Data Retention Policy

Effective date: 14 August 2026
Last updated: 14 August 2026

1. Introduction

UK Peptides (“UK Peptides”, “we”, “us” or “our”) respects the privacy of individuals whose personal information we process.

This Data Retention Policy explains how long we retain personal data and other information collected through our website, communications and business activities, and the circumstances in which information is securely deleted, anonymised or otherwise disposed of.

We aim to retain personal data only for as long as it is necessary for the purpose for which it was collected, unless we have a legal, regulatory, contractual or legitimate business reason to retain it for longer.

This policy should be read together with our Privacy Policy and any other applicable terms and policies published on our website.

2. Our approach to data retention

UK Peptides follows the principle that personal data should not be retained for longer than necessary.

When determining how long information should be retained, we consider:

  • The purpose for which the information was collected.
  • Whether we continue to have a legitimate business need for the information.
  • Applicable legal, accounting, tax or regulatory requirements.
  • Contractual obligations.
  • The potential need to establish, exercise or defend legal claims.
  • The security and privacy risks associated with retaining the information.
  • Whether the information can be securely deleted or anonymised.

We do not retain personal information indefinitely simply on the basis that it may be useful in the future.

The UK GDPR does not prescribe one universal retention period for all personal information. Retention periods should instead be justified by the purpose for which the information is held. ICO guidance

3. Types of information we may retain

Depending on how you interact with UK Peptides, we may retain information including:

  • Name and contact details.
  • Email addresses and telephone numbers.
  • Delivery and billing information where applicable.
  • Enquiry and correspondence records.
  • Order and transaction records.
  • Payment and accounting records.
  • Website enquiry and contact-form submissions.
  • Marketing preferences and consent records.
  • Records relating to customer service and complaints.
  • Technical information such as IP addresses and website usage information, where collected.
  • Records relating to legal, regulatory or compliance matters.

We seek to collect and retain only information that is adequate, relevant and necessary for the purposes for which it is processed.

4. Retention periods

The following schedule provides our standard retention periods. These periods may be extended where there is a lawful reason to do so.

Information Standard retention period
General website enquiries and correspondence Up to 24 months after the enquiry or last meaningful correspondence
Customer service records Up to 24 months after the matter is resolved
Marketing records and preferences Until consent is withdrawn or the information is no longer required, subject to periodic review
Records of marketing consent or objection For as long as necessary to demonstrate and manage the individual’s marketing preference
Customer/order records For as long as necessary to administer the customer relationship and meet applicable legal and accounting requirements
Financial and accounting records Normally up to 7 years, or longer where required by applicable law or necessary for tax, accounting or legal purposes
Complaints and dispute records Up to 6 years after resolution, or longer where reasonably necessary to establish, exercise or defend legal claims
Website/server/security logs Normally up to 12 months, subject to technical requirements and security considerations
Cookies and similar technologies According to the applicable cookie duration stated in our Cookie Policy
Data relating to legal claims or investigations Until the matter is resolved and for as long as reasonably necessary afterwards
Records required for regulatory or legal compliance For the period required by the applicable legal or regulatory obligation

These periods are intended as standard guidelines rather than an automatic requirement to retain every record for the entire period.

Where information is no longer required, we will seek to delete or anonymise it sooner where appropriate.

5. Marketing information

Where you have provided consent to receive marketing communications, we may retain information necessary to manage that consent and your communication preferences.

If you withdraw consent or object to direct marketing, we will stop using your information for that marketing purpose.

We may retain a limited record of your request or preference where necessary to ensure that we respect your decision and do not inadvertently send further marketing communications.

6. Financial and transaction records

Records relating to payments, purchases, invoices, refunds and other financial transactions may need to be retained for accounting, tax, fraud prevention, legal and regulatory purposes.

Where a specific statutory retention requirement applies, UK Peptides will retain the relevant information for the period required by law.

7. Legal claims and investigations

We may retain personal information beyond the standard retention period where reasonably necessary to:

  • Establish, exercise or defend legal claims.
  • Comply with a legal obligation.
  • Cooperate with law enforcement, regulators or other competent authorities.
  • Investigate suspected fraud, misuse, security incidents or other unlawful activity.
  • Preserve evidence relevant to an actual or reasonably anticipated dispute.

Information retained for these purposes will be limited to what is reasonably necessary.

8. Deletion and secure disposal

When personal information reaches the end of its applicable retention period, we will take reasonable steps to:

  • Securely delete electronic information.
  • Permanently destroy physical records where appropriate.
  • Anonymise information where deletion is not necessary or practical and the information can no longer identify an individual.
  • Remove information from systems and records where technically and operationally appropriate.

Backup copies may remain for a limited period where immediate deletion from backup systems is not technically feasible. Where this occurs, the information will remain subject to appropriate security controls and will be deleted or overwritten in accordance with the applicable backup cycle.

9. Third-party service providers

UK Peptides may use third-party service providers to operate its website, process communications, provide hosting, process payments, maintain business systems or provide other services.

Where third parties process personal data on our behalf, we expect them to apply appropriate security and retention controls and to process information in accordance with applicable data protection requirements and our instructions.

Third-party providers may have their own retention periods where they are independently responsible for particular processing activities.

10. Data security

We take reasonable technical and organisational measures to protect retained information against:

  • Unauthorised access.
  • Accidental loss.
  • Destruction.
  • Damage.
  • Unauthorised disclosure.
  • Unlawful processing.

Access to personal information is limited to those who need it for legitimate business purposes.

The ICO identifies appropriate security and storage controls as an important part of complying with the UK GDPR’s data protection principles. ICO guidance

11. Data subject rights

Depending on the circumstances and applicable law, individuals may have rights concerning their personal information, including rights to:

  • Request access to their personal information.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of information in certain circumstances.
  • Request restriction of processing in certain circumstances.
  • Object to certain processing, including direct marketing.
  • Request portability of certain information.

These rights are subject to applicable legal exemptions and limitations.

Our privacy information explains how individuals can exercise their rights. The ICO states that privacy information should include applicable retention periods and information about individuals’ rights. ICO guidance

12. Requests for deletion

If you ask us to delete your personal information, we will consider your request in accordance with applicable data protection law.

We may be required or permitted to retain certain information despite a deletion request, for example where retention is necessary to comply with a legal obligation or to establish, exercise or defend legal claims.

Where information is retained following a deletion request, we will restrict its use to the purpose for which it must be retained where appropriate.

13. Periodic review

UK Peptides will periodically review the personal information it holds to determine whether it is still necessary.

Where information is no longer required, it should be securely deleted or anonymised.

Our retention practices may be reviewed and amended when there are changes to our business activities, technology, legal requirements, regulatory guidance or the purposes for which information is processed.

The ICO recommends that organisations periodically review the personal data they hold and erase or anonymise information that is no longer needed. ICO guidance

14. Changes to this policy

We may update this Data Retention Policy from time to time to reflect changes in our business practices, technology, legal requirements or regulatory guidance.

The latest version will be made available on our website.

15. Contact us

If you have any questions about this Data Retention Policy or how UK Peptides handles personal information, please contact us:

UK Peptides
113 Bruce Grove
London
N17 6UR
United Kingdom

Email: sales@ukpeptides.uk
Telephone: +44 7950 377498