Last updated: July 17, 2026
JTR — Jewellery Technology Research (“JTR”, “we”, “us”, “our”) designs and builds diamond-detection instruments, operates accredited gemology laboratories, runs the JTR Academy, and sells and supports these products and services through this website and store (together, the “Services”). This Privacy Policy explains what personal data we collect, why we process it, whom we share it with, how long we keep it, and the rights you have over it — including data you share with us through messaging channels such as WhatsApp, Facebook Messenger and Instagram.
We process personal data in accordance with the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where it applies to you, the EU General Data Protection Regulation (2016/679) and the UK GDPR (together, “GDPR”). Where this Privacy Policy and our Terms & Conditions conflict on the handling of personal data, this Privacy Policy controls.
Please read this Privacy Policy carefully. By using the Services or communicating with us, you acknowledge that you have read and understood it.
The data controller (veri sorumlusu under the KVKK; “controller” under the GDPR) that determines the purposes and means of processing your personal data is:
JTR Jewellery Technology Research
580 5th Avenue, Ste 629, New York, NY 10036, United States
Phone: +1 (917) 268-4747
Email: jtr.nyc@jtr.org
You can contact us about any data-protection matter, or to exercise your rights, using the details above or in Section 15. If you require our registered establishment, VERBİS registration or KEP (registered electronic mail) address for a formal KVKK application, or the details of our representative in the European Union or United Kingdom, we will provide them on request.
Depending on how you interact with us, we may collect or process the following categories of personal data, together with any inferences drawn from it:
We do not seek to collect special categories of personal data (such as health, biometric or religious data). Please do not send us such data through any channel unless we specifically request it and set out a lawful basis for doing so.
We only process personal data where we have a lawful basis to do so. Under the KVKK (Articles 5 and 6) and the GDPR (Article 6), we rely on the following bases, depending on the purpose:
You can reach JTR through third-party messaging services operated by Meta Platforms — WhatsApp (including the WhatsApp Business Platform), Facebook Messenger and Instagram Direct. If you contact us on these channels, we process the following as part of that conversation:
Why. We use messaging data to respond to your enquiries, provide order and product support, arrange bookings and appointments, and — only where you have opted in — send you permitted business or promotional messages. Our legal bases are performance of a contract and our legitimate interest in responding to conversations you start; for marketing messages we rely on your consent.
Meta’s role. The messaging platforms are provided by Meta, which transmits and processes your messages as the platform operator under its own terms and privacy policy. WhatsApp messages are protected by end-to-end encryption in transit. When you message us, Meta processes that interaction in accordance with its own WhatsApp and Meta privacy policies, over which we have no control. We receive and store a copy of the conversation in our own customer-support systems to serve you and keep a record of our correspondence.
What we do not do. We do not sell your messaging data, and we do not share the contents of your messages with third parties for their own marketing. We use messaging data only for the purposes described here and share it only with the processors that operate our support systems (Section 8).
Retention. We keep messaging records for as long as needed to resolve your enquiry and to keep a reasonable record of our dealings with you, and then delete or anonymise them in line with Section 12. You can ask us to delete your conversation with us at any time (Section 10), and you can manage or delete messages on your own device through the platform.
We use cookies and similar technologies to operate the Services, remember your preferences and locale, keep your cart, secure sign-in, and — with your consent — to measure usage and support marketing. Strictly necessary cookies are used on the basis of our legitimate interest in providing a working, secure website; all other categories are used only with your consent, which you can manage or withdraw at any time. You can also control cookies through your browser settings, though disabling some may affect how the Services work.
We share personal data only where necessary and under appropriate safeguards, including with:
Our providers act as our processors (veri işleyen) and are bound by contracts requiring them to protect your data and use it only on our instructions, except where they act as independent controllers under their own policies (such as Meta and our payment providers).
JTR operates across Türkiye, the European Union and the United States, and some of our providers are located abroad. This means your personal data may be transferred to, stored in, or accessed from countries other than the one you live in. Where we transfer personal data internationally, we rely on a lawful transfer mechanism:
Subject to the conditions and exceptions in applicable law, you have the following rights over your personal data.
Under the KVKK (Article 11), you may: learn whether your data is processed and request information about it; learn the purpose of processing and whether it is used accordingly; learn the third parties to whom it is transferred at home or abroad; request correction of incomplete or inaccurate data; request its erasure or destruction; request that these actions be notified to third parties to whom the data was transferred; object to a result arising solely from automated analysis of your data; and claim compensation for damage arising from unlawful processing.
Under the GDPR (Articles 15–22), you may: access your data; have it rectified; have it erased; restrict or object to its processing; receive it in a portable format; withdraw consent; and not be subject to solely automated decisions with legal or similarly significant effects.
How to exercise your rights. Contact us using the details in Section 15. KVKK applications may be made in writing or through the methods set out in the Communiqué on Application Procedures, including via your registered electronic mail (KEP) address; we respond within the statutory period (at most 30 days). We may need to verify your identity before acting on a request, and you may appoint an authorised agent. We will not treat you unfairly for exercising your rights.
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Some fraud-prevention and security checks are automated, but they do not by themselves determine outcomes without human involvement where required by law.
We take appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, disclosure or alteration, including access controls, encryption in transit, and secure hosting. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; please avoid sending sensitive information over unsecured channels.
We keep personal data only for as long as necessary for the purposes set out in this Privacy Policy — typically for the duration of your relationship with us and thereafter for the periods required to meet legal, accounting, tax and dispute-resolution obligations. When data is no longer needed, we delete or anonymise it, and we destroy it in line with our KVKK retention-and-destruction policy (saklama ve imha politikası).
The Services are intended for businesses and adults and are not directed at children. We do not knowingly collect personal data from children under the age of majority in your jurisdiction. If you believe a child has provided us with personal data, please contact us and we will delete it.
If you have concerns about how we handle your personal data, please contact us first using the details below so we can address them. You also have the right to lodge a complaint with a supervisory authority — in Türkiye, the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu); in the EEA, your local data protection authority; and in the UK, the Information Commissioner’s Office (ICO).
For any question about this Privacy Policy, our data practices, or to exercise your rights, please contact us:
JTR Jewellery Technology Research
580 5th Avenue, Ste 629, New York, NY 10036, United States
Phone: +1 (917) 268-4747
Email: jtr.nyc@jtr.org
We may update this Privacy Policy from time to time to reflect changes in our practices or for operational, legal or regulatory reasons. We will post the revised version here, update the “Last updated” date above, and provide any further notice required by applicable law.