Privacy Policy
How we collect, use and protect your personal data.
Last updated:
This Privacy Policy explains how PRCN Lab ("PRCN Lab", "we", "our", "us") collects, uses, stores and protects personal data when you visit PRCNLab.com or use our services.
PRCN Lab is a UAE-licensed entity with a branch established in the European Union. We process personal data in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"), and other applicable laws including UAE Federal Law No. 8 of 2019 on Medical Products, the Profession of Pharmacy and Pharmaceutical Facilities.
If you have questions about this policy or how we handle your data, contact us at [email protected].
Who We Are
PRCN Lab is the data controller for personal data processed through this website. We operate through:
-
A UAE-licensed parent entity, responsible for our pharmaceutical operations in the United Arab Emirates.
-
A European Union branch, which acts as the data controller for personal data processed within or hosted in the EU.
We sell pharmaceutical products, peptides and medical supplies to licensed healthcare professionals, clinics, and individual consumers who are consultancy clients of a licensed physician. Our customer base is global.
For any privacy-related question or request, contact us at [email protected].
Who This Policy Applies To
This policy covers two types of users:
Business users (B2B)
Licensed clinics, hospitals, pharmacies, physicians and other healthcare professionals or facilities who purchase from us in a professional capacity.
Consumer users (B2C)
Individuals who are consultancy clients of a licensed physician or clinic who place orders for products prescribed or recommended by their treating physician.
The data we collect, how we use it and how long we retain it differ between these two groups. Where the rules differ, this policy says so.
Data We Collect
3.1 Business users
When a clinic, pharmacy or healthcare professional registers and places orders, we collect:
-
Full name, job title, professional licence number and issuing authority
-
Facility name, facility licence number and licensing jurisdiction
-
Business email, phone number and billing address
-
Delivery address (which may be a clinic, pharmacy or warehouse)
-
Order history and product selections
-
Payment method details (processed by our payment provider — we do not store card numbers)
-
Tax registration number and trade licence details
3.2 Consumer users under a physician's consultancy
When an individual customer registers via a physician's consultancy link, we collect:
-
Full name, government-issued ID number where required for restricted products, date of birth
-
Contact email, phone number, residential or delivery address
-
Consulting physician's name, licence number and clinic
-
Prescription or clinical authorisation document where the product requires it
-
Order history and payment details (card details processed by our payment provider, not stored by us)
Where you upload a prescription or any document containing your health information, that document is special category personal data under GDPR Article 9 and is processed under the stricter requirements set out in Section 6 below.
3.3 All users (automatic collection)
When you visit the website, we collect automatically:
-
IP address, browser type, device type and operating system
-
Pages visited, time on site and referral source
-
Cookie identifiers (see Section 9)
How We Use Your Data
We use the data we collect to:
-
Verify your professional credentials (B2B) or your physician's consultancy (B2C) before fulfilling orders
-
Create and manage your account
-
Process and deliver your orders, including coordinating with logistics partners
-
Issue invoices and meet tax, accounting and pharmaceutical traceability obligations
-
Respond to your enquiries through our contact form, email or phone
-
Send transactional messages such as order confirmations, shipping updates and account notifications
-
Send marketing communications about new products, clinical updates or PRCN Lab Academy programmes — only with your explicit consent, which you can withdraw at any time
-
Detect and prevent fraud, misuse of restricted products and security incidents
-
Improve the website and services through aggregated, anonymised analytics
We never sell your personal data.
Lawful Basis for Processing
Under the GDPR (Article 6) and the UAE PDPL (Article 5), we process your data on the following legal grounds:
Consent
Marketing communications, non-essential cookies and processing of special category (health) data.
Contract performance
Processing necessary to fulfil orders, manage your account and deliver our services.
Legal obligation
Processing required by applicable law, including tax, pharmaceutical traceability, anti-money-laundering and prescription record-keeping.
Legitimate interest
Fraud prevention, security monitoring and service improvement, where our interest doesn't override your rights.
For prescription, referral and other health-related documents you upload, we rely on your explicit consent under GDPR Article 9(2)(a). Where you are resident in a jurisdiction with additional health data rules, those rules apply in parallel.
Health and Prescription Information
When you upload a prescription, a referral letter or any other document that connects your identity to a medical treatment, that document is treated as special category personal data under GDPR Article 9, and as health data under applicable national law where relevant.
For health-related data we apply additional protections:
-
Access is restricted to authorised pharmacists, medical staff and IT personnel on a need-to-know basis, with role-based access controls and multi-factor authentication.
-
Health data is encrypted at rest (minimum AES-256) and in transit (minimum TLS 1.2).
-
Health data is processed only for the purpose of fulfilling your order, providing pharmaceutical care, or where required by law.
-
Health data is retained for the minimum period required by applicable law. For customers subject to UAE Federal Law No. 2 of 2019, this may include retention for at least 25 years from the date of the last related healthcare service.
Health-related data is stored on secure servers within the European Economic Area.
