Skip to main content

Privacy Policy

What personal data DNA-LABS collects, why, who else sees it, how long we keep it, and the rights you have over it.

Last reviewed: 14 August 2026

Who is responsible

DNA-LABS ([REGISTERED COMPANY NAME AND ADDRESS — to be completed]) is the controller of the personal data described here. If you have a question about this policy, or want to exercise any of the rights below, use the contact address at the end of this page.

What we collect

Account — your name, email address, and your password, which is stored only as a salted hash and is never readable by us. Orders — the shipping name, address, phone number and email you enter, what you ordered, your order history, and the payment reference our payment processor returns. Compliance — your confirmation that you are 21 or over and ordering for laboratory research, the date and the exact wording you agreed to, and a date of birth if you choose to give one. Technical — your IP address when you sign in, used to limit repeated attempts, and a record of account events such as sign-ins, profile changes and password changes. Stored in your browser rather than by us — your cart, language, theme and recent searches. We never receive or store your card details.

Why we use it, and on what legal basis

To perform our contract with you: processing, shipping and supporting your order, and keeping a record of what was supplied. To meet legal obligations: holding the age and research-use confirmation, and retaining sales records for tax and accounting. For our legitimate interests in keeping the service secure and working: limiting repeated sign-in attempts and preventing abuse. With your consent, for anything optional: error-monitoring telemetry, and marketing email if we ever send it. We do not sell your personal data, and we do not make automated decisions about you or profile you.

Who else processes it

Stripe processes payments and receives your email address and order total; your card details go straight to Stripe and never reach our servers. Sentry receives error reports, which can include your IP address and account identifier — this runs only if you accept optional storage in the cookie banner. Cloudflare serves our product images, so it sees your IP address as your browser loads them. Our hosting and database providers store data on our behalf. Each of them acts on our instructions under a data-processing agreement, and none of them may use your data for their own purposes.

Transfers outside the EEA

Some of those providers process data outside the European Economic Area, including in the United States. Where that happens, the transfer relies on the European Commission's standard contractual clauses or on an adequacy decision covering the country concerned.

How long we keep it

Order records — including the shipping details captured at the time of the order — are kept for as long as tax and accounting law requires, and are retained even if you close your account, for that reason. Account details are kept while your account is open. The record of account events is kept as evidence of the confirmations and consents you gave. Sign-in sessions expire after one hour, and the credentials that renew them after seven days. The age confirmation and language choice stored in your browser last one year, and you can clear them from your browser at any time.

Cookies and browser storage

Strictly necessary storage always runs, because the site does not function without it: your sign-in and security cookies, the age and research-use confirmation, your cart, and your language and theme choices. Optional storage runs only if you accept it: error-monitoring telemetry sent to Sentry, which can include your IP address. You choose when you first arrive, and you can change your mind at any time using "Cookie preferences" in the footer. Declining, or withdrawing later, stops optional telemetry from starting.

How we protect it

Connections are encrypted in transit. Passwords are stored only as salted bcrypt hashes. The tokens that authenticate you to our backend are held inside an encrypted, HTTP-only session cookie and are never exposed to code running in your browser. Access to production data is limited to the people who need it.

Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict how we use it, or to send it to another provider in a portable format. You can object to processing we base on our legitimate interests, and you can withdraw any consent you have given — withdrawal does not affect what we did while the consent was in place. We will respond within one month. You can delete your saved address yourself at any time from your profile. Some order information has to be retained for tax purposes and cannot be erased on request; if that applies to you we will tell you which parts and why.

Complaints

If you think we have handled your data wrongly, please raise it with us first so we have the chance to put it right. You also have the right to complain to a data protection supervisory authority. In Greece that is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens, dpa.gr.

Children

This site is not intended for anyone under 21, and we do not knowingly collect personal data from children. If you believe a minor has given us personal data, contact us and we will delete it.

Changes to this policy

If we change how we handle personal data we will update this page and the review date at the top. Where a change needs your consent, we will ask for it before it takes effect.

Contact us

For any privacy question, or to exercise any of the rights above, email:

[email protected]