PRIVACY POLICY

NEXYRA RESEARCH LTD.
Research Peptides & Biochemical Compounds
PRIVACY POLICY

Effective Date: March 7, 2026     |     Last Updated: March 7, 2026

Nexyra Research Ltd. ("Nexyra", "we", "us", or "our") is committed to protecting the privacy and personal data of all individuals who interact with our website, products, and services. This Privacy Policy explains how we collect, use, store, share, and protect your personal information, and sets out your rights in relation to that information.
By accessing our website or placing an order with us, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please do not use our website or services.

1. Who We Are & How to Contact Us
Nexyra Research Ltd. is the data controller responsible for your personal data.

Company Name: Nexyra Research Ltd.
Registered Address: 124-128 City Road,
London,
United Kingdom,
EC1V 2NX
Company Registration Number: 17057743
Email: privacy@nexyraresearch.com
Data Protection Officer: Ramez

If you have any questions about this policy or wish to exercise your rights, please contact us using the details above.

2. What Personal Data We Collect
2.1 Data You Provide Directly
When you use our website, create an account, or place an order, we may collect the following categories of personal data:
•    Identity Data: full name, job title, institution or organisation name.
•    Contact Data: email address, telephone number, billing and delivery address.
•    Account Data: username, password (stored in encrypted form), account preferences.
•    Order & Transaction Data: details of products purchased, order history, invoices, payment records.
•    Communications Data: any correspondence you send us, including support enquiries, return requests, and feedback.
•    Compliance & Verification Data: information required to verify your status as a legitimate researcher, including institutional affiliation and any self-certification statements you complete at checkout.

2.2 Data Collected Automatically
When you visit our website, we automatically collect certain technical data, including:
•    Technical Data: IP address, browser type and version, device type, operating system, time zone.
•    Usage Data: pages viewed, links clicked, referring URLs, session duration, and other browsing behaviour on our site.
•    Cookie & Tracking Data: data collected through cookies and similar tracking technologies (see Section 9 for full details).

2.3 Data from Third Parties
We may receive personal data about you from the following third-party sources:
•    Payment processors (e.g., Stripe, PayPal) who confirm payment status and flag fraudulent transactions.
•    Logistics and courier partners who provide delivery status updates.
•    Analytics providers who supply aggregated insights about website usage.
•    Fraud prevention and identity verification services.

3. How We Use Your Personal Data
We use your personal data only where we have a lawful basis for doing so. The table below summarises our primary processing activities:

•    Processing and fulfilling your orders — lawful basis: performance of a contract.
•    Managing your account and providing customer support — lawful basis: performance of a contract.
•    Verifying your eligibility as a research professional — lawful basis: legal obligation and legitimate interests.
•    Processing payments and preventing fraud — lawful basis: legal obligation and legitimate interests.
•    Sending transactional emails (order confirmations, shipping updates, invoices) — lawful basis: performance of a contract.
•    Sending marketing communications where you have opted in — lawful basis: consent.
•    Improving our website, products, and services through analytics — lawful basis: legitimate interests.
•    Complying with legal, regulatory, and tax obligations — lawful basis: legal obligation.
•    Maintaining records for audit purposes — lawful basis: legal obligation and legitimate interests.

We will never use your personal data for purposes that are incompatible with the purpose for which it was originally collected, without first notifying you and, where required by law, obtaining your consent.

4. Research-Use Compliance & Verification
Because our products are sold exclusively for legitimate research purposes, we collect and retain certain data to verify and document purchaser eligibility. This may include institutional affiliations, self-certification declarations, and records of acceptance of our Terms & Conditions. This data is retained for compliance and audit purposes and is not used for marketing.
We may be required to disclose this data to regulatory authorities if lawfully requested to do so.

5. Marketing Communications
We will only send you marketing emails if you have explicitly opted in to receive them. You may withdraw your consent to marketing communications at any time by:
•    Clicking the 'Unsubscribe' link at the bottom of any marketing email.
•    Contacting us directly at privacy@nexyraresearch.com.
•    Updating your communication preferences in your account settings.

Withdrawing your consent to marketing will not affect our ability to send you transactional emails related to your orders, account, or security.

6. Sharing Your Personal Data
We do not sell, rent, or trade your personal data. We may share your data with the following categories of recipients, strictly for the purposes described in this policy:

6.1 Service Providers & Processors
•    Payment processors: to securely handle transactions (e.g., Stripe, PayPal).
•    Logistics and courier companies: to fulfil and deliver your orders.
•    IT infrastructure and cloud hosting providers: to operate and maintain our website and systems.
•    Email and customer communication platforms: to send transactional and marketing emails.
•    Analytics providers: to understand website usage (data is aggregated or pseudonymised where possible).

