Last updated: 15 March 2026: 4/26/2026
Data Controller
The data controller for your personal data is FSC TopNutrition, with registered address at C. de la Libertad, 59, 28100, Madrid (Spain) and contact email fsctopnutrition@gmail.com.
This privacy policy describes how we collect, use, retain and protect your personal information when you use our online store or visit our physical store, in accordance with Regulation (EU) 2016/679 (GDPR) and other applicable data protection legislation.
Personal Data We Process
Depending on the nature of your relationship with us, we may process the following data:
Identification and contact data
- Name, surname, postal address and email address
- Phone number and billing information
- Payment information (handled entirely by Stripe; we do not store card details)
- Communication preferences and account settings
Technical and browsing data
- IP address, device type, browser and operating system
- Pages visited, session duration and traffic source
- Approximate location data (IP-based)
- Cookies and tracking technologies (see our Cookie Policy)
Purposes and Legal Basis for Processing
We process your data for the following purposes and legal bases:
- Order management and fulfilment, payment processing (performance of contract)
- Transactional communications: order confirmations, shipping notifications and after-sales support (performance of contract)
- Customer service, complaint and returns management (performance of contract / legitimate interest)
- Improvement of products, services and user experience (legitimate interest)
- Sending commercial communications and newsletters (explicit consent, revocable at any time)
- Compliance with legal and tax obligations and fraud prevention (legal obligation)
Data Sharing with Third Parties
We do not sell or share your data with third parties for commercial purposes. We only communicate data in the following cases:
- Service providers necessary for business operations (web hosting, email platform, technical support), under a data processing agreement
- Payment gateway Stripe, for secure transaction processing
- Transport and logistics companies, solely with the data needed to deliver your order
- Public authorities when required by law or necessary to protect legitimate rights
Data Security
We apply appropriate technical and organisational measures to ensure the confidentiality, integrity and availability of your personal data: TLS/SSL encryption on all communications, storage on secure servers, role-based access control, regular backups and security audits. However, no system is completely infallible and in the event of a security breach we will act in accordance with the GDPR.
Your Rights
As a data subject, you may exercise the following rights at any time by sending your request to fsctopnutrition@gmail.com:
- Right of access: obtain confirmation of whether we process your data and receive a copy
- Right of rectification: correct inaccurate or incomplete data
- Right of erasure ('right to be forgotten'): request deletion of your data when no longer necessary
- Right to data portability: receive your data in a structured, commonly used format
- Right to restriction of processing: request temporary suspension of the use of your data
- Right to object: object to processing based on legitimate interest or for direct marketing purposes. You also have the right to lodge a complaint with the relevant data protection authority.
Cookies and Tracking Technologies
We use first-party and third-party cookies to improve navigation, analyse site usage and personalise the user experience. Please see our Cookie Policy for more information and to manage your preferences.
Privacy Contact
To exercise your rights or ask any questions about the processing of your personal data, you can contact us at:
Your privacy, our priority
We process your data with transparency, security and strict compliance with European regulations. Our team is available to answer any privacy-related questions.
Encryption & Security
All communications and transactions are protected with bank-level SSL/TLS encryption.
Full Transparency
We clearly explain what data we collect, for what purpose and how long we retain it.
Your Rights, Always Active
Access, correct or delete your data at any time. You can also lodge a complaint with your data protection authority.