Privacy Policy
How Capsules UK Ltd collects, uses, shares and protects personal data of trade-account applicants, portal users and website visitors, under UK GDPR and the Data Protection Act 2018.
Draft — pending legal review
This is placeholder content prepared for internal review and is not legal advice. It must be reviewed and approved by a qualified legal professional before publication. Items marked [PLACEHOLDER] require specific information.
Last updated: 22 June 2026
Introduction
This Privacy Policy explains how we collect, use, store, share and protect personal data when you visit this website, apply for a trade account, use our customer portal, or otherwise interact with us. Capsules.com is a business-to-business supplier of empty two-piece HPMC and gelatin capsules to trade customers, such as manufacturers, contract packers and brands. We do not sell to consumers and our website is not directed at the general public.
We are committed to protecting your personal data and to handling it in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR). This policy should be read together with our Cookie Policy and our Terms of Use.
[PLACEHOLDER: This is draft content prepared for internal review. It must be reviewed and approved by a qualified data protection or legal professional before publication.]
Who We Are (Data Controller)
Capsules UK Ltd is the data controller responsible for the personal data described in this policy. This means we decide how and why your personal data is processed. As we expand into other markets, a separate group entity (for example, our planned US entity) may act as controller for customers in that region; where this applies we will update this policy and tell you which entity is your controller.
- Controller: Capsules UK Ltd
- Registered company number: [PLACEHOLDER: company registration number]
- Registered office address: [PLACEHOLDER: registered address]
- Data protection contact: [PLACEHOLDER: DPO or privacy contact email]
- ICO registration number: [PLACEHOLDER: ICO registration / data protection fee reference]
We have not appointed a statutory Data Protection Officer where one is not legally required, but you can contact our data protection lead using the details above for any privacy-related query. [PLACEHOLDER: confirm whether a DPO is appointed and update accordingly.]
Scope Of This Policy
This policy applies to personal data we process about people who interact with us in a business context. That includes trade-account applicants and their named contacts, authorised users of our customer portal, ordering, billing and technical contacts at customer companies, suppliers and professional contacts, and visitors to our website.
Because we deal with companies rather than consumers, much of the data we hold relates to individuals acting on behalf of a business (for example, a buyer or a quality contact at a manufacturer). That information is still personal data where it identifies an individual, and it is protected by this policy.
Personal Data We Collect
We collect and process the following categories of personal data. We aim to collect only what we need for the purposes described in this policy. We do not intentionally collect special category data (such as health or biometric data), and we ask that you do not provide it to us.
| Category | Examples | Source |
|---|---|---|
| Identity and contact data | Full name, job title or role, business email address, business telephone number, the company you represent | Provided by you when you apply for a trade account, are added as a portal contact, or contact us |
| Trade-account application data | Company name, trading address, company registration / VAT details, business sector, intended use, indicative volumes, references or trade information you supply | Provided by you in the trade-account application form |
| Account and portal data | User account identifier, sign-in records, authentication tokens, roles and permissions, contacts linked to your company account | Generated when an account is created and when you use the portal; managed via our authentication provider |
| Order and transaction data | Order requests, purchase order references, dispatch and tracking details, ETAs, agreed pricing applicable to your account, ordering and delivery contacts | Generated through your use of the portal and our order processes |
| Billing and financial contact data | Billing contact name and email, invoice references, payment status; payments are made via hosted invoice/quote links provided by our accounting system | Provided by you and generated through invoicing; we do not capture or store payment card details ourselves |
| Documents and correspondence | Emails, support requests, enquiries, and document access activity (for example, access to Certificates of Analysis, specifications and regulatory or batch-traceability documents) | Provided by you and generated through your interactions with us |
| Website usage and technical data | IP address, device and browser type, pages viewed, referring pages, and strictly necessary cookie identifiers; region preference and detected-country signals used to route UK and US visitors | Collected automatically when you use the website (see our Cookie Policy) |
We do not currently operate advertising cookies, and analytics are not yet implemented; if we introduce analytics or other non-essential cookies in future we will update this policy and our Cookie Policy and, where required, ask for your consent. [PLACEHOLDER: confirm analytics status at launch.]
How We Collect Your Personal Data
- Directly from you: when you apply for a trade account, are added as a contact under a company account, place or request orders, contact our sales or support team, or correspond with us.
- Automatically: when you use our website, through strictly necessary cookies and similar technologies and from server logs (see our Cookie Policy for details).
- From your colleagues: a company administrator or authorised contact at your business may provide your details to add you as a portal user or order/billing/technical contact.
- From third parties and public sources: for example, company information services or references, where relevant to assessing or administering a trade account. [PLACEHOLDER: confirm any third-party data sources actually used.]
