One-Stop In Vitro Diagnostics (IVD) CDMO Partner | From Lab to Market
Expert Call: (86) 23-86916205

GDPR Compliance

Effective Date: [05,15, 2026]
Last Updated: [05,15, 2026]

At IVD CDMO (“IVD CDMO,” “we,” “our,” or “us”), we respect privacy and are committed to protecting personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the UK GDPR, and related privacy regulations where applicable.

This GDPR Compliance Statement explains how we apply GDPR-related principles to our website, B2B inquiry process, marketing communication, cookie usage, and business data handling practices.

This page should be read together with our:

  • Privacy Policy
  • Cookie Policy
  • Terms of Use
  • Legal Notice

IVD CDMO is a B2B service presentation and business inquiry platform focused on in vitro diagnostics-related services, including IVD antibody development, antigen development, immunoreagent development, assay development support, OEM services, and CDMO manufacturing solutions.

Our website is intended for professional and business users. We do not provide medical diagnosis, treatment, patient-facing healthcare services, or direct clinical testing services through this website.


1. Our GDPR Commitment

We are committed to handling personal data in a lawful, fair, transparent, secure, and responsible manner.

Where GDPR or UK GDPR applies, we aim to ensure that personal data is processed according to core data protection principles, including:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

2. Scope of This GDPR Compliance Statement

This statement applies to personal data collected through:

  • Website visits
  • Contact forms
  • Request a quote forms
  • Technical inquiry forms
  • Email communication
  • Newsletter subscriptions
  • Business development communication
  • Cookie and analytics technologies
  • B2B marketing interactions
  • Supplier, partner, or distributor communication

This statement does not apply to employment-related data, offline contractual data, or project-specific confidential information that may be governed by separate agreements.


3. Personal Data We May Process

As a B2B platform, we generally process limited business contact and inquiry information, such as:

  • Name
  • Company name
  • Job title
  • Business email address
  • Business phone number
  • Country or region
  • Website or company profile
  • Inquiry details
  • Product or service interests
  • Project requirements
  • Communication history
  • Cookie and website usage data
  • IP address and device information

We collect only the information reasonably necessary to respond to business inquiries, provide technical and commercial communication, improve website performance, and support lawful B2B marketing activities.


4. Information We Do Not Intentionally Collect

Our website is not designed to collect patient-related medical information.

Through this website, we do not intentionally collect:

  • Protected health information
  • Patient-identifiable medical information
  • Clinical records
  • Diagnostic reports
  • Patient test results
  • Patient samples
  • Genetic data
  • Biometric data
  • Sensitive health information
  • Children’s personal information
  • Payment card information
  • Government identification numbers

Please do not submit patient-identifiable medical information, clinical records, diagnostic reports, or sensitive health data through our website forms, email inquiry channels, or other public communication channels.

If such information is submitted unintentionally, we may delete, reject, quarantine, or securely remove it where appropriate.


5. Purposes of Processing

We may process personal data for the following purposes:

5.1 Business Inquiry Response

To respond to contact requests, quotation requests, technical inquiries, partnership discussions, and service-related communication.

5.2 Technical and Commercial Evaluation

To understand your project requirements, assess service feasibility, prepare proposals, provide technical communication, and support potential business cooperation.

5.3 Website Operation and Security

To operate, maintain, secure, troubleshoot, and improve our website, forms, hosting environment, and digital infrastructure.

5.4 Analytics and Website Improvement

To analyze website traffic, visitor behavior, page performance, content quality, SEO performance, and user experience.

5.5 B2B Marketing Communication

To send company updates, technical articles, service information, event invitations, newsletters, and other relevant B2B communication, where permitted by law or based on consent where required.

5.6 Legal and Compliance Purposes

To comply with applicable laws, respond to lawful requests, protect legal rights, prevent fraud, manage disputes, and maintain business records.


6. Lawful Bases for Processing

Where GDPR or UK GDPR applies, we rely on one or more lawful bases under Article 6. The ICO explains that organizations must apply at least one lawful basis whenever they handle personal information. (ICO)

6.1 Consent

We may rely on consent when you:

  • Subscribe to newsletters
  • Accept non-essential cookies
  • Request optional marketing communication
  • Agree to specific data processing activities

You may withdraw consent at any time where processing is based on consent.

6.2 Contract or Pre-Contractual Steps

We may process personal data when necessary to respond to your inquiry, prepare a quotation, evaluate a project, negotiate an agreement, or provide requested services.

6.3 Legitimate Interests

We may process personal data based on legitimate interests, including:

  • Responding to B2B inquiries
  • Managing business relationships
  • Improving website functionality
  • Maintaining website security
  • Conducting limited B2B marketing
  • Preventing fraud or misuse
  • Developing service offerings

When relying on legitimate interests, we consider whether your rights and freedoms override our business interests.

6.4 Legal Obligation

We may process personal data where necessary to comply with legal, tax, accounting, regulatory, export control, recordkeeping, or dispute resolution obligations.


7. GDPR Rights of Individuals

If GDPR, UK GDPR, or similar laws apply to you, you may have the following rights regarding your personal data:

7.1 Right of Access

You may request confirmation of whether we process your personal data and request access to that data.

7.2 Right to Rectification

You may request correction of inaccurate or incomplete personal data.

7.3 Right to Erasure

You may request deletion of your personal data where applicable, subject to legal, contractual, or legitimate business retention requirements.

7.4 Right to Restrict Processing

You may request that we restrict certain processing activities in specific circumstances.

7.5 Right to Data Portability

Where applicable, you may request a copy of your personal data in a structured, commonly used, machine-readable format.

7.6 Right to Object

You may object to certain processing based on legitimate interests, including certain B2B marketing activities.

