Information we collect
The European Peptide Evidence Brief form collects a first name and email address. A phone number and country are optional. The form also records the email-consent choice, the separate mobile-consent choice, the consent wording version and timestamp, the source page and any UTM source, medium or campaign values already present in the page address. A hidden honeypot field is used to reduce automated spam and is not used for profiling.
Why we use it
Email details are used to send requested supplier assessments, ranking changes, documentation alerts and evidence-verification guides. The lawful basis for this direct email marketing is the subscriber’s explicit consent. A phone number must not be used for mobile alerts unless the separate mobile-consent box was selected. Consent records are kept so the publisher can demonstrate when and how permission was given.
Withdrawal and unsubscribe
You may withdraw either consent at any time. Every marketing email must provide an unsubscribe route. Until the controller’s verified privacy contact is published below, the policy cannot be treated as legally final.
Service providers and transfers
Netlify hosts the website and receives newsletter submissions as a data processor on the publisher’s instructions. Account-specific sub-processors, storage locations and any transfer mechanism outside the European Economic Area must be confirmed against the publisher’s Netlify agreement and current service configuration before final legal approval. No external CRM has been connected by this implementation.
Retention and security
Subscriber access is limited through the hosting account, and submissions are transmitted over HTTPS. A verified retention and deletion schedule has not yet been supplied. The publisher must configure and document one before this policy receives final legal approval.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability, and you may withdraw consent without affecting processing already carried out. The controller identity, registered address, privacy contact and relevant supervisory authority must be added once verified.
Information still required from the publisher
| Required item | Current status | Why it is needed |
|---|---|---|
| Legal data-controller identity and registered address | Not supplied | Identifies who determines the processing |
| Privacy and data-rights contact | Not supplied | Provides a verified withdrawal and rights-request channel |
| Subscriber retention and deletion period | Not supplied | Defines when Netlify form data is removed |
| Netlify account region, DPA and current sub-processors | Account verification required | Completes processor and international-transfer disclosures |
| Relevant supervisory authority | Jurisdiction not supplied | Completes complaint information |
