This page contains both:
- Part A — Privacy Policy (United States) — applies to U.S. residents.
- Part B — EU/UK GDPR Privacy Notice — applies to users located in the European Economic Area, the United Kingdom, and Switzerland. Where Part B applies to you, it prevails over Part A.
If you are unsure which Part applies to you, contact privacy@peptriva.com.
Part A — Privacy Policy (United States)
This Privacy Policy describes how we collect, use, share, and protect your personal information when you visit peptriva.com (the “Site”) and use our research-platform, ecommerce, membership, subscription, and AI Research Assistant services (together, the “Services”).
In this Policy, “peptriva,” “we,” “us,” and “our” refer to Wayne Ventures SEZC, a Cayman Islands company trading as “Peptriva,” with registered office at 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands. Wayne Ventures SEZC is the seller of record and the controller responsible for personal data processed through the Site.
This Privacy Policy is designed to comply with U.S. state privacy laws including: the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”); the California Online Privacy Protection Act (CalOPPA); the Virginia Consumer Data Protection Act (VCDPA); the Colorado Privacy Act (CPA); the Connecticut Data Privacy Act (CTDPA); the Utah Consumer Privacy Act (UCPA); and other applicable state privacy laws.
A separate Privacy Notice is provided in Part B for users located in the European Economic Area, the United Kingdom, and Switzerland; that notice prevails for those users.
peptriva’s Site is intended for adults 21+ who attest to being Qualified Researchers. We do not knowingly collect personal information from anyone under the age of 21.
A.1 Information We Collect
We collect the following categories of personal information.
A.1.A Information You Provide Directly
- Identifiers: name, email address, postal address, phone number, mobile number, account username, password (hashed), and (for institutional buyers) organization name and your role within it.
- Researcher attestation data: confirmations that you are at least 21 years of age and a Qualified Researcher acquiring research products solely for bona fide laboratory use, your jurisdiction, and any institutional or research-context information you choose to provide.
- Commercial / transaction data: products purchased, subscriptions, protocol selections, order history, refunds, replacements, and store credits.
- Payment metadata: billing address and payment-method metadata (card brand, last four digits, expiration). Full card numbers are processed by our PCI-compliant payment providers and are not stored on our systems.
- Communications and User Submissions: emails, support tickets, chat messages, survey responses, product reviews, comments, and content you submit to the AI Research Assistant or other interactive features.
- Marketing preferences: opt-in / opt-out status for email and SMS communications and your communication preferences.
A.1.B Information We Collect Automatically
- Device and usage data: IP address, device identifiers, browser type and version, operating system, language, referring/exit pages, pages viewed, time spent, click and scroll behavior, and similar telemetry.
- Cookies and similar technologies: first- and third-party cookies, pixels, SDKs, and local-storage entries used for site functionality, security, analytics, and (where you have consented) advertising. See Section A.5.
- Bot-detection and security signals: to protect our checkout, account creation, and forms from automated abuse and fraud, our bot-detection provider (Cloudflare Turnstile) processes a limited set of technical signals — your IP address, a TLS fingerprint, your browser’s User-Agent, and the site key of the page — solely to distinguish human visitors from bots. It uses no interactive puzzles and is not used to identify or profile you. See Cloudflare’s Turnstile Privacy Addendum.
- Approximate location: derived from your IP address.
A.1.C Sensitive Personal Information
We do not knowingly collect biometric data, precise geolocation, government-issued identifiers (e.g., SSN, driver’s license), or health information through the Services. You agree not to submit protected health information (PHI) or other regulated personal data through any field on the Site, including the AI Research Assistant. If we discover that such information has been submitted, we will delete it. We do not use sensitive personal information for purposes that would trigger the CPRA “limit use of sensitive personal information” right.
A.1.D Information from Third Parties
- Payment processors and fraud-prevention services (transaction outcome, AVS/CVV results, risk scores).
- Shipping carriers (delivery status and address validation).
- Identity, age, and researcher-attestation verification providers (where used).
- Analytics, marketing, and customer-data platforms (audience and engagement signals consistent with your consent settings).
