pursuant to Articles 13 and 14 of the Regulation (EU) 679/2016 ("GDPR")
This Privacy Notice describes the processing of personal data of users (the "Users") of Artshell S.r.l.'s services, which include our website www.artshell.eu and any related applications and digital platforms (collectively referred to as the "Applications").
- Data controller and Data Controller contact data
- The data controller is the company Artshell S.r.l., a company operating in the sector of management of works of art and, more specifically, in the development of IT systems to facilitate and streamline the activities relating to the management, classification and share of works of art and artistic collections.
- Artshell S.r.l. has its registered office in Milan, 20123, Via Carducci n. 8, Tax Code and VAT Number 10440980968 (hereinafter referred to as "Artshell", the "Company", or the "Data Controller").
- In case of any doubt about how personal data are processed by the Company, please contact the same:
- * * * * * * *
- The information you find on this page shall not be applicable to websites, apps and contents of third parties in general, not even if they are accessible from the Website. In these cases, personal data protection provisions of such third parties shall apply, which may be different from the provisions hereof and that are recommended to be referred to before providing any data.
- Data collection and type of processed data
- Navigation data automatically collected by Applications: access and navigation data
- When Users access the Applications, the IT systems and software procedures based on which the Applications operates acquire, during their standard operation, access and navigation data (for example: IP addresses or the domain names of the computers used by Users, URI - Uniform Resource Identifier - addresses of the resources requested, time of the request, method used in submitting the request to the server, size of the file obtained in response to the request, the numeric code indicating the status of the response provided by the server and other parameters relating to the operating system and the IT environment of the User - the "Navigation Data").
- Data provided by Users to contact the Data Controller: Personal information, contact data and personal data voluntarily provided by Users
- In the Website section "Contact us", subject to confirming of having read this privacy policy, the User who intends to contact the Data Controller is requested to provide specific personal data, by filling in the specific form on the Website, i.e.: name, surname, telephone (optional), email address and any other personal data voluntarily provided by the User in the content of the message sent to the Data Controller (the "Request Data"). More specifically, such data are requested to respond to Users' requests and provide information and clarifications about the SaaS Services and recommend to the Users the best solution for their business.
- Pursuant to Article 14 of the GDPR, it should also be noted that if Artshell is contacted through social networks, the Request Data may be provided also through such social networks (i.e. Facebook® or Instagram®, Linkedin®); in that case the subject sending us the Data will be, as the case may be, (i) the US company META Inc., providing here its privacy notice; or the US company Google Inc., providing here its privacy notice.
- The provision of Request Data is entirely voluntary. Users may choose not to provide this data, but as a consequence, while they can still navigate the Website and use our Applications, they will not receive responses to their inquiries or obtain any information or clarifications they wish to receive from Artshell. Similarly, Account Data is collected based on the extent and nature of the data provided by the Users themselves, whether through our Website or Applications.
- The Users are invited not to provide third party personal data unless this is required (for example, because the Users who want to receive information from Artshell do not have their own email address and do not have any other direct contact address): in this case, we remind that the Users have to fulfill personal data protection law obligations and, in particular, have to inform the third parties about the data provision and collect their consent, should that be the case.
- Data provided by Users: personal or contact data for the creation of the Artshell Account
- In the Website header and footer it is possible to access the section "Login" in which the User is requested, subject to acceptance of the SaaS License Terms and Conditions and of this privacy policy, to provide specific personal data: name, surname, email address (the "Account Data"). Such data is requested, in particular, for the registration of an account that allows to access a reserved area thanks to which it is possible to use the services (the "SaaS Services") relating to the use of the web or mobile based platform called "Artshell" (the "Platform"). Subject to the foregoing, the SaaS Services will be used by the Users also by entering the data relating to their credit card or after payment of the subscription level selected - except for the "FREE" subscription -, in accordance with the SaaS License Terms and Conditions.
- The provision of the Account Data takes place on a voluntary basis: if Users do not provide it, they can still navigate on the Website without benefiting from the functionalities of such area and of the SaaS Services. Moreover, the Account Data is collected if, to the extent that and as such data is provided by the same Users.
- The section "Login" where, subject to the acceptance of the SaaS License Terms and Conditions and of this privacy policy, the Users are requested to provided the Account Data for registration at Artshell, is also reachable through a specific link generated and sent by another User (including entities organizing online exhibitions, associations, non-profit spaces, private collections, museums, art galleries, cultural institutes, online arts and event service companies and any other subject organizing online events of any kind for commercial, promotional or information purposes), already holding an Artshell account, through the Network, Chatting and Events Saas Services , as better specified in the SaaS License Terms and Conditions
- The Users are invited not to provide third party personal data unless this is required (for example, because the Users who want to receive information from Artshell do not have their own email address and do not have any other direct contact address): in this case, we remind that the Users have to fulfill personal data protection law obligations and, in particular, have to inform the third parties about the data provision and collect their consent, should that be the case.
- Data provided by Users: personal data and email for the Newsletter
- Users may register at Artshell newsletter service, by filling in the specific registration form on the Website and providing some specific personal data: name, surname, email address (the "Newsletter Data"). Such data is requested, in particular, for the purpose of allowing the User to benefit from such service and, therefore, to receive by email updates on the world of art and on Artshell services. Newsletter Data also include personal data of the User registered at Artshell related to the activities of reading and interacting with the newsletters (and other communications) received(i.e. statistical data).
- The provision of Newsletter Data is necessary: any refusal to provide such data will not allow Artshell to send the newsletter to the User.
- (Navigation Data, Account Data, Newsletter Data hereinafter jointly referred to as "Data")
- Cookies
- In the Website IT techniques are used for the direct acquisition of user's ID personal data consisting of "code strings": i.e. the "cookies".
- For all information about the cookies on the Website and about the related personal data processing click here.
- Legal basis and purposes of data processing
- The Navigation Data will be used:
- for the purpose of monitoring the proper operation of the Applications,
- in aggregate and unidentified form, for statistical purposes related to understanding how the Applications are used by Users, to facilitate easier access and increase their attractiveness, as well as
- To detect any technical issue as soon as possible.
- The legal basis of such data processing is the Company's legitimate interest in improving its digital services, which is compatible with the data subjects' position as: (a) the monitoring of the Website and Applications' operations, along with the statistical analysis of their usage, does not entail direct identification of individuals; and (b) the Company's interest in improving its digital offerings is also beneficial for Users, who can then enjoy more efficient and optimized experiences on both the Website and Applications.
- The Request Data will be used to respond to the requests that the Users may send to Artshell by filling in the specific form available on the Website: to this end, it is necessary that Users provide their personal and contact data as, otherwise, Artshell will not be able to respond to their requests.
- The legal basis of such processing is to enforce pre-contractual measures (e.g., reply to specific clarifications requested about the SaaS Services) adopted on the User's specific request.
- The Account Data shall be used for the purpose of allowing the creation of a User Account, which enables the access to a reserved area through which the User may use the Artshell SaaS Services.
- The legal basis of such data processing is the necessity to perform an agreement to which the User is a party (i.e. the SaaS License Terms and Conditions).
- It should be noted that the email included in the Account Data shall also be used to forward information exclusively about the progress and the operating functionalities of Artshell SaaS Services.
- The legal basis of such data processing is the Company's legitimate interest in transparent information with the Users in order to improve as much as possible the performance of the agreement, and such processing is compatible with the data subjects' position as: (a) the communication has the exclusive purpose to inform the User using Artshell SaaS Services about the updates and improvements thereof; and (b) the interest of the Company reasonably seems to correspond exactly also to the interest of the Users, who may always know the functionalities of Artshell SaaS Services.
- The Newsletter Data will be used only for the purpose of sending to the User any emails with information about the world of art, the new digital solutions to facilitate and streamline the activities relating to the management, classification and share of works of art and artistic collections, as well as about Artshell activities, so that the opportunities offered by the Platform from time to time may be evaluated by the User.
- It should be noted that the Newsletter Data and, more specifically, the email address provided, shall also be used to send the User customized communications, prepared ad hoc, without using automated profiling systems, based on the features of the individual User and the specific categories of beneficiaries of Artshell Saas Services in which the User is included (e.g. art collector, museum, artist, etc.).
