Last updated: 4 September 2026
1. Scope of this Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored and shared when you:
- visit nada-labs.com;
- create or use a customer account;
- place an order;
- complete our customer or institution verification;
- contact NADA-Labs; or
- otherwise interact with our website and services.
We process personal data in accordance with applicable data-protection laws, including the European Union General Data Protection Regulation (“GDPR”) and the Hong Kong Personal Data (Privacy) Ordinance (“PDPO”), where applicable.
2. Data Controller
The controller responsible for the processing of personal data under the GDPR and the data user under the PDPO is:
NM Group Global Limited
Operating under the name NADA-Labs
Flat 2304, 23/F
Ho King Commercial Centre
2–16 Fa Yuen Street
Mong Kok, Hong Kong
Website: nada-labs.com
Where the appointment of a representative within the European Union under Article 27 GDPR is required, the representative is:
3. Visiting Our Website
3.1 Server Log Files
When you access our website, technical information may be transmitted automatically by your browser and recorded in server log files.
This information may include:
- your IP address;
- the date and time of access;
- the page or file requested;
- the referring website;
- browser type and version;
- operating system;
- HTTP status code; and
- the amount of data transferred.
This processing is necessary to display the website, maintain its stability and security, diagnose technical problems and detect abuse or attempted attacks.
The legal basis is our legitimate interest in operating a secure and functional website under Article 6(1)(f) GDPR.
Server log files are normally deleted or anonymised after 6 months, unless longer storage is necessary to investigate a security incident or comply with a legal obligation.
3.2 Web Fonts
Our website uses the typefaces Outfit, Inter Tight and IBM Plex Mono provided through Google Fonts.
When these fonts are loaded from Google servers, your browser may establish a connection with Google and transmit technical data, including your IP address.
The relevant provider is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Data may also be processed by affiliated companies in the United States or other countries.
The fonts are used to provide a consistent and readable presentation of our website. The legal basis is Article 6(1)(f) GDPR, where reliance on legitimate interests is permitted. Where consent is legally required, the fonts will be loaded only after the relevant consent has been provided.
Further information is available in Google’s own privacy information.
3.3 Research-Use and Institution Confirmation
When you first access the website, you may be asked to confirm that you are acting as a qualified researcher or on behalf of a business, laboratory or research institution.
The confirmation may be stored locally in your browser under the key “nada.gate” so that the notice does not need to be displayed every time you visit.
Your selected language may be stored under “nada.lang” or in the cookie “nada_lang”.
These initial browser entries are used to remember your selections. They do not by themselves contain your name or contact details.
4. Customer Accounts
You may be able to place an order as a guest or create a customer account.
When you create or use an account, we may process:
- your name;
- your email address;
- your password in encrypted or hashed form;
- your company, laboratory or institution;
- your billing and delivery addresses;
- your telephone number;
- your saved account preferences; and
- your order history.
The account enables you to view previous orders, manage addresses and follow the status of current orders.
Passwords are stored as cryptographic hashes and are not visible to us in plain text.
The legal basis is the performance of the account agreement and the provision of the requested account functions under Article 6(1)(b) GDPR.
5. Customer and Institution Verification
Because NADA-Labs supplies products only for legitimate professional laboratory and research purposes, we may request information needed to verify the purchaser and the associated organisation.
This may include:
- the name and type of organisation;
- the purchaser’s position or professional role;
- an institutional or business email address;
- the organisation’s website;
- billing or registration information;
- the intended research field;
- confirmation of professional or institutional use; and
- supporting documentation where reasonably necessary.
We use this information to determine whether an order meets our professional-customer, research-use and compliance requirements.
The legal bases are:
- taking steps before entering into a contract and performing the contract under Article 6(1)(b) GDPR;
- compliance with applicable legal obligations under Article 6(1)(c) GDPR; and
- our legitimate interests in preventing misuse, fraud and unlawful distribution under Article 6(1)(f) GDPR.
6. Orders
When you submit an order, we may process:
- your first and last name;
- company, laboratory or institution name;
- billing and delivery addresses;
- email address;
- telephone number;
- date of birth where genuinely required;
- products ordered;
- order value;
- selected payment method;
- selected shipping method;
- order and payment status;
- order date;
- customer communications;
- research-use confirmation; and
- the research field selected during checkout.