Purposes And Lawful Bases For Processing
Under UK GDPR we must have a lawful basis for processing your personal data. The table below sets out what we use your data for and the lawful basis we rely on under Article 6 of the UK GDPR. Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms.
| Purpose | Data used | Lawful basis (UK GDPR Art 6) |
|---|---|---|
| Assessing and approving trade-account applications | Application data, identity and contact data, company information | Legitimate interests (Art 6(1)(f)) to assess suitability of prospective trade customers; and steps prior to entering a contract (Art 6(1)(b)) |
| Creating and administering company accounts and portal user access | Identity and contact data, account and portal data, roles and permissions | Performance of a contract (Art 6(1)(b)); and legitimate interests (Art 6(1)(f)) in securely managing company-level access |
| Authenticating users and securing the portal | Account data, authentication tokens, sign-in records, technical data | Legitimate interests (Art 6(1)(f)) to keep accounts and data secure; and contract (Art 6(1)(b)) |
| Processing order requests and providing order, dispatch, ETA and tracking information | Order and transaction data, contact data | Performance of a contract (Art 6(1)(b)) |
| Providing customer-specific catalogue, pricing and documents (COAs, specifications, regulatory and batch-traceability documents) | Account data, order data, document access data | Performance of a contract (Art 6(1)(b)); and legal obligation (Art 6(1)(c)) for record-keeping and traceability |
| Invoicing and facilitating payment via hosted invoice/quote links | Billing and financial contact data, transaction data | Performance of a contract (Art 6(1)(b)); and legal obligation (Art 6(1)(c)) for accounting and tax records |
| Responding to enquiries and providing customer support | Contact data, correspondence | Legitimate interests (Art 6(1)(f)); or contract (Art 6(1)(b)) where related to an existing account |
| Sending service and transactional communications (for example, magic-link sign-in emails, order and account notifications) | Identity and contact data, account data | Performance of a contract (Art 6(1)(b)); and legitimate interests (Art 6(1)(f)) in administering the service |
| Operating, securing and improving the website | Website usage and technical data, strictly necessary cookies | Legitimate interests (Art 6(1)(f)) to provide a secure, functional website; strictly necessary cookies are exempt from consent under PECR |
| Setting non-essential cookies or analytics (if introduced) | Cookie and usage data | Consent (Art 6(1)(a)) and PECR consent requirements |
| Complying with legal, regulatory, tax and accounting obligations | Most categories as relevant | Legal obligation (Art 6(1)(c)) |
| Establishing, exercising or defending legal claims, and preventing fraud | Most categories as relevant | Legitimate interests (Art 6(1)(f)); and legal obligation (Art 6(1)(c)) where applicable |
| Sending B2B marketing about our products and services (where applicable) | Identity and contact data | Legitimate interests (Art 6(1)(f)) for relevant business contacts, subject to PECR; or consent (Art 6(1)(a)) where required |
You can object to processing based on legitimate interests, and you can withdraw any consent at any time. Where you do, this will not affect the lawfulness of processing carried out before withdrawal. We will always provide a simple way to opt out of marketing communications.
Who We Share Your Personal Data With
We do not sell your personal data. We share it only where necessary for the purposes set out in this policy, and we require our processors to protect it and to act only on our instructions under a written contract that meets the requirements of Article 28 of the UK GDPR.
- Hosting and platform providers: our website and portal are hosted on Vercel, which processes technical and usage data on our behalf.
- Database and authentication provider: Supabase, which hosts our database and handles account authentication (including emailed magic-link sign-in and planned single sign-on).
- Email provider: a transactional email provider (for example, a service such as Resend or Postmark) used to send sign-in, order and account emails. [PLACEHOLDER: confirm chosen email provider.]
- Accounting and payment system: our accounting provider (for example, QuickBooks or Xero) used for invoicing and to generate hosted invoice/quote payment links; we do not capture or store payment card details ourselves. [PLACEHOLDER: confirm chosen accounting provider.]
- Inventory, fulfilment and document systems and third-party logistics providers, where engaged, to fulfil orders and provide tracking and documentation. [PLACEHOLDER: confirm operational stack and 3PL providers once selected.]
- Professional advisers, such as our lawyers, accountants, auditors and insurers, where reasonably necessary.
- Regulators, law enforcement and other authorities, where we are required to do so by law or to protect our rights.
- Other group entities, such as our planned US entity, where relevant to providing services to you (see International Transfers below).
- Acquirers or successors in the event of a business sale, merger or reorganisation, subject to appropriate confidentiality and data protection safeguards.
International Transfers
Some of our processors and group entities are located outside the United Kingdom, including in the United States. Where we transfer personal data outside the UK, we make sure it is protected by an appropriate safeguard recognised under UK data protection law.
- Transfers to countries covered by UK adequacy regulations, where the UK government has decided the country provides an adequate level of protection.
