This Policy does not impose any limits on the collection, use or disclosure of information concerning corporate or commercial entities, certain publicly available information or information that cannot be associated with a specific individual.
What information do we collect from you?
We will collect and process the following data about you:
- Information that you provide by filling in forms on one or more of our sites (collectively, the “site”). This includes information provided at the time of registering to use our site, subscribing to our service, posting material or requesting further services including, for example, name, home and/or business address, email address, telephone number, demographic information such as age and/or other information that may identify you as an individual, username and password if you create an account on our site and such other information as may be necessary for the purposes identified in this Policy. We may also ask you for information when you enter a competition or promotion sponsored by us, sign-up for e-mail newsletters and when you report a problem with our site.
- If you contact us, we may keep a record of that correspondence and/or collect your name and contact information (depending on the nature of your query).
- We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.
- Details of (if applicable) transactions and appointment bookings you carry out through our site and of the fulfilment of your orders.
- Any other data you may provide to us in connection with our services and/or our site, including but not limited to:
- information you provide when you compile wishlists or other gift registries;
- information you provide when you use interactive areas of our site;
- information you provide when using the Account features, including the Preference Centre, Newsletter subscriptions and Register My Diamond features;
- email addresses of your friends and other that you give us in relation to a service (in which case we will assume that you have obtained permission from the applicable individual); and
- pictures, videos and messages which you submit to us either via our social media sites (including by use of hashtags associated with us) or our site.
- Information collected from your use of our website or other digital services:
- Details of your visits to our site and information generated in the course of the use our site (including the timing, frequency and pattern of service use) including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own billing purposes or otherwise as set out in this Policy, and the resources that you access;
- We will collect information about how you interact with our adverts and newsletters, including whether you open or click links in any correspondence. If you do not interact with our communications for a period of time we will use this information to assess whether to continue to send you communications;
- We may collect information about the device you use to access our website or digital services, including where available your IP address, operating system and browser type, for system administration and to report aggregate information to our advertisers. This is statistical data about our users’ browsing actions and patterns. We use this information for internal system administration, to help diagnose problems with our server, and to administer our site. Such information may also be used to gather broad demographic information, such as country of origin and internet service provider. Any or all of activities with regard to our site usage information may be performed on our behalf by our service providers (see the Service Providers section below).
We may also use personal data we obtain from social media (for example, Facebook, Instagram, Twitter, YouTube and WeChat to display on our site, our social media pages and for our (and our businesses’) research and analytics purposes. This is usually personal data that you submit to us (e.g. on our site or our social media pages) or you bring to our attention using hashtags or tagging relating to us, our business, our industry and our interests.
Why do we collect this information?
We process your personal information for the following reasons:
- To fulfil our promise to you where we agree to provide you with our products and services in order to:
- process information at your request to take steps to enter into a contract for sale or for services;
- provide you with our products and services,
- process payments;
- make deliveries;
- maintain business and service continuity;
- send service communications so that you receive a full and functional service and so we can perform our obligations to you. These may be sent by email or post or, if the circumstances require it, we may contact you by phone. These will include notifications about changes to our service; and
- record information to facilitate your rights under guarantee.
- On the basis of your consent:
- Where we rely on your consent for processing this will be brought to your attention when the information is collected from you or be a result of a request by you, such as you choosing to share your wishlists or gift registry;
- To display your messages/captions, photos and/or videos (which may include ‘likes’, comments or other reactions to such messages/captions, photos and/or videos) on our site
- We will contact you with direct marketing communications if you consent to us doing so and you have the right to withdraw consent at any time.
- To provide you with the best service and improve and grow our business (our legitimate interests) we will process information in order to:
- provide you with a personalised service;
- respond to any queries and complaints that you may have;
- improve our products and services;
- keep our site and systems safe and secure;
- understand our customer base and purchasing trends;
- tailor advertising to you;
- create custom audiences on social media sites based on your information and engagement with us so we can target our advertising to similar audiences;
- defend against or exercise legal claims and investigate complaints; and
- understand the effectiveness of our marketing.
We will also carry out analytics to improve our products and services as set out above.
- To comply with legal requirements relating to:
- the provision of products and services;
- data protection;
- health and safety;
- anti-money laundering;
- fraud investigations;
- assisting law enforcement; and
- any other legal obligations placed on us from time to time.
How long do we keep hold of your information?
- We will keep information about you for a minimum of one year after using such information and for a maximum of 6 years after the end of our relationship with you unless obligations to our regulators require otherwise or we are required remove such data from our records.
