1. Who we are
ICA GEM LABORATORIES COMPANY LIMITED, Thai company registration ID 0105560179379 (“ICA GemLab”, “we”, “us” or “our”), is responsible for the personal data described in this Privacy Policy unless a quotation, order form, invoice or location-specific notice identifies another ICA GemLab entity as the data controller.
ICA GEM LABORATORIES COMPANY LIMITED Trading name: ICA / GemLab 919/7–8, 6th Floor, Jewelry Trade Center Silom Road, Silom Sub-District Bangrak District, Bangkok 10500, ThailandPrivacy and general enquiries: info@icagemlab.com Telephone: +66 2 630 0001
This Policy applies to visitors to icagemlab.com, users of ICA GemLab report-verification services, Clients, prospective Clients, suppliers, event and publication contacts, and persons whose data is provided in connection with a laboratory submission.
2. Personal data we collect
Depending on your relationship with us, we may collect:
- identity and contact data, such as name, organisation, role, postal address, email address and telephone number;
- Client and compliance data, such as account details, authorised representatives, identity documents where legally required, ownership or source information, sanctions and customs information;
- order and transaction data, including requested Services, quotations, invoices, payment status, shipping details, declared values and correspondence;
- submission and report data, such as report numbers, item descriptions, photographs, declared owner or submitter information, examination instructions and analytical records;
- communications, including emails, telephone notes, enquiries, complaints, event registrations and preference records;
- technical data, such as IP address, browser and device information, requested pages, timestamps, security events and server logs; and
- consent and marketing data where you choose to receive updates.
We do not intentionally request sensitive personal data unless it is necessary for legal compliance or a specific Service. Please do not send unnecessary passport, financial, health or other sensitive information by ordinary email.
3. How we obtain personal data
We obtain personal data directly from you; from your employer, agent, the owner of an item, a courier, business partner or authorised submitter; through laboratory orders and report verification; from payment and communication providers; and from lawful public sources where needed for due diligence or legal compliance.
If you provide information about another person, you must be authorised to do so and must make this Policy available to that person where appropriate.
4. Why we use personal data
We process personal data to:
- answer enquiries and recommend an appropriate Service;
- prepare quotations, administer Client relationships, accept submissions and perform contracts;
- receive, identify, examine, secure and return submitted items;
- issue, maintain, verify, correct and protect gemmological reports;
- process payments, invoices, accounting, tax, customs and shipping;
- maintain laboratory quality, scientific traceability, reference data and fraud prevention;
- protect our premises, systems, Clients, personnel and intellectual property;
- comply with legal, regulatory, sanctions, court and law-enforcement obligations;
- establish, exercise or defend legal claims;
- measure and improve our website and professional communications; and
- send news, research or Service updates where you consent or applicable law otherwise permits.
5. Legal bases
Under Thailand’s Personal Data Protection Act B.E. 2562 (2019), and under the EU or UK GDPR where either law applies, we rely as appropriate on steps requested before entering into a contract, performance of a contract, compliance with legal obligations, our legitimate interests in operating a secure and scientifically accountable laboratory, consent, and the establishment, exercise or defence of legal claims.
You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal and does not prevent processing based on another lawful ground.
6. Report verification and scientific records
The verification portal helps users confirm whether report data corresponds with ICA GemLab’s official records. A result may display report and gemstone information. Clients must not submit unnecessary personal information for inclusion in a report.
ICA GemLab may retain report numbers, gemstone photographs, analytical measurements and related scientific records for extended periods where necessary to preserve report integrity, identify fraud, support re-examination, maintain reference collections and enable scientific research. Where possible, research and publication use is separated from identifiable Client information.
Online submission enquiries
When you use the website’s submission-enquiry form, the information entered is transmitted to ICA GemLab to answer the enquiry and prepare a possible laboratory submission. Required fields are limited to contact information and practical details about the item and requested analysis. Do not include payment-card data, identity documents or other unnecessary sensitive information.
Form messages and the automatic submission acknowledgement containing Bangkok shipping information may be delivered by Resend, Inc., acting as an email-delivery provider, when that service is activated. Technical anti-abuse data such as the request time and IP address may be processed temporarily to validate the request and limit repeated submissions. The website does not create a public account or store the completed form in a client-accessible database.
7. Cookies and Google Analytics 4
Essential technologies
The website and its hosting infrastructure use essential technical processing, local storage and server logs to deliver pages, remember your privacy choice, maintain security, prevent abuse and diagnose faults. These functions do not require analytics consent where applicable law permits.
Google Analytics
With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google LLC and other Google group companies may process data in the United States and other countries.
Google Analytics helps us understand in aggregated form how visitors find and use the website, which pages and Services are of interest, whether navigation works as intended and how the website can be improved. Depending on your device and consent settings, measurement data may include a randomly generated online identifier, pages viewed, approximate session duration, navigation events, referring source, broad geographic information, browser, device type, operating system, language, screen information, and interactions such as selecting a report, viewing a Service or following a contact link.
We do not send names, email addresses, telephone numbers, report numbers, gemstone-owner details or other directly identifying information to Google Analytics. URLs, page titles and event parameters must not contain such information.
