Privacy Policy
Explore our high-purity peptides with guaranteed 99%+ purity.
Privacy Policy
Last updated: 30 August 2026
Introduction
This Privacy Policy explains what personal data we process when you visit beyond-peptides.com, create an account, place an order, subscribe to our newsletter or contact us. It also explains the legal basis for each processing activity, who receives your data, how long we keep it and which rights you have under the EU General Data Protection Regulation (GDPR).
Our shop is addressed to professional users and research institutions. All products are sold for laboratory research use only and are not intended for human consumption. We do not knowingly address our services to consumers buying for private use or to anyone under 18 years of age.
We do not sell your personal data, and we do not pass it on to third parties so that they can advertise to you on their own behalf.
1. Who is responsible for your data
The controller for the processing described here is:
FORGETRADE LIMITED (trading as Beyond Peptides)
Flat 2304, 23/F Ho King Commercial Centre
2-16 Fa Yuen Street, Mong Kok, Hong Kong
Company Registration Number 80355843 (Companies Registry, Hong Kong)
Email: [email protected]
Please use this email address for any question about this policy and for every request concerning your rights. Further company details are available in our Imprint.
Companies involved in the order process. Some steps of the order process are handled for us by BP Research Sp. z o.o., ul. Młyńska 16, 61-730 Poznań, Poland. You will come across this company in three places: it is named as the account holder when you pay by bank transfer, it is shown as the sender on the parcel you receive, and our order confirmations and other automated emails are sent from the address [email protected]. BP Research carries out these steps for us and on our instructions. Responsibility for the processing described in this policy stays with FORGETRADE LIMITED, and you can address every request concerning your rights to the email address above.
2. Visiting our website
Server logfiles
Every time a page is requested, our web server automatically records technical connection data. This includes your IP address, the date and time of the request, the requested address, the referring page, the transferred data volume, the HTTP status code and information your browser transmits about itself (browser type and version, operating system).
We use this data to deliver the requested page, to keep the site stable and to detect and defend against attacks, for example brute force attempts or automated scraping. Server logfiles are stored for 14 days and are then deleted automatically. The legal basis is our legitimate interest in the secure and reliable operation of our website (Art. 6(1)(f) GDPR).
Hosting and content delivery network
Our website is hosted on a dedicated server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Helsinki, Finland, so all data stored in our shop database is held inside the European Union. Hetzner processes data on our behalf under a data processing agreement.
Our website is delivered through the content delivery network and security service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. All requests to our site pass through Cloudflare’s network, which means Cloudflare processes your IP address and the technical request data. Cloudflare filters malicious traffic, absorbs denial of service attacks and delivers static files from a server close to you. The legal basis is our legitimate interest in the security and performance of our website (Art. 6(1)(f) GDPR). Details on the transfer to the USA are set out in section 9.
Country detection
To show you the correct currency, tax treatment, shipping options and product availability, we determine the country you are connecting from. This is done by evaluating your IP address against a geolocation database and by reading the country information supplied by our content delivery network. We do not store a movement profile and we do not determine your precise location. The legal basis is the performance of the contract and pre-contractual steps (Art. 6(1)(b) GDPR) together with our legitimate interest in showing correct prices and availability (Art. 6(1)(f) GDPR).
Web fonts
The typeface used for the text on our website is stored on our own server and delivered from there. No connection to Google Fonts is established when you visit our pages, and no data such as your IP address is transmitted to Google for this purpose.
3. Customer account and orders
Account
You can order as a guest or create a customer account. If you create an account, we process the email address and password you choose, your name and the billing and delivery addresses you store, plus your order history. Passwords are stored as a cryptographic hash and are never visible to us in plain text. The account lets you see past orders, reuse stored addresses and track deliveries.
The legal basis is the performance of the user contract you enter into when registering (Art. 6(1)(b) GDPR).
