Privacy Policy
Effective Date: September 2026 | Last Updated: September 10, 2026
1. Our Commitment to Your Privacy
At Mihilak Gems ("we", "us", or "our"), client discretion and data security are foundational principles. As purveyors of rare, unheated Ceylon gemstones and bespoke fine jewelry, we understand that our private collectors require the utmost confidentiality regarding their acquisitions, inquiries, and personal details.
This Privacy Policy explains what information we collect when you visit our website (https://www.mihilakgems.com), submit concierge inquiries, schedule private showroom appointments, or acquire gemstones from our vault.
2. Information We Collect
We may collect information directly provided by you, including:
- Contact Information: Full name, email address, WhatsApp/telephone number, and country of residence when submitting inquiries or booking consultations.
- Acquisition Preferences: Target gemstone varieties (e.g., Ceylon Royal Blue Sapphire, Padparadscha), carat weight preferences, color saturation requirements, and bespoke design briefs.
- Transaction & Invoicing Details: Shipping address, customs clearance details, and payment verification references. We do not store full credit card or raw banking credentials on our web servers.
- Technical & Analytical Data: IP address, browser type, device information, and pages visited, collected through secure anonymized telemetry to ensure website stability and performance.
3. How We Use Your Information
Your information is utilized solely for legitimate business and client service purposes:
- To provide tailored gemological advice and present curated gemstone selections via our private concierge.
- To facilitate National Gem and Jewellery Authority (NGJA) certificate verification and export documentation.
- To arrange secure, fully-insured international courier delivery (FedEx/DHL/Brink's Global Services) to your destination.
- To prevent fraudulent inquiries, spam, and maintain site security via automated protection filters.
4. Data Protection & Third-Party Disclosure
We implement industry-standard encryption protocols (TLS 1.3, strict security headers, and encrypted storage). We never sell, rent, trade, or monetize your personal data to advertisers or third-party marketing brokers.
Information is shared only with verified service providers strictly necessary to execute your requests:
- Authorized gemological testing laboratories (e.g., NGJA, GIA, GRS) for certificate issuance.
- Licensed international couriers and customs brokers for insured shipment and export compliance.
- Secure, PCI-DSS compliant financial settlement institutions for processing international bank transfers or escrow payments.
5. Legal Basis & Data Retention
Under international privacy frameworks (including GDPR), we process personal data based on (a) performance of a contractual inquiry or purchase agreement, (b) compliance with statutory export documentation laws, or (c) legitimate interest in preventing financial fraud.
Retention Periods: Transaction invoices and export certificate archives are retained for 7 years in compliance with national commercial tax laws. General concierge chat logs and inquiries are purged within 24 months of inactive communication unless a continuing client relationship exists.
6. Your Legal Rights & Complaints
Depending on your jurisdiction (including EU/UK GDPR and California CCPA), you have the right to:
- Request access to the personal data we maintain about you.
- Request rectification of inaccurate details or complete erasure of non-statutory records.
- Opt out of direct collector updates at any time by notifying our compliance officer.
- Lodge a privacy inquiry or complaint directly with our compliance desk at concierge@mihilakgems.com, which will be addressed within 14 business days.
7. Data Controller & Compliance Office
The Data Controller responsible for your personal information is Mihilak Gems (Pvt) Ltd, registered under the National Gem and Jewellery Authority of Sri Lanka:
