Legal

Privacy policy

Last updated 14 August 2026

Novantra Labs, Inc. operates a closed ordering portal for verified institutional accounts. This policy describes what we collect, why, how long we keep it, and what you can ask us to do about it. It is written to the Virginia Consumer Data Protection Act (VCDPA) and the California Consumer Privacy Act as amended (CCPA/CPRA).

Who we deal with. Accounts are held by organizations, not individuals. The personal information we hold is almost entirely business contact information about people acting in a professional capacity. We do not operate a consumer storefront and we do not knowingly collect information from anyone under 18.

What we collect

Account application data

Legal entity name, EIN, institution type, business addresses, phone, website, and the name, job title, institutional email and phone of the person applying. Also the written description of intended research use, and the documents uploaded in support — typically a business licence, a W-9, and proof of institutional affiliation.

Login data

Name, job title, phone, email, password hash, and the time of the last sign-in.

Order data

What was ordered, against which manufacturing lot, at what price, where it shipped, and the certificate of analysis current for that lot when it left.

Attestation records

At checkout we record the exact text you agreed to, a SHA-256 of that text, your identity, your organization’s identity, the timestamp, your IP address and your browser’s user agent string.

Technical and security data

IP address, user agent, and the country resolved from your IP address. Requests from outside the United States are refused and the attempt is logged with its country and timestamp.

Audit records

Every change to an account, a price, a role or an order, recorded with who made it, when, and from which IP address.

We do not use advertising trackers, analytics pixels, or third-party cookies. The only cookies set are the session cookie that keeps you signed in and the cart cookie that remembers what you have selected. Both are strictly necessary and neither is shared.

Why we collect it

  • To verify that an account is institutional. This is the primary control on who may see our catalog at all, and it requires a person to read the application and the documents supporting it.
  • To supply and trace orders. Each shipment must remain traceable to an exact lot and an exact certificate of analysis, years later.
  • To evidence what buyers agreed to. The attestation record exists to answer, with certainty, what a given buyer accepted on a given date.
  • To keep the service secure. Rate limiting, sign-in monitoring and geographic restriction all rely on technical data, and each is there to prevent abuse of a channel that must stay closed.
  • To meet our record-keeping obligations as a supplier of laboratory materials.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done either. Under the CCPA you therefore have nothing to opt out of, and we provide no “do not sell” link because there is no such processing to decline.

How long we keep it

Order and attestation records are retained for 7 years. The full schedule:

RecordRetentionErasable on request
Attestation records

The record of what a buyer agreed to, with the exact text and its SHA-256. This is the artefact that answers "prove what this buyer agreed to on date X".

7 years from the attestation dateNo — see below
Audit log

The record of who did what: every verification decision, price change, role change and order transition, with the actor and their network address.

7 years from the eventNo — see below
Orders

Commercial and traceability record. Each line binds a shipment to a specific lot and to the certificate of analysis current when it left.

7 years from the order dateNo — see below
Account applications

What an organization claimed when it applied, including its stated intended use — the evidence behind the approval decision.

7 years from the decisionNo — see below
Verification documents

Business licences, W-9s and institutional affiliation proof supporting an approval decision.

7 years from the decisionNo — see below
User profiles

Contact details for the individuals who order against an account.

Until erasure is requested, or the account closesYes
CRM activities, notes and tasks

Internal commentary about an account relationship.

3 years from last contact, or until erasure is requestedYes
Organization records

The institutional account itself. Held by the organization, not by an individual, so an individual cannot request its erasure.

7 years after the last orderNo — see below

Your rights

If you are a Virginia or California resident you may ask us to confirm what we hold about you, give you a copy of it, correct it, or erase it. You may exercise these rights without being charged and without being given a worse service for having done so.

Two of these are self-service in the portal, on your account page:

  • Download a copy. Produces a machine-readable JSON file containing everything we hold that identifies you: your profile, your organization, your orders, your attestations, and your own activity in our audit log.
  • Erase your details. Removes your name, job title and phone number, and deactivates your login immediately.

For correction, or for anything you would rather handle by email, write to privacy@novantralabs.example. We respond within 45 days and will tell you promptly if we need a further 45, as the VCDPA permits. If we refuse a request you may appeal by replying to our decision; we will answer an appeal within 60 days and, if we still refuse, tell you how to complain to the Virginia Attorney General.

What we cannot erase, and why

Three categories of record survive an erasure request. This is the most important section of this policy, so it is stated plainly rather than buried.

Attestation records

When you place an order you attest to a specific set of statements — that you are authorised to bind your organization, that the materials are for laboratory research only, that they will not be given to humans or animals. We store the exact wording you were shown and a cryptographic hash of it. Erasing that record would not protect you. It would destroy the only proof of what you actually agreed to, which is as much your protection as ours in any dispute about what was represented at the time. These records are immutable at the database level: our own software cannot alter or remove them, and neither can an administrator.

Audit log entries

We record who approved an account, who changed a price, who moved an order and when. This exists so that decisions about access to controlled materials can be reconstructed and challenged. An audit trail that a participant can edit is not an audit trail, so these entries are also immutable at the database level. We capture the actor’s email address on the entry itself, rather than as a reference to a user record, specifically so that the trail remains intelligible after that user has been erased.

Order and traceability records

Every shipment is tied to a specific manufacturing lot and to the certificate of analysis current when it left our facility. If a question arises about material supplied three years ago, the answer must still exist. These are retained for 7 years.

Both the VCDPA and the CCPA allow a controller to retain personal information where it is necessary to comply with a legal obligation, to establish or defend legal claims, or to complete a transaction the consumer requested. These three categories fall squarely in that space. Everything outside them is erasable, and erasure happens immediately when you ask.

How we protect it

  • All traffic is encrypted in transit with TLS.
  • Verification documents and certificates of analysis are stored outside the web root and are reachable only through access-controlled routes. There is no public URL for them.
  • The database is not reachable from the public internet; it accepts connections only from the application on a private network.
  • Backups are encrypted with AES-256 before they leave our infrastructure.
  • Sign-in is rate-limited by network address and locks an account after repeated failed attempts. There is no social sign-in and no self-service registration that grants access to anything.
  • Passwords are stored only as salted hashes. We cannot recover your password and will never ask you for it.

Who else sees it

We disclose personal information only to service providers acting on our instructions: our hosting provider, our email delivery provider, our payment and freight partners, and professional advisers where a matter requires it. Each is bound by contract to use the information only to provide that service. We do not disclose personal information to any other party except where we are legally required to, and we will tell you if that happens unless we are prohibited from doing so.

We do not transfer personal information outside the United States. The service is available only within the United States.

Contact

Novantra Labs, Inc.
1200 Research Parkway, Suite 400
Richmond, VA 23219
United States

Privacy enquiries: privacy@novantralabs.example
General enquiries: accounts@novantralabs.example

Note for the operator, not for publication. This document is a scaffold. Its structure and every factual claim in it match what the system actually does, but it has not been settled by counsel. See docs/privacy-policy.md for the list of questions a lawyer needs to answer, and remove this notice once they have.