Legal

Privacy Policy

Last updated: 15 May 2026

This Privacy Policy explains how BOLMANIA ("we", "us") processes personal data when you use our website, create an account, purchase artworks, participate in auctions, or register for events. We process data in accordance with the EU General Data Protection Regulation (GDPR) and Dutch implementation law (AVG). Last updated: 15 May 2026.

1. Data controller

[Legal entity name and form, e.g. BOLMANIA B.V.]

Address: [Street, postal code, city, Netherlands]

Email: hello@bolmania.com

Chamber of Commerce (KVK): [KVK number]

VAT: [VAT ID / BTW-nummer]

2. Personal data we collect

We may process the following categories of data:

  • Identity and contact details (name, email address)
  • Account credentials (encrypted passwords via our authentication provider)
  • Order, auction, and payment references (payments are processed by Stripe; we do not store full card numbers)
  • Event registration details and guest counts
  • Communications you send via contact forms or email
  • Technical data (IP address, browser type, device information in server logs)
  • Cookie preferences (see our Cookie Policy)

3. Purposes and legal bases

We process personal data for:

  • Providing the gallery, checkout, and auction services (contract)
  • Managing your account and authentication (contract / legitimate interest)
  • Event registration and customer support (contract / legitimate interest)
  • Complying with tax, accounting, and legal obligations (legal obligation)
  • Securing and improving our website (legitimate interest)
  • Marketing only with your consent where required

4. Recipients and processors

We share data with trusted processors only as needed to operate the platform, including hosting, database, email (e.g. Resend), payment (Stripe), and object storage providers. Processors act under data processing agreements where required.

We do not sell your personal data.

5. Retention

We retain personal data only as long as necessary for the purposes above, including statutory retention periods for financial records (typically up to 7 years in the Netherlands).

Account data is kept while your account is active and deleted or anonymised within a reasonable period after closure, unless retention is required by law.

6. Your rights

Under the GDPR you may have the right to:

  • Access, rectify, or erase your data
  • Restrict or object to certain processing
  • Data portability where applicable
  • Withdraw consent at any time (without affecting prior lawful processing)
  • Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)

7. Security

We apply appropriate technical and organisational measures, including encryption in transit (HTTPS), access controls, and secure session handling. No method of transmission over the internet is 100% secure.

8. Contact

For privacy requests, contact hello@bolmania.com. We will respond within one month, subject to applicable extensions.

This text is provided for transparency and does not constitute legal advice. Have a qualified lawyer review it for your organisation before launch.