GDPR Addendum

Home / GDPR Addendum

Romanian Version

Effective May 25, 2018, The General Data Protection Regulation (GDPR) (EU) 2016/679, a regulation in EU law, will regulate data protection and privacy for all individuals within the European Union. It also addresses the export of personal data outside the EU. The GDPR replaces the 1995 Data Protection Directive. It is supported by Privacy Shield which is still in effect, and described in our Privacy Policy.

ARTFIRST is committed to your privacy. This GDPR Addendum explains our collection, use, disclosure, retention, and protection of your personal information, as EU Data Subjects, in the manner compliant with the regulations set forth in the GDPR

Table of Contents

  1. Scope
  2. Personal information we collect
  3. How we use your personal information
  4. Your choices about how we use your personal information
  5. Ways you can access, control, and correct your personal information
  6. How we might share your personal information
  7. How long we keep your personal information
  8. Cookies & Similar Technologies
  9. How do we protect your personal information
  10. Global Privacy Standards
  11. Data Controllers and Data Protection Officers
  12. Other important privacy information
  13. Contact Us

Scope

This privacy notice applies to any ARTFIRST website, application, service, or tool (collectively “Services”) where this privacy notice is referenced, regardless of how you access or use them, including through mobile devices.

Learn more: Scope

This privacy notice applies to any ARTFIRST website, application, service, or tool (collectively “Services”) where this privacy notice is referenced, regardless of how you access or use them, including through mobile devices.

This privacy notice also applies to the provision of ARTFIRST services through any ARTFIRST partner’s website, application, service, or tool where it is referenced and where your listings and their content are published or advertised in accordance with the terms of this privacy notice.

We may amend this privacy notice at any time by posting the amended version on this site including the effective date of the amended version. We will announce any material changes to this privacy notice through the ARTFIRST Message Center and/or via email.

Lawful Bases

Regarding the lawful bases required by article 5 and the specific bases considered lawful under article 6 of GDPR, two lawful bases apply depending on the data and its use:

Consent: The data subject has freely given consent for their information to be processed for a specific purpose.

For all processing involved with educating the consumer about what is available and what each might find of particular interest, and all data collection involved with improving the quality of our services and your experience with using them, commonly known as Marketing and User Experience, our lawful basis is consent, freely given, as defined by GDPR.

Legitimate Interest: processing is necessary for the purposes of the legitimate interests pursued by the controller

For the provision of a transaction marketplace, once a hopeful buyer starts the process that ultimately could lead to a purchase, that process is controlled by our Legitimate Interest in your data, all of which is used to manage the transactions and provide services for the buying process, and some of which are used in support of the contract entered into directly with the seller once the buying process is initiated. This would include the collection of data to fulfill the contract including address and credit card data. Legitimate Interest is the basis for processing and retaining data to facilitate authorization to bid, fraud detection, the provision of a a safe and secure marketplace including the open market processing itself, the placement of price offers through bidding or buy now, the completion of those purchases by both buyers and sellers, and the correct and lawful conclusion and accounting for those purchases. All this data collection and processing has its legal basis in article 6: Legitimate Interest.

Who Controls Your Information

Regardless of where you are in the world when you access our services, you are contracting with:

ARTFIRST, SRL
str. Nucului, nr. 6, bl. V-106,sc. 2, et. 3, ap. 41, Sector 3

ARTFIRST SRL is your data controller, and is responsible for the collection, use, disclosure, retention and protection of your personal information in accordance with our global privacy standards, this privacy notice, as well as any applicable national laws.

Your data controller may transfer data to other members of the ARTFIRST, SRL. corporate family who have agreed to follow the policy set forth by ARTFIRST, SRL, as described in this privacy notice.

We may process and retain your personal information on our servers in the U.S. and elsewhere in the world where our data centers are located.

Where we have a legal obligation to do so, we have appointed data protection officers (DPOs) to be responsible for the privacy program at each of the respective data controllers.

Personal information we collect

What is personal information?

Personal Information is information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

We do not consider personal information to include information that has been anonymized or aggregated so that it can no longer be used to identify a specific natural person, whether in combination with other information or otherwise.

