Legal

Privacy Policy

Effective: June 25, 2026 · Last updated: July 23, 2026

This page contains both:

If you are unsure which Part applies to you, contact privacy@peptriva.com.

Part A — Privacy Policy (United States)

This Privacy Policy describes how we collect, use, share, and protect your personal information when you visit peptriva.com (the “Site”) and use our research-platform, ecommerce, membership, subscription, and AI Research Assistant services (together, the “Services”).

In this Policy, “peptriva,” “we,” “us,” and “our” refer to Wayne Ventures SEZC, a Cayman Islands company trading as “Peptriva,” with registered office at 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands. Wayne Ventures SEZC is the seller of record and the controller responsible for personal data processed through the Site.

This Privacy Policy is designed to comply with U.S. state privacy laws including: the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”); the California Online Privacy Protection Act (CalOPPA); the Virginia Consumer Data Protection Act (VCDPA); the Colorado Privacy Act (CPA); the Connecticut Data Privacy Act (CTDPA); the Utah Consumer Privacy Act (UCPA); and other applicable state privacy laws.

A separate Privacy Notice is provided in Part B for users located in the European Economic Area, the United Kingdom, and Switzerland; that notice prevails for those users.

peptriva’s Site is intended for adults 21+ who attest to being Qualified Researchers. We do not knowingly collect personal information from anyone under the age of 21.

A.1 Information We Collect

We collect the following categories of personal information.

A.1.A Information You Provide Directly

A.1.B Information We Collect Automatically

A.1.C Sensitive Personal Information

We do not knowingly collect biometric data, precise geolocation, government-issued identifiers (e.g., SSN, driver’s license), or health information through the Services. You agree not to submit protected health information (PHI) or other regulated personal data through any field on the Site, including the AI Research Assistant. If we discover that such information has been submitted, we will delete it. We do not use sensitive personal information for purposes that would trigger the CPRA “limit use of sensitive personal information” right.

A.1.D Information from Third Parties

A.2 How We Use Personal Information

We use personal information for the following business and commercial purposes:

A.3 How We Share Personal Information

We do not sell personal information for monetary consideration. We may “share” personal information (as broadly defined under the CCPA/CPRA) with the following categories of recipients, only as needed to operate the Services and subject to written confidentiality and security obligations:

We do not knowingly disclose personal information to third parties for cross-context behavioral advertising without an opportunity to opt out. To opt out, see Section A.6.

A.4 Data Retention

We retain personal information only as long as needed for the purposes described in this Policy, to comply with legal and tax obligations (typically up to 7 years for transaction records), to defend or pursue legal claims, and to enforce our agreements. Member COA archives may be retained per the membership terms (e.g., 12 months after cancellation). Inactive account data may be deleted or anonymized after a reasonable period. Anonymized or aggregated data, which can no longer be linked to an identified or identifiable person, may be retained indefinitely.

A.5 Cookies and Tracking Technologies

We use strictly necessary cookies (for login, cart, age-gate, and security), functional cookies (for preferences), analytics cookies (to measure usage), and, where lawful and consented, marketing cookies. You can manage non-essential cookies via the cookie banner on the Site and your browser settings. Disabling cookies may affect functionality. Some browsers send a Global Privacy Control (“GPC”) signal; we treat a recognized GPC signal as a valid request to opt out of “sale” and “sharing” for the originating browser.

A.6 Your Privacy Rights

A.6.A U.S. State Rights (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and Similar)

Subject to verification and applicable exceptions, you may have the right to:

A.6.B EU/UK/Swiss Residents

If you are located in the European Economic Area, the United Kingdom, or Switzerland, please refer to Part B (EU/UK GDPR Privacy Notice), which describes additional rights (including rights to access, rectification, erasure, restriction, objection, portability, and to lodge complaints with supervisory authorities) and information about international transfers.

A.6.C How to Submit a Request

Submit privacy requests by emailing privacy@peptriva.com. You may also designate an authorized agent. We will verify your identity using account credentials and/or transaction details. We respond within the time required by applicable law (generally 45 days under CCPA/CPRA, with one 45-day extension for complex requests).

A.7 International Transfers

We are based in the Cayman Islands, and our service providers may operate in the United States and elsewhere. If you access the Services, your personal information may be processed in the Cayman Islands, the United States, and other countries with different data-protection laws. For transfers from the EEA, UK, or Switzerland, we use appropriate safeguards (such as Standard Contractual Clauses and the UK International Data Transfer Addendum) as described in Part B.

A.8 Security

We use reasonable administrative, technical, and physical safeguards to protect personal information, including encryption in transit, access controls, and vendor due diligence. No system is perfectly secure; we cannot guarantee absolute security.

