Skip to content

PEPTAS

Privacy Policy

Privacy Policy
Effective and last updated: July 29, 2026

1. Scope and our privacy commitment

This Privacy Policy explains how Peptas.com collects, uses, stores, discloses, and protects personal data. It applies to Site visitors, account holders, prospective customers, customers, consignees, payers, institutional contacts, suppliers, and people who communicate with us. It should be read with any shorter Personal Information Collection Statement shown at the point where information is requested.

For purposes of Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486), the data user is Ikigai Corporation Limited, a company registered in Hong Kong (Business Registration No. 69705679) with registered office at Room 1213, 12/F., Tower A, Hunghom Commercial Centre, 39 Ma Tau Wai Road, Hunghom, Kowloon, Hong Kong, which owns and operates Peptas.com and determines the purpose and manner of the relevant processing. Operator details are also stated on the Regulatory Information page. Privacy questions and requests can be sent to info@peptas.com.

We seek to follow the Data Protection Principles concerning purpose and manner of collection, accuracy and retention, use, security, openness, and access and correction. We collect data that is reasonably necessary for genuine business and legal purposes, explain those purposes, and do not sell sensitive research-order information as a business model.

2. Personal data we collect

Depending on how you interact with us, we may collect the following categories:

  • Identity and contact data: name, title, age or confirmation of age, organization, department, professional role, billing and delivery addresses, email address, telephone number, and preferred language.
  • Account and authentication data: username, encrypted or hashed password information maintained by the Site platform, account preferences, login history, security events, and verification status.
  • Order and research-context data: Products viewed or ordered, quantities, quotation requests, order numbers, lawful intended-use statements, end-user and consignee information, permit or licence details, institutional affiliation, shipping instructions, returns, complaints, and customer-service correspondence.
  • Transaction data: payment method type, payment status, currency, invoice information, limited payment references, fraud-screening results, refunds, and chargeback records. Full card credentials are generally entered into and handled by a payment processor rather than intentionally stored by Peptas, but the processor may return a token, card brand, last digits, or risk result.
  • Technical and usage data: internet protocol address, device and browser information, operating system, approximate location inferred from network data, referral source, pages viewed, searches, interactions, timestamps, cookie identifiers, and diagnostic logs.
  • Compliance and security data: identity evidence, sanctions or fraud review information, business registration information, import and export documentation, communications about prohibited use, and records needed to investigate misuse, safety, or legal obligations.
  • Communications and marketing data: messages, attachments, survey responses, consent choices, subscription status, support history, and records of requests not to receive direct marketing.

We do not ask you to send health information, clinical data, patient records, or information about personal use of research materials. Do not include such data in an order note or support message. If you send unnecessary sensitive information, we may delete, restrict, or retain a minimal record as reasonably needed for safety, legal compliance, or incident handling.

3. Sources of personal data

We collect data directly from you when you browse, create an account, place an order, request a quotation, subscribe, contact support, submit documentation, or exercise a right. We may receive data from your employer, institution, purchasing agent, payer, consignee, or colleague when they include you in a transaction. If you provide another person’s data, you represent that you are authorized to do so and have given any notice required by law.

We may receive transaction and risk data from payment processors, identity-verification providers, banks, fraud-prevention services, sanctions screening sources, carriers, customs agents, ecommerce providers, hosting providers, analytics services, and cookie-consent tools. We may also use public professional or government records when reasonably necessary to verify an organization, licence, sanctions status, or apparent fraud. We do not use intrusive data collection merely because information is publicly accessible.

