Document
PRIVACY-POLICY
Privacy Policy
What we collect when you order, why we hold it, and what we deliberately do not do with it.
Last updated [DATE]
Pending legal review
This document has been drafted for review and has not yet been checked by a lawyer qualified in data protection law. Highlighted fields remain to be completed, and the list of processors in section 7 must be finalised with the actual providers in use. Remove this notice once the review is complete.
This policy explains how personal data is handled when you use xvmolecular.com and when you place an order with us. It is written to meet Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Croatian Act on the Implementation of the GDPR. We have tried to describe what actually happens rather than to describe the most flattering version of it.
Section 1Who is the controller
The controller of the personal data described here is [LEGAL ENTITY NAME], a sole trader (obrt) registered in the Republic of Croatia, trading as XV Molecular.
- Controller
- [LEGAL ENTITY NAME]
- Crafts Register no.
- [MBO / REGISTER NUMBER]
- Contact for privacy matters
- [CONTACT EMAIL]
- Registered office
- [REGISTERED ADDRESS]
We are a small operation and we are not required to appoint a data protection officer, so we have not appointed one. Privacy questions and requests go to the contact address above and are handled by the controller directly.
Section 2What we collect
We collect what an order actually requires, and we would rather list it precisely than describe it in general terms.
- Name and delivery address. Needed to address the parcel and to hand it to the carrier. Without it there is no delivery.
- Email address. Used to send the order confirmation, payment instructions, the invoice, dispatch and tracking information, and to answer you if you write to us.
- Telephone number — optional. Collected only if you choose to give it, so that the carrier can reach you about a delivery and, where you have asked for it, so that we can send an SMS notification about your order. You can order without giving a number.
- Order details. The items, quantities, prices, the euro total, the shipping option, the order number and the date, the invoice issued for the order, and the tracking number once the parcel is handed over.
- Payment data. The deposit address generated for your order, the cryptocurrency and network used, the amount, and the transaction identifier recorded on the public ledger. Where a refund or return of funds is made, the destination address you confirm to us. See section 11.
- Correspondence. Messages you send us and our replies, including complaints and withdrawal notices, together with anything you attach to them.
- Technical data generated by serving the website. Our web server, like any web server, processes the IP address, the time of the request, the page requested and the browser's user-agent string in order to deliver the page and to keep the service secure and available.
We do not ask for and do not want special categories of data — health data in particular. Please do not send us medical or health information; it is not relevant to a research-use order, and if you send it anyway we will delete it once the message it belongs to has been dealt with.
You do not create an account to order, so there is no password and no profile held with us. Giving the data listed above is a contractual necessity: if you do not provide it, we cannot conclude or perform the sale.
Section 2aAbandoned checkout
This one is easy to miss, so it gets its own section.
While you are filling in the checkout, your email address and phone number are sent to our server as you type them — shortly after you stop typing, and before you press the button to place the order. They are stored together with what is in your basket and its value.
The purpose is narrow: if you leave the checkout without finishing, we are able to send you one reminder. Nothing else is captured this way — not your name, not your address, not your postcode.
Legal basis: our legitimate interest in recovering an incomplete order (GDPR Article 6(1)(f)). You can object to it at any time under Article 21, and we will delete the record.
How to avoid it entirely: complete the checkout in one go, or write to us and we will erase the entry. A record that never turns into an order is deleted once it is no longer capable of serving that purpose, and in any case is not kept beyond the retention period in Section 6.
Section 3What we do not collect
Deliberate omissions
- No third-party analytics. We do not use Google Analytics or any other external analytics or measurement service.
- No tracking cookies. We set no advertising, profiling, remarketing or cross-site tracking cookies, and there are no social media tracking pixels or advertising tags on the site.
- No profiling. We do not build behavioural profiles of visitors and we take no decisions about you by automated means that produce legal or similarly significant effects.
- We do not sell personal data, and we do not share it with advertisers, data brokers or list vendors — for money or otherwise.
- No marketing without your request. We do not add customers to a mailing list as a side effect of ordering.
- No card or bank data. Payment is in cryptocurrency, so we never receive card numbers, bank account details or the identity documents a payment processor would demand.