We collect personal information from you when you use our Services.

Learn more: Personal information we collect

We collect personal information from you and any devices (including mobile devices) you use when you: use our Services, register for an account with us, provide us information on a web form, update or add information to your account, or when you otherwise correspond with us.

Some of this personal information, such as a verifiable way to identify you, is necessary to enter into our Terms Agreement. The provision of all other personal information is voluntary, but may be essential in order to use our Services, such as the bidding, buying or selling information needed to conclude a transaction.

We may also collect personal information from other sources, as described below.

Personal information you give us when you use our Services or register for an account with us

  • Identifying information such as your name, addresses, telephone numbers or email addresses when you register for an account with us
  • Bidding, buying, or selling information you provide during a transaction, or other transaction-based content that you generate or that is connected to your account as a result of a transaction you are involved in
  • Other content that you generate, or that is connected to your account (such as adding items to your Watch List, Favorites, etc.)
  • Financial information (such as credit card or bank account numbers) in connection with a transaction.
  • You may also provide us other information through a web form, by updating or adding information to your account, through your interactions with our customer care agents, form based communications with houses, dispute resolution, or when you otherwise communicate with us regarding our Services
  • Additional information we are required or authorized by applicable national laws to collect and process in order to authenticate or identify you or to verify the information we have collected

information we collect automatically when you use our Services or register for an account with us

  • We collect information about your interaction with our Services, your advertising preferences, and your communications with us. This is information we receive from devices (including mobile devices) you use when you access our Services. This information could include the following: Device ID or unique identifier, device type, ID for advertising, and unique device token
  • Location information, including location information from your mobile device. Keep in mind that most mobile devices allow you to control or disable the use of location services by any application on your mobile device in the device’s settings menu. Location can also be derived from your network (IP) address.
  • Computer and connection information such as statistics on your page views, traffic to and from the sites, referral URL, ad data, your IP address, your browsing history, and your web log information

Personal information we collect using cookies and similar technologies

  • We use cookies, web beacons, unique identifiers, and similar technologies to collect information about the pages you view, the links you click, and other actions you take when using our Services, within our advertising or email content

Personal information collected from other sources

  • We supplement the personal information we collect directly with information collected from third parties and add it to your account information. For example, we collect and use demographic and other information that is publicly available in an applicable jurisdiction, additional contact information, credit check information, and information from credit bureaus, as allowed by applicable national laws
  • Social Media: We allow you to share information with social media sites. We do not use social media sites to create your account, or to connect your account with the respective social media site. When you interact with ARTFIRST content on various media platforms (e.g. Facebook, Instagram) we see that content and your identity, as per your privacy options with the particular platform in question. We do not store this content on our systems. It remains entirely subject to the privacy policies of each platform
  • We only use anonymized analytical data from social media platforms in the aggregate, (e.g., content viewed by our users, content liked by our users, and information about the advertisements our users have been shown or have clicked on, etc.). You control the personal information you allow us to have access to in aggregate through the privacy settings on the applicable social media site.
  • If you give us personal information about someone else through communication with us regarding our Services, you must do so only with that person’s authorization. You should inform them how we collect, use, disclose, and retain their personal information according to our privacy notice

How we use your personal information

We use your personal information to provide and improve our Services, provide you with a personalized experience on our sites, contact you about your account and our Services, provide you customer service, provide you with personalized advertising and marketing, to detect, prevent, mitigate, investigate and track fraudulent or illegal activities, and to track actions related to the exercise of contractual obligations between our marketplace buyers and sellers.

Learn more: How we use your personal information

We use the personal information we collect from you for a range of different business purposes and according to different legal bases of processing. The following is a summary of how and according to which legal bases we use your personal information.