Orders
When you place an order we process your first and last name, company or institution name if you provide one, billing address, delivery address, email address, telephone number, date of birth where it is requested, the products ordered, the order value, the chosen payment and shipping method and the order date. We also record your confirmation that you are ordering for research purposes and the research field you select at checkout. This confirmation documents that our products are sold for laboratory use only.
We use this data to process your order, to issue the invoice, to arrange dispatch, to answer questions about the order and to handle returns, complaints and refunds. The legal basis is the performance of the purchase contract (Art. 6(1)(b) GDPR). Storing invoices and transaction records is additionally required by commercial and tax law (Art. 6(1)(c) GDPR). We rely on our legitimate interest in preventing fraud and misuse of our shop for the security checks that accompany an order (Art. 6(1)(f) GDPR).
The data marked as mandatory at checkout is required to conclude and perform the contract. Without it we cannot process your order.
Payment
We currently offer two payment methods, and the data processed depends on which one you choose.
- Bank transfer. We display our bank details after you place the order. When you transfer the amount, our bank receives the payment data from your bank, and we see the account holder name, the amount, the date and the reference you entered. We use this information to match the incoming payment to your order. Your bank and our bank act as independent controllers for the payment itself and process your data under their own privacy policies and under banking law.
- Bitcoin. Bitcoin payments are handled through the payment service Blockonomics. Blockonomics generates a payment address for your order and monitors the blockchain for the incoming transaction, then reports the payment status back to our shop. In this process Blockonomics receives the order reference, the amount and the technical data of your request. We do not receive any identity data from the blockchain, only the public transaction information. Blockonomics processes the data on our behalf under a data processing agreement.
We never receive or store credit card numbers or online banking credentials. The legal basis for processing payment data is the performance of the contract (Art. 6(1)(b) GDPR), and for retaining payment records our legal obligations under commercial and tax law (Art. 6(1)(c) GDPR).
Shipping
To deliver your order we pass the recipient name, the delivery address and, where the carrier requires it for delivery notifications, your email address and telephone number to the carrier handling your shipment. We work with UPS and DHL. Each carrier receives only the data needed for the individual shipment and uses it to produce the shipping label, to deliver the parcel and to send you tracking notifications.
For shipments that cross a customs border we additionally provide the data required on customs declarations, in particular the recipient name and address and a description of the goods. These declarations are processed by the customs authorities of the destination country.
The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and, for customs documentation, compliance with legal obligations (Art. 6(1)(c) GDPR). If your delivery address is outside the European Economic Area, the transfer of your address to that country is necessary in order to perform the contract with you (Art. 49(1)(b) GDPR).
4. Contacting us and customer support
If you write to us at [email protected] we process your email address, your name if you provide it and the content of your message, including any order details you mention. We use this only to answer your enquiry and to document how it was resolved. The legal basis is our legitimate interest in answering enquiries addressed to us (Art. 6(1)(f) GDPR) or, if your message concerns an existing or intended order, the performance of the contract and pre-contractual steps (Art. 6(1)(b) GDPR).
Telegram
We also offer support through the messenger Telegram, and we link to our Telegram channel from our website. If you contact us there, we process your Telegram user name, any name you have set in your profile and the content of your messages. In this channel an automated assistant answers standard questions and can, for example, confirm an order, provide tracking information or supply customs details, and our staff read and answer the conversation as well. This automation only supports the conversation, it does not make any decision about you.
Telegram is operated by Telegram Messenger Inc. outside the European Union and processes your data as an independent controller under its own privacy policy. We have no influence on that processing. If you would prefer not to use Telegram, please contact us by email instead. The legal basis for our processing in this channel is our legitimate interest in offering an additional, fast support channel (Art. 6(1)(f) GDPR), and, where your message concerns an order, the performance of the contract (Art. 6(1)(b) GDPR).
5. Newsletter, download offers and stock notifications
Newsletter and free download
You can subscribe to our newsletter and request our free eBook by entering your email address. We use the address to send you information about new products, restocks, promotions and topics relevant to laboratory users. Signing up requires your active consent, and the legal basis is Art. 6(1)(a) GDPR.
