top of page

Privacy Policy

Prometheus Biolabs

Last Updated: [05/03/2026]

1. Data Controller

Prometheus Biolabs is the data controller responsible for processing personal data in accordance with the UK GDPR and Data Protection Act 2018.

2. Personal Data Collected

We may collect:

  • Full name

  • Contact information

  • Date of birth (if required for safety compliance)

  • Emergency contact details

  • Medical disclosures relevant to laboratory safety

  • Payment information (processed by secure third-party providers)

  • Website usage data

Failure to provide required information may result in refusal of course participation.

3. Legal Basis for Processing

We process data under:

  • Contractual necessity (course delivery)

  • Legal obligation (health & safety compliance)

  • Legitimate interests (business administration)

  • Consent (marketing communications)
     

4. Special Category Data

Health information provided for safety purposes is processed under Article 9(2)(b) and 9(2)(h) UK GDPR where necessary for health and safety compliance.

Such data is stored securely and accessed only where strictly necessary.

5. Data Sharing

We may share personal data with:

  • Laboratory host facilities

  • Regulatory authorities

  • Insurers (if incident reporting is required)

  • Payment processors

We do not sell or rent personal data.

6. Data Retention

Data is retained only as long as necessary for:

  • Contractual performance

  • Legal compliance

  • Insurance defence periods

  • Health & safety record retention

Data is securely deleted thereafter.

7. Data Security

We implement appropriate technical and organisational measures including:

  • Access controls

  • Encrypted payment processing

  • Secure storage systems

  • Restricted access to health data

However, no system is completely secure, and transmission of data is at your own risk.

8. Your Rights

You have the right to:

  • Access your data

  • Rectify inaccuracies

  • Request erasure (where legally permissible)

  • Restrict processing

  • Object to processing

  • Lodge a complaint with the Information Commissioner’s Office (ICO)

Requests should be directed to:
[ Prometheusbiolabs@outlook.com ]

9. Marketing Communications

You will only receive marketing communications if you opt in.
You may unsubscribe at any time.

 

10. Changes to This Policy

We reserve the right to amend this Privacy Policy at any time.
The current version will always be published on our website.

bottom of page