4. Why we use personal data

We may use personal data for the following purposes, where reasonably related to the purpose of collection or otherwise permitted by law:

  • to operate, secure, troubleshoot, and improve the Site;
  • to create and administer accounts and authenticate users;
  • to respond to inquiries, prepare quotations, process orders, issue invoices, collect payment, arrange delivery, and provide support;
  • to verify age, identity, institutional authority, end use, consignee, destination, licences, sanctions status, and transaction legitimacy;
  • to prevent fraud, diversion, prohibited human or veterinary use, security incidents, abuse, and unlawful transactions;
  • to manage inventory, testing documentation, batch traceability, complaints, replacements, refunds, recalls, safety notices, and product-quality investigations;
  • to comply with tax, accounting, customs, import, export, pharmaceutical, controlled-chemical, court, regulatory, and law-enforcement obligations;
  • to establish, exercise, or defend legal claims and enforce Site policies;
  • to understand aggregate Site use, improve navigation, measure performance, and maintain consent preferences;
  • to send service messages, including order, security, policy, compliance, and delivery notices; and
  • to send direct marketing only where the required notice and consent or indication of no objection has been obtained, and always subject to an effective opt-out.

Under Hong Kong law, personal data generally should not be used for a new purpose unrelated to the original purpose without the prescribed consent, unless a statutory exemption applies. If we want to use identifiable data for a materially new purpose, we will seek consent or rely on another lawful route available under Applicable Law. Where the law of another jurisdiction applies, we rely on an appropriate basis such as contract necessity, legal obligation, legitimate interests balanced against individual rights, consent, or protection of vital interests.

5. Whether providing data is mandatory

You may browse basic Site content without creating an account, subject to cookies and technical logs. Data marked required in a form is needed for the stated purpose. If you do not provide required identity, order, payment, delivery, or compliance information, we may be unable to create an account, respond fully, accept an order, ship, process a claim, or comply with a legal request.

Marketing consent is optional and should be presented separately from acceptance of purchase terms. Refusing marketing does not prevent an ordinary order. We may still send non-promotional messages needed for an existing transaction, security, legal compliance, or material policy change. Where feasible, we support guest checkout so an account is not required solely to make a purchase.

6. Cookies and similar technologies

We use cookies, local storage, tags, pixels, and similar technologies for strictly necessary Site functions, security, cart and checkout operation, preference storage, analytics, and, where enabled and consented to, marketing. Our Cookie Policy gives more detail about categories, choices, likely recipients, and browser controls.

Strictly necessary technologies may operate without optional consent where permitted because the service cannot function securely without them. Non-essential analytics or advertising technologies should be controlled through the consent banner where required. The PEPTAS first-party consent manager stores and communicates your choices. Rejecting optional cookies is designed to be as straightforward as accepting them, although some preference or embedded features may not work.

Cloudflare Turnstile is used on selected contact, authentication, account, checkout, payment, and order-tracking forms to distinguish legitimate submissions from automated abuse. When a protected form is displayed or submitted, Cloudflare may process network and device information, browser characteristics, interaction signals, the Site hostname, the form action, and a short-lived verification result. PEPTAS receives the result needed to accept or reject the submission and does not expose the secret verification credential to the browser. We classify this processing as strictly necessary security processing rather than optional audience analytics. Cloudflare’s independent processing is described in its privacy policy.

7. Direct marketing

We may use your name, business contact details, customer relationship, and broad areas of product interest to send information about research products, availability, events, or company updates only after giving the notice required by Hong Kong law and obtaining consent or an indication of no objection in the required form. We do not combine mandatory transaction acceptance with an unavoidable direct-marketing consent.

You can opt out at any time by using an unsubscribe link or emailing info@peptas.com. We will stop the relevant direct marketing without charge and keep a suppression record so we do not accidentally re-enroll the same address. An opt-out does not prevent order confirmations, safety notices, compliance requests, or replies to your messages. We do not provide personal data to another person for that person’s direct marketing in return for money or other property without the specific notice and written consent required by law.

8. Who may receive personal data

We disclose only what is reasonably necessary for the relevant purpose. Recipients may include:

  • hosting, ecommerce, security, maintenance, email, customer-support, analytics, and consent-management providers;
  • payment processors, banks, fraud-prevention and identity-verification providers;
  • warehouses, packaging providers, carriers, freight forwarders, brokers, insurers, laboratories, and quality consultants;
  • professional advisers, auditors, accountants, and insurers under appropriate duties;
  • customs, tax, health, trade, sanctions, law-enforcement, judicial, and regulatory authorities where disclosure is required or legally permitted;
  • a genuine buyer, investor, lender, successor, or restructuring participant subject to confidentiality and data-protection safeguards; and
  • your employer, institution, purchasing organization, payer, consignee, or authorized representative where relevant to the transaction.

