www.keepmoments.eu
This Privacy Policy explains how personal data is processed in connection with your use of the KEEPMOMENTS online store available at www.keepmoments.eu (the "Store"). KEEPMOMENTS creates bespoke memorial and keepsake jewellery, made to order from material that you consign to us. Much of what is described below concerns information of a deeply personal nature, and it is set out plainly so that you can understand exactly what happens to your data and to the material you entrust to us.
1. General provisions, controller and EU contact point
-
This Privacy Policy sets out the rules for the processing and protection of personal data collected in connection with the use of the Store. It governs the processing of personal data of visitors and customers of the Store.
-
Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR"), and with other applicable data protection legislation.
-
The data controller is:
KEEP MOMENTS LTD A private company limited by shares, incorporated in England and Wales Companies House registration number: 11909402 Registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom EU operational address (order fulfilment, handling of consigned material, dispatch and returns): Wapienna 4A/2, 71-790 Szczecin, Poland E-mail: [email protected] Phone: +48 731 850 700
(the "Controller", referred to below also as "we", "us" or "our").
-
EU/EEA contact point. Order fulfilment, the handling of consigned material, dispatch and returns all take place at the Controller's operational establishment at Wapienna 4A/2, 71-790 Szczecin, Poland. The processing of personal data described in this Policy therefore takes place in the context of the activities of that establishment within the European Union. If you are in the European Union or the European Economic Area, you may contact the Controller on all matters relating to the processing of your personal data at that address and at [email protected].
-
The Controller exercises particular care to protect the interests of the persons whose data it processes, and in particular ensures that the data it collects is processed lawfully, collected for specified and legitimate purposes, and not further processed in a manner incompatible with those purposes.
-
No Data Protection Officer. The Controller has not appointed a Data Protection Officer, as it is not required to do so. For all matters relating to the processing and protection of personal data, you may contact the Controller directly at [email protected].
2. Joint controllership of customer accounts (Art. 26 GDPR)
- The group of stores to which KEEPMOMENTS belongs runs on one shared customer-account system. This means that a single customer account allows you to shop across several group stores, even where those stores are operated by different companies within the group. As a result, customer-account data is jointly controlled by two companies acting as joint controllers within the meaning of Art. 26 GDPR:
- KEEP MOMENTS LTD, a private company limited by shares incorporated in England and Wales, Companies House registration number 11909402, registered office 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom; and
- MILKIES LTD, a private company limited by shares incorporated in England and Wales, Companies House registration number 10195739, registered office 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom.
-
Essence of the arrangement. The joint controllership covers only the shared customer-account data held in the common group account infrastructure. The two companies have agreed between themselves their respective roles and responsibilities for that data, in particular which of them performs which duties towards you, including responding to requests by which you exercise your rights. The purpose of the arrangement is to operate one customer account that works across several group stores. The legal basis is the performance of the account contract (Art. 6(1)(b) GDPR) together with the joint controllers' legitimate interest in offering a unified group account (Art. 6(1)(f) GDPR). The scope of the sharing is limited to the shared group account infrastructure.
-
Single contact point and your rights. Regardless of the internal division of responsibilities, you may exercise all of your data protection rights, and address any request or query, to a single contact point: [email protected]. You may exercise your rights against either of the joint controllers, and each will give effect to your request.
3. Scope of personal data collected
- In connection with your use of the Store, the Controller collects the following personal data:
a) data you provide directly: first and last name, e-mail address, phone number, delivery address, billing details (including a tax identification number in the case of business customers);
b) order data: information about the piece you order and its personalisation or engraving, the chosen payment method, and the delivery address;
c) account data (if you create an account): your password (stored in encrypted/hashed form), your order history, and any saved preferences;
d) consigned-material data: the special-category data described in section 4 below, arising from the material you send us and the context of your order;
e) data collected automatically: IP address, browser type and version, operating system, screen resolution, pages visited, time spent on the site, clicks, and information from cookies and the tracking tools described in section 8.
- Providing personal data is voluntary. However, providing the data necessary to fulfil an order is required in order to place and complete that order; without it, the contract cannot be performed.
