GDPR
Privacy Policy
Last updated: March 2025.
This privacy policy describes how Artifex Dei collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR).
Data Controller
The data controller is the Artifex Dei platform, available at artifexdei.com. For all privacy and data processing inquiries, contact us at: info@artifexdei.com
Data We Collect
We collect a minimal set of data necessary for the platform to function:
- —Email address and password (for authentication via Supabase Auth)
- —Artist name (for public profile)
- —Short biography and artist statement (optional, for public profile)
- —City, region, and country (optional, for public profile)
- —Profile photo (optional)
- —Artwork data: title, description, category, medium, dimensions, photos
- —Visitor inquiries (name, email, message) sent directly to the artist
Purpose and Legal Basis
- —Contract performance: managing your account and displaying profiles on the platform
- —Legitimate interest: protecting the platform from abuse and verifying content authenticity
- —Consent: processing optionally entered profile data
Cookies
We use only essential cookies. We do not use cookies for tracking, analytics, or advertising.
- —Session cookies (Supabase Auth): required for authentication and maintaining logged-in sessions
- —Language preference cookie (locale): remembers your chosen interface language (HR/EN)
Data Sharing
Your data is not sold to third parties. We use the following technology partners who process data on our behalf with appropriate GDPR protections:
- —Supabase (database and authentication) — EU infrastructure
- —Resend (transactional email for inquiries) — data is not retained
- —Vercel (hosting) — EU region
Data Retention
Your data is retained while you have an active account. After account deletion, all personal data and content is deleted within 30 days. You can request deletion of your account and all data at any time via the dashboard or at info@artifexdei.com
Your Rights
Under GDPR you have the following rights:
- —Right of access: you can request a copy of your personal data
- —Right to rectification: you can correct inaccurate data
- —Right to erasure ("right to be forgotten"): you can request deletion of all your data
- —Right to data portability: you can request your data in machine-readable format
- —Right to object: you can object to processing based on legitimate interest
- —Right to lodge a complaint with a supervisory authority
Contact and GDPR Requests
To exercise your rights or for any questions about data processing, contact us at: info@artifexdei.com — we respond within 30 days.