GIBQ — Global Institute for Biomedical Quality
  • Documents
  • Standards
  • Registry
  • For Buyers
  • About
  • Newsroom
Apply

Legal

Privacy Policy

Privacy Policy

Version 1.4 Effective Date: September 24, 2026

gibq.org is operated by GIBQ Operations LLC, a Delaware limited liability company.


1. Introduction

This Privacy Policy describes how GIBQ Operations LLC, a Delaware limited liability company ("we," "us," "our," or "GIBQ Operations"), collects, uses, discloses, and safeguards information when you visit gibq.org, submit a vendor application, communicate with us, or otherwise interact with services we operate (collectively, the "Services").

GIBQ Operations is the data controller for personal information processed in connection with the Services. GIBQ Operations LLC currently owns all GIBQ intellectual property. GIBQ™ and GIBQ Verified™ are unregistered trademarks of GIBQ Operations LLC. A future two-entity structure with a separate standards-holding nonprofit may be established.

By accessing the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, do not use the Services.

2. Scope and Vendor Eligibility

This Policy applies to all visitors to gibq.org, all vendors submitting an application for verification under the GIBQ Verified standard, and all persons who otherwise communicate with us in connection with the Services.

2.1 Phase 1 — United States Vendors Only

During Phase 1, vendor applications for GIBQ Verified status are accepted only from entities legally formed and operating in the United States. Vendor applications submitted from outside the United States will not be processed during Phase 1. We may expand vendor eligibility to additional jurisdictions in subsequent phases; if we do, this Policy will be updated accordingly.

Notwithstanding the Phase 1 vendor restriction above, gibq.org is accessible globally. Visitors from outside the United States, including the European Economic Area ("EEA"), the United Kingdom, and Canada, may browse the website, read about the GIBQ Verified standard, and contact us. Such visitors are entitled to the rights described in Section 9 below.

3. Information We Collect

We collect only information that is reasonably necessary to evaluate vendor applications, operate the Services, communicate with you, and meet our legal obligations. We do not sell personal information.

3.1 Information You Provide

  • Vendor application data: legal entity name, business address, contact person's name and title, business email address, business telephone number, website URL, and a description of the products you intend to submit for verification.
  • Audit submission data: Certificates of Analysis ("COAs"), product labels, packaging artwork, supporting test methodology documentation, lot numbers, and any sworn attestation forms required as part of the GIBQ Verified audit process.
  • Payment information (Phase 2 onward): when paid tiers become available, billing contact information and payment method details. Payment card numbers are processed by our third-party payment processor and are not stored on our systems.
  • Communications: emails, contact-form submissions, and any correspondence you send to us, including the metadata associated with those communications.

3.2 Information Collected Automatically

  • Technical data: IP address, browser type and version, operating system, device type, referring URL, pages viewed, and timestamps of activity.
  • Privacy-friendly analytics: aggregated, non-identifying usage data collected through Vercel Analytics and Vercel Speed Insights. These tools do not set tracking cookies, do not collect personally identifying information, and do not perform cross-site tracking.
  • Strictly-necessary cookies: a small number of cookies required for the website to function, such as session and security cookies. These cookies are exempt from consent requirements under applicable law.

3.3 Information We Do Not Collect

We do not knowingly collect personal information from minors under the age of sixteen (16). The Services are intended for business and professional use only. If you believe a minor has provided personal information to us, please contact us using the address in Section 12 and we will delete it.

We do not collect or process special categories of data (such as health, biometric, racial or ethnic, religious, or political data) in the ordinary course of operating the Services.

3.4 Information We Collect from Vendors' Public Websites

To invite research peptide vendors to apply for GIBQ Verified status, we collect a limited amount of business information that vendors have published on their own websites. This consists of the vendor's business name and website address, the names of products for which the vendor publishes documentation, and the business contact details the vendor lists publicly, such as a general business email address and, where the vendor publishes them, the name, title, and business email address of a contact person. We collect this information only from the vendor's own website. We may use AI-assisted research tools to identify the vendor's business name, website address, product names, and general business email address, meaning an address such as info@ or sales@ that does not identify an individual. A member of our staff reviews the source web page and confirms each item before we use it. The name, title, and business email address of a contact person are collected by hand by a member of our staff, and not with automated or AI-assisted tools. Our AI-assisted research tools do not access websites that state they do not wish to receive unsolicited messages or whose robots.txt file disallows automated access. We do not obtain this information from purchased or rented lists, data brokers, or other third parties.

