Welcome to the SwellStop.com Privacy Policy. SwellStop.com (the “Website”) is an e-commerce shop for customers in the European Union (EU), the United States, and worldwide. We value your privacy and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws worldwide ( privacypolicies.com ). This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. We have structured this policy to include all necessary information, such as our contact details, the personal data we collect, the purposes of processing, our legal bases, disclosures to third parties, international transfers, retention, security measures, your data subject rights, and how to contact us or supervisory authorities ( privacypolicies.com ). By using our Website, you consent to the practices described in this policy.
The entity responsible for your personal data (“Controller”) is EUNICA Pharm srl , the company behind SwellStop.com. EUNICA Pharm srl is an Italian company (located in Caronno Pertusella (VA), 21042 Italy) that processes orders and securely stores related billing information on-site. As the Controller, we determine the purposes and means of processing your personal data in accordance with privacypolicies.com . For questions or concerns regarding your personal data, you can contact us as follows:
We currently do not have an EU representative (as we are based in the EU) and no designated Data Protection Officer (DPO) because our activities do not meet the GDPR criteria for a DPO (e.g., our core activities do not involve large-scale processing of sensitive data or systematic monitoring of individuals on a large scale). See commission.europa.eu . We will reassess this if our processing activities change. In the meantime, please direct all data protection-related inquiries to the contacts listed above.
We only collect personal information that is necessary for the operation of our e-commerce services and to provide you with support. This includes:
We do not collect sensitive personal data (e.g., regarding health, racial or ethnic origin, political opinions, or religious beliefs) and do not knowingly collect personal data from children under the age of 16. Our website and services are not directed at children. If we become aware that a minor under the age of 16 has provided us with personal data without verifiable parental consent, we will delete it.
We process personal data for the following purposes. For each purpose, we also explain the legal basis under the GDPR or other applicable laws that permits us to process the data:
We do not use your personal data for purposes incompatible with those mentioned above, unless we obtain your consent or this is required/permitted by law. Furthermore, we do not make any automated decisions, including profiling, that have legal or similarly significant effects on you. (For example, we do not use algorithms to deny services or set individual prices without human intervention.)
Like most websites, we use cookies and similar tracking technologies to operate our website and improve your user experience. Cookies are small text files that are stored on your device when you visit our site. They perform various functions – from keeping you logged in to remembering your shopping cart – and also help us understand how our website is used and to advertise more effectively. In this section, we explain our use of cookies and your choices.
Categories of cookies we use:
Your choice: On your first visit (and at regular intervals), you will see a cookie banner. You can accept or reject all non-essential cookies /adjust your settings. If you accept, analytics and advertising cookies will be set as described. If you reject, we will only set essential cookies. You can change your preferences at any time via the “Cookie Settings” link on our website or delete cookies in your browser (this will cause the banner to reappear on your next visit).
Please note that opting out on our website does not necessarily delete data already stored by third parties (e.g., Facebook or Google). However, you can use the tools provided by these companies: for example, adjusting the advertising settings in your Facebook or Google account or completely disabling personalized ads. We recommend familiarizing yourself with these options.
For further details, please see our separate Cookie Policy (if available) or contact us if you have any questions about our use of cookies and similar technologies.
We treat your personal data with care and confidentiality. We do not sell your personal information to unrelated companies for money (wearehearken.com ). However, to operate our business and provide services, we share data with trusted third parties under strict conditions – solely for the purposes outlined in this policy and in accordance with applicable law. In e-commerce, it is common practice to share data with service providers such as payment processors, shipping companies, analytics and advertising partners, etc., to the extent necessary for processing transactions and operating the website (privacypolicies.com ). The main categories of recipients are:
In all cases of data transfer, we only share the minimum necessary information. We ensure that commissioned third parties are obligated to protect the data. Our service providers are vetted for security standards; where necessary, contracts are in place to guarantee GDPR-compliant processing. For more detailed information, please contact us at any time.
Because we serve customers worldwide and use service providers in various countries, your personal data may be transferred across borders. If you are located in the EU/EEA or the United Kingdom, please note that some of our service providers/partners are located outside these regions , including the United States. The GDPR and similar laws impose strict requirements for transfers to “third countries” (outside the EU/EEA, without an adequacy decision) – privacypolicies.com . We take the necessary safeguards for such transfers.
