Research Peptides UK Domestic Stock Fast Dispatch Discreet Packaging Research Use Only Orders Shipped from the UK Research Peptides UK Domestic Stock Fast Dispatch Discreet Packaging Research Use Only Orders Shipped from the UK
Legal & Compliance

Privacy Policy

Last updated: May 2026

UK GDPR Compliant
Your privacy matters to us.

This policy explains what personal data we collect, why we collect it, and how we handle it. Nova Biolabs is committed to transparency and to meeting its obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Nova Biolabs ("we", "us", "our") is the data controller for personal data collected through www.novabiolabs.co.uk. We are a UK-based research peptide supplier.

If you have any questions about how we handle your data, please contact us:

2. What Data We Collect

We only collect the data that is necessary to provide our service.

  • Order data — full name, email address, phone number, shipping address, and country. Collected when you place an order.
  • Communication data — messages sent to us via WhatsApp or email.
  • Marketing data — your email address, if you sign up for restock notifications.
  • Technical data — IP address, browser type, and pages visited, collected via cookies when you browse our site.

We do not collect sensitive personal data (such as health data) and we do not knowingly collect data from individuals under the age of 18.

3. Why We Collect It (Legal Basis)

Under UK GDPR, we must have a lawful basis for processing your personal data. Our bases are:

  • Contract Order processing — we need your details to fulfil and dispatch your order.
  • Consent WhatsApp opt-in — contact via WhatsApp is based on your consent given voluntarily at checkout.
  • Consent Restock notifications — based on your consent when you submit your email address.
  • Legitimate Interests Site analytics — we have a legitimate interest in understanding how our site is used so we can improve it.

4. How We Use Your Data

  • To process and dispatch your order
  • To communicate with you about your order via WhatsApp or email
  • To send restock notifications, if you opted in
  • To improve our website and user experience

We will not use your data for any purpose incompatible with the purposes listed above without obtaining your prior consent.

5. Who We Share It With

We do not sell, rent, or trade your personal data. We use a small number of trusted third-party services to operate our site and process orders. Where your data is passed to these services, we do so only to the extent necessary:

  • EmailJS (emailjs.com) — to send order confirmation emails. Your order details are passed to their servers for this purpose.
  • Formspree (formspree.io) — to handle restock notification signups. Your email address is transmitted to their servers.
  • Google Fonts — fonts are loaded directly from Google's servers when you visit our site. Your IP address may be logged by Google as a result.
  • Blockchain.info — used to detect Bitcoin payment confirmations. No personal data is transmitted to this service.
  • QR Server API (goqr.me) — used to generate QR codes displayed on this site. No personal data is included in these requests.

All third-party providers we use are required to handle your data securely and in accordance with applicable data protection law.

6. How Long We Keep It

  • Order data — retained for 7 years, as required by UK HMRC accounting and record-keeping rules.
  • Marketing emails — retained until you unsubscribe or withdraw consent. You may unsubscribe at any time by contacting us.
  • Cookie data — see the Cookies section below for specific retention periods.
  • Communication data — retained for a reasonable period to resolve any queries, then deleted.

Once data is no longer required for the purpose it was collected, we will delete or anonymise it securely.

7. Your Rights Under UK GDPR

As a data subject, you have the following rights in relation to your personal data:

Right of access — request a copy of your data
Right to rectification — correct inaccurate data
Right to erasure — request deletion of your data
Right to object — object to how we use your data
Right to portability — receive your data in a usable format
Right to restrict processing — limit how we use your data

To exercise any of these rights, please email us at info@novabiolabs.co.uk. We will respond within one calendar month.

You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk or by calling 0303 123 1113.

8. Cookies

We use a small number of cookies that are strictly functional. No advertising or third-party tracking cookies are used on this site.

If Google Analytics is enabled on this site in the future, this policy will be updated to reflect the additional cookies set. You will be informed via the cookie consent banner.

You can manage or delete cookies through your browser settings at any time. Note that disabling functional cookies may affect your experience on this site.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. The date at the top of this page will always reflect when the policy was last revised.

We encourage you to review this page periodically. Where changes are material, we will take reasonable steps to notify you.

10. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please get in touch with us:

Nova Biolabs
← Back to Home