NUTRIMEDA

Privacy Policy.

Last updated: 11 June 2026 · Applies to nutrimeda.com and the Nutrimeda nutrition practice

Your privacy matters here for a simple reason: the work we do together often involves information about your health. This policy explains, in plain language, what personal data Nutrimeda collects, why, on what legal basis, how long it is kept, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

1. Who is responsible for your data

The data controller is Nutrimeda Limited, a company registered in Ireland (Company No. 585283), trading as Nutrimeda, registered office: Dublin, Ireland.

Contact for anything in this policy: through the enquiry form at nutrimeda.com. The practice is run by Margarita Jurjonaitė, MPharm, MSc.

2. What data we collect

When you use the enquiry form

When you become a client

When you visit the website

3. Health data — a special category

Information about your health is "special category data" under Article 9 GDPR and receives extra protection. Nutrimeda processes it only with your explicit consent, which is collected in writing before your first consultation (Article 9(2)(a) GDPR). You may withdraw that consent at any time by contacting us; we will stop the related processing, though withdrawal does not affect what was lawfully done before it, and without this data we are unable to provide nutrition services.

4. Why we use your data, and the legal basis

PurposeLegal basis (GDPR)
Replying to your enquiry and arranging a Discovery call Steps prior to a contract — Art. 6(1)(b); your consent given on the form
Providing consultations, written plans and follow-up support Performance of a contract — Art. 6(1)(b); explicit consent for health data — Art. 9(2)(a)
Writing a summary letter to your GP Your explicit consent — Art. 6(1)(a) and Art. 9(2)(a); only ever at your request
Invoicing, accounting and tax records Legal obligation — Art. 6(1)(c)
Keeping the website secure and diagnosing technical problems Legitimate interests — Art. 6(1)(f)
Occasional practice news or articles by email Consent — Art. 6(1)(a); only if you separately opt in, withdraw any time

We do not sell personal data, do not use it for advertising, and do not make automated decisions or profiling that produce legal or similarly significant effects.

5. Who can see your data

Within the practice, only Margarita Jurjonaitė. Outside it, data is shared only with service providers ("processors") who act under contract and on our instructions:

Beyond that, data leaves the practice only when you ask (for example, the GP letter) or where the law requires it. The current list of providers is available on request.

6. International transfers

Where a provider stores data outside the European Economic Area, the transfer is protected by an EU adequacy decision or the European Commission's Standard Contractual Clauses. Details for any specific provider are available on request.

7. How long we keep data

DataRetention
Enquiries that do not lead to an engagement12 months, then deleted
Client records (intake, notes, plans, labs)8 years after your last appointment
Invoices and accounting records7 years, as required by Irish tax law
Email correspondenceReviewed and pruned with the client record

8. Your rights

You can at any time ask to: access a copy of your data; correct anything inaccurate; delete data (where we have no legal duty to keep it); restrict or object to processing; receive data you provided in a portable format; and withdraw consent without affecting prior processing. Contact us through the enquiry form at nutrimeda.com — we respond within one month.

If you are unhappy with how your data is handled, you have the right to lodge a complaint with the Irish supervisory authority: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 · www.dataprotection.ie. We would, of course, prefer the chance to resolve any concern directly first.

9. Cookies

This website sets no cookies other than those strictly necessary for it to function, and uses no analytics or advertising trackers. That is why you see no cookie banner. If this ever changes, this policy will be updated and consent will be requested before any non-essential cookie is set.

10. Security

Client records are stored in encrypted, access-controlled systems protected by strong, unique passwords and two-factor authentication. Paper notes, where they exist, are kept locked. No system is perfectly secure, but the practice is deliberately small: one practitioner, minimal data, shared with no one by default.

11. Children

The practice is designed for adults and the website is not directed at anyone under 18. We do not knowingly collect children's data.

12. Changes to this policy

Any material change will be posted on this page with a new "last updated" date. Significant changes affecting current clients will be communicated by email.