Introduction and Data Controller
Protecting your personal data is important to us. We process your data exclusively within the framework of the applicable legal provisions, in particular the General Data Protection Regulation (GDPR). This Privacy Policy informs you about the type, scope, and purpose of the personal data we collect, how we process it, and the rights available to you.
We follow the principle of data minimisation: we only collect and store the data that is necessary to process your order and operate our online shop.
Data controller (GDPR)
MINCESTRA LIMITED
Room 23/F, Lee Garden Two28 Yun Ping RoadCauseway BayHong Kong- Brand
- Peptide Club
- Website
- www.peptideclub.net
- Contact
- Contact us
What Personal Data We Process
In connection with your order and your use of our website, we process the following data:
- Order and contact data: first and last name, delivery and billing address, email address and – if provided – your telephone number.
- Contract and order data: information about the products you have ordered, order number, order date, and order history.
- Payment data: depending on the payment method selected, payment information is processed via the relevant payment service provider. Complete payment data (e.g. card numbers) is generally processed directly by the payment service provider and is not stored by us.
- Technical data: when you visit our website, technical information is automatically collected, e.g. IP address, browser type, device, and time of access (see the "Cookies" section).
We only collect the minimum information required to deliver your parcel and process the contract.
Purposes of Processing and Legal Bases
We process your data for the following purposes:
- Processing your order and delivery (legal basis: Art. 6(1)(b) GDPR – performance of the contract). This includes transferring the necessary data to shipping service providers and payment service providers.
- Communicating with you regarding your order, e.g. shipping notifications or queries (Art. 6(1)(b) GDPR).
- Email marketing (see Section 4).
- Compliance with legal obligations, e.g. commercial and tax retention requirements (Art. 6(1)(c) GDPR).
- Operating, securing, and improving our website (Art. 6(1)(f) GDPR – legitimate interest).
Email Marketing and Newsletter
We use your email address to send you information, offers, and news about our products. This applies to:
- customers who have made a purchase with us, within the scope of legally permitted marketing to existing customers, and
- individuals who have actively subscribed to our newsletter and have thereby given their consent (Art. 6(1)(a) GDPR).
You may object to receiving marketing emails at any time or withdraw your consent at any time, without incurring any costs other than the transmission costs according to the basic rates. To do so, simply contact us or use the unsubscribe link contained in every email.
Telephone Number
If you provide us with your telephone number, we will use it exclusively for the purposes of order processing and delivery (e.g. for queries or for the shipping service provider to make contact). Providing your telephone number is generally voluntary.
Disclosure to Third Parties
Your data is only disclosed where this is necessary for the performance of the contract or permitted by law, in particular to:
- shipping service providers (e.g. DHL) for the delivery of your order,
- payment service providers for processing payment,
- service providers who support us in operating the website (e.g. hosting, IT, email distribution), in each case on the basis of corresponding data processing agreements.
We do not otherwise disclose or sell your data to third parties.
Retention Period
We only store your personal data for as long as is necessary for the stated purposes or for as long as we are legally required to retain it (in particular tax and commercial retention periods). After these periods expire, the data is deleted.
Your Rights
Within the framework of the legal provisions, you have the right at any time to:
- access the data we process (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure of your data (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to the processing (Art. 21 GDPR),
- withdraw any consent given with effect for the future.
To exercise your rights, an informal message via our contact form is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority.
Data Security
We take appropriate technical and organisational measures to protect your data against loss, misuse, and unauthorised access. Transmission via our website is encrypted (SSL/TLS).
Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy in order to adapt it to changes in the legal situation or to changes in our offering. The current version published on this website applies in each case.
Contact
For data protection questions or to exercise your rights, contact us.