We use this information to:
- review and process the order;
- verify the purchaser;
- receive and allocate payment;
- issue invoices;
- prepare and dispatch the products;
- provide tracking information;
- respond to order-related questions;
- process complaints, replacements or refunds;
- prevent fraud and misuse; and
- maintain legally required transaction records.
The legal basis is primarily the performance of the purchase contract under Article 6(1)(b) GDPR.
Where records must be retained for tax, accounting, customs or commercial-law purposes, the legal basis is Article 6(1)(c) GDPR.
Security and fraud-prevention checks are based on our legitimate interests under Article 6(1)(f) GDPR.
Mandatory information is identified during checkout. Without this information, we may be unable to verify the purchaser or process the order.
7. Payments
Payments are processed by the payment method and payment provider selected during checkout.
Current payment providers:
The payment provider may receive information such as your name, billing address, email address, order amount, transaction reference and payment details.
NADA-Labs does not receive or store complete payment-card numbers where payment is handled directly by an external payment provider.
Each payment provider processes personal data in accordance with its own privacy information and legal obligations.
The legal basis for payment processing is the performance of the purchase contract under Article 6(1)(b) GDPR. Fraud prevention and transaction security may additionally be based on Article 6(1)(f) GDPR.
8. Shipping and Delivery
We use DHL and UPS to arrange deliveries.
For the individual shipment, we may provide the selected carrier with:
- recipient name;
- company or institution name;
- delivery address;
- email address;
- telephone number;
- parcel and tracking information; and
- information required for customs clearance.
The carrier receives only the data reasonably required to create the shipping label, transport and deliver the parcel, provide tracking notifications and complete customs formalities.
For shipments crossing a customs border, data may also be provided to customs authorities, logistics partners and other competent authorities.
The legal bases are the performance of the purchase contract under Article 6(1)(b) GDPR and compliance with customs or other legal obligations under Article 6(1)(c) GDPR.
Where the delivery address is outside the European Economic Area, transmitting the delivery information to the destination country may be necessary to perform the contract with you.
9. Contacting NADA-Labs
If you contact us through email or a contact form, we may process:
- your name;
- email address;
- company or institution;
- subject;
- message content;
- attachments;
- order number; and
- any other information you voluntarily provide.
We use this information to review and respond to your enquiry.
Where the enquiry concerns an existing or proposed order, the legal basis is Article 6(1)(b) GDPR. For general enquiries, security matters and business correspondence, the legal basis is our legitimate interest under Article 6(1)(f) GDPR.
The contact form uses a hidden anti-spam field and does not use an external CAPTCHA or profiling service unless otherwise stated.
10. Certificates of Analysis and Batch Searches
Searching for a Certificate of Analysis by entering a batch or lot number does not normally require you to provide personal data.
The lookup is performed within the website. Standard technical server-log information may nevertheless be generated when the relevant page or file is accessed.
11. Cookies and Similar Technologies
NADA-Labs uses cookies and browser-storage technologies necessary for the operation of the website and online shop.
These may include technologies required for:
- website and account sessions;
- shopping-cart functions;
- checkout and order processing;
- fraud and security protection;
- language selection;
- research-use confirmation; and
- WooCommerce order attribution.
We do not use advertising, behavioural-tracking or analytics cookies unless this Privacy Policy and our Cookie Policy are updated and, where required, prior consent is obtained.
Further details about individual cookies, their purposes and storage periods are provided in our separate Cookie Policy.
12. Email Services
Emails and customer communications are handled using:
see contact us
The email provider may process sender and recipient addresses, message content, metadata and attachments in order to transmit, receive and store communications.
The legal basis depends on the purpose of the communication and is generally Article 6(1)(b), Article 6(1)(c) or Article 6(1)(f) GDPR.
13. Hosting and Technical Service Providers
The hosting provider processes technical website data, server logs and information submitted through the website on our behalf.