Our newsletters are sent through GetResponse S.A., Arkonska 6/A3, 80-387 Gdansk, Poland, and through Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany, part of Brevo SAS, France). Both providers process your data on our behalf under data processing agreements and store it on servers within the European Union.
Our newsletters contain a tracking pixel and individually tagged links. This lets us see whether an email was opened and which links were clicked, so that we can measure how well our mailings work and improve their content. This measurement is covered by the consent you give when subscribing.
You can withdraw your consent at any time with effect for the future. Every newsletter contains an unsubscribe link at the bottom, and you can also simply email us at [email protected]. After you unsubscribe we keep your email address on a suppression list so that our system reliably stops contacting you. Withdrawing consent does not affect the lawfulness of the mailings sent before the withdrawal.
Back in stock notifications
For products that are temporarily unavailable you can join a waiting list. We store the email address you enter and the product concerned, and we use them for a single message telling you that the product is available again. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time using the link in that message or by emailing us. The entry is deleted once the notification has been sent or when you withdraw your consent.
Cart reminder emails
If you have consented to marketing cookies and you leave items in your cart without completing the order, we may send you a reminder to the email address you entered. This is done through the providers named above. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time through the Cookie Settings link in our footer or by unsubscribing from the reminder email.
6. Product reviews and partner programme
Reviews
If you write a product review, we publish the name you enter, the rating, the review text, the date and any images you upload. Your email address is stored but is not published. Please do not include personal details in a review that you do not want to be publicly visible. The legal basis is your consent, given by submitting the review (Art. 6(1)(a) GDPR), and our legitimate interest in showing genuine customer feedback (Art. 6(1)(f) GDPR). You can ask us to remove your review at any time.
Partner programme
We run an affiliate programme through the platform GoAffPro. If you reach our shop through a partner link and you have consented to marketing cookies, a cookie records which partner referred you, so that the partner can be credited if you place an order. The platform receives the order reference and the order value for the commission calculation, not your name or address. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time through the Cookie Settings link in our footer.
7. Analytics, error monitoring and spam protection
Our own visitor statistics
We operate our own analytics installation (the open source software Matomo) on our own infrastructure at stats.beyond-peptides.com. It records page views, the approximate region derived from the IP address, the referring source, the device and browser type, and, on the order confirmation page, the order value and the products ordered, so that we can see which pages and channels lead to orders.
This installation runs without cookies, it does not follow you across other websites, and the data is not passed to any third party. It is stored on our own systems and is used for long term comparison of how our shop performs. The legal basis is our legitimate interest in understanding and improving the use of our shop (Art. 6(1)(f) GDPR).
Attribution and usage measurement with your consent
If you allow analytics cookies, we additionally record which channel brought you to our shop, for example a search engine, a newsletter or a direct visit, and we record which pages you viewed during your visit. We use this to see which channels actually generate orders. The legal basis is your consent (Art. 6(1)(a) GDPR and, for the storage on your device, § 25(1) TDDDG). You can withdraw it at any time through the Cookie Settings link in our footer.
Error monitoring and session recording
To find and fix technical faults we use the monitoring service Sentry (Functional Software, Inc., 45 Fremont Street, San Francisco, CA 94105, USA). Our data is stored in Sentry’s European region on servers in Germany.
When an error occurs in your browser, Sentry receives the error message, the address of the page, the browser and operating system, the IP address and the sequence of actions that led up to the error. We use this exclusively to reproduce and correct faults, in particular in the ordering process. The legal basis is our legitimate interest in a functioning and secure shop (Art. 6(1)(f) GDPR). You can object to this processing at any time under section 11.
Session recording only with your consent. If you allow analytics cookies, a small share of visits is additionally recorded as a session replay, and a replay is also recorded when an error occurs during such a visit. A recording reproduces the movements, the clicks and the layout of the pages you saw. All text and all images are masked before the recording leaves your browser, so neither what you typed nor what was displayed to you can be read from it. Without your consent no recording is created. The legal basis is your consent (Art. 6(1)(a) GDPR and, for the storage on your device, § 25(1) TDDDG). You can withdraw it at any time through the Cookie Settings link in our footer.
