Who is responsible
Paterson Jewellery Co., Ltd, Gemopolis Industrial Zone, Bangkok, Thailand, company registration 010556211327, decides why and how the personal data described here is used. In the language of these laws we are the data controller.
Privacy questions and requests do not go to a general inbox. Use the request page, which tells you what we need in order to answer and how long we take.
We are not required to appoint a data protection officer: our core business is manufacturing jewellery, not monitoring people, and we hold no special-category data. Where the law requires a representative inside the United Kingdom or the European Union, that appointment is in progress. Not live yet.
Which laws this answers to
We are a Thai company selling to jewellers abroad, so more than one set of rules applies at once. Naming them matters, because your rights come from them rather than from our goodwill.
Thailand’s Personal Data Protection Act applies to everything we do, because we are established here.
The EU General Data Protection Regulation, and the UK version of it, apply because we offer goods to businesses in the European Economic Area and the United Kingdom. That is true even though our customers are companies: these records name real people — whoever applies, whoever signs in, whoever places the order.
Canada’s anti-spam law, CASL, governs any commercial email we send into Canada.
California’s CCPA does not apply to us, on our reading: it catches businesses above roughly $26.6 million in annual revenue, or handling the data of 100,000 or more Californians a year, or making half their money selling personal information. We are none of those. We say so plainly rather than publishing a compliance apparatus we are not bound by — but see below for what Californian customers get anyway.
Reading the site
You can read every public page without telling us anything. Our host keeps standard server logs — IP address, browser, page requested, time — as every web server does, and we use them to deliver and secure the site.
We count visitors with Vercel Web Analytics and Speed Insights: how many people arrive, which pages they read, roughly which country they are in, and how quickly pages load. Neither stores anything on your device, neither uses a cookie, and neither identifies you.
We also use Google Analytics, which does set a cookie. It loads only if you agree. Until you choose, and if you decline, the Google tag is never fetched. Google advertising storage stays switched off even for visitors who allow analytics, so we run no remarketing and no advertising cookies. You can change your answer from the link in the footer.
Sending an enquiry
The enquiry form collects a company name, a contact name, an email address, what you need made, and any file you attach. We use it to answer you and, if it turns into work, to quote for it.
Applying for a trade account
The application collects what every certified member of the Responsible Jewellery Council must gather before trading: company name and registration number, addresses, business activity, the names of beneficial owners, shareholders and directors, a contact person with their position, telephone and email, a signed declaration, and supporting documents such as a registration certificate.
Some of that is personal data about named individuals rather than about a company, and we treat it that way.
Holding a trade account
Once an account is open we hold what running it requires: who is entitled to sign in, the price list that applies to that account and country, purchase orders and the quotations, proforma invoices and invoices that follow them, approvals you give on a CAD version, the allocations you hold on a Howlet run, and the production stage each of your jobs has reached.
The production stages come from the job card our own factory system scans. They describe your order, not you. Not live yet.
Cookies
Two kinds, and only two.
Necessary. When trade accounts open, signing in will set a session cookie so the site knows you are still signed in as you move between pages. It does nothing else and the site cannot offer a signed-in area without it, so it is not something we ask permission for. Not live yet.
Analytics. Google Analytics, described above, and only with your agreement. Your answer is remembered in your browser’s own storage rather than in a cookie, so declining leaves nothing behind but the record of the decline.
No advertising cookies. No tracking pixels. No third-party fonts — ours are served from this domain.
Why we are allowed to hold it
Different reasons for different things, not one reason for everything. The law calls these lawful bases, and we have to name the right one for each purpose rather than claim a single blanket permission.
Company and contact details, and everything involved in quoting, ordering and invoicing: to take steps you have asked for before entering a contract, and then to perform it. (GDPR Article 6(1)(b).)
Beneficial owners, shareholders and directors, and the sourcing declaration: because certification and anti-money-laundering checks require them. A legal obligation, and our legitimate interest in trading lawfully and keeping our certification. (Article 6(1)(c) and 6(1)(f).)
Invoices and the records behind them: a legal obligation, because Thai tax and accounting law requires us to keep them. (Article 6(1)(c).)
Server logs and cookieless visitor counts: our legitimate interest in delivering the site and knowing whether it works. (Article 6(1)(f).) You can object to this, and we tell you how below.
Google Analytics and marketing email: your consent, and nothing else. (Article 6(1)(a); PDPA section 19.) Consent can be withdrawn as easily as it was given, and withdrawing it does not affect anything we did while it stood.
Marketing is separate, and it is yours to stop
The marketing checkbox on the application is separate from the declaration and is never a condition of opening an account. If you tick it we record the date, the time, the IP address it came from and the exact wording you were shown, because that record is what makes your consent evidenced rather than asserted.
