Skip to main content

Privacy & Data Policy

Transparent protocols on how we safeguard your information within the UK scientific community.

Updated January 2026Jurisdiction: United Kingdom
Encrypted transactions
SSL/TLS encryption for all laboratory procurement
UK compliance
Fully aligned with UK GDPR & DPA 2018 standards
Data sovereignty
You maintain complete control over your research data

1. Data Controller & Compliance

Cobalt Peptides operates as the primary data controller. We are committed to maintaining the highest standards of data integrity for our research partners, fully adhering to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information Collection Protocols

To facilitate professional laboratory supply, we collect specific data points categorized as follows:

Active Disclosure

  • Institutional/Personal Account Details
  • Verified Shipping & Logistics Addresses
  • Technical Support Correspondences

Automated Telemetry

  • Anonymized Usage & Traffic Patterns
  • Browser Fingerprinting for Security
  • Session State & Cart Authentication

3. Secure Data Processing

Your data is utilized strictly to fulfill orders and enhance the research procurement experience. We use PayPal and Fena to handle payment processing. For Pay by Bank, authentication happens with your bank; we do not receive your bank login credentials.

Note

We do not sell research data or customer lists to third-party marketing firms. Information sharing is limited to essential logistics partners (e.g., UK couriers).

Support Conversations & Uploaded Files

  • You can only send us a file when our support team has asked for one — there is no always-on upload. A request stays open for 3 days (with one reminder) and then closes itself.
  • Uploaded photos and documents are visible only to our support team, are never made public, and are used solely to resolve your enquiry.
  • Every uploaded file carries a scheduled removal date. Files are deleted when the conversation permanently closes, and immediately on a verified erasure request — whichever comes first. Files supporting an active payment dispute are retained until the dispute concludes, then deleted.
  • The text of support conversations is retained as business correspondence and is covered by your statutory rights below.

4. Your Statutory Rights

As a UK-based researcher, you have the following rights under the GDPR framework:

  • Right of Access (SAR)
  • Right to Rectification
  • Right to Erasure (Right to be Forgotten)
  • Right to Restrict Processing
  • Right to Data Portability
  • Right to Object
  • Automated Decision-Making Rights

5. Contact Data Protection Officer

For all data-related inquiries or to exercise your rights, please contact our support team. We aim to respond to all Subject Access Requests (SAR) within 30 days.

Information Commissioner's Office (ICO)

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the UK's supervisory authority at ico.org.uk.