We send outreach only to vendors located in the United States, and only to business email addresses that the vendor has published. We do not send outreach to an address on a website that states it does not wish to receive unsolicited messages. Each outreach message identifies itself as a solicitation, includes our postal address, and offers an unsubscribe link and the option to reply "unsubscribe." We honor unsubscribe requests within ten (10) business days.

If a vendor does not respond within thirty (30) days after our last outreach message, we discard the product list and contact details collected for it. We retain only the vendor's business name, its website address, and the dates we contacted it, so that we do not contact the vendor again within twelve (12) months. If a vendor responds and requests an application, the information becomes vendor application data under Section 3.1. This does not remove a supplier's general business email address from the Supplier Contact Directory described in Section 3.5, which is maintained separately.

When a person unsubscribes, we record that person's email address and the associated business name on a suppression list, and we keep that record for as long as we conduct vendor outreach so that the request continues to be honored. We use the suppression list only to prevent further messages and do not share it with anyone other than the service providers that deliver our email.

3.5 Supplier Contact Directory and "Ask Your Supplier" Page

We maintain a directory of research peptide suppliers based in the United States, for use on our "Ask Your Supplier" page at gibq.org/ask. For each supplier, the directory contains only the supplier's business name, its website address, a general business email address that the supplier publishes on its own website, the address of the web page on which that email address is published, and the date the entry was verified. The directory does not contain the names, personal email addresses, or other personal information of individuals. To build the directory, we use AI-assisted research tools that visit each supplier's own website and identify these items. A member of our staff then opens the recorded web page and confirms each item against it before the entry is added. No entry is added without that review. We do not use purchased or rented lists, data brokers, or other third-party sources, and we do not collect addresses from websites that state they do not wish to receive unsolicited messages or whose robots.txt file disallows automated access.

The directory is searchable on the page, one supplier at a time, and is not published as a list. Inclusion in the directory does not indicate any application to GIBQ, any relationship with GIBQ, or any evaluation by GIBQ. We exclude any address on our suppression list (Section 3.4). A supplier may request removal at gibq.org/directory/removal. We remove the listing within five (5) business days and re-list it only at the supplier's request.

The "Ask Your Supplier" page does not ask visitors for their name or email address. When a visitor chooses to contact a supplier, the visitor's own email program opens a pre-written message that the visitor may edit and send. We do not send, receive, or store that message. If a visitor chooses to suggest a supplier for certification, we record only the supplier name, the supplier website, and the date. We use suggestions to decide which suppliers to contact, and to report to suppliers the number of suggestions that have named them. We do not record who made a suggestion. Technical data described in Section 3.2 is processed in the ordinary course and is not linked to searches, messages, or suggestions.

4. How We Use Information and Our Legal Bases

We use the information described in Section 3 only for the purposes set out in the table below. The legal bases identified are those applicable under the European Union General Data Protection Regulation ("GDPR") and the United Kingdom General Data Protection Regulation ("UK GDPR"). For United States residents, the equivalent purposes are described in Section 9.2.

PurposeCategories of DataLegal Basis (GDPR/UK GDPR)
Evaluate vendor applications and conduct the GIBQ Verified auditVendor application and audit submission dataPre-contractual measures (Art. 6(1)(b))
Issue, maintain, suspend, or revoke GIBQ Verified status; maintain the public registryVendor application data; audit results; communicationsPerformance of contract (Art. 6(1)(b))
Operate, secure, and improve the website and ServicesTechnical data; aggregated analyticsLegitimate interests (Art. 6(1)(f))
Communicate with you and respond to inquiriesContact information; communicationsLegitimate interests (Art. 6(1)(f))
Invite vendors to apply for GIBQ Verified status, and honor unsubscribe requests (Section 3.4)Business contact details and product names collected from vendors' public websites; suppression listLegitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) for honoring unsubscribe requests
Operate the Supplier Contact Directory and "Ask Your Supplier" page; record supplier suggestions (Section 3.5)Supplier business names, website addresses, published general business email addresses, source web page addresses, and verification dates; supplier suggestions (supplier name, website, date)Legitimate interests (Art. 6(1)(f))
Comply with legal, regulatory, accounting, audit, and tax obligationsAll categories as requiredLegal obligation (Art. 6(1)(c))
Protect, establish, exercise, or defend legal claimsAll categories as requiredLegitimate interests (Art. 6(1)(f))
Process payments (Phase 2 onward)Billing and payment informationPerformance of contract (Art. 6(1)(b))

We do not engage in automated decision-making that produces legal or similarly significant effects on individuals. Vendor audit determinations are reviewed and approved by a qualified human reviewer.