Service providers are expected to process data under instructions, protect it, and use it only for authorized purposes, subject to their independent legal duties. Some providers, such as banks, carriers, and government authorities, may act as independent data users for their own required purposes. We do not authorize a provider to use confidential research-order details for unrelated advertising.

9. Cross-border data transfers

Peptas serves international customers and may use service providers or infrastructure outside Hong Kong. Personal data may therefore be stored, accessed, or processed in a jurisdiction with different privacy laws. We take reasonably practicable steps to assess recipients, limit data, use contractual safeguards, apply security controls, and provide notice appropriate to the transfer.

Where a law requires a recognized transfer mechanism, we will use one that is available and appropriate, such as contractual clauses, a statutory exception, or explicit consent where valid. Hong Kong’s cross-border-transfer requirements and regulatory guidance may evolve. We will update practices when binding requirements take effect. A customer must not use the Site to transfer patient data, clinical records, or regulated research-participant data to us.

10. Retention and deletion

We retain personal data only as long as reasonably necessary for the purpose of collection and related lawful purposes. Criteria include the account relationship, order lifecycle, product traceability and safety needs, warranty and complaint periods, tax and accounting rules, customs and trade records, payment disputes, fraud prevention, direct-marketing suppression, legal limitation periods, investigations, and the need to establish or defend claims.

Different records have different periods. A failed cart may be retained for less time than an invoice or compliance record. We may keep a minimal suppression entry after deleting marketing-profile data. Backup copies are protected and age out under backup schedules rather than being individually edited immediately. When data is no longer needed, we delete, anonymize, or securely isolate it unless law requires retention.

You may request deletion, but the right is not absolute under every law. We may retain data needed to complete an order, comply with legal duties, investigate prohibited use, prevent fraud, resolve a dispute, maintain safety and batch records, or exercise legal rights. We will explain a refusal where legally required and not prohibited.

11. Accuracy and account choices

We take reasonably practicable steps to keep data accurate for the purpose for which it is used. You can help by updating account details and promptly correcting changes to contacts, authority, consignee, address, permits, or tax information. We may confirm important details before shipping or responding to a sensitive request.

Do not replace an account holder with a different person if audit history must be preserved. Contact us to correct the record. We may retain prior values in transaction or security logs where needed for integrity. A correction to profile data does not automatically rewrite an invoice, customs declaration, or historical record that was accurate when created.

12. Security

We use technical and organizational measures appropriate to the nature of the data and reasonably foreseeable risks. Measures may include access controls, least-privilege administration, transport encryption, password hashing, managed hosting controls, malware and vulnerability monitoring, backups, logging, payment-provider tokenization, staff confidentiality, service-provider review, and incident procedures.

No internet service or storage system can be guaranteed completely secure. You must use a strong unique password, secure your email and devices, sign out of shared systems, and promptly report suspicious activity. Do not send card details, passwords, government identifiers, patient records, or unnecessary confidential information by ordinary email.

If a personal-data incident occurs, we will investigate, contain, document, and notify affected people or authorities when required or appropriate in light of the risk. A security statement is not a warranty against all attacks, and it does not reduce any duty imposed on us by law.

13. Access, correction, and other privacy rights

Under Hong Kong law, an individual may make a data-access request and, after obtaining access, request correction of inaccurate personal data, subject to statutory procedures, exemptions, identity verification, permitted fees, and response periods. You may also ask about the kinds of data we hold and our main policies and practices. Requests should identify the data and relationship clearly enough for us to locate records.

