Global Privacy Notice
Document control
Document code: RJ-LS-11
Version: 3.8
Version date: 29 September 2026
Effective date: 1 October 2026
Issued by: Ralph Jacobs SA (Pty) Ltd (reg. 2019/101093/07) and Ralph Jacobs NZ Limited (company no. 9334729) — see Where We Sell for which company sells to you
Supersedes: all earlier published versions of this document
1. Responsible party / agency / controller
This Notice applies to personal information processed through Ralph Jacobs global e-commerce, showroom, consultation, payment, fulfilment, compliance, help centre, blog, media-hosting, campaign, review, email and after-sales operations.
The responsible Ralph Jacobs entity depends on the order, market and processing activity:
- For transactions with Ralph Jacobs SA (Pty) Ltd — orders delivered within South Africa — Ralph Jacobs SA (Pty) Ltd is the responsible party, and POPIA applies.
- For transactions with Ralph Jacobs NZ Limited — orders delivered to every other country — Ralph Jacobs NZ Limited is the agency responsible, and the New Zealand Privacy Act 2020 applies. Where the GDPR or UK GDPR applies because we are offering goods to you in the EU or UK, we comply with those in addition.
- Which company is responsible for your information follows the same allocation as which company sells to you. It is named on your order confirmation. See Where We Sell and Who You Buy From. Where the Australian Privacy Act, the GDPR or the UK GDPR applies to our processing, we comply with it in addition.
- JewelFix, our repair and claims division, is part of the same company, not a separate one. Information you give JewelFix, including at jewelfix.co, is held by the company responsible under this section and used for your repair or claim. It is used for marketing only where the law allows.
Contact:
- Telephone: +27 87 551 7635
- Privacy and access requests: privacy@ralphjacobs.org, or online at privacy.ralphjacobs.org
- Legal notices: legal@ralphjacobs.org
- Global legal hub: https://ralphjacobs.org
- Help centre: https://ralphjacobs.help
- Physical address: Shop 6B, Lake Umuzi Waterfront, 1 Kiewiet Street, Secunda, Mpumalanga, 2302, South Africa
- Registered office and address for legal service of documents: 1 Kiewiet Street, Lake Umuzi Waterfront, Secunda, Mpumalanga, 2302, South Africa
For transactions with Ralph Jacobs SA (Pty) Ltd
Information Officer / Head of Private Body: Rikus Kotzé, Director
Deputy Information Officer: Sameeya Dinat
Information Officer contact: privacy@ralphjacobs.org / +27 87 551 7635
Information Regulator registration number: 2026-067180, issued 19 September 2026
For transactions with Ralph Jacobs NZ Limited
Privacy Officer: Christiaan (Tiaan) Kotze
Privacy Officer contact: privacy@ralphjacobs.org
2. Personal information processed
Ralph Jacobs may process:
- identity and contact data, including names, surname, email address, phone/mobile number, account details, communication preferences and customer reference numbers;
- e-commerce and account data, including signup/account-creation records, login/session records, cart records, wish lists where used, order history, quote history, product selections and accepted legal-suite versions;
- billing, delivery and collection data, including billing address, delivery address, collection location, delivery recipient, collection recipient, courier instructions and proof of delivery/collection;
- jewellery and service data, including ring sizes, engravings, design preferences, CAD approvals, stone selections, resizing, repairs, warranty notes, valuation/appraisal notes and bespoke/customer-supplied-material records;
- payment, refund, chargeback and finance data, including payment method, proof of payment, refund route, banking proof, payment-provider reference, finance/credit/BNPL status and fraud-screening information;
- KYC, CDD and EDD data where required, including identity or passport details, date of birth, nationality, residential address, occupation or nature of business, authority to act, representative details, company/trust/partnership information, directors/members/trustees/partners/controlling persons, beneficial owners, payer details, source of funds, source of wealth, delivery/collection authority and supporting documents;
- screening and legal-compliance data, including sanctions, politically exposed person, prominent influential person, family/associate, adverse-media, fraud, unusual-transaction and risk-review outcomes;
- marketing and preference data, including email, SMS, WhatsApp, phone, social-platform or other campaign signup records, account-creation marketing preferences, consent wording/version, opt-out/suppression records, campaign source and campaign engagement where tracked;
- online and technical data, including website, storefront, help-centre, blog, media-hosting, cookie, pixel, tag, device, browser, IP address, approximate location, referrer, page-view, click, scroll, search, cart, checkout, consent-preference, campaign-attribution and security-log data;
- communication data, including emails, SMSs, WhatsApp messages, calls, social-media messages, website forms, help-centre tickets, complaint messages and legal requests;
- media data, including photographs, videos, CAD renders, repair images, production images, customer-supplied images, social-media content and approved marketing media;
- CCTV, visitor, access-control and premises-security information;
- regulator, dispute and legal data, including complaint records, PAIA/privacy requests, court/regulator/ombud correspondence, FIC/AML/CFT reporting evidence, tax/customs records and legal-claim material; and
- staff, contractor, supplier, service-provider and operator data where it is linked to customer service, compliance, security, accounting, fulfilment or business administration.
