Privacy Policy
How Symax Peptides collects, uses and protects personal data under the GDPR. Last updated 14 September 2026.
Who is responsible for your data
Symax Peptides is the data controller for this website. If you have any question about how we handle your personal data, or you wish to exercise any of the rights set out below, write to us at research@symaxpeptides.com and we will respond within one month.
What we collect
Information you give us: name, billing and delivery address, email address, telephone number, company or institution name, VAT number where supplied, and the contents of any message you send us.
Order information: what you bought, when, at what price, and the delivery and payment method chosen.
Payment information: handled entirely by our payment provider. We receive confirmation that a payment succeeded and the last four digits of the card. We never see or store full card numbers.
Technical information: IP address, browser and device type, pages viewed and referring site, collected through cookies and server logs.
Why we use it, and our legal basis
- To fulfil your order — necessary for performance of our contract with you.
- To keep accounting and tax records — necessary for compliance with a legal obligation.
- To answer enquiries and provide support — our legitimate interest in running a responsive business.
- To protect the site against fraud and abuse — our legitimate interest in security.
- To send marketing email — only with your consent, which you may withdraw at any time.
- To measure how the site is used — only with your consent to analytics cookies.
Cookies
Essential cookies keep your cart and session working and cannot be switched off. Analytics cookies, if you consent, tell us which pages are used and where visitors drop off. You can change or withdraw your cookie choices at any time through your browser settings or the cookie controls on this site.
Who we share data with
We share the minimum necessary with our payment provider, our shipping carriers, our hosting provider and our email service provider. Each acts under contract and may use your data only to provide that service to us.
We may also disclose data where we are legally required to. We do not sell personal data and we do not share it with advertisers.
Transfers outside the EEA
Our infrastructure is based in the European Union. Where a supplier processes data outside the EEA we rely on an adequacy decision or on Standard Contractual Clauses approved by the European Commission.
How long we keep it
Order and invoice records are kept for the period required by Croatian tax law. Support correspondence is kept for three years. Marketing contact details are kept until you unsubscribe. Analytics data is retained in aggregate form only.
Your rights
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time where our use is based on consent.
To exercise any of these, email us. We respond within one month.
If you are not satisfied with our response you may complain to the Croatian Personal Data Protection Agency (AZOP) or to the supervisory authority in your own country.
Security
The site runs over TLS encryption. Access to order data is restricted to staff who need it, and payment card data never reaches our systems.
Children
This site is not directed at anyone under 18 and we do not knowingly collect their data.
Changes to this policy
We will post any change here and update the date shown above. Material changes affecting how we use your data will be notified by email where we hold your address.