Privacy Policy
Last updated:
Triscience Labs ("we", "our", or "us") respects your privacy and is committed to handling your personal data lawfully, fairly, and transparently. This policy explains what information we collect when you visit trisciencelabs.com or interact with our research-supply services, why we process it, who we share it with, and the rights you have under the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") and the revised Swiss Federal Act on Data Protection ("revFADP", in force since 1 September 2023).
1. Information we collect
We only collect data that is necessary for the purposes set out in this policy. Depending on how you use our website and services, this may include the following categories of personal data:
- Identification and contact data — name, business affiliation, postal address, email address, and telephone number you provide when requesting a Certificate of Analysis (CoA), placing an order, or contacting us.
- Account data — credentials, preferences, and communication settings if and when you register for a research-buyer account.
- Order and transaction data — products requested or purchased, billing information, shipping details, and history of correspondence with our team.
- Technical data — IP address (truncated where feasible), browser type and version, time zone, device type, operating system, referring URL, and pages viewed.
- Usage data — interactions with the portfolio listing, search queries on the site, and aggregate analytics signals.
- Communications — content of messages, support tickets, and any documents you send to us.
2. How we collect information
We collect personal data through three main channels:
- Directly from you — when you fill in a form, request a CoA, place an order, sign up for updates, or correspond with us by email.
- Automatically — through cookies and similar technologies that record technical and usage data when you browse the site (see section 7).
- From third parties — limited to service providers who help us deliver the website (e.g., hosting, payment processing, shipping carriers) and only to the extent strictly necessary.
3. Legal bases for processing
Under GDPR Art. 6(1) and the corresponding revFADP provisions, we rely on one or more of the following legal grounds when we process your personal data:
- Performance of a contract — to process your order, ship goods, issue invoices, and provide support.
- Legal obligation — to comply with accounting, tax, customs, export-control, and product-stewardship requirements that apply to research-grade peptides.
- Legitimate interests — to operate, secure, and improve our website, prevent fraud, and communicate with research customers about ongoing matters. We balance these interests against your rights and freedoms in every case.
- Consent — for non-essential cookies, marketing communications, and any optional data sharing. Consent can be withdrawn at any time without affecting the lawfulness of prior processing.
4. How we use your information
We process your personal data only for the specific, legitimate purposes listed below:
- To deliver the products and documents you request (CoA, order confirmations, shipping updates).
- To verify that prospective customers are bona fide research entities, since all of our compounds are sold for research use only and are not intended for human consumption.
- To manage our business records, including invoicing, accounting, and regulatory reporting.
- To operate, maintain, and secure the website, including detecting and preventing abuse, fraud, and unauthorised access.
- To improve our portfolio, content, and user experience using aggregated and, where consented, individual analytics.
- To send service-related communications and, with your prior consent, periodic updates about new compounds or quality programmes. Every marketing email contains a one-click unsubscribe link.
- To comply with applicable laws, lawful requests from authorities, and our internal compliance and ethics policies.
5. Product authenticity verification
Our products carry a unique single-use code, printed both as text and as a QR code on the vial label. When you check a vial on our verification page (/verify or /en/verify) — by scanning the QR code, following its link, or typing the code by hand — your browser sends the code to a verification service that we operate ourselves on our own infrastructure. This is a first-party API: the request is not sent to any third-party verification provider, advertising network, or analytics service.
We process this data on the basis of our legitimate interest (GDPR Art. 6(1)(f) and the corresponding revFADP provisions) in protecting customers against counterfeit and tampered products and in safeguarding the integrity of our supply chain.
- What we store — for each code we keep only the date and time of its first verification, the date and time of its most recent verification, and a counter of how many times it has been checked. This is what lets us distinguish a freshly opened vial (first verification) from a code that has been seen before (a possible sign of tampering or cloning).
- How the code is stored — the code itself is never stored in readable form. The database holds only a keyed cryptographic hash (HMAC-SHA256) of the code; the secret key is kept separately from the database (in a managed secret store, never alongside the data), so a database leak on its own cannot be turned back into a usable code, and a stored verification record cannot be linked back to you.
- No tracking data is kept — we do not store your IP address, approximate location, device, browser, or any cookie in connection with a verification. Your IP address is used only momentarily, in memory, to rate-limit abusive request volumes, and is never written to the verification database.
- No account is required — verifying a vial does not require you to log in or to provide any personal data. If you choose to report a suspected counterfeit, that simply pre-fills our contact form, which is handled as described elsewhere in this policy.
8. International data transfers
Our infrastructure is operated primarily in Switzerland and the European Economic Area. When we engage processors outside of these regions, we put in place appropriate safeguards as required by GDPR Art. 46 and revFADP Art. 16, including the European Commission Standard Contractual Clauses, the Swiss FDPIC-approved versions of those clauses, and where applicable supplementary technical and organisational measures.
You may request a copy of the safeguards in place by contacting us.
9. Security and data retention
We apply technical and organisational measures appropriate to the risk, including transport-layer encryption, access controls based on least privilege, regular backups, internal logging, and security training for staff who handle personal data.
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected and to satisfy applicable legal obligations. Order, invoicing, and tax records are typically retained for ten (10) years in line with Swiss commercial law. Account and customer-service records are retained for the duration of the relationship plus a reasonable period afterward, generally not exceeding three (3) years. Anonymised analytics data may be retained indefinitely.
10. Your rights
Under the GDPR and the revFADP, you have the following rights regarding your personal data:
- Access — to know what data we hold about you and obtain a copy.
- Rectification — to ask us to correct inaccurate or incomplete data.
- Erasure — to ask us to delete your data when it is no longer necessary or when you withdraw consent, subject to overriding legal obligations.
- Restriction — to limit how we process your data while a query is being resolved.
- Objection — to object to processing based on legitimate interests, including profiling, and at any time to direct marketing.
- Portability — to receive a copy of the data you provided in a structured, machine-readable format and to transmit it to another controller.
- Withdrawal of consent — without affecting the lawfulness of prior processing.
- Complaint — to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch) or with the supervisory authority in your EU/EEA country of residence.
11. Children’s privacy
Our website and products are intended exclusively for adult research professionals. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has provided us with personal data, please contact us and we will delete the information without undue delay.
12. Third-party links
Our pages occasionally link to external resources such as PubChem, ClinicalTrials.gov, peer-reviewed journals, and Wikimedia Commons. These websites operate independently and have their own privacy practices. We are not responsible for their content or for the way they handle personal data, and we encourage you to read their privacy notices before submitting any information to them.
13. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices, in technology, or in applicable law. The "Last updated" date at the top of this page indicates when the policy was last revised. Material changes will be highlighted on this page in advance, and where required by law we will obtain your fresh consent. Your continued use of the site after the effective date constitutes acceptance of the updated policy.