Privacy Policy
How Arcadia Diagnostics handles website data, COA lookup logs, and client testing information. No sale of data; testing results are confidential by default.
About this document
This policy explains what Arcadia Diagnostics collects, why, how long it is kept, and what you can ask us to do about it. It covers the website, the certificate of analysis lookup, and client testing records.
Effective 19 August 2026 · Version 1.0.
1. Scope
This policy describes what information Arcadia Diagnostics collects through its website and certificate of analysis lookup, what it does with client and testing information, and how to make a request about your data.
Arcadia Diagnostics tests materials, not people. We do not accept human or animal biological specimens, we do not perform clinical or diagnostic testing, and we do not hold health information about any individual.
This policy covers the website and the COA lookup. Handling of client testing records is also governed by the confidentiality terms of the services agreement and the Terms of Service.
2. Information collected through the website
Information you send us. If you email us or use a contact form, we receive what you choose to send: typically your name, email address, organization, and the content of your inquiry, including any details you supply about a material or a testing requirement. We keep inquiry correspondence as a business record.
The inquiry form on the Contact page collects four things and nothing else: your name, your institution or company (optional), your email address, and your message. Submissions are delivered to arcadiadiagnostics.contact@gmail.com and are also stored on the website's own server so that an inquiry is not lost if email delivery fails. The form sets no cookie and does not profile you.
Server logs. Our hosting infrastructure records standard technical information about requests: IP address, user-agent string, requested URL, referring URL, response status, and timestamp. These logs are used to operate the site, diagnose faults, and detect abuse.
Server logs are held by our hosting provider, Hostinger International Ltd, acting as our processor, and are retained for 30 days.
Cookies and analytics. The site runs no analytics, no advertising networks, no cross-site tracking pixels, and no third-party scripts of any kind — all fonts, styles, and code are served from our own domain. No cookie is set for ordinary visitors. The only cookies that can be set are functional ones belonging to the WordPress administration login, which apply to laboratory staff signing in, and to the hosting platform's page cache. There is no consent banner because there is nothing to consent to.
We do not use advertising networks, cross-site tracking pixels, or cross-context behavioral advertising.
3. The certificate of analysis lookup
The COA lookup requires no account and no registration. You do not sign in and we do not ask who you are.
What is logged. For each lookup we record the accession number submitted, the timestamp, the requesting IP address and user-agent, and whether a record was returned. Nothing else.
Why it is logged. Solely to protect client confidentiality and site availability:
- Rate limiting. Lookups are rate limited per source. Logs are what make that enforceable.
- Abuse and enumeration detection. Certificates are private by default and accession numbers are high-entropy and non-sequential precisely so the record set cannot be walked. Repeated failed lookups are the signature of an attempt to guess identifiers, and we monitor for it.
- Integrity investigations. Where a forged or altered certificate is circulating, lookup logs help establish what was actually retrieved and when.
Lookup logs are not used to profile visitors, are not combined with marketing data, and are not shared for any commercial purpose.
Lookup logs are retained for 90 days and then deleted. We do not publish the specific rate limit thresholds, because publishing them would tell someone attempting enumeration exactly how to stay under them.
What is displayed. Published certificates show analytical and sample information only — report and accession identifiers, status and dates, sample as received, methods, results with units and reporting limits, and the client-declared lot identifier. Submitter names, individual contact details, addresses, internal client codes, and pricing are never displayed. No personal data about any individual appears in a published certificate.
4. Client and testing information
For clients, we hold the information needed to run the engagement and keep a defensible record: contact details for the people we correspond with, submission and chain-of-custody records, sample descriptions and declared identities, raw analytical data, reports, and billing records.
Testing data is confidential by default. Client identity, sample information, and results are not disclosed to third parties except with the client's written authorization, to subcontractors engaged for the work under equivalent confidentiality obligations, or where required by law.
We do not confirm client relationships. We do not tell third parties whether a person or company is a client, or whether any product or lot has been tested here.
Publication is opt-in. A certificate appears in the COA lookup only where the client has given written, revocable authorization identifying which fields may be displayed. Publication is never automatic and never applied retroactively to past reports.
Withdrawal of publication. A client may withdraw publication consent in writing at any time. Withdrawal takes effect on the next business day, after which the accession returns no result to the public lookup. Withdrawal applies to a certificate as a whole and cannot be used selectively — we will not remove an unfavorable certificate while leaving favorable ones published, because a curated set of results is a misleading one. The underlying analytical record is retained regardless, and a certificate we have issued is never altered to change a result; an error is corrected by issuing an identified amendment that supersedes the original.
5. How information is used
We use the information described above to:
- respond to inquiries and prepare quotations;
- perform, document, and report testing;
- issue submission instructions and manage sample custody;
- invoice and collect payment;
- maintain analytical and quality records for the retention periods stated in our Terms;
- operate, secure, and troubleshoot the website and COA lookup, including rate limiting and abuse detection; and
- comply with legal obligations and respond to lawful requests.
Where the GDPR or UK GDPR applies, our lawful bases are: performance of a contract for quotation, testing, reporting, custody, and invoicing; legal obligation for tax, records, and lawful requests; and legitimate interests for operating and securing the website and the COA lookup, including request logging, rate limiting, and abuse detection. Our interest there is protecting client confidentiality and site availability, which we consider is not overridden by the limited technical data involved.
