Privacy Policy

For solarayeurope.com and UK online sales 


Last Updated: August 26, 2026

Introduction


Healthway INT LTD (formerly NU U Nutrition LTD) respects your privacy and is committed to protecting your personal data. Healthway INT Ltd. is the UK controller for customer information collected through the Solaray Europe UK website. We use trusted service providers to operate the store, including a UK fulfilment provider, and authorised personnel at our U.S. parent company may securely access systems to support customer service, IT, security, finance, legal, compliance, and business operations. International access is protected by approved contractual safeguards and security measures. 

Privacy contact: privacy@nutracorp.com 

HEALTHWAY INT LTD. (formerly NU U NUTRITION LTD)

Unit 1 Platinum Road, Manchester, United Kingdom, M41 7LJ

Registration # 08855609

 

1. Who we are and what this policy covers 

This policy explains how Healthway INT Ltd. (formerly NU U Nutrition Ltd.), trading as Solaray ("Healthway", "we", "us" or "our"), collects and uses personal data when you visit solarayeurope.com, create an account, buy products for delivery in the United Kingdom, contact us, submit a review, join or receive marketing, or otherwise interact with our UK online store. 

Healthway INT Ltd. is the controller responsible for the personal data described in this policy. Solaray is a brand used by the Nutraceutical Corporation group. Other group companies and service providers may process personal data for us as described below, but this does not change Healthway’s responsibility for the UK website processing it controls. 

This policy should be read with our Terms of Service, Returns/Refund Policy, Shipping Policy, and Cookie Policy. Where we collect information for a specific purpose, we may also provide a shorter notice at the point of collection. 

2. Key points 

  • Orders: we use identity, contact, payment-status, order, and delivery information to accept payment, fulfil and deliver orders, manage returns, and provide customer service. 
  • UK fulfilment: our UK-based fulfilment provider processes order and delivery information on our instructions for warehousing, packing, shipping, delivery, returns, and related support. 
  • U.S. group access: authorised personnel at Nutraceutical Corporation in the United States may have controlled remote access to ecommerce, order-management, customer-support, and related systems to help operate, secure, and support the business. 
  • International safeguards: UK-to-U.S. access is treated as an international transfer and is protected through an intercompany transfer agreement, the UK Addendum to the EU Standard Contractual Clauses where required, a transfer risk assessment, and supplementary security measures. 
  • Marketing and cookies: we send electronic marketing only where permitted by law and provide opt-out controls. Non-essential cookies and similar technologies are used only in accordance with your consent choices and our Cookie Policy. 
  • Your rights: UK data-protection law may give you rights of access, correction, erasure, restriction, objection, portability, withdrawal of consent, and complaint to the Information Commissioner’s Office. 

3. Personal data we collect 

Category 

Examples 

Identity and account data 

Name, title, username or account identifier, password or authentication information, and account preferences. 

Contact data 

Billing and delivery address, email address, telephone number, and delivery-contact details. 

Order and transaction data 

Products ordered, quantities, order number, purchase and return history, discounts, refund information, transaction identifiers, payment status, and amounts paid. We do not intend to receive or store full payment-card details when payment is handled by our payment provider. 

Delivery and fulfilment data 

Recipient name, delivery address, delivery instructions, carrier, tracking number, delivery status, failed-delivery information, and return information. 

Communications and support data 

Emails, messages, calls, enquiries, complaints, feedback, reviews, and records of how we respond. 

Technical and usage data 

IP address, device and browser information, timestamps, security logs, pages viewed, interactions, referral information, and cookie or similar-technology identifiers. 

Marketing data 

Marketing choices, consent records, opt-outs, campaign interactions, and preferences. 

Fraud and security data 

Information used to authenticate users, detect suspicious activity, prevent fraud, protect systems, and investigate incidents. 

Product-safety information 

Information you choose to provide about a product complaint or adverse event. This may include health information where necessary to investigate, respond, and meet safety or regulatory obligations. 

Derived and aggregated data 

Segments, trends, statistics, or insights derived from the data above. We treat derived information as personal data if it can identify you; properly anonymised information is not personal data. 

 

We do not intentionally collect criminal-offence data through the website. Please do not provide special-category data unless it is necessary for a product-safety report, complaint, or another purpose we have specifically requested. 

