Privacy policy
Privacy policy
We collect very little, we collect it for one reason, and we can tell you exactly where it sits. This page says what that is without the usual hedging about partners and affiliates we do not have.
Read this first
These are the current operating policies of an early-stage company, written in plain language by the people who run it. They have not been reviewed by external counsel, and they are not a substitute for an agreement negotiated with your institution. If your purchasing office, technology transfer office, or legal team needs different terms, a master agreement, a data processing addendum, or a signed non-disclosure agreement, ask us before you order. We would rather negotiate than discover a mismatch after a shipment has left.
We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not run advertising trackers, and there is no third-party analytics script on this site as at 2026-09-01.
1Scope, and who is responsible
This policy covers wetwareworld.com and the correspondence that follows from it. Wetware World is the controller of the personal data described here — in GDPR terms, we decide what is collected and why. Suppliers we approach on your behalf are separate controllers of anything we pass to them, which is covered in clause 5 and in confidentiality and your specification.
We have not appointed a data protection officer. We are not at a scale that requires one under Article 37, and we are not going to name a fictional person in a role nobody holds. Privacy requests go to a monitored inbox and are handled by a person: hello@wetwareworld.com.
2What we collect
Three categories, and nothing else.
| Category | What is actually in it |
|---|---|
| Quote form submissions | Your name, email address, institution, country, and any telephone number you choose to give. The technical content of your request: component category, quantities, specification text, quality documentation required, target dates, budget band, and any files you attach. The research use attestation and whether you consented to your identity being disclosed to suppliers. |
| Correspondence | Emails you send us and our replies, including attachments, quotations, purchase orders and delivery correspondence. |
| Server and request logs | Generated automatically by our host when a page or form is requested: IP address, timestamp, requested URL, user agent, and response status. Used for security and to keep the site up. |
Submissions are stored. A quote request is not a message that passes through and disappears — it is written to a record so that we can source against it, quote it, and answer questions about it months later. That record is what clause 6 governs.
We do not ask for and do not want: government identifiers, financial account details through the web form, health information about identifiable individuals, or anything about a research subject. If your specification concerns human-derived material, describe the material and the consent framework, not the donor. Do not send us identifiable donor data.
Cookies: this site sets no cookies of its own and runs no advertising or analytics trackers. Our host may set a strictly necessary cookie for security and bot mitigation. If we ever add analytics, this paragraph changes first and the effective date moves with it.
3Why we collect it, and the lawful basis
| Purpose | Lawful basis |
|---|---|
| Reading your request, sourcing against it, and returning a quotation | Steps taken at your request prior to entering a contract (Art. 6(1)(b)) |
| Fulfilling an order, arranging shipment, handling a claim | Performance of a contract (Art. 6(1)(b)) |
| Keeping records of quotations, orders and correspondence | Legal obligation for tax and trade records, and our legitimate interest in defending a claim (Art. 6(1)(c) and (f)) |
| Export, sanctions and end-use screening before shipment | Legal obligation, and legitimate interest in lawful and safe supply (Art. 6(1)(c) and (f)) |
| Keeping the site up and defending it from abuse | Legitimate interest (Art. 6(1)(f)) |
| Sending you anything not connected to your request | Consent (Art. 6(1)(a)), never pre-ticked, withdrawable at any time |
We do not profile you, we do not score you, and no automated decision with legal or similarly significant effect is made about you. A person reads every quote request.
4Where it is stored and who processes it
This site is hosted on Cloudflare Pages, and the form endpoint runs on Cloudflare's platform. That means Cloudflare, as our hosting provider and processor, handles the request traffic for every page you load and every form you submit, including the associated request logs and its own security and bot-mitigation processing. Cloudflare operates a global network, so traffic is served from the point of presence nearest you.
The full list of processors, as at 2026-09-01:
- Cloudflare — site hosting, form endpoint, request logs, DDoS and bot mitigation, and storage of submitted quote requests.
- Our email provider — receipt and storage of correspondence, quotations and attachments.
- Google Fonts — the site loads webfonts from Google's font hosts, which means your browser makes a request to those hosts carrying your IP address and user agent. We do not receive that data. If your institution disallows this, tell us and we will discuss self-hosting the fonts.
That is the whole list. There is no customer relationship management platform, no marketing automation, no advertising network, no session recorder, and no data broker receiving anything from us. If that list grows, this clause is updated before the tool is switched on.
