AURELIA
AURELIA

Privacy Policy

What we hold about you, why we are allowed to hold it, and how to make us stop. This site sets no cookies, runs no trackers and never handles a card number.

Last updated 1 August 2026

Who is responsible

Aurelia Maison de Joaillerie (“Aurelia”, “we”, “us”) decides why and how the personal information described here is used. We are the data controller for that information.

Write to us about anything on this page at atelier@aurelia.example.com, or by post to 5th Avenue Atelier, New York, NY.

What we collect, and when

We only hold what you type into one of two forms. There is no account to create and nothing is gathered in the background as you browse.

  • Enquiry about a piece — your name, email address, telephone number, an optional note, and the pieces you selected together with the metal, stone and engraving you chose.
  • Private consultation — your name, email address, telephone number, your preferred date and the message you write.

With both we also store the IP address and browser identification the request arrived with, to block automated abuse of the forms.

The design configurator calculates prices in your browser. Nothing is sent to us unless you ask to save an estimate, and a saved estimate holds the configuration, not your identity.

What we never collect

An Aurelia acquisition is confirmed by an advisor, never by a card form on this website. We do not ask for, receive or store card numbers, bank details or any other payment credentials here.

We run no advertising trackers, no analytics profiling and no third-party marketing pixels, and we do not buy, sell or exchange personal information with anyone.

Why we are allowed to use it

  • To answer you. Handling an enquiry or arranging a consultation is a step taken at your request before any agreement — we need the information to reply at all.
  • Our legitimate interest. Keeping IP addresses briefly lets us stop automated submissions and protect the maison and our visitors from abuse of the forms.

Cookies

The public website sets no cookies at all. There is no consent banner because there is nothing to consent to.

One cookie exists on this domain: a sign-in cookie for members of the atelier who administer the catalogue. It is issued only after a successful staff sign-in, cannot be read by scripts, expires after eight hours, and is never set for a visitor.

Where it is kept, and who else sees it

Your information is stored in a PostgreSQL database hosted in Frankfurt, Germany, and the website is served from the same region. Three suppliers process data strictly on our instructions:

  • Vercel — hosting and delivery of the website.
  • Neon — the managed database in which enquiries are stored.
  • Resend — delivery of the confirmation and notification emails.

Where any of these processes data outside the European Economic Area, that transfer is covered by the European Commission’s Standard Contractual Clauses. Beyond these suppliers, we disclose personal information only when the law requires it of us.

How long we keep it

An enquiry or consultation record is kept while we are in conversation with you and afterwards for as long as we may need it to honour the guarantees attached to a piece or to meet an obligation the law places on us.

You do not have to wait for any of these periods to end. Ask us to erase your information and we will, unless the law requires us to keep a specific record.

Your rights

You may ask us to:

  • give you a copy of what we hold about you;
  • correct anything that is wrong;
  • erase it;
  • stop or limit what we do with it;
  • send it to you, or to someone else, in a portable form;
  • stop relying on our legitimate interest, where that is our basis.

Write to atelier@aurelia.example.com. We will answer within one month. You never have to pay to exercise these rights, and asking will never affect how we treat you as a client.

If you believe we have handled your information badly, you may also complain to the data protection authority in the country where you live or work.

Security

The site is served only over an encrypted connection. Staff passwords are stored as one-way hashes and never in a readable form. Administrative pages are closed to search engines and require a sign-in that is re-checked on every request. Form submissions are rate-limited, and application logs are configured to strip names, addresses and telephone numbers before anything is written down.

Children

This website is intended for adults. We do not knowingly collect information from anyone under 16. If you believe a child has sent us their details, write to us and we will remove them.

Changes to this policy

If we change how we handle personal information, we will update this page and move the date above. Where a change materially affects you and we hold your address, we will tell you directly rather than rely on you noticing.