4. Special-category data (Art. 9 GDPR): consigned biological material
-
The pieces we make are produced to order from material that you consign (send in) to us. Depending on the piece, this material may include cremation ashes (human and animal/pet), hair or fur, breast milk, flowers or fabric (for example a piece of a wedding dress), or umbilical cord.
-
Because of the nature of this material and the context surrounding an order (which may, for example, concern the loss of a close person, the loss of a child, or the hair or breast milk of a living person), the Controller may process information that constitutes or reveals special-category personal data within the meaning of Art. 9 GDPR, in particular data concerning the health, and possibly the genetic data, of the living customer or of another identifiable living person.
-
Legal basis. The legal basis for processing this special-category data is your explicit consent (Art. 9(2)(a) GDPR), which you give at the point of placing your order and when you send the material to us. You may withdraw this consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and it may make completing your order impossible.
-
A deceased person is not a data subject under the GDPR. The special-category protection described here therefore attaches to the living customer and to any other identifiable living person whose data may be revealed by the material or the order.
5. Handling of consigned material and return of the remainder
- Material consigned by you is handled with the corresponding care. In particular:
a) it is stored securely, with access restricted to authorised workshop staff directly involved in fulfilling your order;
b) it is used solely to make the piece you have ordered;
c) it is identified throughout by your order code;
d) once your order is complete, any unused material is returned to you, or, only on your express instruction, securely destroyed;
e) you may request the return or the destruction of consigned material at any time by contacting the Controller at [email protected].
- Cremation ashes and other consigned biological material are irreplaceable, and they are handled with that fact in mind throughout the process, from receipt at the workshop in Szczecin to the return of any remainder to you.
6. Purposes and legal bases of processing
- Personal data is processed for the following purposes and on the following legal bases:
a) performance of the sales contract, including contact about your order and the handling of complaints and returns: Art. 6(1)(b) GDPR (performance of a contract or steps taken at your request before entering into a contract);
b) maintaining your customer account in the Store: Art. 6(1)(b) GDPR (performance of the contract for the provision of electronic services);
c) operating the unified group account and the related sharing between the joint controllers described in section 2: Art. 6(1)(b) GDPR (performance of the account contract) together with Art. 6(1)(f) GDPR (the legitimate interest of the joint controllers in offering one account across the group stores);
d) sending transactional e-mails relating to your order (for example order confirmation, dispatch notice): Art. 6(1)(b) GDPR;
e) sending the newsletter and marketing communications by e-mail: Art. 6(1)(a) GDPR (your consent), which you may withdraw at any time without affecting the lawfulness of processing carried out before the withdrawal;
f) analytics and advertising tracking by means of the tools named in section 8: Art. 6(1)(a) GDPR (your consent given through the consent banner). These tools are not activated on the basis of legitimate interest; they remain blocked until you consent;
g) login and registration via Google and via Facebook (social login): Art. 6(1)(b) GDPR (creation and operation of your account) together with your decision to connect the relevant account, as described in section 9;
h) establishing, exercising and defending legal claims: Art. 6(1)(f) GDPR (the Controller's legitimate interest in protecting its rights);
i) complying with tax and accounting obligations: Art. 6(1)(c) GDPR (a legal obligation to which the Controller is subject);
j) processing of special-category consigned material: Art. 9(2)(a) GDPR (your explicit consent), as described in section 4.
- Where the Controller provides product recommendations based on your purchase history, this limited profiling serves only to adapt the offer shown to you. It does not involve solely automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR. You may object to such profiling at any time.
7. Recipients of personal data and transfers to third countries
- Personal data may be shared with the following recipients, solely to the extent necessary to achieve the purposes set out above. Each recipient is bound by a data-processing agreement and is required to ensure an appropriate level of protection.
| Recipient | Purpose | Data location / transfer basis |
|---|---|---|
| Own hosting infrastructure (Medusa application + PostgreSQL database, on the Controller's own server) | Operation of the Store, customer accounts and orders | European Union |
| Directus (content management system) | Content and media | European Union |
| Cloudflare (R2 storage + content delivery network) | Storage and delivery of media | European Union, with a global edge network |
| Stripe | Processing of card and local payments | European Union / United States (processor; EU-US Data Privacy Framework / Standard Contractual Clauses) |
| Mailchimp / Mandrill (The Rocket Science Group LLC) | Transactional and marketing e-mail | United States (Standard Contractual Clauses / Data Privacy Framework) |
| DHL Express | Shipping of the order and of consigned material | Per destination country |
| Sentry | Error monitoring | European Union (EU data residency) |
| Google (Google Analytics 4, Google Tag Manager, Google Ads, Google login) | Analytics, advertising and login | United States (EU-US Data Privacy Framework / Standard Contractual Clauses) |
| Meta (Meta Pixel, Conversions API, Facebook login) | Advertising and login | United States (EU-US Data Privacy Framework / Standard Contractual Clauses) |
| TikTok (TikTok Pixel, Events API) | Advertising | Transfers outside the EEA (Standard Contractual Clauses; EEA / United States / Singapore) |
| Microsoft Clarity | Session recording and heatmaps | United States (Standard Contractual Clauses) |
-
The Controller's own infrastructure (the Medusa application, the PostgreSQL database, Directus and Cloudflare R2 storage) is hosted within the European Union.
-
Transfers to the United States and other third countries. Some of the advertising, analytics and e-mail providers named above are established in the United States, and some other providers transfer data outside the European Economic Area. For such transfers, the Controller relies on the EU-US Data Privacy Framework (Art. 45 GDPR) where the relevant provider is certified, and otherwise on Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) or other appropriate safeguards under applicable data protection law.
-
The Controller does not sell personal data to third parties.
-
You have the right to obtain a copy of the safeguards applied to such transfers by contacting the Controller at [email protected].
8. Cookies and tracking: consent
-
Consent banner and Consent Mode. When you first visit the Store, a consent banner is shown. The Store uses its own consent banner together with Google Consent Mode v2. Until you make a choice, all non-essential tags and tools remain blocked (Consent Mode v2 defaults to "denied"). The banner offers granular categories (necessary, analytics, marketing), and rejecting non-essential cookies is as easy as accepting them. You can withdraw your consent at any time through a persistent link/icon available in the footer of the Store. Your consent choice is logged as proof. The banner links to the Cookie Policy, where the individual cookies and their durations are described.
-
Legal basis. The legal basis for all non-essential cookies and tracking tools is your consent (Art. 6(1)(a) GDPR), together with the applicable e-privacy rules transposing Directive 2002/58/EC. Essential cookies, which are necessary for the Store to function (for example the shopping cart, login and session), do not require consent.
-
Tools used. Subject to your consent, the Store uses the following tools, and only these:
a) Google Analytics 4 and Google Tag Manager: analytics, to understand how the Store is used;
b) Meta Pixel and Conversions API (CAPI): advertising measurement, operating both in the browser and server-side;
c) TikTok Pixel and Events API: advertising measurement, operating both in the browser and server-side;
d) Google Ads: remarketing and conversion measurement;
e) Microsoft Clarity: a tool that records interactions with the Store (session recording) and produces heatmaps. Given the sensitive nature of what you share with us, Clarity is activated only with your consent, and it is configured to mask sensitive fields, including form fields, personal data, engraving text and uploads, so that such content is not captured.
-
Server-side processing. For the Meta Conversions API and the TikTok Events API, conversion data is also sent to Meta and TikTok server-side. This server-side processing is likewise gated by your consent, and identifying data is hashed before transmission.
-
Browser-level control. Independently of the consent banner, you can manage or delete cookies at any time in your web browser settings, including blocking them. Restricting essential cookies may affect the proper functioning of the Store.
9. Social login (Google / Facebook)
-
The Store allows you to log in or register using your Google account or your Facebook account.
-
If you choose this option, the Controller receives from the relevant provider a limited set of data, namely your e-mail address, your name, and a unique identifier, for the purpose of creating and operating your account.
-
The legal basis is Art. 6(1)(b) GDPR (creation and operation of your account) together with your decision to connect the relevant account.
-
The login process is also governed by the privacy policies of Google and of Meta, which apply to the processing those providers carry out on their own side.
10. Retention periods
-
Order and contract data is kept for the duration of the contract and thereafter for the period necessary to handle complaints and to establish, exercise or defend legal claims. This corresponds to the applicable limitation period, which is up to 6 years under the law of England and Wales; limitation periods in individual EU/EEA Member States may be shorter.
