Privacy Policy

Last updated: 20 July 2026

1. About This Privacy Policy

This Privacy Policy explains how Mevian Medicare Ltd collects, uses, stores and protects personal data when visitors use the Epitilia website or contact us through it.

The data controller responsible for the processing described in this policy is:

Mevian Medicare Ltd
Registered office: Ioanni Tsirou 11, Limassol, Cyprus
Company registration number: HE 438985
VAT number: 10438985M
Email: info@mevian.com
Telephone: +357 99 00 55 26

This Privacy Policy should be read together with our Cookie Policy, Terms of Use and Disclaimer.

2. Personal Data We Collect

We may collect personal data directly from visitors when they submit an enquiry or communicate with us.

This may include:

  • Name
  • Email address
  • Telephone number
  • Country
  • Company or organisation
  • Professional role
  • Information included in an enquiry or message
  • Records of correspondence with us

We may also collect limited technical and website-usage information, including:

  • Cookie-consent preferences
  • IP address and general geographical location
  • Device and browser type
  • Operating system
  • Pages visited
  • Approximate visit duration
  • Referring website or source
  • Website interactions and navigation
  • Technical, security and error information

Google Analytics information is collected only after the visitor provides consent.

3. Information Visitors Should Not Submit

The website’s contact form is intended for general product, professional and distribution enquiries.

Visitors should not use the contact form to submit:

  • Medical records
  • Detailed health information
  • Patient files
  • Test results
  • Prescription information
  • National identification documents
  • Payment-card information
  • Information about another person without proper authority

If sensitive or unnecessary personal data is submitted, we may delete it where it is not required to respond to the enquiry or comply with a legal obligation.

4. How We Use Personal Data

We may use personal data to:

  • Respond to product and professional enquiries
  • Communicate with wholesalers, distributors and potential business partners
  • Provide information about product availability
  • Assess potential distribution or commercial relationships
  • Arrange requested calls or follow-up communications
  • Maintain records of business correspondence
  • Operate, secure and maintain the website
  • Prevent spam, misuse, fraud or malicious activity
  • Understand website traffic and performance
  • Improve website content and usability
  • Establish, exercise or defend legal claims
  • Comply with legal, regulatory and professional obligations

We will not use personal data for purposes that are incompatible with those described in this Privacy Policy unless permitted or required by law.

5. Legal Bases for Processing

We process personal data only where we have a valid legal basis.

Responding to Enquiries

When someone contacts us about our products, product availability, distribution or a potential professional relationship, processing may be necessary to take steps at that person’s request before entering into a contract.

Where no potential contract is involved, we may process the information based on our legitimate interest in responding to enquiries and conducting professional business communications.

Business Administration and Records

We may process correspondence and business-contact information based on our legitimate interests in managing our operations, maintaining appropriate records and developing professional relationships.

Website Security

Technical and security information may be processed based on our legitimate interests in protecting the website, preventing misuse, maintaining availability and investigating security incidents.

Google Analytics

Google Analytics is used only with the visitor’s consent.

Visitors may reject Google Analytics without losing access to the website and may withdraw consent at any time through the Cookie Settings link.

Legal Obligations

We may process or retain personal data where necessary to comply with applicable legal, tax, accounting, regulatory or law-enforcement obligations.

Legal Claims

We may process personal data where necessary to establish, exercise or defend legal claims.

6. Google Analytics

We use Google Analytics to understand how visitors use the website and to improve its content, performance and usability.

Google Analytics may collect information about:

  • Pages viewed
  • Session duration
  • Website navigation
  • Device and browser type
  • General location
  • Referring sources
  • Technical interactions and errors

Google Analytics must remain disabled until the visitor provides consent through the cookie banner.

We do not use Google Analytics for personalised advertising, remarketing or creating advertising profiles. Google Signals and advertising-personalisation features should remain disabled.

Google states that individual IP addresses from users in the European Union are not logged or stored. IP addresses may be used briefly to derive general location information before being discarded.

Google Analytics user-level and event-level data will be retained for a maximum of 14 months, after which it will be automatically deleted in accordance with the configured retention settings.

Further information about the cookies used by Google Analytics is available in our Cookie Policy.

7. Cookies

The website uses strictly necessary cookies and, where consent has been provided, Google Analytics cookies.

Strictly necessary cookies support essential website functions and store cookie preferences.

Google Analytics cookies are optional and will not be activated before consent is obtained.

Visitors can review, change or withdraw their choices at any time through the Cookie Settings link in the website footer.

Further information is provided in our Cookie Policy.

8. Who May Receive Personal Data

Personal data may be shared with carefully selected recipients where necessary, including:

  • Website hosting and infrastructure providers
  • Website developers and technical-support providers
  • Email and communication-service providers
  • Cookie-consent and website-security providers
  • Google, where consent to Google Analytics has been provided
  • Legal, accounting, regulatory or professional advisers
  • Public authorities, courts, regulators or law-enforcement bodies where required by law
  • A purchaser, successor or professional adviser involved in a genuine business restructuring, merger or transfer, subject to appropriate confidentiality and data-protection safeguards

Service providers may process personal data only for the agreed purposes and in accordance with applicable data-protection obligations.

