Legal
Privacy policy
Controller
The controller of personal data described in this policy is Dohrna Research Supplies Limited, registered in Malta under company number C 116978, registered office 4th Floor Kingsway Palace, Triq ir-Repubblika, Valletta VLT 1115.
Data protection contact: dpo@dohrna.com.
What this site does with personal data, in one paragraph
This site sells laboratory reagents for research use to customers in the United States. It takes an order, records the research-use declaration that accompanies it, and passes the order to the supplier and the carrier. It keeps a first-party record of a small number of events so that the business can see whether the shop works. It runs no advertising, no third-party analytics and no tracking script of any kind. Everything below is the detail of that paragraph.
Categories of personal data
| Category | Examples | Source |
|---|---|---|
| Account identity | Name, email address, password (stored only as a salted hash) | The account holder |
| Delivery and contact details | Recipient name, delivery address, telephone number, email address; saved addresses on an account | The customer |
| Declaration records | The typed full name used to sign the research-use declaration, the text and version signed, the timestamp, the IP address and the browser identification string at the time of signing | Captured automatically when the declaration is signed |
| Order records | Products ordered, quantities, prices, destination, order reference, the text of the order message, referral code where one was recorded | Generated by the transaction |
| Usage events | The kind of event (an order recorded, a destination refused, a referral link opened, an account action), the page it happened on, the time, the detected country of the connection, and a salted one-way hash of the session identifier where one exists | Generated by the site, first-party |
| Connection details | The country the connection was detected from, and — only where the check is enabled — whether the connection appears to be routed through a VPN or proxy | Derived from the connection at the edge of the network |
| Referral attribution | A referral code carried in a link, stored in the browser for sixty days and attached to an order placed within that window | The link the customer arrived by, or a code typed at checkout |
| Correspondence | Enquiries and the answers given, by email or in the ordering conversation | The customer |
| Payment metadata | None at present. No card payment is taken on this site: an order is recorded here and settled by arrangement in the ordering conversation. When a payment service provider is engaged, the card scheme, the last four digits and the authorisation outcome will be received from that provider and this table will say so | — |
Full card numbers are never received or stored by the controller under any arrangement.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Taking and fulfilling the order, and operating an account where one is opened | Art. 6(1)(b) — contract |
| Recording and retaining the research-use declaration as evidence of the conditions of supply | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interests |
| Applying destination and end-use controls, and sanctions and embargo screening | Art. 6(1)(c) — legal obligation |
| Detecting the country of a connection so that the site shows the correct supply position | Art. 6(1)(f) — legitimate interests |
| Reduction of fraud and payment-dispute risk | Art. 6(1)(f) — legitimate interests |
| Product safety, traceability and incident notification | Art. 6(1)(c) — legal obligation |
| Counting orders, refusals and referral arrivals in a first-party event record | Art. 6(1)(f) — legitimate interests |
| Paying affiliate commission on attributed orders | Art. 6(1)(b) — contract (with the affiliate); Art. 6(1)(f) — legitimate interests |
| Non-essential cookies and similar technologies, should any be introduced | Art. 6(1)(a) — consent |
Purchase history is handled as sensitive
A person's ordering history is capable of supporting an inference about the health status of an identifiable person. The controller therefore handles ordering history under the heightened standard that would apply to special-category data, whether or not it constitutes such data in law.
In practical terms:
- ordering history is never used for advertising, audience building or retargeting;
- ordering history is never disclosed, licensed or sold to a third party;
- access within the controller is limited to operators with an operational need;
- the first-party event record carries no name, email address or delivery address — an event names an order reference, a destination country and a referral code at most;
- retention is limited to the periods stated below.
Recipients
Personal data is disclosed to the following processors, each under a written Art. 28 agreement or the provider's standard data-processing terms:
- Hosting — Vercel Inc. (United States), which serves the site and runs its server-side code.
- Database — Neon Inc. (United States; the database is located in the AWS us-east-2 region), which holds accounts, orders, declarations and the event record.
