Legal
Privacy policy
What we collect, why we collect it, who else sees it, how long we keep it, and what you can require us to do about it.
Draft prepared for review
This document was drafted as part of the site build. It has not been reviewed or approved by a licensed attorney, and it is not legal advice. It must be reviewed by qualified counsel in every jurisdiction Ethereal Peptides intends to sell into before the site goes live.
This policy explains how Ethereal Peptides handles personal information collected through this website, through orders placed on it, and through correspondence with us. It applies to visitors and buyers alike.
We collect what an order and a compliance obligation genuinely require, and not more. We do not sell personal information.
1.Who is responsible
Ethereal Peptides is the controller of the personal information described in this policy — meaning we decide what is collected and why.
Privacy enquiries, including requests to exercise the rights in section 9, should be sent through the compliance route on our contact page.
2.Information we collect
Information you give us. Name, email address, billing and delivery addresses, telephone number where provided, organisation and role where provided, order contents, the research-use acknowledgement recorded against an order, and the content of any message you send us. There are no customer accounts, so we hold no passwords or account credentials.
Information collected automatically. IP address, approximate location derived from it, browser and device characteristics, pages viewed, referring page, and timestamps, collected through server logs and our hosting provider's standard request logging.
Information from third parties. Delivery status from carriers, and where applicable the results of sanctions or restricted-party screening.
What we do not collect. We never see or store payment card numbers, bank details or any financial credential — every payment method we accept is settled outside this website, so no payment data is entered here at all. What we record against an order is that payment was received and by which method. We do not knowingly collect special category or sensitive personal data, and you should not send it to us. We do not ask about health, and health information is not a relevant category for a research-use supply relationship.
4.How we use information, and on what basis
- To perform the contract — processing and dispatching orders, taking payment, providing tracking, handling returns and answering support enquiries.
- To comply with legal obligations — tax and accounting records, sanctions screening, and retention of the research-use acknowledgement as a compliance record.
- For our legitimate interests — preventing fraud and abuse, securing the site, and enforcing our Terms of Service and compliance policies. We balance these against your interests and rights.
- With your consent — any marketing email. Consent can be withdrawn at any time, without affecting processing already carried out.
We do not use personal information for automated decision-making that produces legal or similarly significant effects. Every order is reviewed by a person before it is dispatched, because payment is confirmed manually.
6.International transfers
We and our service providers operate in more than one country, so personal information may be transferred to and processed in a jurisdiction other than your own, including the United States. Where information is transferred out of the United Kingdom or the European Economic Area, we rely on an adequacy decision where one applies, or on Standard Contractual Clauses together with any additional measures the transfer requires.
7.How long we keep it
- Order and transaction records, including the research-use acknowledgement — retained for the period required by tax, customs and regulatory law, and thereafter for as long as needed to defend legal claims.
- Account information — for as long as the account is open, and for a limited period afterwards to handle residual queries.
- Support correspondence — generally two years from the last message in the thread.
- Server logs — a short rolling window, kept for security and diagnostics.
- Marketing consent records — until consent is withdrawn, plus a record of the withdrawal itself.
When information is no longer needed it is deleted or irreversibly anonymised. Note that the compliance record attached to an order cannot be deleted on request while a legal retention obligation applies to it.
8.Security
We apply technical and organisational measures appropriate to the information we hold: encryption in transit, access limited to personnel who need it, segregation of payment handling to the processor, and logging of administrative access. No system is perfectly secure, and we do not claim otherwise. Where a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.
9.Your rights
Depending on where you are, you may have some or all of the following rights:
- Access — to obtain a copy of the personal information we hold about you;
- Rectification — to have inaccurate information corrected;
- Erasure — to have information deleted where we have no continuing basis to keep it;
- Restriction and objection — to limit or object to processing carried out on the basis of legitimate interests;
- Portability — to receive information you provided in a structured, machine-readable format;
- Withdrawal of consent — at any time, where processing relies on consent;
- Non-discrimination — we will not degrade service or pricing because you exercised a privacy right.
Requests are answered within the period the applicable law allows — one month under UK and EU data protection law, forty-five days under California law, extendable where a request is complex. We may need to verify your identity first. If you are dissatisfied with our response you may complain to your local supervisory authority.
10.Marketing
We send marketing email only where you have opted in, and every such message carries a working unsubscribe link that takes effect immediately. Transactional messages — order confirmations, dispatch and tracking notices, and replies to your own enquiries — are not marketing and continue regardless of marketing preferences.
11.Age of users
This site is intended for qualified researchers aged 21 or over. It is not directed at children, and we do not knowingly collect personal information from anyone under 21. If we learn that we have, we will delete it and close any associated account.
12.Third-party links
Product pages cite external scientific literature, and certificates may be hosted or verified by a third-party laboratory. Those sites have their own privacy practices, which we do not control and are not responsible for. This policy covers only what we do.
13.Changes to this policy
We may update this policy as our practices, our providers or the law change. The date at the head of this document reflects the current version. Where a change materially affects how we handle information already collected, we will take reasonable steps to tell you directly.
14.Contact
To exercise a right, ask a question, or raise a concern about how we handle personal information, use the compliance route on our contact page. We would rather resolve a complaint ourselves than have you take it elsewhere first, but you are entitled to do either.