Privacy
1. Introduction
1.1 This policy applies where we are acting as a data controller with respect to the personal data of our website visitors and subscribers; in other words, where we determine the purposes and means of the processing of that personal data.
1.2 In this policy, “we”, “us” and “our” refer to Get Diamonds IVZW. For more details about us, see Section 11.
2. The personal data that we process
2.1 We may process data about your use of our website and services (“website usage data”). The website usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the usage data is our website analytics tracking system.
2.2 We may process personal information contained in any communication regarding our services between you and us (“communication data”). The communication data may be processed for the purposes of answering your query and similar queries in the future, identifying patterns in the enquires, and for the purpose of keeping records of our interaction.
2.3 We may process data enabling us to get in touch with you (“contact data”). The contact data may include your name, email address, organisational affiliation, telephone number, postal address and/or social media account identifiers. The source of the contact data is you, your employer or associations of which you are a member or may have been in touch with.
2.4 We may process personal information relating to our subscribers and their references (“subscriber data”). The subscriber data may include your name, address, your company, your identity number, a copy of your government approved ID, your function in the company, your VAT number, your contact details, the diamonds you purchased, and information contained in communications between us and you. The source of the customer relationship data is you, your employer, people that referenced you, and your activity on our website.
2.5 We may process information relating to transactions, including purchases of diamonds (“transaction data”). The transaction data may include your name, and the transaction details. The source of the customer relationship data is your activity on our website.
3. Purposes of processing and legal bases
3.1 Operating the website – We may process website usage data, subscriber data and transaction data for the purposes of operating our website and providing our services thereon. The legal basis for this processing is our legitimate interests, namely the proper administration of our website, services and business.
3.2 Relationships and communications – We may process communication data, contact data and subscriber data for the purposes of managing our relationships, communicating with you by email and/or telephone and/or other means, providing support services and complaint handling. The legal basis for this processing is the performance of a contract between you or taking steps at your request prior to entering in a contract. In other cases, i.e. where there is no contract with you and no steps taken at your request prior to entering a contract, the legal basis for the processing is our legitimate interest, namely communications with our website visitors and the proper administration of our services and business.
3.3 Providing our services – We may process any of your personal data identified in this policy for providing our services, mainly facilitating the purchase and sale of diamonds. The legal basis for this processing is the performance of a contract between you and us.
3.4 Direct marketing – We may process contact data for the purposes of creating, targeting and sending direct marketing communications by email and making contact by telephone for marketing-related purposes. The legal basis for this processing is our legitimate interests, namely promoting our business and communicating marketing messages and offers to our contacts. You will always have the option to unsubscribe to these direct marketing communications.
3.5 Research and analysis – We may process website usage data and/or transaction data for the purposes of researching and analysing the use of our website and services, as well as researching and analysing other interactions with our business. The legal basis for this processing is our legitimate interests, namely monitoring, supporting, improving and securing our website, services and business generally.
3.6 Record keeping – We may process your personal data for the purposes of creating and maintaining our databases, back-up copies of our databases and our business records generally. The legal basis for this processing is our legitimate interests, namely ensuring that we have access to all the information we need to properly and efficiently run our business in accordance with this policy.
3.7 Security and fraud prevention – We may process any of your personal data identified in this policy for the purposes of security and the prevention of fraud and other criminal activity. The legal basis of this processing is our legitimate interests, namely the protection of our website, services and business, and the protection of others.
3.8 Legal claims – We may process any of your personal data identified in this policy where necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure. The legal basis for this processing is our legitimate interests, namely the protection and assertion of our legal rights, your legal rights and the legal rights of others.
3.9 Insurance and professional advice – We may process any of your personal data identified in this policy where necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, or obtaining professional advice. The legal basis for this processing is our legitimate interests, namely the proper protection of our business against risks.
3.10 Legal obligations and vital interests – In addition to the specific purposes for which we may process your personal data set out in this Section 3, we may also process any of your personal data where such processing is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
4. Providing your personal data to others
4.1 Other subscribers – Certain elements of the subscriber data that are necessary to get in touch with you may be published on the website in order for other subscribers to get in touch with you.
4.2 Management service providers – We may disclose your personal data to management service providers who provide us with such services in order to allow them to perform their duties.
4.3 Payment service providers – Subscriber data and transaction data may be provided to a payment services providers that we will be working with from time to time. We will share transaction data with our payment services providers only to the extent necessary for the purposes of processing your payments, refunding such payments and dealing with complaints and queries relating to such payments and refunds.
4.4 Insurers and professional advisers – We may disclose your personal data to our insurers and/or professional advisers insofar as reasonably necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, obtaining professional advice, or the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
4.5 Marketing service providers – We may disclose contact data to media marketing operators, and to ActiveTrail Ltd, or to other similar service that can process e-mailings or provide marketing services, for the purpose of inter alia operating out mailing operations.