2A. Default collection points
Ralph Jacobs commonly collects personal information when a person:
- browses or uses a Ralph Jacobs website, storefront, help centre, blog, media page or campaign page;
- signs up, creates an account, subscribes to marketing, requests a quote or completes a form;
- places an order, pays, requests delivery, requests collection, returns an item or asks for a refund;
- communicates by email, SMS, WhatsApp, phone, social media, website form, help-centre ticket or in-store consultation;
- enters a bespoke, repair, resize, valuation, insurance, second-hand, trade-in, customer-supplied-material, high-value or credit-related process;
- submits KYC/CDD/EDD, FIC/AML/CFT, source-of-funds, source-of-wealth, beneficial-owner, authority, payer, delivery or collection information;
- interacts with emails, SMSs, WhatsApp messages, online advertisements, analytics tags, pixels or cookies where lawful; or
- is named by a customer, payer, entity, representative, beneficial owner, recipient, collector, supplier, staff member, regulator or legal adviser.
2B. Information collected from third parties
Ralph Jacobs may collect personal information about a person from someone other than that person where lawful and necessary. This may include information from a customer, payer, delivery recipient, collector, entity representative, beneficial owner, director, partner, trustee, supplier, courier, payment provider, fraud or screening provider, public source, government system, regulator, ombud, court, law-enforcement authority, professional adviser or another Ralph Jacobs entity.
Where New Zealand privacy law applies and we collect information about you from someone other than you, we will tell you that we have done so, what we collected and why, unless an exception in that law applies.
3. Purposes
Ralph Jacobs processes personal information to:
- operate websites, storefronts, help centre, blog, media hosting and digital platforms;
- create and manage accounts, signups, preferences, consents and opt-outs;
- respond to enquiries, forms and quotes;
- conclude and perform contracts;
- manufacture, source, resize, repair and deliver jewellery;
- process payments, refunds, chargebacks and fraud checks;
- verify billing, delivery, collection, recipient and courier details;
- operate customer service, help-centre, complaint, return, warranty and after-sales processes;
- provide service messages and transaction updates through email, SMS, WhatsApp, phone or other channels;
- send direct marketing, abandoned-cart, account, product, event, promotion, review or brand communications only where lawful and subject to opt-out rights;
- measure and improve websites, storefronts, campaigns, products, content, customer service, security and fraud controls;
- comply with FIC, AML/CFT, sanctions, tax/GST/VAT, accounting, customs, consumer, second-hand goods, PAIA, POPIA, New Zealand Privacy Act, Australian Privacy Act where applicable, court and regulatory duties;
- verify identity, authority, beneficial ownership, payer details, source of funds, source of wealth, sanctions, PEP/PIP/family/associate and adverse-media status where required;
- submit, file or disclose required information through government, regulator, tax, customs, ombud, court, law-enforcement, FIC/goAML, New Zealand FIU, AUSTRAC or other legally required systems;
- keep records and defend legal claims;
- secure premises, systems, payments and uploads;
- manage group-company, professional-adviser, service-provider, operator and third-party application relationships; and
- administer, audit and improve the business.
4. Lawful bases / legal basis
Ralph Jacobs does not rely on consent for every processing activity. Processing may be based on contract, legal obligation, legitimate interest, consent, protection of lawful interests, performance of a public-law duty where applicable, or another lawful basis under POPIA, the New Zealand Privacy Act, Australian Privacy Act, GDPR/UK GDPR or other applicable privacy law.