Sharing Your Data
We don't sell your personal data. We share it only with the following categories of recipients, under written agreements that require them to handle your data in line with this policy and applicable law:
-
Payment processors — to handle transaction authorisation. Card data is processed by our PCI-DSS-compliant payment provider and is not stored on our servers.
-
Logistics and courier partners — to deliver your orders. We share only what is needed for delivery (name, delivery address, contact number, and for restricted products, any required clinical documentation).
-
IT infrastructure providers — hosting, email, analytics and security providers, bound by data processing agreements.
-
Healthcare and pharmaceutical regulators — where required by law or in response to a valid legal request. Depending on where you are located, this may include MOHAP, Emirates Drug Establishment, the Department of Health Abu Dhabi, the Dubai Health Authority, the Italian Medicines Agency (AIFA), or other competent authorities.
-
Tax and legal authorities — where required by applicable law or in response to a valid legal request.
-
Professional advisors — auditors, lawyers and accountants, under confidentiality obligations.
We share data only to the extent necessary for the recipient to perform its function.
International Data Transfers
PRCN Lab's data infrastructure is located in the European Economic Area (EEA).
For data subjects in the EEA
Your personal data is processed within the EEA. Where we engage a sub-processor outside the EEA, we transfer your data only to jurisdictions covered by an EU adequacy decision, or under Standard Contractual Clauses (SCCs) approved by the European Commission, or under other safeguards permitted under GDPR Chapter V.
For data subjects in the UAE
When you provide personal data through this website, it may be transferred to and processed on servers located in the EU. Such transfers are made under safeguards approved by the PDPL and its Executive Regulations (Cabinet Decision No. 111 of 2023). If you are subject to additional national rules on the cross-border transfer of health data, contact us before uploading any prescription or clinical document so we can advise on the appropriate handling.
For data subjects elsewhere
Similar safeguards apply based on your jurisdiction of residence.
If you want details of specific recipients or sub-processors involved in cross-border transfers, contact us at [email protected].
Data Retention
We retain your data only as long as necessary for the purposes set out in this policy:
Account data (B2B and B2C)
Duration of your active account plus 5 years after account closure, unless a longer period is required by law.
Order and transaction records
10 years, in line with EU and UAE commercial and tax record-keeping obligations.
Health-related data, prescriptions and clinical documents
The minimum period required by applicable law, which for some jurisdictions (including the UAE) may be at least 25 years from the date of the last related healthcare service.
Contact form submissions
Up to 2 years unless the matter requires ongoing correspondence.
Marketing consent records
Until you withdraw consent, plus a record of the withdrawal for accountability purposes.
Anti-money-laundering and pharmaceutical traceability records
As required by applicable law.
When the retention period ends, we delete or anonymise your data securely.
Your Rights
Under the GDPR and the UAE PDPL you have the following rights regarding your personal data:
Right of access
Request a copy of the personal data we hold about you.
Right to rectification
Request correction of inaccurate or incomplete data.
Right to erasure
Request deletion of your data where we have no lawful reason to keep processing it. This right is limited for health-related data subject to statutory retention.
Right to restriction
Request that we limit processing of your data in certain circumstances.
Right to portability
Receive your data in a structured, machine-readable format to transfer to another provider.
Right to object
Object to processing based on legitimate interest or to direct marketing.
Right to withdraw consent
Withdraw consent at any time for any processing that relies on consent.
Right to object to automated decision-making
Applies where a decision affecting you is made solely by automated means and has legal or similar significant effects.
To exercise any of these rights, contact [email protected]. We will respond within 30 days. If we need to verify your identity before fulfilling the request, we may ask for additional information.
If you believe we have not handled your data correctly, you have the right to lodge a complaint:
-
In the EU: with your national data protection authority (for example, the Garante per la protezione dei dati personali in Italy).
-
In the UAE: with the UAE Data Office.
-
Elsewhere: with your local data protection authority.
Security
We apply technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or alteration. These include:
-
TLS 1.2 or higher for all data transmitted between your browser and our servers.
-
AES-256 encryption for personal data at rest, including health-related data.
-
Hashed and salted password storage — we never store plaintext passwords.
-
Role-based access controls, with access limited to staff who need the data for their job.
-
Multi-factor authentication for all administrative system access.
-
Regular security assessments, vulnerability monitoring and patch management.
-
Logging and monitoring of access to systems that hold personal data.
-
Staff training on data protection and information security.
-
Incident response procedures with defined escalation and notification steps.
Data breach notification. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in line with GDPR Article 33 and PDPL Article 33. Where a breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
Children's Data
The website and services are not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact [email protected] and we will delete it.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, legal obligations or services. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page.
We encourage you to review this page periodically. Continued use of the website or services after changes are published constitutes acceptance of the updated policy.
Contact
For any questions, requests or concerns about this Privacy Policy or how we handle your personal data, contact us at [email protected].
Questions about your data?
Our team is available to assist with any questions about how we collect, use, or store your personal information.