We do not sell or rent personal data.

9. International Transfers

Some service providers, including Google, may process information outside Cyprus or the European Economic Area.

Where personal data is transferred to a country outside the European Economic Area, we will use a legally recognised transfer mechanism where required. This may include:

  • A European Commission adequacy decision
  • The EU–US Data Privacy Framework for participating and certified organisations
  • European Commission Standard Contractual Clauses
  • Other safeguards permitted by applicable data-protection law

Google states that it participates in the EU–US Data Privacy Framework. Additional safeguards may apply under Google’s data-protection terms.

Visitors may contact us for further information about the safeguards relevant to their personal data.

10. How Long We Retain Personal Data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected.

General enquiry and correspondence records will normally be retained for up to 24 months after the most recent meaningful communication.

Information connected with an active or potential commercial relationship may be retained for the duration of that relationship and for any additional period required for legal, tax, accounting or dispute-resolution purposes.

Technical and security logs will normally be retained for no longer than 12 months unless a longer period is necessary to investigate a security incident or establish a legal claim.

Cookie-consent records may be retained for up to five years where necessary to demonstrate compliance with consent requirements.

Google Analytics user-level and event-level data will be retained for a maximum of 14 months.

Data may be retained for longer where required by law, regulation, a legal claim or an instruction from a competent authority.

When personal data is no longer required, it will be deleted, anonymised or securely destroyed.

11. Data Security

We use reasonable technical and organisational measures intended to protect personal data against:

  • Unauthorised access
  • Accidental loss
  • Unlawful use
  • Alteration
  • Disclosure
  • Destruction

These measures may include access controls, secure hosting, software updates, backups, encryption in transit and restrictions on access to personal data.

No internet transmission or storage system can be guaranteed to be completely secure. Visitors should avoid sending confidential or sensitive information through the general contact form.

12. Data-Protection Rights

Subject to the conditions and limitations of applicable law, individuals may have the right to:

  • Request access to their personal data
  • Request correction of inaccurate or incomplete data
  • Request deletion of their personal data
  • Request restriction of processing
  • Object to processing based on legitimate interests
  • Receive certain personal data in a structured, commonly used and machine-readable format
  • Request transmission of eligible data to another controller
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority
  • Receive information about relevant international-transfer safeguards

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

We may ask for reasonable information to confirm the identity of the person making a request. We will normally respond within one month, subject to any extension permitted by law for complex or numerous requests.

Requests may be sent to info@mevian.com.

13. Right to Object

Individuals have the right to object at any time to processing based on our legitimate interests where their particular circumstances justify the objection.

Where personal data is processed for direct marketing, individuals may object at any time. We will stop using the data for direct marketing after receiving an objection.

The website does not currently operate a newsletter or automated email-marketing programme.

14. Automated Decision-Making

We do not use personal data collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects.

15. Children’s Personal Data

Although Epitilia includes a paediatric formulation, this website is intended primarily for wholesalers, distributors, healthcare professionals and other adult professional users.

The website is not directed at children, and we do not knowingly collect personal data directly from children through it.

Parents and caregivers should not submit identifying or medical information about a child through the general contact form.

If we become aware that personal data has been submitted directly by a child without appropriate authorisation, we will take reasonable steps to delete it.

16. External Links

The website may contain links to third-party websites.

Mevian Medicare Ltd is not responsible for the privacy practices, security or content of external websites. Visitors should review the privacy policies of third-party websites before providing personal data.

17. Complaints

Individuals are encouraged to contact us first if they have concerns about how their personal data is handled.

They also have the right to lodge a complaint with:

Office of the Commissioner for Personal Data Protection
Kypranoros 15
1061 Nicosia, Cyprus

Postal address: P.O. Box 23378, 1682 Nicosia, Cyprus
Telephone: +357 22 818 456
Email: commissioner@dataprotection.gov.cy
Website: www.dataprotection.gov.cy

The right to complain to the supervisory authority does not affect any other administrative or judicial remedy.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • Changes to the website
  • Changes to our processing activities
  • The introduction or removal of service providers
  • Changes to legal or regulatory requirements
  • Changes to Google Analytics or other website technologies

The revised policy will be published on this website and the “Last updated” date will be amended.

Where required, visitors will be notified of material changes or asked to provide consent again.

19. Contact Us

Questions, requests or concerns about this Privacy Policy or the processing of personal data may be directed to:

Mevian Medicare Ltd
Ioanni Tsirou 11
Limassol, Cyprus

Company registration number: HE 438985
VAT number: 10438985M
Email: info@mevian.com
Telephone: +357 99 00 55 26

Request a callback

Get in touch

Fill the form bellow, and one of our team member get back in touch with you shortly.