Privacy Policy
Last updated: 21 October 2025
Harmony Jewelers (“Harmony”, “we”, “us”, “our”) is committed to protecting your privacy. This Policy explains how we collect, use, disclose, and safeguard personal data when you visit harmonyjewelers.ae, contact us, purchase in-boutique, or engage with our social/WhatsApp channels.
We process personal data in accordance with the UAE Personal Data Protection Law (PDPL) and applicable guidance. Where we ship internationally, local rules at the destination may also apply.
1) Who we are & how to contact us
- Controller: Harmony (a Mazrui Retail Company)
- Trading As: Harmony Jewelers
- Boutique: Ground Floor, Marina Mall, Abu Dhabi, United Arab Emirates
- Phone: +971 (2) 491 6100 WhatsApp: +971 54 584 8399
- Email: [email protected]
For privacy requests (access, deletion, etc.), email [email protected] with the subject “PDPL Request”.
2) Scope of this Policy
This Policy covers personal data we process when you:
- Browse our website or interact with our cookie/banner tools;
- Create an account, place orders, book appointments, or request concierge support;
- Communicate with us by phone, email, WhatsApp, social media, or web forms;
- Visit our boutique (including CCTV for safety and loss-prevention);
- Participate in events, surveys, or marketing programs.
It does not apply to third-party websites/services that we don’t control. Their privacy notices govern their handling of your data.
3) What data we collect
A. Data you provide
- Identity & contact: name, email, phone, delivery/billing address;
- Purchase & service: orders, invoices, repair history, certificate numbers (e.g., GIA/SwissLab), ring sizes, preferences;
- Payment: masked card data via our payment gateway (we don’t store full card numbers);
- KYC/verification (where required): Emirates ID/passport copy, proof of address, authorized collector’s ID;
- Bespoke/after-sales: sketches, measurements, design notes, engraving text;
- Communications: queries, live-chat/WhatsApp messages, support records.
B. Data collected automatically
- Device & usage: IP address, device/browser type, language, pages visited, session timestamps, referrers;
- Cookies/SDKs: identifiers for analytics, preferences, and (with consent) advertising/retargeting.
C. In-boutique data
- CCTV footage for security and incident response (see Retention).
- Appointment logs (date/time, consultant, requested services).
D. Special categories (limited)
We do not intentionally collect health, religion, or biometric data. If you disclose sensitive information (e.g., for accessibility needs), we will only process it with your explicit consent and for the stated purpose.
4) Why we use your data & legal bases (PDPL)
| Purpose | Examples | Legal Basis |
|---|---|---|
| Order fulfillment | Process orders, payments, delivery, certificates, invoices | Contract performance |
| Customer support | Answer queries, repairs, resizing, warranty handling | Contract / Legitimate interests |
| Bespoke services | Design consultations, sketches, approvals | Contract / Consent (for optional photos/references) |
| Fraud/KYC checks | High-value order verification, chargeback prevention | Legal obligation / Legitimate interests |
| Marketing | Email/SMS/WhatsApp newsletters, event invites | Consent (opt-in) |
| Analytics & improvement | Site performance, UX metrics, A/B tests | Legitimate interests / Consent for non-essential cookies |
| Security | CCTV, access logs, incident response | Legitimate interests / Legal obligation |
| Legal compliance | VAT/tax records, consumer law, complaints | Legal obligation |
Your PDPL rights include: access, rectification, erasure, restriction, objection (including to direct marketing), portability (where applicable), and not to be subject to solely automated decisions producing legal/similarly significant effects.
5) Cookies & similar technologies
Categories we use
- Strictly necessary: checkout, security, consent storage (always on).
- Functional: remembering preferences (on/off).
- Analytics: understanding site usage (consent).
- Marketing/retargeting: personalized offers (consent).
You can manage preferences via our cookie banner and browser settings. Disabling non-essential cookies won’t affect checkout but may reduce personalisation/analytics.