-
Accounting and tax records are kept for the statutory retention period under the applicable accounting and tax law, generally up to 6 years.
-
Account data is kept for as long as you maintain your account, and after its deletion only for as long as required by law or until any potential claims are time-barred.
-
Newsletter and marketing-consent data is kept until you withdraw your consent.
-
Consent logs (the record proving that consent was given) are kept as evidence for the relevant limitation period, up to 6 years after the consent ends.
-
Data processed on the basis of legitimate interest (such as analytics and the handling of claims) is kept until an effective objection is raised or until the purpose of the processing ceases.
-
Server logs are kept for no longer than 12 months.
-
Tracking cookies and tools are kept for the durations stated in the Cookie Policy.
-
Consigned material is kept only for as long as needed to fulfil your order; any unused remainder is then returned to you, or, on your instruction, securely destroyed.
11. Your rights
- As a data subject, you have the right to:
a) access your personal data and obtain a copy of it (Art. 15 GDPR);
b) have your personal data rectified (Art. 16 GDPR);
c) have your personal data erased, the "right to be forgotten" (Art. 17 GDPR);
d) restrict the processing of your personal data (Art. 18 GDPR);
e) data portability (Art. 20 GDPR);
f) object to the processing of your personal data, including profiling (Art. 21 GDPR);
g) withdraw your consent to processing at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3) GDPR).
-
To exercise these rights, please contact the Controller by e-mail at [email protected], or by post to: KEEP MOMENTS LTD, Wapienna 4A/2, 71-790 Szczecin, Poland.
-
The Controller will deal with your request without undue delay, and in any event within one month of receipt. In particularly complex cases, or where there are numerous requests, this period may be extended by a further two months, of which the Controller will inform you within one month of receiving your request.
12. Internal complaint and right to lodge a complaint with a supervisory authority
-
If you are not satisfied with how the Controller has handled your data or your request, you may complain directly to the Controller at [email protected]. The Controller will acknowledge your complaint, investigate it, and inform you of the outcome.
-
You also have the right to lodge a complaint with a supervisory authority. As this Store serves customers across the European Union and the European Economic Area, you may lodge your complaint with the data protection supervisory authority of the EU/EEA Member State in which you habitually reside, in which you work, or in which the alleged infringement took place. A list of national supervisory authorities and their contact details is maintained by the European Data Protection Board. Exercising your right to an internal complaint does not affect your right to complain to a supervisory authority.
13. Security
- The Controller applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in particular:
a) encryption of connections using a TLS (Transport Layer Security) certificate;
b) restricting access to personal data to authorised persons only, where necessary for their tasks;
c) regular data backups;
d) server hardening, firewalls, and intrusion detection and prevention.
-
The Controller reviews its security measures regularly to keep them adequate to current threats.
-
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, the Controller will notify the competent supervisory authority without undue delay, and where feasible within 72 hours of becoming aware of the breach (Art. 33 GDPR). Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, the Controller will also notify those individuals without undue delay (Art. 34 GDPR).
14. Children
-
The Store is not directed at children. The Controller does not knowingly collect the personal data of children. The applicable age of digital consent is 16, or the lower age set by the law of the Member State concerned (which may be as low as 13).
-
If the Controller becomes aware that it has collected the personal data of a child without the appropriate parental consent, it will delete that data without undue delay.
15. Changes to this Privacy Policy
-
The Controller may amend this Privacy Policy in the event of changes in the law, changes in technology, or changes in the way personal data is processed.
-
The Controller will inform you of any material changes by publishing the updated Privacy Policy on the Store's website and, where applicable, by sending a notice to the e-mail address associated with your account.
-
Where consent is the legal basis for processing, any material change affecting that processing will require your renewed consent.
16. Final provisions
-
This Privacy Policy supplements the Terms and Conditions of the KEEPMOMENTS online store.
-
In matters not covered by this Privacy Policy, the provisions of the GDPR and other applicable data protection legislation apply.
-
Controller and seller identity:
KEEP MOMENTS LTD A private company limited by shares, incorporated in England and Wales Companies House registration number: 11909402 Registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom EU operational and returns address: Wapienna 4A/2, 71-790 Szczecin, Poland E-mail: [email protected] Phone: +48 731 850 700
Last updated: 15 June 2026