Privacy Policy
Website www.21app.art and 21App application
This policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (hereinafter "GDPR") and describes how 21 APP S.r.l. (hereinafter "21APP" or the "Data Controller") processes personal data within the site https://21app.art/, the 21App application, and related services.
1. Data Controller
The Data Controller is 21 APP S.r.l., with registered office at Via Lorenzo Perosi 3, 30030 Pianiga (VE), Italy, Tax Code and VAT No. 05625570261, e-mail: app@21app.art; PEC (certified e-mail): 21app.art@legalmail.it.
Data subjects can send requests about the processing of their personal data, or to exercise their rights under the GDPR, to the Controller at the contact details above, with the subject line: "Privacy – data subject request".
2. Categories of personal data
In relazione alle funzionalità utilizzate, ai servizi richiesti e alle operazioni effettuate, 21APP può trattare:
Identifying and contact data: name, surname, email address, country, any phone number, and other identifying, contact, and account-related data;
denominazione o ragione sociale, Codice Fiscale, Partita IVA, dati di fatturazione, coordinate bancarie e altri dati societari, amministrativi e fiscali;
Verification and compliance data: data and documents required for identity verification, for compliance with anti-money laundering (AML/KYC) obligations, as well as for security and fraud prevention purposes;
Transaction and service data: data related to user requests and operations, such as amounts, dates, identifiers, and status of the Registered User, evaluation requests, quotes, mandates, offers, orders, purchases, sales, payments, brokerage fees, refunds;
indirizzi di ritiro e di consegna, istruzioni di consegna, dati della spedizione e altre informazioni necessarie al trasporto e alla gestione logistica delle opere;
Data on Works and Private Ledger: personal data possibly contained in the information and documentation related to ownership, provenance, authenticity, state of preservation, and value of the works, including certificates, invoices, appraisals, administrative measures, and other documents submitted by the User for cataloging in the Private Ledger or for sale;
dati contenuti nelle richieste di informazioni, nelle comunicazioni, nelle richieste di assistenza, nei reclami e nelle contestazioni;
Data for events and community: data related to registration and participation in events, meetings, previews, clubs, and other initiatives organized or promoted by 21APP;
Browsing and technical data: IP address, technical identifiers, access data, logs, information about the device, browser, and operating system, as well as other technical, browsing, and security data related to the use of the site and the application. For more information, please refer to the Cookie Policy.
3. Purposes and legal bases
Personal data are processed for the following purposes and based on the corresponding legal bases:
Management of the contractual relationship and Services: to manage registration, account creation, the reserved area, profiling of the Registered User, the Private Ledger, requests for information, evaluation and assistance, ancillary art services, participation in events and clubs, quotes, publication of Works, mandates, offers, orders, purchases, sales, payments via PSP (Stripe), commissions, refunds, verifications on the Works, shipments, deliveries, guarantees, and complaints.
Legal basis: Execution of a contract or pre-contractual measures taken at the request of the data subject, pursuant to art. 6, par. 1, lett. b), GDPR.
Compliance with legal obligations: to fulfill applicable legal obligations of an administrative, accounting, tax, invoicing, and reporting nature, as well as obligations regarding consumer protection, anti-money laundering (AML/KYC), transaction traceability, circulation of works of art, and protection of cultural heritage.
Legal basis: Fulfillment of a legal obligation to which the Data Controller is subject, pursuant to art. 6, par. 1, lett. c), GDPR.
Protection of rights and management of disputes: to manage complaints, disputes, and extrajudicial or judicial controversies, as well as to ascertain, exercise, or defend a right of 21APP in judicial or administrative proceedings.
Legal basis: Legitimate interest of the Data Controller in protecting their rights, pursuant to art. 6, par. 1, lett. f), GDPR.
Platform security and fraud prevention: to ensure the security of the site, application, accounts, services, and transactions, prevent and detect fraud, abuse, illegal use, and unauthorized access, and carry out necessary technical checks.
Legal basis: Legitimate interest of the Data Controller in ensuring the security and reliability of their services, pursuant to art. 6, par. 1, lett. f), GDPR.
Marketing and promotional communications: to send newsletters and promotional communications related to artists, works, events, and services of the 21APP ecosystem.
Legal basis: Consent of the data subject, pursuant to art. 6, par. 1, lett. a), GDPR. (Consent is optional and can be revoked at any time).
4. Nature of the conferment
The provision of data marked as mandatory or otherwise necessary for the requested service is essential to create the Account, obtain the status of Registered User, access the Services, complete transactions in the marketplace, or participate in reserved events. The failure to provide such data prevents the delivery of the requested service.
5. Methods of processing
The processing is carried out using IT, telematic, and, where necessary, paper tools, by authorized and adequately trained personnel. 21APP adopts technical and organizational measures appropriate to the risk aimed at ensuring the confidentiality, integrity, and availability of the data.
6. Recipients of personal data
For the pursuit of the described purposes, personal data may be communicated or made accessible to:
Employees, collaborators, and authorized persons operating under the authority of 21APP;
Consultants and professionals in administrative, accounting, tax, legal, insurance, or art matters;
Providers of IT and technological services (hosting, cloud, maintenance, CRM, electronic communications);
Payment Service Providers (PSP): in particular Stripe Payments Europe Ltd, which manages payment flows, the Express onboarding of sellers, and financial verifications as an independent or data processor;
Buyers, Sellers, and counterparties involved in individual buying and selling transactions;
Carriers, shippers, and custodians responsible for the logistics, custody, and delivery of the works;
Experts and art consultants appointed for appraisals, assessments, or due diligence;
Public authorities, judicial police bodies, Revenue Agency and supervisory bodies in cases provided for by law.
7. Transfers of data outside the European Economic Area (EEA)
Personal data is mainly processed within the European Economic Area. If the use of technology providers involves the transfer to non-EEA countries, such transfer will take place in compliance with Articles 44 et seq. GDPR, based on Adequacy Decisions of the European Commission or Standard Contractual Clauses (SCC).
8. Data retention
Personal data is retained for the time necessary to achieve the purposes for which it was collected. In particular:
Requests for information not followed by registration: retained for a maximum of 12 months from the closure of the request;
Account and Registered User data (including Private Ledger data): retained for the entire duration of the contractual relationship and the activation of the Account. In case of Account closure, the data is retained for the time necessary to allow for any export and complete deletion operations;
Contractual, accounting, and trading data: retained for 10 years from the conclusion of the transaction or contractual relationship, in compliance with tax and civil obligations (art. 2220 c.c.);
Data for AML/KYC checks: retained for the period established by applicable anti-money laundering regulations;
Data for marketing purposes: retained until consent is revoked and in any case no longer than 24 months from collection.
9. Minors
The services of 21APP are reserved exclusively for adults (over 18 years of age). 21APP does not knowingly collect personal data from minors.
10. Rights of the data subjects
The data subject may exercise at any time the rights provided for by Articles 15 et seq. of the GDPR (access, rectification, erasure, restriction, portability, objection, and withdrawal of consent) by sending an email to app@21app.art or a certified email to 21app.art@legalmail.it. The data subject also has the right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).
11. Updates to the information
This information may be modified or updated as a result of regulatory or operational changes. The updated version will always be published on the site https://21app.art/ and can be consulted in the application.