A.9 SMS Program Data

If you enroll in our SMS programs, we collect your mobile number, opt-in status, message-interaction data (e.g., HELP/STOP responses), and related metadata solely to administer SMS messaging. We do not share SMS originator opt-in data or consent with third parties, except service providers who support message delivery or as required by law. Standard message and data rates may apply. Text STOP to opt out at any time. See our Website Terms and Conditions for additional SMS terms.

A.10 AI Research Assistant Data

Prompts and outputs from the AI Research Assistant are logged for security, abuse-prevention, evaluation, and product-improvement purposes. We may review queries to enforce scope limits (e.g., to refuse human-use, dosing, or medical questions). Do not submit protected health information, government identifiers, or third-party personal information to the Assistant. Member-tier conversation history may be retained per the membership-feature description on the Site.

A.11 Children

The Services are not directed to or intended for anyone under 21. We do not knowingly collect personal information from anyone under 21. If we learn we have collected such information, we will delete it. Parents or guardians who believe a minor has provided personal information should contact privacy@peptriva.com.

A.12 Third-Party Links

The Site may link to third-party sites and services. Their privacy practices are governed by their own policies, which we do not control.

A.13 Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will post a notice on the Site and update the “Last Updated” date. Your continued use of the Services after changes become effective constitutes acceptance of the updated Policy.

A.14 Contact Us

Privacy questions, requests, or complaints: privacy@peptriva.com.

Mail: Peptriva, Attn: Privacy, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands.

Part B — EU/UK GDPR Privacy Notice

Online Services and AI Research Assistant

Controller: Wayne Ventures SEZC (a Cayman Islands company, trading as Peptriva)

This Privacy Notice explains how Wayne Ventures SEZC, a Cayman Islands company trading as Peptriva (“peptriva,” “we,” “us,” or “our”), processes your personal data when you visit https://www.peptriva.com (the “Site”), interact with our research-platform services (the “Services”), or use our AI Research Assistant. It is provided to satisfy our information obligations under Articles 13 and 14 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), and, where applicable, the UK GDPR and the EU AI Act.

We address you (“you” / “your”) directly. Where this notice and Part A (U.S. Privacy Policy) differ for users in the European Economic Area (“EEA”), the United Kingdom, or Switzerland, this Part B prevails for those users.

B.1 Data Controller and Representatives

The controller responsible for processing your personal data is:

Wayne Ventures SEZC (trading as Peptriva)
Registered office: 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands.
Contact: privacy@peptriva.com

Data Protection Officer

We have not appointed a Data Protection Officer because none of the conditions in Art. 37(1) GDPR are met: our core activities do not consist of processing operations requiring large-scale, regular, and systematic monitoring of data subjects, nor do they consist of large-scale processing of special categories of data. For all data-protection inquiries, please contact privacy@peptriva.com.

EU / UK Representative

As controllers established outside the European Union and the United Kingdom, we have appointed the following representatives in accordance with Art. 27 GDPR and the equivalent UK GDPR provision:

EU Representative: Peptriva Research, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands. Email: hello@peptriva.com.

UK Representative: Peptriva Research, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands. Email: hello@peptriva.com.

B.2 Data We Collect

In connection with your use of the Site and Services, we process the following categories of personal data:

B.2.1 Information You Provide Directly

B.2.2 Information We Collect Automatically

B.2.3 Information from Third Parties (Art. 14 GDPR)

We may receive personal data about you from the following sources, where you have not provided it to us directly:

Where we receive personal data from these sources, we will inform you in accordance with Art. 14 GDPR within one month and, where required, identify the source on request.

B.2.4 Special Categories of Personal Data (Art. 9 GDPR)

We do not knowingly collect special categories of personal data (e.g., health data, biometric data, data revealing ethnic origin, political opinions, religious or philosophical beliefs, or data concerning sex life or sexual orientation) through the Site or Services. You agree not to submit protected health information or any such data through any field on the Site, including the AI Research Assistant. If we discover that such data has been submitted, we will delete it without undue delay.

B.3 Purposes, Legal Bases, and Retention Periods

The following table provides an overview of the processing purposes, the applicable legal basis, and the retention period.

