Free shipping over €250 — dispatched the next business day, tracked across the EU, with a lot-matched COA.

en

Policy

Privacy policy

We only collect what we need to process an order, reply to an enquiry and keep the site running. Below we explain precisely what that involves under the EU General Data Protection Regulation (GDPR), including the cookies and browser storage in use.

Controller

[TODO: client — registered company name and legal form], trading as Peptide Medix EU, [TODO: client — registered office address in the EU], registration number [TODO: client — company registration number and register], is the controller of your personal data. Please send any privacy question or request to info@peptidemedixeu.com.

Data protection officer: [TODO: client — name and contact of the data protection officer, or state that none is required under Art. 37 GDPR].

Data we collect

  • Order data — your name, email address, phone number, organisation, VAT ID, billing and delivery addresses, the items ordered and your confirmation of research use.
  • Enquiry data — the content you enter in the contact form, the email address you provide for our reply, and your confirmation of consent.
  • Account data — only if you open an account: name, email address, organisation, saved address and a hashed password. Your password is never kept in readable form.
  • Technical data — IP address, browser user agent and request data, which our hosting provider processes to deliver and protect the site and which we store alongside order and enquiry records to prevent fraud and misuse.

This site does not collect payment card details: card data is never entered, processed or stored here, and invoices with payment instructions are sent separately. We do not knowingly process special categories of personal data or data relating to anyone under 18.

Purposes of use

We use your data to carry out orders, reply to enquiries, issue invoices and documents, operate your account, protect the site and comply with the record-keeping duties that come with supplying research reagents. We never sell personal data, never use it to create advertising profiles and never take automated decisions producing legal or similarly significant effects for you.

PurposeLegal basis under the GDPR
Handling orders, invoices, delivery, returns, requests for documents and your accountPerforming a contract or taking steps before entering one — Art. 6(1)(b)
Replying to contact enquiriesSteps before entering a contract — Art. 6(1)(b); our legitimate interest in replying — Art. 6(1)(f)
Checking VAT IDs and buyer eligibilityLegal obligation — Art. 6(1)(c); legitimate interest in supplying lawfully — Art. 6(1)(f)
Keeping accounting and tax recordsLegal obligation — Art. 6(1)(c)
Protecting the site and preventing fraud and spamLegitimate interest in running a secure service — Art. 6(1)(f)
Optional analytics (only if added in the future)Consent — Art. 6(1)(a), which you may withdraw at any time

Recipients

  • Infrastructure providers — the site is hosted on Cloudflare, which handles requests and stores site data (orders, enquiries and accounts) for us.
  • Email provider — [TODO: client — email / helpdesk provider, e.g. Google Workspace], through which we correspond with you.
  • Carriers — the delivery address and contact information required to deliver a parcel ([TODO: client — carriers used, e.g. DHL, DPD, GLS]).
  • Banks and payment providers — so that payments can be received and matched to invoices.
  • Professional advisers and public authorities — accountants and auditors for statutory duties, and authorities wherever the law obliges us to disclose data.

Our service providers act on our behalf under a data processing agreement (Art. 28 GDPR). If a provider transfers data outside the European Economic Area, the transfer is based on an adequacy decision — such as the EU–US Data Privacy Framework for certified recipients — or on the European Commission's Standard Contractual Clauses. There are no other recipients: your details are never passed to marketing networks or data brokers.

Cookies and browser storage

We set no advertising, analytics or third-party tracking cookies. The only storage used is what is strictly necessary for a service you have requested, which does not need consent under the EU ePrivacy rules:

NameTypePurposeDuration
pe_cart_v1Local storageHolds your basket as you move between pages; it only reaches us when you place an order.Until you clear it or place an order
pe_localeLocal storageStores the language you selected.Until you clear it
pe_cookie_consentLocal storageRecords that the cookie notice has been shown to you.Until you clear it
pe_last_order, pe_ovr_v1Session storageDisplays your order confirmation and caches current prices.Until the tab is closed
Account session cookieCookie (HttpOnly)Keeps you logged in to your customer account. It is set only when you log in and contains an opaque identifier that we can revoke on the server.Session / until you log out
__cf_bm, cf_clearanceCookie (Cloudflare)Can be set by our hosting provider to tell people from bots and protect the site.30 minutes to 1 year

Should we ever add analytics, it would run only with your consent, and this page would be updated beforehand. You can reopen the notice at any time through “Cookie settings” in the footer, and you can remove cookies and local storage in your browser settings — bear in mind that clearing local storage also empties your basket.

How long we keep data

DataRetention period
Orders, invoices and correspondence about themAs commercial and tax law requires, usually 10 years [TODO: client — confirm statutory period for [TODO: client — EU member state of registration]]
Contact enquiriesNo longer than 24 months after the exchange has ended
Account dataUntil you ask us to delete your account (after which order records are kept only as far as the law requires)
IP address and user agent stored with orders and enquiriesNo longer than 12 months
Hosting and security logsIn line with Cloudflare's retention periods, usually a few days

Data we no longer need is deleted or anonymised.

Your rights

The GDPR gives you the right to see the personal data we hold on you (Art. 15), to have it rectified (Art. 16) or erased (Art. 17), to restrict processing (Art. 18) or object to it (Art. 21), to receive your data in a portable format (Art. 20), and to withdraw consent at any time without affecting processing carried out before (Art. 7(3)).

Send us an email and we will deal with your request within one month, free of charge and without making it difficult for you — although we may ask you to confirm your identity. You may also complain to a data protection supervisory authority, particularly in the member state where you live or work. Our lead supervisory authority is [TODO: client — lead data protection supervisory authority].

Security measures

All traffic uses HTTPS. Passwords are saved as PBKDF2-SHA256 hashes with an individual random salt for each user, so neither we nor anyone who got hold of the database could read them. Sessions are held on the server, allowing us to revoke them, and administrative access is limited.

No system can be completely secure. If you think you have discovered a vulnerability on this site, please let us know before making it public, and we will work with you to fix it.

Contact

For privacy questions and data requests: info@peptidemedixeu.com. We revise this policy whenever our processing changes, and the date on this page shows the latest revision.