Privacy Policy
This Privacy Policy explains how personal information is handled in connection with LABSZPHC at www.labszphc.com, including product galleries, inquiries and product-code verification. It is a privacy notice, not a transfer of ownership in your messages or a waiver of your legal rights.
Effective date: [INSERT THE ACTUAL PUBLICATION DATE]
1. Website operator and privacy contact
The controller responsible for the processing described in this policy is the person or organisation operating LABSZPHC, identified below.
Legal name: [FULL LEGAL NAME OF THE OPERATOR]
Business/contact address and country: [ADDRESS AND COUNTRY]
Privacy contact email: [MONITORED PRIVACY EMAIL ADDRESS]
Website: www.labszphc.com
Use the privacy email above for questions or requests about your personal information. You do not have to use the product inquiry form or agree to unrelated terms to exercise your privacy rights.
2. Information you provide
When the contact form is enabled and you submit an inquiry, we receive your country or place of residence, email address, inquiry type, message, and the product associated with your inquiry. You enter your email twice to help prevent typing errors.
You may also choose to provide a phone number, WhatsApp number, Telegram username or Signal username. These fields are optional. Messages may include your name, company or other details you choose to share.
We receive the agreement confirmations submitted with the form and the submission time. Contact details, messages and these confirmations are sent to our designated email inbox. The current gallery plugin does not create a separate inquiry database, but emails, mail-delivery logs and backups may retain this information.
Required fields are needed to process the form. Without them, the form cannot be submitted. Please do not send passwords, payment credentials, identity documents, sensitive medical information or unnecessary information about other people.
3. Product-code verification records
When you enter an authentication code, the verification service processes it to look for a matching database record. Imported codes are stored as keyed hashes rather than complete readable codes; a short ending portion of each imported code is also retained.
The system records verification outcomes, query times, an IP-derived keyed hash and browser user-agent information. For matching codes it also keeps a query count and first and most recent query times. These records support verification, abuse prevention and troubleshooting.
Query counts and earlier query times are not displayed in the public success response, but they remain in the backend. A hashed identifier is not a guarantee of anonymity. The request also exposes an IP address to the hosting infrastructure, which may record it in server or security logs.
Replacing a code dataset does not necessarily erase the previous records: the replacement function keeps old code and query tables as backups. Those backups must be included in our retention and deletion procedures.
4. Technical data, cookies and browser storage
Website requests can include an IP address, user-agent information, requested URL and request time. Hosting and security systems process technical information to deliver pages, investigate errors and protect the website.
The LABSZPHC header supplied for this site uses browser local storage with the key labszphc_last_visit to remember a visit timestamp and display the previous visit. That item remains until overwritten or removed from browser storage; the supplied header code does not assign it a fixed expiry. The clock display reads the browser’s reported time zone and measures time on the current page locally. This header code does not itself send those display values to an external location service.
You can remove this stored value through your browser’s site-data settings. Doing so resets the previous-visit display; it does not delete server-side verification logs or correspondence.
Complete before publication: [AUDIT THE LIVE THEME AND PLUGINS. LIST ANY OTHER COOKIES, CONSENT STORAGE, TRANSLATION/EMBEDDED SERVICES, ANALYTICS OR ADVERTISING TOOLS; STATE THEIR PROVIDERS, PURPOSES, DURATIONS AND AVAILABLE CONTROLS. IF NONE ARE USED, CONFIRM THAT FACT HERE.] Where applicable law requires prior consent, implement that control before enabling non-essential storage or tracking. Publishing this text does not implement a consent mechanism.
5. Contact-form security and Cloudflare Turnstile
The contact form is designed to use Cloudflare Turnstile once configured. When that protection is active, Cloudflare processes technical signals, including the client IP address, user-agent information, TLS fingerprint and site/origin information, to distinguish human visitors from bots. Cloudflare also describes processing signals to improve its bot-detection capabilities.
Our server submits the challenge response and request IP address to Cloudflare for verification before accepting a message. The plugin does not include your message text or contact fields in that verification request. For Cloudflare’s explanation of its roles and processing, read the Turnstile Privacy Addendum.
IP-derived rate-limit counters are also used to reduce repeated submissions. The current contact plugin sets a ten-minute counter expiry; the verification plugin sets a one-minute counter expiry. These counters are separate from longer-lived emails and verification logs.
[CONFIRM TURNSTILE IS ENABLED AND ITS ACTUAL SETTINGS BEFORE PUBLICATION. DO NOT LIST PROJECT HONEY POT OR OTHER SECURITY SERVICES UNLESS THEY ARE ACTUALLY USED.]
6. Purposes and lawful grounds
We use inquiry information to understand and answer requests, verification information to provide code checks, and technical/security information to operate and protect the website. Where necessary, relevant records may also be processed to meet a specific legal obligation or establish, exercise or defend legal claims.