Spam protection
Our forms are protected against automated misuse without involving any third party. Two checks do this. The form contains a field that stays invisible to you and has to remain empty; programs that fill in every field give themselves away. In addition the form records how long the page had been open when it was sent, and a submission that arrives faster than a person could realistically type is rejected. Both checks run on our own server, no data is passed to anyone else for this purpose, and nothing is stored on your device.
The legal basis is our legitimate interest in protecting our forms and our shop against spam and automated abuse (Art. 6(1)(f) GDPR). Until August 2026 we used Google reCAPTCHA for this purpose. It has been removed and is no longer loaded on any page of our shop.
8. Cookies and your choice
We use cookies and comparable storage techniques on your device. Cookies that are strictly necessary to provide the shop you requested are set without consent. This covers the shopping cart and your session, the currency and region setting, security checks and the storage of your own cookie choice. For everything else we ask for your consent before anything is stored on or read from your device, as required by § 25(1) TDDDG and Art. 6(1)(a) GDPR.
Our consent banner offers three optional categories:
- Functional: remembers the products you recently viewed.
- Analytics: measures how visitors reach and use our shop, including which channel an order came from.
- Marketing: enables cart reminder emails and credits our partners when you reach our shop through their link.
You can accept all categories, reject all of them or select them individually. Your decision is stored in the cookie bp_consent for six months and can be changed at any time through the Cookie Settings link in our footer. Withdrawing your consent does not affect the lawfulness of the processing carried out before the withdrawal. You can also delete or block cookies in your browser settings, but the shop will then no longer work fully.
A detailed list of the individual cookies, their purpose and their storage period is available in our Cookie Policy.
9. Recipients and transfers to third countries
Inside our company, only the staff who need your data for order processing, accounting or support have access to it. Beyond that, we use the following categories of recipients:
| Recipient | Purpose | Location of processing |
|---|---|---|
| BP Research Sp. z o.o. | Payment collection by bank transfer, dispatch of orders, sending of automated emails | Poland (EU) |
| Hetzner Online GmbH | Hosting of the shop and the database | Germany, servers in Finland (EU) |
| Cloudflare, Inc. | Content delivery network, protection against attacks | USA and global network |
| UPS, DHL | Delivery of orders, tracking, customs documents | EU and destination country |
| Blockonomics | Processing of Bitcoin payments | Outside the EU |
| Banks involved | Execution of bank transfers | EU |
| GetResponse S.A., Brevo | Newsletter, transactional emails, cart reminders | Poland, Germany, France (EU) |
| Functional Software, Inc. (Sentry) | Error monitoring; session replay only with your consent | EU region, servers in Germany; provider based in the USA |
| GoAffPro | Affiliate and partner programme | Outside the EU |
| Telegram Messenger Inc. | Support through the Telegram channel | Outside the EU |
| Tax advisors, auditors, authorities | Accounting, statutory duties, customs | According to the case |
Providers acting on our behalf are bound by data processing agreements under Art. 28 GDPR and may use your data only according to our instructions. Carriers, banks and Telegram act as independent controllers for their own part of the process.
Transfers outside the EEA. As the controller, we are based in Hong Kong, and some of the providers listed above process data outside the European Economic Area. In these cases we rely on the Standard Contractual Clauses adopted by the European Commission, or, where a provider is certified, on the EU-US Data Privacy Framework. Where you order a delivery to a country outside the EEA, the transfer of your address to the carrier and the customs authorities there is necessary for the performance of the contract with you (Art. 49(1)(b) GDPR). You can request a copy of the safeguards in place from us at any time.
10. How long we keep your data
We keep personal data only as long as it is needed for the purpose it was collected for or as long as statutory retention periods require.
- Server logfiles: 14 days, then deleted automatically.
- Orders, invoices and payment records: for the duration of the commercial and tax retention periods that apply to us, up to seven years from the end of the year in which the order was placed. During this period the data is only used for accounting and for legal claims.