5. How We Share Information

We share personal information only as described below. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

5.1 Service Providers and Sub-Processors

We engage third-party service providers to perform functions on our behalf, including website hosting, email delivery, document storage, payment processing (Phase 2 onward), and analytics. Except for the AI-assisted research providers described below, these providers process information only as instructed by us and under written agreements that require confidentiality and appropriate safeguards. Our current service providers, by category, are:

  • Cloud hosting and content delivery: Vercel
  • Database, authentication, document storage, and back-office tooling: Supabase
  • Email delivery, including vendor outreach and transactional messages: Resend
  • Rate limiting, caching, and security: Upstash
  • Error monitoring: Sentry
  • AI-assisted research: third-party artificial intelligence service providers
  • Productivity and email infrastructure: Google Workspace
  • Privacy-friendly analytics: Vercel Analytics and Vercel Speed Insights
  • Payment processing (Phase 2 onward): not yet engaged

We engage AI-assisted research providers through standard commercial subscriptions and on their standard terms of service, not under agreements negotiated with us. Where a provider offers a setting that prevents information we submit from being used to train its models, we turn that setting on. We use these providers only to identify business information that suppliers and vendors publish on their own websites, as described in Sections 3.4 and 3.5. We do not submit vendor application materials, audit records, communications, or other information we hold to them.

We will update this list when we add or change a service provider.

5.2 Future Standards-Holding Entity

No separate standards-holding entity currently exists, and we do not disclose personal information to any such entity. If a separate standards-holding nonprofit is established in the future, we will update this Policy before sharing any information with it.

5.3 Public Registry

We maintain a public registry on gibq.org, including a searchable registry at gibq.org/certified-vendors and verification pages at gibq.org/verify. The registry lists every certificate that has ever been issued, together with its current status: active, suspended, under appeal, revoked, expired, or withdrawn. For each certificate, the registry displays the vendor's legal entity name, trade names, and brand names; its website domains; the certificate number; the version of the GIBQ 7-Point Standard; the products covered by the certificate; the current status; and the dates on which the certificate was issued, expires or expired, and changed status. The registry does not display the reasons for any suspension or revocation. Declined or closed applications, and vendors that have not applied, are not listed. The public registry does not include personal information about individual employees of the vendor unless the vendor expressly authorizes such disclosure.

5.4 Legal and Safety Disclosures

We may disclose information when we believe in good faith that disclosure is required by law, court order, or governmental request; necessary to enforce our agreements or this Policy; or appropriate to protect the rights, property, or safety of GIBQ Operations, its affiliates, vendors, users, or the public.

5.5 Business Transfers

If GIBQ Operations is involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency proceeding, personal information may be transferred to the relevant counterparty as part of that transaction. Any such transfer will remain subject to the protections set out in this Policy or a successor policy that provides equivalent protections.

5.6 With Your Direction

We share information with third parties when you direct us to do so or otherwise consent to the disclosure.

6. International Data Transfers

GIBQ Operations LLC is established in the United States, and the Services and supporting infrastructure are hosted primarily in the United States. Some of our service providers, including our AI-assisted research providers, may process information in other countries. If you access the Services from outside the United States, the information we collect about you will be transferred to, stored in, and processed in the United States, and may be processed in other countries by those service providers.

The United States may not provide the same level of legal protection for personal information as your country of residence. For transfers of personal information from the EEA, the United Kingdom, or Switzerland to the United States, we rely on the Standard Contractual Clauses approved by the European Commission (and, as applicable, the UK International Data Transfer Addendum) as the legal mechanism for the transfer. A copy of the relevant clauses is available on request using the contact information in Section 12. Our AI-assisted research concerns only suppliers and vendors based in the United States, and we do not use AI-assisted research providers to process information we receive from the EEA, the United Kingdom, or Switzerland.

7. Data Retention

We retain personal information only for as long as necessary for the purposes for which it was collected, to comply with our legal, accounting, or reporting obligations, or to establish, exercise, or defend legal claims. The retention periods below are guidelines; specific periods may be longer where required by applicable law or where the information is the subject of a legal hold.