- The UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, for transfers to countries without adequacy.
- Where relevant, transfers made under the UK Extension to the EU-US Data Privacy Framework for certified US recipients.
Our planned expansion to a US entity, and our use of US-based processors such as our hosting and database providers, may involve transfers to the United States. You can ask us for more information about the safeguards we use and, where appropriate, a copy of the relevant transfer mechanism, using the contact details above. [PLACEHOLDER: confirm specific transfer mechanisms in place with each processor.]
How Long We Keep Your Personal Data
We keep personal data only for as long as we need it for the purposes set out in this policy, including to satisfy any legal, accounting, regulatory or reporting requirements, and to establish, exercise or defend legal claims. When we no longer need personal data, we will securely delete or anonymise it.
- Trade-account applications that are not approved: retained for a limited period to administer the decision and handle any follow-up, then deleted. [PLACEHOLDER: confirm retention period, e.g. 12 months.]
- Customer account, order and portal records: retained for the duration of the account relationship and for a period afterwards. [PLACEHOLDER: confirm retention period after account closure.]
- Invoices and accounting records: retained to meet UK tax and accounting obligations (typically at least six years). [PLACEHOLDER: confirm statutory retention period.]
- Quality and traceability documents (such as COAs and batch records): retained in line with regulatory and traceability requirements. [PLACEHOLDER: confirm retention period.]
- Website logs and strictly necessary cookie data: retained for a short period for security and operational purposes.
Your Data Protection Rights
Under the UK GDPR you have a number of rights in relation to your personal data. These rights are not absolute and may not apply in every situation, but we will always consider your request and respond in line with the law.
- The right to be informed about how we use your personal data (which this policy provides).
- The right of access to obtain a copy of the personal data we hold about you.
- The right to rectification to have inaccurate or incomplete data corrected.
- The right to erasure to ask us to delete your data in certain circumstances.
- The right to restrict processing to ask us to limit how we use your data in certain circumstances.
- The right to data portability to receive certain data in a structured, commonly used, machine-readable format, or to have it transferred to another controller.
- The right to object, including to processing based on our legitimate interests and to direct marketing.
- Rights relating to automated decision-making and profiling; we do not currently make decisions about you based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, please contact us using the details in the Who We Are section. We may need to verify your identity before responding. We will respond within one month, although we may extend this by up to two further months for complex or numerous requests, and we will tell you if we need to do so. Exercising your rights is normally free of charge.
How To Complain
If you have any concern about how we handle your personal data, please contact us first and we will do our best to resolve it. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
- Information Commissioner's Office (ICO)
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
- Post: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the chance to address your concerns before you approach the ICO, so please consider contacting us in the first instance.
How We Protect Your Personal Data
We take the security of personal data seriously and use appropriate technical and organisational measures to protect it against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include access controls and role-based permissions, encryption in transit, secure authentication (including magic-link sign-in and planned single sign-on), and the use of reputable hosting and infrastructure providers.
Access to the customer portal and to company data is restricted to authorised users, and we apply the principle that users should see data for their company according to their role (for example, billing contacts may have invoice access while quality contacts may have document and COA access). Where we suffer a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO and, where required, affected individuals, in line with our legal obligations.
Children
Our website, products and customer portal are intended for business customers and the professionals who work for them. They are not directed at children, and we do not knowingly collect personal data relating to children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
Cookies
We use strictly necessary cookies to operate the website and portal, including authentication and session cookies (for example, our Supabase authentication cookies and a session cookie), and cookies that remember your region preference and detected country so we can route UK and US visitors correctly. These strictly necessary cookies do not require your consent under PECR.
We do not currently use advertising cookies, and analytics are not yet in place. If we introduce non-essential cookies or analytics in future, we will update our Cookie Policy and obtain your consent where required. Please see our separate Cookie Policy for full details. [PLACEHOLDER: confirm cookie inventory and link to Cookie Policy.]
Changes To This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or business, including as we expand into new markets such as the United States. When we make material changes, we will update the effective date below and, where appropriate, notify you.
- Effective date: [PLACEHOLDER: effective date]
- Last reviewed: [PLACEHOLDER: review date]
- Version: [PLACEHOLDER: version number]
Contact Us
If you have any questions about this Privacy Policy or about how we handle your personal data, or if you wish to exercise any of your rights, please contact us:
- Capsules UK Ltd
- Registered office: [PLACEHOLDER: registered address]
- Company number: [PLACEHOLDER: company registration number]
- Data protection contact: [PLACEHOLDER: privacy / DPO email]
- Governing law and jurisdiction: this policy and any dispute relating to it are governed by the laws of [PLACEHOLDER: governing-law venue, e.g. England and Wales], and subject to the jurisdiction of its courts.