- Unpaid orders are moved to the recycle bin 90 days after they were created, failed orders after 30 days, and are deleted from there.
- Customer account: for as long as your account exists. If you ask us to delete it, we remove the account and the data linked to it, except for the order records we have to keep for the periods stated above.
- Newsletter: until you withdraw your consent. Afterwards we keep your address on a suppression list so that we do not contact you again.
- Back in stock notifications: deleted once the notification has been sent or when you withdraw your consent.
- Support correspondence: as long as we need it to handle your request, and afterwards for as long as we may need it to establish, exercise or defend legal claims.
- Consent cookie: six months, then you are asked again.
- Error reports and session replays: deleted automatically after the retention period configured in our monitoring account, at the latest after 90 days.
- Visitor statistics: stored on our own systems and used for long term comparison of how our shop performs.
Once a retention period ends, we delete the data or remove all identifying details from it.
11. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR): you can ask us to confirm whether we process data about you and to send you a copy of it together with information about the processing.
- Rectification (Art. 16 GDPR): you can ask us to correct inaccurate data and to complete incomplete data.
- Erasure (Art. 17 GDPR): you can ask us to delete your data, unless we are required to keep it, for example for invoices covered by tax law.
- Restriction (Art. 18 GDPR): you can ask us to restrict processing, for example while we check whether data is accurate.
- Data portability (Art. 20 GDPR): you can ask to receive the data you provided to us in a structured, commonly used and machine readable format, or to have it transmitted to another controller.
- Objection (Art. 21 GDPR): you can object at any time, on grounds relating to your particular situation, to processing that we base on our legitimate interest. This applies in particular to error monitoring, to our visitor statistics and to our security measures. The session recording described in section 7 runs on your consent instead, which you can withdraw at any time. We will then stop the processing unless we can demonstrate compelling legitimate grounds that override your interests. Against direct marketing you can object at any time without giving reasons, and we will stop it immediately.
- Withdrawal of consent (Art. 7(3) GDPR): where processing is based on your consent, you can withdraw it at any time with effect for the future.
How to exercise your rights. Send your request by email to [email protected]. To make sure we do not disclose data to the wrong person, we confirm your identity by sending a confirmation email to the address stored in our system, and we may ask you for details of an order. We answer within one month. If a request is particularly complex, we may extend this period by up to two further months and will tell you why.
Right to lodge a complaint (Art. 77 GDPR): if you believe that we process your data unlawfully, you can lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA member state where you live, where you work or where the alleged infringement took place. We would appreciate the opportunity to look into your concern first.
12. Data security
We protect your data with technical and organisational measures against loss, manipulation and unauthorised access.
- The entire website, including the account area and the checkout, is transmitted encrypted with TLS. You can see this from the https address and the padlock in your browser.
- Passwords are stored only as a cryptographic hash and are never readable to us.
- Administrative access to our systems is limited to a small number of people, secured by strong authentication and logged.
- Our shop, its extensions and the server software receive security updates regularly, and the server is protected against automated attacks and denial of service attacks.
- We collect only the data we actually need. In particular, we never receive card numbers or online banking credentials.
Please note that no transmission over the internet can be completely secure. If you suspect that your account has been accessed by someone else, please contact us immediately.
13. No automated decision making
We do not use automated decision making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. Automated steps such as an order confirmation email, the shipping options offered for your address or the automated replies in our Telegram channel are simple process steps, and they are reviewed by our staff where a decision is needed.
14. Minors
Our shop is addressed to professional users and research institutions and not to minors. We do not knowingly collect data from persons under 18 years of age. If you become aware that a minor has provided us with data, please tell us and we will delete it.
15. Changes to this policy
We update this Privacy Policy when we change our services or when legal requirements change. The version published on this page always applies, and the date below shows when it was last revised. If a change materially affects the way we process your data, we will point this out separately, for example by a notice on our website or by email to registered customers.
Last updated: 29 August 2026