This privacy policy explains how we handle your personal data on digitalgemology.com, where we sell 3D files and cutting files and will offer courses. It is written to be read, so the short version comes first.
We collect what we need to sell you a file and let you download it, and to run a course you have enrolled in. We do not sell your data, we do not use it for advertising, and we do not track you across other websites. We never see your card details.
1. Who we are
Digital Gemology is a trading name of Compliance Condo B.V., a private limited company established in the Netherlands, which also trades as Brilliani and Brilliani Labs.
We act as the data controller for the personal data we process through this site. Our other sites, brilliani.com and brillianilabs.com, have their own privacy policies for the processing that happens there.
2. What personal data we process
2.1 Order data
- Name and email address, so we can send your files, your receipt and your invoice.
- Billing address or country, and for business customers the company name and VAT number.
- Evidence of your country of residence, as EU VAT law requires for digital sales: normally your billing country together with a second, independent indicator such as the country of the bank that issued your card.
- Order history, the files you bought, and the licence attached to each.
- Payment status. Card details are handled by our payment provider; we never receive them.
2.2 Download and account data
- The email address or account through which you reach your downloads.
- A record of when each file was downloaded. We keep this to deliver what you paid for, to help if a download fails, and to recognise a download link that is being shared.
2.3 Course data (when courses open)
- Your enrolment, your progress through the lessons and the results of any exercises.
- Anything you choose to submit to us, such as questions or work for feedback.
2.4 Communication data
- Messages you send us by email, including requests to be told when the store or a course opens.
- Complaints and support requests.
2.5 Technical data
- Our hosting provider processes your IP address and basic request data to deliver pages and to protect the site against attack. We do not use it to identify you.
- Your choice of black or white page theme, stored on your own device (see the Cookie Policy).
We do not currently run analytics or advertising trackers on digitalgemology.com.
3. Why we process it, on what basis, and for how long
| Purpose | Basis (GDPR Art. 6) | Retention period |
|---|---|---|
| Selling you a file or a course: processing the order, delivering the files, invoicing | Performance of a contract (1(b)) | 7 years for invoice and tax records |
| Keeping your downloads available and knowing which licence you hold | Performance of a contract (1(b)) | For as long as we offer re-downloads of your purchase, and the licence record for as long as the licence runs |
| Proving the VAT we charged was correct (country evidence) | Legal obligation (1(c)) | 10 years, as EU rules on digital sales under the One Stop Shop require |
| Running a course you enrolled in, including your progress | Performance of a contract (1(b)) | While your access runs, then deleted within 12 months, unless you ask us to keep a record of completion |
| Answering questions and handling complaints | Performance of a contract (1(b)) or legitimate interest (1(f)) in answering people who write to us | 2 years after the matter is closed, or 5 years where the message is the record of an agreement or a dispute |
| Telling you when the store or a course opens, if you asked us to | Consent (1(a)) | Until the launch message is sent or you withdraw consent, whichever is first |
| Preventing fraud and the sharing of paid files | Legitimate interest (1(f)) | Up to 1 year after detection |
| Keeping the site secure and available | Legitimate interest (1(f)) | Handled by our hosting provider, briefly; we keep no logs of our own that identify visitors |
| Accounting and tax | Legal obligation (1(c)) | 7 years |
Legitimate interest: where we rely on it, our interests are protecting the files we sell from being passed around, keeping the site secure, and being able to show what was asked and agreed. We keep the impact proportionate: we keep no more than those purposes need, we build no profile from it, and we delete it on the schedule above. You can object at any time under section 7.
4. Who we share your data with
We share personal data only where it is necessary, and only with parties bound by a data processing agreement or another valid legal ground. We never sell your data.
| Party | What they do for us, and where |
|---|---|
| Cloudflare, Inc. | Hosting of the site and delivery of downloads, with protection against attack: EU/US (EU-US Data Privacy Framework / SCCs) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Checkout and card payment processing, including the country evidence needed for VAT: EEA/US (EU-US Data Privacy Framework / SCCs) |
| Google LLC | Google Workspace, which carries our email: US (EU-US Data Privacy Framework / SCCs) |
Where a provider is in the United States, we rely on the EU-US Data Privacy Framework where it is certified under it, and otherwise on the European Commission's Standard Contractual Clauses, together with the supplementary measures in its data processing agreement. We keep a record of which mechanism applies to each provider and review it when a certification changes.
We may also have to share data with the tax authorities or with other public bodies where the law requires it.
5. Cookies and similar technologies
We keep this to the minimum. The full, per-item overview is in our Cookie Policy. In short: our hosting provider sets a bot-protection cookie, your theme choice is kept on your own device, and checkout sets the payment provider's fraud-prevention cookies when you pay. There are no analytics or advertising cookies. If we ever add analytics, it will load only after you consent, and this policy and the Cookie Policy will be updated before it does.
6. Security
We take appropriate technical and organisational measures to protect your personal data against loss, unauthorised access or disclosure, including encrypted connections (TLS), access restricted to the people who need it, and processors contractually bound to security obligations. The detail is in our cyber security notice.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of it (GDPR Art. 33). Where the breach is likely to result in a high risk to you, we will also tell you directly and without undue delay (GDPR Art. 34), describing what happened, the likely consequences and what we have done about it. We keep an internal register of all data breaches.
7. Your rights
Under the General Data Protection Regulation you have the following rights:
| Right | What this means |
|---|---|
| Access | You can ask which personal data we process about you, and for a copy. |
| Rectification | You can have incorrect or incomplete data corrected. |
| Erasure | You can ask us to delete your data, unless the law requires us to keep it. |
| Restriction | You can ask us to restrict processing for a time. |
| Portability | You can receive your data in a common, machine-readable format. |
| Objection | You can object to processing based on legitimate interest. |
| Withdrawing consent | Where we rely on consent, you can withdraw it at any time, as easily as you gave it. |
| Automated decisions | We make no decisions about you based solely on automated processing. |
To exercise any of these rights, email [email protected] from the address you bought with, so we can be reasonably sure it is you. We respond within one month; in complex cases we may extend this by two months, and we will tell you if we do. It is free.
What erasure means for a purchase. If you ask us to delete your data, we delete your download records, course progress and correspondence. We have to keep your invoices for seven years and the VAT country evidence for ten, because the law requires it. Your licence to use files you already downloaded is not affected, but we will no longer be able to offer you re-downloads.
You also have the right to lodge a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl, or with the supervisory authority in your own country.
8. Marketing
We send marketing email only if you have asked for it, and every message has a way to stop further ones. Asking us to tell you when the store or a course opens is a request for exactly that one message, not a newsletter subscription.
9. Minors
Our files and courses are not directed at people under 16, and we do not knowingly process their data. If you think we have collected data from a minor by mistake, tell us at [email protected] and we will delete it.
10. Changes to this policy
We will update this policy when our services, our providers or the law change, and in particular before we open accounts, courses or any new kind of processing. The version and date are at the top of the page. Where a change is significant and we hold your email address, we will tell you by email.
Version 1.0 is the first edition for digitalgemology.com. It is adapted from the privacy policy of Brilliani Labs and follows the same practice.
11. Contact
We have not appointed a data protection officer, as the law does not require one for our processing. Privacy questions go to the address above and are answered by a person.