4. How we collect personal data 

  • Directly from you when you browse, register, order, contact us, request support, submit a review, make a return, report a product concern, or choose marketing preferences. 
  • Automatically from your browser or device through server logs, cookies, pixels, tags, and similar technologies, subject to applicable consent requirements. 
  • From service providers, including payment, ecommerce, fulfilment, delivery, customer-support, security, analytics, and marketing providers. 
  • From our group companies where necessary to operate, support, secure, administer, or oversee the UK ecommerce business. 
  • From publicly available sources or authorities where lawful and relevant, for example to prevent fraud or comply with legal obligations. 

5. How and why we use personal data 

The table below describes our principal processing activities. More than one lawful basis may apply depending on the circumstances. 

Purpose 

Data used 

Lawful basis 

Create and manage your account 

Identity, contact, account, technical, and security data. 

Performance of a contract; legitimate interests in account administration and security. 

Process payment and complete your purchase 

Identity, contact, order, transaction, payment-status, technical, and fraud data. 

Performance of a contract; legitimate interests in fraud prevention and payment administration; legal obligation where applicable. 

Fulfil, ship, deliver, and manage returns 

Identity, contact, order, delivery, transaction, and communications data. 

Performance of a contract; legitimate interests in logistics, service quality, and resolving delivery issues. 

Provide customer service and respond to enquiries 

Identity, contact, order, delivery, account, and communications data. 

Performance of a contract; legitimate interests in customer service and relationship management. 

Handle product complaints, adverse events, recalls, and safety matters 

Identity, contact, order, communications, and relevant product-safety or health information. 

Legal obligation; substantial public interest or other applicable condition for special-category data; legitimate interests in product safety and legal claims. Where required, consent. 

Operate, maintain, troubleshoot, and secure the website and systems 

Identity, account, technical, usage, fraud, security, order, and transaction data. 

Legitimate interests in secure and reliable operations, fraud prevention, business continuity, and improving services; legal obligation where applicable. 

Keep records, manage tax/accounting, and establish or defend legal claims 

Identity, contact, order, transaction, delivery, communications, and security data. 

Legal obligation; legitimate interests in governance, audit, compliance, debt recovery, and legal claims. 

Improve products, website, and customer experience 

Usage, technical, order, communications, review, and aggregated data. 

Legitimate interests in improving the business and services; consent where required for non-essential cookies or tracking. 

Send service communications 

Identity, contact, account, order, delivery, and communications data. 

Performance of a contract; legal obligation; legitimate interests in administering the customer relationship. 

Send marketing and measure marketing performance 

Identity, contact, marketing, order, usage, and technical data. 

Consent where required; otherwise legitimate interests where the UK electronic-marketing rules permit, including any applicable existing-customer exception. You may opt out at any time. 

Business transactions and reorganisation 

Relevant categories necessary for due diligence, negotiation, completion, and transition. 

Legitimate interests in managing a sale, acquisition, financing, restructuring, or transfer; legal obligation where applicable. 

 

6. Marketing 

We may send you marketing about Solaray Europe products and offers where you have consented or where applicable law otherwise permits. When relying on an existing-customer exception, we will use contact details obtained in connection with a sale or genuine sales enquiry, market our own similar products or services, and provide a clear opportunity to opt out when details are collected and in each message. 

You can opt out at any time by using the unsubscribe link in a marketing message, changing available account preferences, or contacting us. Opting out of marketing does not stop operational messages about an order, account, product-safety matter, or other service you requested. 

We do not sell your personal data. We do not allow our processors to use it for their own advertising or unrelated purposes. If our advertising practices materially change, we will update this policy and obtain consent where required. 

7. Cookies and similar technologies 

We use cookies and similar technologies to operate the website, keep the shopping basket and checkout functioning, maintain security, remember choices, understand use of the website, and support advertising or marketing where enabled. Except where a technology is strictly necessary or another legal exemption applies, we will not place or access it until you have made the required consent choice. 

Our cookie banner and Cookie Policy, located at the end of this Privacy Policy, identify the technologies in use, their purposes, providers, duration, and whether information is transferred internationally. You can change or withdraw your choices using the cookie-preference control on the website. Withdrawing consent does not affect processing that occurred before withdrawal. 

8. How we share personal data 

We share personal data only where necessary for the purposes described in this policy, subject to appropriate contracts, access controls, and confidentiality obligations. 

Recipient 

Role and purpose 

Typical data 

UK fulfilment provider (currently Fulfilment Crowd) 

Processor acting on our instructions for warehousing, inventory administration, picking, packing, shipping, delivery coordination, returns, and related fulfilment support. 

Name, contact details, order, delivery, tracking, return, and related communications data. 

Carriers and delivery partners 

Independent controller or processor depending on the service and law, for transport, tracking, delivery, customs where applicable, and resolving delivery issues. 

