Legal
Last updated: June 11, 2026
Effective Date: January 1, 2026
Last Updated: June 11, 2026
This Privacy Policy governs the relationship between JEWELER STUDIO LLC(“Company”) and the business entity or professional individual subscribing to the Services (“The Subscriber”).
The Company collects the following data to maintain the business relationship:
Unlike standard usage data, KYC/Compliance Data is handled with enhanced security:
6.1 Subprocessors
The Company utilizes the following vetted subprocessors to provide the Service:
6.2 Third-Party Integrations & Webhooks
The Platform provides functionality (such as webhooks and APIs) allowing the Subscriber to export Lead Data to external applications, CRMs, or Third-Party Integrations. The Company does not vet, monitor, or control these external integrations. The Subscriber acknowledges that configuring a webhook constitutes a direct instruction to transmit data outside the Company's secure infrastructure. The Company strictly disclaims all liability for the privacy practices, data security, downtime, or potential breaches of any Third-Party Integration utilized by the Subscriber.
The Company employs AES-256 encryption at rest and TLS 1.2+ in transit. In the event of a confirmed breach of sensitive Compliance Data, the Company will notify the Subscriber within 72 hours of discovery.
The Subscriber warrants that:
For all legal or data inquiries:
Jeweler Studio LLC
Attn: Data Protection Officer
6115 97th St Unit 2K
Rego Park, NY 11374
Email: Contact@jewelerstudio.ai
This Data Processing Addendum (“DPA”) forms part of the Master Service Agreement or Terms of Service (the “Agreement”) between JEWELER STUDIO LLC (“Company”) and THE SUBSCRIBER(the “Subscriber”).
Notwithstanding the roles of the parties defined herein, the Subscriber hereby assigns all right, title, and interest in and to the Lead Datato the Company as a material condition of using the Platform. This assignment ensures the Company's ability to maintain a centralized, high-value data asset for AI training and platform optimization. The Company grants the Subscriber a license to use this data during the term of their subscription as defined in the Privacy Policy.
The Subscriber provides General Authorization for the Company to utilize the subprocessors listed in the Privacy Policy (including but not limited to Google Cloud, AWS, Render, and Cloudflare). The Company shall provide notice of any changes to its subprocessor list via the Subscriber Dashboard or official email notification.
The Company shall implement industry-standard security measures, including:
The Company shall notify the Subscriber without undue delay, and in any event within 72 hours, after becoming aware of a confirmed personal data breach affecting End-User data. The notice will include the nature of the breach and the Company's remediation plan.
Upon termination of the Agreement, the Company shall, at the Subscriber's choice, delete or return End-User personal data, excluding:
Subscriber's right to audit is limited to one remote inspection of Company's compliance documentation per calendar year. Such audit requires 30 days' written notice and must be conducted without disrupting the Company's standard business operations.
To the extent that the Subscriber is located in the EEA, UK, or Switzerland, the parties agree that the relevant Standard Contractual Clauses (SCCs)are incorporated herein by reference to ensure the legality of cross-border data transfers to the Company's US-based servers.
This DPA shall be governed by the laws of the State of New York without regard to conflict of law principles. Any disputes arising hereunder shall be resolved in the state or federal courts located in New York County.