We use your personal information to fulfill a contract with you and provide you with our Services, to comply with our legal obligation, protect your vital interest, or as may be required for the public good. This includes:

  • To provide payment processing and account management, operate, measure and improve our Services, keep our Services safe, secure and operational, and customize site content that includes items and services that you may like in response to actions that you take
  • To contact you regarding your account, to troubleshoot problems with your account, to resolve a dispute, to collect fees or monies owed or as otherwise necessary to provide you customer service
    • When contacting you for such purposes as outlined above, we may contact you via email, telephone, SMS/text messages, postal mail, and via mobile push notifications
    • When contacting you via telephone, to ensure efficiency, we may use autodialed or pre-recorded calls and text messages as described in our Terms Agreement and as authorized by applicable law. Message and data rates may apply
  • To provide other services requested by you as described when we collect the information
  • We use general location information to provide you with location based services (such as advertising, search results, and other personalized content)
  • To prevent, detect, mitigate, and investigate fraud, security breaches or other potentially prohibited or illegal activities
  • To enforce our Terms And Conditions Agreementthis privacy notice, or other policies as well as contracts between buyers and sellers, and to monitor for multiple, fake, unauthorized, aliased, or misleading personal accounts for violations of our policies, seller/buyer contracts, or applicable laws.

We use your personal information to pursue our legitimate interests where your rights and freedoms do not outweigh these interests. We have implemented controls to balance our interests with your rights. This includes to:

  • Improve our Services, for example by reviewing information associated with stalled or crashed pages experienced by users allowing us to identify and fix problems and give you a better experience
  • Personalize, measure, and improve our advertising based on your advertising customization preferences
  • Contact you via email or postal mail in order to offer you coupons, discounts and special promotions, poll your opinions through surveys or questionnaires and inform you about our Services, as authorized by applicable law
  • Deliver targeted marketing, service updates, and promotional offers based on your communication preferences
  • Measure the performance of our email marketing campaigns (e.g. by analyzing open and click rates)
  • Measure sellers’ performance (e.g. by using shipment tracking information that sellers and shipping providers send or provide through ARTFIRST)
  • Monitor and improve the information security of our site and mobile applications
  • Use your sensitive personal information to facilitate transactions in certain categories

You have the right to object to this processing at any time. Please contact contact@artfirst.ro with your objections and we will deal with them in a timely manner in compliance with the regulations.

With your consent, we may use your personal information to:

  • Provide you with marketing via telephone calls, email, SMS or text
  • Provide you with marketing from other ARTFIRST SRL. corporate family members
  • Provide you with marketing from third parties most notably our sellers
  • Customize third party advertising you might see on third party websites
  • Use your precise geo-location to provide location based services

You have the right to withdraw your consent at any time. You can do so through our ARTFIRST mobile app settings pages or, if you cannot easily find the appropriate pages, through contact with contact@artfirst.ro with your objections and we will deal with them in a timely manner in compliance with the regulations.

We may use technologies that could be considered automated decision making or profiling. We will not make automated decisions about you that would significantly affect you, unless such a decision is necessary as part of a contract we have with you or that we have with our sellers, we have your consent, or we are required by law to use such technology.

Your choices about how we use your personal information

You have choices about how we use your personal information to communicate with you, to send you marketing information, how we provide you with customized and relevant advertising, and whether you want to stay signed into your account.

Learn more: Your choices about how we use your personal information

Communication preferences

You can control your email communication preferences by emailing us at contact@artfirst.ro.

Marketing

If you do not wish to receive marketing communications from us, you can unsubscribe via the link in an email you received, change your Communication Preferences within ARTFIRST mobile app, indicate your communication preferences using the method described within the direct communication from us or contact us as described in the Contact Us section below. Keep in mind, we do not sell, rent, or otherwise disclose your personal information to third parties for their marketing purposes without your consent.

Advertising

If you do not wish to participate in our advertising personalization programs, you can opt-out by following the directions provided within the applicable advertisement. The effect of an opt-out will be to stop personalized advertising, but it will still allow the collection of personal information as otherwise described in this privacy notice. We do not allow third parties to track or collect your personal information on our sites for their own advertising purposes, without your consent.

