Privacy Policy

This Privacy Policy defines the rules for the processing and protection of personal data of customers of the 7stars.nl online store operating on the Dutch market. This document has been developed in accordance with EU Regulation 2016/679 (GDPR/AVG) and the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act (Wwft).

1. Data Controller

The data controller is:

7STARS B.V

info@7starsbv.com

Keizersgracht 123, 1015 CJ
Amsterdam, Netherlands

KVK: 42008672
BTW: NL123456789B0
Bank account number: NL67 INGB 0119 9224 36

2. Legal Basis for Processing

We process personal data based on:

  • Art. 6(1)(b) GDPR/AVG: Necessity for the performance of a sales contract (fulfillment of orders for gemstones).
  • Art. 6(1)(c) GDPR/AVG: Legal obligation incumbent on the controller resulting from Dutch regulations:
    • Wwft (Wet ter voorkoming van witwassen en financieren van terrorisme) – regarding customer identification.
    • Algemene wet inzake rijksbelastingen – regarding the retention of tax records.
  • Art. 6(1)(f) GDPR/AVG: Legitimate interest (direct marketing, debt collection, fraud prevention).

3. Scope of Collected Data and Wwft Procedure

Due to the trade in high-value goods (diamonds, sapphires, rubies, emeralds), we collect:

Transactional Data: First and last name, delivery address, e-mail address, phone number, purchase history.

Verification Data (Wwft): For transactions exceeding statutory thresholds (including cash payments above EUR 10,000) or transactions deemed unusual, we are obliged to conduct “Customer Due Diligence” (CDD). This may include:

  • Identity verification based on a valid ID document.
  • Identifying the Ultimate Beneficial Owner (UBO) in the case of companies.
  • Reporting unusual transactions to FIU-Nederland.

4. Data Security

We have implemented the highest standards of data protection:

  • SSL/TLS encryption for all data transmissions.
  • Transaction monitoring systems for financial security.
  • Restricted physical and digital access to verification data (stored on secure servers in accordance with EU standards).

5. Data Retention Period

Data is stored for the period necessary to achieve the purposes, but no shorter than:

  • 7 years: Financial and accounting data (Belastingdienst requirement).
  • 5 years: Documentation regarding identity verification and customer due diligence (pursuant to Art. 33 of the Wwft), calculated from the end of the business relationship or the execution of the transaction.
  • Until consent is withdrawn: In the case of marketing activities.

6. Data Recipients (Derden)

Data may be shared only with authorized entities:

  • Payment service providers (e.g., iDEAL, Mollie, banks).
  • Logistics companies specializing in high-value transport (e.g., FedEx, UPS with insurance).
  • State authorities: Belastingdienst, FIU-Nederland, the Public Prosecutor’s Office, or the Police – solely on the basis of explicit legal provisions.

7. User Rights (GDPR/AVG)

In accordance with European and Dutch law, every customer has the right to:

  • Access their data and receive a copy thereof.
  • Rectify (correct) data.
  • Erasure of data (the “right to be forgotten”) – subject to the reservation that data stored under the Wwft cannot be deleted before the expiry of the 5-year statutory period.
  • Object to marketing.
  • That all presented certificates belong to our trading partners.

8. Complaints

In case of concerns regarding the method of data processing, the user has the right to lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens (AP), The Hague.