CategoryRetention Period
Vendor application and audit records (certified vendors)Duration of certification plus seven (7) years
Vendor application records (declined or withdrawn applicants)Twenty-four (24) months from final decision or withdrawal
Communications and contact-form submissionsThirty-six (36) months from last interaction
Vendor outreach records for vendors that do not request an application (Section 3.4)Product list and contact details: thirty (30) days after the last outreach message. Business name, website address, and contact dates: twelve (12) months after the last outreach message
Unsubscribe (suppression) list (Section 3.4)For as long as we conduct vendor outreach
Supplier Contact Directory entries (Section 3.5)Until the supplier requests removal, the address is added to the suppression list, or we determine the address is no longer published by the supplier
Supplier suggestions (Section 3.5)Twenty-four (24) months from submission; aggregate counts may be kept indefinitely
Billing and payment records (Phase 2 onward)Seven (7) years for tax and accounting compliance
Server logs and security event recordsUp to twelve (12) months
Aggregated and anonymized analyticsNo fixed period (no longer constitutes personal information)

When the applicable retention period expires, we will delete or irreversibly anonymize the personal information.

8. Security

We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards include access controls, encryption of data in transit, secure cloud infrastructure, and ongoing review of our information-security practices.

No method of electronic transmission or storage is completely secure, and we cannot guarantee the absolute security of personal information. You are responsible for maintaining the confidentiality of any account credentials you receive in connection with the Services. If you suspect that your interaction with us has been compromised, contact us immediately using the information in Section 12.

9. Your Rights

9.1 Rights for Persons in the EEA, the United Kingdom, and Switzerland

If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights with respect to your personal information, subject to the conditions and limitations set out in the GDPR and UK GDPR:

  • Right of access: you may request confirmation of whether we process personal information about you and, if so, request a copy of that information.
  • Right to rectification: you may request that we correct inaccurate or incomplete personal information about you.
  • Right to erasure: you may request that we delete personal information about you in defined circumstances.
  • Right to restriction of processing: you may request that we limit how we process your personal information in defined circumstances.
  • Right to data portability: you may request a copy of personal information you have provided to us in a structured, commonly used, machine-readable format.
  • Right to object: you may object to processing of your personal information that is based on legitimate interests.
  • Right to withdraw consent: where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint: you have the right to lodge a complaint with the data protection authority of the country in which you reside, work, or where the alleged infringement took place.

To exercise any of these rights, contact us using the information in Section 12. We will respond within the period required by applicable law (generally one month, extendable by up to two further months for complex requests). We do not currently maintain a representative in the European Union under Article 27 of the GDPR; this Policy will be updated if we appoint one.

9.2 Rights for United States Residents

Depending on your state of residence, you may have rights under United States state privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comprehensive privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Jersey, New Hampshire, and other states with similar laws. Subject to the conditions and limitations of the applicable statute, those rights generally include:

  • The right to know what personal information we collect, use, disclose, and share.
  • The right to access and receive a copy of your personal information.
  • The right to correct inaccurate personal information.
  • The right to request deletion of your personal information.
  • The right to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not currently sell personal information or share it for cross-context behavioral advertising. If this changes, we will provide a clear opt-out mechanism on the website.
  • The right to limit the use and disclosure of sensitive personal information. We do not collect sensitive personal information in the ordinary course of operating the Services.
  • The right to non-discrimination for exercising any of the foregoing rights.

California residents may designate an authorized agent to make a request on their behalf. We may require verification of the agent's authority and your identity before responding.

9.3 How to Submit a Request

You may submit a privacy rights request by emailing privacy@gibq.org. We will need to verify your identity before responding to certain requests. Verification will be proportionate to the sensitivity of the data and the nature of the request. We will not charge a fee for responding to a request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act, as permitted by applicable law.

10. Cookies and Similar Technologies

We use a small number of strictly-necessary cookies for site functionality and security (for example, session and CSRF cookies). We also use privacy-friendly analytics that do not set tracking cookies, do not collect personally identifying information, and do not perform cross-site tracking.

We may, in the future, use additional cookies and similar technologies for advertising, conversion measurement, or behavioral analytics. If we do, we will update this Policy and deploy a consent management tool that permits you to accept or reject those non-essential categories before they are activated. Until that time, no advertising or cross-site tracking technologies are loaded on the Services.