Staying Signed in

When you sign in to your account on our Services, we give you the option to stay signed in to your account for certain amount of time. If you are using a public or shared computer, we encourage you not to choose to stay signed in. You or any other user of the computer/browser you signed in on will be able to view and access most parts of your account and take certain specific actions during this signed in period without any further authorization. The specific actions and account activities that you or any other user of this computer/browser may take include:

  • Bid, buy or make an offer on an item
  • Canceling auction bids in a timely fashion (Once an offered lot is close, the disposition of the sale is controlled by auction house terms of sale, and are typically final.)
  • View the ARTFIRST mobile app page
  • View the profile page
  • Conduct after-sale activities, like confirming winning bids and prices, contacting the seller regarding the item, submitting lot disputes or claims, etc.

If you attempt to change your password, email address, update any other account information or attempt other account activity beyond those listed above, you may be required to enter your password.

You can typically end your signed in session by either signing out and/or clearing your cookies. If you have certain browser privacy settings enabled, simply closing your browser may also end your signed in session. If you are using a public or shared computer, you should sign out and/or clear your cookies when you are done using our Services to protect your account and your personal information.

Ways you can access, control, and correct your personal information

We respect your right to access, correct, request deletion or request restriction of our usage of your personal information as required by applicable law. We also take steps to ensure that the personal information we collect is accurate and up to date.

  • You have the right to know what personal information we maintain about you
  • We will provide you with a copy of your personal information in a structured, commonly used and machine readable format on request
  • If your personal information is incorrect or incomplete, you have the right to ask us to update it
  • You have the right to object to our processing of your personal information
  • You always have the right to ask us to delete or restrict how we use your personal information. This right is determined by applicable law and may impact your access to some of our Services

Learn more: Ways you can access, control, and correct your personal information

Access, correction, and deletion of your personal information

You can see, review and change most of your personal information by signing in to your account. Please, update your personal information immediately if it changes or is inaccurate. Keep in mind, once you make a public posting, you may not be able to change or remove it.

We will honor any statutory right you might have to access, modify or erase your personal information. To request access and to find out whether any fees may apply, if permitted by applicable national laws, please contact us at contact@artfirst.ro. Where you have a statutory right to request access or request the modification or erasure of your personal information, we can still withhold that access or decline to modify or erase your personal information in some cases in accordance with applicable national laws.

If you request that we stop processing some or all of your personal information or you withdraw (where applicable) your consent for our use or disclosure of your personal information for purposes set out in this privacy notice, we might not be able to provide you all of the Services and customer support offered to our users and authorized under our Privacy Policy and our Terms Agreement.

Upon your request, we will close your account and remove your personal information from view as soon as reasonably possible, based on your account activity and in accordance with applicable national laws.

How we might share your personal information

We may disclose your personal information to other members of the ARTFIRST SRL corporate family, to sellers if you successfully complete a purchase, or to third parties. This disclosure may be required for us to provide you access to our Services, to comply with our legal obligations, to enforce our Terms Agreement, to facilitate our marketing and advertising activities, or to prevent, detect, mitigate, investigate and track prohibited, fraudulent or illegal activities related to our Services. We attempt to minimize the amount of personal information we disclose to what is directly relevant and necessary to accomplish the specified purpose. We do not sell, rent, or otherwise disclose your personal information to third parties for their marketing and advertising purposes without your consent.

Learn more: How we might share your personal information

We may disclose your personal information to the following parties for the following purposes:

ARTFIRST SRL corporate family members, who may use it to:

  • Provide joint content and services (like registration, transactions, and customer support)
  • Help detect, investigate, mitigate and prevent potentially fraudulent and illegal acts, violations of our Terms Agreement, and data security breaches
  • Monitor for multiple, fake, unauthorized, aliased, or misleading personal accounts for violations of our policies, seller/buyer contracts, or applicable laws.
  • Provide you personalized advertising
  • Improve their products, sites, applications, services, tools, and marketing communications
  • Members of our ARTFIRST SRL corporate family will use your personal information to send you marketing communications only if you have consented to receive such communications from them or if otherwise permitted by the law

Service Providers and financial institutions partners as follows:

  • Third party service providers who help us to provide our Services, payment processing services, assist us in providing customize advertising, to assist us with the prevention, detection, mitigation, investigation and tracking of potentially illegal acts, violations of our Terms Agreement, fraud and/or security breaches, bill collection, affiliate and rewards programs and other business operations
  • Third party financial institutions with whom we partner to offer financial products to you, for them to provide joint content and services (such as, registration, transactions and customer support). These third party financial institution partners will use your personal information to send you marketing communications only if you have requested their services directly
  • Third party shipping providers (e.g., DHL, UPS, USPS, FAN COURIER, etc.) with whom we share delivery address, contact information and shipment tracking information for the purposes of facilitating the delivery of items purchased and other delivery related communications
  • Third party providers of websites, applications, services and tools that we cooperate with so that they can publish or advertise your listings and their content on their websites or in their applications, services and tools. If we transfer personal information along with the content of your listings to third party providers, this will be solely on the basis of an agreement limiting use by the third party provider of such personal information to processing necessary to fulfil their contract with us and obligating the third party provider to take security measures with regard to such data. Third party providers are not permitted to sell, lease or in any other way transfer the personal information included in your listings to third parties

Law enforcement, legal proceedings, and as authorized by law

  • To comply with our legal requirements, enforce our Terms Agreement, respond to claims that a listing or other content violates the rights of others, or protect anyone’s rights, property or safety
  • To law enforcement or governmental agencies, or authorized third-parties, in response to a verified request or legal process relating to a criminal investigation or alleged or suspected illegal activity or any other activity that exposes us, you, or any other of our users to legal liability. We will only disclose information we deem relevant to the investigation or inquiry, such as name, city, state, postcode, telephone number, email address, User ID history, IP address, fraud complaints, bidding and listing history
  • To third parties involved in a legal proceeding, if they provide us with a subpoena, court order or substantially similar legal basis, or we otherwise believe in good faith that the disclosure of information is necessary to prevent imminent physical harm or financial loss or to report suspected illegal activity

ARTFIRST sellers as authorized by you, or essential to your use of our Services

  • When transacting with a seller through our services, the seller may request that we provide him/her with information about you necessary to complete the transaction, such as your name, account ID, email address, contact details, shipping and billing address, or other information from you needed to promote the reliability and security of the transaction.
  • If a transaction fails, is put on hold, or is later invalidated, we may also provide the seller with details of the unsuccessful transaction
  • The seller receiving your information is only permitted use it for purposes related to the transaction. Unless you have consented to receive marketing from them, they should not contact you for marketing purposes. Each seller/business will have a privacy policy that pertains to their use of your information
  • Contacting users with unwanted or threatening messages is a violation of our Terms Agreement

Change of ownership

If we are subject to a merger or acquisition with/by another company, we may share information with them in accordance with our global privacy standards. Should such an event occur, we will require that the new combined entity follow this privacy notice with respect to your personal information. If we intend to handle your personal information for any purposes not covered in this privacy notice, you will receive prior notification of the processing of your personal information for the new purposes.

How long we keep your personal information

We retain your personal information for as long as necessary to provide the Services you have requested, or for other essential purposes such as complying with our legal obligations, resolving disputes, and enforcing our policies.

Learn more: How long we keep your personal information

How long we retain personal information can vary significantly based on context of the Services we provide and on our legal obligations. The following factors typically influence retention periods:

  • How long is the personal information needed to provide our Services? This includes such things as maintaining and improving the performance of our products, keeping our systems secure, and maintaining appropriate business and financial records. This is the general rule that establishes the baseline for most of our data retention periods
  • Is the personal information sensitive? If so, a shortened retention time is generally appropriate. Credit Card information is retained in compliance with PCI DSS version 3.2
  • Have you provided consent for a longer retention period? If so, we will retain data in accordance with your consent
  • Are we subject to a legal, contractual, or similar obligation to retain your personal information? Examples can include mandatory data retention laws in the applicable jurisdiction for financial reporting or recording other business activities, government orders to preserve data relevant to an investigation, or personal information retained for the purposes of litigation

After it is no longer necessary for us to retain your personal information, we will dispose of it in a secure manner according to our data retention and deletion policies.