Purpose Data Categories Legal Basis Retention Period
Providing the Services (account, orders, subscriptions, protocol shipments, COA delivery, customer notifications) Identity, account, transaction, payment metadata Art. 6(1)(b) GDPR — contract performance Duration of relationship + up to 10 years for invoices and tax records
Identity, age, and Qualified Researcher attestation; access and jurisdictional limit enforcement Identity, attestation data, IP address, device data Art. 6(1)(b) and (c) GDPR — contract / legal obligation; Art. 6(1)(f) — legitimate interest in lawful access controls Duration of account + 12 months
Customer support: replies to inquiries, complaints, replacements, and out-of-spec claims Identity, communications, transaction data Art. 6(1)(b) GDPR (contract); Art. 6(1)(f) (legitimate interest) 6 months after resolution; longer for warranty or legal-claim defence
Security and fraud prevention; misuse, chargeback abuse, and breach of Terms Account, device, transaction, payment metadata, server logs Art. 6(1)(f) GDPR — legitimate interest in protecting users and the business 7–30 days for raw logs; up to 24 months for security investigation records
Operating, securing, evaluating, and improving the AI Research Assistant Prompts, outputs, conversation metadata Art. 6(1)(b) GDPR (provision of feature); Art. 6(1)(f) (safety and improvement) Up to 24 months
Personalisation (cart, preferences, protocol selections) Account, usage data Art. 6(1)(b) GDPR (contract); Art. 6(1)(f) (functional UX) Duration of account
Marketing communications to existing customers (similar products, member benefits) Identity, contact, transaction data Art. 6(1)(f) GDPR + applicable national soft opt-in (e.g., Reg. 22 PECR (UK), Art. L.34-5 CPCE (FR), § 7(3) UWG (DE)) or Art. 6(1)(a) consent Until you object / withdraw consent
Newsletter, research digests, non-essential marketing Identity, contact data, engagement data Art. 6(1)(a) GDPR — consent Until you withdraw consent
Loyalty / rewards program (where offered) Account, transaction data Art. 6(1)(b) GDPR — program contract Duration of participation + 12 months
Analytics and product improvement Pseudonymised usage and device data Art. 6(1)(a) (consent) for non-essential analytics; Art. 6(1)(f) for strictly necessary measurement Up to 26 months (pseudonymised); aggregated data may be retained indefinitely
Legal compliance (tax, accounting, recordkeeping; defending claims; enforcing Terms) All categories as relevant Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legal-claims defence) Per applicable retention obligation; typically 6–10 years for invoices
Business transactions (merger, financing, acquisition) All categories as relevant Art. 6(1)(f) GDPR — legitimate interest in orderly business transfer Until completion; thereafter under successor entity’s notice

Legitimate interests we pursue under Art. 6(1)(f) GDPR include: keeping the Site secure and free from fraud; preventing and prosecuting misuse and breaches of our Terms; understanding and improving how our Services are used; communicating with our existing customers about similar research products; defending and pursuing legal claims; and the orderly transfer of our business.

B.4 Recipients of Your Data

To fulfil the purposes described above, your personal data may be disclosed to the following categories of recipients, in each case subject to written confidentiality and security obligations (typically a Data Processing Agreement under Art. 28 GDPR):

We do not sell your personal data. A current list of our processors is available on request from privacy@peptriva.com.

B.5 International Data Transfers

Personal data is processed by us in the Cayman Islands and by service providers established in the United States and elsewhere. Neither the Cayman Islands nor the United States benefits from a comprehensive EU adequacy decision (the EU-U.S. Data Privacy Framework provides a partial adequacy finding limited to certified U.S. organisations). Where we transfer personal data to third countries, we ensure appropriate safeguards under Chapter V GDPR, including:

A copy of the relevant safeguards or DPF certification information for a specific transfer is available on request from privacy@peptriva.com.

B.6 Retention Periods

We retain personal data only as long as necessary for the purposes described in Section B.3, to comply with our legal and tax obligations, to defend or pursue legal claims, and to enforce our agreements. The default retention periods are set out in the table in Section B.3. Where data are processed for several purposes with different retention obligations, we apply the longest applicable period.

After expiry of the applicable retention period, personal data will be deleted or anonymised. Anonymised or aggregated data, which can no longer be linked to an identified or identifiable natural person, may be retained indefinitely.

B.7 Your Rights

Under the GDPR you have the following rights regarding your personal data:

To exercise your rights, contact privacy@peptriva.com. We will respond within one month of receipt of your request, extendable by a further two months for complex requests in accordance with Art. 12(3) GDPR. We may need to verify your identity using account credentials and/or transaction details. You may also designate an authorised agent.

Right to Object (Art. 21 GDPR)

Where we process your personal data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation.

Where your personal data is processed for direct marketing purposes, you have the right to object at any time, without needing to provide specific reasons. This also applies to profiling insofar as it is related to such direct marketing.

If you object, we will cease processing your data for those purposes, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.

To exercise this right, contact privacy@peptriva.com or, for marketing communications, use the unsubscribe link in any email or text STOP to any SMS message.

B.7.1 Whether the Provision of Personal Data Is Required

Provision of identity, contact, payment, and Qualified Researcher attestation data is necessary for the conclusion and performance of our contract with you, and in part for compliance with our legal obligations (Art. 13(2)(e) GDPR). If you do not provide these data, we will not be able to verify your eligibility, accept your order, deliver your subscription, or provide membership benefits. Provision of marketing data is voluntary; refusal has no consequence other than that you will not receive the relevant communications.

