Brilliani · Compliance Condo B.V.
Privacy Policy
Version 2.4, July 2026
This privacy policy explains how we handle your personal data across our websites, including our webshop at www.brilliani.com and Brilliani Labs at brillianilabs.com (our real-time diamond simulator and professional tools).
1. Who are we?
Brilliani is the trade name of Compliance Condo B.V., a private limited company established in the Netherlands that sells jewellery through its webshop at www.brilliani.com and operates the Brilliani Labs tools at brillianilabs.com.
We act as the data controller for the personal data we process in the course of our services.
2. What personal data do we process?
We may process the following categories of personal data about you:
2.1 Order data
- First and last name
- Delivery and billing address
- Email address
- Phone number (optional)
- Payment details (processed via our payment service provider; we do not store full card details)
- Order history and order status
- Customisation instructions or engraving text (for made-to-order products)
2.2 Account data
- Login details (email address and encrypted password)
- Address book and preferences
2.3 Communication data
- Messages sent by email or contact form
- Messages you send us on WhatsApp, together with the phone number and display name your WhatsApp account shows us
- Complaints and service requests
2.4 Marketing and analytics data
- Email address (newsletter)
- IP address and cookie IDs
- Click and browsing behaviour on the webshop
- Browser type and device data
2.5 Brilliani Labs account and usage data Brilliani Labs
- Google sign-in data. When you sign in to Brilliani Labs with Google, we receive from Google your name, email address, and your unique Google account identifier. We use these to create and recognise your account.
- Session data. While you are signed in we set a secure, HttpOnly session cookie and keep a matching session record so you stay logged in. Session tokens are stored only in hashed form.
- Usage / activity log. While you are signed in, we record which pages and tools you open, together with the date and time and your approximate location (country, derived from your IP address). We use this to keep the tools secure and to understand how our professional users use them.
- Subscription & payment data. If you take out a paid Brilliani Labs subscription, your payment is processed by Stripe. We receive your subscription status and a Stripe customer/subscription identifier, but never your full card details. Stripe handles card data directly as our payment processor.
3. On what basis and for what purpose do we process your data?
| Purpose | Basis (GDPR Art. 6) | Retention period |
|---|---|---|
| Performance of the purchase agreement (processing orders, shipping, invoicing) | Performance of a contract (1(b)) | 7 years (statutory tax retention) |
| Customer support and handling of complaints | Performance of a contract (1(b)) | 2 years after the matter is closed, unless the correspondence forms part of the record of an agreement or a dispute, in which case the row below applies |
| Keeping business correspondence (email, contact form and WhatsApp) as the record of what was asked and what was agreed, and as evidence if a matter is later disputed | Legitimate interest (1(f)) in being able to establish, exercise or defend a legal claim; legal obligation (1(c)) where the correspondence forms part of our business administration | As a rule 5 years from the end of the matter, matching the Dutch limitation period for contractual claims. 7 years where the message forms part of our accounting records. Longer only for as long as an actual dispute or proceeding is still running |
| Sending marketing emails (newsletter) | Consent (1(a)) | Until consent is withdrawn |
| Fraud and abuse prevention | Legitimate interest (1(f)) | Up to 1 year after detection |
| Web analytics and improving the webshop | Consent (1(a)) | In accordance with the cookie policy |
| Targeted advertising (Meta / Google) | Consent (1(a)) | In accordance with the cookie policy |
| Legal obligations (accounting, taxes) | Legal obligation (1(c)) | 7 years |
| Providing access to Brilliani Labs (account creation, sign-in, keeping you logged in) | Performance of a contract (1(b)) and legitimate interest (1(f)) in offering a secure, access-controlled professional tool | While your account is active; deleted within 12 months of account closure or on request. If you do not sign in for 24 months we treat the account as abandoned and delete it, together with its activity log, automatically. Accounts with a running or lifetime subscription are never deleted for inactivity. Sessions expire after 30 days and are cleared from our database shortly afterwards. |
| Securing Brilliani Labs and understanding how it is used (activity log) | Legitimate interest (1(f)) | Up to 12 months, then deleted or aggregated |
| Processing Brilliani Labs subscription payments (billing, renewals, refunds) via Stripe | Performance of a contract (1(b)); legal obligation (1(c)) for invoicing and tax | 7 years for invoice/tax records; subscription status kept while your account is active |
Legitimate interest: We have a legitimate interest in preventing fraud, abuse and deception, and in keeping our tools secure and improving them. We always weigh this interest against your privacy interests.
