Privacy
notice.

How Rutheniai s.r.o., the company behind the GemsLabé brand, processes personal data collected through gemsla.be and in the course of its gemological services — what is collected, why, on what legal basis, for how long, and what you can do about it.

Version 1.1 · Effective from 5 September 2026

Who processes your data

Rutheniai s.r.o. is the controller of the personal data described on this page. It decides why and how that data is processed, and it is the party you contact about it.

Controller

Company
Rutheniai s.r.o., trading under the GemsLabé brand at gemsla.be
Registered office
Karpatské námestie 7770/10A, 831 06 Bratislava – Rača, Slovak Republic
IČO
57 211 604
Commercial register
Municipal Court Bratislava III, Section Sro, Insert No. 191615/B
Contact e-mail
olena.rybnikova@gemsla.be

The company is not required to appoint a data protection officer and has not appointed one. Write to the address above with any question about this notice or any request concerning your data; enquiries are handled personally by Olena Rybnikova.

Processing is governed by Regulation (EU) 2016/679 (GDPR) and by Act No. 18/2018 Coll. on the protection of personal data.

What we process, why, and on what legal basis

Three sets of processing operations happen here. Each one is set out with the data involved, the purpose it serves, the legal basis under Article 6(1) GDPR, and how long the data is kept.

Site accounts and sign-in

Data
Name and e-mail address, an irreversible hash of your password, the role assigned to the account, and technical sign-in records — session and CSRF cookies, timestamps and IP address.
Purpose
Creating and operating your account, authenticating you, keeping the parts of the site that require sign-in secure, and preventing abuse.
Legal basis
Article 6(1)(b) GDPR — performance of the contract for the use of the account you asked for. For the security records, Article 6(1)(f) — our legitimate interest in protecting the site against unauthorised access.
Cookies
The sessionid and csrftoken cookies are strictly necessary for signing in. No advertising or profiling cookies are set; the optional analytics cookies described below are set only if you accept them.
Retention
For as long as the account exists. On deletion of the account the data is erased; technical security records are kept for up to 12 months.

Contact enquiries

Data
The name, e-mail address, selected service and message you submit through the contact form on gemsla.be, together with any later correspondence about that enquiry.
Purpose
Reading and answering your enquiry, preparing a quotation, and agreeing the examination of an item.
Legal basis
Article 6(1)(b) GDPR — steps taken at your request before entering into a contract. Where an enquiry leads to no contract, Article 6(1)(f) — our legitimate interest in answering people who write to us and in keeping a record of what was answered.
Retention
Up to three years from the last message in the exchange, then erased. If the enquiry turns into an order, the correspondence follows the retention of the contract.

B2B contract contacts, signatories and training participants

Data
Name, job title, business e-mail address and telephone number of the client company's contact persons; the name, function and signature of the person signing the framework agreement; the name of a training participant and, where a confirmation of attendance is issued, the record of its completion.
Purpose
Concluding and performing the framework agreement and the orders placed under it, communicating about orders and handovers of items, issuing certificates, and organising and documenting training.
Legal basis
Article 6(1)(f) GDPR — the legitimate interest of both companies in performing the contract concluded between them, in which the individuals concerned act as representatives rather than as parties. For the signed agreement, invoices and accounting records, Article 6(1)(c) — compliance with a legal obligation.
Our status
In relation to these people we act as an independent controller, not as a processor for the client company, as stated in Article 11.2 of our General Terms and Conditions.
Retention
For the term of the agreement, and afterwards for ten years from the end of the accounting period to which the document relates, as required by Act No. 431/2002 Coll. on accounting. Training attendance records are kept for five years.

Analytics, and the choice you are given

Visits to the public pages of gemsla.be are measured with Google Analytics 4 — but only if you accept, and only from the moment you accept.

Until you answer the banner, no Google tag is loaded and no request goes to Google. Reject and nothing is loaded, now or later; the answer is remembered so that you are not asked again. Accept and the tag is loaded and measurement begins on the page you are on — nothing you did before accepting is sent afterwards.

Site analytics

Data
The address and title of the public page you are viewing and of the page you came from, the standard campaign parameters of a link that brought you here, and what Google derives from the request itself — approximate location no finer than city level, language, device, browser and operating system. Google assigns a random identifier to your browser. When you search the store or the blog, the words you searched for, how many stones or articles matched, whether a filter or a tag was active, and which stone or article you then opened from the results.
Purpose
Counting visits and seeing which stones, certificates and articles are read, and which searches find something and which find nothing, so that the catalogue and the writing follow what people actually look for.
Legal basis
Article 6(1)(a) GDPR — your consent; and for the storing and reading of the cookies themselves, § 109(8) of Act No. 452/2021 Coll. on electronic communications.
Cookies
The _ga and _ga_<stream> cookies, set only once you accept. Rejecting sets none, and withdrawing deletes the ones already set.
What is never sent
Filter and pagination state, report and invoice identifiers, contact form values, account identifiers, and signed links to stored files. Query strings are stripped from the page address, the page title and the referring address before anything leaves your browser, save for the standard campaign parameters named above — so the address of a page of search results is never sent, and a search reaches Google only as the separate measurement described below.
Recipient
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as processor, with onward transfer to Google LLC in the United States covered by the EU–US Data Privacy Framework and by standard contractual clauses.
Retention
Event data is kept in the analytics property for no more than 14 months and is then deleted automatically.

