01 · Data we collect
Contact, order, institution.
When you create a researcher account or place an order, we collect a limited set of identifying data: full name, institutional affiliation, business email, shipping address, and contact telephone. For orders that ship internationally, we additionally capture the end-user's stated research purpose and the institution's registered jurisdiction.
Payment card numbers are processed directly by our payment gateway; our servers never store the primary account number, expiration, or security code — only a tokenised reference for dispute and reconciliation.
02 · How we use it
Fulfilment, compliance, correspondence.
Your data is used to fulfil orders, generate Certificates of Analysis, satisfy export-control obligations, respond to your inquiries, and — if you have opted in — to send occasional laboratory correspondence. We do not sell personal data. We do not rent, license, or trade mailing lists.
03 · Cookies & telemetry
Functional only, by default.
The site uses a small number of first-party cookies to persist your session, your cart contents, and your age-attestation. Anonymous aggregate analytics are captured to understand how researchers discover and move through the catalog; no individual is identified in these reports. You may block non-essential cookies through your browser without loss of core functionality.
04 · Third parties
Payment, analytics, freight.
We share the minimum necessary data with vetted sub-processors: a payment gateway (to authorise and settle transactions), an analytics provider (aggregate-only), and contracted freight carriers (name, address, and phone number, strictly for delivery). A current list of sub-processors is available on request.
05 · Retention
As long as we must, no longer.
Order records and shipment logs are retained for seven years to satisfy tax and export-control recordkeeping obligations. Researcher account data is retained for the active life of the account plus twenty-four months, after which it is purged or anonymised. Backup archives roll off on a quarterly cadence.
06 · Your rights
CCPA, GDPR, and plain English.
Residents of California and the European Economic Area have specific statutory rights to access, correct, port, and delete their personal data, and to object to certain processing. We honour these rights for all researchers regardless of jurisdiction, subject only to the retention obligations noted above.
To exercise any right, write to the contact address below. We will acknowledge receipt within seven business days and respond substantively within thirty.
07 · Security
Encryption, principle of least privilege.
Data in transit is protected by TLS 1.3. Data at rest is encrypted with industry-standard ciphers. Access to production systems is restricted to named personnel under multi-factor authentication and reviewed quarterly. We disclose material data incidents to affected researchers without undue delay.
08 · Contact
Write to the laboratory.
Questions, requests, or complaints may be directed to: The Pure Pep, LLC — Privacy Office, [street address], Houston, Texas [ZIP], United States, or privacy@[placeholder-domain].