- We will surely destroy, erase or make anonymous documents or other records containing personal information as soon as it is reasonable to assume that the original purpose is no longer being served by retention of the information and retention is no longer necessary for legal or business purposes.
- We will take due care when destroying personal information so as to prevent unauthorized access to such information.
Who might we share your information with?
For the purposes set out in the ‘Why do we collect this information?’ section above, we will share your personal information with:
- the following categories of third parties, some of whom we appoint to provide services, including:
- business partners, subsidiaries, suppliers and sub-contractors for the performance of any contract we enter into with you.
- analytics and search engine providers that assist us in the improvement and optimisation of our site.
- Customer survey providers in order to receive feedback and improve our services.
- any member of our group of companies.
- marketing agencies, media agencies and analytics providers in the form of aggregate statistics regarding user behaviour as a measure of interest in, and use of, our site and marketing e-mails in the form of aggregate data, such as overall patterns or demographic reports. These third parties will not be able to relate this data to identifiable individuals.
Additionally, we will disclose your personal information to the relevant third party:
- In the event that we sell or buy any business or assets, in which case we will disclose your personal data to the prospective seller or buyer of such business or assets.
- If we are acquired by a third party, in which case personal data held by us about our customers will be one of the transferred assets.
How is your data stored and kept secure?
At Excelsior Bijoux Company Limited, we take your safety and security very seriously and we are committed to protecting your personal information. All information kept by us is stored on our secure servers. Where we have given you (or where you have chosen) a password that enables you to access certain parts of our service, you are responsible for keeping this password confidential. We ask you not to share a password with anyone and we recommend that you change your password every three months.
While we have implemented reasonable technical and organisational precautions to protect the security and integrity of personal data provided to our site, due to the inherent nature of the internet as an open global communications vehicle, we cannot guarantee that information, during transmission through the internet or while stored on our system or otherwise in our care, will be absolutely safe from intrusion by others, such as hackers. We do however maintain physical, electronic and procedural safeguards to protect your personal information.
We may transfer and store your data outside your country. We will only do so if adequate protection measures are in place in compliance with data protection legislation. Your personal information may also be processed by staff operating outside your country who work for us or for one of our service providers for the purposes outlined in this Policy. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services. While your personal information is located outside your country, it will be subject to the laws of the jurisdiction in which it is retained, including laws that may require disclosure of personal information to foreign government authorities.
What are your rights?
Where processing of your personal data is based on consent, you can withdraw that consent at any time, provided reasonable written notice of withdrawal of consent is given by you to us. Upon receipt of your written notice, we will inform you of the likely consequences of the withdrawal, which may include the inability of us to provide (or to continue providing) certain products or services for which the delivery and use of that information is required.
You have the following rights. You can exercise these rights at any time by contacting us at email@example.com or Excelsior Bijoux Company Limited, 2823/3, My office, Charoenkrung Road, Bangkorlaem, Bangkorlaem, Bangkok 10120. Thailand
You have the right:
- to ask us not to process your personal data for marketing purposes. We will inform you (before collecting your data) if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes;
- to ask us not to process your personal data for scientific or historical research purposes, where relevant, unless the processing is necessary in the public interest.
- to request from us access to personal information held about you;
- to ask for the information we hold about you to be rectified if it is inaccurate or incomplete;
- to ask for data to be erased provided that the personal data is no longer necessary for the purposes for which it was collected, you withdraw consent (if the legal basis for processing is consent), you exercise your right to object, set out below, and there are no overriding legitimate ground for processing, the data is unlawfully processed, the data needs to be erased to comply with a legal obligation or the data is children’s data and was collected in relation to an offer of information society services;
- to ask for the processing of that information to be restricted if the accuracy of that data is contested, the processing is unlawful, the personal data is no longer necessary for the purposes for which it was collected or you exercise your right to object (pending verification of whether there are legitimate grounds for processing);
Should you have any issues, concerns or problems in relation to your data, or wish to notify us of data which is inaccurate, please let us know by contacting us using the contact details above.
Access to your information
Upon request and authentication of identity, we will provide you with personal information under our control, information about the ways in which that information is being used and a description of the individuals and organizations to whom such information has been disclosed.
We will make personal information available within 30 days or provide written notice where additional time is required to fulfill the request.
In some situations, we may not be able to provide access to certain personal information. We may also be prevented by law from providing access to certain personal information.
Where an access request is refused in whole or in part, we will notify you in writing, giving the reason for refusal.
Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies or content contained on those sites. Please check these policies before you submit any personal data to these websites.