Depending on where you live and which law applies, you may also have rights to object, restrict processing, withdraw consent, request deletion, obtain portability, or complain to a privacy regulator. These rights may be limited by legal obligations, third-party rights, security, privilege, fraud prevention, research integrity, or exceptions in the relevant law. Withdrawing consent does not invalidate processing already lawfully performed and may make a requested service impossible.

Send requests to info@peptas.com with the subject “Privacy Request.” We may ask for proportionate identity evidence and proof of authority for a representative. We will not request more data than reasonably needed for verification. If we cannot comply, we will give the explanation required by law. Hong Kong residents may contact the Office of the Privacy Commissioner for Personal Data regarding concerns.

14. Age restriction

The Site and Products are intended for adults aged 21 or older acting in a professional or institutional capacity. We do not knowingly solicit personal data from children or permit minors to order. If you believe a minor supplied personal data, contact us so we can investigate and delete or restrict it where appropriate. This age rule is a commercial and safety control and does not claim that every visitor is verified through a government identity check.

15. Automated tools and fraud decisions

Payment, security, and fraud providers may generate automated risk indicators. We may use them to request verification, delay, or refuse a transaction. We do not intend to make a solely automated decision that produces a legally significant effect where Applicable Law requires human review. You may contact us to explain relevant facts or challenge an apparent error, subject to limits needed to protect confidential anti-fraud methods.

16. Changes and contact

We may update this Privacy Policy when data practices, providers, Products, laws, or Site features change. Material changes will receive an additional notice where appropriate or required. The current version applies prospectively from the displayed effective date. Prior versions may be retained for compliance records.

For privacy questions, access or correction requests, marketing opt-outs, or concerns about a provider, email info@peptas.com. Include your name, relationship to Peptas, relevant order or account reference, jurisdiction, and the specific request. Do not send unnecessary identity documents until we explain a secure verification method.


General Legal Provisions Applying to This Policy

The provisions in this section form part of this policy and should be read together with the policy-specific sections above. They are included so that important rules are not left to implication. If a policy-specific provision directly conflicts with a provision in this section, the policy-specific provision controls for the subject covered by that policy. If these provisions conflict with a non-waivable right under applicable law, the non-waivable right controls only to the extent of that conflict.

Definitions and interpretation

In these provisions, “Peptas,” “we,” “us,” and “our” mean the person or entity that owns and operates Peptas.com and supplies the relevant products or services as identified in the written quotation, the order confirmation, the invoice, or legally required business information displayed on the Site. “Site” means Peptas.com and any page, account area, form, communication, or digital service operated under that domain. “Product” means an item offered through the Site. “Customer,” “you,” and “your” mean the person visiting the Site, submitting information, creating an account, requesting a quotation, or placing an order, and any organization on whose behalf that person acts. “Applicable Law” means every law, regulation, court order, licence condition, import or export control, sanctions measure, professional rule, and binding government requirement that applies to the relevant person, Product, transaction, shipment, or activity.

Headings, summaries, examples, frequently asked questions, and tables are provided for readability. They do not limit the operative wording. Words such as “including,” “includes,” and “for example” are illustrative and do not create an exhaustive list. A reference to writing includes email and other electronic records unless Applicable Law requires another form. Singular words include the plural and vice versa where the context permits. A duty not to do something includes a duty not to authorize, assist, encourage, or permit another person to do it. References to a statute include amendments, replacements, subsidiary legislation, and official requirements made under it.

Nothing on the Site creates a partnership, joint venture, fiduciary relationship, employment relationship, agency, medical relationship, or professional advisory relationship between you and Peptas. No person may bind Peptas or make a representation on its behalf unless that authority is confirmed in writing by an authorized representative. Product information, customer-service responses, educational material, and links are not legal, medical, clinical, regulatory, tax, customs, investment, or other professional advice.

Authority, eligibility, and institutional responsibility

You may use the Site and transact with us only if you are at least 21 years old, have legal capacity to enter a binding agreement, and are not prohibited by Applicable Law from accessing the Site or acquiring the Products. If you act for a company, university, laboratory, government body, clinic, reseller, or other organization, you represent that you have authority to bind that organization and that the organization accepts responsibility for your acts and omissions. We may request reasonable evidence of age, identity, professional status, institutional affiliation, intended research purpose, destination, end user, funding source, or authority to order.

