Last updated: 8 September 2026.
This privacy policy explains how Medicera Group SIA ("we", "us") processes personal data when you visit infuzionsystem.com and our other market websites, use our customer portal and online shop, contact us, take part in our training platform or submit a quality complaint. It also explains your rights under the EU General Data Protection Regulation (GDPR).
1. Data controller
Medicera Group SIA, Vilandes iela 8-22, LV-1010 Riga, Latvia. Registration number: 50203240641. VAT number: LV50203240641.
Questions about this policy or about your personal data: contact@infuzionsystem.com or +46 8 544 853 00.
2. What data we process, why and on what legal basis
Visitors to our websites
When you visit our websites our web server records technical data such as IP address, browser type, requested pages, referring page and time of the visit. We use this to deliver the website, keep it secure, detect abuse and compile aggregated statistics. Legal basis: our legitimate interest in operating a secure website. Server logs are retained for a maximum of 90 days.
Contact form and email enquiries
When you contact us through the contact form, by email or by phone we process the details you provide, typically name, email address, phone number, company and the content of your message. We use them to answer your enquiry and to follow up on it. Legal basis: your consent when you tick the box in the contact form, and our legitimate interest in responding to enquiries. Enquiries are kept for up to 12 months after the matter has been closed, unless they lead to a customer relationship.
Customer accounts and the online shop
The online shop and customer portal are for professional customers. To administer an account we process the name, email address, phone number, role and login details of the persons the customer designates as users, together with the customer's company details, delivery and invoice addresses and VAT number. When an order is placed we process order lines, prices, chosen delivery option, payment method and payment status, and we keep the order and invoice history. Legal basis: performance of our contract with the customer, and our legal obligation to keep accounting records. Accounting records, including invoices, are kept for as long as applicable accounting legislation requires. Account data is kept for as long as the account is active and thereafter for as long as we have a legal obligation or a legitimate interest, for example to handle complaints.
Online payments
Card payments, Revolut Pay, Apple Pay and Google Pay are processed by Revolut on a payment page hosted by Revolut. Your card details are entered directly with Revolut and never reach our servers. We receive the payment status, the card type and the last four digits of the card number so that we can match the payment to your order and process refunds. Revolut processes your payment data as an independent controller in accordance with its own privacy policy. Legal basis: performance of the contract.
Distributors
Clinics and salons are usually served by a distributor responsible for their market. The distributor can see and administer the customer accounts, orders and credit transactions of its own customers in the portal. Data about a customer's contact persons is therefore shared with that customer's distributor for the purpose of account administration, ordering and support. Legal basis: performance of the contract.
Support and service
When you contact our support, report a device issue or ask for service we process your contact details, the details of your business and the information you give about the issue in our support and service systems, so that we can handle the case and keep a record of it. Legal basis: performance of the contract and our legitimate interest in documenting service history. Support cases are kept for three years after they are closed.
Training platform
If your customer account gives you access to our training courses we process your course enrolments, lesson progress, quiz answers and results, and the certificates issued to you, in order to provide the training and document your qualification. Legal basis: performance of the contract and our legitimate interest in documenting who has completed which training. Training records are kept for as long as the account exists and thereafter for as long as the certificate is valid.
Quality complaints
Clients of a clinic can report a concern about a treatment through our quality complaint form. The report can be submitted anonymously. If you choose to leave an email address so that we can follow up, it is stored encrypted and is never shared with the clinic or distributor that the report concerns. Attachments have image metadata (such as location data) removed automatically. Reports are handled by a small, restricted team. Legal basis: our legitimate interest in maintaining treatment quality and brand integrity, and, for the email address, your consent. Please do not include health data or other information about other persons in your report. Reports are kept for as long as the investigation and any follow-up require, and thereafter as needed to document how the matter was handled.
Social media chat
Our websites can offer a Messenger chat provided by Meta Platforms. If you use it, Meta processes your data according to its own privacy policy, and we see the messages you send us. Legal basis: your consent.
3. Who we share data with
We share personal data only where necessary for the purposes above, with:
- Payment provider. Revolut, for online payments and refunds.
- Accounting and invoicing. Our accounting and invoicing system provider, for invoices, credit notes and bookkeeping.
- Distributors. The distributor responsible for your market, as described above.
- Carriers. The carrier delivering your order receives the delivery address and contact details for the delivery.
- IT suppliers. Hosting, email delivery and support tools that process data on our behalf under data processing agreements.
- Authorities. Where we are required to by law.
We do not sell personal data.
4. Transfers outside the EU/EEA
We store our data within the EU/EEA. Some of the suppliers above may process data in the United Kingdom (Revolut) or the United States (Meta). Transfers to the United Kingdom are covered by the European Commission's adequacy decision. Transfers to the United States take place under the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
5. Cookies
Our websites use the following cookies that are necessary for the site to work:
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you logged in and remembers your language and shopping cart during a visit. | Deleted when the browser is closed, or after 2 hours of inactivity |
| XSRF-TOKEN | Protects forms against cross-site request forgery. | 2 hours |
| remember_web | Keeps you logged in if you tick "Remember me". | Until you log out |
| laravel_cookie_consent | Remembers that you have seen the cookie notice. | 20 years |
Third-party cookies from Meta are set only if you use the Messenger chat. We do not use advertising cookies. You can delete or block cookies in your browser settings; the shop and portal require cookies to function.
6. Your rights
You have the right to:
- access the personal data we hold about you and receive a copy of it,
- rectify inaccurate or incomplete data,
- erase data that we no longer need to keep,
- restrict processing in certain circumstances,
- data portability for data you have given us and that we process on the basis of consent or a contract,
- object to processing based on our legitimate interest,
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.
To exercise your rights, contact contact@infuzionsystem.com. We may need to verify your identity before acting on a request. If you are unhappy with how we handle your data you can lodge a complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija), www.dvi.gov.lv, or with the supervisory authority in the country where you live (in Sweden, the Swedish Authority for Privacy Protection, IMY, www.imy.se).
7. Security
Our websites and portal are served over encrypted connections (TLS). Access to personal data is restricted to staff who need it for their work. Passwords are stored hashed, and accounts can be protected with two-factor authentication. Card data is handled solely by our payment provider.
8. Changes to this policy
We may update this policy when our processing or the law changes. The current version is always published on this page, with the date of the latest update at the top.
English
Spanish
Danish
German
Dutch
Swedish
Portuguese