PeaceGold Jewellery Community Workshop
Privacy Policy
Last updated: 31 July 2026
This Privacy Policy explains how PeaceGold collects, uses and protects your personal data when you visit our website, book a class, commission work from us, or otherwise get in touch. We are committed to protecting your privacy and handling your information openly and responsibly.
We handle personal data in accordance with UK data protection law, namely the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”), in each case as amended by the Data (Use and Access) Act 2025.
1. Who we are
PeaceGold is a trading name of Valerio Jewellery Limited, a company registered in England and Wales under company number 15819668, whose registered office is at 53 Fore Bondgate, Bishop Auckland, County Durham, DL14 7PE. Valerio Jewellery Limited is the “data controller” responsible for your personal data.
If you have any questions about this policy or about how we use your information, please contact us atcontact@peacegold.org, or write to us at the address above.
2. The personal data we collect
Depending on how you interact with us, we may collect:
• Identity and contact details — your name, email address, telephone number and postal address.
• Booking information — the classes or services you book, dates, and any preferences you tell us about.
• Health and accessibility information — where you choose to tell us about an allergy, medical condition, pregnancy or additional need. This is “special category” data and is covered separately in section 3.
• Payment information — your payment is processed securely through Squarespace, our website and payment provider. We receive confirmation that a payment has been made but do not collect or store your full card details.
• Bespoke and repair details — information about the piece you would like us to make, repair or remodel, including any details you share about its history or significance.
• Photographs — images taken in the workshop or of finished pieces, where you have agreed (see section 6).
• Marketing preferences — whether you have chosen to receive our newsletter or other updates.
• Correspondence — messages you send us and our replies.
• Website and technical data — information collected automatically when you use our site, such as your device type, browser and how you use our pages, gathered through cookies (see section 13).
Where a young person aged 16 or 17 is booked onto a class, we collect the young person’s details together with the parent or guardian’s details (see section 9).
3. Health and accessibility information
Our classes involve tools, heat and chemicals, so we ask you to tell us about anything that might affect your safety or your ability to take part — for example an allergy, a medical condition, pregnancy, or a disability for which you would like an adjustment.
Information about your health is “special category” personal data, which the law protects more strictly. We rely on your explicit consent under Article 9(2)(a) of the UK GDPR, together with consent under Article 6(1)(a), to hold and use it. You give that explicit consent by choosing to provide the information when you book or before your class; you do not have to give it, and you can withdraw your consent at any time by contacting us, although this may mean we cannot make certain adjustments or confirm that a class is suitable for you.
If there is a medical emergency during a class and you are not able to give consent yourself, we may share relevant health information with emergency services or medical staff in order to protect your life or someone else’s. Where we do that, we rely on vital interests under Articles 6(1)(d) and 9(2)(c).
We use this information only to keep you safe and to make reasonable adjustments. It is seen only by the tutors and staff involved in your session, is never used for marketing, and is deleted within 30 days of your class unless you have asked us to keep it for future bookings.
4. How we collect your data
We collect most of this information directly from you — when you book a class, make an enquiry, commission a piece, sign up to our newsletter, or contact us. Some technical data is collected automatically through cookies when you use our website. We may also receive limited information from the service providers who help us run bookings and payments.
5. How and why we use your data
We only use your personal data where the law allows us to. Below sets out what we do, why, and the lawful basis under the UK GDPR that we rely on.
What we do Why (purpose) Lawful basis Take and manage your class booking To provide the class or service you have booked and paid for Performance of a contract — Art 6(1) (b)
Handle payment To take payment and keep financial records Contract — Art 6(1)(b); Legal obligation — Art 6(1)(c)
Contact you about your booking To send confirmations, joining details and any changes Performance of a contract — Art 6(1) (b)
Keep you safe in the workshop To take account of an allergy, medical condition, pregnancy or additional need you have told us about, and make reasonable adjustments Consent — Art 6(1)(a), and explicit consent for health data — Art 9(2)(a)
Respond to a medical emergency To pass relevant health information to emergency services if you are unable to tell them yourself Vital interests — Art 6(1)(d) and Art 9(2)(c)
Provide bespoke, repair or remodelling work To design, quote for and complete your commission Performance of a contract — Art 6(1) (b)
Take and use photographs of people To show our classes and work on our website and social media, where you have agreed Consent — Art 6(1)(a)
Keep our records and accounts To meet tax, accounting and legal duties Legal obligation — Art 6(1)(c)
Send marketing and our newsletter To tell you about classes, events and news, if you have opted in Consent — Art 6(1)(a)
Improve and secure our website To run our site, understand how it is used and keep it safe Legitimate interests — Art 6(1)(f)
Handle enquiries and complaints To respond to you and resolve any issues Legitimate interests — Art 6(1)(f)
Where we rely on legitimate interests, we have considered your rights and interests and are satisfied that our use of your data is fair and does not override them. Where we rely on consent — for health information, photographs or marketing — you can withdraw it at any time, and withdrawing it will not affect anything we did lawfully beforehand.
6. Photography and images
We love showing the work that happens in our workshop, and we sometimes take photographs of classes in progress and of finished pieces for our website, printed materials and social media.
• We will always ask for your permission before using a photograph in which you or another participant is identifiable, and we ask for that permission separately from your booking.
• You are free to say no, and saying no will never affect your place on a class or the service you receive.
• You can change your mind at any time by emailing us. We will stop using the image going forward and remove it from our own website and social media accounts, although we may not be able to recover copies that others have already shared or reposted.
• Where a participant is aged 16 or 17, we ask for the agreement of both the young person and their parent or guardian before using an identifiable image.
Photographs of a finished piece on its own, with no identifiable person in the image, are not personal data, but if you would rather we did not publish images of your commission at all, just tell us and we will note that on your record.