A.2 How We Use Personal Information
We use personal information for the following business and commercial purposes:
- Providing the Services: creating and managing your account; processing orders and subscriptions; fulfilling shipments; issuing receipts, COAs, and notifications.
- Identity, age, and researcher attestation: enforcing the 21+ age gate, the Qualified Researcher representations, and jurisdictional limits described in our Terms and Waiver Agreement.
- Customer support: responding to inquiries, resolving complaints, and managing replacements, refunds, and out-of-spec claims.
- Security and fraud prevention: detecting, investigating, and preventing fraud, unauthorized access, misuse, chargeback abuse, and breaches of our Terms.
- AI Research Assistant: operating, securing, evaluating, and improving the Assistant, including reviewing prompts and outputs for safety, scope-compliance, and quality. We do not use personal information you submit to the Assistant to train third-party generative AI models.
- Personalization: remembering your preferences, cart, and protocol selections.
- Marketing: sending email or SMS updates, restock alerts, member offers, and research-content digests, with your consent where required; and measuring marketing effectiveness.
- Loyalty / Rewards: administering any rewards program described in our Terms.
- Analytics and product improvement: understanding how the Services are used and improving them.
- Legal compliance: complying with tax, accounting, recordkeeping, regulatory, and legal-process obligations; defending claims; enforcing our Terms.
- Business transactions: evaluating or completing a merger, financing, acquisition, reorganization, dissolution, or similar transaction.
A.3 How We Share Personal Information
We do not sell personal information for monetary consideration. We may “share” personal information (as broadly defined under the CCPA/CPRA) with the following categories of recipients, only as needed to operate the Services and subject to written confidentiality and security obligations:
- Service providers: hosting, infrastructure, security, analytics, customer support, email/SMS, payment processing, fraud prevention, identity and age verification, shipping carriers, tax calculation, and similar vendors — including Cloudflare, Inc. (content delivery, security, and bot detection via Turnstile).
- Affiliates: our corporate affiliates and group entities, for the operation of the Site, customer support, and administration of the business as a single enterprise.
- Professional advisors: lawyers, auditors, and accountants.
- Authorities and others: where required by law, legal process, or to protect rights, safety, or property; and counterparties and their advisors in connection with corporate transactions.
We do not knowingly disclose personal information to third parties for cross-context behavioral advertising without an opportunity to opt out. To opt out, see Section A.6.
A.4 Data Retention
We retain personal information only as long as needed for the purposes described in this Policy, to comply with legal and tax obligations (typically up to 7 years for transaction records), to defend or pursue legal claims, and to enforce our agreements. Member COA archives may be retained per the membership terms (e.g., 12 months after cancellation). Inactive account data may be deleted or anonymized after a reasonable period. Anonymized or aggregated data, which can no longer be linked to an identified or identifiable person, may be retained indefinitely.
A.5 Cookies and Tracking Technologies
We use strictly necessary cookies (for login, cart, age-gate, and security), functional cookies (for preferences), analytics cookies (to measure usage), and, where lawful and consented, marketing cookies. You can manage non-essential cookies via the cookie banner on the Site and your browser settings. Disabling cookies may affect functionality. Some browsers send a Global Privacy Control (“GPC”) signal; we treat a recognized GPC signal as a valid request to opt out of “sale” and “sharing” for the originating browser.
A.6 Your Privacy Rights
A.6.A U.S. State Rights (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and Similar)
Subject to verification and applicable exceptions, you may have the right to:
- Know / Access: confirm whether we process your personal information and obtain a copy of it, including the categories of sources, recipients, and purposes.
- Correct: request correction of inaccurate personal information.
- Delete: request deletion of personal information we collected from you.
- Opt-out of sale / sharing: opt out of any “sale” or “sharing” of personal information for cross-context behavioral advertising, including via Global Privacy Control.
- Limit use of sensitive personal information: where applicable; we do not knowingly use sensitive personal information for purposes that would trigger this right.
- Non-discrimination: we will not discriminate against you for exercising these rights.
- Appeal: if we deny a request, you may appeal by replying to our response. We will respond within the time required by your state’s law.
