Legal

Privacy Policy

Information on the processing of personal data on this website pursuant to Articles 13 and 14 GDPR.

Version: August 2026

1. Controller

The controller within the meaning of Art. 4(7) GDPR for data processing on this website is the entity named in the imprint: Natural Herbs Pharma s.r.o., Prague, Czech Republic. Full contact details can be found there.

No data protection officer has been appointed, as there is no obligation to do so under Art. 37 GDPR. For all questions regarding data protection, you can reach us using the contact details given in the imprint.

2. Principles and scope of processing

We process personal data only insofar as this is necessary to provide a functioning website together with our content and services, or where you have given your consent. Processing takes place solely on the legal bases set out in Art. 6 GDPR; the applicable legal basis is stated for each processing activity below.

We do not process special categories of personal data within the meaning of Art. 9 GDPR — in particular health data — via this website. Our offering is directed exclusively at commercial buyers (pharmacies, wholesalers, manufacturers); the contact form processes business contact details, not patient or health data. Please do not send us any health data or personal data relating to third parties via this website.

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place on this website.

3. Hosting and server log files

This website is hosted by ALL-INKL.COM – Neue Medien Münnich, proprietor: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. Processing takes place on servers located in Germany. A data processing agreement pursuant to Art. 28(3) GDPR is in place with the host.

When you access this website, the host automatically collects information in what are known as server log files, which your browser transmits:

  • IP address of the requesting device
  • date and time of access
  • name and URL of the file retrieved
  • website from which the access originated (referrer URL)
  • browser and operating system used (user agent)
  • volume of data transferred and HTTP status code

The purpose of this processing is to deliver the website, to ensure trouble-free operation and to maintain system and IT security. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in providing this website securely and reliably. The log files are deleted automatically by the host after a short period, unless they are exceptionally required to investigate a specific security incident. The data is not combined with other data sources.

4. Technical operation of the website (processing on our behalf)

The design, technical upkeep and maintenance of this website are carried out by our service provider puox – Eduard Pflugfelder (Germany). Acting as a processor pursuant to Art. 28 GDPR, the provider acts solely on our instructions and may, in the course of maintenance, technically access the website and the data transmitted through it. A data processing agreement forms the basis of this activity.

Backup copies of the website are transferred in encrypted form and stored with the host in Germany. No transfer to third countries takes place in this context.

5. SSL/TLS encryption

To protect the transmission of confidential content — such as enquiries you send via the contact form — this website uses SSL/TLS encryption in line with the current state of the art. You can recognise an encrypted connection by the “https://” prefix and the padlock symbol in your browser bar. When encryption is active, the data you transmit to us cannot be read by third parties.

6. Contact form and contact by email

If you contact us via the contact form, we process the data you provide: name and email address (mandatory, without which we cannot answer your enquiry), your message (mandatory) and, optionally, your telephone number and subject (Art. 13(2)(e) GDPR). The same applies if you contact us directly by email.

The purpose of this processing is to handle and respond to your enquiry and to initiate a business relationship. The legal bases are Art. 6(1)(b) GDPR (steps taken prior to entering into a contract) and — where your enquiry is not directed at a contract — your consent pursuant to Art. 6(1)(a) GDPR, which you give via the mandatory checkbox in the form. You may withdraw this consent at any time with effect for the future (Art. 7(3) GDPR); an informal email is sufficient. The lawfulness of processing carried out before withdrawal remains unaffected.

Technical implementation (Contact Form 7). The contact form is implemented using the WordPress plugin “Contact Form 7”. When you submit it, your details are processed on our web server (hosting in Germany, see section 3) and delivered to us by email; transmission takes place over an encrypted connection. The form data is not permanently stored in the website database. No providers outside the EU are involved in sending the form; no third-country transfer takes place in this context.

7. Fonts (locally hosted)

This website uses the typefaces “Inter” and “Lora” for a consistent presentation. The font files are stored locally on our web server and are loaded exclusively from there (self-hosting). No connection to servers operated by Google or other third parties is established when the fonts are loaded; no personal data is transmitted to third parties in this process.

8. Cookies and consent management

We currently set no cookies requiring consent for the mere visiting of this website. No analytics, statistics, marketing or advertising cookies are in use, and no connection to third-party servers is established when a page is called up.

To obtain, manage and document consent we use the consent tool “Real Cookie Banner” (devowl.io GmbH, Germany). It stores your selection and documents it for evidentiary purposes (Art. 7(1) GDPR), setting a strictly necessary cookie for this purpose. The legal basis is Art. 6(1)(c) GDPR in conjunction with our obligation to demonstrate compliance, together with our legitimate interest in lawful consent management (Art. 6(1)(f) GDPR). Should we use services requiring consent in future, these will only be loaded after your express consent; you may change or withdraw consent at any time with effect for the future.

9. Google Search Console, site verification and PageSpeed Insights

We use the WordPress plugin “Site Kit by Google” to connect our website with three Google services: Search Console, site verification and PageSpeed Insights. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

No web analytics service and no tag manager are integrated. Neither Google Analytics nor Google Tag Manager is active; no Google script is loaded when you visit this website, no Google cookies are set, and no visitor-related analysis of your usage behaviour takes place.

Search Console provides us exclusively with aggregated, non-personal reports on the search terms for which our pages appear in Google Search; this data arises at Google in the course of searches, not through any collection on our website. Site verification consists of proof of our ownership. We call up PageSpeed Insights as needed from the protected administration area; in doing so Google retrieves our pages, not your data. The legal basis for this use is Art. 6(1)(f) GDPR; our legitimate interest lies in the discoverability and technical optimisation of our website. Further information: policies.google.com/privacy

10. Wordfence (firewall and security)

To protect this website against attacks, malware and unauthorised access, we use the security plugin Wordfence from Defiant, Inc. (USA). Wordfence inspects incoming requests and processes in particular IP addresses, request data and access times; suspicious or malicious access is blocked. IP addresses may be transmitted to Defiant servers in the USA in this context, for example for comparison with known attacker lists.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting the website, its visitors and the data transmitted through it — at the same time, this use serves to fulfil our obligations under Art. 32 GDPR. The third-country transfer to the USA is safeguarded by the EU standard contractual clauses (Art. 46(2)(c) GDPR). Security-related log data is stored only for as long as is necessary to defend against attacks. Further information: wordfence.com/privacy-policy

11. Your rights as a data subject

You have the following rights in respect of your personal data:

  • right of access to the data processed (Art. 15 GDPR)
  • right to rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to data portability (Art. 20 GDPR)
  • right to withdraw consent given, with effect for the future (Art. 7(3) GDPR)

Right to object (Art. 21 GDPR). Where we process your data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

12. Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in particular in the Member State of your residence, place of work or the place of the alleged infringement. As our registered office is in the Czech Republic, the supervisory authority responsible for us is: Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, www.uoou.cz.

13. Retention period

Unless a more specific retention period is stated in this privacy policy, your personal data remains with us until the purpose of processing ceases to apply, you withdraw consent, or you legitimately request erasure. We delete data from contact enquiries once the enquiry has been conclusively dealt with and no retention obligations stand in the way. Where a business relationship arises, we retain business records in accordance with commercial and tax law requirements; the legal basis for this is Art. 6(1)(c) GDPR. Once the periods have expired, the data is deleted.

14. Amendments to this privacy policy

We adapt this privacy policy whenever data processing on this website changes — for example through new services — or legal requirements change. The version published here at any given time applies.