Last updated: [date]
1. Data controller
[Identity and contact of the data controller.]
2. Data we collect
[Categories of data: identity, contact, KYC documents (ID, bank details), bidding activity, technical data.]
3. Why we collect it
[Purposes: account management, identity verification, running auctions, legal obligations.]
4. Legal basis
[Legal bases under GDPR: contract, legal obligation, consent, legitimate interest.]
5. Who has access
[Who can access data: platform, sale organisers (only for their sales), no third-party advertising.]
6. How long we keep it
[Retention periods for each category of data.]
7. Security
[Security measures: documents stored outside the web root, restricted access, encryption in transit.]
8. Your rights
[GDPR rights: access, rectification, erasure, restriction, portability, objection, and how to exercise them.]
9. Contact & complaints
[Contact for privacy requests and right to lodge a complaint with the supervisory authority.]