A search is counted once — when you have stopped typing and its results are in front of you, or straight away if you open one of them before that, so that what you opened is never reported without the search that led to it — rather than once per keystroke. Turning a page, re-sorting the results or switching how they are laid out counts nothing further, and a search that returns nothing is counted too, because that is the part worth knowing about. The words are stripped of spacing and capitalisation and shortened to 64 characters, and a term that reads like an e-mail address or a telephone number is withheld altogether and reported only as redacted. Sanitising free text cannot promise to catch every personal detail somebody might type into a search box, so please do not type into it anything you would not want measured.

The advertising and profiling features of Google Analytics are switched off: no Google signals, no ad personalisation, and no advertising cookies. The measurement is not used to identify you and is not joined to your account or to your enquiries.

You can change your answer at any time through the “Analytics preferences” control in the footer of every page. Withdrawing stops the tag already running on the page you are on — not merely from the next page onwards — deletes the analytics cookies, and is remembered for later visits. Withdrawal does not affect the lawfulness of the measurement carried out before it.

Browsing by our own staff while signed in is not measured, and the administration, sign-in, report and invoice pages are left out of measurement altogether.

How long data is kept

Personal data is erased once the purpose it was collected for has fallen away and no statutory retention period still applies to it. The period for each processing operation is stated above; where several apply to the same document, the longest one governs.

These statutory periods override any shorter period: ten years for accounting records under Act No. 431/2002 Coll. on accounting, and the limitation periods under the Commercial Code for claims arising from the agreement.

Who else sees the data

Personal data is never sold, and it is not passed to anyone for their own marketing. It is disclosed only to:

  • Service providers that run the site and the systems behind it — hosting and cloud infrastructure, file storage, and e-mail delivery. They act as processors under Article 28 GDPR, on written instructions, and may not use the data for their own purposes.
  • Google, for the site analytics described above, and only where you have accepted it.
  • Our accountant, and our legal advisers where a claim has to be pursued or defended.
  • Public authorities, where disclosure is required by law.

Where a provider processes data outside the European Economic Area, the transfer is covered by an adequacy decision of the European Commission or by standard contractual clauses under Chapter V GDPR.

No automated decision-making or profiling within the meaning of Article 22 GDPR takes place.

Providing the data is voluntary, but without it we cannot open an account for you, answer an enquiry, or conclude and perform the agreement.

Your rights

Under Articles 15 to 22 GDPR you have the following rights in relation to the data we hold about you.

Access
To be told whether we process data about you and, if so, to receive a copy of it together with the information set out on this page.
Rectification
To have inaccurate data corrected and incomplete data completed.
Erasure
To have data deleted where it is no longer needed, where you successfully object to the processing, or where it has been processed unlawfully — save for periods we are legally required to keep it for.
Restriction of processing
To have processing limited to mere storage while an objection, or a dispute about the accuracy of the data, is being resolved.
Data portability
To receive the data you provided in a structured, commonly used and machine-readable format, and to have it transmitted to another controller, where the processing is based on a contract and carried out by automated means.
Objection
To object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest — the account security records and the contract-contact data described above. We then stop unless we demonstrate compelling legitimate grounds that override your interests.
Withdrawal of consent
Where processing is ever based on your consent, to withdraw it at any time, without affecting the lawfulness of the processing carried out before the withdrawal.

Write to olena.rybnikova@gemsla.be to exercise any of these rights. We answer within one month of receiving the request; for complex requests that period may be extended by a further two months, in which case we tell you within the first month. Exercising a right is free of charge — a manifestly unfounded or excessive request may attract a reasonable fee or be refused.

Complaint to the supervisory authority

If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the Slovak supervisory authority. You can do so whether or not you have raised the matter with us first, though we would rather hear from you and put it right.

Supervisory authority

Authority
Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic)
Address
Hraničná 12, 820 07 Bratislava 27, Slovak Republic
E-mail
statny.dozor@pdp.gov.sk
Website
dataprotection.gov.sk

You may also seek a remedy before the competent court.

Changes to this notice

This notice is version 1.1 and is effective from 5 September 2026. If the processing described here changes, an updated version is published at this address with a new effective date. Material changes affecting people who hold a site account are also notified by e-mail.