B.8 Cookies and Tracking Technologies

Our Site uses cookies and similar technologies. Strictly necessary cookies (for login, cart, age-gate, and security) are set on the basis of Art. 6(1)(f) GDPR and the local implementations of Art. 5(3) ePrivacy Directive. All other cookies and tracking technologies are set only with your prior consent (Art. 6(1)(a) GDPR), which you may grant or withdraw via our cookie banner and preference centre. The following table provides an overview:

Category Tool / Provider Purpose Duration Legal Basis
Strictly necessary Self-hosted session cookies Login, cart, age-gate, CSRF, load balancing Session Art. 6(1)(f) GDPR / Art. 5(3) ePD
Functional Self-hosted preference cookies Remembering preferences (language, theme, protocol selections) Up to 12 months Consent (Art. 6(1)(a))
Analytics Google Analytics 4 (GA4) Measuring site usage to improve content and UX Up to 13 months Consent (Art. 6(1)(a))
Marketing Google Ads (conversion measurement) Audience building and ad measurement Up to 13 months Consent (Art. 6(1)(a))

You can manage your preferences at any time through our cookie banner, the “Manage Cookies” link in the site footer, or your browser settings. We honour Global Privacy Control (“GPC”) signals as a request to opt out of “sale” and “sharing” for the originating browser.

B.9 AI Processing and Automated Decision-Making

We use automated processing technologies, including artificial intelligence, in connection with the Site and Services. We inform you about the nature, scope, and purpose of this processing.

AI System / Technology Purpose Decision Type Legal Basis
AI Research Assistant (powered by Anthropic Claude) A chemistry-and-handling reference: peptide chemistry, sequence questions, HPLC/MS interpretation, storage and reconstitution, research-paper queries (members only). Refuses human-use, dosing, medical, brand-comparison, and similar out-of-scope queries. Informational only. Outputs are not automated individual decisions producing legal or similarly significant effects within the meaning of Art. 22 GDPR. Outputs must be independently verified by a Qualified Researcher. Art. 6(1)(b) GDPR (provision of the Assistant feature); Art. 6(1)(f) (legitimate interest in safety review and improvement).
Risk scoring for fraud prevention Identifying potentially fraudulent or high-risk transactions (e.g., identity mismatch, velocity, geo-anomaly). Automated screening that may delay or hold an order pending manual review. No legal decision is made solely by the system; a human reviewer makes the final determination. Art. 6(1)(f) GDPR — legitimate interest in fraud prevention.
Personalisation and recommendations Suggesting relevant research content based on declared research interests. Recommendations only. No legally significant effect. Art. 6(1)(a) GDPR (consent) where based on non-essential profiling; Art. 6(1)(b) for in-account research-context personalisation.

Where an automated decision produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR (for example, definitive refusal of an order solely on automated grounds), you have the right to obtain human intervention, to express your point of view, and to contest the decision. Contact privacy@peptriva.com to exercise this right.

B.9.1 AI Act Transparency

In accordance with Art. 50 of the EU AI Act (Regulation (EU) 2024/1689), we inform you that:

B.10 Data Security and Breach Notification

We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against unauthorised access, loss, destruction, or alteration. These include encryption in transit (TLS 1.2+) and at rest, role-based access controls, audit logging, vendor due diligence, principle-of-least-privilege provisioning, and regular review of our security posture. No system is perfectly secure; we cannot guarantee absolute security.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and, where the risk is high, we will inform affected data subjects without undue delay (Art. 34 GDPR).

B.11 Children’s Data

Our Site and Services are exclusively directed at adult researchers. Access is gated at 21 years of age (which exceeds the minimum age applicable in any EU/EEA Member State or the United Kingdom for information-society services under Art. 8 GDPR), and we require an attestation that you are at least 21 years old and a Qualified Researcher. We do not knowingly collect personal data from anyone under the age of 21.

If we become aware that personal data of a person under 21 has been collected without the required adult capacity, we will delete that data without undue delay. Parents, guardians, or other adults who believe a minor has provided personal data to us should contact privacy@peptriva.com.

B.12 Changes to This Notice

We may update this notice from time to time to reflect changes in legislation, our processing activities, or our service providers. The current version is always available on the Site. We will notify you of material changes by posting a notice on the Site for a reasonable period of time and, where the change is significant or required by law, by direct communication.

B.13 Contact and Supervisory Authorities

If you have any questions about the processing of your personal data or wish to exercise your rights, you can reach us at:

Supervisory authorities

You may lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement. A directory of EU/EEA supervisory authorities is maintained by the European Data Protection Board at https://edpb.europa.eu/about-edpb/board/members_en. UK residents may complain to the Information Commissioner’s Office (ICO) at https://ico.org.uk.

Effective: June 25, 2026 · Last updated: July 23, 2026