Privacy Policy
Last updated: September 2026 · Datenschutzerklärung
1. Who is responsible
The controller under the General Data Protection Regulation (GDPR) is the operator of the website theartistsartmarket.com.
The site is still being built and is not yet publicly available. The full details of the controller — legal entity, postal address, legal representation and contact address — will be added here, and in the Impressum, before the site goes live.
2. Scope
This policy covers theartistsartmarket.com and all of its subpages, together with the services we run under that domain. The site is under construction, so some of the processing described below only begins once the corresponding feature is published.
3. Visiting the site (server logs)
Every request to our web server processes the technical data your browser sends automatically:
- the truncated IP address of the requesting device
- the date and time of the request
- the address requested and the volume of data transferred
- the response status code, browser type and operating system
Purpose: serving the site, keeping it secure and defending against attacks. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in secure, uninterrupted operation. Retention: 14 days at most, then deleted automatically.
4. Cookies and consent
Strictly necessary cookies are set without consent under § 25(2) TDDDG; they are required to operate the site and to keep you signed in. Every non-essential cookie is set only after you have given explicit consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You can change or withdraw your choice at any time through the cookie notice on the site. Withdrawal takes effect going forward and does not affect processing already carried out.
5. Accounts and signing in
We use Clerk for registration and sign-in. This processes your email address, your name where you provide one, and sign-in times and session information.
If you sign in with Google, all we receive from Google is your email address, your name and your profile picture where you have one. We do not request and cannot access anything else in your Google account — not your mail, your contacts or your files.
Purpose: providing your account and attributing your submissions to you. Legal basis: Art. 6(1)(b) GDPR — performance of a contract and steps taken at your request before entering into one. Retention: for as long as the account exists. When you delete your account the sign-in data is removed, unless a statutory retention period requires us to keep it.
6. Artist submissions
When you apply to an open call or submit work, we process what you provide: your name, contact details, information about you and about the work, and the images and documents you upload.
Purpose: reviewing and processing your submission and displaying it on the platform. Legal basis: Art. 6(1)(b) GDPR. Retention: until the process concludes, and beyond that for as long as the work remains published on the platform.
7. Email
Transactional email — confirmations and status updates about your submission — is sent through Brevo. This transmits your email address, your name and the content of the message.
Legal basis: Art. 6(1)(b) GDPR for messages that form part of our relationship with you; Art. 6(1)(a) GDPR where you have subscribed to a newsletter. You can end a newsletter subscription at any time using the unsubscribe link in every message.
8. Payments
Purchases are handled through Shopify. You enter your payment details directly with that provider; full card or bank details never reach our systems. We receive only what we need to fulfil the order.
Legal basis: Art. 6(1)(b) GDPR. Retention: commercial and tax retention periods of up to ten years.
9. Services we use and who receives your data
We use the processors below. A data processing agreement under Art. 28 GDPR is in place with each of them.
| Service | Purpose | Where processed |
|---|---|---|
| Clerk | Registration and sign-in | United States |
| Sign-in with a Google account | United States | |
| Supabase | Database and file storage | EU (Frankfurt) |
| Brevo | Sending email | EU (France) |
| Shopify | Payments | EU / Canada |
| Cloudflare | DNS and site delivery | EU / United States |
Transfers outside the EU
Where data is transferred to a country outside the EU and the EEA, we rely on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, or on an adequacy decision where one exists for that country.
10. Your rights
You have the following rights over your personal data at any time:
- Access to the data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Portability of your data in a common format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent, effective going forward (Art. 7(3) GDPR)
A message to the contact address in section 1 is enough to exercise any of these. Separately, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular the authority where you normally live.
11. No automated decision-making
We do not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
12. Changes to this policy
We update this policy whenever the features we offer or the services we use change. The version published on this page is the one that applies.