ÉDITION
Documents · 03

Privacy Policy

Version of July 22, 2026

Published pursuant to art. 18.1(2) of Federal Law No. 152-FZ “On Personal Data”.

01Controller

Platform operator: [legal form and name], OGRN [—], INN [—], address: [—], e-mail: hello@edition.art. Requisites are placeholders to be completed before public launch.

Personal-data requests: privacy@edition.art.

02Data processed

  • Account: name, e-mail, password (stored only as a cryptographic hash).
  • Activity: bidding, purchase and offer history.
  • Artist profile: name/pseudonym, birth year, biography — published with the artist’s consent.
  • Technical: session cookie, language preference, IP address and server logs.

03Purposes and legal bases

Data is processed to perform the contract (registration, bidding, settlement, delivery), on the basis of consent (artist profile publication; newsletters, if enabled), and to comply with legal obligations (accounting, responses to state authorities). Art. 6 of 152-FZ.

04Data localisation

Recording, systematisation, accumulation and storage of Russian citizens’ personal data use databases located in the Russian Federation (art. 18(5) of 152-FZ). No cross-border transfers are made.

05Cookies

The platform uses strictly necessary cookies only: the session identifier (authentication) and the language preference. No third-party analytics, ad trackers or pixels are used.

06Sharing

Data is shared only with: the seller and buyer, to the extent needed to complete the transaction; the delivery service; the payment provider; and state authorities upon lawful request. Data is never sold.

07Retention

Account data is kept while the account is active and is deleted or anonymised once the purposes are achieved. Transaction documents are retained for 5 years (accounting requirements, Law 402-FZ).

08Your rights

You may request information about processing, demand rectification, blocking or erasure, and withdraw consent (art. 14 of 152-FZ). Send requests to privacy@edition.art; responses are given within 10 business days (art. 20 of 152-FZ).

09Security

Measures under art. 19 of 152-FZ are applied: password hashing (scrypt), TLS encryption, role-based access, access logging. Incidents are notified to Roskomnadzor within the statutory 24/72-hour windows (art. 21 of 152-FZ).

The Russian version is legally binding; the English text is a courtesy translation.