News

All Recent Posts From XipBlog

Protecting your privacy and the security of your personal data is our top priority.

As an online pharmacy, to allow you to purchase certain products or provide consulting services, we may need to collect and process "sensitive" data.

Below, we explain, in a transparent manner, how we manage, protect, and store this information in full compliance with the European Regulation (GDPR No. 2016/679) and applicable national legislation.

1. What data we process and why

Personal data (and health-related data) are collected exclusively with your explicit consent (which you can revoke at any time). We process this data to:

  • Release and fulfill product orders.
  • Allow tax deductions for healthcare expenses (transmission of data to the Health Card System via Tax Code), where required and permitted.
  • Respond to requests for pharmaceutical advice or customer support for specific products.

2. Security Measures

To ensure that your sensitive data is not intercepted, lost, or used unlawfully, we adopt cutting-edge technical and organizational security measures:

  • Data Encryption: All transactions and exchanges of personal data on our site are carried out via a secure HTTPS protocol with SSL/TLS encryption. Sensitive data in our databases is protected by advanced encryption systems. Limited Access: Access to your health data is strictly limited to authorized personnel (e.g., pharmacists on our team or specifically appointed technical personnel) who have received appropriate operational training and are subject to a duty of confidentiality. Anti-Intrusion Systems: Our website and servers are protected by up-to-date firewalls, intrusion detection systems (IDS), and constant monitoring against cyber attacks.

3. Data Retention

Your sensitive data is not retained indefinitely:

  • Purchase and billing data (including data transmitted to the Health Card System) are retained for the period required by tax and accounting laws (typically 10 years).
  • Data provided for assistance or consulting purposes is retained only for the time strictly necessary to process your request and is then deleted or anonymized.
  • Data provided for site registration is retained until you request deletion or anonymization.

4. Data Sharing

Your sensitive data will never be sold, transferred, or disclosed to third parties for marketing or commercial profiling purposes. They may only be disclosed to:

  • Financial and healthcare authorities (e.g., the Health Card System for tax deductions).
  • Couriers and postal services (limited to the logistical data required for the delivery of the package, which is packaged anonymously and discreetly to avoid revealing its contents).
  • Technology partners appointed as Data Processors (e.g., website hosting providers) bound by strict confidentiality agreements.

5. Your Rights

You can exercise the rights provided by the GDPR at any time. You have the right to:

  • Access your data and request a copy.
  • Request rectification, updating, or deletion of your data (right to be forgotten).
  • Withdraw consent to the processing of your health data (in this case, you may no longer be able to complete the purchase of certain products).

For any questions or to exercise your rights, you can contact our Data Protection Officer (DPO), Dr. Giuseppe Basile, at the email address: ordini@irisfarma.com.

6. Data Controller

With regard to this website, Parafarmacia Nazionale snc is the data controller, with registered office at Via Nazionale, 156 - Paola - 87027 (CS), C.U. 010433, VAT and Tax Code IT 03311010783. For any clarification or to exercise your rights, you can contact us at the following numbers:

  • Phone: +390982585186
  • Fax: +393716385896
  • Email: ordini@irisfarma.com
In addition to the traditional methods of withdrawal (e-mail, post, fax), you can exercise your right of withdrawal electronically via the withdrawal button in the footer or in your customer account.
Fast Order