1. Who we are
Genexis Health Ltd. is the data controller for personal data collected through this website. You can reach us at research@genexishealth.uk.
2. What we collect
Information you give us
- Order and contact details: full name, email address, mobile number and delivery address.
- Compliance declarations: a record of the research-use confirmations you complete and the date and time each was given.
- Any information you send us in response to a query about an order.
- Correspondence you send to our support or compliance addresses.
When you place an order these details are transmitted to and stored in our order database, hosted by Supabase. They are not held only in your browser.
Information collected automatically
- Standard server log data, including IP address, browser type and pages requested;
- Local storage entries recording that you completed the site entry confirmation and the contents of your current order. These stay in your browser and are not transmitted to us unless you submit an order.
- Aggregate site statistics collected by Cloudflare Web Analytics — page views, referring site, country, browser and device type. This is measured without cookies and without any cross-site identifier, so it cannot follow you to other websites and does not build a profile of you. We see totals, not individuals.
We do not collect payment card details through this website. Payment is handled separately once an order is approved, through a payment provider that processes those details directly.
3. Why we use it
- To review, accept, fulfil and deliver your order;
- To keep a record of the compliance declarations you made — this is central to how we operate lawfully;
- To respond to enquiries and provide support;
- To keep the records we are required to keep for tax, accounting and regulatory purposes;
- To detect and prevent misuse of our products, fraud, and attempts to circumvent our research-use controls;
- To comply with legal obligations, including export control and sanctions screening.
We do not sell personal data, and we do not use it for behavioural advertising.
4. Our lawful basis
- Performance of a contract — processing your order and delivering goods.
- Legal obligation — tax and accounting records, export control screening, and any disclosure we are required by law to make.
- Legitimate interests — retaining compliance declarations, preventing misuse of our products, and protecting our business. We consider these interests are not overridden by your rights, given the safety risk that misuse presents.
- Consent — where you opt in to any optional communication.
5. Who we share it with
We share personal data only where necessary, with:
- Shipping carriers and customs authorities, to deliver and clear your order;
- Payment providers, to raise and process a payment request;
- Netlify, which hosts this website and runs the code that receives your order;
- Supabase, which hosts the database holding order records and the compliance declarations attached to them;
- Cloudflare, which provides the cookieless analytics described above;
- Professional advisers — accountants, auditors and lawyers — under duties of confidentiality;
- IT and hosting providers acting as our processors under written contract;
- Regulators, law enforcement or emergency services, where we are legally required to disclose or where we consider there is a serious risk to someone's safety.
6. How long we keep it
- Order records and compliance declarations: retained for a minimum of six years from the date of the order. Declarations are our evidence that supply was made on a research-use basis, so we retain them for the full period.
- Analytical and lot records: five years from release.
- Correspondence: up to three years, unless it forms part of an order or compliance record.
- Refused orders and blocked accounts: retained as long as necessary to enforce the block and defend any claim.
7. International transfers
Where we transfer personal data outside your country, we do so using an approved transfer mechanism — an adequacy decision, or standard contractual clauses with appropriate supplementary measures. You may request details of the mechanism used.
8. Your rights
Subject to the applicable regime, you may have the right to:
- Access the personal data we hold about you;
- Have inaccurate data corrected;
- Request erasure, where we have no overriding basis to retain it;
- Restrict or object to processing;
- Receive your data in a portable format;
- Withdraw consent where processing is based on consent.
Please note that we will normally decline a request to erase compliance declarations attached to a completed order. Those records establish the basis on which we lawfully supplied a controlled research material, and we have an overriding legitimate interest and, in some cases, a legal obligation in retaining them for the retention period stated above.
To exercise a right, email research@genexishealth.uk. We respond within one month and may need to verify your identity first.
9. Cookies and local storage
This site does not use advertising or third-party tracking cookies. It uses your browser's local and session storage for three strictly functional purposes:
-
gx.gate— records that you completed the site entry confirmation, with the policy version and timestamp, so you are not asked again for 90 days; gx.cart— the contents of your current order;-
gx.cartAckandgx.lastOrder— session-only entries supporting the checkout declaration and your order confirmation page.
These never leave your browser unless you submit an order — at which point your order details and the record of the declarations you completed are sent to our order database. Clearing your browser storage removes the local entries, and you will be asked to complete the entry confirmation again.
Our analytics come from Cloudflare Web Analytics, which sets no cookies and uses no cross-site identifier. That is deliberate: we can see how many people visit without tracking anyone, and without putting a consent banner in your way.
We load web fonts from Google Fonts, which means your browser makes a request to Google's servers when you load a page. If you would prefer we self-host fonts instead, let us know.
10. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls limiting order data to staff who need it, and retention limits. No system is perfectly secure; if a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required.
11. Contact and complaints
Contact research@genexishealth.uk with any privacy question. If you are not satisfied with our response, you may complain to the data protection supervisory authority in your country. In the UK this is the Information Commissioner's Office; in the EU it is your national data protection authority.