Who we are
This Privacy Policy describes how VaVeria GmbH (“GEMIUS”, “we”, “us”, or “our”), a limited liability company (GmbH) based in Zurich, Switzerland, with registered office at Universitätstrasse 65, 8006 Zurich, processes personal data of visitors to gemius-stones.com, users of the application at app.gemius-stones.com, and Enterprise customers integrating our pricing data via API.
GEMIUS acts as data controller for the personal data described in this policy. For all matters relating to the processing of your personal data, including exercising your rights under the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR), please contact us at privacy@gemius-stones.com (see Section 13).
What data we collect
We collect personal data that you provide directly, that is generated by your use of the Service, and that is technically required to deliver the Service. We do not collect special categories of personal data (Article 9 GDPR / Article 5(c) FADP), biometric data, or precise location data.
- Account dataEmail address, hashed password, optional first name, tier level, profession (optional), country (optional), and account creation timestamp.
- Sign-in data received from GoogleIf you choose “Sign in with Google”, Google sends us your name, your email address and its verified status, your Google profile picture, and a Google account identifier that lets us recognise you on your next sign-in. Google releases this only after you approve it on Google’s own screen, and Google does not let you exclude any of it while still using that sign-in method. We use it to create and identify your account, nothing else. Signing up with an email address and password instead avoids this entirely.
- Usage dataSearch queries (gem species and attribute selections), saved searches, price-alert subscriptions, share-link metadata for shareable valuations.
- Technical dataIP address (for rate-limiting and security), user agent, approximate timestamp, referring page, and the language of your browser. We do not maintain permanent IP logs. When you sign in we also keep a session record, so that you can review your own active sessions and sign any of them out. That record holds the device and browser, the approximate city and country, and the IP address the session signed in from. Section 7 states how long we keep it.
- Cookies & localStorageStrictly necessary cookies (authentication, CSRF, session) and preference data (theme, chosen display currency, and a dismissed-hint flag). The preference data is stored only if you accept the Preferences category. Our analytics are cookieless and store nothing on your device (see Section 9).
- Enterprise / API dataFor Enterprise customers using our REST API: API key identifier, request metadata (endpoint, timestamp, response code), and aggregated usage counters for billing and rate-limiting. We do not log request payloads beyond what is technically necessary.
- Billing data (when activated)If you subscribe to a paid tier, our payment processor (currently Stripe) collects payment-method information. We do not store credit card numbers or banking details on our systems. The processor acts as the merchant of record and a separate data controller for that data.
- Preference dataOptional profile preferences you set, interface locale, timezone, and avatar image, kept to personalise your experience. You can change or remove these at any time in your account settings.
- Newsletter subscriptionIf you subscribe to our newsletter, we keep your email address and your consent status so we can send the updates you asked for. You can unsubscribe at any time via the link in every newsletter or by contacting us.
- Subscription & billing metadataFor paid tiers we keep the status of your subscription, the billing interval (monthly or yearly), and the current period-end date in order to operate your plan. Payment-card details are handled solely by our payment processor (above) and are never stored on our systems.
- Certificate uploads (Professional & Premier)If you upload a lab report to pre-fill a valuation, we store the file you upload and the gemstone attributes read from it. A lab report describes a stone, not a person.
Why we collect it (legal basis)
We process your personal data on the following legal bases under GDPR Article 6 and FADP Articles 30 & 31:
- ContractArt. 6(1)(b) GDPRAccount creation, subscription management, delivery of pricing services, and Enterprise/API access, necessary for the performance of our agreement with you.
- Legitimate interestArt. 6(1)(f) GDPRService security (rate-limiting, fraud prevention), product improvement (aggregate usage statistics), and the protection of our intellectual property in the underlying gemstone pricing dataset. We also improve our certificate-reading from the lab reports our users upload, and confirm an uploaded report against the issuing laboratory to help detect fraud. We have conducted a balancing test for each legitimate-interest processing activity.
- ConsentArt. 6(1)(a) GDPRAny future marketing communications (none today), and the newsletter if you subscribe. Our cookieless analytics do not rely on consent. They run under our legitimate interest (Art. 6(1)(f)) because they store nothing on your device and identify no one (see Section 9).
- Legal obligationArt. 6(1)(c) GDPRRetention of billing records for tax and accounting purposes under Swiss Code of Obligations Art. 958f (10 years).
How we use it
We use your personal data exclusively for the following purposes:
- Service deliveryAuthenticating your access, processing pricing queries, computing variance bands and attribute breakdowns, storing your saved searches and price alerts, generating shareable valuation links (all tiers), and routing Enterprise API calls. When you upload a lab report, we also read it to pre-fill your valuation.
- Service securityDetecting and preventing abuse: rate limiting, IP-based anomaly detection, blocking automated scraping or bulk extraction of our pricing dataset.