These are choices, not accidents, and they are the reason this policy is short. If any of them changes, this document changes with it and the date at the top moves.
Section 4Legal basis
Every processing operation described here rests on one of the following grounds.
- Performance of a contract — Article 6(1)(b) GDPR. Name, address, email, order details, payment and shipping data are processed because they are necessary to conclude and perform your purchase: to confirm the order, take payment, dispatch the parcel, and deal with returns, withdrawals and complaints.
- Legal obligation — Article 6(1)(c) GDPR. Invoices and the accompanying accounting records are processed and retained because Croatian accounting and tax legislation requires it.
- Legitimate interests — Article 6(1)(f) GDPR. Server logs and basic security measures are processed in our legitimate interest in keeping the website available and protecting it and our customers against attack, fraud and abuse; and we may retain records of a transaction where they are needed to establish, exercise or defend a legal claim. We have weighed these interests against your rights and consider the processing limited and expected.
- Consent — Article 6(1)(a) GDPR. Used only where you actively opt in to something, such as an SMS notification about your order. Consent can be withdrawn at any time, with effect for the future.
Section 5How we protect it
Customer data held in our order database is stored encrypted, and access to it is restricted to the people who need it in order to fulfil orders and answer customers. The website is served over HTTPS, so data you submit is encrypted in transit. Administrative access is protected by authentication and is not shared.
We would rather be exact than impressive: this is a small operation, and the measures above are the measures we have. We do not claim full-disk encryption of the servers, a formal information security certification, or a security operations team, because we do not have them. No system is perfectly secure, and no one can honestly promise that it is. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Croatian supervisory authority within 72 hours as Article 33 GDPR requires, and we will tell affected customers directly where Article 34 requires it.
Section 6How long we keep it
- Invoices and accounting records. Kept for the retention period that Croatian accounting and tax legislation prescribes, calculated from the end of the business year to which the record relates. This is a legal obligation: we cannot delete these records on request before the period expires, and a request for erasure of an invoice will be refused for that reason.
- Order and delivery records. Kept while the order is being performed and afterwards for as long as claims arising from it may still be made — chiefly the statutory periods for defect liability and the general limitation period — after which they are deleted or reduced to the accounting record.
- Correspondence. Kept while the matter is open and for a reasonable period afterwards so that we can answer follow-up questions, then deleted.
- Server logs. Kept only for the short period needed for security and diagnostics, then rotated out.
- Phone number given for SMS notification. Deleted once the order it relates to has been delivered and the return and withdrawal periods have passed, unless you have asked us to keep it.
When a retention period ends the data is deleted, or anonymised so that it can no longer be linked to you.
Section 7Who else sees it
Personal data leaves us only where an order cannot be performed otherwise, and only the part that is genuinely needed.
- The carrier. The postal operator that carries your parcel — for shipments handed over in Croatia, Hrvatska pošta — receives your name, delivery address and, where you gave one, your telephone number. It has to: a parcel cannot be addressed or delivered without them. The carrier processes those details as a controller in its own right for the purposes of the postal service, and in the destination country the shipment is handled by the local postal operator and, where applicable, by customs.
- Our email provider. The service that sends and stores our mail necessarily processes your email address and the content of the messages exchanged with you.
- Hosting and infrastructure. The provider that hosts the website and the order database stores the data on our behalf. Any provider that stores or transmits data for us acts as a processor on our instructions, under a written agreement meeting Article 28 GDPR, and may not use the data for its own purposes.
- Our accountant. Invoices and accounting records are processed by the bookkeeping service that prepares our statutory accounts and tax filings.
- Public authorities. Customs, tax and other authorities receive data where a law requires disclosure — for example customs data accompanying an international shipment.
Nobody outside this list receives your personal data, and nobody on it is permitted to use it for their own marketing.
Section 8International transfers
We ship worldwide, with the exception of the United States, so an order to a destination outside the European Economic Area necessarily involves sending your name and address to that country: to the local postal operator that completes the delivery, and to the customs authority that clears the shipment. That transfer is necessary for the performance of the contract you have concluded with us, and where no adequacy decision covers the country concerned it relies on Article 49(1)(b) GDPR. Once your details are in the hands of a foreign postal operator or customs authority, the protection they receive is the protection of that country's law, which may be weaker than the protection of EU law. Ordering to such a destination means accepting that.
