Loading…
Version 1.2 Effective Date: September 23, 2026
gibq.org is operated by GIBQ Operations LLC, a Delaware limited liability company.
This Privacy Policy describes how GIBQ Operations LLC, a Delaware limited liability company ("we," "us," "our," or "GIBQ Operations"), collects, uses, discloses, and safeguards information when you visit gibq.org, submit a vendor application, communicate with us, or otherwise interact with services we operate (collectively, the "Services").
GIBQ Operations is the data controller for personal information processed in connection with the Services. GIBQ Operations LLC currently owns all GIBQ intellectual property. GIBQ™ and GIBQ Verified™ are unregistered trademarks of GIBQ Operations LLC. A future two-entity structure with a separate standards-holding nonprofit may be established.
By accessing the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, do not use the Services.
This Policy applies to all visitors to gibq.org, all vendors submitting an application for verification under the GIBQ Verified standard, and all persons who otherwise communicate with us in connection with the Services.
During Phase 1, vendor applications for GIBQ Verified status are accepted only from entities legally formed and operating in the United States. Vendor applications submitted from outside the United States will not be processed during Phase 1. We may expand vendor eligibility to additional jurisdictions in subsequent phases; if we do, this Policy will be updated accordingly.
Notwithstanding the Phase 1 vendor restriction above, gibq.org is accessible globally. Visitors from outside the United States, including the European Economic Area ("EEA"), the United Kingdom, and Canada, may browse the website, read about the GIBQ Verified standard, and contact us. Such visitors are entitled to the rights described in Section 9 below.
We collect only information that is reasonably necessary to evaluate vendor applications, operate the Services, communicate with you, and meet our legal obligations. We do not sell personal information.
We do not knowingly collect personal information from minors under the age of sixteen (16). The Services are intended for business and professional use only. If you believe a minor has provided personal information to us, please contact us using the address in Section 12 and we will delete it.
We do not collect or process special categories of data (such as health, biometric, racial or ethnic, religious, or political data) in the ordinary course of operating the Services.
To invite research peptide vendors to apply for GIBQ Verified status, we collect a limited amount of business information that vendors have published on their own websites. This consists of the vendor's business name and website address, the names of products for which the vendor publishes documentation, and the business contact details the vendor lists publicly, such as a general business email address and, where the vendor publishes them, the name, title, and business email address of a contact person. We collect this information by hand from the vendor's own website. We do not use automated scraping tools, and we do not obtain this information from data brokers or other third parties.
We send outreach only to vendors located in the United States, and only to business email addresses that the vendor has published. We do not send outreach to an address on a website that states it does not wish to receive unsolicited messages. Each outreach message identifies itself as a solicitation, includes our postal address, and offers an unsubscribe link and the option to reply "unsubscribe." We honor unsubscribe requests within ten (10) business days.
If a vendor does not reply within thirty (30) days after our last outreach message, we discard the product list and contact details collected for it. We retain only the vendor's business name, its website address, and the dates we contacted it, so that we do not contact the vendor again within twelve (12) months. If a vendor replies and requests an application, the information becomes vendor application data under Section 3.1.
When a person unsubscribes, we record that person's email address and the associated business name on a suppression list, and we keep that record for as long as we conduct vendor outreach so that the request continues to be honored. We use the suppression list only to prevent further messages and do not share it with anyone other than the service providers that deliver our email.
We use the information described in Section 3 only for the purposes set out in the table below. The legal bases identified are those applicable under the European Union General Data Protection Regulation ("GDPR") and the United Kingdom General Data Protection Regulation ("UK GDPR"). For United States residents, the equivalent purposes are described in Section 9.2.
