Privacy Policy
This Privacy & Cookie Policy explains how Ossila Limited (UK) and Ossila B.V. (Netherlands) (together "Ossila," "we," "us," "our") collect, use, and protect your information when you visit our website at www.ossila.com (the "Site").
Who We Are
This privacy policy applies to Ossila Ltd. and its subsidiaries.
For the purposes of this document, "Ossila", "we", "us", and "our" refers to:
Ossila Limited (parent company)
- Registered in England and Wales
- Company Number: 06920105
- Address: Solpro Business Park, Sheffield, S4 7WB, United Kingdom
- Phone: +44 (0) 114 2999 180
- Email: info@ossila.com
Ossila B.V. (wholly-owned subsidiary)
- Registered in the Netherlands
- CCI Number: 84102241
- Address: Leiden BioScience Park, BioPartner 3 Galileïweg 8, 2333BD Leiden, NL
- Phone: +31 (0)718 081020
- Email: info@ossila.com
Data Controllers
Both Ossila Limited and Ossila B.V. act as joint data controllers for the processing activities described in this policy. For EU customers, Ossila B.V. serves as your primary contact point and acts as the EU representative for Ossila Limited under GDPR Article 27.
Data Processing
Orders may be processed by Ossila Ltd (UK) or Ossila B.V. depending on operational requirements and factors such as your billing and shipping addresses. Relevant information about your order will be shared between Ossila Ltd. and Ossila B.V as required to facilitate this, and both entities may access your data for business operations, customer support, and analytics. Privacy requests can be directed to either entity.
All website operations, analytics, and marketing activities are managed centrally by Ossila Limited (UK) for all customers. Website data (browsing, analytics cookies) is processed by Ossila Limited regardless of your location.
Legal Basis for Processing
We process your personal data on the following legal bases under GDPR:
- Your consent, i.e. when you explicitly agree (e.g., accepting analytics cookies, opting in to marketing emails)
- Contractual necessity to fulfill our contract with you (e.g., processing and delivering your orders)
- Legal obligations to comply with laws (e.g., tax and accounting requirements)
- Legitimate interests for our business operations where not overridden by your rights (e.g., fraud prevention, improving our Site with anonymized analytics)
Information We Collect
We collect information when you interact with us, including when you:
- Interact with an advert for Ossila
- Browse our Site
- Create an account on our Site
- Contact us with enquiries
- Request a quotation
- Place an order
- Enter competitions
- Subscribe to our mailing list
- Apply for jobs
Information You Provide
The types of information we collect include:
- Personal details: name, email address, institution, phone number
- Account and order information: billing and shipping addresses, purchase history
- Payment information: partial details (full details processed by our payment providers)
- Communications: messages you send us via contact forms, email, or phone
- Job applications: CV, cover letter, references
Information Collected Automatically
We automatically collect information necessary to operate the Site:
- Session identifiers to maintain your shopping cart
- Authentication tokens if you create an account
- Localization preferences (language, currency, country)
- Security and fraud prevention data
We collect anonymous, aggregated usage data through our analytics platforms:
- Pages visited and time spent (no user identification)
- Product views and search terms (aggregated data only)
- Approximate location (derived from anonymized IP addresses)
- Browser type and device category (for compatibility testing)
- Referral source (how you found our Site)
- Traffic source (search, paid advertising, direct links, etc.)
- Device type, operating system, screen resolution
- Actions taken on the site: links clicked, products added to cart, etc.
This anonymous data collection is done without persistent identifiers or cookies (each visit is treated independently) with IP anonymization enabled (more details below).
When you consent to analytics cookies, we collect additional data using pseudonymized identifiers to better understand how users interact with the Site, including session level data and data on repeat visits. This data is collected by Shopify Analytics (built into our e-commerce platform, Shopify), Google Analytics 4 (GA4), and Matomo Analytics.
Other Data
We may also receive information from payment processors regarding transaction status or fraud screening results and from shipping carriers regarding the status of your order.
In limited circumstances where essential delivery information is missing, we may also collect publicly available information (such as phone numbers from institutional websites) to ensure your order reaches you without delays. We only collect publicly available information when it is necessary to fulfil our contract with you (e.g., completing delivery), you have not provided essential information through other means, and the information is already publicly accessible.