The person placing an order is responsible for ensuring that every employee, contractor, student, principal investigator, consignee, agent, and downstream recipient who may possess or handle a Product is appropriately qualified, trained, authorized, and supervised. Internal approval by an employer or institution does not replace a government licence, ethics approval, import permit, controlled-substance authorization, or other external requirement. An account, quotation, invoice, order acceptance, shipment, or prior sale does not establish eligibility for any later transaction.

We may refuse registration, restrict an account, request additional verification, cancel an order, withhold shipment, limit quantities, or end a relationship if we reasonably believe that a transaction presents a safety, fraud, sanctions, reputational, legal, regulatory, payment, diversion, or misuse risk. We may do so without disclosing confidential screening criteria or information that could defeat fraud or compliance controls. We will exercise these rights subject to Applicable Law and will not rely on them to avoid a mandatory obligation already owed to you.

Research-use framework

Unless a Product page expressly states otherwise and the statement is legally authorized, Products offered on the Site are supplied exclusively as laboratory research materials. They are not medicines, foods, dietary supplements, cosmetics, consumer chemicals, veterinary products, diagnostic products, or medical devices. They are not offered for administration to humans or animals, for compounding, for clinical investigation without required authorization, or for the diagnosis, prevention, mitigation, treatment, or cure of any disease or condition. Labels such as “research use only” and “not for human or veterinary use” are material conditions of sale and use, not marketing slogans.

You must not ingest, inject, inhale, implant, apply, administer, prescribe, dispense, recommend, resell for personal use, or otherwise expose a human or animal to a Product. You must not use a Product as an active ingredient in a food, supplement, cosmetic, drug, medicine, veterinary preparation, or consumer product. You must not seek dosing, cycle, reconstitution-for-administration, treatment, or self-experimentation guidance from us. A discussion found elsewhere on the internet, a publication, a third-party practice, a product name, or a reference to an area of scientific investigation does not change these restrictions.

Products must be handled only in a suitable professional laboratory by trained personnel using an institutionally approved protocol, appropriate engineering controls, personal protective equipment, storage controls, waste procedures, incident response, and risk assessment. You are responsible for reviewing available safety information and determining whether additional testing, controls, approvals, or documentation are required for your intended lawful research. You must prevent unauthorized access and maintain custody records appropriate to the nature of the material.

You are responsible for identifying and complying with Applicable Law in every jurisdiction connected with your activity, including Hong Kong, the billing location, shipment origin, transit countries, destination, place of possession, place of research, and location of each end user. Requirements may concern pharmaceuticals, poisons, dangerous drugs, controlled chemicals, precursor chemicals, biological materials, customs classification, strategic commodities, import and export licensing, sanctions, anti-money-laundering controls, consumer protection, workplace safety, environmental disposal, research ethics, data protection, and professional practice.

Peptas remains responsible for legal duties that Applicable Law places on Peptas and that cannot lawfully be transferred to a customer. Your compliance obligation does not excuse our non-delegable duties. Likewise, our review of an order does not transfer your legal duties to us. We do not promise that a Product may lawfully be purchased, imported, possessed, resold, or used in every jurisdiction. Availability on the Site, receipt of a payment, issuance of a quotation, or successful delivery of a previous order is not legal clearance for a current transaction.

You must obtain all licences, permits, declarations, end-use statements, registrations, approvals, consents, and exemptions required for your role before the relevant activity occurs. On request, you must provide accurate supporting documents and cooperate with lawful due diligence. You must not misdescribe a Product, value, origin, end use, consignee, or transaction; divide orders to evade a limit; use a forwarding arrangement to avoid a restriction; or ask us to omit, alter, or falsify customs or shipping information. We may share information with carriers, payment providers, professional advisers, insurers, regulators, customs authorities, or law enforcement when reasonably necessary and legally permitted.