Where a processor we use stores data outside the EEA, the transfer is made under an adequacy decision or under the European Commission's standard contractual clauses. Section 11 describes the separate and quite different situation of blockchain data, which is public everywhere by design.
Section 9Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy of it, with information about how it is processed;
- rectification of data that is inaccurate or incomplete;
- erasure where the data is no longer needed for the purpose it was collected for, or is processed unlawfully — subject to records we are legally required to keep, chiefly accounting documents;
- restriction of processing while a dispute about accuracy or lawfulness is resolved;
- data portability — to receive the data you gave us, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible;
- object to processing based on our legitimate interests, on grounds relating to your particular situation; and
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out beforehand.
To exercise any of these, write to [CONTACT EMAIL]. Please give the order number or the email address used for the order so that we can find the right records; where we cannot identify you from what you send, we may ask for further information, but we will not demand identity documents as a matter of routine. We answer within one month, as Article 12 GDPR requires, and will tell you if that period has to be extended for a complex request. Exercising your rights is free of charge.
Right to complain
If you believe your data has been handled unlawfully you may lodge a complaint with the Croatian supervisory authority — Agencija za zaštitu osobnih podataka (AZOP), the Personal Data Protection Agency of the Republic of Croatia, azop.hr — or with the supervisory authority of the EU or EEA state in which you live or work. You may also bring proceedings before a court. We would appreciate the chance to put a problem right first, but nothing obliges you to come to us before going to the regulator.
Section 10Cookies and local storage
The site uses only storage that is strictly necessary for the functions you have asked for. There is no consent banner because there is nothing here that requires consent.
| Key | Purpose |
|---|---|
| xvm_cart | Browser local storage. Remembers the items in your basket so that they are still there if you reload the page or come back later. |
| xvm_age_ok | Browser local storage. Records that you have confirmed the research-use and age statement shown when you enter the site, so that you are not asked again on every page. |
Both entries are stored in your own browser, on your own device. They are not sent to third parties, they contain no identifier that lets anyone track you across other websites, and no advertising or analytics service can read them. You can clear them at any time through your browser's settings for site data; the only consequence is that your basket empties and the entry confirmation appears again.
The site is served without third-party fonts, scripts or embeds loaded from external domains, so viewing a page does not disclose your visit to anyone else.
Section 11Blockchain notice
Please understand this before you pay
A cryptocurrency payment is recorded on a public, permanent ledger that we do not control and cannot alter. The deposit address, the sending address, the amount and the time of the transaction are visible to anyone in the world, for as long as that network exists. We cannot delete, correct or restrict that record — not for you, not for ourselves, not on the instruction of a court. No one can.
This has consequences worth stating plainly. Blockchain records do not carry your name, but a wallet address can in some circumstances be linked to a person, by us or by anyone else analysing the chain — particularly where the same address is also used elsewhere in a way that identifies its owner. Your right to erasure and your right to rectification cannot be exercised against the public ledger, because we are not in a position to give effect to them there; they apply in full to the copy of the transaction data held in our own records.
What we do hold, and can act on, is the link between a transaction and an order: the deposit address we generated for you, the transaction identifier, and the order it belongs to. That link is processed to verify payment and to keep the accounting records the law requires, and it is subject to the retention periods in section 6.
We issue a fresh deposit address for every order rather than reusing one, which limits how much of our order flow is visible to an outside observer of the chain. If public visibility of a payment matters to you, consider it before you send funds, and consider which wallet you send from.
Section 12Changes and contact
We may update this policy when what we do changes — a new processor, a new function on the site, or a change in the law. The current version is the one published on this page, with the date at the top. Where a change is significant we will make it visible on the site rather than relying on you to notice the date. Changes are not retroactive: data already collected continues to be handled on the basis described when it was collected, unless a new legal ground applies.
For any privacy question or request, write to [CONTACT EMAIL], or by post to [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. The commercial side of your purchase is covered by our Terms of Sale.
All products sold by XV Molecular are intended strictly for laboratory and research purposes. Not for human consumption. Not for veterinary use. Products are not available to U.S. residents.
Privacy Policy · last updated [DATE]