Complete the applicable legal grounds before publication: [IDENTIFY THE LAW(S) THAT APPLY AND MAP EACH PURPOSE TO ITS CORRECT BASIS. FOR EXAMPLE, WHERE GDPR APPLIES, ASSESS PRE-CONTRACT STEPS FOR A PERSON’S OWN REQUEST, LEGITIMATE INTERESTS FOR RELEVANT BUSINESS COMMUNICATION/SECURITY, SPECIFIC LEGAL OBLIGATIONS, AND CONSENT ONLY WHERE ACTUALLY RELIED UPON. STATE THE LEGITIMATE INTEREST AND APPLICABLE OBLIGATION WHERE RELEVANT.]
Simply viewing this website is not treated as blanket consent to every use of your information. If a particular activity relies on consent, you may withdraw that consent; withdrawal does not affect processing lawfully carried out beforehand. It does not require deletion of information that must be retained on a separate valid legal ground.
7. Who receives information
Information is handled by authorised people responsible for operating the site and answering inquiries, and by the hosting, email-delivery, backup and security providers needed for those tasks. Cloudflare receives the security information described above when Turnstile is enabled.
[INSERT ACTUAL HOSTING, EMAIL/SMTP, BACKUP AND OTHER RELEVANT PROVIDERS, THEIR ROLES AND PRIVACY LINKS. CONFIRM WHETHER ANY ADDITIONAL RECIPIENTS, MARKETING USE, DATA SALE OR ADVERTISING SHARING EXIST; DISCLOSE THEM ACCURATELY IF APPLICABLE.]
Information may be disclosed to professional advisers or competent authorities when necessary for a valid legal obligation or legal claim. This policy does not authorise unrestricted forwarding of your information to unrelated third parties.
8. International handling of information
Where our operator or service providers handle information outside your country, the destination and legal protections may differ from those in your location.
[IDENTIFY THE ACTUAL COUNTRIES/REGIONS OF HOSTING, EMAIL STORAGE, REMOTE ACCESS AND OTHER PROCESSING. DESCRIBE ANY REQUIRED TRANSFER MECHANISM OR SAFEGUARDS AND HOW A PERSON CAN REQUEST DETAILS. DO NOT CLAIM CONTRACTUAL SAFEGUARDS OR CERTIFICATIONS WITHOUT CHECKING THEM.]
9. Retention and deletion
Our retention arrangements must distinguish inquiries, verification records, technical logs and backups. The current custom plugins do not automatically delete inquiry emails or historical verification tables after a fixed retention period.
- Inquiry emails, related contact details and agreement records: [RETENTION PERIOD OR SPECIFIC DECISION CRITERIA, INCLUDING WHEN THE PERIOD STARTS].
- Verification query logs and code-linked query history: [RETENTION PERIOD OR SPECIFIC DECISION CRITERIA].
- Hosting/security logs: [ACTUAL PROVIDER/ADMINISTRATOR RETENTION SETTINGS].
- Database backups, superseded code tables and email backups: [BACKUP RETENTION/ROTATION AND DELETION PROCEDURE].
Where a specific legal obligation or active dispute requires longer retention, relevant information may be kept for that purpose. We assess deletion requests under applicable law and explain any applicable limitation. Clearing browser cookies or leaving the website does not itself remove information already held in emails, logs or backups.
10. Your privacy rights
Depending on the law that applies and the processing involved, you may have rights to access or obtain a copy of your information, correct inaccurate information, request deletion, restrict processing, receive portable data, or withdraw consent. These rights are subject to the conditions and exceptions in the applicable law.
Right to object: where applicable, you may object to processing based on legitimate interests. If your information is used for direct marketing, applicable law may give you an unconditional right to object to that marketing.
Send requests to the privacy contact in Section 1. We may ask for proportionate information to confirm your identity and locate the relevant records, and will respond within the applicable statutory timeframe. Do not send an identity document unless we explain why it is necessary and provide an appropriate way to supply it.
You may also complain to the data protection authority competent for your location or the relevant processing. [IDENTIFY THE RELEVANT AUTHORITY AND COMPLAINT LINK AFTER CONFIRMING THE OPERATOR’S LOCATION AND APPLICABLE LAW.]
11. Security, external services and submitted material
Administrative access controls, keyed hashing of verification codes, validation and anti-abuse checks are used in the supplied plugins. No transmission or storage system can be guaranteed completely secure. Please provide only information needed for your inquiry.
If you follow a link to a social network, messaging platform or other external website, its own privacy terms apply to its processing. An external link does not by itself give that platform access to your submitted inquiry. Embedded services, if present, must be disclosed separately in this policy.
Sending an inquiry does not transfer ownership of your message or grant a general licence to publish your name, image or personal story. Any separate use of personal material for public marketing or community presentation requires an appropriate legal basis and, where applicable, separate permission.
12. Children, changes and contacting us
[CONFIRM THE SITE’S INTENDED AUDIENCE, ANY ACTUAL AGE RESTRICTION AND HOW CHILDREN’S DATA IS HANDLED. DO NOT COPY A 21+ RESTRICTION UNLESS IT IS YOUR REAL POLICY.]
If you believe information about a child has been submitted inappropriately, please contact us so the circumstances can be reviewed under applicable law.
We will update this policy when relevant processing changes and show the effective date above. Where required, we will provide additional notice or obtain consent before starting a new use. Changes do not remove rights that applicable law grants you.
Privacy questions and requests: [MONITORED PRIVACY EMAIL ADDRESS].