This Privacy Policy explains how PeptideX processes personal data when you visit our website, create an account, place an order, or contact us.
1. Controller
PeptideX is a trade name of XXXXXXXXXXXXXXXXXXX B.V., registered in The Netherlands.
Full company details are available in the Legal Notice on this website.
For privacy-related questions or requests, you can contact us at:
Email: [email protected]
2. Scope
This Privacy Policy applies to all visitors, customers, and users of the PeptideX website within the Benelux and the European Union.
3. Personal data we process
Depending on your interaction with our website, we may process the following categories of personal data:
- Identification data such as name and company name
- Contact details such as email address and billing or shipping address
- Order, invoice, and transaction data
- Payment-related identifiers provided by payment service providers
- Account information if you create an account
- Communication data when you contact us
- Technical data such as IP address, browser type, device information, and log data
PeptideX does not intentionally process special categories of personal data as defined under the GDPR.
4. Purposes of processing
Personal data is processed for the following purposes:
- Processing and fulfilling orders
- Handling payments, invoicing, and refunds
- Customer communication and support
- Account creation and administration
- Compliance with legal, tax, and accounting obligations
- Fraud prevention, security, and abuse detection
- Maintaining and improving website functionality
5. Legal basis
Personal data is processed on one or more of the following legal grounds:
- Performance of a contract
- Compliance with legal obligations
- Legitimate interests, such as security and operational continuity
- Consent, where required by applicable law
6. Payment processing
Payments are handled through third-party payment service providers. PeptideX does not store full payment card details.
Payment service providers process personal data in accordance with their own privacy policies and applicable laws.
7. Cookies and similar technologies
PeptideX uses cookies and similar technologies to ensure proper website functionality and to collect privacy-friendly analytical insights.
Where required by law, consent is requested before placing non-essential cookies. More information is available in our Cookie Policy.
8. Sharing of personal data
Personal data is shared only with third parties that are necessary to operate the website and fulfill orders, such as:
- Payment service providers
- Shipping and logistics partners
- Hosting, security, and IT service providers
Personal data is not sold or shared for marketing or advertising purposes.
9. Data retention
PeptideX retains personal data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law.
The following retention periods apply:
- Customer accounts
Inactive customer accounts are retained for up to 24 months after the last activity, after which they may be anonymized or deleted, unless retention is required for legal or administrative reasons. - Pending and failed orders
Personal data related to pending or failed orders is retained for up to 7 days, after which it may be removed or anonymized. - Cancelled orders
Personal data related to cancelled orders is retained for up to 12 months to handle inquiries, disputes, and administrative checks. - Completed and refunded orders
Personal data related to completed and refunded orders is retained for up to 7 years, in accordance with applicable tax, accounting, and legal obligations.
Where personal data must be retained to comply with legal obligations, it will not be erased upon request until the legally required retention period has expired.
10. Your rights
Under applicable data protection laws, you have the right to:
- Access your personal data
- Request correction of inaccurate or incomplete data
- Request deletion of personal data, where legally permitted
- Request restriction of processing
- Object to processing based on legitimate interests
- Request data portability
- Withdraw consent, where processing is based on consent
Requests can be submitted using the contact details above. Identity verification may be required.
11. Security
PeptideX implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or misuse.
12. Third-party content
The website may contain embedded content from third-party services. Such content is governed by the privacy policies of the respective third parties.
13. International data transfers
Where personal data is processed outside the European Economic Area, appropriate safeguards are applied in accordance with applicable data protection laws.
14. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time. The version published on the website is the applicable version.
15. Complaints
If you believe that your personal data is processed unlawfully, you have the right to lodge a complaint with the competent data protection authority.