- Product improvementAggregate, non-identifying usage analysis to improve the accuracy of our pricing model and the usability of the Service. Individual user behavior is never the basis of any automated decision affecting you.
- CommunicationService-related notices (account, billing, security incidents) and, only with your explicit opt-in, product updates or newsletters.
- Statutory obligationsTax and accounting recordkeeping, responses to lawful requests from authorities under Swiss law.
We do not sell personal data. We do not share personal data with advertisers, data brokers, or any third party for their independent marketing purposes.
Recipients of your personal data
We do not sell or rent your personal data. We share it only with the following categories of recipients, all of whom act as data processors under our written instructions and under data-processing agreements compliant with GDPR Art. 28 and FADP Art. 9:
- Hostinger International LtdHosting · EU (servers in Germany)Operates the EU-based servers in Germany (Frankfurt region) that host the application, the relational database, and encrypted backups. Data-processing agreement: hostinger.com/legal/dpa.
- Cloudflare, Inc.CDN · United States (SCCs)Operates the globally distributed edge network that routes, caches, and protects traffic to and from our service. Routing edges may be located outside the EU/EEA. Only transit metadata traverses them. Substantive personal data remains stored on EU servers. Data-processing agreement: cloudflare.com/cloudflare-customer-dpa.
- ResendTransactional email · United States (SCCs)Delivers account and security emails (verification, password reset, billing receipts, security notices). Active only when email features are enabled. Data-processing agreement: resend.com/legal/dpa.
- Functional Software, Inc. (d/b/a Sentry)Error tracking · United States (EU-region hosting, SCCs)Captures application error and crash reports to help us detect and fix faults. Hosted in Sentry’s EU region (Frankfurt, Germany). Configured to exclude personal data: no user-identifying payloads, and client IP addresses are not stored. Data-processing agreement: sentry.io/legal/dpa.
- Umami Software, Inc.Product analytics · EU-hostedCookieless, EU-hosted product analytics measuring aggregate site usage: no cookies, no cross-site tracking, no advertising profiles, IP addresses hashed and not retained. Because it stores nothing on your device it runs for all visitors without consent (outside ePrivacy Art. 5(3)) and honours your browser’s Do-Not-Track / GPC signal. Data-processing agreement: umami.is/dpa.
- Google (Gemini)Certificate reading · under Google’s DPAReads uploaded lab reports to extract their gemstone attributes. Google does not use the uploads to train its own models. Data-processing agreement: cloud.google.com/terms/data-processing-addendum.
- Stripe Payments Europe, Ltd. / Stripe, Inc.Payments · Ireland (EU) / United States (SCCs)Handles payment-method information for paid subscriptions. Stripe acts as the merchant of record and as a separate data controller for payment-card data. We do not store credit card numbers or banking details on our systems. Data-processing agreement: stripe.com/legal/dpa.
- Professional advisorsAuditors, lawyers, and accountants engaged on a confidentiality basis when required for the operation of our business.
Data residency. All personal data we process as controller is stored on servers located in Switzerland and/or the European Economic Area (Germany). Edge caching and email/CDN transit may briefly route metadata through other jurisdictions. Substantive personal data is not stored outside Switzerland or the EEA without a transfer mechanism approved under FADP Art. 16 / GDPR Chapter V (Standard Contractual Clauses or an adequacy decision).
Current sub-processor list. The named entities listed above constitute our current sub-processors as of the effective date of this policy. We will notify users by email at least 15 days before adding a new sub-processor with access to personal data, giving you the opportunity to object on reasonable data-protection grounds. For the most up-to-date list at any time, contact privacy@gemius-stones.com.
International data transfers
Your personal data is stored at rest on servers located in Switzerland and/or the European Economic Area (Germany, Frankfurt region). Edge caching and request transit may briefly route metadata through points of presence in other jurisdictions to deliver the service to you efficiently, substantive personal data is not stored outside Switzerland or the EEA at rest.
For any transfers that fall outside the EU/EEA and Switzerland, we rely on the following safeguards:
- SCC Module 2Standard Contractual Clauses (Module 2: controller to processor) under Commission Implementing Decision (EU) 2021/914.
- Adequacy decisionsWhere applicable, we rely on European Commission adequacy decisions and the Swiss Annex 1 list of countries with adequate data protection.
- Transfer impact assessmentFor each transfer mechanism, we have assessed the legal regime of the destination country and the technical measures (encryption in transit and at rest) protecting the data.
Retention periods
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law:
- Account dataFor the lifetime of your account. After account deletion, an anonymized record is retained in our deletion log for audit purposes (no personal identifiers).
- Search activity90 days from the date of the search. New searches do not reset retention of prior searches.
- Saved searches & alertsUser-controlled: retained until you delete them, or for the lifetime of your account.
- Price alerts (notification log)12 months from the alert event.