Children's Privacy
Our Site is not directed at children under 16. We do not knowingly collect personal information from children. If you believe your child has provided us with personal information, please contact us at info@ossila.com and we will delete any identifiable information. Please note that our anonymized website analytics cannot identify individual users, including children.
How We Use Your Information
We use the information we collect to:
- Deliver products and services, i.e. processing and fulfilling your orders
- Provide customer support, offer technical advice and provide order support
- Run business operations and improve our services, including our Site
- Improve our products and services, develop new products and fix technical issues
- Comply with legal obligations including tax, accounting, law enforcement requirements
- Maintain security, preventing fraud and eliminating cyber security threats
Information gathered when an order is placed (or when steps have been taken to enter into a purchasing contract) is used to arrange delivery, process payments (if applicable) and for company record-keeping. If you make an enquiry, then that information is used to respond to the enquiry and for company record-keeping.
Anonymous analytics information collected about site usage is used to help us improve the Site and analyze trends such as which products and services interest our customers, how customers find us, and how they interact with the Site.
We do not display third-party advertising on our website or collect data for external advertisers. We only collect data necessary to allow us to advertise on Google Search and improve our own marketing campaigns.
Website Analytics
We collect anonymized website analytics to improve our site and understand customer needs. This processing is based on our legitimate business interest. To protect your privacy rights, we use IP anonymization, no persistent identifiers, and treat each visit independently. The data is fully anonymized, does not use cookies, and cannot identify individuals.
This data is processed by Google Analytics 4 and Matomo Cloud. Consenting to analytics and marketing cookies enables cross-session tracking on both platforms and enables Shopify's in-built e-commerce tracking.
Google Analytics 4 (GA4)
We operate Google Analytics 4 in "Consent Mode v2". This means that GA4 sends only anonymous, aggregated data without cookies unless you provide consent.
In addition, we take the following measures to protect your privacy:
- IP addresses fully anonymized
- Google Signals disabled (no cross-device tracking via Google accounts)
- Data sharing with Google products and services disabled
- Ads personalization disabled
- Granular location and device data collection disabled
- No cross-site tracking
GA4 data is processed by Google LLC (USA, EU-US Data Privacy Framework)
Matomo Cloud
Matomo is a privacy-focused analytics tool. We use Matomo with "requireCookieConsent" enabled, which means it only sets cookies after you click "Accept All" on our cookie banner. Without your consent, Matomo operates in cookieless mode, collecting only anonymous, aggregated data.
We take the following measures to protect your privacy:
- IP addresses anonymized to 2 bytes (e.g., 192.168.x.x → 192.168.0.0)
- User IDs and Order IDs pseudonymized (hashed, not stored in plain text)
- No data sharing with third parties
- Raw visitor data deleted after 744 days
Matomo Cloud data is processed by InnoCraft Ltd (Germany, EU).
Cookies
Cookies are text-only pieces of information that a website transfers to a visitor's local storage or other web-browsing device for record-keeping purposes. Persistent cookies remain on your device for a set period, or until you delete them.
We use cookies to help improve your use of our website by remembering information, such as the saved items in your cart or your currency choice. With your consent, we also use cookies for website analytics, marketing, and advertising purposes.
In addition to cookies, we use browser storage to save functional data like currency exchange rates locally in your browser until you end your current browsing session.
Essential Cookies
These cookies are strictly necessary for the Site to function. You cannot disable them without breaking core functionality.
| Provider | Cookie Name | Description | Duration |
|---|---|---|---|
| Shopify | See www.shopify.com/uk/legal/cookies | Various essential e-commerce cookies | Various |
| Ossila Ltd | ossilaCountry | Saves your country selection | 365 days |
| Ossila Ltd | ossilaCurrency | Saves your currency selection | 365 days |
| Ossila Ltd | ossilaLanguage | Saves your language selection | 365 days |
| Ossila Ltd | cookiesAccepted | Saves your cookie preference | 365 days |
| Ossila Ltd | hideCookieLawWarning | Saves whether you have accepted the cookie policy banner | 365 days |
Analytics and Advertising Cookies
These cookies track individual user behaviour for enhanced insights. They are only set if you click "Accept All" on our cookie banner.
