Privacy Policy
Effective date: 21 July 2026. Last updated: 21 July 2026.
All compounds catalogued by Biogenetic Research Labs Ltd are for in-vitro laboratory research only. They are not medicinal products and are not for human or veterinary use.
This policy explains what personal data Biogenetic Research Labs Ltd collects, why, on what lawful basis, who we share it with, how long we keep it, and what rights you have. It is written to meet the UK General Data Protection Regulation and the Data Protection Act 2018.
Who is responsible for your data
Biogenetic Research Labs Ltd, company number 17298432, registered office 20 Wenlock Road, London, England, N1 7GU, is the data controller.
We have not appointed a Data Protection Officer, because we are not required to. Data protection questions go to hello@protocolpeptides.co.uk.
We are in the process of registering with the Information Commissioner’s Office, and will publish our registration number here before launch.
What we collect
- Identity and contact data. Name, email address, telephone number, delivery address, billing address, and the name of the organisation where you give one.
- Account data. Login credentials in hashed form, order history, saved addresses, communication preferences, and the date of your last activity.
- Order and transaction data. What you ordered, when, the price, delivery method, tracking reference, and the batch numbers dispatched to you.
- Payment data. Card payments are processed by our payment provider. We receive the outcome, the last four digits, the card type and the billing address. We never receive or store your full card number, expiry date or security code.
- Compliance data. The age confirmation and research-use confirmation you give at the gate and at checkout, with the date, time and a truncated IP address. We hold this because it is the evidence that the confirmation was given.
- Cookie consent data. Your cookie choices, the time you made them, the policy version, and a random consent identifier. This record is not linked to your account.
- Technical and usage data. IP address, browser and device type, operating system, referring page, pages viewed, and interaction events.
- Communications data. Emails, contact form messages and support correspondence.
What we do not collect. We do not ask for and do not want health data, medical history, or any other special category data under Article 9 of the UK GDPR. Do not send it to us. If you send it anyway we will delete it and will not use it.
Why we use it, and our lawful basis
| What we do | Data used | Lawful basis |
|---|---|---|
| Take and fulfil your order, dispatch it, and handle returns | Identity, contact, order, payment, compliance | Article 6(1)(b), performance of a contract |
| Create and run your account | Identity, contact, account | Article 6(1)(b), performance of a contract |
| Send transactional emails: confirmation, dispatch, refund, Certificate of Analysis release, account and password | Identity, contact, order | Article 6(1)(b), performance of a contract |
| Keep records of age and research-use confirmations | Compliance | Article 6(1)(c), legal obligation, and Article 6(1)(f), legitimate interests in demonstrating a compliant listing position |
| Keep a record of your cookie choices | Cookie consent | Article 6(1)(c), legal obligation under PECR and the UK GDPR to demonstrate consent |
| Keep accounting and tax records | Identity, order, payment | Article 6(1)(c), legal obligation (Companies Act 2006, VAT Act 1994, Taxes Management Act 1970) |
| Prevent and detect fraud, and keep the site secure | Technical, order, payment outcome | Article 6(1)(f), legitimate interests in protecting the business and its users |
| Answer support enquiries | Contact, communications, order | Article 6(1)(f), legitimate interests in responding to you |
| Measure how the site is used | Technical, usage | Article 6(1)(a), consent, given through the cookie banner |
| Send research updates by email | Identity, contact | Article 6(1)(a), consent. Where you have already ordered from us we may rely on the soft opt-in in regulation 22 of PECR for similar compounds, with an unsubscribe link in every message |
| Handle a legal claim or a regulatory request | Any relevant data | Article 6(1)(c) or Article 6(1)(f) |
Who we share it with
We do not sell personal data and we do not share it for anyone else’s marketing.
We use the following categories of processor. Each is bound by a written contract meeting Article 28 of the UK GDPR.
| Purpose | Processor | Where data is processed |
|---|---|---|
| Website hosting and delivery | to be confirmed before launch | to be confirmed before launch |
| Payment processing | to be confirmed before launch | to be confirmed before launch |
| Order and catalogue platform | to be confirmed before launch | to be confirmed before launch |
| Transactional email | to be confirmed before launch | to be confirmed before launch |
| Research-updates email | to be confirmed before launch | to be confirmed before launch |
| Website analytics | to be confirmed before launch | to be confirmed before launch |
| Delivery and tracking | to be confirmed before launch | United Kingdom and destination country |
| Accounting | to be confirmed before launch | to be confirmed before launch |
We also disclose data where the law requires it, including to HMRC, Border Force, the MHRA, the police, or a court.
Sending data outside the UK
Where a processor is outside the UK, we transfer data only if the destination is covered by UK adequacy regulations, or under the ICO’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. You can ask us for a copy of the safeguard used for a specific transfer.
How long we keep it
| Record | Retention |
|---|---|
| Order, invoice and payment records | Six years from the end of the financial year in which the order was placed, for tax and accounting |
| Age and research-use confirmations | Six years, held with the order they relate to |
| Account data | While the account is open. If you do not sign in or place an order for 12 months, the account is closed and the account data is deleted or anonymised. We email you 30 days before that happens. |
| Support correspondence | Three years from the last message |
| Consent and withdrawal records for email | Until you withdraw, then 24 months, so we can prove we stopped |
| Cookie consent records | 24 months from the choice |
| Analytics data | 14 months, then deleted or aggregated |
| Server and security logs | 90 days |
| Age gate cookie | Thirty days. Age gate decline cookie: 24 hours. Neither contains an identifier |
Your rights
Under the UK GDPR you have the right to:
- Be told what we hold and get a copy of it.
- Have inaccurate data corrected.
- Have data erased, where we do not need it for a legal obligation such as tax records.
- Restrict how we use it while a question about it is resolved.
- Receive data you gave us in a portable machine readable form.
- Object to processing based on legitimate interests, and object at any time to direct marketing.
- Withdraw consent at any time, without affecting anything done before you withdrew it.
If you have an account, you can request a copy of your data, correct your details, or ask for your account and data to be erased from Your data. You can also email hello@protocolpeptides.co.uk. We respond within one month. There is no charge. We may ask you to confirm your identity first.
Where we cannot erase everything, we tell you exactly what we are keeping and why. Order, invoice and compliance records are kept for six years because tax law and our regulatory position require it; the rest is deleted.
Automated decisions
We do not make decisions about you by automated means alone that produce a legal or similarly significant effect. Our payment provider runs automated fraud screening on transactions, which can result in a payment being declined. If that happens you can contact us and we will look at it manually.
Security
The site is served over TLS. Passwords are stored hashed and salted. Access to order and personal data is restricted to named personnel and is logged. Payment card data never reaches our systems. We keep a record of security incidents and will notify the ICO within 72 hours, and you without undue delay, where a breach meets the threshold in Articles 33 and 34.
Cookies
Cookies and similar technologies are covered in full in our Cookie Policy. You can change your choices at any time from Cookie Settings in the footer.
Research use
All compounds catalogued by Biogenetic Research Labs Ltd are for in-vitro laboratory research only. They are not medicinal products, are not for human or veterinary use, and are not intended for diagnosis or treatment. Nothing you send us about your intended research constitutes health data about you, and you should not send us health information about yourself or anyone else.
Complaining to the regulator
If you are not satisfied with how we have handled your data you can complain to the Information Commissioner’s Office.
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
We would prefer the chance to put it right first. Email hello@protocolpeptides.co.uk.
Changes to this policy
We update this policy when our processing changes. The effective date is at the top of this page. Where a change is significant we tell account holders by email.