Privacy Policy
This policy explains how Certa Labs UK collects, uses, and protects your personal data. Last updated: March 2026.
1. Who We Are
Certa Labs UK is a professional histology laboratory based in the United Kingdom. We are committed to protecting your personal data and handling it responsibly in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For any data protection queries, please contact us at [email protected].
2. What Data We Collect
We may collect and process the following personal data:
— Contact information: name, email address, phone number, and organisation name provided via our quote request form or direct correspondence. — Project information: details about your research, sample types, and service requirements that you share with us. — Technical data: IP address, browser type, and usage data collected automatically when you visit our website. — Communication records: emails, messages, and any other correspondence between you and Certa Labs UK.
3. How We Use Your Data
We use your personal data for the following purposes:
— To respond to quote requests and enquiries. — To deliver and manage the histology services you have engaged us for. — To send service-related communications, including project updates and invoices. — To improve our website and services through aggregated, anonymised analytics. — To comply with legal and regulatory obligations.
We do not use your data for unsolicited marketing without your explicit consent.
4. Legal Basis for Processing
We process your personal data on the following legal bases:
— Contractual necessity: to fulfil our obligations under a service agreement with you. — Legitimate interests: to respond to enquiries and manage our business operations. — Legal obligation: where processing is required to comply with applicable law. — Consent: where you have explicitly agreed to a specific use of your data.
5. Data Sharing
Certa Labs UK does not sell, rent, or trade your personal data. We may share your data with trusted third-party service providers who assist us in operating our business (such as email delivery services), strictly under confidentiality agreements and only to the extent necessary.
We may also disclose your data where required by law, court order, or regulatory authority.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Client project data is typically retained for a period of 7 years following project completion for legal and audit purposes. Website enquiry data is retained for 2 years unless a service relationship is established.
7. Cookies
Our website may use essential cookies to ensure basic functionality. We do not use tracking or advertising cookies without your consent. You can control cookie settings through your browser preferences at any time.
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
— Right of access: to request a copy of the data we hold about you. — Right to rectification: to request correction of inaccurate or incomplete data. — Right to erasure: to request deletion of your data where there is no legitimate reason for us to retain it. — Right to restriction: to request that we limit how we use your data. — Right to data portability: to receive your data in a structured, machine-readable format. — Right to object: to object to processing based on legitimate interests.
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. All data is stored securely and access is restricted to authorised personnel only.
While we take every reasonable precaution, no method of transmission over the internet is entirely secure. We cannot guarantee absolute security of data transmitted to our website.
10. Third-Party Links
Our website may contain links to third-party websites. Certa Labs UK is not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external sites you visit.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically. Continued use of our website or services following any changes constitutes acceptance of the revised policy.
12. Contact & Complaints
If you have any questions or concerns about how we handle your personal data, please contact us at [email protected].
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
