Privacy policy
1. Who we are
Bioscity Limited ("Bioscity", "we", "us") is a private limited company registered in England and Wales, company number 14994244, registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We are the data controller for the personal data described in this policy.
You can reach us about anything in this policy at hello@bioscity.co.uk.
2. What this policy covers
This policy applies to bioscity.co.uk and to the products we operate: esimkart.com, isorganized.com, domainif.com, iamasoftwareengineer.com, bioscity.com, hostook.com and any other site that links here. If a product publishes its own privacy notice, that notice adds product-specific detail and this policy still applies to everything it does not cover.
It does not cover third-party sites we link to, including eSIM providers listed on esimkart, Etsy, Stripe or Wise. Their own policies apply when you use their services.
3. What we collect
Information you give us
- Contact details when you email us, fill in a contact or partner form, or ask for a quote: name, email address, company, phone number and whatever you write in the message.
- Account details when you register on a product: name, email address, password (stored hashed, never in plain text), and settings you choose.
- Content you upload to a product, for example the list of domains you import into DomainIf.
- Billing details when you buy something: name, email address, billing address, and for invoices your company name and VAT number.
Information collected automatically
- Server logs: IP address, date and time, pages requested, referring page, browser and operating system. Every web server records this.
- Usage data inside a product, such as which features you use and when you last signed in.
- Cookies and similar technologies, described in section 8.
Information from others
- Payment status from Stripe or Wise: whether a payment succeeded, the amount, the last four digits and brand of the card, and the country it was issued in. We never receive your full card number.
- Affiliate network data on esimkart: when you buy an eSIM from a provider after clicking a link on our site, the network tells us that a sale happened and the commission. It does not tell us who you are.
4. How we use it and why we are allowed to
UK data protection law requires a lawful basis for each use. Ours are listed next to each purpose.
| Purpose | Lawful basis |
|---|---|
| Providing a product or service you signed up for, including taking payment and sending receipts | Performance of a contract |
| Replying to your messages and quotes | Legitimate interests, or steps before entering a contract |
| Keeping the sites secure, preventing fraud and abuse, and keeping server logs | Legitimate interests |
| Accounting, tax and company records | Legal obligation |
| Product news and offers by email | Consent, or the soft opt-in for existing customers. You can unsubscribe at any time. |
| Analytics to understand how the sites are used | Consent where non-essential cookies are used; otherwise legitimate interests using aggregated, cookieless statistics |
| Responding to legal requests and enforcing our terms | Legal obligation, legitimate interests |
Where we rely on legitimate interests we have checked that our interest does not override your rights. You can object at any time, see section 10.
We do not sell personal data, and we do not make automated decisions about you that have legal or similarly significant effects.
5. Who we share it with
Only with providers we need to run the business, and only what they need:
- Payment processors: Stripe Payments UK Ltd and Stripe Payments Europe Ltd for card payments; Wise Payments Ltd for bank transfers.
- Hosting and infrastructure providers that run our servers, databases, backups and content delivery.
- Email providers for transactional email and, if you opted in, newsletters.
- Affiliate networks on esimkart, which receive an anonymous click identifier, not your personal details.
- Etsy, if you buy an isorganized product there; Etsy is the seller of record for that transaction.
- Professional advisers: accountants, and lawyers where needed.
- Authorities when the law requires it, for example HMRC or a court order.
If Bioscity is sold or merges with another company, personal data will pass to the new owner under the same terms, and we will tell you.
6. International transfers
We are based in the UK. Some of our providers store or process data outside the UK, mainly in the European Economic Area and the United States. Where that happens we rely on the UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or the provider's certification under the UK Extension to the EU-US Data Privacy Framework.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account and product data | While your account is active, then deleted or anonymised within 90 days of closure |
| Invoices, payment records, receipts | 6 years after the end of the financial year, as UK tax law requires |
| Emails and contact form messages | Up to 3 years, so we can follow up on earlier conversations |
| Server logs | 90 days, longer only if needed to investigate an incident |
| Marketing consent and unsubscribe records | Until you unsubscribe, plus a record that you did so |
8. Cookies
Cookies are small files a site stores in your browser. We use them in three ways:
- Essential: keeping you signed in, remembering your language or currency, protecting forms against forgery, and Stripe's fraud-prevention cookies on payment pages. These do not need consent and cannot be switched off without breaking the site.
- Analytics: only where a product shows a cookie banner and you accept. bioscity.co.uk itself sets no analytics cookies.
- Affiliate tracking on esimkart: when you click through to a provider, the provider or its network may set a cookie so that a later purchase is attributed to us. This is described on esimkart and governed by the provider's policy.
You can delete or block cookies in your browser settings. Blocking essential cookies will stop sign-in and checkout from working.
9. Security
All our sites are served over HTTPS. Passwords are hashed. Card data is handled entirely by Stripe. Access to servers is limited to the people who need it and protected with keys and two-factor authentication. No system is perfectly secure; if we discover a breach that puts you at risk, we will tell you and the Information Commissioner's Office as the law requires.
10. Your rights
Under UK GDPR you can ask us to:
- Access the personal data we hold about you and get a copy.
- Correct anything that is wrong or incomplete.
- Delete your data, unless we must keep it, for example invoices.
- Restrict how we use it while a question is resolved.
- Port data you gave us to another provider in a machine-readable format.
- Object to processing based on legitimate interests, and to any direct marketing, at any time.
- Withdraw consent where consent is the basis, without affecting what was done before.
Email hello@bioscity.co.uk. We reply within one month and do not charge. We may ask you to confirm your identity first.
If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to sort it out first.
11. Children
Our products are for adults and for businesses. We do not knowingly collect personal data from anyone under 18. If you think a child has given us data, email us and we will delete it.
12. Changes
We will update this policy when our practices or the law change. The date at the top tells you when. For significant changes we will email account holders or show a notice on the product.
13. Contact
Bioscity Limited, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
hello@bioscity.co.uk, +44 742 496 7502.
