Privacy Policy of Obsidian Heights
Obsidian Heights ("we," "our," or "us") is committed to protecting the privacy of individuals who visit our online platform and interact with our services. This Privacy Policy outlines how we collect, use, disclose, and protect your personal data in compliance with relevant data protection laws, including the General Data Protection Regulation (GDPR) and the Personal Data Protection Act 2012 (PDPA) of Singapore.
1. Information We Collect
We collect various types of information from and about you, including personal data, as you interact with our online presence and engage with our luxury mineral, bespoke design, and hospitality consulting services.
- Personal Identifiable Information (PII): This includes information you voluntarily provide to us when you inquire about our products or services, request a consultation, make a purchase, or communicate with us. This may include your name, contact details (such as email address, phone number, and mailing address), and any other information you choose to provide in forms or direct communications.
- Financial Information: When you make a purchase or engage in a transaction with us, we may collect billing and payment information. Please note that we do not store full credit card details on our servers; these are processed securely by third-party payment processors.
- Preference Information: Details regarding your interests in specific minerals, stones, design styles, or hospitality projects, which help us tailor our offerings and communications.
- Technical and Usage Data: When you visit our online platform, we automatically collect information about your device and how you interact with our site. This may include your IP address, browser type, operating system, referring URLs, pages viewed, and the dates/times of your visits. This data is primarily collected through cookies and similar tracking technologies.
- Communication Data: Records of your communications with us, including emails, chat transcripts, and phone call recordings (where applicable and with your consent).
2. How We Use Your Information
We use the information we collect to operate, maintain, and provide you with the high-quality services and personalized experiences Obsidian Heights is known for.
- To Provide Services: To fulfill requests for our curated minerals and precious stones, create custom jewelry, deliver interior design consultations, supply architectural stone, and provide advisory services for luxury resort development. This includes order processing, delivery, and customer support.
- To Communicate With You: To respond to inquiries, send service-related notifications, updates on your orders or projects, and provide information about our products and services that may be of interest to you.
- For Personalization: To understand your preferences and tailor our offerings, recommendations, and the content of our online platform to better suit your needs.
- For Business Operations: For internal record keeping, accounting, billing, and order management.
- For Marketing and Promotional Purposes: With your consent, to send you newsletters, promotional materials, or information about new collections, events, or services we believe may be relevant to you. You can opt-out of these communications at any time.
- For Analytics and Improvement: To analyze how our online platform is used, track performance, and identify areas for improvement in our website functionality and service delivery.
- For Legal and Security Purposes: To comply with legal obligations, enforce our terms and conditions, and protect the security and integrity of our online platform and services, as well as the rights, property, or safety of Obsidian Heights, our clients, or others.
3. Legal Basis for Processing (GDPR)
For individuals residing in the European Economic Area (EEA), we process your personal data based on the following legal grounds:
- Consent: Where you have given explicit consent for specific processing purposes (e.g., for marketing communications). You can withdraw your consent at any time.
- Contractual Necessity: Where the processing is necessary for the performance of a contract with you or in order to take steps at your request prior to entering into a contract (e.g., processing your order or consultation request).
- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject (e.g., tax or accounting requirements).
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, and your interests and fundamental rights do not override those interests (e.g., improving our services, preventing fraud, or ensuring the security of our online platform).
4. Sharing and Disclosure of Your Information
We do not sell, trade, or otherwise transfer your personal data to outside parties for their independent marketing purposes without your explicit consent. We may share your information in the following circumstances:
- Service Providers: We may share your data with trusted third-party service providers who assist us in operating our online platform, conducting our business, or serving our clients (e.g., payment processors, shipping companies, IT support, analytics providers, marketing agencies). These parties are obligated to keep your information confidential and use it only for the purposes for which we disclose it to them.
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity.
- Legal Requirements and Protection: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency). We may also disclose your data to protect the rights, property, or safety of Obsidian Heights, our clients, or others.
- With Your Consent: We may share your information with other third parties when we have your explicit consent to do so.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The retention period will vary depending on the type of data and the purpose of its processing. For example, we retain transaction data for a certain period to comply with tax and audit obligations.
When your personal data is no longer required, we will securely delete or anonymize it.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, access controls, secure servers, and regular security assessments. While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. Therefore, we cannot guarantee its absolute security.
7. Your Data Protection Rights
Depending on your location and applicable data protection laws, you may have the following rights regarding your personal data:
- Right to Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): You have the right to request the deletion of your personal data under certain circumstances (e.g., if the data is no longer necessary for the purposes for which it was collected).
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data under certain circumstances.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
- Right to Object: You have the right to object to the processing of your personal data, particularly when processing is based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. For Singapore, this would be the Personal Data Protection Commission (PDPC).
To exercise any of these rights, please contact us using the contact details provided below. We may require specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights).
8. Cookies and Tracking Technologies
Our online platform uses cookies and similar tracking technologies to enhance your browsing experience, analyze site usage, and support our marketing efforts. Cookies are small data files stored on your device. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our online platform may become inaccessible or not function properly.
9. Links to Third-Party Websites
Our online platform may contain links to third-party websites for your convenience or information. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party websites you visit.
10. Children's Privacy
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete that information as quickly as possible.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will post the updated policy on this page, and the "Last Updated" date will reflect the effective date of the changes. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
12. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, or if you wish to exercise your data protection rights, please contact us at:
Obsidian Heights
75 Tras Street, #09-02,
Singapore, Singapore, 079014
Singapore
This Privacy Policy was last updated on 2024-07-30.