- The legal basis of such processing is the need to enforce pre-contractual measures adopted on the specific request of the User. The Newslettering service may be disabled by the recipient by clicking "Unsubscribe".
- Data recipients
- The Data will be provided to and may be known by: (i ) by the Company's employees and collaborators, duly instructed about the data processing; and (ii) by third parties providing ancillary services or services instrumental to the Company's activity, in relation to the development, provision and operating management of the Applications, specifically appointed as data processors.
- In addition, the Account Data may also be provided to, and may be known by, third parties that process data as autonomous data controllers like, by way of example without limitation, entities organizing online exhibitions, associations, non-profit spaces, private collections, museums, art galleries, cultural institutes, online arts and event service companies and any other subject organizing online events of any kind for commercial, promotional or information purposes who - through the SaaS Services usable through the Platform - have set up specific exhibition areas accessible (a) through specific login sections and (b ) subject to prior acceptance of the Terms and Conditions and of the privacy notice of such entities.
- Place of Data processing and transfer of Data to foreign countries
- The processing of the User Data shall take place at the aforementioned Company's registered office, and the Data shall be retained in the servers located within the European Union.
- Any further transfer of Data to foreign countries shall take place, if to Countries not benefiting from any European Commission adequacy decision and, consequently, not providing an adequate level of personal data protection, solely (i ) subject to prior adoption of adequate guarantees like, by way of example without limitations, the stipulation of the relevant clauses approved by the European Commission, or (ii) upon occurrence of a derogation of the prohibition of transfers outside the European Union and, therefore, again by way of example without limitations, subject to prior reception of the explicit and informed consent of the User, or only to the extent that it is necessary for the performance of an agreement entered into between the User and the Company, or between the Company and a third party to the User's benefit, or upon enforcement of pre-contractual measures adopted on the User's request.
- Processing modes, security measures and Data retention period
- Data will be processed both on paper and by means of digital, computer or automated tools, through systems ensuring their protection, security and confidentiality.
- The Company also adopted specific and adequate, logical, legal, organizational and technical security measures to prevent loss, unlawful or unauthorized use of Data and unauthorized access to Data.
- Navigation Data - not allowing User identification - are retained for max. 7 days and are immediately deleted after their aggregation (subject to any required assessment of any offenses by the competent Judicial Authority).
- Request Data, having the purpose of responding to Users' requests, shall be retained for 12 months after reception of the relevant request.
- Account Data, having the purpose of responding to the User's request to access the reserved area and use Artshell SaaS Services, shall be retained for the entire duration of the agreement term and for the limitation period envisaged by the applicable legislative provisions.
- Newsletter Data shall be retained and processed for max. 24 months after registration. Artshell shall ask the User by a 1-month prior notice whether the User wishes to continue receiving the newsletter: in case of refusal, Newsletter Data shall be deleted; in case of consent, Newsletter Data shall be retained and processed for an additional period of 24 months.
- Data shall be retained for a longer period of time if this is necessary to perform any statutory and/or legal obligations as well as to ensure legal protection of the Company's rights, in compliance with the ordinary limitation terms.
- User's rights
- Users, as data subjects (i.e. subjects to whom Data refer) also hold the rights assigned by the GDPR. More specifically, pursuant to articles 12-23 of the GDPR, the data subjects shall have the right to request and obtain, at any time, access to their personal data, information about the processing, rectification and/or update of personal data, erasure or restriction of processing. Moreover, they also have the right to object to processing and to request data portability (i.e. to receive personal data in a structured, commonly used, machine-readable format). Finally, data subjects have always the right to revoke their consent at any time (in any case, this shall not affect the lawfulness of data processing made based on the consent given before its revocation) and to file a complaint to any personal data protection authority (in Italy: the Personal Data Protection Authority)
- The aforementioned rights may be exercised at any time, by simple request to the Data Controller, to be sent:
- For any other information or clarification about the aforementioned rights, you may contact the Company at the same addresses.
- * * * * * * *
The Company may amend this privacy notice to adapt it to any future extension or modification of the Applications.
Information updated on December 5, 2023