Legal

Privacy Policy

Last updated 29 August 2026

This site sets no cookies, runs no analytics, and makes no third-party requests. Fonts, images and every other asset are served from pepteye.com. Nothing about your visit is tracked, shared or sold.

Who we are

PeptEye is an independent supplier-evidence research operation. For the purposes of the UK GDPR and the EU GDPR, PeptEye is the controller of the personal data described below. Contact us at hello@pepteye.com about anything in this policy, including any request to exercise the rights set out at the end.

1. Visitors to this website

We collect nothing. This site is static HTML. There are no forms, no cookies, no analytics, no tracking pixels, no session storage and no embedded third-party content. Downloading the specimen register does not identify you and does not require an email address.

Our hosting provider keeps standard server logs, which typically include IP addresses, timestamps and requested files. Those logs are generated and retained by the host under its own arrangements; we do not analyse them, build profiles from them, or combine them with anything else.

2. People who contact us

If you email us, we hold your message and whatever it contains — typically your name, your email address, your practice and what you are asking about. We use it to answer you and, if you become a client, to carry out the engagement. Our lawful basis is legitimate interests before an engagement and performance of a contract once there is one.

We do not add you to a mailing list, we do not send marketing you did not ask for, and we do not pass your details to anyone else.

3. Clients and engagement files

A Supplier Evidence Register and its underlying evidence archive belong to the client who commissioned them. We deliver the file to the client and to nobody else.

  • We do not publish client files, in whole or in part, and we do not identify a client as a client without their written agreement.
  • We do not sell findings to suppliers, pharmacies, laboratories, insurers, media or anyone else.
  • We do not contact your suppliers without your written instruction.
  • Where an engagement is commissioned through a client's attorney, the file is delivered to that attorney.

Retention: we keep a copy of the delivered register and its evidence archive for [RETENTION PERIOD — to be set with counsel] so that a file can be reproduced or extended if you ask. A client may ask us to delete their copy at any time, and we will confirm deletion in writing.

4. People named in the records we research

This section is the one that matters most, and most privacy policies do not have it.

Our work consists of reading published records. Those records sometimes name people — clinicians, practice owners, license holders. We may record a name, a professional title, a license number, a practice address and what a published source says, together with the source and the date we retrieved it.

Everything we record about a named individual is already published, by that person, by their practice, or by a public authority. We do not use covert means, we do not obtain records by deception or by circumventing access controls, and we do not collect health data, personal contact details, or anything about anyone's private life.

Our lawful basis is legitimate interests: independent evidence research into the safety and provenance of medicines supply is a matter of real public and professional importance, it can only be done by examining what practices actually publish, and it is carried out on professional information in a professional context. We have weighed that against the interests of the individuals concerned, and we limit what we hold accordingly.

How we limit it

  • Findings are private by default. Research conducted for a client goes to that client. It is not published.
  • Specimens are de-identified. Where we publish an example of our work, the subject is de-identified and quoted material is paraphrased — unless the subject has agreed in writing to be named.
  • Right of reply. Where we prepare a named assessment of a practice, the findings are put to that practice before the document is treated as final, and their response is recorded in it.
  • No allegations. We record what a source says and the date it said it. We draw no legal conclusions, and the absence of a public record is never reported as the absence of a record.

If you are named in something we hold and you want to know what it says, write to us. See your rights below.

5. Who we share data with

Nobody, other than the service providers we need to operate: our web host, our email provider, and — where a client asks for it — a file-transfer service used to deliver large evidence archives. Each acts on our instructions. We do not sell personal data, and we do not share it for advertising.

We may disclose information where we are legally required to, or to establish or defend a legal claim.

6. Where data is held

PeptEye operates from the United Kingdom and serves clients in the United States. Personal data may therefore be transferred between the UK, the EEA and the US, using providers who offer appropriate safeguards for such transfers.

7. Security

Files are held on access-controlled systems. Registers are delivered to named recipients. No system is perfectly secure, and we do not claim otherwise.

8. Your rights

Depending on where you live, you may have the right to ask us for a copy of the personal data we hold about you; to have it corrected; to have it erased; to restrict or object to how we use it; and to receive it in a portable form. Where we rely on legitimate interests, you may object, and we will stop unless we have compelling grounds not to.

We do not charge for this and we will respond within one month. Write to hello@pepteye.com.

If you are in the UK you may complain to the Information Commissioner's Office; if you are in the EEA, to your national data protection authority. We would rather you came to us first.

9. Children

This site is directed at healthcare businesses. It is not intended for anyone under 18 and we do not knowingly collect data from children.

10. Changes

If this policy changes we will update the date at the top. Material changes will be described here rather than made quietly.

← Back to pepteye.com