Privacy
Privacy policy
Updated 13 June 2026
LotusFarma is operated by LotusFarma, Roeselaarsestraat 147, 8870 Izegem, Belgium, VAT [BTW NUMBER]. We are the controller for personal data processed through this website.
This notice explains how we handle personal data for an informational pharmacy website and offline order requests. No medicines are sold online and no online payment is taken on this site today.
Controller and contact
Controller: LotusFarma, Roeselaarsestraat 147, 8870 Izegem, Belgium, VAT [BTW NUMBER]. Legal email: [EMAIL]. Phone: +32 471 75 11 01.
Deletion requests and data-rights requests can be made by email or by phone. We may ask for information needed to confirm your identity before acting.
Personal data we collect
- Order requests: name, email, delivery option and note.
- Leads and opening notifications: name, email, phone and message.
- Admin audit events: operational records of admin actions, used to protect the service and investigate misuse.
- Technical data necessary to serve the website and secure forms, such as server logs.
Purposes and legal bases
- To receive and follow up non-binding order requests: steps before or performance of a contract under GDPR Article 6(1)(b).
- To answer leads, contact requests and opening notifications: consent or your request under GDPR Article 6(1)(a) and, where relevant, Article 6(1)(b).
- To keep audit and security records: legitimate interest in operating a secure pharmacy service under GDPR Article 6(1)(f).
- To meet legal and bookkeeping obligations after an offline order is confirmed: legal obligation under GDPR Article 6(1)(c).
Recipients and hosting
Personal data is available only to pharmacy staff, authorized administrators and technical providers who need it.
The website is hosted on Railway. The current deployment uses a US Railway region; LotusFarma is moving this hosting to an EU region. Until then, appropriate safeguards will be used for any processing outside the European Economic Area.
We do not sell personal data.
Retention
- Order requests and confirmed offline orders are kept for the legal bookkeeping and pharmacy record-retention period that applies to the transaction.
- Lead and opening-notification records are kept until consent is withdrawn or until they are no longer needed for the request.
- Admin audit events are kept only as long as needed for security, abuse investigation and accountability.
- Where full deletion is not possible because of legal retention duties, records can be restricted or anonymized where appropriate.
Cookies and analytics
We do not use marketing cookies or tracking analytics today. The site may use technical processing that is necessary to deliver pages, remember essential choices or secure forms.
If marketing cookies, profiling or analytics are introduced later, this notice and any consent controls will be updated first.
Your rights
Under the GDPR, you can ask for access, correction, deletion, restriction, portability and objection where those rights apply. You can also withdraw consent at any time without affecting earlier lawful processing.
We aim to respond within one month. If a request is complex or repeated, the GDPR allows an extension or, in limited cases, a reasonable administrative fee.
You can complain to the Belgian Data Protection Authority, the Gegevensbeschermingsautoriteit / Autorité de protection des données, if you believe your data-protection rights have not been respected.