A.6.B EU/UK/Swiss Residents
If you are located in the European Economic Area, the United Kingdom, or Switzerland, please refer to Part B (EU/UK GDPR Privacy Notice), which describes additional rights (including rights to access, rectification, erasure, restriction, objection, portability, and to lodge complaints with supervisory authorities) and information about international transfers.
A.6.C How to Submit a Request
Submit privacy requests by emailing privacy@peptriva.com. You may also designate an authorized agent. We will verify your identity using account credentials and/or transaction details. We respond within the time required by applicable law (generally 45 days under CCPA/CPRA, with one 45-day extension for complex requests).
A.7 International Transfers
We are based in the Cayman Islands, and our service providers may operate in the United States and elsewhere. If you access the Services, your personal information may be processed in the Cayman Islands, the United States, and other countries with different data-protection laws. For transfers from the EEA, UK, or Switzerland, we use appropriate safeguards (such as Standard Contractual Clauses and the UK International Data Transfer Addendum) as described in Part B.
A.8 Security
We use reasonable administrative, technical, and physical safeguards to protect personal information, including encryption in transit, access controls, and vendor due diligence. No system is perfectly secure; we cannot guarantee absolute security.
A.9 SMS Program Data
If you enroll in our SMS programs, we collect your mobile number, opt-in status, message-interaction data (e.g., HELP/STOP responses), and related metadata solely to administer SMS messaging. We do not share SMS originator opt-in data or consent with third parties, except service providers who support message delivery or as required by law. Standard message and data rates may apply. Text STOP to opt out at any time. See our Website Terms and Conditions for additional SMS terms.
A.10 AI Research Assistant Data
Prompts and outputs from the AI Research Assistant are logged for security, abuse-prevention, evaluation, and product-improvement purposes. We may review queries to enforce scope limits (e.g., to refuse human-use, dosing, or medical questions). Do not submit protected health information, government identifiers, or third-party personal information to the Assistant. Member-tier conversation history may be retained per the membership-feature description on the Site.
A.11 Children
The Services are not directed to or intended for anyone under 21. We do not knowingly collect personal information from anyone under 21. If we learn we have collected such information, we will delete it. Parents or guardians who believe a minor has provided personal information should contact privacy@peptriva.com.
A.12 Third-Party Links
The Site may link to third-party sites and services. Their privacy practices are governed by their own policies, which we do not control.
A.13 Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will post a notice on the Site and update the “Last Updated” date. Your continued use of the Services after changes become effective constitutes acceptance of the updated Policy.
A.14 Contact Us
Privacy questions, requests, or complaints: privacy@peptriva.com.
Mail: Peptriva, Attn: Privacy, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands.
Part B — EU/UK GDPR Privacy Notice
Online Services and AI Research Assistant
Controller: Wayne Ventures SEZC (a Cayman Islands company, trading as Peptriva)
This Privacy Notice explains how Wayne Ventures SEZC, a Cayman Islands company trading as Peptriva (“peptriva,” “we,” “us,” or “our”), processes your personal data when you visit https://www.peptriva.com (the “Site”), interact with our research-platform services (the “Services”), or use our AI Research Assistant. It is provided to satisfy our information obligations under Articles 13 and 14 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), and, where applicable, the UK GDPR and the EU AI Act.
We address you (“you” / “your”) directly. Where this notice and Part A (U.S. Privacy Policy) differ for users in the European Economic Area (“EEA”), the United Kingdom, or Switzerland, this Part B prevails for those users.
B.1 Data Controller and Representatives
The controller responsible for processing your personal data is:
Wayne Ventures SEZC (trading as Peptriva)
Registered office: 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands.
Contact: privacy@peptriva.com
Data Protection Officer
We have not appointed a Data Protection Officer because none of the conditions in Art. 37(1) GDPR are met: our core activities do not consist of processing operations requiring large-scale, regular, and systematic monitoring of data subjects, nor do they consist of large-scale processing of special categories of data. For all data-protection inquiries, please contact privacy@peptriva.com.
EU / UK Representative
As controllers established outside the European Union and the United Kingdom, we have appointed the following representatives in accordance with Art. 27 GDPR and the equivalent UK GDPR provision:
EU Representative: Peptriva Research, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands. Email: hello@peptriva.com.