4.6 CRM providers – We may disclose or contact data, communication data and subscriber data to our suppliers of client relationship management (CRM) or database software insofar as reasonably necessary for establishing such a database.
4.7 Website service providers – We may disclose website usage data, subscriber data and transaction data to the operators of our website trading platform for the purposes of operating the trading platform. We may disclose website usage data to other suppliers of website services insofar as reasonably necessary for domain or website hosting.
4.8 Certification and delivery service providers – We may provide your subscriber, communication and transaction data to I Hennig & Co Ltd, the company providing certification and delivery services for the diamonds purchased through our Buy Now and Silent Auction.
4.9 KYC service providers – We may provide your subscriber data to third parties, including I Hennig & Co Ltd, that provide us with KYC services in order to approve new subscribers.
4.10 Vital interests – In addition to the specific disclosures of personal data set out in this Section 4, we may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
4.11 Legal defence – We may also disclose your personal data where such disclosure is necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
5. International transfers of your personal data
5.1 In this Section 5, we provide information about the circumstances in which the personal data of European Union data subjects may be transferred to countries outside the European Economic Area (EEA).
5.2 You acknowledge that personal data that you submit through our website or services in order to allow other subscribers to contact you may be available around the world.
5.3 Our certification, delivery and KYC service provider, I Hennig & Co is located in the United Kingdom. The competent data protection authorities in the EU have made an adequacy determination with respect to the data protection provided by the United Kingdom.
5.4 Our platform operator and CRM service provider, our media marketing provider, and our management service provider are located in Israel. The competent data protection authorities in the EU have made an adequacy determination with respect to the data protection provided by Israel.
5.5 The data centers of our mail-out campaign service provider ActiveTrail Ltd are located in the European Union. More details are available at: https://www.activetrail.com/privacy_policy/.
6. Retaining and deleting personal data
6.1 This Section 6 sets out our data retention policies and procedure, which are designed to help ensure that we comply with our legal obligations in relation to the retention and deletion of personal data.
6.2 Personal data that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
6.3 We will retain your personal data as follows:
(a) website usage data will be retained for […] months as defined in Google Analytics;
(b) communication data will be retained for a period of 12 months, unless the data also falls under subscriber data, in which case, the retention period of sub-section (d) will apply;
(c) contact data will be retained for as long as the contact receives the marketing communications from us. The moment the contact will ask to unsubscribe, the contact data will be deleted immediately;
(d) subscriber data will be retained for as long as the subscriber account remains active with us;
(e) transaction data will be retained for as long as the subscriber account linked to the transaction remains active with us.
6.4 Notwithstanding the other provisions of this Section 6, we may retain your personal data where such retention is necessary for conducting our legal defence, for protecting our interests in case of a legal suit, for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
7. Amendments
7.1 We may update this policy from time to time by publishing a new version on our website.
7.2 You should check this page occasionally to ensure you are happy with any changes to this policy.
8. Your rights
8.1 In this Section 8, we have listed the rights that you have under data protection law.
8.2 Your principal rights under data protection law are:
(a) the right to access – you can ask for copies of your personal data;
(b) the right to rectification – you can ask us to rectify inaccurate personal data and to complete incomplete personal data;
(c) the right to erasure – you can ask us to erase your personal data;
(d) the right to restrict processing – you can ask us to restrict the processing of your personal data;
(e) the right to object to processing – you can object to the processing of your personal data;
(f) the right to data portability – you can ask that we transfer your personal data to another organisation or to you;
(g) the right to complain to a supervisory authority – you can complain about our processing of your personal data;
(h) the right to withdraw consent – to the extent that the legal basis of our processing of your personal data is consent, you can withdraw that consent.
8.3 These rights are subject to certain limitations and exceptions. You can learn more about the rights of data subjects by visiting https://edpb.europa.eu/our-work-tools/general-guidance/gdpr-guidelines-recommendations-best-practices_en.
8.4 You may exercise any of your rights in relation to your personal data by written notice to us, using the contact details set out below.
9. Terms of Use
9.1 This Privacy and cookies policy should be read in conjunction with the Terms of Use and the cookie policy on our website.
10. Personal data of children
10.1 Our services are targeted at businesses and persons over the age of 18.
10.2 If we have reason to believe that we hold personal data of a person under that age in our databases, we will delete that personal data.
11. Our details
11.1 This website is owned and operated by Get Diamonds IVZW
11.2 We are registered in the Belgium as an international non-profit (IVZW) with registration number 0767522594, and our registered office is at Pelikaanstraat 62, 2018 Antwerp, Belgium.
11.3 You can contact us:
(a) by post, at Get Diamonds IVZW, Pelikaanstraat 62, 2018 Antwerp, Belgium;
(b) by phone: +1 (917) 672 6799;
(c) by email: [email protected].