Privacy Policy — Peptigen Labs
British research laboratory supplier • Same-day UK dispatch before 14:00 • Independently purity tested • Tracked next-day delivery • For research use onlyBritish research laboratory supplier • Same-day UK dispatch before 14:00 • Independently purity tested • Tracked next-day delivery • For research use onlyBritish research laboratory supplier • Same-day UK dispatch before 14:00 • Independently purity tested • Tracked next-day delivery • For research use onlyBritish research laboratory supplier • Same-day UK dispatch before 14:00 • Independently purity tested • Tracked next-day delivery • For research use onlyBritish research laboratory supplier • Same-day UK dispatch before 14:00 • Independently purity tested • Tracked next-day delivery • For research use onlyBritish research laboratory supplier • Same-day UK dispatch before 14:00 • Independently purity tested • Tracked next-day delivery • For research use only
HOME/LEGAL
// Legal & Policies

Privacy Policy

UK GDPR · Data Protection Act 2018 · Last updated February 2026 (v2 — card payments)

1. Data Controller

Peptigen Labs Ltd ("we", "us", "our"), trading as Peptigen Labs at peptigenlabs.co.uk, is the data controller for personal information collected through the Website. You can contact us at info@peptigenlabs.co.uk.

2. Information We Collect

Order data: name, billing address, delivery address, email, phone number, organisation / institution, order history, chosen delivery option and any research-use acknowledgement ticked.

Account data (if you create a Lab Access account): email, hashed password, name, associated orders.

Communications: any message you send via the contact form, email or phone, and our reply.

Newsletter: email and (optionally) name, if you opt in.

Technical data: IP address, device / browser identifiers, referring page, pages visited, and (with consent) analytics cookies to help us improve the Website.

Payment data — bank transfer: where you pay by UK bank transfer, authorisation occurs entirely within your own bank's secure environment. We do NOT collect, see, transmit or store your online-banking credentials, passcode, biometric data or one-time-password. We do receive a bank-side payment reference, the masked sender account / sort code and a confirmation of cleared funds.

Payment data — card: where you pay by debit or credit card, your card number, expiry and CVV are transmitted over TLS to our server, encrypted using AES-256, and forwarded directly to our PCI-DSS compliant card payment service provider (Global Pay Limited) for authorisation. Raw card details are NOT persisted, written to disk, logged, retained on our systems or shared beyond our card processor. We retain only the card last-four digits, card brand (e.g. "VISA •••• 4242"), the gateway transaction reference and the authentication result, in each case to support receipting, refunds, chargeback evidence and fraud screening for the legal-retention period applicable to financial records.

Fraud-screening data: where required to assess transaction risk we may also process the IP address from which the Order was placed, browser/device fingerprint, AVS / 3DS authentication result, and the velocity of recent Orders associated with the same customer, card, IP or shipping address.

3. Lawful Basis

Contract necessity (UK GDPR Article 6(1)(b)) — to take and fulfil Orders, provide Lab Access, respond to enquiries.

Legal obligation (Article 6(1)(c)) — to retain order / accounting records, respond to lawful requests.

Consent (Article 6(1)(a)) — marketing emails and non-essential analytics cookies. Withdrawable at any time.

Legitimate interests (Article 6(1)(f)) — fraud prevention, security of the Website, defending legal claims, and running our business.

4. Retention

Order and accounting records: 6 years from the end of the financial year in which the Order was placed (UK HMRC / Companies House requirement).

Lab Access accounts: until deletion is requested or 3 years of inactivity.

Contact form messages: up to 24 months after the matter closes.

Newsletter records: until you unsubscribe.

Server / security logs: up to 12 months.

5. Sharing

Order data is shared, strictly to fulfil your Order or to comply with our legal obligations, with: (a) our UK courier partners (e.g. Royal Mail, DPD or equivalent) for label generation and tracked delivery; (b) Fena Money Ltd, our FCA-authorised Open Banking provider, where you pay by bank transfer; (c) Global Pay Limited (and/or any successor card processor we appoint), our PCI-DSS compliant card payment service provider, where you pay by debit or credit card; (d) Resend.com (Resend, Inc.), our email service provider, for order confirmation and dispatch notifications; (e) Meta Platforms Ireland Ltd, where you have consented to advertising cookies, solely for advertising conversion measurement; and (f) our cloud hosting providers (data processors) under written data processing agreements.

Where a chargeback, dispute or fraud investigation arises, we may additionally share transaction, communication, device and authentication evidence with the relevant card scheme (Visa / Mastercard / American Express), our acquiring bank, and (where there is a reasonable suspicion of fraud) the National Fraud Intelligence Bureau (Action Fraud) and Cifas. Such sharing is undertaken under the legitimate-interests lawful basis (UK GDPR Art. 6(1)(f) — prevention of fraud).

We may disclose data where required by law, court order, lawful request from a regulator, or to protect the rights, property or safety of Peptigen Labs, our customers or others.

We do NOT sell your personal data. We do NOT share it with third parties for their own marketing.

6. International Transfers

We store data primarily within the UK / EEA. Where any processor operates servers outside the UK / EEA, transfers are protected by an appropriate safeguard (UK International Data Transfer Addendum, adequacy regulations or standard contractual clauses).

7. Your Rights

Under UK GDPR you have rights to: access, rectification, erasure (subject to our retention obligations), restriction, objection, portability, and to withdraw consent at any time.

To exercise any right, email info@peptigenlabs.co.uk. We will respond within one calendar month. You may need to verify your identity.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

We implement appropriate technical and organisational measures to protect personal data, including TLS encryption in transit, hashed passwords, access controls, principle of least privilege, regular backups and audit logging. No system can be 100% secure; you are responsible for keeping your Lab Access credentials confidential.

9. Children

The Website is strictly for qualified researchers and laboratory buyers aged 18+. We do not knowingly collect data from children. If you believe a child has provided personal data, please contact us immediately and we will delete it.

10. Cookies

See our Cookie Policy for details.

11. Changes

We may update this Privacy Policy from time to time. The "last updated" date at the top of the policy shows when it was last revised.

Need help? Get in touch with our UK team.

Contact Peptigen Labs