UK Representative: Peptriva Research, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands. Email: hello@peptriva.com.
B.2 Data We Collect
In connection with your use of the Site and Services, we process the following categories of personal data:
B.2.1 Information You Provide Directly
- Identity and contact data: name, email address, postal address, telephone or mobile number, account username, hashed password, and (for institutional buyers) organization name and your role within it.
- Researcher attestation data: confirmations that you are at least 21 years of age and a Qualified Researcher acquiring research products solely for bona fide laboratory use, your jurisdiction, and any institutional or research-context information you choose to provide.
- Commercial / transaction data: products you purchase, subscriptions and protocol selections, order history, refunds, replacements, and store credits.
- Payment metadata: billing address and payment-method metadata (card brand, last four digits, expiration). Full card numbers are processed by our payment providers and are not stored on our systems.
- Communications and User Submissions: emails, support tickets, chat messages, survey responses, product reviews, comments, and content you submit to the AI Research Assistant or other interactive features.
- Marketing preferences: opt-in / opt-out status for email and SMS communications and your communication preferences.
B.2.2 Information We Collect Automatically
- Device and usage data: IP address, device identifiers, browser type and version, operating system, language, referring/exit pages, pages viewed, time spent, click and scroll behaviour, and similar telemetry.
- Cookies and similar technologies: first- and third-party cookies, pixels, SDKs, and local-storage entries used for site functionality, security, analytics, and (where you have consented) advertising. See Section B.8.
- Bot-detection and security signals: to protect our checkout, account creation, and forms from automated abuse and fraud, our bot-detection provider (Cloudflare Turnstile) processes a limited set of technical signals — your IP address, a TLS fingerprint, your browser’s User-Agent, and the site key of the page — solely to distinguish human visitors from bots. This processing is strictly necessary for security and relies on our legitimate interests (Art. 6(1)(f) GDPR); it uses no interactive puzzles and is not used to identify or profile you. See Cloudflare’s Turnstile Privacy Addendum.
- Approximate location: derived from your IP address.
B.2.3 Information from Third Parties (Art. 14 GDPR)
We may receive personal data about you from the following sources, where you have not provided it to us directly:
- Payment processors and fraud-prevention services (transaction outcome, AVS/CVV results, risk scores).
- Shipping carriers (delivery status, address validation).
- Identity, age, and researcher-attestation verification providers (where used).
- Analytics, marketing, and customer-data platforms (audience and engagement signals consistent with your consent settings).
Where we receive personal data from these sources, we will inform you in accordance with Art. 14 GDPR within one month and, where required, identify the source on request.
B.2.4 Special Categories of Personal Data (Art. 9 GDPR)
We do not knowingly collect special categories of personal data (e.g., health data, biometric data, data revealing ethnic origin, political opinions, religious or philosophical beliefs, or data concerning sex life or sexual orientation) through the Site or Services. You agree not to submit protected health information or any such data through any field on the Site, including the AI Research Assistant. If we discover that such data has been submitted, we will delete it without undue delay.
B.3 Purposes, Legal Bases, and Retention Periods
The following table provides an overview of the processing purposes, the applicable legal basis, and the retention period.
