Research onlyFor laboratory research · Not intended for human or animal application
BasePurity
Privacy Policy

What we do with your data.

BasePurity processes personal data in line with the General Data Protection Regulation (GDPR). Below you can read which data we collect, what for, how long we keep it and which rights you have.

Last updated · August 2026

Data controller

BasePurity is the data controller for personal data processed via this website.

For privacy-related queries: [email protected].

Which data we collect

For an order we process your first and last name, email address, telephone number, delivery address, payment details (through our payment provider, we never see full card numbers) and the IP address the order was placed from.

For a newsletter signup: your email address, and your name if you fill it in.

For use of the website: technical data through cookies, see our cookie policy.

Purpose and legal basis

We process your data on the following legal grounds (Art. 6 GDPR):

Performance of the contract, for order handling, delivery and customer communication.

Legal obligation, for tax administration (7-year retention requirement).

Legitimate interest, for fraud prevention, webshop security and product improvement.

Consent, for marketing cookies and newsletter messaging. You can withdraw consent at any time.

Retention periods

Order data: 7 years (tax retention requirement).

Account and contact data: up to 2 years after last activity.

Newsletter sign-up: until unsubscribe.

Website cookies: varies per cookie (see cookie policy).

After the retention period, data is securely deleted or anonymised.

Who we share data with

We share your data only with parties needed to fulfil your order, and we have a processing agreement with each of them:

Our payment provider, for handling the payment.

Our carrier (PostNL or similar), for delivery.

Our email provider, for transactional mail and the newsletter.

Our hosting party, for the webshop infrastructure.

We never sell your data on for marketing purposes.

International transfers

Where a processor is located outside the European Economic Area (EEA), we ensure appropriate safeguards via the European Commission's Standard Contractual Clauses (SCCs).

Security

We take appropriate technical and organisational measures: TLS encryption across the whole site, access to personal data limited to those who need it, periodic backups and monitoring for suspicious activity. Should a data breach occur, we report it within 72 hours to the Dutch Data Protection Authority and, where required, to the people affected.

Your rights

Under the GDPR you have the right to:

Access the data we hold about you (Art. 15).

Rectification of inaccurate data (Art. 16).

Erasure of your data (Art. 17), unless we have a legal retention obligation.

Restriction of processing (Art. 18).

Data portability, a copy of your data in a common format (Art. 20).

Object to processing based on legitimate interest (Art. 21).

Withdraw consent at any time, without affecting the lawfulness of prior processing.

Requests via [email protected]. We respond within 30 days.

Filing a complaint

Not happy with how we handle your data? You can always file a complaint with the Dutch Data Protection Authority, at autoriteitpersoonsgegevens.nl.

Questions?

Question not covered here?

Our customer service answers within one working day, in English, Dutch or German. Send a short email and we will sort it out.