Recipient name, address, contact details, delivery instructions, order reference, and tracking information. 

Payment and fraud-prevention providers 

Usually independent controllers or processors for authorisation, payment, refunds, chargebacks, fraud screening, and compliance. 

Identity, contact, transaction, device, fraud, and payment information handled directly by the provider. 

Ecommerce, hosting, IT, security, communications, and customer-support providers 

Processors supporting the website, accounts, infrastructure, authentication, security, communications, and support. 

Relevant identity, contact, account, order, communications, technical, usage, and security data. 

Nutraceutical Corporation and authorised U.S.-based personnel 

Group service provider and, for limited activities, a separate controller. Supports Shopify and order-management administration, customer service, IT, security, finance, legal, compliance, management, and business operations. 

Names, contact details, billing and shipping addresses, order and delivery data, transaction identifiers/status, customer communications, technical and security data. 

Professional advisers, insurers, auditors, banks, and authorities 

Independent controllers or processors for advice, audit, insurance, financing, legal claims, regulatory reporting, and compliance with lawful requests. 

Only the data reasonably necessary for the relevant purpose. 

Transaction counterparties 

Potential or actual buyers, sellers, lenders, investors, and advisers in a corporate transaction or reorganisation. 

Only information reasonably necessary, ordinarily subject to confidentiality and data-minimisation controls. 

 

Our processors may not use personal data for their own purposes. They may process it only on documented instructions, must protect it, and must assist us with applicable data-protection obligations. Some recipients, such as payment providers, carriers, professional advisers, or authorities, may determine their own purposes and means of processing and therefore act as independent controllers. 

9. UK fulfilment and delivery processing 

To complete your order, we disclose the minimum information reasonably needed to our UK fulfilment provider and relevant carriers. The fulfilment provider acts as our processor for the contracted services and is required to: 

  • process personal data only on our documented instructions and only to provide the fulfilment services; 
  • limit access to authorised personnel with a need to know and confidentiality obligations; 
  • maintain appropriate technical, organisational, and physical security measures; 
  • assist with data-subject requests, incidents, audits, impact assessments, and regulatory obligations; 
  • use approved subprocessors under equivalent data-protection obligations; and 
  • return or securely delete personal data when the services end, unless law requires retention. 

Carriers may receive delivery information from the fulfilment provider. Their own privacy notices may apply where they act as independent controllers for transport or legal purposes. 

10. International data transfers and U.S. group access 

The UK website is operated by a UK company, but authorised personnel at Nutraceutical Corporation, our U.S. parent company, may remotely access personal data in Shopify, order-management, customer-support, and related systems. This access supports customer service, IT, security, finance, legal, compliance, management, and other documented group operations. Remote access from the United States is treated as an international transfer where UK data-protection law requires. 

For UK-to-U.S. restricted transfers, we use an intercompany data-transfer agreement incorporating or supported by the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses, as applicable. We also assess transfer risks and apply supplementary measures designed to protect the data. These measures include: 

  • role-based access and least privilege; 
  • multi-factor authentication for material administrative and remote access; 
  • encryption in transit and at rest where appropriate; 
  • centralised identity controls and timely access revocation; 
  • logging, monitoring, endpoint protection, vulnerability management, backup, and incident response; 
  • confidentiality commitments and privacy and security training; 
  • onward-transfer restrictions and vendor oversight; and 
  • procedures for government-access requests, including notice where lawful, review, challenge or narrowing where appropriate, and disclosure minimisation. 

We may also use providers in other countries. Before making a restricted transfer, we use an applicable adequacy regulation or approved safeguard and complete any assessment required by law. You may contact us for information about the safeguard used for a particular transfer. We may provide a summary or redacted copy where necessary to protect commercial or security information. 

11. Data security 

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures are selected according to the nature of the data and processing risks and include access controls, authentication, encryption where appropriate, monitoring, secure configuration, incident response, business continuity, personnel confidentiality, training, and supplier oversight. 

No internet transmission or storage system is completely secure. If a personal-data breach occurs, we will investigate, mitigate, document, and notify the Information Commissioner’s Office and affected individuals where required by law. 

12. Data retention 

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including to complete orders, provide support, meet legal, tax, accounting, product-safety and regulatory requirements, resolve disputes, prevent fraud, enforce agreements, and establish or defend legal claims. We determine retention by considering the amount, nature and sensitivity of the data, risk of harm, purpose, available alternatives, and applicable legal requirements. 

Record type 

Retention approach 

Account data 

For the life of the account and then for the period reasonably required for closure, fraud prevention, disputes, and legal obligations. 

