Privacy Policy
1. Introduction
Genecore Laboratories ("we," "us," "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our peptide testing and verification services.
We comply with the EU General Data Protection Regulation (GDPR).
Important Note: Genecore Laboratories provides analytical testing services only. We do not endorse, sponsor, or have any affiliation with companies or products submitted for testing. Our role is strictly limited to providing independent analytical testing and verification.
2. Information We Collect
2.1 Account Information
- Name and company name
- Email address
- Phone number
- Billing and shipping address
- Password (encrypted)
2.2 Order and Sample Data
- Peptide sample information (expected peptide name, molecular weight, formula)
- Sample source and batch numbers
- Service type selected (HPLC, LC-MS, LAL, etc.)
- Order reference numbers and payment information
- Test results and analytical data
2.3 Technical Information
- IP address and browser information
- Cookies and session data
- Usage analytics and access logs
- Device and operating system information
2.4 Payment Information
Payment processing is handled by our third-party payment processor. We do not store full credit card details on our servers. Our payment processor's privacy policy governs how they handle your payment data.
3. How We Use Your Information
We use your personal data for the following purposes:
- Service Delivery: Processing orders, conducting tests, generating certificates
- Communication: Sending order confirmations, test results, and service updates
- Payment Processing: Managing payments and invoicing through our payment processor
- Quality Assurance: Maintaining test records and quality standards
- Legal Compliance: Meeting regulatory requirements and legal obligations
- Service Improvement: Analysing usage patterns to improve our platform
- Security: Protecting against fraud and unauthorised access
4. Newsletter and Marketing Communications
If you sign up for our newsletter or opt in during account registration, we may send you:
- News about new testing capabilities and services
- Exclusive offers and promotions
- Updates on peptide verification and industry insights
- Important service announcements
4.1 What We Collect
For newsletter subscriptions, we collect:
- Email address
- Subscription source (registration, footer form, or portal)
- Subscription date
- IP address (for fraud prevention)
4.2 Your Choices
- Opt-In/Opt-Out at Registration: When creating an account, you can choose whether to receive our newsletter
- Unsubscribe Link: Every marketing email includes an unsubscribe link at the bottom
- Portal Settings: Manage your email preferences anytime in your account dashboard under Settings
- Contact Us: Email info@genecorelaboratories.com to update your preference
4.3 Data Retention
Newsletter subscription data is retained while you remain subscribed. If you unsubscribe, we keep a record of your email address and unsubscribe date for 12 months to ensure we don't accidentally re-subscribe you after this is deleted.
5. Legal Basis for Processing
Under EU GDPR, we process your data based on:
- Contract Performance: Processing data necessary to provide our testing services
- Legitimate Interests: Improving services, preventing fraud, and maintaining security
- Legal Obligation: Complying with laboratory standards and record-keeping requirements
- Consent: Marketing communications (where you have opted in)
6. Data Sharing and Third Parties
As a bridging service connecting clients with testing laboratories, we may share your data with:
- Independent Laboratory Partners: Professional labs that conduct peptide testing on our behalf (under strict confidentiality agreements)
- Payment Processors: For secure payment processing
- Email Service Providers: For sending order confirmations and notifications
- Cloud Hosting: Secure servers for data storage and platform hosting
- Error & Security Monitoring: EU-hosted error tracking to detect and fix faults, configured not to collect customer personal data
- Legal Authorities: When required by law or to protect our rights
We never sell your personal data to third parties.
7. Data Retention
We retain your data for the following periods:
- Account Data: Until account deletion or 3 years of inactivity
- Order Records: 7 years (for regulatory compliance)
- Test Results: 7 years (for quality assurance and traceability)
- Certificates: Indefinitely (for public verification)
- Payment Records: 7 years (for tax and accounting purposes)
8. Your Rights Under EU GDPR
You have the following rights regarding your personal data:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data (subject to legal obligations)
- Right to Restriction: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Opt out of marketing communications at any time
To exercise any of these rights, contact us at info@genecorelaboratories.com.
9. Cookies
Genecore Laboratories uses only strictly necessary cookies. We do not use advertising, analytics, or third-party tracking cookies, and we never sell or share cookie data. Any usage statistics we keep are derived from our own server-side access logs, not from cookies or trackers.
Because these cookies are essential to operate the website and deliver the service you have requested, EU law (ePrivacy Directive) does not require us to ask for your consent to use them. They cannot be disabled without breaking core functionality such as logging in.
Your display preference (light or dark theme) is saved in your browser's local storage, not a cookie, and is never transmitted to us.
You can block or delete cookies through your browser settings, but you will then be unable to log in to the platform.
10. Data Security
We implement industry-standard security measures including:
- SSL/TLS encryption for data transmission
- Encrypted password storage (encrypt/hashing)
- Continuous error and security monitoring, with prompt application of security updates
- Access controls and authentication mechanisms
- Secure database hosting with regular backups
- Employee confidentiality agreements
11. International Data Transfers
Your data is primarily stored within the European Economic Area (EEA). Where a processor (for example our payment or hosting provider) transfers personal data outside the EEA, we rely on appropriate safeguards, including:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions where applicable
- Appropriate technical and organisational measures
12. Children's Privacy
Our services are intended for research professionals and businesses. We do not knowingly collect data from individuals under 18 years of age.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through our platform. The "Last Updated" date at the top of this page indicates when the policy was last revised.
14. Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us:
