Privacy Policy
Who we are
This shop is operated by Crystallized Intelligence SARL-S, 38 Route d'Echternach, 1453 Luxembourg ("we"). We are the data controller for the personal data described here. Contact: info@crystallized.lu.
What we collect and why
We collect only what is needed to run this shop (data minimisation, Art. 5(1)(c) GDPR):
- Orders — name, billing and shipping address, email address, and the contents of your order. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Without this data we cannot deliver your order.
- Payment — handled entirely by our payment provider Mollie. We never see or store your card details.
- Order emails — we email you to confirm and update your order (Art. 6(1)(b)). Marketing email is sent only if you separately opt in (Art. 6(1)(a)) and every message includes an unsubscribe link; you can withdraw consent at any time (Art. 7(3)).
- Server logs — our hosting provider processes technical logs (including IP addresses) for security. Legal basis: legitimate interests (Art. 6(1)(f)) in keeping the service secure.
We do not create customer accounts, we do not profile you, and we make no automated decisions about you (Art. 22).
Who receives your data
- Print partner — Gelato ASA, Dronning Eufemias Gate 8, 0191 Oslo, Norway (EEA) receives your name and shipping address to print your order (processor under Art. 28 GDPR), and engages the printing facility nearest you as a sub-processor. We sell only within the EU, so that facility is normally in the EU/EEA.
- Delivery carrier — the carrier that brings the parcel to your door receives your name and address and acts as an independent controller for the delivery, under its own privacy notice.
- Payment provider — Mollie B.V., Amsterdam, Netherlands.
- Hosting — Scaleway SAS, France (EU region).
- Email delivery — order emails are sent by our hosting provider's mail server (Scaleway SAS, France). We use no separate email-marketing provider.
Mollie and Scaleway process your data inside the EU. Gelato engages sub-processors both inside and outside the EEA — including cloud infrastructure, support and analytics providers in the United States — and is required to cover those transfers by the EU–US Data Privacy Framework or Standard Contractual Clauses (Arts. 44–49 GDPR). Gelato publishes its current sub-processor list in its Data Processing Terms; you may ask us about it at any time.
How long we keep it
- Order and invoice data: 10 years (Luxembourg commercial-law bookkeeping obligation; Art. 6(1)(c) GDPR).
- Marketing consent and email address: until you unsubscribe.
- Server logs: our host discards raw access logs within 24 hours and we keep no archived copies. Diagnostic logs written by the shop software (e.g. payment errors) are kept for up to 30 days and then deleted automatically.
- Backups: our host keeps daily backups for 7 days, weekly backups for 4 weeks and monthly backups for 6 months. Data you ask us to erase disappears from live systems immediately and from backups as those rotate, within 6 months at the latest.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection — absolute for direct marketing (Art. 21). Write to info@crystallized.lu; we respond within one month (Art. 12(3)). You may also complain to the Luxembourg supervisory authority, the CNPD (Commission nationale pour la protection des données, cnpd.public.lu) (Art. 77).
Cookies
We use only strictly necessary first-party cookies (cart and session). No tracking, no third-party cookies — see the Cookie Policy.