Withdraw it any time, by replying to any message or writing to us. Withdrawing marketing consent costs you nothing else — we will still send the confirmations, quotations and invoices your account needs, because those are part of the contract rather than marketing.
Who else sees it
Suppliers who process data on our instructions and may not use it for their own purposes: Vercel, which hosts the site and provides the cookieless visitor counts; Supabase, which will hold accounts and order records Not live yet.; Klaviyo, for account and order email Not live yet.; FlowAccount, our Thai accounting system, for invoicing Not live yet.; and Woodpecker, if we wrote to you before you applied.
Google, only if you allowed analytics.
Auditors of the Responsible Jewellery Council may inspect account records, including the ownership information, as part of the certification cycle we are audited against. That is the reason the information is collected in the first place.
Otherwise, only where the law requires it. We do not sell personal data and we never will.
Where it goes
We are in Thailand. Our trade-desk database runs in Singapore — moved there from the United States on 3 September 2026, deliberately, to keep your records in the same region as the factory and shorten the chain they travel. The site itself is served from a global network, and page requests are logged in the United States.
Out of the United Kingdom and the European Economic Area, we rely on the Standard Contractual Clauses approved by the European Commission, which each of our suppliers builds into its own data processing terms.
Out of Thailand, neither Singapore nor the United States is a country the Personal Data Protection Committee has recognised as adequate, so both run on the suitable protection measures route in section 29 of the PDPA — our suppliers’ terms, recorded by us as the safeguard we rely on, and written so that you keep your rights and a remedy wherever the data sits. Singapore is the shorter chain of the two, which is why the database is there.
Our own factory system stays inside our network in Bangkok and sends production stages out; nothing reaches into it from the internet.
How long we keep it
A period for each thing, decided in advance rather than when you ask.
Enquiries that never become accounts: two years from our last exchange.
An application we decline: two years, then deleted.
An application we approve, and the account it becomes: the life of the account, then seven years.
Orders and the invoices behind them: seven years.
Consent records: while the consent stands, and three years after it is withdrawn — that record is the proof it existed and that you ended it.
Server logs: the short period our host keeps them. We hold no copy.
Google Analytics: fourteen months. Not live yet.
The seven-year figures are not us being reluctant. Thai tax and accounting law requires the commercial record, and the application file is the evidence of the due diligence a certified member is audited against. We cannot delete those on request before the period runs — but if you ask, we will tell you exactly which record is being kept, under which rule, and until when, and delete everything that falls outside it.
If our arrangement with Howlet changes
This site is operated by Paterson Jewellery and the accounts on it are ours. Howlet product reaches these pages through a read-only connection to Howlet’s own store, and no trade account data travels the other way. If that partnership changed, your account, your orders and your records would stay with Paterson Jewellery and would not transfer with it.
What you can ask for
These are rights the law gives you, not favours we grant. You may ask for:
Access — a copy of what we hold about you, and an explanation of why.
Rectification — correction of anything wrong or incomplete.
Erasure — deletion, subject to the records we are required to keep.
Restriction — that we hold it but stop using it, while something is in dispute.
Objection — to any use resting on our legitimate interests, including the server logs and visitor counts.
Portability — the data you gave us, in a form you can take elsewhere.
Withdrawal of consent — for analytics or marketing, at any time.
Not to be subject to automated decisions. We make none. No account is approved or refused by a machine; a person reads every application.
Use the request page. We answer within thirty days. Asking costs nothing, and we will not treat you any differently for having asked.
If we get it wrong, complain — to the Personal Data Protection Committee in Thailand; to your own national supervisory authority anywhere in the European Economic Area; to the Information Commissioner’s Office in the United Kingdom; or, if we emailed you in Canada, to the CRTC under CASL. You do not have to come to us first.
If something goes wrong
If personal data of yours is lost, exposed or reached by someone who should not have reached it, we have seventy-two hours from realising it to tell the regulator, and we tell you directly as well where the risk to you is real — your documents, your commercial terms, or anything that could be reused against you elsewhere.
We would rather tell you early with an incomplete picture than wait until we have a tidy account of it. The procedure is written down and agreed in advance, so that nobody is deciding what to do on the day.
If you are in California
As set out above, we do not meet the thresholds that make California’s privacy law apply to us, so we are not going to publish a set of promises under a statute that does not bind us.
What we will tell you is the thing the law exists to establish: we do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no opt-out link because there is nothing to opt out of.
Every right listed above is open to you on the same terms as everyone else, through the same page, answered in the same thirty days.
Changes
If we change this policy we change the date below. Where a change materially affects an open trade account we tell the account holder directly rather than relying on you to notice.