We do not use client testing data to train models, to build market intelligence products, or for any purpose beyond delivering and documenting the engagement.
6. We do not sell your data
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not rent, trade, or otherwise make personal information or client testing data available to data brokers, marketers, or any third party for their own purposes.
We do not publish client lists, client logos, testimonials, or aggregate statistics derived from client work.
Information is disclosed only to:
- service providers acting on our instructions, such as website hosting and email — our hosting provider, Hostinger International Ltd, and our email provider, Google LLC, each under their respective data processing terms;;
- subcontract laboratories, where a determination is referred, under confidentiality obligations and in accordance with the Terms of Service; and
- authorities, where disclosure is required by law, court order, or valid legal process. Where we are permitted to notify the affected client, we will.
7. Retention
We keep information for these periods, counted from the last relevant event:
- Inquiry correspondence and form submissions — 24 months, so that we can pick up a conversation a client returns to.
- Client account and billing records — seven years, to meet tax and accounting obligations.
- Sample material — 30 days after the report is issued, then disposed of or returned.
- Raw analytical data and issued reports — five years, so an issued report stays supportable.
- Server logs — 30 days.
- COA lookup logs — 90 days.
We retain analytical records for the period stated in our Terms of Service so that an issued report remains supportable. Records are deleted or securely destroyed at the end of the applicable period.
8. Security
Access to client testing records is limited to personnel who need it to perform or review the work. Systems holding client data are access-controlled and reports are released only by an authorized signatory.
The COA lookup is designed so that confidentiality does not depend on obscurity of the interface alone: identifiers are high-entropy and non-sequential, there is no listing or index endpoint, requests are rate limited, and unauthorized records are indistinguishable from nonexistent ones in the response.
In practical terms: all traffic to the site is encrypted in transit with TLS, and the site is served over HTTPS only. Certificate files and instrument traces are stored outside the publicly served directory tree, behind a deny-all rule, and are released only through signed links that expire; a tampered link is rejected rather than served. Administrative access is limited to named accounts, the certificate records are not exposed to the public site, the REST API, search, sitemaps, or feeds, and repeated failed lookups are rate limited. The hosting platform takes regular automated backups. We describe only controls that are actually in place.
Email is not a secure channel. Information you send by email may be read in transit or at rest by parties outside our control. Do not send anything by email that requires stronger protection; contact us first and we will agree an alternative.
If a breach affecting personal information or client testing data occurs, we will investigate immediately, notify affected clients directly without undue delay, and notify the relevant supervisory authority within 72 hours of becoming aware where the applicable law requires it.
9. Your rights and how to make a request
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information we hold about you, to object to or restrict certain processing, and to be free from discrimination for exercising those rights.
Depending on the law that applies to you, those rights may include: the right to know what we hold and to obtain a copy; to have inaccurate information corrected; to have information deleted; to restrict or object to processing; to receive your information in a portable format; to opt out of sale or sharing, of which we do neither; and not to be discriminated against for exercising a right. If you are in the EEA or the UK you may also complain to your supervisory authority, and if you are in a US state with a privacy statute you may contact your state attorney general.
To make a request, email arcadiadiagnostics.contact@gmail.com with the subject line "Privacy request". We will ask for information sufficient to verify that the request comes from you or an authorized agent.
We verify a request by corresponding with the email address already associated with the information, or, where there is none, by asking for enough detail to match the request to a record. We respond within 30 days, and where a request is complex we may extend once by a further 30 days and will tell you why within the first period. If we decline a request in whole or in part we will say so and explain the basis; you can appeal by replying to that response, and we will review the appeal and respond within a further 30 days.
Note that requests to delete may be limited where we are required to retain analytical records, billing records, or correspondence to support a report we have issued or to meet a legal obligation. Where that applies we will tell you what is being retained and why.
10. Other matters
Children. The website is directed to businesses and research organizations. We do not knowingly collect information from children. We do not knowingly collect information from anyone under 16, and the site is not directed to children.
International transfers. Information is stored and processed in the United States. Where personal information is transferred from the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum as the transfer mechanism.
Third-party links. Pages on this site may link to external references such as standards bodies and published literature. Those sites have their own privacy practices and this policy does not cover them.
Changes. We may update this policy. The current version and its effective date appear at the top of this page. Where a change is material, clients with an engagement in progress are notified by email at least 30 days before it takes effect. Prior versions are available on request.
Privacy contact
Privacy inquiries are handled by the laboratory's authorized signatory, Callum Solomon, and reach us at arcadiadiagnostics.contact@gmail.com with the subject line "Privacy request". If you need to make a request by post rather than by email, write to us at that address and we will supply a postal route.
Arcadia Diagnostics does not carry out large-scale monitoring or large-scale processing of special-category data, and is not required to appoint a Data Protection Officer. It does not target the EEA or the UK and has not appointed a representative there. If either position changes, this section will name the appointee.
Get started
Discuss your testing requirements
Tell us the compound, the format and the questions you need answered. We will confirm the appropriate methods, the sample quantity required and the turnaround before anything ships.