How we collect, use, and protect your personal data.
Last updated: February 2024
Introduction
Retalabs (“we,” “our,” or “us”) operates the website retalabs.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or make a purchase.
We comply with the General Data Protection Regulation (GDPR) and Dutch data protection laws. By using our website, you consent to the practices described in this policy.
If you have questions about this policy, contact our Data Protection Officer.
What Data We Collect
Personal Information
We collect information you provide directly, including:
- Name and contact details (email, phone, address)
- Company or institution name
- VAT or tax identification number
- Payment information (processed securely by third-party providers)
- Order history and preferences
Automatically Collected Data
When you visit our website, we automatically collect:
- IP address and browser type
- Device information
- Pages visited and time spent on the site
- Referring website
Cookies and Tracking
We use cookies to:
- Maintain your shopping cart
- Remember your preferences
- Analyze site traffic and performance
- Prevent fraud
You can disable cookies in your browser settings; however, this may affect website functionality.
How We Use Your Data
We use your data for the following purposes:
Order Processing
- Fulfill and ship your orders
- Process payments and prevent fraud
- Provide order updates and tracking information
- Handle returns and customer service inquiries
Communication
- Respond to your questions and requests
- Send order confirmations and shipping notifications
- Provide product updates (only with your consent)
- Request feedback or reviews
Legal Compliance
- Meet regulatory requirements for research chemical sales
- Verify research-use intent and institutional affiliation
- Comply with tax and accounting obligations
- Respond to legal requests or court orders
Site Improvement
- Analyze usage patterns to improve our website
- Detect and prevent technical issues
- Enhance security and prevent fraud
We do not sell your personal data to third parties.
Data Sharing
Service Providers
We share data with trusted third parties who perform services on our behalf, including:
- Payment processors (secure transaction handling)
- Shipping carriers (delivery fulfillment)
- Email service providers (order communications)
- Website hosting and analytics providers
These parties access your data only to perform specific tasks and are contractually obligated to protect it.
Legal Requirements
We may disclose your data if required to:
- Comply with applicable laws or regulations
- Respond to valid legal processes or government requests
- Protect our rights, property, or safety
- Prevent fraud or illegal activity
Business Transfers
If Retalabs is acquired or merged, your data may be transferred to the new owner. We will notify you of any such change.
Your Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your data when there is no compelling reason for us to keep it.
Right to Restrict Processing
Request that we limit how we use your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing.
Right to Withdraw Consent
Withdraw consent for data processing where we rely on your consent.
To exercise these rights, email us. We respond within 30 days.
Complaints
If you believe we have violated your privacy rights, you may file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- SSL encryption for all data transmission
- Secure server infrastructure with firewalls
- Regular security assessments and updates
- Access controls limiting who can view personal data
- Staff training on data protection
While we strive to protect your data, no internet transmission is completely secure. We cannot guarantee absolute security.
Data Retention
We retain your personal data only as long as necessary:
- Order information: 7 years (legal requirement for tax and accounting)
- Account details: Until you delete your account or request deletion
- Marketing consent: Until you unsubscribe
- Website logs: 12 months
After these periods, data is securely deleted or anonymized.
Contact
For questions about this Privacy Policy or to exercise your data rights:
Data Protection Officer
Email: [email]
Address: [Your Business Address], Netherlands
We respond to all inquiries within 30 days.