereinafter referred to as the "Policy") applies to all personal data that ТОВ "ММ МЕДІК" (hereinafter referred to as the "Controller") may obtain about the User during their use of the website https://mm-medic.com (hereinafter referred to as the "Website") in connection with the purchase of physical products.
1.2
The Site is also used by ПО «ІНСТИТУТ ПЛАЗМОТЕРАПІЇ ТА РЕГЕНЕРАТИВНОЇ МЕДИЦИНИ» (EDRPOU code 45871060) to provide services (seminars, webinars, courses, conferences, treatment protocols, digital products). The processing of personal data related to the services provided by ПО «ІНСТИТУТ ПЛАЗМОТЕРАПІЇ ТА РЕГЕНЕРАТИВНОЇ МЕДИЦИНИ» is governed by a separate Privacy Policy of ПО «ІНСТИТУТ ПЛАЗМОТЕРАПІЇ ТА РЕГЕНЕРАТИВНОЇ МЕДИЦИНИ».
1.3
Consent to the processing of personal data is given by the User by checking the appropriate checkbox during registration on the Website or when placing an Order. Such consent is voluntary, informed, and unambiguous in accordance with the requirements of the Law of Ukraine "On Personal Data Protection." The Website may be used without granting consent to personal data processing, albeit with limited functionality.
1.4
If User does not agree with terms of this Policy, they must refrain from using Site and stop providing their personal data.
2. Term definitions
- Personal data information or set of information about natural person who is identified or can be specifically identified.
- Personal data processing any action or set of actions such as collection, registration, accumulation, storage, adaptation, modification, renewal, use and dissemination, depersonalization, destruction of personal data.
- Controller of personal data (Controller) ТОВАРИСТВО З ОБМЕЖЕНОЮ ВІДПОВІДАЛЬНІСТЮ "ММ МЕДІК" (EDRPOU code 40823358), which determines the purpose of personal data processing, establishes the composition of such data, and the procedures for their processing.
- User any natural person who visits the Website, registers on it, or purchases products through the Website.
- Web-site a website located on the Internet at https://mm-medic.com, including all its web pages and subdomains.
- Cookie files small text files stored on User's device when visiting Site and containing information about their actions on Site.
3. Composition and purpose of personal data collection
3.1
Owner may collect and process following User's personal data:
- Surname, first name, patronymic;
- Email address;
- Mobile phone number;
- Delivery address (country, city, street, building, apartment, postal code);
- Date of birth (at User's discretion);
- Order history and purchased goods;
- Information about payment method (without storing full bank card data);
- Other data provided voluntarily by User (e.g. reviews, comments, questions).
3.2
Personal data collected and processed exclusively for following purposes:
- User identification when registering on Site and authorization in personal account;
- Placing, processing, and fulfilling the User's orders for products;
- Delivery of goods to address specified by User;
- Processing payments for products through payment systems;
- Informing User about order status, delivery changes, news and promotions (subject to separate consent);
- Providing technical support and consultations to User;
- Improving Site functionality, personalizing content and recommendations;
- Analyzing visits and activity on Site to improve user experience;
- Fulfilling requirements of current legislation of Ukraine.
3.3
Owner does not collect personal data relating to racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, conviction for criminal offense, as well as data relating to health, sexual life, biometric or genetic data, except when such data provided voluntarily by User or necessary for fulfillment of contractual obligations.
3.4
The Controller acknowledges that the order history for medical devices and related products may indirectly contain information about the User's health (sensitive personal data). In this regard, the Controller undertakes to apply an enhanced level of protection to such data, restrict the range of persons with access to it, and refrain from using it for purposes unrelated to Order fulfillment without the User's separate explicit consent.
4. Transfer of personal data to third parties
4.1
The Controller has the right to transfer the User's personal data to third parties solely to the extent necessary to achieve the processing purposes specified in this Policy and solely with the User's consent.
4.2
If the User's Order also includes services provided by ТОВ "ІПРМ," the User's personal data may be transferred to ТОВ "ІПРМ" to the extent necessary for the fulfillment of such an Order, provided the User has given the appropriate consent.
4.3
Personal data may be transferred to following third parties:
- Delivery services: ТОВ "НОВА ПОШТА" and other logistics operators—for the delivery of products under the User's orders. The following data is transferred: surname, first name, patronymic, phone number, and delivery address.
- Payment systems: ТОВ "ЛІКВІД ФІНАНС" (LiqPay)—for processing online payments. The Controller does not store the full details of the User's bank cards; all payment information is processed directly by the payment system.
- Other third parties: According to requirements of legislation of Ukraine, personal data may be transferred to law enforcement agencies, judicial authorities or other state institutions based on official request in accordance with current legislation.
4.4
The Controller requires third parties to whom the User's personal data is transferred to maintain confidentiality and ensure an appropriate level of data protection in accordance with the legislation of Ukraine.