If a licence or approval is delayed, denied, suspended, or revoked, you must notify us promptly. We may suspend performance while the issue is reviewed. Neither party is required to perform an act that would violate Applicable Law. Where lawful performance is impossible, we may cancel the affected portion of the transaction and address any payment according to the applicable policy, the allocation of responsibility for the problem, costs already incurred, and mandatory law.

Electronic transactions and communications

You consent to transact and communicate electronically. Subject to Applicable Law, electronic records, click acceptance, checkbox selections, account activity, order submissions, emails, and system logs may satisfy requirements for writing, acceptance, delivery, and retention. You are responsible for providing a current email address and monitoring messages, account notices, tracking updates, and requests for information. A notice is not invalid merely because an automated filter or internal routing rule prevented you from reading it.

An automated acknowledgment confirms only that a submission reached our system. It is not necessarily acceptance of an order, confirmation of product availability, regulatory clearance, or a promise to ship. A binding sale is formed only at the point specified in the Terms and Conditions of Sale. We may correct an electronic transmission error before acceptance and may contact you to verify an instruction that appears incomplete, inconsistent, unusual, or unauthorized.

You must not impersonate another person, use an address or payment instrument without authorization, manipulate technical records, or deny an electronic action genuinely performed by you or under your control. We may use reasonable authentication and audit records to evaluate a dispute. This paragraph does not prevent you from showing that a record is inaccurate, compromised, or legally insufficient.

Site information, availability, and corrections

We aim to present accurate and current information, but scientific, regulatory, logistical, and commercial information can change. Site content may contain typographical errors, translation differences, outdated references, incomplete descriptions, or technical display problems. Images may be illustrative and colors, labels, vials, packaging, or batch presentation may vary. A reference standard, molecular description, publication, or research summary does not guarantee that a Product is suitable for a particular protocol or produces a particular result.

We may correct errors, update content, change specifications, discontinue Products, impose quantity limits, or suspend Site functions. Before a binding sale is formed, we may correct an obvious pricing, availability, tax, shipping, or description error and invite you to proceed on corrected terms. After a binding sale is formed, any correction that materially affects your rights will be handled under Applicable Law and the governing sale terms. We will not knowingly rely on a disclaimer to preserve a materially false trade description or misleading omission.

The Site may be unavailable because of maintenance, security events, hosting failures, carrier outages, software changes, government action, or circumstances beyond reasonable control. We do not promise uninterrupted or error-free access. You should retain copies of order records, policies, certificates, and communications needed for your institutional files. We may limit access to protect the Site, customers, data, systems, or legal compliance.

Third-party services, links, and statements

The Site may use or link to payment processors, carriers, analytics providers, consent tools, social networks, laboratories, publications, or other third parties. A link, technical integration, reference, or display of a third-party name does not mean that we control or endorse every statement, policy, security practice, product, or service of that party. Third parties may impose separate terms and privacy notices. You should review them before using the relevant service.

We are responsible for selecting and managing service providers to the extent required by Applicable Law. We are not responsible for an independent third party’s acts outside our control merely because its service is linked from the Site. However, this limitation does not remove responsibility that Applicable Law assigns to us for our own selection, instructions, representations, data handling, or non-delegable duties. A third-party laboratory report or certificate describes the sample and methods identified in that report; it is not a regulatory approval, medical endorsement, or universal guarantee about every unit or every possible use.

Reviews, testimonials, forum posts, and customer statements represent the views of their authors. They must not be interpreted as instructions for human or veterinary use. We may remove statements that promote prohibited use, make unsupported health claims, disclose confidential information, or violate law or Site rules. Removal does not mean that we can identify and prevent every improper statement.

Account and information security

You must provide complete and accurate information and keep it current. You are responsible for protecting passwords, devices, authentication methods, and account access. Do not share credentials with unauthorized persons. Notify us promptly at info@peptas.com if you suspect unauthorized access, a fraudulent order, or a compromise affecting information supplied to us. We may temporarily restrict an account while investigating.

