Privacy Policy

Last Updated: September 19, 2026

European Research Chemicals (“we,” “our,” or “us”) is committed to protecting the privacy, security, and confidentiality of personal and institutional data. This Privacy Policy explains how we collect, use, process, and safeguard your information in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and relevant European data protection legislation.

1. Data Controller

The data controller responsible for your personal data is:

European Research Chemicals

Attn: Data Protection Officer (DPO)

Email: dpo@europeanresearchchemicals.eu

Purpose: Compliance, EU Privacy Inquiries, and Data Subject Access Requests (DSAR).

2. Information We Collect

To process orders, verify research credentials, and fulfill legal obligations across the EU, we collect the following categories of data:

A. Account & Verification Data

  • Full name, professional title, and institutional/corporate affiliation.
  • Business email address, telephone number, and registered office/facility address.
  • Account credentials (hashed passwords, username).
  • Institutional verification documents (VAT ID, laboratory license, or research accreditation) submitted to verify compliance with our Strict Research Policy.

B. Transaction & Order Data

  • Ordered reference materials, CAS numbers, batch numbers, and quantity.
  • Billing address, delivery location within the EU, and invoice records.
  • Payment transaction metadata (e.g., SEPA transaction IDs or blockchain payment confirmations; we do not store full credit card numbers).

C. Technical & Usage Data

  • IP address, browser type, operating system, and network access timestamps.
  • On-site interactions, search parameters, and referral URLs.
  • Security logging data used to detect and prevent unauthorized platform access.

3. Legal Bases for Processing (GDPR Article 6)

We process your personal data under the following lawful bases:

  1. Contractual Performance (Art. 6(1)(b)): Processing necessary to execute orders, deliver packages, manage accounts, and provide batch-specific COA reports.
  2. Legal Obligation (Art. 6(1)(c)): Compliance with EU chemical oversight laws, REACH reporting regulations, tax record-keeping, and regulatory auditing.
  3. Legitimate Interests (Art. 6(1)(f)): Protecting platform security, verifying client legitimacy to prevent non-laboratory misuse, and optimizing site functionality.
  4. Consent (Art. 6(1)(a)): Subscription to scientific updates or non-essential telemetry/cookie usage (withdrawable at any time).

4. How We Use Your Data

Your information is processed strictly for legitimate operational purposes:

  • Order Execution: Processing, vacuum packaging, and dispatching orders to verified EU destinations.
  • Quality Assurance: Generating and linking lot-specific HPLC and NMR Certificates of Analysis (COA) to your customer dashboard.
  • Client Verification: Verifying that orders are placed by legitimate scientific entities for in-vitro or laboratory research.
  • Security & Fraud Prevention: Monitoring platform activity to enforce site security and prevent fraudulent transactions.

5. Data Sharing & International Transfers

We maintain a strict no-sale policy for customer data. We only share information with trusted third parties under binding Data Processing Agreements (DPAs):

  • Logistics & Express Couriers: Licensed EU transport partners (e.g., DHL, DPD, UPS) to execute discreet, climate-controlled shipping.
  • Financial Institutions: Payment processors and SEPA clearinghouses for transaction verification.
  • Legal Authorities: Regulatory agencies or law enforcement bodies only when mandated by European law or valid court order.
Data Sovereignty Guarantee: All primary servers, databases, and cold backups are located within secure, climate-controlled data centers strictly inside the European Economic Area (EEA).

6. Data Retention Policy

We retain data only as long as necessary for the purpose it was collected:

Data Type Retention Period Justification
Transaction & Invoice Records 10 Years Required under EU Tax & Commercial Accounting Laws
Verification Documents Duration of active account + 3 Years
Chemical compliance and REACH auditing standards
Technical & Log Files 90 Days Platform security monitoring and DDoS protection
Inactive Accounts Purged after 2 Years of inactivity GDPR minimization principle

7. Your Data Rights under GDPR

As an EU data subject, you hold the following rights regarding your personal information:

  • Right of Access (Art. 15): Request a copy of all personal data held about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete information.
  • Right to Erasure / “Right to be Forgotten” (Art. 17): Request deletion of your data (subject to statutory tax or legal retention requirements).
  • Right to Restrict Processing (Art. 18): Request that we temporarily suspend data processing under specific conditions.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format (JSON/CSV).
  • Right to Object (Art. 21): Object to processing based on legitimate interests or direct communications.
To exercise any of these rights, contact our DPO directly at dpo@europeanresearchchemicals.eu. We respond to all formal access requests within 30 days.

8. Cookies & Tracking Technologies

We utilize a privacy-first approach to cookies:

  • Strictly Necessary Cookies: Required for shopping cart maintenance, secure login, and session navigation.
  • Analytical / Performance Cookies: Anonymized, self-hosted analytics used to optimize site speed without tracking individual identifiers across external domains.
You can manage or disable non-essential cookies at any time via our footer Cookie Settings banner.

9. Security Measures

We employ enterprise-grade security protocols to protect scientific and client records:

  • End-to-end TLS 1.3 / AES-256 encryption for all web traffic and database storage.
  • Strict role-based access control (RBAC) and mandatory Multi-Factor Authentication (MFA) for administrative staff.
  • Isolated infrastructure protecting sensitive verification records from public web vectors.

10. Complaints & Regulatory Contact

If you believe our data processing violates European data privacy law, you have the right to lodge a complaint with your local Data Protection Authority (DPA) within your EU member state, or with the Lead Supervisory Authority in our primary EU jurisdiction.