7.7 Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time.

7.8 Right to Lodge a Complaint

You may lodge a complaint with a relevant data protection authority.

The right to be informed is a key GDPR transparency requirement; organizations should provide clear information about processing purposes, retention periods, and who personal data is shared with. (ICO)


8. How to Exercise Your GDPR Rights

To exercise your rights, please contact us at:

Email: [[email protected]]
Subject Line: GDPR Request

Please include sufficient information to help us identify and process your request, such as:

  • Your name
  • Company name
  • Business email address
  • The nature of your request
  • The country or region where you are located
  • Any relevant website form or communication history

We may need to verify your identity before responding to your request.

We will respond within the timeframe required by applicable law.


9. Cookie Consent and Tracking Technologies

Our website may use cookies and similar technologies for website operation, analytics, performance measurement, security, and B2B marketing.

Where required by GDPR, UK GDPR, ePrivacy rules, PECR, or similar laws, we will request consent before placing non-essential cookies, such as analytics or marketing cookies.

You may:

  • Accept all cookies
  • Reject non-essential cookies
  • Manage cookie preferences by category
  • Withdraw or change consent later

Strictly necessary cookies may be used without consent where they are required for basic website operation or security.

Please review our Cookie Policy for more information.


10. Data Minimization

We aim to collect only the personal data necessary for clearly defined business purposes.

For example, we may need your name, company, business email, country, and inquiry details to respond to a quotation request. We do not need patient medical records, clinical reports, diagnostic results, or sensitive health data for ordinary B2B website inquiries.

Users should avoid submitting unnecessary personal or sensitive information through website forms.


11. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this statement and our Privacy Policy.

Retention periods may depend on:

  • The nature of the inquiry
  • Business communication status
  • Contractual or pre-contractual needs
  • Legal, accounting, and tax obligations
  • Dispute resolution requirements
  • Security and fraud prevention needs
  • Marketing subscription or opt-out status

When personal data is no longer required, we will delete, anonymize, or securely archive it where appropriate.


12. Data Security

We apply reasonable technical and organizational measures to protect personal data from unauthorized access, loss, misuse, disclosure, alteration, or destruction.

These measures may include:

  • Access control
  • Secure hosting
  • Firewall and malware protection
  • Secure communication protocols
  • Limited internal access
  • Vendor security review
  • Data minimization
  • Backup and recovery procedures
  • Internal confidentiality obligations

However, no website, email system, or online transmission method is completely secure. Users should not submit highly confidential or sensitive information through general website forms unless a secure communication method has been arranged.


13. International Data Transfers

Because IVD CDMO operates as an international B2B platform, personal data may be processed or stored outside the European Economic Area, the United Kingdom, or Switzerland.

Where required by applicable data protection laws, we will use appropriate safeguards for international data transfers, which may include:

  • Standard Contractual Clauses
  • Data Processing Agreements
  • Vendor due diligence
  • Access controls
  • Security measures
  • Contractual confidentiality obligations

14. Third-Party Processors and Service Providers

We may use trusted third-party service providers to support website operation and business communication, including:

  • Website hosting providers
  • Email service providers
  • CRM systems
  • Analytics providers
  • Cookie consent tools
  • Cybersecurity providers
  • Form processing tools
  • Marketing automation tools
  • Cloud storage providers
  • IT support providers

Where required, such service providers are expected to process personal data only according to our instructions and applicable data protection requirements.


15. Data Controller and Data Processor Roles

For ordinary website visits, B2B inquiries, newsletter subscriptions, and business communication, IVD CDMO generally acts as a data controller, because we determine the purposes and means of processing personal data.

For certain service provider relationships, third-party vendors may act as data processors on our behalf.

For project-specific business cooperation, data protection roles may be further defined in separate agreements, such as a Data Processing Agreement, Service Agreement, Supply Agreement, Quality Agreement, or Non-Disclosure Agreement.


16. Automated Decision-Making

We do not use website visitor or inquiry data for automated decision-making that produces legal or similarly significant effects on individuals.

We may use analytics, spam protection, CRM scoring, or marketing automation tools to improve website operation, filter abuse, and manage business communication, but these tools are not intended to make legally significant decisions about individuals.


17. Special Category Data

GDPR provides additional protection for special category data, including health data, genetic data, biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, and other sensitive categories.

Our website is not intended to collect or process special category data.

Please do not submit patient-identifiable medical information, diagnostic reports, clinical records, genetic data, biometric data, or sensitive health information through this website.


18. Children’s Data

Our website is intended for professional and business users. It is not directed to children.

We do not knowingly collect personal data from children through this website.

If you believe that a child has submitted personal data to us, please contact us and we will take appropriate steps to delete the information where required.


19. Data Breach Response

If we become aware of a personal data breach, we will assess the nature and potential impact of the incident.

Where required by applicable data protection laws, we will notify the relevant supervisory authority and affected individuals within the legally required timeframe.

We also maintain reasonable internal procedures to help detect, respond to, and mitigate data security incidents.


20. Updates to This GDPR Compliance Statement

We may update this GDPR Compliance Statement from time to time to reflect changes in:

  • Legal requirements
  • Website functionality
  • Data processing practices
  • Cookie tools
  • Business operations
  • Security measures
  • International data transfer practices

The updated version will be posted on this page with a revised “Last Updated” date.

Your continued use of our website after an update means that you acknowledge the revised statement.


21. Contact Us

If you have questions about this GDPR Compliance Statement or wish to exercise your privacy rights, please contact us:

IVD CDMO
Website: [https://www.ivdcdmo.com]
Email: [[email protected]]
Business Contact: [[email protected]]
Address: [Chongqing International Biological City Nanfu Road, Banan District, Chongqing, China]