4.5
The Controller does not sell, exchange, or transfer the User's personal data to third parties for marketing purposes without the User's separate consent.
5. Personal data storage period
5.1
User's personal data stored by Owner for period necessary to achieve processing purposes defined in this Policy, but not longer than provided by legislation of Ukraine.
5.2
Personal data storage periods:
- Account data (name, email, phone)—for the entire period the User's account remains active and for 3 (three) years after its deletion or the last activity on the Website;
- Order history and financial transactions—for 3 (three) years from the date of the last order (in accordance with the requirements of the tax and accounting legislation of Ukraine);
- Reviews and comments—for the entire period of their publication on the Website or until their removal at the User's request;
- Technical data (IP address, cookies)—for 12 (twelve) months from the date of the last visit to the Website.
5.3
After expiration of storage period, personal data subject to destruction, unless otherwise provided by legislation of Ukraine or there are no other legal grounds for their storage.
5.4
User has right at any time to demand deletion of their personal data by contacting Owner at contacts specified in Section 9 of this Policy.
7. Rights of personal data subject
7.1
User, as personal data subject, has all rights provided by Article 8 of Law of Ukraine "On Personal Data Protection".
7.2
User has right to:
- To know the sources of collection, the location of their personal data, the purpose of processing, and the location or place of residence (stay) of the Controller;
- Receive information about conditions for providing access to personal data, in particular information about third parties to whom their personal data transferred;
- Access to their personal data;
- To receive, no later than thirty calendar days from the date of receipt of the request, a response as to whether their personal data is being processed, as well as the content of such personal data;
- Present motivated requirement to Owner with objection to processing of their personal data;
- To submit a reasoned request for the modification or destruction of their personal data if such data is being processed unlawfully or is inaccurate;
- To the protection of their personal data against unlawful processing and accidental loss, destruction, or damage;
- Appeal with complaints about processing of their personal data to Commissioner of Verkhovna Rada of Ukraine for Human Rights or to court;
- Apply legal remedies in case of violation of legislation on personal data protection;
- Make reservations regarding limitation of right to process their personal data when giving consent;
- Withdraw consent to personal data processing at any time by written appeal to Owner.
7.3
To exercise their rights, User can contact Owner with written request to email or postal address specified in Section 9 of this Policy. Owner undertakes to consider User's request and provide response no later than 30 (thirty) calendar days from date of receipt of request.
8. Personal data protection
8.1
Owner takes all necessary organizational, technical and legal measures to ensure protection of User's personal data from unlawful or accidental access, destruction, distortion, blocking, copying, distribution, as well as from other unlawful actions of third parties.
8.2
Personal data protection measures include:
- Appointment of responsible persons for organization of processing and protection of personal data;
- Development and implementation of internal regulatory documents on processing and protection of personal data;
- Application of organizational and technical information protection means (encryption, passwords, access restriction);
- Use of secure HTTPS protocol for data transmission through Site;
- Regular backup and protection from data loss;
- To oversight of compliance with personal data protection legislation by the Controller's employees and third parties;
- Registration and accounting of all actions with personal data;
- Assessment of effectiveness of personal data protection measures and their regular update.
8.3
Owner undertakes to immediately inform User about any incidents related to unauthorized access or disclosure of personal data, as well as take all possible measures to eliminate consequences of such incidents.
8.4
User also responsible for maintaining confidentiality of their account data (login, password) and undertakes not to disclose them to third parties. In case of detection of facts of unauthorized access to account, User undertakes to immediately inform Owner about this.
9. Controller Contact Information
9.1
In the event of any questions regarding personal data processing, the exercise of rights, or complaints about the Controller's actions, the User may contact the Controller at the following:
10. Final provisions
10.1
This Policy takes effect from moment of its publication on Site and valid indefinitely until replacement with new version.
10.2
The Controller reserves the right to amend this Policy. In the event of material changes, the Controller undertakes to notify Users no fewer than 14 (fourteen) calendar days before the new version takes effect by posting a notice on the Website and/or sending a notification to the User's email address.
10.3
All issues not regulated by this Policy subject to resolution in accordance with current legislation of Ukraine, in particular Law of Ukraine "On Personal Data Protection", Law of Ukraine "On Information", Civil Code of Ukraine.
10.4
Current version of Policy always available at page: https://mm-medic.com/privacy.
10.5
After receiving notice of the changes, the User has the right to withdraw their consent to personal data processing by submitting a written request to the Controller. If the User continues to use the Website after the new version of the Policy takes effect and does not withdraw their consent, they are deemed to have accepted the new version.
If you have questions or comments about this Policy, you can contact us using contact details specified in Section 9. We value your trust and undertake to ensure maximum level of protection of your personal data.