You can configure your browser to refuse all cookies or to alert you when cookies are being sent. If you reject strictly-necessary cookies, parts of the Services may not function correctly.

For full details, see our Cookie Policy.

11. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will revise the "Effective Date" at the top of this Policy and, if the changes are material, provide additional notice through the Services or by other reasonable means. Your continued use of the Services after the Effective Date of an updated Policy constitutes your acknowledgment of the updated Policy.

12. Contact Information

Questions, concerns, and privacy rights requests may be directed to:

GIBQ Operations LLC Attn: Privacy Officer Email: privacy@gibq.org General inquiries: info@gibq.org Website: gibq.org

13. Governing Law and Venue

This Privacy Policy and any disputes arising under or in connection with it shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict-of-laws principles. Any action, suit, or proceeding arising under or in connection with this Policy shall be brought exclusively in the state or federal courts located in Wilmington, Delaware, and the parties consent to the personal jurisdiction of such courts and waive any objection based on inconvenient forum.

Nothing in this Section 13 limits any non-waivable rights you may have under the consumer protection or privacy laws of your state, country, or region of residence.

14. Revision History

VersionEffective DateSummary
1.1September 22, 2026Prior version.
1.2September 23, 2026(1) Adds Section 3.4 on business contact details collected from vendors' public websites for vendor outreach, including U.S.-only outreach, the unsubscribe and suppression-list practice, and the thirty-day discard rule, with the corresponding purpose in Section 4 and retention periods in Section 7. (2) Names the current service providers in Section 5.1 by category. (3) Updates the description of the public registry in Section 5.3 to reflect that it lists every certificate ever issued with its current status and status dates, and never the reasons for a status change. No other changes.
1.3September 24, 2026Section 3.4: "If a vendor does not reply within thirty (30) days" changed to "If a vendor does not respond within thirty (30) days," and "replies and requests" changed to "responds and requests," so that a request made through the request page, as well as by email reply, is treated as a response and converts outreach information into vendor application data. No other changes.
1.4September 24, 2026(1) Adds Section 3.5 on the Supplier Contact Directory and "Ask Your Supplier" page, including the use of AI-assisted research tools to identify directory entries on each supplier's own website, with staff confirmation of each entry against its source web page before it is added. (2) Section 3.4: replaces the statement that vendor information is collected by hand without automated scraping tools. Business names, website addresses, product names, and general business email addresses may now be identified with AI-assisted research tools and are confirmed by staff against the source web page; contact-person names, titles, and business email addresses remain collected by hand. Also states that the outreach discard rule does not remove directory entries. (3) Section 4: adds the purpose for the directory and supplier suggestions. (4) Section 5.1: adds AI-assisted research as a service-provider category, and states that those providers are engaged through standard commercial subscriptions on their standard terms, with model-training settings turned off where available, and are used only for the research described in Sections 3.4 and 3.5. (5) Section 6: states that the Services and supporting infrastructure are hosted primarily in the United States, that some service providers, including AI-assisted research providers, may process information in other countries, and that AI-assisted research providers are not used for information received from the EEA, the United Kingdom, or Switzerland. (6) Section 7: adds retention periods for directory entries and supplier suggestions. No other changes.

GIBQ Operations LLC · Privacy Policy v1.4 · September 24, 2026 GIBQ™ and GIBQ Verified™ are unregistered trademarks of GIBQ Operations LLC.

GIBQ
70 Middle Neck Road, Suite 5
Great Neck, NY 11021

Standards

7-Point StandardLabel StandardSeal PolicyMethodologyRegistry

About

About GIBQCertification ProcessFor SuppliersIndependenceAppeals & ComplaintsNewsroomDocuments

Contact

General inquiries

info@gibq.org

Press

press@gibq.org

Privacy & legal

privacy@gibq.org

© 2026 GIBQ Operations LLC. All rights reserved.

gibq.org is operated by GIBQ Operations LLC, a Delaware limited liability company. GIBQ Operations LLC currently owns all GIBQ intellectual property. GIBQ™ and GIBQ Verified™ are unregistered trademarks of GIBQ Operations LLC. A future two-entity structure with a separate standards-holding nonprofit may be established.

Privacy Policy·Terms of Service·Cookie Policy·Vendor Verification Agreement