Privacy
How we handle your data
Data controller
The data controller for personal data processed through endopep.com is AB.G.PERSSON LTD, a company registered in England and Wales under company number 16308961, with registered office at Dept 2206, 43 Owston Road, Carcroft, DN6 8DA, United Kingdom. Contact for data-protection matters: privacy@endopep.com.
UK–EU transfers
AB.G.PERSSON LTD is established in the United Kingdom. The European Commission's adequacy decision of 28 June 2021 recognises the United Kingdom as providing an adequate level of data protection for transfers of personal data from the EU and EEA. Personal data of EU data subjects is therefore transferred between the EU and the UK under Article 45 GDPR without further safeguards. Where any sub-processor is located outside both the EU/EEA and the UK, the transfer is protected by Standard Contractual Clauses or a recognised adequacy decision under Article 46 GDPR.
Data we collect
For each buyer account we collect: name, institutional email address, job title, principal investigator where applicable, institution legal name, institution domain, EU VAT number, institutional shipping address, documentary evidence of affiliation uploaded at registration, and the record of every pre-order declaration accepted at checkout together with its timestamp, IP address and user-agent. For each order we additionally collect order items, invoice number, payment status and shipping tracking data.
Legal basis for processing
Processing is carried out on the following bases under Article 6 GDPR: (a) performance of a contract for account creation, eligibility verification, order processing and shipping; (b) compliance with a legal obligation for tax, accounting, REACH Article 36 record-keeping, and chemical-supply record-keeping; (c) legitimate interest for fraud prevention, eligibility verification, audit response and dispute resolution.
Third-party processors
Personal data is shared only with the processors strictly necessary for the service: the fulfilment carrier (shipping address only), the invoicing and banking provider (invoice and payment data), the email-delivery provider (transactional communications), and the hosting and database infrastructure for endopep.com. Every processor is bound by a data-processing agreement in compliance with Article 28 GDPR. Personal data is not sold, rented or shared with any third party for marketing purposes.
International transfers
Personal data is stored on servers located in the European Union or the European Economic Area. Where any processor stores data outside the EEA, the transfer is protected by Standard Contractual Clauses or an adequacy decision under Article 46 GDPR.
Retention
Account and order data is retained for ten years after the last order, consistent with tax-retention and REACH Article 36 obligations. Pre-order declaration records are retained for ten years. Marketing subscriptions are retained until unsubscribed. On request, non-mandatory data is deleted within 30 days.
Cookies
endopep.com uses only essential cookies required for session, cart persistence and security. No tracking cookies, advertising cookies or third-party analytics are used. See the cookies section of the Terms for details.
Your rights
Under GDPR, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and the right to data portability. You may lodge a complaint with the data protection authority of your EU member state at any time. Contact privacy@endopep.com to exercise these rights.
Contact
For privacy-related enquiries: privacy@endopep.com. Written correspondence may be addressed to the registered office of AB.G.PERSSON LTD at Dept 2206, 43 Owston Road, Carcroft, DN6 8DA, United Kingdom.