Privacy policy
Privacy Policy
How GEME collects, uses, shares and protects personal data.
Last updated: 29 July 2026
1. Who We Are
ROKH SRL is responsible for the personal data described in this Policy unless another party is identified as an independent controller.
ROKH SRL
Boulevard Louis Schmidt 29, 1040 Etterbeek (Brussels), Belgium
Company registration: 0719.978.144
VAT number: BE0719978144
Privacy contact: info@gemebio.com
General contact: support@gemebio.com
2. Scope
This Policy applies to personal data processed through:
- gemebio.com and Shopify checkout, customer accounts and order services;
- GEME Life and related service portals;
- device registration, ownership binding and warranty services;
- GEME Dots, entitlements, referrals and benefit programmes;
- customer support, surveys, reviews and community features;
- marketing communications; and
- related online or offline interactions with GEME.
A third-party retailer, marketplace, payment provider or delivery provider may separately process personal data under its own privacy notice.
3. Personal Data We Collect
Identity and contact data
Name, email address, telephone number, billing and delivery address, account identifier and customer identifier.
Order and transaction data
Products ordered, order number, price, currency, tax and delivery details, payment status, refund and return history, and retailer or marketplace order identifier.
We do not normally retain complete payment-card details. Those details are processed by authorised payment providers.
Account and programme data
Login and verification information, GEME Dots balances and ledger entries, entitlements, tier, benefits, redemption history, referrals, surveys and programme participation.
Device and service data
Product model and serial number, registration and ownership-binding information, purchase channel, delivery date, warranty and GEME Care status, device status, diagnostic events, error codes, connectivity information, service history and support records.
Communications and content
Customer-service messages, reviews, survey answers, feedback, photographs, videos, files and community content that you choose to provide.
Technical and usage data
IP address, browser, device and operating-system information, cookie identifiers, pages viewed, interactions, approximate location derived from IP address, referral source, campaign information, and security or fraud indicators.
Marketing preferences
Subscription and unsubscribe status, consent records, communication preferences, and advertising or cookie choices.
4. How We Collect Data
We collect personal data directly from you; automatically when you use our website or services; from Shopify, payment and delivery providers; from authorised retailers or marketplaces where needed for warranty, registration or support; and from public business registers or sanctions-screening sources where necessary for verification or legal compliance.
5. How and Why We Use Personal Data
To process orders and provide services
We use data to manage checkout, payment confirmation, delivery, account access, device registration, product support, returns, refunds, warranty, GEME Care, entitlements and rewards. The legal basis is performance of a contract or steps requested before entering a contract.
To meet legal obligations
We use data for tax, accounting, product-safety, regulatory, sanctions, fraud-prevention and consumer-rights obligations.
To operate and protect our business
We use data for security, authentication, fraud detection, service monitoring, claim handling, internal reporting and enforcement of our terms. The legal basis may be contract, legal obligation or our legitimate interests in operating a secure and reliable business.
To improve products and services
We analyse support patterns, service performance, website use and aggregated product information. The legal basis may be our legitimate interests or consent where required.
To communicate about orders and services
We send transactional emails, delivery notifications, safety notices, service messages and recall communications. The legal basis may be contract, legal obligation or legitimate interests.
To send marketing
We send marketing with consent where required. Where local law permits existing-customer marketing on another lawful basis, we provide a clear opportunity to opt out. You may unsubscribe at any time. Service and safety messages are not marketing.
To personalise content and measure advertising
Non-essential cookies and similar technologies are used only with consent where required. You can manage those choices through Cookie Preferences.
6. Information Required to Provide Services
Certain information, such as delivery details, payment confirmation, product serial number for registration, and information needed to investigate a warranty claim, may be required to provide the requested product or service.
If required information is not provided, we may be unable to complete the order, register the device, verify an entitlement or assess the relevant support request.
7. Automated Checks
We may use automated indicators to identify suspected fraud, account abuse or security risks.
Where applicable law gives you rights concerning a decision based solely on automated processing that produces legal or similarly significant effects, we will provide the required information and opportunity for human review.