Transfers to the USA (EU-US Data Privacy Framework and Standard Contractual Clauses): On July 10, 2023, the EU Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF) wilmerhale.com . Where possible, we base transfers to US service providers on this framework (e.g., Meta and Google are certified).
If a recipient is not (or not yet) certified under an adequacy mechanism, we use the EU Commission’s Standard Contractual Clauses (SCCs) as the primary transfer mechanism (privacypolicies.com ). These oblige the recipient to comply with EU data protection standards. We may conduct transfer impact assessments and review additional technical measures (e.g., additional encryption).
Further international transfers: For transfers outside the EU/EEA/UK (e.g., support service providers in India or the Philippines), we ensure a suitable legal basis – typically Standard Contractual Clauses (SCCs) or, where applicable, an adequacy decision . In exceptional cases, we may rely on an exception under Article 49 GDPR (e.g., contract performance for delivery to an address outside the EEA or explicit consent ).
Regardless of the mechanism, your data will always be handled securely . We contractually require confidentiality and security; in case of non-compliance, we will terminate data transfers or cooperation.
If you require further information regarding international transfers or specific guarantees (e.g., a copy of the SCCs used), please contact us using the details in the Contact section.
We retain personal data only as long as necessary to fulfill the purposes for which we collected it – including for business operations and to comply with legal, accounting, or reporting requirements (privacypolicies.com ). This aligns with the GDPR’s “storage limitation” principle (privacypolicies.com ). The retention period varies depending on the data type and context. The most important timeframes/criteria are outlined below:
After the respective retention period expires , we delete or anonymize the data. If immediate deletion is not possible (e.g., in encrypted backups), the data remains securely isolated until deletion.
We take the security of your personal information very seriously and have implemented various technical and organizational measures to prevent unauthorized access, loss, alteration, or disclosure. These include, but are not limited to:
If you suspect that your account has been compromised or that the security of your data is at risk, please contact us immediately so that we can take appropriate action.
If you are located in the EU, the EEA, the UK, or certain other jurisdictions, you have specific rights regarding your personal data, which we respect and guarantee. These rights under the GDPR and similar laws include : privacypolicies.com
These rights arise from the GDPR (privacypolicies.com ) and similar laws and are subject to certain conditions. To exercise your rights: Contact us by email at info@swellstop.com or by mail (see Contact). For security purposes , we may verify your identity (e.g., by comparing known information, using your account, or – only as a last resort – by checking your ID without storing the ID data).
There is no fee for exercising your rights . However, in the case of manifestly unfounded or excessive requests, we may charge a reasonable fee or reject the request – with justification.
We will respond as quickly as possible and no later than one month after receipt. In complex cases or with a high volume of requests, this period may be extended by up to two months; we will inform you of the reasons and duration within the first month.
If we are unable to comply with your request in whole or in part, we will explain the reasons (e.g., legal retention obligations).
Right to lodge a complaint: You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live, work, or where the alleged infringement took place (privacypolicies.com ). In Italy, this is the Garante per la Protezione dei Dati Personali , Piazza Venezia 11, 00187 Rome, Tel. +39 06 696771, Email: protocollo@gpdp.it (garanteprivacy.it ). In the United Kingdom: Information Commissioner’s Office (ICO).
We would be happy to clarify your concerns directly with you before you file a complaint with an authority.
If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Furthermore, we generally explain our data handling practices in the USA and strive to comply with other state data privacy laws (Virginia, Colorado, etc.).
Categories of personal information (last 12 months): In the past 12 months, we have collected the following categories (according to California law):
We do not collect sensitive personal information as defined by California law without consent, and we do not collect data from individuals under the age of 16.
Sources of personal information: Directly from you (registration, checkout, contact) and indirectly through your interactions (cookies/analytics) on springernature.com . No data purchases from data brokers.
Purposes of data collection/use: As described in the section “How we use your personal data” (order processing, customer service, payments, marketing, advertising/measurement, service improvement, security/fraud prevention, debugging/troubleshooting, legal obligations) springernature.com springernature.com .
