Identity of the Data Controller
MenMed (men-med.com) is the Data Controller for the processing of personal data described in this notice. The owner and legal representative is Rowena Calderwood.
Registered contact address: 19 Rue d'Italie, 13100 Aix-en-Provence, France.
Contact email: [email protected].
Scope of this Notice
This notice explains how MenMed processes personal data in connection with its informational services on men’s health, including the operation of the website, handling of inquiries, optional communications (such as newsletters), audience measurement, security and maintenance of the service. It applies to visitors, subscribers, contributors, and any person who contacts MenMed through the website or by email.
Categories of Personal Data Processed
Data You Provide Voluntarily
- Identification and contact data: name, email address, and any details you include when you contact us or subscribe to optional updates.
- Professional details (if you submit editorial contributions or professional inquiries): role, organization, credentials (where applicable).
- Preferences and consents: communication preferences, cookie choices, and records of consent.
- Content of communications: the text of messages you send to us.
Data Collected Automatically
- Technical and usage data: IP address, device and browser information, pages viewed, timestamps, referral URLs, and similar diagnostic logs generated by our servers and audience measurement tools.
- Cookies and similar technologies: subject to your choices, we may store or read identifiers to enable essential site functions, remember preferences, and measure audience engagement.
Special Categories of Data (Health Information)
MenMed is an informational resource. We do not require or intentionally solicit health or other special category data. Please do not include sensitive information about your health or other special categories of data in free-text fields. If you choose to disclose such information, we will process it only to the minimum extent necessary to respond to your request and based on your explicit consent implied by your voluntary disclosure. You may withdraw this consent at any time.
Purposes of Processing and Legal Bases
- Operating and securing the website (providing content, preventing abuse, detecting errors, ensuring availability): legitimate interests (ensuring a secure and functional service) and, where logs are necessary for compliance, legal obligation.
- Responding to inquiries and correspondence: legitimate interests (handling requests and communications); if your request concerns pre-contractual steps for a service you ask us to provide, performance of a contract or pre-contractual measures.
- Providing optional communications (e.g., newsletters or updates): consent. You may withdraw consent at any time without affecting prior lawful processing.
- Audience measurement and analytics: consent, unless limited, strictly necessary audience measurement is implemented under applicable French guidance; where consent is required, analytics will only run after you have consented.
- Maintaining records of consents and compliance: legal obligation (EU and French data protection law) and legitimate interests (demonstrating compliance).
Cookies and Similar Technologies
We use cookies and similar technologies to operate the site, remember preferences, and, with consent, measure audience engagement. Upon your first visit, and thereafter at intervals, you may be asked to set your cookie preferences. You can also adjust your browser settings to manage or block cookies; doing so may affect site functionality.
Categories
- Strictly necessary cookies: required for core functions (e.g., security, load balancing). These are placed on the basis of our legitimate interests and do not require consent.
- Preference cookies: remember your choices (e.g., language or cookie settings); used with your consent or, where strictly necessary for the requested service, our legitimate interests.
- Analytics cookies: help us understand traffic and improve content; used only with your consent.
Typical Durations
- Session cookies: deleted when you close your browser.
- Preference cookies: typically retained up to 12 months.
- Analytics cookies/identifiers: retained no longer than 13 months in accordance with French CNIL recommendations.
You may change or withdraw your cookie choices at any time through your browser settings and, where available, our on-site consent tools. For assistance, contact [email protected].
Recipients and Processors
We restrict access to personal data to authorized personnel and trusted service providers acting on our instructions. Categories of recipients include:
- Hosting and infrastructure providers (website and email servers, content delivery, security).
- Analytics and audience measurement providers (if you consent).
- Communication tools and newsletter services (if you subscribe).
- Professional advisers (legal/accounting) where necessary.
- Regulatory or judicial authorities when required by law.
Where we engage processors, we do so under written agreements that include confidentiality, security, and data protection obligations as required by the GDPR.
International Data Transfers
We seek to use providers located in the European Union/European Economic Area whenever possible. If personal data is transferred outside the EU/EEA, we implement appropriate safeguards such as European Commission Standard Contractual Clauses and, where necessary, supplementary measures. You may request a copy of applicable safeguards by contacting [email protected].
Retention Periods
- Communications and inquiry records: retained for the time necessary to handle your request and up to 24 months thereafter for follow-up and accountability, unless a longer period is required by law.
- Newsletter and marketing preferences: retained until you unsubscribe or withdraw consent; minimal logs may be kept for up to 24 months to demonstrate compliance.
- Server logs and security records: typically retained for up to 12 months unless needed longer for security, legal, or compliance purposes.
- Cookies and analytics data: retained as described in the Cookies section.
When retention is no longer necessary, data will be securely deleted or anonymized.
Security Measures
We employ appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include access controls on a need-to-know basis, encryption in transit where applicable, secure configurations, logging and monitoring, and processor due diligence. While no system can be perfectly secure, we regularly review our controls to maintain a level of security appropriate to the risk.
Your Rights
Under the GDPR and the French Data Protection Act (Loi Informatique et Libertés), you have the following rights, subject to conditions and exemptions:
- Right of access to your personal data and to obtain a copy.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure (right to be forgotten).
- Right to restriction of processing.
- Right to data portability (for data you provided to us, processed by automated means and based on consent or contract).
- Right to object to processing based on our legitimate interests, including, at any time, to direct marketing.
- Right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Right not to be subject to a decision based solely on automated processing, including profiling, producing legal or similarly significant effects (we do not engage in such decisions).
To exercise your rights, contact [email protected]. We may need to verify your identity. We aim to respond within one month, extendable by two months for complex requests. You also have the right to lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), the French Data Protection Authority.
Children’s Data
MenMed is intended for adults. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us so we can take appropriate action.
Confidentiality of Health-Related Communications
Content on MenMed is for informational purposes only and does not replace professional medical advice. Avoid sharing personal health information through our contact channels. If you choose to disclose such information, it will be processed only with your explicit consent, for the limited purpose of addressing your inquiry, and will be protected with heightened confidentiality.
Data Protection Officer
MenMed has not appointed a Data Protection Officer as it is not required to do so under current criteria. For all data protection matters, please use the contact details provided in this notice.
Changes to This Notice
We may update this notice to reflect changes in our processing or legal obligations. Material changes will be highlighted on our website. The effective date of this notice is 15 September 2025.
Contact Information
Data Controller: MenMed (Rowena Calderwood)
Postal address: 19 Rue d'Italie, 13100 Aix-en-Provence, France
Email: [email protected]