GDPR

Privacy Policy

Last updated: March 2025.

This privacy policy describes how Artifex Dei collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR).

Data Controller

The data controller is the Artifex Dei platform, available at artifexdei.com. For all privacy and data processing inquiries, contact us at: info@artifexdei.com

Data We Collect

We collect a minimal set of data necessary for the platform to function:

  • Email address and password (for authentication via Supabase Auth)
  • Artist name (for public profile)
  • Short biography and artist statement (optional, for public profile)
  • City, region, and country (optional, for public profile)
  • Profile photo (optional)
  • Artwork data: title, description, category, medium, dimensions, photos
  • Visitor inquiries (name, email, message) sent directly to the artist

Purpose and Legal Basis

  • Contract performance: managing your account and displaying profiles on the platform
  • Legitimate interest: protecting the platform from abuse and verifying content authenticity
  • Consent: processing optionally entered profile data

Cookies

We use only essential cookies. We do not use cookies for tracking, analytics, or advertising.

  • Session cookies (Supabase Auth): required for authentication and maintaining logged-in sessions
  • Language preference cookie (locale): remembers your chosen interface language (HR/EN)

Data Sharing

Your data is not sold to third parties. We use the following technology partners who process data on our behalf with appropriate GDPR protections:

  • Supabase (database and authentication) — EU infrastructure
  • Resend (transactional email for inquiries) — data is not retained
  • Vercel (hosting) — EU region

Data Retention

Your data is retained while you have an active account. After account deletion, all personal data and content is deleted within 30 days. You can request deletion of your account and all data at any time via the dashboard or at info@artifexdei.com

Your Rights

Under GDPR you have the following rights:

  • Right of access: you can request a copy of your personal data
  • Right to rectification: you can correct inaccurate data
  • Right to erasure ("right to be forgotten"): you can request deletion of all your data
  • Right to data portability: you can request your data in machine-readable format
  • Right to object: you can object to processing based on legitimate interest
  • Right to lodge a complaint with a supervisory authority

Contact and GDPR Requests

To exercise your rights or for any questions about data processing, contact us at: info@artifexdei.com — we respond within 30 days.

Politika privatnosti | Artifex Dei