Legal
Privacy Notice
Last updated: May 2025
GemsRoute ("Platform") is a diamond traceability service. This notice explains which personal data we collect, why we collect it, how long we retain it, and your rights under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Data Controller
The data controller for personal data processed through the Platform is the operating entity of GemsRoute. Authorised dealers who register stones and push events via the API act as independent data controllers for the data they submit and are solely responsible for compliance with KVKK in that capacity.
2. Data We Collect
We collect the following categories of data: (a) Account data — display name, e-mail address, phone number, authentication provider identifiers; (b) Verification data — certificate numbers and gemological attributes (shape, carat weight, colour, clarity) submitted during a verification search; (c) Ownership claim data — claim type, supporting description, and submission metadata; (d) Incident report data — incident type, description, and associated stone reference; (e) Usage data — IP address, browser, locale, and page interaction logs for security and analytics.
3. Publicly Visible Data
Stone detail pages may display gemological attributes (shape, carat weight, colour, clarity, certificate number) and dealer-provided event titles that are explicitly marked PUBLIC. No name, contact detail, or other personal identifier is displayed on public pages. The "Ownership Verified" badge indicates that an ownership record exists but does not reveal the identity of the owner.
4. Legal Basis for Processing
We process personal data on the following legal bases: (a) Performance of a contract — to provide account access, process ownership claims, and manage incident reports; (b) Legitimate interests — to maintain platform security, prevent fraud, and improve service quality; (c) Legal obligation — to comply with applicable laws and respond to lawful requests from authorities; (d) Consent — for optional communications such as product updates, which may be withdrawn at any time.
5. Retention
Account data is retained for the duration of the account and deleted within 30 days of a verified deletion request. Verification search logs are retained for 90 days. Ownership claim and incident report records are retained for 5 years to satisfy legal traceability obligations. Anonymised aggregate analytics data may be retained indefinitely.
6. Your Rights
Under KVKK Article 11, you have the right to: learn whether your personal data is being processed; request information about the processing; learn the purpose of processing and whether data is used in accordance with that purpose; know the third parties to whom data is transferred; request rectification of incomplete or inaccurate data; request erasure or destruction of data where processing conditions no longer apply; object to outcomes arising solely from automated processing; and claim compensation for damages caused by unlawful processing. To exercise these rights, contact us at the address below.
7. International Transfers
Personal data may be transferred to cloud infrastructure providers located outside Turkey. Such transfers are carried out in accordance with KVKK Article 9 and, where applicable, under standard contractual clauses or equivalent safeguards.
8. Contact
For questions about this notice or to exercise your rights, please write to: [email protected]. We will respond within 30 days.