1. General provisions
1.1
This Privacy Policy (hereinafter referred to as the "Policy") applies to all personal data that ПО "ІПРМ" (hereinafter referred to as the "Controller") may obtain about the User during their use of the website https://mm-medic.com (hereinafter referred to as the "Website") in connection with receiving services, registering for events, and accessing digital products.
1.2
The Website is also used by ТОВ "ММ МЕДІК" (EDRPOU code 40823358) for the sale of physical products (medical devices, hygiene products, cosmetics). The processing of personal data related to the purchase of products by ТОВ "ММ МЕДІК" is governed by a separate Privacy Policy of ТОВ "ММ МЕДІК."
1.3
Consent to the processing of personal data is given by the User by checking the appropriate checkbox during registration on the Website, placing an Order, or registering for an event. Such consent is voluntary, informed, and unambiguous in accordance with the requirements of the Law of Ukraine "On Personal Data Protection." The Website may be used without granting consent to personal data processing, albeit with limited functionality.
1.4
If User does not agree with terms of this Policy, they must refrain from using Site and stop providing their personal data.
2. Term definitions
- Personal data information or set of information about natural person who is identified or can be specifically identified.
- Personal data processing any action or set of actions such as collection, registration, accumulation, storage, adaptation, modification, renewal, use and dissemination, depersonalization, destruction of personal data.
- Controller of personal data (Controller) ПО «ІНСТИТУТ ПЛАЗМОТЕРАПІЇ ТА РЕГЕНЕРАТИВНОЇ МЕДИЦИНИ» (EDRPOU code 45871060), which determines the purpose of personal data processing, establishes the scope of such data, and the procedures for processing it.
- User any natural person who visits Site, registers on it or uses services provided through Site.
- Services seminars, webinars, courses, conferences, treatment protocols, digital products, and other services provided by the Controller through the Website.
- Web-site a website located on the Internet at https://mm-medic.com, including all its web pages and subdomains.
- Cookie files small text files stored on User's device when visiting Site and containing information about their actions on Site.
3. Composition and purpose of personal data collection
3.1
Owner may collect and process following User's personal data:
- Surname, first name, patronymic;
- Email address;
- Mobile phone number;
- Date of birth (at User's discretion);
- Professional information (specialty, place of work—at the User's discretion, for event registration purposes);
- Order history and purchased services;
- Information about payment method (without storing full bank card data);
- Data on event attendance and course completion;
- Other data provided voluntarily by User (e.g. reviews, comments, questions).
3.2
Personal data collected and processed exclusively for following purposes:
- User identification when registering on Site and authorization in personal account;
- Placing, processing, and fulfilling the User's orders for services;
- Registering the User for seminars, webinars, courses, conferences, and other events;
- Providing access to digital products and treatment protocols;
- Processing payments for services through payment systems;
- Informing the User of order status, changes to event schedules, news, and promotions (subject to separate consent);
- Providing technical support and consultations to User;
- Improving Site functionality, personalizing content and recommendations;
- Analyzing visits and activity on Site to improve user experience;
- Fulfilling requirements of current legislation of Ukraine.
3.3
Owner does not collect personal data relating to racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, conviction for criminal offense, as well as data relating to health, sexual life, biometric or genetic data, except when such data provided voluntarily by User or necessary for fulfillment of contractual obligations.
3.4
The Controller acknowledges that the order history for medical and educational services (attending seminars, purchasing treatment protocols, etc.) may indirectly contain information about the User's health or professional specialty (sensitive personal data). In this regard, the Controller undertakes to apply an enhanced level of protection to such data, restrict the range of persons with access to it, and refrain from using it for purposes unrelated to Order fulfillment without the User's separate explicit consent.
4. Transfer of personal data to third parties
4.1
The Controller has the right to transfer the User's personal data to third parties solely to the extent necessary to achieve the processing purposes specified in this Policy and solely with the User's consent.
4.2
If the User's Order also includes products sold by ТОВ "ММ МЕДІК," the User's personal data may be transferred to ТОВ "ММ МЕДІК" to the extent necessary for the fulfillment of such an Order, provided the User has given the appropriate consent.
4.3
Personal data may be transferred to following third parties:
- Payment systems: ТОВ "ЛІКВІД ФІНАНС" (LiqPay)—for processing online payments. The Controller does not store the full details of the User's bank cards; all payment information is processed directly by the payment system.
- Event organization partners: event organizers, lecturers, and speakers—to the extent necessary for the conduct of the event and the provision of services (participant's name and contact details).
- Other third parties: According to requirements of legislation of Ukraine, personal data may be transferred to law enforcement agencies, judicial authorities or other state institutions based on official request in accordance with current legislation.
4.4
The Controller requires third parties to whom the User's personal data is transferred to maintain confidentiality and ensure an appropriate level of data protection in accordance with the legislation of Ukraine.
