← Back to home

Privacy Policy

1. General

What is this privacy policy and who is your data controller?

In this privacy policy (the "Privacy Policy") we, UAB "Max Nutrition" 305420438 ("Company", "we", "us" or "our"), explain how we, as a data controller, handle your Personal data (the "Personal data") when you visit our website/websites (the "Website"), use our mobile app/apps (the "Mobile App"), contact us through our official social media pages or email, and / or use our services.

If you purchase multiple products through our website, please note that the privacy policies of all such products will apply. In the event of any discrepancy or conflict between this Privacy Policy and the privacy policy of any specific product, the terms of the product-specific privacy policy shall take precedence with respect to that product.

What are personal data?

We care about the safety and security of your Personal data and make every effort to ensure it. Personal data refer to any information relating to an identified or identifiable natural person (e.g. your name, email address, etc.).

When processing your Personal data, the Company is guided by and complies with General Data Protection Regulation 2016/679 (the "GDPR"), California Consumer Privacy Act and any other applicable statutory regulations governing the protection of your Personal data.

All the definitions used in this Privacy Policy have the same meaning as prescribed in the Company's General Terms and Conditions unless expressly provided otherwise in this Privacy Policy.

Have any privacy related questions or inquiries?

In case of any questions or inquiries, or in case you would like to exercise any of your rights provided in this Privacy Policy, you may submit such inquiries and requests by means provided in the Contacts section of this Privacy Policy and / or you may also contact our Data Protection Officer regarding all privacy related issues by email: hello@melties.health.

2. What information you will find in this Privacy Policy?

  • Personal data processing principles we follow (Section 3);
  • Personal data we collect, processing purposes, legal grounds and retention periods (Section 4);
  • Personal data retention periods (Section 5);
  • To whom we provide your Personal data (Section 6);
  • Direct marketing and other marketing operations (Sections 7 and 8);
  • Security of your Personal data (Section 9);
  • Your rights related to Personal data you possess (Section 10);
  • Other privacy matters that you should take into account (Sections 11–18).

3. What data processing principles we follow?

We adhere to the general data processing principles established in the relevant privacy legal acts, including, but not limited to the following principles:

  • Lawfulness, fairness and transparency — we process Personal data in a lawful, fair and transparent manner;
  • Purpose limitation — we process Personal data for specified, explicit and legitimate purposes and we do not further process them in a manner incompatible with those purposes;
  • Personal data minimization — we process Personal data that are appropriate, relevant and only necessary for the purposes for which they are processed;
  • Accuracy — we process accurate and updated Personal data;
  • Limitation of storage period — we keep Personal data in a form which permits identification of you for no longer than is necessary for the purposes for which the Personal data are processed;
  • Integrity and confidentiality — we process Personal data in such a way as to ensure, through appropriate technical or organisational measures, adequate security of Personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

4. Personal data we collect, purposes, legal grounds and retention periods

We process the following Personal data for the purpose of:

  • Offering a personalized plan for you — we may process test quiz data (including sensitive Personal data related to your health, age, height, weight, target weight). We obtain such data directly from you. The legal basis is your consent (Art. 6(1)(a) GDPR). You may withdraw your consent at any time. Data is retained for no longer than 2 years following your last update or until you withdraw your consent.
  • Subscribing to our services and provision of our services — name, surname, email, phone number, bank account and transaction details, purchase history, other data you provide while registering. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Retained for no longer than 5 years following the end of the services, unless the law requires longer (e.g. accounting purposes).
  • Subscribing to email messages and newsletters — email address and purchase history. Legal basis: your consent (Art. 6(1)(a) GDPR) or our legitimate interest to offer similar goods/services to existing customers (Art. 21(2)(b) GDPR). You may withdraw consent or object at any time. Retained for no longer than 2 years.
  • Customer service — email address, content of the request, metadata of your communication, and other account info necessary to fulfil your request. Legal basis: consent (Art. 6(1)(a) GDPR) or our legitimate interest (Art. 6(1)(f) GDPR). Retained for no longer than 3 years, unless processing is needed longer for legitimate interest or legal claims.

We may use third-party Artificial Intelligence ("AI") tools to automate and optimize the processing of customer requests submitted through email or our customer support chatbot. These tools may analyze and interpret information you provide, categorize requests, and generate answers. By contacting our customer support, you acknowledge and agree to the processing of health-related information using AI tools solely for the purpose of providing effective customer support.

We may employ automated decision-making (including refund requests). You have the right to request human intervention. Data shared with third-party AI providers is governed by data protection laws and, where transferred outside the EEA, by Standard Contractual Clauses approved by the European Commission.

  • Managing and administering our social media accounts (Facebook, Instagram, TikTok, LinkedIn) — profile name, photo, reactions (likes, comments, shares). Legal basis: consent (Art. 6(1)(a) GDPR) or our legitimate interest (Art. 6(1)(f) GDPR). Retained as long as the account is valid.
  • Administrating and securing the Website and Mobile App — device data (IP, geographic location, browser type/version, OS, device type, screen resolution), and (with consent) location and motion activity data, plus usage data. Obtained via cookies and similar technologies. Legal basis: consent (Art. 6(1)(b) GDPR) or legitimate interest (Art. 6(1)(f) GDPR). Retained for no longer than 2 years from consent or as needed for our legitimate interest.
  • Establishment, exercise or defence of legal claims — Personal data necessary for the specific purpose. Legal basis: legal obligation and/or legitimate interest (Art. 6(1)(e), (f) GDPR). Retained as long as necessary.
  • Insurance, risk management, professional advice — Personal data necessary for the purpose. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) or legal obligation (Art. 6(1)(e) GDPR).
  • Compliance with legal obligations — Personal data necessary to comply (Art. 6(1)(e) GDPR). Retained as required by law.

