Privacy Policy
Last updated: March 2026
CERTALAB S.R.L., operating as CertaPeptides (“we”, “our”, “us”), is committed to protecting the privacy and personal data of our customers and website visitors in accordance with the General Data Protection Regulation (GDPR) and applicable EU privacy laws.
Data Controller
The data controller responsible for your personal data is:
CERTALAB S.R.L.
Intr. Gheorghe Simionescu, Nr. 19, Ap. B26
Bucuresti, Sectorul 1, Romania
Email: privacy@certapeptides.com
Phone: +40 750 437 038
Website: certapeptides.com
What Data We Collect
We collect personal data necessary to process your orders and provide our services: name and contact information (email, phone, address), billing and shipping addresses, payment information (processed securely by our payment providers — we do not store card details), order history and product preferences, communication records when you contact our support team, and website usage data through cookies (see our Cookie Policy).
How We Use Your Data
We process your personal data for the following purposes: fulfilling and shipping your orders (contractual necessity), processing payments (contractual necessity), communicating about your orders and account (contractual necessity), sending marketing communications (with your consent), improving our website and services (legitimate interest), complying with legal and regulatory obligations (legal obligation), and fraud prevention and security (legitimate interest).
Your Rights Under GDPR
As an EU resident, you have the right to: access your personal data, rectify inaccurate data, request erasure of your data (“right to be forgotten”), restrict processing of your data, data portability (receive your data in a portable format), object to processing based on legitimate interest, and withdraw consent at any time where processing is based on consent. To exercise any of these rights, please contact us at privacy@certapeptides.com.
Data Retention
We retain your personal data only as long as necessary: order and transaction data for 7 years (tax/legal requirements), account data until you request deletion, marketing consent records until withdrawal, and website analytics data for 26 months.
Third-Party Sharing
We share data only with: payment processors for transaction processing, shipping carriers for order delivery, analytics providers (PostHog, Google Analytics — with your consent) for website improvement, error tracking (Sentry — with your consent) for site reliability, Cloudflare for website security and performance, and email service providers for order confirmations and marketing. We do not sell or rent your personal data to third parties.
Analytics and Error Tracking
With your consent (via our cookie banner), we use the following analytics and monitoring tools:
- PostHog (EU-hosted at eu.i.posthog.com): Website analytics including page views, navigation patterns, and session recordings (with all form inputs masked). Data is processed in the EU. PostHog only loads after you click “Accept All” on our cookie banner.
- Sentry (EU-hosted at ingest.de.sentry.io): Frontend error tracking to identify and fix website issues. Captures JavaScript errors with session context (all text inputs masked). Sentry only loads after you click “Accept All” on our cookie banner.
- Cloudflare: Our website uses Cloudflare for security, performance, and DDoS protection. Cloudflare processes technical data (IP addresses, request headers) as a data processor.
If you choose “Essential Only” or “Reject All” on our cookie banner, no analytics or error tracking scripts will be loaded. You can change your cookie preferences at any time by clicking “Manage Cookies” in our website footer.
Contact
For privacy inquiries:
CERTALAB S.R.L.
Email: privacy@certapeptides.com
Phone: +40 750 437 038
Intr. Gheorghe Simionescu, Nr. 19, Ap. B26, Bucuresti, Sectorul 1, Romania
You also have the right to lodge a complaint with your local data protection authority.