| Provider | Description |
|---|---|
| Google Analytics (GA4) | Used to analyze cross-session website traffic, understand our customers, and improve our marketing and advertising campaigns (see support.google.com/analytics/answer/11397207) |
| Matomo | Used to analyze cross-session website traffic, understand our customers, and improve our marketing and advertising campaigns (see matomo.org/faq/general/faq_146/) |
| Google Ads | Used to improve our paid advertising campaigns (see business.safety.google/adscookies) |
| Shopify | Used by Shopify to generate reports on Site usage (see www.shopify.com/legal/cookies) |
How to Control Cookies
On your first visit to our Site, you will see a banner asking for cookie consent:
- "Essential Only" allows only essential cookies required for site functionality
- "Accept All" allows all cookies, including essential and analytics/advertising
When you choose "Essential Only", we will still collect anonymous, aggregated statistics as described in the "Website Analytics" section above, but without using cookies or tracking you across sessions.
Your choice is saved in a cookie (cookiesAccepted) that lasts for 1 year, unless you choose to reset your cookie preferences or delete your saved cookies. To reset your cookie preferences, click "Reset Cookie Preferences" in the footer. This will delete non-essential cookies. You will then be prompted to make a new choice.
You can also block or delete cookies through your browser. Disabling cookies may negatively affect the functionality of our website.
Data Sharing and Transfers
Sharing between Ossila Ltd. and Ossila BV
Ossila BV is a wholly owned subsidiary which has been set up by Ossila Ltd. to serve the European market. Personal data including your name and delivery address and other relevant information about your order may be shared between Ossila Ltd. and Ossila BV for:
- Order processing and fulfillment
- Customer support
- Inventory management
- Consolidated analytics and business reporting
Disclosure of Information to Third Parties
We do not, and will never, sell any of your personal data to any third party. However, we share your data with the following categories of companies -- some of whom are located outside the UK/EU -- as an essential part of being able to provide our services to you.
| Service Provider | Purpose | What We Share | Privacy Policy |
|---|---|---|---|
| Shopify Inc. | E-commerce platform | Order details, customer information | Shopify Privacy |
| Google LLC | Site analytics (GA4) and advertising (Google Ads) | Browsing behavior, anonymized data | Google Privacy |
| InnoCraft Ltd (Matomo) | Site analytics | Anonymized usage data | Matomo Privacy |
| Stripe | Card payment processing | Payment information | Stripe Privacy |
| DHL, FedEx, UPS | Shipping and logistics | Name, address, contact details, order information for delivery and customs | Various |
| Zoho | Customer relationship management (CRM) | Customer enquiries, order information | Zoho Privacy |
Other Disclosures
We also use standard business tools (email, cloud storage, collaboration software, banking services) to run our operations. These tools may incidentally process customer data as part of our normal business activities.
We may also disclose your information:
- To comply with legal obligations
- To protect our rights and prevent fraud
- With your explicit consent
Data Retention
We retain your personal data only for as long as necessary to:
- Fulfil the purposes described in this policy
- Comply with legal obligations
- Resolve disputes and enforce our agreements
When data is no longer needed, we securely delete or anonymize it.
Data Security
While no internet transmission or electronic storage method is completely secure, we use appropriate technical and organizational security measures to protect your personal data, including encryption, access controls, and secure payment processing.
Recruitment
When you apply for a job with us, we will securely store your application (and therefore your personal details) for the duration of the active recruitment process for that specific role.
Recruitment Process
- Initial screening: In the first instance, all applications will only be viewed by a member of our HR team
- Shortlisting: If you are successful in the HR pre-screen, your application (and any information that you have provided within) will be shared with internal recruitment personnel, who will decide whether to progress you on to the interview stage
- Interviews: You may be invited for an initial telephone interview with a member of our HR team, or the hiring manager for the role. Promising candidates will ultimately be invited to onsite face-to-face interviews with us
- References: Regardless of whether you've included the contact details for obtaining references, we will always ask your permission before getting in touch with your reference providers
Data Retention for Recruitment
- Unsuccessful candidates: Once the recruitment round has closed, we will delete all applications from unsuccessful candidates
- Interview notes: Our HR team may retain notes from the interviews for a period of one year (the legally recommended retention period)
- CV and cover letter: We will not keep your CV and cover letter beyond the recruitment round unless we have specifically gained your consent to do so
Third-Party Applications
If your application is submitted through a third-party site, you must check that company's privacy policy directly. Please note that we will always be happy to accept direct applications. We do not work with recruitment agencies.