Orders, payments, refunds, tax and accounting records 

For the period required by applicable tax, accounting, consumer, and limitation laws and our documented retention schedule. 

Delivery, return, and customer-support records 

For as long as needed to complete service, resolve issues, monitor performance, and address complaints or claims. 

Product complaints and adverse-event records 

For the period required by applicable product-safety, regulatory, quality, pharmacovigilance or vigilance, and limitation requirements. 

Marketing records 

Until you opt out or consent is withdrawn, plus a limited suppression record so we can honour the choice. 

Cookie and consent records 

For the period shown in the Cookie Policy or needed to demonstrate and manage consent choices. 

Security logs and incident records 

For a risk-based period needed to protect systems, investigate events, and meet legal or audit requirements. 

 

When data is no longer needed, we delete it, anonymise it, or isolate it until secure deletion is possible. Properly anonymised data may be retained and used without further notice because it no longer identifies an individual. 

13. Your UK data-protection rights 

Depending on the circumstances, you may have the right to: 

  • ask for access to your personal data and information about how it is used; 
  • ask us to correct inaccurate or incomplete personal data; 
  • ask for erasure where there is no lawful reason for continued processing; 
  • ask us to restrict processing in specified circumstances; 
  • object to processing based on legitimate interests and object at any time to direct marketing; 
  • receive certain personal data in a structured, commonly used, machine-readable format and ask us to transmit it to another organisation where technically feasible; 
  • withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing; and 
  • complain to the Information Commissioner’s Office. 

To exercise a right, email privacy@nutracorp.com with the subject line “UK Privacy Rights”. You may also write to the address in section 17. Please note that, where permitted under applicable law, we may decline a request if we are unable to verify your identity (or an agent’s authority to make the request) and confirm the personal information we maintain relates to you. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. 

We aim to respond within the period required by law. If a request is complex or numerous, the law may permit an extension; if so, we will explain the extension. 

14. Children 

The website and products are intended for adults and are not directed to children under 18 years of age. We do not knowingly collect personal data from children through the website. If you are under 18, do not use or provide any information on this website or through its features, including interactive or public comment features, or provide any information about yourself to us, including your name, address, telephone number, email address, screen name, or user name. If we learn we have collected or received personal information from a child under 18 without verified parental consent, we will delete that information. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action. 

15. Third-party links and services 

The website may contain links to third-party websites, plug-ins, social-media features, or services. Those third parties may collect or receive personal data under their own privacy notices. We do not control their independent processing. Please review their notices before providing personal data or enabling a connection. 

16. Changes to this policy 

We review this policy periodically and may update it to reflect changes in law, technology, services, or processing. We will notify you of any changes by posting the new Privacy Policy on this page. If there are material changes to this Privacy Policy, we will let you know via email and/or a prominent notice on our Site, prior to the change becoming effective and update the date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

17. Cookies

As you navigate through and interact with our website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               

·       Details of your visits to our website, including traffic data, location data, logs, and other communication data and the resources that you access and use on the website.

·       Information about your computer and internet connection, including your IP address, operating system, and browser type.

The information we collect may include personal information, or we may maintain it or associate it with personal information we collect in other ways or receive from third parties. It helps us to improve our website and to deliver a better and more personalized service, including by enabling us to:

·       Estimate our audience size and usage patterns.

·       Store information about your preferences, allowing us to customize our website according to your individual interests.

·       Speed up your searches.

·       Recognize you when you return to our website.

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see Cookie policy

In addition, some content or applications on the website may be served by third-parties, including advertisers, ad networks and servers, content providers, and application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our website. The information they collect may be associated with your personal data or they may collect information, including personal data, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.

We do not control these third parties' tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly as they may provide you with ways to choose not to have your information collected or used in this way. If you are based in the European Union you may visit the website of the European Interactive Digital Advertising Alliance (“EIDAA”) at https://www.edaa.eu as well as of the European Advertising Standards Alliance (“EASA”) at http://www.easa-alliance.org.

18. Contact us and complaints 

Controller: Healthway INT Ltd. (formerly NU U Nutrition Ltd.), trading as Solaray  

Unit 1 Platinum Road, Manchester, United Kingdom, M41 7LJ 

Registration # 08855609 

Privacy contact: Chief Compliance Officer 

Email: privacy@nutracorp.com 

Customer service and product enquiries: customerservice@solarayeurope.com 

You may complain to the UK Information Commissioner’s Office. Current contact methods are available on the ICO website. 

We would appreciate the opportunity to address your concern first, but you are not required to contact us before approaching the ICO.