
GDPR Compliant
QG MED is fully compliant with the General Data Protection Regulation (GDPR), ensuring your privacy rights are respected and your data is handled transparently.
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data privacy law enacted by the European Union in May 2018. It is widely regarded as the world's strongest set of data protection rules, and sets a global benchmark for how organizations should handle personal data.
GDPR applies to any organization that processes the personal data of EU residents, regardless of where the organization is based. It gives individuals greater control over their personal information and establishes strict requirements for consent, transparency, and accountability.
Non-compliance can result in fines of up to €20 million or 4% of global annual revenue — whichever is higher — reflecting the seriousness with which the EU treats data privacy.
Your Rights Under GDPR
Right of Access
You can request a copy of all personal data we hold about you at any time.
Right to Rectification
You can ask us to correct inaccurate or incomplete personal data.
Right to Erasure
You can request that we delete your personal data ("right to be forgotten").
Right to Portability
You can request your data in a structured, machine-readable format to transfer elsewhere.
Right to Object
You can object to us processing your data for direct marketing or other purposes.
Right to Restriction
You can ask us to limit how we use your data in certain circumstances.
How QG MED Upholds GDPR
- We only collect personal data that is strictly necessary for fulfilling your order and providing our services.
- We obtain clear, explicit consent before using your data for marketing communications.
- Your data is never sold to third parties under any circumstances.
- We use encrypted storage and secure transmission protocols for all personal data.
- We maintain a clear data retention policy and delete data when it is no longer needed.
- We have appointed a Data Protection Officer (DPO) to oversee compliance.
- In the event of a data breach, we will notify affected users within 72 hours as required by law.
- We provide a straightforward process to exercise any of your rights listed above.
Exercise Your Rights
To exercise any of your GDPR rights or if you have questions about how we handle your data, please contact our privacy team:
We will respond to all requests within 30 days as required by GDPR.
