Loading...
Loading...
Last updated: July 8, 2026
The data controller is the Athenoir Association (Stichting), registered in Amsterdam, the Netherlands. For data protection inquiries, contact privacy@athenoir.com.
Account data: Name, email address, password (hashed), role, subscription tier.
Artist profiles: Name, nationality, biography, portfolio images, medium, location, education, exhibition history. For unclaimed profiles, only publicly available information is used (Article 14, GDPR).
Transaction data: Purchase details, payment status, shipping information, commission records. Financial details are processed by Stripe and never stored on our servers.
Usage data: Page views, search queries, feature usage (anonymized via analytics).
Consent: Newsletter subscriptions, marketing communications, premium content access.
Contractual necessity: Account management, transaction processing, artist claim workflow.
Legitimate interest: Platform security, fraud prevention, service improvement, preliminary artist profiles from public sources (Article 6(1)(f), GDPR).
We create preliminary artist profiles using publicly available information from gallery websites, exhibition catalogs, and public databases. This processing is based on our legitimate interest in building a comprehensive art platform (Article 6(1)(f), GDPR).
Artists may at any time: claim and edit their profile, request corrections, or request complete deletion by emailing privacy@athenoir.com. Unclaimed profiles are automatically deleted after 90 days.
We share data with: Stripe (payments), our SMTP provider (email delivery), and Cloudflare (CDN/security). We do not sell personal data to third parties. Anonymized, aggregated market data may be provided to research partners.
Account data: retained while account is active, deleted within 30 days of account deletion. Transaction records: retained for 7 years (legal/tax requirements). Unclaimed artist profiles: deleted after 90 days. Analytics data: anonymized after 26 months.
You have the right to: access your data, rectify inaccuracies, erase your data ("right to be forgotten"), restrict processing, data portability, and object to processing. To exercise these rights, email privacy@athenoir.com.
Data may be transferred between our entities in the Netherlands (Stichting) and Abu Dhabi (ADGM LLC) under Standard Contractual Clauses. Server infrastructure is located in the EU (Hetzner, Germany).
We use essential cookies for authentication and session management. Analytics cookies (GA4) are loaded only with your consent. You may manage cookie preferences at any time via the cookie banner.
We implement industry-standard security measures including HTTPS encryption, hashed passwords, rate limiting, and regular security audits. Payment data is handled exclusively by Stripe (PCI DSS Level 1 certified).
We may update this policy periodically. Material changes will be communicated via email or platform notification. Continued use after changes constitutes acceptance.