Data Controllers
Depending on which entity holds the relationship with you, the controller of your personal data is:
- SOSNA GEMS INVESTMENTS INC. — registered head office 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States (Florida Profit Corporation, Doc. No. P24000009844, FEI/EIN 32-0763482) — for U.S., LATAM and APAC-facing relationships.
- Sosna Gems Investments a.s. — Školská 689/20, Nové Město, 110 00 Prague 1, Czech Republic (IČO 090 85 840, Municipal Court in Prague, Section B, File 25252) — for EU, UK, Switzerland, GCC and EMEA-facing relationships.
Where both entities are jointly involved (for example a cross-Atlantic transaction), they act as joint controllers with a written arrangement allocating GDPR responsibilities. You may exercise your rights against either entity.
Privacy contact: exchange@sosnagems.com · postal contact addresses are listed on our Imprint.
Personal Data We Process
- Identification and contact: name, salutation, email, phone, postal or shipping address, country of residence, preferred language and currency.
- Inquiry and sourcing content: stone type, budget bracket, deadlines, brief text, references and any documents you attach.
- Transactional and KYC data: identity document number and issuing authority (for qualifying purchases), source-of-funds statements, beneficial ownership, invoice and shipping records.
- Technical data: IP address, device and browser type, referring URL, pages viewed, timestamps, cookie identifiers — collected only to the extent set out in our Cookie Policy.
- Correspondence: emails, meeting notes and voice-call summaries linked to your file.
We do not knowingly collect personal data from children. We do not process special-category data (health, race, religion, biometric) except where you voluntarily provide it in a bespoke brief (for example ring size or wearability considerations); in that case we process it on the basis of your explicit consent and only to fulfil the commission.
Lawful Bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)): to prepare quotations, execute sales, deliver stones and jewelry, and provide bespoke or sourcing services.
- Legal obligation (Art. 6(1)(c)): to comply with AML, KYC, tax, customs, sanctions, Kimberley Process and CITES requirements.
- Legitimate interests (Art. 6(1)(f)): to secure our website, prevent fraud, maintain client records and communicate about relevant offers to existing clients.
- Consent (Art. 6(1)(a)): for optional cookies, direct marketing to non-clients, and any use of special-category data described above.
How We Use Personal Data
- Respond to inquiries and sourcing briefs; prepare and negotiate offers.
- Execute holds, reservations, invoicing, payment collection and shipment.
- Meet legal and regulatory duties (AML/KYC, tax, customs, export controls, sanctions screening).
- Maintain a secure, functional website and diagnose incidents.
- Send editorial updates, plate releases and event invitations to existing clients (opt-out available in every message).
International Transfers
Because the house operates jointly from the United States and the Czech Republic, personal data may be transferred between these jurisdictions. Transfers of personal data of EU/UK residents to the United States and other third countries are protected by the European Commission's Standard Contractual Clauses (2021/914/EU) supplemented, where relevant, by additional technical and organizational safeguards. A copy of the relevant transfer mechanism is available on request.
Retention
- Inquiry and sourcing correspondence: up to 24 months from last contact, unless a transaction proceeds.
- Client and transaction records: for the statutory retention period applicable in the contracting entity's jurisdiction — typically 10 years for AML and tax purposes.
- KYC identity data: for 5 years after the end of the business relationship (or longer where required).
- Marketing consent records: until consent is withdrawn plus the statutory limitation period.
- Technical logs and cookies: as set out in the Cookie Policy.
Your Rights (EU/UK GDPR)
- Access, rectification, erasure, restriction and portability of your personal data.
- Objection to processing based on legitimate interests, including profiling.
- Withdrawal of consent at any time, without affecting the lawfulness of prior processing.
- Complaint to a supervisory authority — for EU residents, typically the Czech Office for Personal Data Protection (ÚOOÚ, uoou.gov.cz) or your local authority.
California Rights (CCPA / CPRA)
California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to opt out of any sale or sharing of personal information, to limit use of sensitive personal information, and to non-discrimination for exercising these rights. SOSNA Diamonds does not sell personal information as defined by the CCPA/CPRA and does not use personal information for cross-context behavioral advertising. Verified requests may be submitted to exchange@sosnagems.com.
Security
We maintain administrative, technical and physical safeguards designed to protect personal data — including encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, audit logging and secure vaulting of KYC materials. No system is perfectly secure; we notify affected individuals and authorities as required by law in the event of a personal-data breach.
Updates
We may update this notice to reflect changes to our services or legal obligations. The effective date at the top of this page marks the latest revision. Material changes will be communicated to active clients.
