Home / Privacy
Legal

Privacy policy

Bacillus F OÜ is an Estonian company, so the GDPR applies to everything below. This page states plainly what we collect, why, how long we keep it and what you can require of us.

Who is responsible

The data controller is Bacillus F OÜ, registered in Estonia. Contact for any privacy matter: info@bacillusf.com. We respond to privacy requests within 30 days, as the GDPR requires, and usually much sooner.

What we collect

When you request access or write to us. Your email address, the shipping country you tell us, and whatever you choose to put in the message — for example the biomarkers you track or the supplements you already take. We ask for nothing beyond what is needed to answer you and, if you order, to ship to you.

When you order. The delivery address and the billing details required to raise a compliant invoice from an Estonian entity.

What we do not collect. We do not ask for health records, we do not require an account, and we hold no passwords because there is no login. We do not collect payment card details — invoices are settled by bank transfer, so your card never touches this site.

Why we hold it, and on what basis

  • To answer your enquiry — legal basis: steps taken at your request prior to entering a contract.
  • To fulfil an order — legal basis: performance of a contract.
  • To keep accounting records — legal basis: our legal obligation under Estonian and EU accounting law.
  • To confirm import eligibility for your destination — legal basis: legitimate interest in shipping compliantly.

We do not use your data for profiling, and we make no automated decisions about you.

Who else sees it

As few parties as possible, and only to do the job:

  • Our email provider, which necessarily processes messages you send us.
  • The shipping carrier for your parcel, which receives the delivery address and nothing else.
  • Our accountant, for invoice records we are legally required to keep.
  • Where a shipment crosses a border, the customs authority receives what the declaration requires.

We do not sell personal data. We do not share it with advertisers, data brokers or affiliate networks — there is no affiliate programme on this site.

Cookies and analytics

This site uses no advertising cookies, no remarketing pixels and no cross-site trackers. There is no Meta pixel, no advertising tag and no social embed that phones home.

Any strictly necessary cookie exists only to make the site function. If we later add privacy-respecting analytics, we will say so on this page and, where consent is required, ask for it before setting anything.

How long we keep it

Enquiry correspondence: 24 months from the last message, so that we can pick up a conversation you started rather than asking you to repeat yourself. Order and invoice records: for the statutory retention period required by Estonian accounting law, currently seven years. Anything else: deleted when the reason for holding it ends.

Your rights

Under the GDPR you may request: access to the data we hold about you, correction of anything inaccurate, erasure where we have no overriding legal duty to retain it, restriction or objection to a particular processing, and portability of what you gave us.

Write to info@bacillusf.com and we will act within 30 days. If you believe we have handled your data badly, you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority in your own country.

If this policy changes materially, the change will appear on this page.