Should the purpose or legal basis change, we will inform you.

5. How long we store your Personal data?

Your Personal data shall not be kept longer than is necessary for the specific purpose. Specific retention terms are in Section 4. After retention ends, or upon your request, Personal data is destroyed using overwriting or physical destruction.

We may aggregate, anonymize or de-identify your data so it can no longer reasonably identify you. Such data is no longer personal and may be used without restriction in any way allowed by law.

We may retain Personal data where necessary to comply with a legal obligation (e.g. accounting, tax) or to protect our interests (e.g. exercise or defence of legal claims).

6. To whom we provide your Personal data?

We may disclose your Personal data to members of our group of companies, our insurers, bailiffs, auditors, attorneys, notaries and other professional advisers, anti-fraud and compliance providers, AI service providers, payment processors, and other service providers (servers, email, analytics, marketing, call centers, order fulfilment and delivery), insofar as reasonably necessary for the purposes described in this Policy.

For payments we use third-party processors; we do not store full card information (only the last 4 digits). Where personal data is transferred outside the EU/EEA, we use Standard Contractual Clauses approved by the European Commission or other legal grounds compatible with Articles 45–49 of the GDPR.

7. Direct marketing communication

We may contact you via email or phone with newsletters, latest information, special offers and marketing campaigns. We may share your contact information with our group companies for direct marketing purposes. SMS/text messages may be sent via automatic dialing systems; message and data rates may apply.

You may opt out of receiving marketing communications at any time via the unsubscribe link in our messages or by contacting us. Opting out of marketing does not stop service-related communication.

8. Other marketing operations and cookies

We may use marketing tools of social media operators (e.g. Google LLC, Meta Platforms Inc.) and share data relevant for marketing with them. Where these operators are outside the EU/EEA, Standard Contractual Clauses apply.

We also use cookies — see our Cookie Policy for more information.

Telemarketing based on Established Business Relationship Rule: We may contact you via phone (TCPA § 310.4(b)(iii)(B)) to check on your order status. Calls may be recorded and stored for 24 months as required by law. You may opt out of telemarketing calls at any time.

9. Security of your Personal data

We use appropriate technical and organisational measures to protect your Personal data, including restricting access, signing confidentiality agreements, training, policies, access control and authentication, and physical security. Data is stored on Company servers or those of contractors bound by data-processing and confidentiality obligations. We cannot objectively guarantee full security.

10. Your rights

Your principal rights under data protection law are:

  • The right to be informed about processing of Personal data.
  • The right to access data.
  • The right to rectification.
  • The right to erasure (in certain circumstances).
  • The right to restrict processing (in certain circumstances).
  • The right to object to processing (including direct marketing).
  • The right to data portability.
  • The right to lodge a complaint with a supervisory authority.
  • The right to withdraw consent at any time.
  • The right not to be subject to a decision based solely on automated processing (with exceptions).

You may exercise these rights by contacting us by email. We must verify your identity and will respond within 1 month (extendable by 2 months for complex requests).

11. Third party websites

Our Website may contain links to third-party websites that have their own privacy policies. We take no responsibility for them — please review their policies before providing any Personal data.

12. Children Personal data

Our Website and Mobile App are targeted only at people over 18. If we learn we hold Personal data of a person under that age without parental consent, we will delete it. If you become aware that your child has provided us with Personal data without your consent, please contact us via email.

13. California Privacy Addendum

If you are a California consumer or resident, in addition to the information provided in this Privacy Policy, you may have additional rights under the California Consumer Privacy Act:

  • We do not knowingly sell personal information nor share it with third parties for direct marketing purposes.
  • We will retain, use, or disclose personal information only for the purposes described in this Privacy Policy.
  • You have the right to not be subject to discrimination if you exercise any of your rights.
  • We do not currently recognize or respond to browser-initiated Do Not Track signals.

14. Right to complaint

If you believe your rights have been violated, contact us by email or file a complaint with the supervisory authority in your EU member state of residence, place of work, or alleged infringement. Our data processing is supervised by the State Data Protection Inspectorate of the Republic of Lithuania, L. Sapiegos St. 17, LT-10312 Vilnius, email ada@ada.lt, www.vdai.lrv.lt.

15. Data scraping

Automated data collection (data scraping) from our Website is strictly prohibited without our explicit written consent. This includes the use of software, bots, scripts or any other automated methods.

16. Updating your data

Please let us know if the personal information we hold about you needs to be corrected or updated.

17. Changes to the Privacy Policy and other information

We reserve the right to change this Privacy Policy at any time. Any changes will be published on the Website, and in case of material changes we may inform you via email or other suitable means. Changes come into force from the date of their publication. In case of translation differences, the English version shall prevail unless otherwise provided.

18. Contacts

In case of any inquiries or if you would like to exercise any of your rights provided in this Privacy Policy, you may submit such inquiries and requests to us via the contacts provided here: melties.health/contacts.