- Billing records10 years per Swiss Code of Obligations Art. 958f.
- Active-session records180 days from the last time the session was seen. Each sign-in creates a record so that you can review your active sessions and sign any of them out, and it holds the device and browser, the approximate city and country, and the IP address the session signed in from. Signing a session out deletes its record immediately, and deleting your account deletes all of them.
- Free-trial eligibility record24 months from the day a free trial is granted. When you sign up we store a scrambled fingerprint of your email inbox, so that one inbox receives the free fourteen day trial once. It holds no email address and no account number, and it cannot be read back as your address. It never prevents you from creating an account. It only means a second free trial is not granted. This record is kept if you delete your account, and is removed automatically after 24 months.
- Server logs & security dataUp to 30 days, except where a security incident requires longer retention for investigation. This covers request and delivery logs. It does not cover the active-session records above, which are listed separately because they are kept longer.
- Uploaded certificatesYour certificate upload history and the files you upload are kept while your account is open, and deleted when you delete your account.
- Free-trial eligibility record24 months. When an account receives its free trial we store a one-way keyed fingerprint of the email address, and nothing else. It contains no address, no name and no link to your account, and it cannot be reversed to identify you. We keep it after an account is deleted, because otherwise deleting an account and signing up again would give an unlimited run of free trials. It is checked once, when a new account is created, and used for nothing else. It never blocks a sign-up. If the same inbox signs up again, that account simply starts on the free tier instead of the trial.
Your rights
You have the following rights regarding your personal data under GDPR Articles 15–22 and the corresponding provisions of the Swiss FADP. To exercise any of these rights, contact us at privacy@gemius-stones.com. We respond within 30 days (FADP statutory response window).
- AccessArt. 15 GDPR · Art. 25 FADPConfirm whether we process your personal data and obtain a copy.
- RectificationArt. 16 GDPR · Art. 32 FADPCorrect inaccurate or incomplete personal data.
- ErasureArt. 17 GDPRRequest deletion, subject to statutory retention obligations (e.g. billing records).
- RestrictionArt. 18 GDPRSuspend processing while a dispute about accuracy or legitimacy is resolved.
- PortabilityArt. 20 GDPRReceive your account data in a structured, machine-readable format (JSON export).
- ObjectionArt. 21 GDPRObject to processing based on legitimate interest.
- Withdraw consentWhere processing is based on consent (marketing), you may withdraw at any time without affecting prior processing. Our cookieless analytics do not rely on consent, so there is nothing to withdraw there (see Section 9).
- Lodge a complaintYou may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you reside in the EU/EEA, with the supervisory authority of your country of residence.
Security measures
We protect your personal data using a combination of technical and organizational measures appropriate to the risk:
- Encryption in transitTLS 1.3 for all browser-to-server traffic, with HTTPS enforced.
- Encryption at restAES-256 disk-level encryption on the database VPS.
- Access controlsRow-level security on user data tables, least-privilege administrator access, SSH key-only VPS access, multi-factor authentication on administrator accounts.
- Password storagePasswords are hashed using a modern adaptive hashing algorithm (bcrypt-class). We never store, log, or have access to plaintext passwords.
- BackupsDaily encrypted snapshots, off-site copies, documented restore procedure.
- Incident responseIn the event of a personal-data breach likely to result in risk to you, we notify you and the supervisory authority within 72 hours as required by GDPR Art. 33.
Automated decision-making
We do not use your personal data to make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects (Article 22 GDPR, Article 21 FADP).
Our pricing model is a statistical algorithm applied to gemstone attributes you provide. The resulting price band is informational and does not constitute an automated decision about you, your account, or your eligibility for any service. Your tier, billing, and account status are governed by the choices you make and the payments processed, not by automated profiling.
If we ever introduce automated decision-making that materially affects users, for example, automated risk scoring for Enterprise onboarding, we will update this section, notify you per Section 12, and provide the rights described in Article 22 GDPR (the right to obtain human intervention, to express your point of view, and to contest the decision).
Changes to this policy
We may update this Privacy Policy from time to time. Material changes, those that affect your rights or expand the categories of data we collect, will be communicated by email and via an in-app banner at least 30 days before they take effect.
Each revision of this policy is dated. The effective date and the date it was last reviewed are visible at the top of this page. Earlier versions remain available on request.
Contact & Data Protection Officer
For any privacy-related question, request, or complaint, contact us at privacy@gemius-stones.com or by post to our registered office (see Section 1).
We have not appointed a Data Protection Officer under Article 37 GDPR. Our processing scale and the categories of data we handle do not meet the criteria that make an appointment mandatory. Privacy enquiries are handled at the address above.
Supervisory authorities
- SwitzerlandFederal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
+41 58 462 43 95. - EU / EEAThe supervisory authority of your country of habitual residence.