Privacy Policy
Last updated 2026. This page explains, in plain language, what personal data Titeris collects, why we collect it, how long we keep it, who we share it with, and your rights under UK GDPR and the Data Protection Act 2018. If a term below feels vague, that's usually because we're describing a general policy honestly rather than inventing a specific figure we can't yet stand behind.
Data we collect
We collect personal data in three places, and nowhere else. First, when you place an order: your name, delivery address, email address, and a payment confirmation from our payment provider. We do not see or store your full card number ourselves; that detail is handled entirely by the payment processor, not by us. Because every listing on this site is age-restricted, checkout also confirms you're 18 or over before an order can complete, so an age confirmation forms part of your order record too.
Second, when you contact us through the contact page or by email: whatever you send us, typically your email address, your name if you give it, and the content of your message. We don't ask for more than we need to answer you.
Third, basic site analytics. We run privacy-respecting, self-hosted analytics rather than a third-party ad-tech platform. It doesn't use cookies, doesn't build a profile of you as an individual, and doesn't follow you across other sites. It counts things like how many people visited a page and roughly where traffic came from, in aggregate, not who you specifically are. We're not going to dress that up as more sophisticated than it is, and we're also not going to pretend it collects less than it does: it's simple, aggregate traffic counting, nothing more.
We don't collect health data, don't ask why you're ordering a research compound, and don't run any kind of profiling to infer anything about you beyond what's needed to ship an order and respond to a message.
Why we collect it, and the legal basis
Order data exists to do one job: fulfil your order and support you if something goes wrong with it. Delivery details go to whichever courier or postal service is actually handling the parcel, name and payment confirmation go through our payment provider to take payment, and none of it is used for anything beyond that transaction and any related support request.
Under UK GDPR, we rely on a small set of lawful bases rather than one catch-all justification. Processing your order (collecting your address, confirming payment, arranging delivery) is necessary to perform the contract you enter into when you buy from us. Keeping records for accounting, tax, and fraud-prevention purposes rests on our legal obligations as a UK business and on our legitimate interest in running a functioning, non-fraudulent shop. Responding to a contact-page message is also a legitimate interest: you asked us something, and we need your details to answer.
We do not sell your data to third parties, full stop. We don't currently run a marketing mailing list, so we're not going to describe an email-marketing policy we haven't built yet; if that changes, this page will say so honestly, and any marketing communication would be sent only on a proper opt-in basis, never bundled silently into an order.
How long we keep it
We keep personal data only for as long as we genuinely need it, not indefinitely by default. Order and transaction records are retained for as long as UK accounting and tax law requires businesses to keep financial records, which in practice runs to several years after the relevant tax year, plus any additional period needed to resolve a dispute, chargeback, or delivery issue tied to that order. That's a legal minimum we're bound by, not a preference of ours.
Messages sent through the contact page are kept only as long as needed to answer you and to have a record in case you follow up, then deleted or archived out of active use. Analytics data is aggregate rather than individually identifying in the first place, so there's no per-visitor record sitting around to retain or delete.
We haven't published an exact day-count retention schedule on this page, and we'd rather be upfront about that than invent a precise figure that sounds authoritative but isn't accurate. If you want to know how long a specific piece of your data has been, or will be, kept, ask us directly through the contact page and we'll give you a straight answer for your actual case.
Third parties we share data with
We share the minimum necessary data with two categories of processor to actually get your order to you: a payment provider, to take and confirm payment without us handling your full card details ourselves, and a delivery carrier, to get the parcel to your address. Each of them only receives the specific fields they need to do their job, not your full order history or account details.
We haven't named specific providers on this page because, honestly, doing so before those relationships are fully locked in would be getting ahead of ourselves, and we'd rather leave a gap here than publish a name that later turns out to be wrong. What we can commit to is the principle: any processor we use is contractually bound to handle your data only for the purpose we've engaged them for, under their own obligations as a data processor under UK GDPR, and we don't hand data to anyone outside that narrow purpose.
Where a processor we use is based outside the UK, UK GDPR requires appropriate safeguards, such as an adequacy decision or standard contractual clauses, before that transfer can happen, and we hold ourselves to that requirement rather than treating it as optional small print.
Your rights under UK GDPR
As a UK resident, you have a set of rights over your own personal data under UK GDPR and the Data Protection Act 2018. In plain terms, you can ask us to:
- Access the personal data we hold about you, and be told what we're doing with it.
- Correct any of it that's inaccurate or incomplete.
- Delete it, where there's no overriding legal reason (such as a tax record we're required to keep) for us to hold onto it.
- Restrict how we use it, in certain circumstances, while a query about it is resolved.
- Object to processing that relies on legitimate interest, including anything we might do on that basis in future.
- Receive a copy of the data you've given us in a portable format, where that applies.
These rights aren't unlimited: a legal obligation to retain accounting records, for example, can outweigh a deletion request for that specific data until the retention period genuinely ends. Where that's the reason we can't act on a request in full, we'll tell you plainly why, rather than staying silent.
How to make a privacy request
Contact us via our contact page and tell us which right you're exercising and, if it's an access or deletion request, enough detail (such as an order reference or the email address you used) for us to actually find your data rather than guess at it. We may need to verify it's genuinely you asking, which protects your data rather than being an unnecessary hurdle.
UK GDPR sets a statutory response window of one calendar month for most requests, extendable by up to two further months for a complex or unusually broad request, in which case we'll explain the delay within the first month rather than let the deadline pass silently. Most requests we get are simple enough to answer well inside that window.
If you're not satisfied with how we've handled a request, you have the right to complain to the UK's independent data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk. We'd genuinely rather you raised it with us first so we can put it right, but that right to escalate is yours regardless.
Changes to this policy
We'll update this page if what we actually do changes, whether that's a new processor, a new analytics setup, or a clarified retention approach, and the "last updated" note at the top will reflect that. We're not going to quietly widen what we collect or how we use it without updating this page to match, since the entire point of publishing a privacy policy is that it describes reality, not an aspiration.