Disclosures (last 12 months): Data is shared with service providers (hosting, email, marketing), payment processors (Stripe, PayPal), logistics (shipping), advertising/analytics partners (Google, Facebook), and legal/regulatory bodies as required. Data
is not shared with data brokers or for independent direct marketing by third parties (springernature.com ).
Selling / “Sharing” for Advertising: We do not sell your personal information for money . The use of advertising cookies (Facebook/Google) may be considered “selling” or “sharing” under the CPRA, as third parties use data for personalized advertising . This typically involves identifiers (cookie ID, IP address) and internet activity .
Your rights under CCPA/CPRA:
Exercising your California rights: Send a request by email to info@swellstop.com (subject: “California Privacy Rights Request”; please specify the right) or by mail (Attention: Privacy; see Contact).
To opt out of sales/sharing, please use the methods mentioned (cookie settings, GPC) or inform us directly.
Verification: To prevent unauthorized access to or deletion of data, we verify your identity depending on the sensitivity and nature of the request (e.g., email confirmation, account login, order verification, sworn statement, or identity service). For authorized representatives, proof of authorization is required.
We aim to respond within 45 days ; if necessary, we may extend this time by another 45 days with justification. Responses will be sent electronically or by mail.
Other US states: In states like Virginia, Colorado, Connecticut, or Utah, similar rights exist (confirmation, access, correction, deletion, opt-out from targeting). We intend to respect these; please use the same contact methods.
In summary, we want to offer all customers transparency and control over their personal information. If you have any questions, please contact us.
Under the GDPR, certain organizations are required to appoint a data protection officer (e.g., those processing large amounts of sensitive data, conducting extensive systematic monitoring, or operating as public bodies) – commission.europa.eu . We have reviewed our obligations and are currently not required to appoint a DPO. Should our activities change, we will reassess this.
We take data protection very seriously. Internally, management is responsible; processes are continuously monitored. If you have any questions, concerns, or complaints, please contact us – we will handle your request with the same care as a formal data protection officer.
If you have any questions or concerns about this privacy policy or the processing of your personal data by SwellStop.com, please feel free to contact us. We are happy to help.
Contact information for data protection inquiries:
Note: When submitting data protection requests, please provide sufficient details (e.g., the email address associated with your account/order) so that we can process your request. Identity verification is required for certain requests (see above).
We usually respond within a few business days. If you don’t receive a response, please send a brief reminder.
Contacting the authorities: If we do not resolve your issue to your satisfaction, you can contact the relevant supervisory authority. Our lead authority is the Italian DPA (Garante per la Protezione dei Dati Personali), Piazza Venezia 11, 00187 Rome, Italy (Tel.: +39 06.696771, Email: protocollo@gpdp.it) garanteprivacy.it . Alternatively, you can contact your local supervisory authority. Customers in the USA can contact their state attorney general or the Federal Trade Commission.
However, we hope to resolve any issues directly with you. Your privacy is important to us, and we are continuously working to protect it as best as possible.
Thank you for reading our privacy policy. Please review this policy periodically – especially if you use our website frequently – to stay informed. We will notify you of any significant changes as described in the next section.
We may update this Privacy Policy from time to time to reflect changes in our practices, new legal requirements, or other operational reasons. When changes are made, we will adjust the “Last Updated” date at the top. For significant changes, we will provide clearer notification or, where required by law, obtain your consent (e.g., a notice on the website or email notification).
Changes will take effect as soon as the revised privacy policy is published. Your continued use of SwellStop.com after an update will be considered – to the extent permitted by law – your acceptance of the amended terms. If you do not agree, you should discontinue using our services and contact us.
We keep previous versions of this privacy policy (with validity dates) available for reference purposes [where applicable, please indicate – e.g. “on request” or as an archive on our website].
By shopping at SwellStop.com or interacting with our website, you entrust us with your personal information. This trust is important to us – we protect your data and handle it responsibly. If you have any questions or feedback about this policy, please contact us .
Thank you for choosing SwellStop.com!
Last updated: June 19, 2025