| Purpose | Categories of Data | Legal Basis (GDPR/UK GDPR) |
|---|---|---|
| Evaluate vendor applications and conduct the GIBQ Verified audit | Vendor application and audit submission data | Pre-contractual measures (Art. 6(1)(b)) |
| Issue, maintain, suspend, or revoke GIBQ Verified status; maintain the public registry | Vendor application data; audit results; communications | Performance of contract (Art. 6(1)(b)) |
| Operate, secure, and improve the website and Services | Technical data; aggregated analytics | Legitimate interests (Art. 6(1)(f)) |
| Communicate with you and respond to inquiries | Contact information; communications | Legitimate interests (Art. 6(1)(f)) |
| Invite vendors to apply for GIBQ Verified status, and honor unsubscribe requests (Section 3.4) | Business contact details and product names collected from vendors' public websites; suppression list | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) for honoring unsubscribe requests |
| Comply with legal, regulatory, accounting, audit, and tax obligations | All categories as required | Legal obligation (Art. 6(1)(c)) |
| Protect, establish, exercise, or defend legal claims | All categories as required | Legitimate interests (Art. 6(1)(f)) |
| Process payments (Phase 2 onward) | Billing and payment information | Performance of contract (Art. 6(1)(b)) |
We do not engage in automated decision-making that produces legal or similarly significant effects on individuals. Vendor audit determinations are reviewed and approved by a qualified human reviewer.
We share personal information only as described below. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
We engage third-party service providers to perform functions on our behalf, including website hosting, email delivery, document storage, payment processing (Phase 2 onward), and analytics. These providers process information only as instructed by us and under written agreements that require confidentiality and appropriate safeguards. Our current service providers, by category, are:
We will update this list when we add or change a service provider.
No separate standards-holding entity currently exists, and we do not disclose personal information to any such entity. If a separate standards-holding nonprofit is established in the future, we will update this Policy before sharing any information with it.
We maintain a public registry on gibq.org, including a searchable registry at gibq.org/certified-vendors and verification pages at gibq.org/verify. The registry lists every certificate that has ever been issued, together with its current status: active, suspended, under appeal, revoked, expired, or withdrawn. For each certificate, the registry displays the vendor's legal entity name, trade names, and brand names; its website domains; the certificate number; the version of the GIBQ 7-Point Standard; the products covered by the certificate; the current status; and the dates on which the certificate was issued, expires or expired, and changed status. The registry does not display the reasons for any suspension or revocation. Declined or closed applications, and vendors that have not applied, are not listed. The public registry does not include personal information about individual employees of the vendor unless the vendor expressly authorizes such disclosure.
We may disclose information when we believe in good faith that disclosure is required by law, court order, or governmental request; necessary to enforce our agreements or this Policy; or appropriate to protect the rights, property, or safety of GIBQ Operations, its affiliates, vendors, users, or the public.
If GIBQ Operations is involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency proceeding, personal information may be transferred to the relevant counterparty as part of that transaction. Any such transfer will remain subject to the protections set out in this Policy or a successor policy that provides equivalent protections.
We share information with third parties when you direct us to do so or otherwise consent to the disclosure.
GIBQ Operations LLC is established in the United States, and the Services and supporting infrastructure are hosted in the United States. If you access the Services from outside the United States, the information we collect about you will be transferred to, stored in, and processed in the United States.
The United States may not provide the same level of legal protection for personal information as your country of residence. For transfers of personal information from the EEA, the United Kingdom, or Switzerland to the United States, we rely on the Standard Contractual Clauses approved by the European Commission (and, as applicable, the UK International Data Transfer Addendum) as the legal mechanism for the transfer. A copy of the relevant clauses is available on request using the contact information in Section 12.
We retain personal information only for as long as necessary for the purposes for which it was collected, to comply with our legal, accounting, or reporting obligations, or to establish, exercise, or defend legal claims. The retention periods below are guidelines; specific periods may be longer where required by applicable law or where the information is the subject of a legal hold.
| Category | Retention Period |
|---|---|
| Vendor application and audit records (certified vendors) | Duration of certification plus seven (7) years |
| Vendor application records (declined or withdrawn applicants) | Twenty-four (24) months from final decision or withdrawal |
| Communications and contact-form submissions | Thirty-six (36) months from last interaction |
| Vendor outreach records for vendors that do not request an application (Section 3.4) | Product list and contact details: thirty (30) days after the last outreach message. Business name, website address, and contact dates: twelve (12) months after the last outreach message |
| Unsubscribe (suppression) list (Section 3.4) | For as long as we conduct vendor outreach |
| Billing and payment records (Phase 2 onward) | Seven (7) years for tax and accounting compliance |
| Server logs and security event records | Up to twelve (12) months |
| Aggregated and anonymized analytics | No fixed period (no longer constitutes personal information) |
When the applicable retention period expires, we will delete or irreversibly anonymize the personal information.