| Purpose | Data Categories | Legal Basis | Retention Period |
|---|---|---|---|
| Providing the Services (account, orders, subscriptions, protocol shipments, COA delivery, customer notifications) | Identity, account, transaction, payment metadata | Art. 6(1)(b) GDPR — contract performance | Duration of relationship + up to 10 years for invoices and tax records |
| Identity, age, and Qualified Researcher attestation; access and jurisdictional limit enforcement | Identity, attestation data, IP address, device data | Art. 6(1)(b) and (c) GDPR — contract / legal obligation; Art. 6(1)(f) — legitimate interest in lawful access controls | Duration of account + 12 months |
| Customer support: replies to inquiries, complaints, replacements, and out-of-spec claims | Identity, communications, transaction data | Art. 6(1)(b) GDPR (contract); Art. 6(1)(f) (legitimate interest) | 6 months after resolution; longer for warranty or legal-claim defence |
| Security and fraud prevention; misuse, chargeback abuse, and breach of Terms | Account, device, transaction, payment metadata, server logs | Art. 6(1)(f) GDPR — legitimate interest in protecting users and the business | 7–30 days for raw logs; up to 24 months for security investigation records |
| Operating, securing, evaluating, and improving the AI Research Assistant | Prompts, outputs, conversation metadata | Art. 6(1)(b) GDPR (provision of feature); Art. 6(1)(f) (safety and improvement) | Up to 24 months |
| Personalisation (cart, preferences, protocol selections) | Account, usage data | Art. 6(1)(b) GDPR (contract); Art. 6(1)(f) (functional UX) | Duration of account |
| Marketing communications to existing customers (similar products, member benefits) | Identity, contact, transaction data | Art. 6(1)(f) GDPR + applicable national soft opt-in (e.g., Reg. 22 PECR (UK), Art. L.34-5 CPCE (FR), § 7(3) UWG (DE)) or Art. 6(1)(a) consent | Until you object / withdraw consent |
| Newsletter, research digests, non-essential marketing | Identity, contact data, engagement data | Art. 6(1)(a) GDPR — consent | Until you withdraw consent |
| Loyalty / rewards program (where offered) | Account, transaction data | Art. 6(1)(b) GDPR — program contract | Duration of participation + 12 months |
| Analytics and product improvement | Pseudonymised usage and device data | Art. 6(1)(a) (consent) for non-essential analytics; Art. 6(1)(f) for strictly necessary measurement | Up to 26 months (pseudonymised); aggregated data may be retained indefinitely |
| Legal compliance (tax, accounting, recordkeeping; defending claims; enforcing Terms) | All categories as relevant | Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legal-claims defence) | Per applicable retention obligation; typically 6–10 years for invoices |
| Business transactions (merger, financing, acquisition) | All categories as relevant | Art. 6(1)(f) GDPR — legitimate interest in orderly business transfer | Until completion; thereafter under successor entity’s notice |
Legitimate interests we pursue under Art. 6(1)(f) GDPR include: keeping the Site secure and free from fraud; preventing and prosecuting misuse and breaches of our Terms; understanding and improving how our Services are used; communicating with our existing customers about similar research products; defending and pursuing legal claims; and the orderly transfer of our business.
B.4 Recipients of Your Data
To fulfil the purposes described above, your personal data may be disclosed to the following categories of recipients, in each case subject to written confidentiality and security obligations (typically a Data Processing Agreement under Art. 28 GDPR):
- Hosting, infrastructure, and security providers, including Cloudflare, Inc. (content delivery, security, and bot detection via Turnstile).
- Payment processors and fraud-prevention services.
- Email and SMS providers.
- Analytics, customer-data, and marketing platforms.
- AI model and platform providers powering the AI Research Assistant.
- Identity, age, and researcher-attestation verification providers.
- Shipping carriers and fulfilment partners.
- Tax-calculation and accounting providers.
- Professional advisors (lawyers, auditors, accountants).
- Authorities and others, where required by law, legal process, or to protect rights, safety, or property; and counterparties and their advisors in connection with corporate transactions.
We do not sell your personal data. A current list of our processors is available on request from privacy@peptriva.com.
B.5 International Data Transfers
Personal data is processed by us in the Cayman Islands and by service providers established in the United States and elsewhere. Neither the Cayman Islands nor the United States benefits from a comprehensive EU adequacy decision (the EU-U.S. Data Privacy Framework provides a partial adequacy finding limited to certified U.S. organisations). Where we transfer personal data to third countries, we ensure appropriate safeguards under Chapter V GDPR, including:
- EU-U.S. Data Privacy Framework (“DPF”), the UK Extension to the DPF, and the Swiss-U.S. DPF, where the recipient is certified.
- EU Standard Contractual Clauses (Module 2 / Module 3, as applicable) approved by the European Commission, supplemented by the UK International Data Transfer Addendum where required.
- Where appropriate, supplementary technical measures (e.g., encryption in transit and at rest, access controls, pseudonymisation) consistent with the EDPB recommendations on supplementary measures.
A copy of the relevant safeguards or DPF certification information for a specific transfer is available on request from privacy@peptriva.com.