4.5
The Controller does not sell, exchange, or transfer the User's personal data to third parties for marketing purposes without the User's separate consent.
5. Personal data storage period
5.1
User's personal data stored by Owner for period necessary to achieve processing purposes defined in this Policy, but not longer than provided by legislation of Ukraine.
5.2
Personal data storage periods:
- Account data (name, email, phone)—for the entire period the User's account remains active and for 3 (three) years after its deletion or the last activity on the Website;
- Order history and financial transactions—for 3 (three) years from the date of the last order (in accordance with the requirements of the tax and accounting legislation of Ukraine);
- Data on event attendance and course completion—for 3 (three) years from the date of the event or course completion;
- Reviews and comments—for the entire period of their publication on the Website or until their removal at the User's request;
- Technical data (IP address, cookies)—for 12 (twelve) months from the date of the last visit to the Website.
5.3
After expiration of storage period, personal data subject to destruction, unless otherwise provided by legislation of Ukraine or there are no other legal grounds for their storage.
5.4
User has right at any time to demand deletion of their personal data by contacting Owner at contacts specified in Section 9 of this Policy.
7. Rights of personal data subject
7.1
User, as personal data subject, has all rights provided by Article 8 of Law of Ukraine "On Personal Data Protection".
7.2
User has right to:
- To know the sources of collection, the location of their personal data, the purpose of processing, and the location or place of residence (stay) of the Controller;
- Receive information about conditions for providing access to personal data, in particular information about third parties to whom their personal data transferred;
- Access to their personal data;
- To receive, no later than thirty calendar days from the date of receipt of the request, a response as to whether their personal data is being processed, as well as the content of such personal data;
- Present motivated requirement to Owner with objection to processing of their personal data;
- To submit a reasoned request for the modification or destruction of their personal data if such data is being processed unlawfully or is inaccurate;
- To the protection of their personal data against unlawful processing and accidental loss, destruction, or damage;
- Appeal with complaints about processing of their personal data to Commissioner of Verkhovna Rada of Ukraine for Human Rights or to court;
- Apply legal remedies in case of violation of legislation on personal data protection;
- Make reservations regarding limitation of right to process their personal data when giving consent;
- Withdraw consent to personal data processing at any time by written appeal to Owner.
7.3
To exercise their rights, User can contact Owner with written request to email or postal address specified in Section 9 of this Policy. Owner undertakes to consider User's request and provide response no later than 30 (thirty) calendar days from date of receipt of request.
8. Personal data protection
8.1
Owner takes all necessary organizational, technical and legal measures to ensure protection of User's personal data from unlawful or accidental access, destruction, distortion, blocking, copying, distribution, as well as from other unlawful actions of third parties.
8.2
Personal data protection measures include:
- Appointment of responsible persons for organization of processing and protection of personal data;
- Development and implementation of internal regulatory documents on processing and protection of personal data;
- Application of organizational and technical information protection means (encryption, passwords, access restriction);
- Use of secure HTTPS protocol for data transmission through Site;
- Regular backup and protection from data loss;
- To oversight of compliance with personal data protection legislation by the Controller's employees and third parties;
- Registration and accounting of all actions with personal data;
- Assessment of effectiveness of personal data protection measures and their regular update.
8.3
Owner undertakes to immediately inform User about any incidents related to unauthorized access or disclosure of personal data, as well as take all possible measures to eliminate consequences of such incidents.
8.4
User also responsible for maintaining confidentiality of their account data (login, password) and undertakes not to disclose them to third parties. In case of detection of facts of unauthorized access to account, User undertakes to immediately inform Owner about this.
9. Controller Contact Information
9.1
In the event of any questions regarding personal data processing, the exercise of rights, or complaints about the Controller's actions, the User may contact the Controller at the following:
10. Final provisions
10.1
This Policy takes effect from moment of its publication on Site and valid indefinitely until replacement with new version.
10.2
The Controller reserves the right to amend this Policy. In the event of material changes, the Controller undertakes to notify Users no fewer than 14 (fourteen) calendar days before the new version takes effect by posting a notice on the Website and/or sending a notification to the User's email address.
10.3
All issues not regulated by this Policy subject to resolution in accordance with current legislation of Ukraine, in particular Law of Ukraine "On Personal Data Protection", Law of Ukraine "On Information", Civil Code of Ukraine.
10.4
Current version of Policy always available at page: https://mm-medic.com/privacy.
10.5
After receiving notice of the changes, the User has the right to withdraw their consent to personal data processing by submitting a written request to the Controller. If the User continues to use the Website after the new version of the Policy takes effect and does not withdraw their consent, they are deemed to have accepted the new version.
If you have questions or comments about this Policy, you can contact us using contact details specified in Section 9. We value your trust and undertake to ensure maximum level of protection of your personal data.