- Backups — an encrypted copy of the database is written nightly to an object-storage provider. The copy is encrypted before it leaves the controller's systems and the provider cannot read it.
- Ordering conversation — where the customer chooses to send the prepared order message, it is sent through WhatsApp, a service of Meta Platforms, under that service's own terms. The order exists in the controller's records whether or not the message is sent.
- Operations record — order and affiliate records are mirrored to Notion Labs, Inc. (United States) for operational use by the controller's staff.
- Carrier — the carrier receives the recipient name, delivery address and telephone number needed to deliver the consignment, and the customs documentation where the destination requires it.
- Connection check — where the VPN and proxy check is enabled, the connecting IP address is sent once to proxycheck.io (United Kingdom) and the verdict is kept in a cookie for thirty days. The check is not enabled unless a key is configured; this policy is updated when it is.
- Email delivery — transactional email (password reset, order acknowledgement) is sent through an email delivery provider once one is configured; until then the site composes such messages and sends none.
- Payment service provider — none at present; named here when engaged.
Personal data is disclosed to public authorities where a legal obligation applies, including customs authorities, medicines regulators and law-enforcement authorities acting under lawful powers.
Transfers outside the EEA
The controller is established in Malta. Hosting, the database and the operations record are located in the United States. Those transfers are made under the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise under Standard Contractual Clauses adopted by the European Commission, supported by a transfer impact assessment. A list of processors, their locations and the transfer basis for each is available on request from dpo@dohrna.com.
Retention
| Record | Retention period |
|---|---|
| Account records | Duration of the relationship, then 6 years |
| Declaration and consent records | 6 years from the signature |
| Order and traceability records | 10 years from placing the Product on the market |
| Usage events | 24 months from the event |
| Connection-check cookies | 30 days |
| Referral attribution in the browser | 60 days from the link being opened |
| Payment metadata, when any | 13 months, aligned to the dispute window |
| Correspondence | 3 years |
| Encrypted backups | 30 days, on a rolling basis |
Rights of the data subject
A data subject has the right to request access to personal data, rectification, erasure, restriction of processing, portability, and to object to processing carried out on the basis of legitimate interests. Where processing rests on consent, consent may be withdrawn at any time without affecting the lawfulness of processing already carried out. Declaration and order records that the controller is required to retain as evidence of the conditions of supply are retained for the period stated above notwithstanding a request for erasure, and the request is answered with an explanation of that basis.
Requests should be addressed to dpo@dohrna.com and are answered within one month.
Complaints to the supervisory authority
A data subject may lodge a complaint with the Office of the Information and Data Protection Commissioner (IDPC), Malta. Contact details are published by that authority.
Automated decision-making
Automated checks are applied when an order is placed: the destination is checked against the allow-list for each compound ordered, the buyer name and destination are screened against sanctions and embargo lists, and the delivery address is screened for patterns the site does not serve. A check that fails refuses the order and states the reason on the screen; nothing is recorded for a refused order beyond the event that it was refused and why. No order is refused or accepted on the basis of profiling, and a refusal may be raised with a person by writing to support@dohrna.com.
Where a business customer supplies a VAT identification number, it is checked against the European Commission's VIES service and the consultation reference is retained.
Security
Transport is protected with TLS. Passwords are stored as salted hashes and are never held in clear. No card data reaches the controller's systems. Access to account and order records is restricted by role and by password. A content security policy permits no third-party script origin, so no tracking or advertising script can be introduced to the site by a tag manager or by a change to page markup alone. Backups are encrypted before they leave the controller's systems.
Breach notification
A personal data breach that meets the Art. 33 threshold is notified to the Office of the Information and Data Protection Commissioner (IDPC), Malta within 72 hours of the controller becoming aware of it, and affected data subjects are informed where Art. 34 applies.
Records of processing
The controller maintains records of processing activities under Art. 30 and a register of processors and their agreements.
Changes
Material changes to this policy are notified to account holders by email. The version in force is the version published on this page.
