This Privacy Notice for Gemsware ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at gemsware.org or any website of ours that links to this Privacy Notice
- Engage with us in other related ways, including any marketing or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at privacy@gemsware.org.
SUMMARY OF KEY POINTS
This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more about personal information you disclose to us.
Do we process any sensitive personal information? Some of the information may be considered "special" or "sensitive" in certain jurisdictions, for example your racial or ethnic origins, sexual orientation, and religious beliefs. We do not process sensitive personal information.
Do we collect any information from third parties? We do not collect any information from third parties.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties. Learn more about when and with whom we share your personal information.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.
How do you exercise your rights? The easiest way to exercise your rights is by emailing us at privacy@gemsware.org, or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.
Want to learn more about what we do with any information we collect? Review the Privacy Notice in full.
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Sensitive Information. We do not process sensitive information.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies. You can find out more about this in our Cookie Notice.
The information we collect includes:
- Log and Usage Data: Service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, settings and activity in the Services (such as timestamps, pages and files viewed, searches, and feature usage), device event information (such as system activity, error reports / crash dumps, and hardware settings).
- Device Data: Information about your computer, phone, tablet, or other device used to access the Services. This may include IP address (or proxy server), application IDs, location, browser type, hardware model, ISP/mobile carrier, operating system, and system configuration.
- Location Data: Information about your device's location, which can be either precise or imprecise (e.g., via GPS or IP address). You can opt out of allowing us to collect this information by disabling Location settings on your device, though certain features may become unavailable.
Google API
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with the law. We may also process your information for other purposes with your consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- To deliver and facilitate our Services: We process technical and usage data to display content, manage site features, and ensure uptime.
- To analyze site performance: We process analytics data to measure website usage, understand reader interest in our content, and improve user experience.
- To ensure security and prevent fraud: We process log and device data (such as IP addresses) to monitor for malicious activity, protect our servers, and troubleshoot technical errors.
- To deliver targeted advertising: With your consent, we process cookie identifiers and interaction data to serve relevant advertisements via Google AdSense.
- To save or protect vital interests: We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.
If you are located in the EU or UK, this section applies to you:
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information:
- Consent (Art. 6(1)(a) GDPR): We process your information when you have given us explicit permission for a specific purpose (such as non-essential tracking cookies or personalized ads via Google AdSense). You can withdraw your consent at any time.
- Performance of a Contract (Art. 6(1)(b) GDPR): We process your information where necessary to deliver our Services to you or fulfill our contractual obligations.
- Legitimate Interests (Art. 6(1)(f) GDPR): We process your information when we have a legitimate interest that does not override your fundamental rights, such as maintaining cybersecurity, preventing fraud, and performing basic aggregate web analytics.
- Legal Obligations (Art. 6(1)(c) GDPR): We may process your information where necessary to comply with a legal obligation, such as cooperating with regulatory bodies or defending against legal claims.
- Vital Interests (Art. 6(1)(d) GDPR): We may process your information where necessary to protect your vital interests or the vital interests of a third party.
If you are located in Canada, this section applies to you:
We may process your information if you have given us specific permission (express consent) or in situations where your permission can be inferred (implied consent). You can withdraw your consent at any time.
In exceptional cases, applicable laws allow processing without consent, such as:
- If collection is clearly in the interest of an individual and consent cannot be obtained in a timely way
- For investigations, fraud detection, and prevention
- For business transactions meeting certain legal conditions
- If contained in a witness statement necessary to assess/settle an insurance claim
- For identifying injured, ill, or deceased persons and communicating with next of kin
- If there are reasonable grounds to believe an individual is a victim of financial abuse
- For investigating a breach of an agreement or violation of law
- To comply with a subpoena, warrant, court order, or court rules
- If produced in the course of employment, business, or profession and consistent with the original purpose
- If solely for journalistic, artistic, or literary purposes
- If publicly available as specified by regulations
- De-identified information for approved research or statistical projects subject to ethics oversight
5. DO WE TRANSFER YOUR INFORMATION INTERNATIONALLY?
In Short: We may transfer, store, and process your information in countries other than your own, including the United States.
Our servers and third-party service providers (such as Google LLC for analytics and advertising) operate globally. As a result, your personal information may be transferred to and processed in countries outside the European Economic Area (EEA) and the United Kingdom.
When we transfer personal data outside the EEA or UK, we ensure an adequate level of data protection by implementing approved safeguards, including:
- Relying on European Commission Adequacy Decisions (including the EU-U.S. Data Privacy Framework for certified entities).
- Executing standard contractual clauses approved by the European Commission (Standard Contractual Clauses - SCCs) or the UK International Data Transfer Addendum (IDTA).
6. WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES?
In Short: We are not responsible for the safety of any information that you share with third parties that we may link to or who advertise on our Services, but are not affiliated with, our Services.
The Services may link to third-party websites, online services, or mobile applications and/or contain advertisements from third parties. We do not make any guarantee regarding such third parties and will not be liable for any loss or damage caused by using them. We cannot guarantee data safety and privacy on third-party sites; please review their respective privacy policies directly.
8. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 13 in the US/UK, under 15 in France, or under 16 across the EU.
We do not knowingly solicit data from or market to children under 13 years of age (US/UK), under 15 years of age (France), or under 16 years of age in other European Union member states. By using the Services, you represent that you meet the age of digital consent in your jurisdiction or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services.
If we learn that personal information from users under the applicable legal age has been collected without verifiable parental consent, we will promptly delete such data from our records. If you become aware of any data collected from minors, please contact us at privacy@gemsware.org.
9. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.
We retain personal information only as long as necessary for the purposes set out here, or to meet tax, accounting, and legal requirements. When we have no ongoing legitimate business need, we will delete or anonymize your data, or securely isolate it in backup archives until deletion is possible.
10. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: Depending on your jurisdiction (such as the EEA, UK, Switzerland, and Canada or certain US states), you have rights allowing greater access to and control over your personal information.
These rights may include:
- The right to request access and obtain a copy of your personal information
- The right to request rectification or erasure
- The right to restrict the processing of your personal information
- Data portability (where applicable)
- The right not to be subject to automated decision-making producing legal effects
- The right to object to processing
Complaints and Supervisory Authorities
If you are unhappy with how we handled your personal data, we encourage you to contact us first at privacy@gemsware.org.
In France (CNIL): You have the right to lodge a complaint with the French Data Protection Authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), online at cnil.fr or by post to: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07.
In the United Kingdom (ICO): If you are in the UK, you can contact the Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Other EEA & Switzerland: Other European Economic Area residents may contact their local Member State data protection authority. Swiss residents may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent
If we rely on consent to process your data, you can withdraw it at any time by contacting us at privacy@gemsware.org. This will not affect the lawfulness of processing conducted prior to withdrawal.
11. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems include a Do-Not-Track (DNT) setting. Because no uniform standard for recognizing DNT signals has been finalized, we do not currently respond to DNT browser signals.
Global Privacy Control (GPC): We recognize and honor GPC signals. If your browser sends a GPC signal, we treat this as a valid opt-out request for targeted advertising under applicable laws like the CCPA. Learn more at globalprivacycontrol.org.
12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: Residents of states such as California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia have specific rights regarding personal data.
Categories of Personal Information We Collect
The table below summarizes the categories of personal information collected over the past 12 months:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | IP address, unique device identifiers, cookie IDs, and contact details if provided voluntarily | YES |
| B. California Customer Records personal info | Name, contact details, financial information | NO |
| C. Protected classification characteristics | Gender, age, race, national origin, marital status | NO |
| D. Commercial information | Transaction history, purchase details | NO |
| E. Biometric information | Fingerprints, voiceprints | NO |
| F. Internet or network activity | Browsing history, search history, interaction with the site, features, and ads | YES |
| G. Geolocation data | Device location derived from IP address (country, city-level) | YES |
| H. Audio, electronic, visual information | Photos, audio recordings, video recordings | NO |
| I. Professional / Employment information | Business contact details, job titles, work history | NO |
| J. Education Information | Student records and directory information | NO |
| K. Inferences drawn from collected info | Profiles reflecting individual preferences or behavior | NO |
| L. Sensitive personal information | Government IDs, precise GPS geolocation, racial/ethnic origin | NO |
Sale or Sharing of Personal Information: We do not sell personal information for monetary compensation. However, we allow third-party advertising partners (such as Google AdSense) to collect identifiers and internet activity via cookies to deliver targeted advertising. Under California privacy law (CCPA/CPRA), this constitutes "sharing" personal data. You can opt out of targeted advertising and cookie-based sharing at any time using our cookie consent banner or by adjusting your browser settings.
Your US State Privacy Rights
- Right to know whether we process your data
- Right to access your personal data
- Right to correct inaccuracies
- Right to request deletion
- Right to obtain a copy of your personal data
- Right to non-discrimination for exercising privacy rights
- Right to opt out of targeted advertising, sale of data, or significant automated profiling
How to Exercise Your Rights
Contact us by email at privacy@gemsware.org. We will verify your identity using existing data or minimal additional verification data. Authorized agents must provide signed permission.
Appeals: If we decline action on your request, you may appeal by emailing us at privacy@gemsware.org. If denied, you can submit a complaint to your state attorney general.
California "Shine The Light" Law
Under California Civil Code Section 1798.83, California residents may request once per year details about personal information disclosed to third parties for direct marketing purposes. Send requests to privacy@gemsware.org.
13. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
Australia and New Zealand
We collect and process personal info under Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020. You may submit complaints to the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner.
Republic of South Africa
You may request access or correction under POPIA/PAIA. Complaints can be directed to The Information Regulator (South Africa):
- Website: inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- Complaints: PAIAComplaints@inforegulator.org.za & POPIAComplaints@inforegulator.org.za
14. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
The revised date at the top indicates when modifications take effect. We encourage periodic review of this document.
15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions, feedback, or wish to exercise your privacy rights, you can email us at:
GemswareEmail: privacy@gemsware.org
16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
To review, update, or delete your personal information, please submit a request to: privacy@gemsware.org.