B.6 Retention Periods
We retain personal data only as long as necessary for the purposes described in Section B.3, to comply with our legal and tax obligations, to defend or pursue legal claims, and to enforce our agreements. The default retention periods are set out in the table in Section B.3. Where data are processed for several purposes with different retention obligations, we apply the longest applicable period.
After expiry of the applicable retention period, personal data will be deleted or anonymised. Anonymised or aggregated data, which can no longer be linked to an identified or identifiable natural person, may be retained indefinitely.
B.7 Your Rights
Under the GDPR you have the following rights regarding your personal data:
- Access (Art. 15 GDPR): obtain confirmation of whether your data are processed and receive a copy.
- Rectification (Art. 16 GDPR): have inaccurate or incomplete data corrected without undue delay.
- Erasure (Art. 17 GDPR): request deletion of your data where legally permissible.
- Restriction (Art. 18 GDPR): request temporary restriction of processing under certain conditions.
- Data Portability (Art. 20 GDPR): receive your data in a structured, commonly used, machine-readable format, and to have those data transmitted to another controller where technically feasible.
- Object (Art. 21 GDPR): object to processing based on our legitimate interests — see the dedicated section below.
- Withdraw consent (Art. 7(3) GDPR): at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
- Lodge a complaint (Art. 77 GDPR): file a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
To exercise your rights, contact privacy@peptriva.com. We will respond within one month of receipt of your request, extendable by a further two months for complex requests in accordance with Art. 12(3) GDPR. We may need to verify your identity using account credentials and/or transaction details. You may also designate an authorised agent.
Right to Object (Art. 21 GDPR)
Where we process your personal data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation.
Where your personal data is processed for direct marketing purposes, you have the right to object at any time, without needing to provide specific reasons. This also applies to profiling insofar as it is related to such direct marketing.
If you object, we will cease processing your data for those purposes, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.
To exercise this right, contact privacy@peptriva.com or, for marketing communications, use the unsubscribe link in any email or text STOP to any SMS message.
B.7.1 Whether the Provision of Personal Data Is Required
Provision of identity, contact, payment, and Qualified Researcher attestation data is necessary for the conclusion and performance of our contract with you, and in part for compliance with our legal obligations (Art. 13(2)(e) GDPR). If you do not provide these data, we will not be able to verify your eligibility, accept your order, deliver your subscription, or provide membership benefits. Provision of marketing data is voluntary; refusal has no consequence other than that you will not receive the relevant communications.
B.8 Cookies and Tracking Technologies
Our Site uses cookies and similar technologies. Strictly necessary cookies (for login, cart, age-gate, and security) are set on the basis of Art. 6(1)(f) GDPR and the local implementations of Art. 5(3) ePrivacy Directive. All other cookies and tracking technologies are set only with your prior consent (Art. 6(1)(a) GDPR), which you may grant or withdraw via our cookie banner and preference centre. The following table provides an overview:
| Category | Tool / Provider | Purpose | Duration | Legal Basis |
|---|---|---|---|---|
| Strictly necessary | Self-hosted session cookies | Login, cart, age-gate, CSRF, load balancing | Session | Art. 6(1)(f) GDPR / Art. 5(3) ePD |
| Functional | Self-hosted preference cookies | Remembering preferences (language, theme, protocol selections) | Up to 12 months | Consent (Art. 6(1)(a)) |
| Analytics | Google Analytics 4 (GA4) | Measuring site usage to improve content and UX | Up to 13 months | Consent (Art. 6(1)(a)) |
| Marketing | Google Ads (conversion measurement) | Audience building and ad measurement | Up to 13 months | Consent (Art. 6(1)(a)) |
You can manage your preferences at any time through our cookie banner, the “Manage Cookies” link in the site footer, or your browser settings. We honour Global Privacy Control (“GPC”) signals as a request to opt out of “sale” and “sharing” for the originating browser.