Cookies & Similar Technologies

When you visit or interact with our sites, services, applications, tools or messaging, we or our authorized service providers may use cookies and other similar technologies to help provide you with a better, faster, and safer experience, and for advertising and marketing purposes.

How do we protect your personal information

We protect your personal information using technical and administrative security measures to reduce the risks of loss, misuse, unauthorized access, disclosure and alteration. Some of the safeguards we use are firewalls and data encryption, physical access controls to our data centers, and information access authorization controls. Our systems and policies are compliant with PCI DSS 3.2, particularly relating to sensitive financial information.

Data Controllers and Data Protection Officers

Learn more about who is your data controller, and is responsible for the collection, use, disclosure, retention and protection of your personal information in accordance with our global privacy standards, this privacy notice, as well as any applicable national laws.

Learn more: Data Controllers and Data Protection Officers

Regardless of where you are in the world when you access our services, you are contracting with:

ARTFIRST, SRL
str. Nucului, nr. 6, bl. V-106, sc. 2, et. 3, ap. 41, Sector 3

All applicable laws, including Privacy Laws, for that location apply, as well as additional National and International regulations.

You can contact our privacy officer directly via contact@artfirst.ro, and they will respond within 30 days in compliance with the GDPR

Other important privacy information

This section describes some additional privacy information related to your use of our Services that you may find important.

Learn more: Other important privacy information

Seller responsibilities over transactional information you receive through ARTFIRST

When you transact with another user, we enable you to obtain or we may provide you with the personal information of the other user (such as their name, account ID, email address, contact details, shipping and billing address) to complete the transaction. Independent from us, you are the controller of such data and we encourage you to inform the other user about your privacy practices and respect their privacy. In all cases, you must comply with the applicable privacy laws, and must give the other user a chance to remove them from your database and them a chance to review what information you have collected about them.

You may use the personal information that you have access to only for ARTFIRST transaction-related purposes, or for other services offered through ARTFIRST (such as escrow, shipping, disputes or fraud complaints, and buyer-seller communications), and for purposes expressly consented by the user to whom the information relates. Using personal information of other users that you have access to for any other purpose constitutes a violation of our Terms Agreement and additional contracts we may have in place with sellers.

Unwanted or threatening email

We do not tolerate abuse of our Services. You do not have permission to add other users to your mailing list (email or postal), call, or send him/her text messages for commercial purposes, even if this user purchased something from you, unless the user has given his/her explicit consent. Sending unwanted or threatening email and text messages is against our Terms Agreement. To report ARTFIRST-related spam or spoof emails please forward the email to contact@artfirst.ro with any additional comments, questions or objections you may have.

Communication tools

We may scan messages automatically and check for spam, viruses, phishing and other malicious activity, illegal or prohibited content or violations of our Terms Agreement, this privacy notice or our other policies.

Children’s Privacy

Our Services are specifically intended only for people who, through age and competence, are able to enter into a contract. Use by all other individuals is specifically precluded. We do not knowingly collect personal information from users deemed to be children under their respective national laws.

Third Party Privacy Practices

This privacy notice addresses only our use and handling of personal information we collect from you in connection with providing you our Services. If you disclose your information to a third party, or visit a third party website via a link from our Services, their privacy notices and practices will apply to any personal information you provide to them or they collect from you.

We cannot guarantee the privacy or security of your personal information once you provide it to a third party and we encourage you to evaluate the privacy and security policies of your trading partner before entering into a transaction and choosing to share your personal information. This is true even where the third parties to whom you disclose personal information are bidders, buyers or sellers on our site.

Contact Us

If you have a question or a complaint about this privacy notice, our global privacy standards, or our information handling practices:

You can reach the Global Privacy Office in writing at:

ARTFIRST, SRL
Attention: Privacy Officer
str. Nucului, nr. 6, bl. V-106, sc. 2, et. 3, ap. 41, Sector 3

You can also email our Privacy team at contact@artfirst.ro

This policy document 1.00 was last revised effective Aug 11, 2018.