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards include access controls, encryption of data in transit, secure cloud infrastructure, and ongoing review of our information-security practices.
No method of electronic transmission or storage is completely secure, and we cannot guarantee the absolute security of personal information. You are responsible for maintaining the confidentiality of any account credentials you receive in connection with the Services. If you suspect that your interaction with us has been compromised, contact us immediately using the information in Section 12.
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights with respect to your personal information, subject to the conditions and limitations set out in the GDPR and UK GDPR:
To exercise any of these rights, contact us using the information in Section 12. We will respond within the period required by applicable law (generally one month, extendable by up to two further months for complex requests). We do not currently maintain a representative in the European Union under Article 27 of the GDPR; this Policy will be updated if we appoint one.
Depending on your state of residence, you may have rights under United States state privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comprehensive privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Jersey, New Hampshire, and other states with similar laws. Subject to the conditions and limitations of the applicable statute, those rights generally include:
California residents may designate an authorized agent to make a request on their behalf. We may require verification of the agent's authority and your identity before responding.
You may submit a privacy rights request by emailing privacy@gibq.org. We will need to verify your identity before responding to certain requests. Verification will be proportionate to the sensitivity of the data and the nature of the request. We will not charge a fee for responding to a request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act, as permitted by applicable law.
We use a small number of strictly-necessary cookies for site functionality and security (for example, session and CSRF cookies). We also use privacy-friendly analytics that do not set tracking cookies, do not collect personally identifying information, and do not perform cross-site tracking.
We may, in the future, use additional cookies and similar technologies for advertising, conversion measurement, or behavioral analytics. If we do, we will update this Policy and deploy a consent management tool that permits you to accept or reject those non-essential categories before they are activated. Until that time, no advertising or cross-site tracking technologies are loaded on the Services.
You can configure your browser to refuse all cookies or to alert you when cookies are being sent. If you reject strictly-necessary cookies, parts of the Services may not function correctly.
For full details, see our Cookie Policy.
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will revise the "Effective Date" at the top of this Policy and, if the changes are material, provide additional notice through the Services or by other reasonable means. Your continued use of the Services after the Effective Date of an updated Policy constitutes your acknowledgment of the updated Policy.
Questions, concerns, and privacy rights requests may be directed to:
GIBQ Operations LLC Attn: Privacy Officer Email: privacy@gibq.org General inquiries: info@gibq.org Website: gibq.org
This Privacy Policy and any disputes arising under or in connection with it shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict-of-laws principles. Any action, suit, or proceeding arising under or in connection with this Policy shall be brought exclusively in the state or federal courts located in Wilmington, Delaware, and the parties consent to the personal jurisdiction of such courts and waive any objection based on inconvenient forum.
Nothing in this Section 13 limits any non-waivable rights you may have under the consumer protection or privacy laws of your state, country, or region of residence.
| Version | Effective Date | Summary |
|---|---|---|
| 1.1 | September 22, 2026 | Prior version. |
| 1.2 | September 23, 2026 | (1) Adds Section 3.4 on business contact details collected from vendors' public websites for vendor outreach, including U.S.-only outreach, the unsubscribe and suppression-list practice, and the thirty-day discard rule, with the corresponding purpose in Section 4 and retention periods in Section 7. (2) Names the current service providers in Section 5.1 by category. (3) Updates the description of the public registry in Section 5.3 to reflect that it lists every certificate ever issued with its current status and status dates, and never the reasons for a status change. No other changes. |
GIBQ Operations LLC · Privacy Policy v1.2 · September 23, 2026 GIBQ™ and GIBQ Verified™ are unregistered trademarks of GIBQ Operations LLC.