7. Marketing and our newsletter
We would love to keep you up to date with our classes, events and news, but only if you want us to. We will only send you marketing by email where you have given us your consent — for example, by ticking a sign-up box. Every marketing email we send includes an easy way to unsubscribe, and you can opt out at any time by clicking “unsubscribe” or by emailing us at contact@peacegold.org. Withdrawing consent will not affect any bookings or services you have with us. We do not use young people’s data for marketing.
8. Who we share your data with
We do not sell your personal data, and we never will. We share it only where necessary to run our services, with trusted providers who act on our instructions as our “data processors”, including:
• Squarespace, which provides and hosts our website and processes your class bookings and payments;
• Our email and newsletter provider, where you have signed up to hear from us;
• Professional advisers such as our accountant, and, where required, HM Revenue & Customs;
• A UK Assay Office, where a piece needs to be hallmarked before it is passed to you; and
• Suppliers for a bespoke commission, where limited information is needed to complete your piece — for example, to source a stone.
We only share the minimum information needed, and we require these providers to keep it secure and to use it only for the purposes we specify. We may also disclose information where we are legally required to do so.
9. Children’s and young people’s data
Some of our classes are open to young people aged 16 to 17, who may only be booked on with the consent of a parent or guardian. We recognise that a young person’s information deserves particular care. We collect only what we need to run the class safely and to stay in contact with the parent or guardian, we keep it no longer than necessary, we do not use it for marketing, and we ask for the agreement of both the young person and their parent or guardian before using any identifiable photograph. If you are a parent or guardian and would like to know what we hold about your child, please contact us.
10. How long we keep your data
We keep your personal data only for as long as we need it, and then delete or anonymise it securely. Our normal retention periods are:
• Booking and class records — 2 years from your last class or contact with us.
• Health and accessibility information — deleted within 30 days of the class, unless you ask us to keep it for future bookings.
• Bespoke, repair and remodelling records — 6 years, so that we can support you with later repairs, resizing or valuation queries.
• Financial and accounting records — 6 years from the end of the financial year they relate to, as required by tax law.
• Enquiries that do not lead to a booking — 12 months.
• Marketing records — until you unsubscribe or ask us to remove you, and we review our list every 2 years.
• Photographs of identifiable people — until you withdraw your consent.
Where we need to keep something longer — for example, because of an ongoing complaint or legal claim — we will keep it only for as long as that requires.
11. Your rights
Under UK data protection law, you have the following rights over your personal data:
• The right to be informed about how we use your data — which this policy provides.
• The right of access — to ask for a copy of the personal data we hold about you.
• The right to rectification — to have inaccurate data corrected.
• The right to erasure — to ask us to delete your data in certain circumstances.
• The right to restrict processing — to ask us to limit how we use your data.
• The right to data portability — to receive certain data in a portable format.
• The right to object — to object to certain uses of your data, including direct marketing.
• The right to withdraw consent — at any time, where we rely on your consent.
To exercise any of these rights, please contact us at contact@peacegold.org. We will respond within the time limits set by law, which is normally within one month. We do not make any decisions about you based solely on automated processing.
12. Complaints about how we handle your data
You have a right under section 164A of the Data Protection Act 2018 to complain directly to us if you think we have handled your personal data wrongly. You can make a complaint:
• using the data protection complaint form on our website;
• by email to contact@peacegold.org; or
• by post to Valerio Jewellery Limited, 53 Fore Bondgate, Bishop Auckland, County Durham, DL14 7PE.
We will acknowledge your complaint within 30 days of receiving it. We will then look into it without undue delay, keep you updated on how it is progressing, and tell you the outcome and the reasons for it.
You can also complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk, or by calling its helpline on 0303 123 1113. You do not have to come to us first, but we would welcome the chance to put things right.
13. Cookies
Our website uses cookies and similar technologies. Some are essential for the site to work and to keep it secure; these are always active. Others are optional and are only used if you agree through our cookie banner, which lets you accept or reject optional cookies just as easily. You can change your choice at any time through the banner or your browser settings, though blocking some cookies may affect how parts of the site work.
Cookie Purpose Duration Type crumb Security — protects forms against crosssite request forgery Session Essential
JSESSIONID Keeps your session active while you browse and book Session Essential
ss_cookieAllowed Remembers the cookie choice you made on our banner 30 days Essential
ss_cid, ss_cvisit, ss_cvr Squarespace Analytics — measures visits and how the site is used Up to 2 years Optional
Third-party cookies Set by embedded content such as video or maps, where used Varies Optional
Some cookies used purely to count visitors and improve how our site works are now exempt from the consent requirement under the Data (Use and Access) Act 2025. We still tell you about them here so that you know what is being used and why.
14. Storing and transferring your data
We take appropriate technical and organisational measures to keep your personal data secure and to protect it against unauthorised access, loss or misuse.
Some of our service providers, including Squarespace, are based in the United States and may store or process data outside the UK. Where that happens, we make sure one of the safeguards recognised by UK law is in place, namely:
• a UK adequacy decision — which includes the UK Extension to the EU–US Data Privacy Framework (the “UK–US Data Bridge”), where the provider is certified under it; or
• the ICO’s International Data Transfer Agreement (IDTA), or the UK Addendum to the European Commission’s Standard Contractual Clauses.
These safeguards are intended to ensure your data continues to receive essentially the same protection as it would in the UK. You can ask us for more detail about the safeguards that apply to a particular provider.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or the law. The current version is always the one published on our website, and we will show the date it was last updated at the top of this page.
16. How to contact us
Valerio Jewellery Limited, trading as PeaceGold
Registered office: 53 Fore Bondgate, Bishop Auckland, County Durham, DL14 7PE
Email: contact@peacegold.org
Registered in England and Wales, company number 15819668