5What suppliers see
This is the question most buyers actually care about, so it gets its own clause here as well as a full document at confidentiality and your specification.
By default, suppliers receive an anonymised version of your requirement. The technical content goes out; your name, your institution and your contact details do not. The quote form carries a checkbox that lets you opt in to your specification being shared under a supplier's standard confidentiality terms; leaving it unticked means we circulate the anonymised version. Where the material requires the end user to be named — a controlled cell line, a material transfer agreement, an export end-use check — we cannot keep you anonymous, and we will tell you that before we circulate anything.
6How long we keep it
| Record | Kept for |
|---|---|
| Quote request that did not become an order | 24 months from last contact, then deleted |
| Files you attached to a request that did not become an order | 12 months from last contact, then deleted |
| Quotations, orders, invoices and delivery records | 7 years from the end of the relevant financial year, to meet tax and trade record obligations |
| Export, permit and end-use screening records | Per the retention period required by the applicable control regime, typically 5 years |
| Correspondence not attached to an order | 24 months from last contact |
| Server and request logs | Per our host's standard log retention, which is short and measured in days |
| Marketing consent record | Until you withdraw consent, plus a record of the withdrawal itself |
You can ask us to delete a quote request earlier and we will, unless it is attached to an order we are legally required to keep records of. See clause 7.
7Your rights, and how to use them
If you are in the UK, the EU, or another jurisdiction with equivalent law, you have the right to:
- ask what we hold about you, and get a copy;
- have inaccurate data corrected;
- have data erased, where we have no overriding legal obligation to keep it;
- restrict or object to processing carried out on the basis of legitimate interest;
- receive data you gave us in a portable, machine-readable form;
- withdraw consent at any time, without that affecting anything done before you withdrew it;
- complain to your supervisory authority — in the UK, the Information Commissioner's Office.
How to make a request. Email hello@wetwareworld.com with the word privacy in the subject line and tell us what you want. There is no form, no portal and no account required. We respond within one month, as the GDPR requires, and usually much faster because there is not much to search.
We may need to check you are who you say you are before we hand over a copy of data. For a quote request that generally means replying from the email address the request came from, which is proportionate and does not require you to send us identity documents. We will not ask you for a passport scan to prove you own an email address.
8California residents
Under the California Consumer Privacy Act as amended, you may request disclosure of the categories and specific pieces of personal information we have collected, request deletion, request correction, and not be discriminated against for exercising any of those rights. The categories we collect are set out in clause 2; the business purposes are in clause 3.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding twelve months. We have no plans to. Because we do not sell or share, there is no do-not-sell mechanism to offer, and we are not going to add a decorative one.
We do not process sensitive personal information for the purpose of inferring characteristics. Make a CCPA request the same way as any other, at hello@wetwareworld.com. An authorised agent may act for you with written authorisation.
9International transfers
Sourcing is international by nature. If we approach a supplier outside your region, the technical content of your requirement goes with the enquiry, and where you have opted in to identity disclosure your contact details go too. Our host operates a global network, so request handling may occur outside your country.
Where personal data leaves the UK or the EEA we rely on an adequacy decision where one exists, and otherwise on the standard contractual clauses in our processor and supplier agreements. If a specific supplier's location is a problem for your institution, say so on the quote request and we will restrict circulation by geography. That is a normal constraint and we handle it routinely.
10Security, stated honestly
The site is served over TLS. Access to submitted requests and to the correspondence mailbox is limited to the people who need it, which today is a small number of people. Attachments are stored with the request rather than scattered across personal machines.
What we do not have: a formal information security management system, an ISO 27001 certification, a SOC 2 report, or a penetration test to show you. We are an early-stage company and saying otherwise would be a lie that is trivially checked. If your institution requires a security questionnaire completed before you can send us a specification, send it and we will answer it accurately, including the questions where the answer is no.
If you become aware of a vulnerability in this site, email hello@wetwareworld.com. We will not threaten you for telling us.
11Children
This is a business-to-business site for laboratory procurement. It is not directed at children and we do not knowingly collect data from anyone under sixteen. If you believe we have, tell us and we will delete it.
12Changes to this policy
When this policy changes, the effective date at the foot of the page changes with it. For a change that materially affects how we handle data already submitted, we will email people with an open request or an active account rather than relying on you re-reading this page.
Questions: hello@wetwareworld.com.
doc WW-PRIV-1.0 · effective 2026-09-01 · research use only · questions to hello@wetwareworld.com