B.9 AI Processing and Automated Decision-Making
We use automated processing technologies, including artificial intelligence, in connection with the Site and Services. We inform you about the nature, scope, and purpose of this processing.
| AI System / Technology | Purpose | Decision Type | Legal Basis |
|---|---|---|---|
| AI Research Assistant (powered by Anthropic Claude) | A chemistry-and-handling reference: peptide chemistry, sequence questions, HPLC/MS interpretation, storage and reconstitution, research-paper queries (members only). Refuses human-use, dosing, medical, brand-comparison, and similar out-of-scope queries. | Informational only. Outputs are not automated individual decisions producing legal or similarly significant effects within the meaning of Art. 22 GDPR. Outputs must be independently verified by a Qualified Researcher. | Art. 6(1)(b) GDPR (provision of the Assistant feature); Art. 6(1)(f) (legitimate interest in safety review and improvement). |
| Risk scoring for fraud prevention | Identifying potentially fraudulent or high-risk transactions (e.g., identity mismatch, velocity, geo-anomaly). | Automated screening that may delay or hold an order pending manual review. No legal decision is made solely by the system; a human reviewer makes the final determination. | Art. 6(1)(f) GDPR — legitimate interest in fraud prevention. |
| Personalisation and recommendations | Suggesting relevant research content based on declared research interests. | Recommendations only. No legally significant effect. | Art. 6(1)(a) GDPR (consent) where based on non-essential profiling; Art. 6(1)(b) for in-account research-context personalisation. |
Where an automated decision produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR (for example, definitive refusal of an order solely on automated grounds), you have the right to obtain human intervention, to express your point of view, and to contest the decision. Contact privacy@peptriva.com to exercise this right.
B.9.1 AI Act Transparency
In accordance with Art. 50 of the EU AI Act (Regulation (EU) 2024/1689), we inform you that:
- You are interacting with an AI system when you use the AI Research Assistant. The Assistant is identified as such in the chat interface.
- AI-generated text outputs are produced by a large-language model and may contain errors. We label outputs and remind users to independently verify information before relying on it.
- We do not use the Assistant to make AI-supported decisions that fall within the high-risk categories listed in Annex III of the AI Act.
- Personal data submitted to the Assistant are not used to train third-party generative AI models. We may use prompts and outputs to operate, secure, evaluate, and improve our own service in accordance with Section B.3.
B.10 Data Security and Breach Notification
We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against unauthorised access, loss, destruction, or alteration. These include encryption in transit (TLS 1.2+) and at rest, role-based access controls, audit logging, vendor due diligence, principle-of-least-privilege provisioning, and regular review of our security posture. No system is perfectly secure; we cannot guarantee absolute security.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and, where the risk is high, we will inform affected data subjects without undue delay (Art. 34 GDPR).
B.11 Children’s Data
Our Site and Services are exclusively directed at adult researchers. Access is gated at 21 years of age (which exceeds the minimum age applicable in any EU/EEA Member State or the United Kingdom for information-society services under Art. 8 GDPR), and we require an attestation that you are at least 21 years old and a Qualified Researcher. We do not knowingly collect personal data from anyone under the age of 21.
If we become aware that personal data of a person under 21 has been collected without the required adult capacity, we will delete that data without undue delay. Parents, guardians, or other adults who believe a minor has provided personal data to us should contact privacy@peptriva.com.
B.12 Changes to This Notice
We may update this notice from time to time to reflect changes in legislation, our processing activities, or our service providers. The current version is always available on the Site. We will notify you of material changes by posting a notice on the Site for a reasonable period of time and, where the change is significant or required by law, by direct communication.
B.13 Contact and Supervisory Authorities
If you have any questions about the processing of your personal data or wish to exercise your rights, you can reach us at:
- Privacy inquiries and requests: privacy@peptriva.com
- Postal address: Peptriva, Attn: Privacy, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands
- EU Representative (Art. 27 GDPR): Peptriva Research, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands, email hello@peptriva.com
- UK Representative (Art. 27 UK GDPR): Peptriva Research, 5th Floor, The Piccadilly Centre, 28 Elgin Avenue, George Town, P.O. Box 2575, Grand Cayman KY1-1103, Cayman Islands, email hello@peptriva.com
Supervisory authorities
You may lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement. A directory of EU/EEA supervisory authorities is maintained by the European Data Protection Board at https://edpb.europa.eu/about-edpb/board/members_en. UK residents may complain to the Information Commissioner’s Office (ICO) at https://ico.org.uk.