You are responsible for actions taken through your account when they were authorized by you or resulted from your failure to use reasonable security. You are not responsible for actions caused solely by our breach of a legal duty or security failure. We may require re-authentication, identity evidence, or confirmation from an institutional email address before processing sensitive requests, changing delivery details, releasing records, or restoring access.

Prohibited conduct

You must not use the Site or Products to violate law, infringe rights, facilitate harm, evade controls, mislead another person, or interfere with systems. Prohibited conduct includes attempting unauthorized access; introducing malware; scraping in a way that disrupts service; reverse engineering security features; abusing promotional offers; making fraudulent claims; laundering funds; using stolen payment information; submitting false identity, end-use, customs, tax, or delivery information; promoting human or veterinary use; and reselling Products under false, misleading, or medically suggestive descriptions.

You must not remove or obscure warnings, batch identifiers, safety information, or chain-of-custody information. You must not relabel a Product as approved for a use for which it is not approved. You must not use our names, trademarks, documents, certificates, images, or test results to imply authorization, affiliation, clinical endorsement, or regulatory approval. We may preserve evidence, suspend service, cancel affected orders, and report reasonably suspected unlawful conduct where legally permitted.

Records, investigations, and cooperation

We may retain records reasonably needed to document consent, orders, payments, shipping, complaints, safety issues, compliance reviews, and legal obligations, subject to the Privacy Policy. In a dispute, relevant records may include order data, correspondence, payment authorization results, carrier scans, delivery photographs, access logs, batch records, certificates, submitted images, and statements from involved parties. No single category of record is automatically conclusive where Applicable Law requires a broader assessment.

You agree to cooperate reasonably with an investigation into fraud, diversion, damage, loss, unauthorized use, regulatory inquiry, safety concern, data request, or chargeback. Cooperation may include preserving packaging, providing photographs, confirming institutional authority, identifying the consignee, and returning or safely destroying material where lawful. We will not request information that is disproportionate to the matter, and privacy or legal requests may be subject to identity verification.

Events beyond reasonable control

Neither party is liable for delay or failure caused by an event beyond its reasonable control to the extent the event actually prevents performance and the affected party takes reasonable steps to reduce the effect. Events may include natural disasters, severe weather, epidemic or public-health measures, war, terrorism, civil disorder, sanctions, embargoes, sudden legal restrictions, customs action, carrier network disruption, labor disputes not limited to the affected party’s own workforce, power or telecommunications failures, cyberattacks by third parties, critical supplier failure, or government orders.

This provision does not excuse payment already due for Products properly supplied, a data-protection duty that can still reasonably be performed, or a duty that Applicable Law does not allow the parties to exclude. The affected party may receive a reasonable extension. If the disruption continues and substantially defeats the transaction, either party may exercise any cancellation right provided by the applicable policy or law. Allocation of prepaid amounts will take account of Products already supplied, irreversible costs lawfully chargeable, and mandatory rights.

Liability boundaries and mandatory rights

Every exclusion, limitation, waiver, indemnity, and allocation of risk in this policy applies only to the maximum extent permitted by Applicable Law. Nothing excludes or limits liability for fraud, fraudulent misrepresentation, willful misconduct, or any other liability that cannot lawfully be excluded or limited. Nothing limits a mandatory remedy available to a consumer under law that applies despite a choice-of-law clause. If Hong Kong’s Control of Exemption Clauses Ordinance or another reasonableness requirement applies, the relevant term is intended to operate only to the extent it satisfies that requirement.

Risk allocations are intended to reflect the specialized, research-only nature of the Products, the customer’s control over selection and use, the need for qualified handling, the limited ability to observe activities after delivery, and the availability of insurance and institutional controls to professional users. They are not intended to excuse a false trade description, misleading omission, wrongful acceptance of payment, breach of a non-excludable duty, or our own conduct where liability cannot fairly or lawfully be shifted.

