Privacy Policy
Last updated: 2026-05-21
1. Data controller
Philmarket Oy (business ID 3636423-6), Finland, is the controller for the processing of your personal data on philmarket.eu. Contact: privacy@philmarket.eu.
2. Data we collect
- Account data: Email address, name (optional).
- Transaction data: Bids, purchases, payment status, amounts, commissions.
- KYC / identity verification: Performed by Stripe Inc. — we store only the verification status and time.
- Listing content: Title, description, images, catalogue numbers.
- Technical data: Session token (session cookie, strictly necessary).
3. Legal basis (GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)): Account management, auctions, purchases, payments.
- Legal obligation (Art. 6(1)(c)): Transaction data is retained for 7 years (Accounting Act), KYC/AML data for 5 years (Anti-Money Laundering Act); and reportable sellers are reported to the Finnish Tax Administration under DAC7 (Directive (EU) 2021/514; Act 1267/2022).
- Legitimate interest (Art. 6(1)(f)): Fraud prevention, platform security.
4. Cookies
We use a single strictly necessary session cookie (__Secure-next-auth.session-token) required for sign-in. It is exempt from consent requirements under the ePrivacy Directive. At checkout (Stripe), Stripe's own fraud-prevention cookies may be set — these are governed by Stripe's privacy policy.
5. Third-party recipients
- Stripe Inc.: Payment processing, identity verification (KYC), payouts. USA — safeguards: EU–US Data Privacy Framework.
- DeepL SE: Automatic translation of listing text. EU.
- Anthropic Inc.: AI-based condition assessment of stamp images. USA — safeguards: standard contractual clauses (SCC).
- Hetzner Online GmbH: Server operations and image storage. EU (Nuremberg).
- Finnish Tax Administration (Verohallinto): where you are a reportable seller, your identity and tax details and your gross proceeds are reported annually under DAC7. The authority shares the data with your country of residence. FI. See the Knowledge centre for the reporting thresholds.
6. Your rights (GDPR Art. 15–22)
- Access (Art. 15): Request a copy via Export my data.
- Rectification (Art. 16): Update your name and email in the account settings.
- Erasure (Art. 17): Delete your account via Delete my account. Note: transaction data is retained under the Accounting Act (7 years) and KYC/AML data under the Anti-Money Laundering Act (5 years).
- Data portability (Art. 20): Download your data via Export my data.
- Objection (Art. 21): Contact privacy@philmarket.eu.
You have the right to lodge a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutettu) in Finland, tietosuoja.fi, or with the supervisory authority in the EU country where you reside.
7. Security
Personal data is transmitted encrypted (TLS 1.3). Databases are protected by row-level security and access is restricted to authorised systems. Personal data breaches are reported to the competent supervisory authority within 72 hours in accordance with GDPR Art. 33.
8. Language
This document is provided in several languages. The English version is authoritative; in the event of any conflict between translations, the English version prevails.
9. Contact
Data protection contact: privacy@philmarket.eu.