8. How We Share Personal Data
We may share personal data with:
- Shopify and e-commerce infrastructure providers;
- payment and fraud-prevention providers;
- warehouse, carrier and customs providers;
- cloud hosting, database and technical-service providers;
- customer-support and communication providers;
- analytics, consent-management and advertising providers;
- authorised repair and service partners;
- accountants, auditors, insurers and professional advisers;
- regulators, courts or law-enforcement bodies where legally required;
- a purchaser or successor in a genuine corporate transaction; and
- other parties where you direct or consent to the sharing.
Providers acting on our instructions may use the data only for contracted purposes and must apply appropriate security and confidentiality measures. Some providers may act as independent controllers for their own regulated or independently determined purposes; their privacy notices then also apply.
9. International Transfers
Personal data may be processed outside the country where you live.
Where required, we use an approved transfer mechanism, such as an adequacy decision, standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, contractual and technical safeguards, or another method permitted by applicable law.
You may contact us for information about the safeguards relevant to your data.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including completing and documenting orders, complying with tax and product-safety obligations, maintaining warranty and device-ownership records, resolving disputes, maintaining security, operating an active account, and preserving a minimal suppression record after an unsubscribe request.
Retention depends on the data category, applicable limitation periods, legal requirements and whether an account, device, claim or contract remains active. When data is no longer required, we delete, anonymise or securely restrict it.
11. Cookies and Similar Technologies
We use necessary technologies to operate the website. For visitors in the EU/EEA and United Kingdom, non-essential analytics, personalisation and advertising technologies are disabled unless and until valid consent is given. Further details appear in our Cookie Policy.
12. Marketing Choices
You can unsubscribe through the link in a marketing email or contact us. Unsubscribing from marketing does not prevent transactional, safety, account, warranty or service messages.
We may retain a minimal record of your opt-out so that we can respect it.
13. Your Privacy Rights
Depending on applicable law, you may have rights to access, obtain a copy, correct, delete, restrict or object to processing, withdraw consent, receive portable data, opt out of certain targeted advertising or sharing, request review of certain automated decisions, and complain to a privacy authority.
These rights may be subject to legal exceptions. We may need to verify your identity before responding. To exercise a right, email info@gemebio.com.
You may use an authorised agent where applicable law permits. We will not discriminate against you for exercising a privacy right.
14. European Union, EEA and United Kingdom
Where the GDPR or UK GDPR applies, you may complain to the supervisory authority in the country where you live or work, or where you believe an infringement occurred.
ROKH SRL is established in Belgium. The Belgian Data Protection Authority may be contacted subject to its legal competence.
15. United States
We do not sell personal information for money.
Some advertising or cross-context behavioural advertising activities may be treated as a "sale", "sharing" or targeted advertising under certain US state laws. Where those laws apply, you may use Cookie Preferences or another opt-out method that we make available.
Applicable residents may also have rights to know, access, correct, delete or obtain a copy of personal information and to appeal certain request decisions.
16. Canada and Quebec
Where Canadian privacy law applies, you may request access to or correction of personal information and may withdraw consent, subject to legal and contractual restrictions.
Withdrawal of consent does not affect processing already lawfully completed and may prevent us from providing a service that requires the relevant data.
Where Quebec law requires a French privacy notice or additional transparency, the applicable French version will be made available.
17. Children
Our products and services are intended for adults and are not directed to children under 16.
We do not knowingly collect personal data from a child in circumstances requiring parental consent without obtaining that consent. Contact us if you believe a child provided personal data improperly.
18. Security
We use reasonable technical and organisational measures designed to protect personal data. No online system is completely secure. You are responsible for protecting account credentials and should contact us promptly if you suspect unauthorised access.
19. Third-Party Links
Third-party websites and services have their own privacy practices. This Policy does not govern a third party acting independently of GEME.
20. Changes and Translations
We may update this Policy to reflect legal, technical or operational changes. We will change the Last updated date and provide additional notice where required for a material change.
Translated versions are intended to have the same meaning. Mandatory local-language and privacy requirements prevail.
21. Contact
Privacy requests: info@gemebio.com
General questions: support@gemebio.com
ROKH SRL
Boulevard Louis Schmidt 29, 1040 Etterbeek (Brussels), Belgium
