Privacy Policy
This policy applies to qualified business and laboratory contacts. PeptideQC Global does not intentionally offer products or services to consumers or children.
1. Controller
Metatron Marketing Ltd., Company No. 16220417, Monomark House, 27 Old Gloucester Street, London, England, WC1N 3AX. Contact: Ingmar@metatron-marketing.com.
2. Data we process
We process organization and contact details, work email, research category, intended-use statement, requested quantity, account qualification and compliance records, communications, order/payment/invoice metadata, shipping information, and technical security logs. We do not request patient, health, dosing or self-use data.
3. Purposes and legal bases
- Responding to inquiries and pre-contract qualification: UK GDPR/GDPR Art. 6(1)(b).
- Research-use, sanctions, fraud, diversion and jurisdiction controls: Art. 6(1)(c) where legally required and Art. 6(1)(f), our legitimate interests in safe and lawful B2B trade.
- Orders, invoices, tax and accounting: Art. 6(1)(b) and (c).
- Site security, abuse prevention and privacy-preserving aggregate traffic measurement: Art. 6(1)(f). Aggregate marketing metrics do not retain raw IP addresses and do not require cookies.
- Targeted business-to-business editorial or commercial communications to relevant professional contacts: Art. 6(1)(f), our legitimate interest in presenting relevant research-supply information. Contacts may come from public corporate sources, which are identified in the first message. We do not use this basis where local law requires prior consent, and every message provides a direct right to object.
- Optional client-side analytics, marketing cookies or other consent-based communications: Art. 6(1)(a), consent.
4. Recipients and processors
Data may be shared only as necessary with hosting and IT providers, CRM/communications providers, payment processors such as Stripe when enabled, professional advisers, laboratories/document providers, carriers and fulfillment providers, and competent authorities. Each recipient receives only the data needed for its role.
5. International transfers
Where data moves between the UK, EEA or other countries, we use an applicable adequacy decision or approved safeguards such as the UK International Data Transfer Addendum or EU Standard Contractual Clauses, plus supplementary measures where appropriate.
6. Retention
Unsuccessful inquiries are normally retained for up to 24 months for qualification, safety and audit purposes. Contract, invoice and tax records are retained for the legally required period, commonly six years or longer where local law requires. Security logs are retained only as long as reasonably necessary. Targeted outreach records are normally retained for up to 24 months; a minimal suppression record may be retained longer to ensure that an objection is respected. Consent records are retained to demonstrate compliance. Legal holds override deletion schedules.
7. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You have an absolute right to object at any time to processing for direct marketing; reply “opt out” to any message or contact the controller and further outreach to that address will stop. You may withdraw consent at any time. You may complain to the UK Information Commissioner’s Office and, where the EU GDPR applies, your local supervisory authority.
8. Automated review
Inquiry data may be automatically routed for manual review based on risk indicators such as dosing, treatment, personal-use or distribution language. We do not make a solely automated decision producing legal or similarly significant effects; qualified staff make final account decisions.
9. Security and children
We use access controls, encryption in transit, logging and data minimization. No online system is risk-free. This B2B service is not directed to anyone under 18, and we do not knowingly collect children’s data.
10. Changes and contact
Material changes will be posted here with a revised effective date. Privacy requests may be sent to the controller email above.