Email Newsletters
If you have opted in to being contacted in this way, we may send you marketing emails to help you see and find our products. Typically, this may include email newsletters about similar products or services.
You will always have the option to unsubscribe from these emails at any time, simply by:
- Clicking the "Unsubscribe" button located at the bottom of each email newsletter
- Contact us by emailing us at info@ossila.com or using the contact form on our website
Certain emails, such as order confirmation emails or legal notices, are sent independently to email newsletters, so you will still receive these if you have opted out of marketing emails.
Your Rights
Under data protection legislation including GDPR and UK GDPR, you have the right to:
- Be informed about how your personal information is being used
- Access the personal information we hold about you
- Request the correction of inaccurate personal information we hold about you
- Request that we delete your data, or stop processing it or collecting it
- Limit how we process your data
- Request that we transfer or port elements of your data
- Object to processing based on legitimate interests
- Stop email marketing and withdraw consent for other consent-based processing
- Complain to your data protection regulator
To exercise these rights, contact us at info@ossila.com.
Managing Cookies and Marketing Preferences
You can change your cookie settings at any time by clicking "reset cookie preferences" in the footer or by using in-built browser controls. You can unsubscribe from any marketing emails by clicking the "unsubscribe" link at the bottom of the email or by contacting us.
Data Erasure Requests
Ossila respects the privacy of our users and their right to control their personal data. We recognize the right to be forgotten, also known as the right to erasure. This gives you the right to request the deletion or removal of personal data.
You can request the deletion of your personal information from our systems via email to info@ossila.com. To expedite the process, your request should include:
- The email subject "Data Erasure Request"
- Your full name and contact details where you can be reached
- Your customer or order ID (if applicable)
- Which data you would like to be provided or have deleted
There are some situations where we cannot delete your data, including:
- To comply with a legal obligation, including but not limited to:
- Demonstrating compliance with international trade restrictions
- Where data is required for accounting or tax reasons (7 year retention)
- Where data is required for the establishment, exercise, or defense of legal claims
- If the request is deemed to be manifestly unfounded or excessive
To prevent unauthorized data processing, we will confirm your identity before assessing the legitimacy of the request, after which all requests will be processed within applicable time limits.
If your request is valid and proceedable, your data will be removed from all live systems. It may take additional time for your personal data to be removed from our automated backup systems.
Changes to Our Privacy Policy
| Date | Description of Change |
|---|---|
| 19/01/2026 | Added detailed website tracking information and explanation of cookie consent mechanism. Updated cookies tables. Updates to international transfer mechanisms (removed outdated Privacy Shield reference, added Data Privacy Framework). Restructured and reworded document for better clarity and readability. |
| 24/10/2023 | More information on the different cookies we use and how to contact us with a data erasure request (no change in policy). Removal of section on user experience tools as these are no longer used. Details on how we use Google Analytics to record anonymous website data. Changes to the wording throughout the policy to add clarity. |
| 13/10/2023 | Updates to the "Disclosure of information to 3rd parties" and "Transfer of information outside of the EU" sections to describe how we work with third party contracted professionals. |
| 10/10/2023 | New recruitment process and information on how we process and store applicant data. |
| 01/11/2021 | Changes to how your data is handled and shared; if you place an order with us and your delivery address is in the EU or EEC, your order will be processed by Ossila BV. Your data, including personal information such as your name and delivery address and other relevant information about your order, will be shared between Ossila Ltd. and Ossila BV. |
Questions or Requests
If you have any queries about our privacy policy or any of your personal data that we hold, you can contact us by phone or email.
UK/General Inquiries
- Email: info@ossila.com
- Phone: +44 (0) 114 2999 180
- Hours: Monday-Friday, 8:00-17:00 (GMT/BST)
EU Inquiries
- Email: info@ossila.com
- Phone: +31 (0)718 081020
- Hours: Mon-Fri, 9:00-17:00 (CET/CEST)