Google states that Google Analytics does not log or store individual IP addresses. For visitors in the European Union, Switzerland and the United Kingdom, IP addresses are used for coarse geolocation and discarded before resulting measurement data is logged. The use of Google Analytics and its identifiers may nevertheless constitute processing of personal data.
The legal basis is your consent. Google Analytics remains disabled until you choose “Accept analytics”. Refusing or withdrawing consent does not restrict access to the website or laboratory information.
Privacy configuration
ICA GemLab configures Google Analytics with analytics storage denied by default, no Analytics script before consent, Google Signals disabled, advertising personalisation and remarketing disabled, no user IDs or directly identifying information, and user-level and event-level retention set to 14 months with reset on new activity disabled.
Google Analytics may set first-party cookies such as _ga to distinguish browsers and _ga_<container-id> to maintain session state. Their maximum duration is normally two years unless configured for a shorter period or deleted by you. The separate consent choice is stored on your device and normally renewed after no more than twelve months.
Google processes Analytics data for us under its data-processing terms. International transfers are protected through mechanisms made available by Google, which may include standard contractual clauses and other legally recognised safeguards. Read the Google Privacy Policy and Google’s information for sites using Analytics for further information.
Your choice
You can withdraw or change consent at any time through Cookie settings. You may also delete cookies in your browser or use Google’s Analytics opt-out browser add-on. Withdrawal applies to future collection and does not make earlier consent-based processing unlawful.
Report-verification portal
The separate report-verification portal may use essential cookies or local storage for security and functionality. Optional analytics on that portal must follow the same consent standard unless a separate, equally clear notice and consent control is provided.
8. When we share personal data
We may share personal data only where reasonably necessary with ICA GemLab international contact locations involved in client communication; qualified laboratories and specialists where separately required and authorised; hosting, cybersecurity, IT, email, document, analytics, payment and communications providers; couriers, freight forwarders, insurers and customs agents; accountants, auditors, banks and advisers; authorities where required or legally justified; and a genuine purchaser or successor subject to appropriate safeguards. ICA GemLab’s own gemmological testing and analytical work are performed at its main laboratory in Bangkok.
We do not sell personal data.
9. International transfers
ICA GemLab operates internationally, and Services may involve laboratories, Clients or providers outside Thailand. Personal data may therefore be transferred across borders. We use legally recognised transfer mechanisms and reasonable contractual, organisational and technical safeguards where applicable. No transfer mechanism can eliminate all risk, but we limit transfers to what is necessary for the relevant purpose.
10. Retention
We keep personal data only for as long as reasonably necessary for contractual, scientific, verification, security, tax and legal purposes. Typical periods are:
- general enquiries that do not lead to an order: up to 24 months after the last substantive contact;
- Client relationships and Service correspondence: normally up to 10 years after completion or the last active relationship;
- accounting, invoice, payment and tax records: for the statutory retention period, normally up to 10 years where appropriate;
- report, verification and analytical records: for as long as needed to preserve report integrity, scientific traceability and fraud prevention, which may be long-term;
- Google Analytics user-level and event-level data: 14 months, with reset on new activity disabled; aggregated reports may remain available for longer;
- the cookie-consent choice: normally no longer than 12 months before renewal;
- routine security and server logs: normally up to 90 days unless required for an incident, investigation or claim; and
- marketing records: until consent is withdrawn, an objection is received or the contact has been inactive for a reasonable period.
When identifiable data is no longer required, we delete it, anonymise it or restrict access, subject to lawful archival and backup cycles.
11. Security
We use proportionate technical and organisational measures intended to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These may include access controls, role-based permissions, secure hosting, backups, logging, staff confidentiality and incident-response procedures. Internet transmission is never completely secure; please use an agreed secure channel for sensitive documents or high-value submission information.
12. Your rights
Subject to applicable law and relevant exceptions, you may request access to and a copy of your personal data; correction; deletion, anonymisation or restriction; object to certain processing and direct marketing; withdraw consent; request portability where applicable; ask about international transfers; and lodge a complaint with Thailand’s Personal Data Protection Committee or another competent supervisory authority.
To exercise a right, contact info@icagemlab.com. We may need to verify your identity and authority. Rights relating to laboratory records may be limited where retention is necessary for report integrity, fraud prevention, legal compliance, scientific traceability or legal claims.
13. Marketing, children and external websites
We send marketing communications only where permitted. You can unsubscribe through the message or by contacting us. Service, report, security and transactional communications are not marketing and may still be sent where necessary.
Our Services are directed to businesses and adults. We do not knowingly collect personal data directly from children through the website. A parent or guardian who believes that a child has provided data should contact us.
Our website may link to third-party websites, payment services, couriers, social networks or other platforms. Those parties process personal data under their own privacy notices.
14. Changes and contact
We may update this Policy to reflect changes in our Services, technology or legal obligations. The current version and effective date will be published on this page. Material changes will be highlighted where reasonably appropriate.
Privacy questions, requests or complaints may be sent to ICA GEM LABORATORIES COMPANY LIMITED, Thai company registration ID 0105560179379, Attn: Privacy, 919/7–8, 6th Floor, Jewelry Trade Center, Silom Road, Silom Sub-District, Bangrak District, Bangkok 10500, Thailand; info@icagemlab.com; +66 2 630 0001.