We may also use carefully selected providers for:
- website maintenance;
- IT security;
- data storage and backups;
- payment processing;
- email delivery;
- order fulfilment;
- shipping;
- accounting; and
- legal or compliance support.
Where providers act as processors on our behalf, they are contractually required to process personal data only on our instructions and to implement appropriate security measures.
14. Recipients of Personal Data
Depending on the transaction or enquiry, personal data may be disclosed to:
- hosting and IT providers;
- payment providers and financial institutions;
- DHL, UPS and other logistics partners;
- customs and tax authorities;
- accounting, legal and compliance advisers;
- email and communication providers;
- fraud-prevention and security providers; and
- courts, regulators or public authorities where legally required.
We do not sell personal data.
15. International Data Transfers
NM Group Global Limited is established in Hong Kong. Information you provide directly to NADA-Labs may therefore be received and processed in Hong Kong.
Some of our service providers may also process personal data outside the European Economic Area.
Where a transfer is subject to the GDPR and the destination country does not benefit from an applicable adequacy decision, the transfer must be covered by a legally recognised mechanism.
You may contact us for additional information about the safeguards applicable to a particular transfer.
16. Retention of Personal Data
We retain personal data only for as long as necessary for the relevant purpose or for a period required by applicable law.
The usual retention criteria are:
- Customer-account data: until the account is deleted, followed by a limited period where necessary for legal claims, security or statutory obligations.
- Order, invoice and transaction data: for the retention period required by applicable tax, accounting, customs and commercial laws.
- Verification information: while the customer relationship remains active and afterwards where necessary for compliance, fraud prevention or legal claims.
- Contact enquiries: until the matter has been resolved and for a reasonable follow-up period.
- Server logs: normally 6 months, unless an incident requires longer investigation.
- Claim and complaint records: for the time needed to resolve the matter and defend or establish legal claims.
When personal data is no longer required, it is deleted, anonymised or securely restricted from further use.
17. Your Rights Under the GDPR
Where the GDPR applies, you may have the right to:
- obtain information about our processing of your personal data;
- request access to your personal data under Article 15 GDPR;
- request correction of inaccurate or incomplete data under Article 16 GDPR;
- request deletion under Article 17 GDPR;
- request restriction of processing under Article 18 GDPR;
- receive eligible data in a portable format under Article 20 GDPR;
- object to processing based on legitimate interests under Article 21 GDPR;
- withdraw consent at any time with effect for the future;
- lodge a complaint with a competent supervisory authority; and
- obtain information about applicable international-transfer safeguards.
These rights may be subject to legal conditions, limitations and statutory retention requirements.
To exercise a right, contact us. We may request reasonable information necessary to confirm your identity.
18. Rights Under Hong Kong’s PDPO
Where the Hong Kong Personal Data (Privacy) Ordinance applies, you may request access to personal data held about you and request correction of inaccurate personal data.
Requests may be sent to us. We may require the information necessary to identify the relevant records and verify the requester’s identity.
19. Complaints
If you have concerns about our handling of personal data, please contact us first so that we can investigate the matter.
Where the GDPR applies, you may also complain to the competent data-protection authority in the country of your habitual residence, place of work or the alleged infringement.
In Hong Kong, complaints may be directed to the:
Office of the Privacy Commissioner for Personal Data, Hong Kong
20. Data Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures include, where appropriate:
- encrypted transmission using TLS/HTTPS;
- access restrictions;
- account and password controls;
- hashed password storage;
- system monitoring;
- backups;
- software updates; and
- limiting access to personnel who require the information for their work.
No online system can provide absolute security. We therefore review and improve our safeguards where reasonably necessary.
21. Automated Decision-Making
NADA-Labs does not use solely automated decision-making that produces legal or similarly significant effects within the meaning of Article 22 GDPR.
Customer, institution, fraud or compliance checks may result in an order being referred for manual review.
22. Children
Our website and products are intended exclusively for authorised professional and institutional research customers. They are not directed at children or private users.
We do not knowingly accept orders from minors.
23. Changes to this Privacy Policy
We may update this Privacy Policy when our processing activities, service providers or legal obligations change.
The current version will always be published on this page. Where changes are material, we may provide an additional notice through the website or by email.