For the Brilliani Labs activity log specifically, our interests are: detecting shared or resold accounts (a single membership signed in from many countries at once), diagnosing faults reported by members, and knowing which tools are actually used so we invest in the right ones. We keep the impact proportionate: we do not store your IP address, only the country derived from it; visitors who are not signed in are never logged at all; the data stays in our own database in Europe and is never sold, shared for advertising or used to build a profile; it is deleted after 12 months; and only two named administrators can read it. We have documented this balancing test and will send you a summary on request. You can object at any time under section 7.
For correspondence, including WhatsApp, our interest is the plain one: a message about an order, a quote or a piece of work is the record of that matter, and we need to be able to show what was asked and what was agreed. That protects you as much as us. We keep the impact proportionate by keeping only the correspondence itself, not building any profile from it, and by working to the retention periods in the table above rather than keeping everything indefinitely. This balancing test is documented too, and a summary is available on request.
4. Who do we share your data with?
We share personal data with third parties only where necessary and on the basis of a data processing agreement or another valid legal ground. We never sell your data.
4.1 Processors (processing on our behalf)
| Party | Purpose & location |
|---|---|
| Shopify Inc. | Webshop platform, order and customer management: US (adequacy decision / SCCs) |
| Mailchimp (Intuit Inc.) | Email marketing: US (SCCs) |
| Google LLC | Google Analytics (statistics), Google Workspace (email/storage), and Google Sign-In (authentication for Brilliani Labs): US (SCCs / EU-US Data Privacy Framework) |
| Cloudflare, Inc. Brilliani Labs | Hosting, serverless functions and database (D1) for brillianilabs.com, including account and activity-log storage: US/EU (SCCs) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. Brilliani Labs | Subscription billing and card payment processing for Brilliani Labs, including the pricing table shown on our subscription page after you sign in: EEA/US (SCCs / EU-US Data Privacy Framework) |
| Meta Platforms Ireland | Meta Pixel for ad measurement: EEA/US (SCCs) |
| Payment service provider(s) | Processing of payment transactions: EEA |
| Logistics partner(s) | Delivery of orders: EEA |
WhatsApp Ireland Limited is deliberately not in this table: it does not process on our behalf. See section 4.3.
4.2 Where your data is stored, and transfers outside the EEA
Brilliani Labs account and activity data stays in Europe. Your Brilliani Labs account, your sessions and your activity log are held in Cloudflare's D1 database in the Western Europe region. Read replication is switched off, so there is no copy of that database outside Western Europe.
Some of our other service providers are located in the United States. We safeguard the lawfulness of those transfers by relying on the EU-US Data Privacy Framework where the provider is certified under it (this covers Google LLC, Cloudflare, Inc. and Stripe, Inc.), and otherwise on the European Commission's Standard Contractual Clauses, Module Two (controller to processor), together with the supplementary measures set out in each provider's data processing agreement. We keep a record of which mechanism applies to each provider and review it when a provider's certification changes.
4.3 If you contact us on WhatsApp
WhatsApp is offered as a convenience next to email. If you use it, WhatsApp Ireland Limited (part of Meta) carries and stores the conversation on its own account, as an independent controller under its own terms and privacy policy. It is not acting on our instructions, which is why it does not appear in the table above. The content of the messages is encrypted in transit, but Meta can still see that your number messaged ours and when. We cannot change that, and we cannot delete anything from WhatsApp's systems: what we can delete is our own copy.
Two practical points. Please do not send special-category data (health information, for example) or payment card details over WhatsApp. And if you make a request under section 7 by WhatsApp we will act on it, but we may ask you to confirm it by email from the address on your account, so we can be reasonably sure it is you. If you would rather not use Meta's infrastructure at all, email [email protected] instead: the same people read it.
