Privacy Policy

Privacy Policy – Lab Jewels

Lab Jewels is the data controller for the processing of your personal data.

Company name: Lab Jewels
Address: P.S. Gerbrandypad 7, Netherlands
Chamber of Commerce (KvK): 93234678
VAT number: 230925613B01
Email (privacy requests): info@lab-jewels.nl

This Privacy Policy is governed by Dutch law and complies with the General Data Protection Regulation (GDPR).

2. What data do we process?

Depending on how you use our webshop, we may process the following categories of personal data:

  • Identification and contact details: first and last name, email address, phone number, shipping and billing address.

  • Order and payment data: ordered products, order history, payment status, and limited payment transaction metadata via our payment service providers.

  • Customer account data (optional): login or account details if you create an account.

  • Communication: content of messages sent to our customer service.

  • Technical and usage data: IP address, device and browser information, session and log data, cookie identifiers, and anonymised or pseudonymised statistics (see Cookie Policy).

Mandatory data: Certain data is required to process your order, such as name, address and payment information. Without this data, we cannot perform the agreement.

 

3. Purposes and legal bases

  • We process personal data for the following purposes and legal grounds:

    • Order processing and delivery (performance of a contract): handling orders, delivery, returns, customer service, warranty and invoicing.

    • Legal obligations (legal obligation): compliance with tax and administrative retention requirements, fraud and abuse prevention where required by law.

    • Website security and business operations (legitimate interest): securing the webshop, error diagnostics, performance measurements and basic statistics that do not unnecessarily infringe your privacy.

    • Marketing communications (consent): newsletters, promotions and personalised advertising via cookies or pixels, only after your consent via the cookie banner or subscription. Consent can be withdrawn at any time.

 

4. With whom do we share data?

We only share personal data when necessary for the purposes described above or to comply with legal obligations.

Categories of recipients include:

  • E-commerce platform and IT service providers: Shopify (hosting and webshop platform) and supporting IT suppliers.

  • Payment service providers: such as Shopify Payments, Mollie or PayPal, depending on the payment methods offered at checkout.

  • Shipping and logistics partners: such as PostNL and Bpost for delivery and return handling.

  • Analytics and advertising tools (with consent): Google Analytics and Meta Pixel.

  • Professional advisers and administration: where applicable, for accounting or audit purposes.

We conclude data processing agreements with our processors. We do not sell your personal data.

 

5. Transfers outside the EU/EEA

Our webshop operates on Shopify, which may result in personal data being stored or processed outside the EU or EEA, including in the United States.

Where applicable, we rely on the EU–U.S. Data Privacy Framework (DPF) or other legally approved transfer mechanisms, such as Standard Contractual Clauses. The current certification status of parties such as Shopify, Google and Meta can be verified in the DPF register of the U.S. Department of Commerce.

 

6. Retention periods

  • Order and invoice data: 7 years, in accordance with Dutch tax legislation.

  • Customer communication: up to 2 years after the last contact, unless a longer retention is required for legal purposes.

  • Marketing data: until consent is withdrawn or, in case of inactivity, no longer than 24 months after the last interaction.

  • Account data: for as long as the account remains active. After termination, data is deleted or anonymised within a reasonable period, unless retention is required by law.

 

7. Cookies and consent

We use cookies and similar technologies. Detailed information about the types of cookies, purposes, retention periods and third parties involved can be found in our Cookie Policy.

For non-essential cookies, such as analytics and advertising cookies, we request your consent via our cookie banner. You can change or withdraw your preferences at any time through the cookie settings on our website, for example via “Cookie settings” in the footer.

 

8. Security

We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access. Payments are processed via specialised payment service providers that comply with recognised security standards. Access to personal data is limited to authorised staff and processors who are bound by confidentiality obligations.

 

9. Your rights

  • You have the right to:

    • Access your personal data

    • Rectify incorrect or incomplete data

    • Request erasure of data, where legally permitted

    • Restrict processing

    • Data portability

    • Object to processing based on legitimate interest and to direct marketing

    • Withdraw consent at any time (without retroactive effect)

    Automated decision-making: We do not make decisions based solely on automated processing that produce legal effects or significantly affect you.

    Requests can be submitted via info@lab-jewels.nl. We will respond within 30 days. If you are not satisfied, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

10. Minors

Our webshop is not intended for individuals under the age of 16. We do not knowingly process personal data of minors. If you believe we have collected such data, please contact us at info@lab-jewels.nl and we will delete it where possible.

 

11. Changes

We may update this Privacy Policy from time to time. The most recent version is always available on our website. In the event of material changes, we will inform you in an appropriate manner, for example via the website or by email.