LIMITED TIME OFFER: 20% OFF SITEWIDE
Last updated:
DiamondsByMe takes the protection of personal information seriously. This notice explains what we use when you visit our UK website, use our services or visit our premises, why we use it, who receives it, how long we keep it and your rights.
DiamondsByMe B.V. is the controller of personal information processed through www.diamondsbyme.co.uk.
DiamondsByMe B.V.
Dienstenstraat 25
3161 GN Rhoon
The Netherlands
Dutch Chamber of Commerce: 24376433
Email: [email protected]
Telephone: +31 10 747 0000
This notice is for customers and visitors in England, Scotland and Wales. Northern Ireland is served through a separate domain.
Depending on how you use our website and services, we may process:
We do not request more information than reasonably necessary. Without required information, we may be unable to fulfil an order, payment, delivery or service request.
We use personal information only where we have a lawful basis:
CCTV protects staff, visitors, jewellery, goods and premises and helps prevent or investigate incidents. We rely on legitimate interests, use signs at the premises and restrict access.
We use information to record and make the configured jewellery, communicate about the order, process payment and arrange delivery.
Payments may be handled by Adyen, Pay.nl, Klarna or PayPal. Delivery details may be shared with carriers including DHL and FedEx.
Payment partners may independently conduct payment, fraud, credit or risk checks under their own notices and terms.
When you contact us, we use contact information, messages, order details and submitted photographs to deal with the request.
Freshdesk/Freshchat and Minimal AI may support chat, information retrieval, drafting and conversation summaries. Important decisions on orders, complaints, warranty or fraud are not made solely by AI where meaningful human review is needed.
Where solely automated processing produces a legal or similarly significant effect, we apply the safeguards and rights required by UK data protection law.
We send newsletters and marketing emails where you have subscribed or where another rule under the Privacy and Electronic Communications Regulations 2003 lawfully permits it. Every marketing email offers an easy opt-out.
We may retain a minimal suppression record to respect an opt-out.
Messages necessary for an order, payment, delivery, return, warranty, repair, security or requested service are service communications rather than newsletters.
CookieHub manages preferences. Essential storage and access technologies support the website and services.
Under PECR, some limited technologies may be used without consent where a statutory exception applies, including where strictly necessary and, subject to legal conditions and a simple means of objecting where required, certain functionality, security or statistical purposes.
Personalisation, remarketing and most advertising technologies are used only after valid consent where required. Refusing non-essential technologies must be as easy as accepting them, and you can change or withdraw preferences at any time through cookie settings.
The CookieHub notice provides the current technical list of technologies, providers, purposes and durations.
With consent where required, services may include Google, Meta, Microsoft, TikTok and Pinterest for analytics, measurement, personalisation and remarketing.
We disclose information only as needed for the purposes above, with consent, or where legally required. Recipients may include:
Each recipient receives only what is necessary. We do not sell personal information.
After a purchase, we may provide name, email address and order number to Trustpilot to send a review invitation. Trustpilot acts under its own responsibility when you create an account or publish a review.
We work with NDBM Thailand Co., Ltd. and our own craftspeople in Thailand. Necessary order and product information may be accessed there for manufacture, engraving, planning, quality control, repair and service.
Access is limited. Payment information, marketing preferences, browsing behaviour and unrelated customer information are not made available for production.
We use contractual, organisational and technical safeguards.
DiamondsByMe is established in the Netherlands, so information collected from UK customers is transferred to and processed in the European Economic Area.
Where the UK has made adequacy regulations for a destination, we may rely on them.
For restricted transfers without adequacy, we use an appropriate safeguard such as the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another lawful mechanism, together with a transfer risk assessment and supplementary measures where required.
Service providers may also use systems or subprocessors outside the UK and EEA. You may contact us for information about the relevant safeguard.
We keep information only as long as needed for its purpose, legal obligations, disputes and legitimate business needs. Broadly:
We use appropriate technical and organisational measures, including access controls, secure connections, supplier agreements, logging, back-ups and periodic reviews.
No system is risk-free. We investigate incidents and comply with applicable notification and communication duties, including reporting qualifying personal data breaches to the Information Commissioner’s Office within the required period.
Depending on the circumstances and lawful basis, you may have rights of access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time without affecting earlier lawful processing.
The right to object to direct marketing is absolute. You may also object to processing based on legitimate interests, in which case we assess whether compelling legitimate grounds or legal claims justify continued processing.
Send requests to [email protected]. We may request proportionate information to verify identity.
We normally respond within one month, calculated in accordance with UK law. A lawful extension may apply for complex or multiple requests, and we will explain it.
You may complain about how we use personal information by emailing [email protected]. You may use another clear contact method; a specific form is not compulsory.
We acknowledge a data protection complaint within 30 days. Without undue delay, we make appropriate enquiries, keep you informed where necessary and tell you the outcome.
You may also complain to the Information Commissioner’s Office:
Information Commissioner’s Office
www.ico.org.uk
Telephone: 0303 123 1113
Your right to complain to the ICO is not affected by first contacting us.
We may update this notice when our services, systems or the law change. The latest version is published on www.diamondsbyme.co.uk. We provide additional notice of significant changes where reasonably appropriate.