If a court or authority finds a limitation too broad, it should be enforced to the broadest lawful and reasonable extent rather than disregarded entirely, where the law allows that approach. Separate limitations are intended to be severable. The existence of a specific remedy does not exclude another mandatory remedy, but you may not obtain double recovery for the same loss.

Assignment, subcontracting, and third-party rights

We may use affiliates and qualified service providers for hosting, payments, testing, storage, fulfillment, shipping, support, professional advice, fraud prevention, and compliance. We remain responsible to the extent required by Applicable Law. We may assign or transfer our rights and obligations as part of a genuine reorganization, financing, merger, acquisition, or sale of the business or relevant assets, provided the transfer does not reduce mandatory rights. You may not assign an order, policy right, or claim in a way that increases our risk or evades a restriction without our prior written consent, except where law gives you a non-waivable transfer right.

Unless a policy expressly says otherwise, a person who is not a party has no right to enforce it under the Contracts (Rights of Third Parties) Ordinance (Cap. 623). Our affiliates, personnel, contractors, laboratories, carriers, licensors, and payment service providers may rely on a provision that expressly protects them. The parties may amend or end their agreement without the consent of any other third party, to the extent permitted by law.

No waiver; severability; entire understanding

A failure or delay in enforcing a right is not a waiver. A one-time waiver applies only to the specific circumstances confirmed in writing. If a provision is unlawful or unenforceable, it will be modified to the minimum extent necessary or severed if modification is not permitted; the remaining provisions continue in effect. Each policy, an accepted quotation, the order confirmation, and any expressly incorporated document form the agreement for their subject matter. They replace prior discussions on that subject but do not exclude liability for fraud or a statement that law prevents us from excluding.

Purchase orders, procurement portals, email signatures, or customer forms do not add or replace terms merely because they are transmitted to us. Additional terms bind us only if an authorized representative expressly accepts them in writing. If an accepted written quotation or negotiated agreement identifies a conflict and states that it overrides a Site term, the negotiated provision controls for that transaction.

Governing law and dispute resolution

Except where mandatory law requires otherwise, this policy and non-contractual obligations connected with it are governed by the laws of the Hong Kong Special Administrative Region, without applying rules that would select another jurisdiction’s law. The courts of Hong Kong have exclusive jurisdiction, subject to any mandatory right you have to bring a claim elsewhere and either party’s right to seek urgent interim relief in a court with authority to grant it.

Before beginning formal proceedings, a party should send a written notice describing the issue, relevant order, requested remedy, and supporting information. The parties should allow at least 30 days for a good-faith attempt to resolve the matter, unless urgent relief, a limitation period, safety, fraud, confidentiality, intellectual property, or regulatory action makes waiting unreasonable. This process does not prevent a report to a regulator or law-enforcement authority and does not remove a statutory complaint right.

Claims should be brought individually unless Applicable Law permits or requires another procedure. No informal communication settles a claim unless it clearly records the agreed resolution and is sent by an authorized person. A payment-provider or carrier process does not finally determine the parties’ legal rights, although its records may be relevant.

Policy updates, language, and contact

We may revise this policy to reflect legal, operational, security, product, or service changes. The “Last updated” date identifies the current published version. Changes apply prospectively when posted or on a later date stated in the notice. A change will not retroactively remove a right that had already accrued unless Applicable Law permits and the change is validly agreed. For a material change, we may provide an additional notice by email, with a quotation, or by a Site banner where appropriate.

The English version controls to the extent permitted by law. A translation is provided for convenience unless it expressly states that it is an official controlling version. If you need this policy in an accessible format or have a question about its meaning, contact us before placing an order. Do not proceed if you do not understand and accept the terms that apply to you.

Formal legal notices, privacy-rights requests, security reports, and legal correspondence may be sent to info@peptas.com. Customer-service questions about products, orders, delivery, or returns should be sent to cs@peptas.com. Include enough information to identify the matter without sending unnecessary sensitive data. A business or postal address should be taken only from the current, verified contact information displayed on the Site or supplied in an official order document; do not rely on an address copied from an unofficial directory or an outdated page.