6) Disclosures to third parties (processors/recipients)
We share data only as needed with:
- Payment gateways & fraud screening providers;
- Logistics & insurance partners for secure shipping/returns;
- Certification labs (e.g., GIA/SwissLab) for report validation;
- IT hosting & support (cloud hosting, CRM, email, analytics);
- Professional advisors (legal/accounting) where necessary;
- Regulators/authorities where legally required.
All processors are bound by contracts to protect your data and act only on our documented instructions.
7) International transfers
Some processors or data centers may be outside the UAE. Where we transfer data internationally, we implement PDPL-compatible safeguards (e.g., contractual clauses, adequacy where available). You can request a copy of relevant safeguards (redacted for security/confidentiality) by contacting us.
8) Data retention (how long we keep it)
We keep personal data only as long as needed for the purpose collected and to satisfy legal/accounting/reporting requirements. Typical periods:
- Orders, invoices, warranty/repair records: 6–10 years (legal & audit);
- Account & communications: while active + up to 3 years after last interaction;
- CCTV: 30–90 days unless an incident requires longer retention;
- Marketing data: until you withdraw consent or object;
- KYC/verification: for the legally required period (typically 5–10 years, depending on the nature and value of transactions).
When a retention period ends, we securely delete or anonymise the data.
9) Security measures
We use a layered approach to safeguard data:
- Encrypted transmission (HTTPS/TLS), restricted access, strong authentication;
- Role-based access controls, logging/monitoring, least-privilege principles;
- Vendor due diligence and data processing agreements;
- Staff training and confidentiality undertakings;
- Secure disposal/anonymisation at end of retention.
No system is 100% secure; we continuously improve our controls and monitor for threats.
10) Data breaches
If a personal data breach occurs, we assess impact and, where required by PDPL, notify the UAE Data Office and affected individuals without undue delay, including steps you can take to mitigate potential harm.
11) Your choices & rights (PDPL)
You can exercise your rights by emailing [email protected]. We will respond within applicable PDPL timelines and may request identity verification.
- Access: receive a copy of your personal data we hold.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion where PDPL conditions apply.
- Restriction: limit processing in certain circumstances.
- Objection: object to processing based on legitimate interests, including direct marketing (we will stop).
- Portability: receive data in a structured, commonly used format where technically feasible.
- Withdraw consent: at any time for activities based on consent (e.g., marketing, optional cookies).
- Automated decisions: you have protections where solely automated decisions produce legal/similarly significant effects.
If you believe we have not resolved your concern, you may lodge a complaint with the relevant UAE authority. We encourage you to contact us first.
12) Marketing communications
We send marketing emails/WhatsApp/SMS only with your opt-in consent. You can unsubscribe via the link in our messages or by contacting us. Service messages (order updates, appointment confirmations) are not marketing and will still be sent.
13) WhatsApp & social channels
If you message us via WhatsApp or social media, your data is also processed by those platforms under their terms. For privacy-sensitive matters (e.g., ID documents), we may redirect you to secure channels.
14) Children’s data
Our services are intended for adults (18+). We do not knowingly collect data from children. If you think a child has provided data to us, contact [email protected] and we will delete it where appropriate.
15) Automated decision-making & profiling
We do not make solely automated decisions that produce legal or similarly significant effects. We may segment audiences for marketing (e.g., interests in emerald vs. pearl) with your consent; you may opt out at any time.
16) Links to third-party sites
Our website may link to sites we do not control (e.g., payment providers, certification labs, designer brands). Their privacy policies govern their use of your data.
17) Changes to this Policy
We may update this Policy from time to time. The “Last updated” date shows the version in effect. Significant changes will be highlighted on our website or communicated by email where appropriate.
18) How to contact us
For questions or requests about this Policy or your data:
- Email: [email protected]
- Phone: +971 (2) 491 6100
- WhatsApp: +971 54 584 8399
- Postal/Boutique: Ground Floor, Marina Mall, Abu Dhabi, UAE
We’re happy to assist with access requests, corrections, opt-outs, or clarifications about how we handle your data.