Consent may be withdrawn where processing is based on consent, including many direct-marketing and non-essential tracking uses. Withdrawal does not affect processing already done lawfully and does not stop processing required for contract, law, FIC/AML/CFT, fraud prevention, tax/customs, records, warranty, complaints, security or legal claims.
5. FIC, AML/CFT and high-value goods
For high-value goods, linked transactions, credit-provider relationships, third-party payers, entity customers, beneficial owners, third-party delivery or collection, unusual instructions, cash or high-risk payment patterns, suspicious indicators, sanctions/PEP/PIP concerns, second-hand jewellery, customer-supplied material, export/import activity or other South African FIC, New Zealand AML/CFT, Australian AML/CTF or global sanctions triggers, Ralph Jacobs may process identity, authority, beneficial-owner, payer, source-of-funds, source-of-wealth, delivery, collection, payment, transaction and screening information as required or permitted by applicable law.
Ralph Jacobs may use internal systems or third-party applications to collect, verify, screen, store, submit or audit this information. Ralph Jacobs may report or submit information to the FIC, goAML, New Zealand Police Financial Intelligence Unit, AUSTRAC, law enforcement, customs, tax authorities, ombuds, courts, regulators or other competent authorities where required or permitted by law and will not disclose suspicious-reporting decisions to customers.
6. Sharing
Ralph Jacobs may share personal information with:
- Ralph Jacobs group companies and related operating entities, including Ralph Jacobs SA (Pty) Ltd and RALPH JACOBS NZ LIMITED, where needed for shared brand, legal, order, fulfilment, compliance, customer-service, finance, marketing, support, IT, audit or group-administration purposes;
- payment providers, banks, card acquirers, payment gateways and credit/BNPL providers;
- courier, logistics, insurance and delivery partners;
- jewellery suppliers, laboratories, valuers and repair specialists;
- identity, KYC, CDD, EDD, fraud, sanctions, PEP/PIP, adverse-media, credit, affordability and screening providers;
- website, e-commerce, CRM, customer-support, help-centre, blog, media-hosting, cloud, SharePoint/document-storage, email, SMS, WhatsApp, analytics, advertising, consent-management, security, backup and IT service providers;
- marketing platforms, agencies, social-media platforms and advertising networks where lawful;
- professional advisers, accountants, auditors and attorneys;
- regulators, courts, law enforcement, tax/customs authorities, ombuds and government systems where required or lawful; and
- other parties with consent or where law permits.
Service providers who process personal information on our behalf are bound by written contract to process it only on our instruction and to keep it secure.
Two of these relationships are not ordinary service-provider relationships, and you should know about them:
- Meta Platforms Ireland Limited. For the website visit and conversion information our advertising tools send to Meta, Ralph Jacobs and Meta Ireland are joint controllers — both responsible, under a written arrangement. Section 5 of our Cookie Policy sets out what that means and how to exercise your rights.
- Buy-now-pay-later and credit providers. Where you choose one of these at checkout, that provider grants the credit under its own agreement with you and decides its own processing. It is not acting on our instruction. Its privacy terms apply to that, not ours.
6A. We will not discuss your order with anybody else
If you buy from us, your purchase is yours. We will not confirm to another person that you bought anything, what it was, what it cost, when you bought it, or what we discussed — including to a spouse, partner, fiancé, family member or the person the piece was bought for.
This is a privacy obligation, not a courtesy. Order details, purchase history and prices are your personal information, and section 11 of the Protection of Personal Information Act allows us to use and disclose them only for the purposes we collected them for. An engagement ring is the clearest case: a great deal of the reason people trust us with one is that we do not tell anybody.
You can authorise somebody else. Send us an email from the address on your order naming the person and what they may deal with. We will note it on your file, and you can withdraw it the same way.
Where we are legally obliged to disclose — a court order, a regulator, the Financial Intelligence Centre — we comply, as section 6 sets out. Nothing else overrides this.
If you are wearing a piece somebody else bought you and it is faulty, we will deal with the fault. We simply will not, in doing so, tell you what was paid or when it was bought. See section 2A of Terms and Conditions.