All third-party processors are required to handle your data in accordance with our instructions and applicable data protection law. We enter into data processing agreements with all processors as required.

6.2 Legal & Regulatory Disclosures
We may disclose your personal data to law enforcement agencies, regulatory bodies, courts, or other authorities where required to do so by applicable law, court order, or where we believe in good faith that disclosure is necessary to protect our legal rights, prevent fraud, or ensure the safety of our staff, customers, or others.

6.3 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of all or part of our business, your personal data may be transferred to the relevant successor entity. We will notify you of any such transfer and any changes to this Privacy Policy that may result.

7. International Data Transfers
Nexyra Research Ltd. is based in the United Kingdom. If we transfer your personal data to a country outside the UK or the European Economic Area (EEA), we will ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the relevant supervisory authority, or that the transfer is to a country deemed to provide an adequate level of data protection.
You may request details of the specific safeguards in place for any international transfers by contacting us at privacy@nexyraresearch.com.

8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. Our general retention periods are as follows:
•    Account and order data: retained for 7 years following your last transaction, in line with standard accounting and tax record-keeping obligations.
•    Customer communications and support records: retained for 3 years after the matter is resolved.
•    Marketing consent records: retained for the duration of the relationship plus 3 years after consent is withdrawn.
•    Research compliance and verification records: retained for 7 years, or as required by applicable regulatory obligations.
•    Website usage and analytics data: retained in anonymised or aggregated form for up to 26 months.

When data is no longer required, it is securely deleted or anonymised in accordance with our data retention schedule.

9. Cookies & Tracking Technologies
9.1 What Are Cookies?
Cookies are small text files placed on your device when you visit our website. We also use similar technologies such as web beacons and pixels. These help us operate our website effectively and understand how visitors interact with our content.

9.2 Types of Cookies We Use
•    Strictly Necessary Cookies: essential for the website to function, including maintaining your session, shopping cart, and security features. These cannot be disabled.
•    Performance & Analytics Cookies: help us understand how visitors use our site, which pages are most popular, and where errors occur. Data is aggregated and anonymous.
•    Functional Cookies: remember your preferences such as language and region settings to personalise your experience.
•    Marketing & Targeting Cookies: used where you have consented, to deliver relevant advertising and track the effectiveness of our campaigns.

9.3 Managing Cookies
You can control and manage cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. You can also opt out of analytics tracking by adjusting your preferences in our cookie consent banner when you first visit the site.

10. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure. These measures include:
•    SSL/TLS encryption for all data transmitted between your browser and our website.
•    Encryption of sensitive data at rest, including payment information and account credentials.
•    Access controls ensuring that only authorised personnel can access personal data, on a need-to-know basis.
•    Regular security assessments and penetration testing of our systems.
•    Staff training on data protection and information security practices.

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

11. Your Rights
Depending on your jurisdiction, you may have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month (or within the extended period permitted by law for complex requests).

•    Right of Access: you have the right to request a copy of the personal data we hold about you (commonly known as a Subject Access Request).
•    Right to Rectification: you have the right to request correction of any inaccurate or incomplete personal data we hold about you.
•    Right to Erasure: in certain circumstances, you have the right to request that we delete your personal data ('right to be forgotten').
•    Right to Restrict Processing: you have the right to request that we limit how we use your data in certain circumstances.
•    Right to Data Portability: where processing is based on consent or contract and is carried out by automated means, you may request a copy of your data in a structured, commonly used, machine-readable format.
•    Right to Object: you have the right to object to processing based on our legitimate interests, and to direct marketing at any time.
•    Rights Related to Automated Decision-Making: you have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects, unless you have given explicit consent or it is necessary for a contract.
•    Right to Withdraw Consent: where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of your rights, please contact us at privacy@nexyraresearch.com. We may need to verify your identity before processing your request. There is generally no fee for exercising your rights, unless a request is manifestly unfounded or excessive.

12. Right to Lodge a Complaint
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the relevant supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO):

Website: www.ico.org.uk
Telephone: 0303 123 1113
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF

We would, however, welcome the opportunity to address your concerns directly before you contact the ICO, and encourage you to contact us in the first instance.

13. Third-Party Websites & Links
Our website may contain links to third-party websites. This Privacy Policy applies only to Nexyra Research Ltd. and does not cover the privacy practices of any external sites we link to. We encourage you to read the privacy policies of any third-party sites you visit, as we have no control over and accept no responsibility for their practices.

14. Children's Privacy
Our website and products are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@nexyraresearch.com and we will take steps to delete such information promptly.

15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post any updated policy on this page with a revised effective date. Where changes are material, we will take additional steps to notify you, such as sending an email or displaying a prominent notice on our website.
Your continued use of our website or services following any update constitutes your acceptance of the revised policy. We encourage you to review this page periodically.