5. Cookies and similar technologies
We use cookies and similar techniques to make our websites work, to personalise your experience and to understand how our websites are used. A full, per-cookie overview (names, providers, purposes and storage periods) is maintained in our separate Cookie Policy. The table below summarises the categories:
| Category | Examples | Purpose |
|---|---|---|
| Functional (necessary) | Shopify session cookie; Brilliani Labs session cookie (__Host-session) and short-lived sign-in state cookie; Stripe fraud-prevention cookies (__stripe_mid, __stripe_sid) set only when you reach our subscription page or checkout after signing in | Shopping cart, login status, keeping you signed in, secure payment and fraud prevention, and security (incl. cross-site request protection) |
| Analytical | Google Analytics (_ga) on www.brilliani.com and brillianilabs.com | Insight into visitor behaviour; anonymised IP |
| Marketing | Meta Pixel, Google Ads | Measuring advertising effectiveness and retargeting |
On brillianilabs.com, analytics cookies (Google Analytics) are placed only after you give your consent through our cookie banner. Essential cookies (which keep you signed in, protect the sign-in process and enable secure payment through Stripe) are always active, as they are necessary to provide the service. No analytics or marketing cookies are set before you consent.
You can adjust your cookie preferences at any time via the cookie banner, the "Cookie settings" link in the footer of every page, or via your browser settings. Please note that disabling functional cookies may affect how the websites work.
6. Security
We take appropriate technical and organisational measures to protect your personal data against loss, unauthorised access or disclosure. These include:
- Encrypted connections (HTTPS/TLS)
- Access to personal data restricted on a 'need-to-know' basis
- For Brilliani Labs: HttpOnly/Secure session cookies and session tokens stored only in hashed form
- Processors contractually bound to security obligations
- Periodic review of our security measures
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of the breach (GDPR Art. 33). Where the breach is likely to result in a high risk to you, we will also inform you directly and without undue delay (GDPR Art. 34), describing what happened, the likely consequences, and the measures we have taken. We keep an internal register of all data breaches.
7. Your rights as a data subject
Under the General Data Protection Regulation (GDPR) you have the following rights:
| Right | What this means |
|---|---|
| Right of access | You can request which personal data we process about you. |
| Right to rectification | You can have incorrect or incomplete data corrected. |
| Right to erasure | You can request that your data be deleted, unless we have a statutory retention obligation. |
| Right to restriction | You can ask us to temporarily restrict processing. |
| Right to portability | You have the right to receive your data in a common format. |
| Right to object | You can object to processing based on legitimate interest or for direct marketing. |
| Automated decision-making | Brilliani does not make decisions based on fully automated processing that has legal effects for you. |
You can exercise your rights by sending an email to [email protected] from the address your account is registered to. We respond within one month; in complex cases we may extend this by two months, and we will tell you if we do. Exercising any of these rights is free.
For Brilliani Labs specifically: ask us to delete your account and we remove your profile, every session and your entire activity log. Ask us for a copy of your data and we send you a machine-readable file containing your account record and your full activity log. The one thing we cannot delete on request is your invoice and payment history, which Dutch tax law requires us to keep for seven years; we hold nothing else about you after an erasure.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).
8. Newsletter and direct marketing
We send you marketing messages only after your explicit consent. You can unsubscribe at any time via the unsubscribe link in every email or by sending a message to [email protected].
We use Mailchimp (Intuit Inc.) to send newsletters. Mailchimp processes your data as a processor on the basis of a data processing agreement.
9. Minors
Our webshop and the Brilliani Labs tools are not directed at persons under the age of 16. We do not knowingly process personal data of minors. If you suspect that we have inadvertently collected data from a minor, please contact us at [email protected].
10. Changes to this privacy policy
We may amend this privacy policy from time to time, for example as a result of changes to our services or to laws and regulations. Version 2.0 added the processing carried out by Brilliani Labs (brillianilabs.com); version 2.1 added Stripe as our payment processor for Brilliani Labs subscriptions, including the pricing table on our subscription page; version 2.2 adds a concrete data-breach notification timeline (section 6) and moves the detailed cookie overview to a separate Cookie Policy; version 2.3 states where Brilliani Labs data is physically stored and which transfer mechanism applies to each provider (section 4.2), adds a 24-month inactivity rule for dormant accounts (section 3), sets out the specific legitimate interests behind the activity log and the safeguards around it (section 3), and explains how to obtain a copy of your data (section 7); version 2.4 adds WhatsApp as a contact channel, states how long we keep business correspondence and why (sections 2.3 and 3), and explains that WhatsApp Ireland Limited acts as an independent controller for anything you send us there (section 4.3). The current version is always available on our website, and the date of the most recent version is stated at the top of this document. In the event of significant changes, we will inform you by email.
11. Contact and data protection officer
Do you have questions or comments about this privacy policy or the processing of your personal data? Please contact us:
Brilliani has not appointed a data protection officer (DPO) at this time, as this is not legally required for our processing activities. For privacy questions, please use the contact details above.