7. Cross-border disclosures and transfers
Some Ralph Jacobs entities, service providers, cloud systems, e-commerce platforms, CRM/help-centre systems, marketing platforms, laboratories, payment tools, communications platforms, analytics tools, media-hosting platforms, fulfilment partners, screening providers, professional advisers or government/regulator systems may process information outside the country where the customer or entity is located.
We only send your information outside your country where we have a lawful basis to do so and appropriate safeguards are in place. This may include POPIA transfer safeguards, New Zealand Privacy Act cross-border disclosure checks, Australian Privacy Principle 8 checks, GDPR/UK GDPR adequacy or transfer safeguards, contractual safeguards and vendor due diligence.
If you want the detail — which system holds what, and which country it sits in — section 8.4 of our PAIA Manual sets it out in a table.
8. Retention
Ralph Jacobs keeps personal information only as long as reasonably necessary for the purpose collected, unless a longer period is required or permitted for FIC/AML/CFT, tax/GST/VAT, customs, accounting, warranty, legal claims, dispute resolution, audit, security or regulatory reasons.
We keep FIC/AML/CFT, KYC/CDD/EDD, tax/GST/VAT, customs, accounting, credit, second-hand goods and regulator records for at least the period the law of the relevant country requires. Marketing opt-out and suppression records may be kept to prove that Ralph Jacobs no longer markets to a person.
9. Direct marketing
We send direct marketing by email, SMS, WhatsApp, phone, social media, online advertising, pixels, tags or other digital channels only where allowed by the CPA, POPIA, New Zealand Privacy Act and Unsolicited Electronic Messages Act where applicable, Australian Spam Act where applicable, EU/UK rules where applicable, and other applicable direct-marketing rules.
We collect marketing consent or preferences during signup, account creation, checkout, quote requests, website forms, help-centre requests, events, promotions or customer communications. Customers may opt out at any time through the unsubscribe/opt-out route supplied in the message or by contacting privacy@ralphjacobs.org.
Where South Africa’s national opt-out registry applies to a marketing channel we use, we check our lists against it and suppress anyone who has blocked marketing.
We may track whether marketing messages are delivered, opened, clicked, responded to, opted out of or otherwise engaged with where lawful and disclosed through this Notice and the Cookie Policy.
10. Security
We use reasonable technical and organisational safeguards appropriate to the sensitivity of the information, including access controls, staff training, secure upload processes, retention rules, confidentiality, vendor controls, breach assessment and incident response.
We do not accept identity or verification documents by email. Where we need them, you complete a form at kyc.ralphjacobs.org — which stores nothing you type — print and sign it, and upload it with your supporting documents to the secure upload at kyc.ralphjacobs.org/upload. That is the only route we accept, and anyone asking you to send such documents another way is not us. See Payments and Verification section 7A.
11. Rights
Data subjects may request access, correction, deletion, objection, restriction where applicable, proof of authority, portability where applicable, or direct-marketing opt-out by contacting privacy@ralphjacobs.org.
Complaints may be lodged with the South African Information Regulator, New Zealand Privacy Commissioner, OAIC, EU/UK supervisory authority or other competent privacy regulator where applicable.
12. If you are outside South Africa
This Notice applies wherever you are. Your own country’s privacy law may give you additional rights, and where it does, those rights apply.
- New Zealand. The Privacy Act 2020 gives you rights of access and correction, and requires us to tell you when we collect information about you from someone other than you.
- Australia. The Australian Privacy Principles may apply to information we hold about you.
- European Union and United Kingdom. Where the GDPR or UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority.
Whatever your location, you can exercise your rights online at privacy.ralphjacobs.org (recommended: it lets you upload proof of identity securely), with our fillable form, or by emailing privacy@ralphjacobs.org. We will not charge you for a reasonable request about your own personal information, and we will not treat you differently for making one.
A request for a company record — as opposed to your own personal information — is a different thing. In South Africa that is a request under the Promotion of Access to Information Act, and the fees for it are fixed by regulation rather than by us. They are set out in our PAIA Manual.
13. Changes
We may update this Notice. The version that applies to you is the one published at the time we dealt with you, and every version we have published is kept at ralphjacobs.org/versions/.
Every legal publication issued by Ralph Jacobs, grouped by category. Each entry shows its current version, status and effective date. Superseded and withdrawn versions are retained permanently and stay reachable at their original addresses, so a version you accepted or downloaded in the past can still be read and verified.
