Updated
September 16, 2026
Data Processing Addendum - 2026
Table of content
This Data Processing Addendum replaces and consolidates the previous Artlogic version and will also apply to ArtCloud.
For existing customers they are effective from 16 October 2026.
For new customers they are effective immediately.
Data Processing Addendum (“DPA”)
This DPA is incorporated into and forms part of the Agreement as defined in the Artlogic General Terms & Conditions of Service (“General Terms”). This DPA shall apply if and to the extent that the Processor collects or processes Personal Data in performing the Agreement.
- Definitions
- "Applicable Data Protection Laws" means the EU General Data Protection Regulation (“GDPR”), UK GDPR and the UK Data Protection Act 2018.
- “Controller” means You, as defined in the General Terms.
- “Data Subject” and “Personal Data” have the meanings set out in Applicable Data Protection Laws.
- “Processor” means Artlogic, as defined in the General Terms.
- Processing of Personal Data
- Instructions: Processor shall process Personal Data only on the documented instructions of Controller, including with regard to transfers of personal data to a third country.
- Purpose: The scope, nature, and purpose of the processing are set out in Annex I.
- Compliance: Clause 2.1 shall not apply to the extent Controller’s instructions are contrary to Applicable Data Protection Laws, in which case Processor shall inform Controller of such legal requirement, unless the law prohibits such information on important grounds of public interest.
- Processor Personnel: Processor shall ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Data Subject Rights: Processor shall, insofar as is possible, assist Controller by appropriate technical and organisational measures to fulfill Controller’s obligations to respond to requests for exercising Data Subject rights under Applicable Data Protection Laws.
- Deletion or Return: Processor shall (at the option of Controller) delete or return Personal Data processed by the Controller under this DPA after the end of the provision of services relating to such data, and shall delete existing copies of such data unless prohibited by applicable law.
- Information and Audit: Processor shall make available to Controller all information necessary to demonstrate compliance with the obligations of this DPA, and shall contribute to data protection audits, including inspections, conducted by the Controller or an auditor mandated by Controller.
- Security of Processing
- Measures: Taking into account the state of the art and the nature of processing, Processor shall implement the technical and organisational security measures specified in Processor’s Security policy at https://artlogic.net/legal/security/.
- Assistance: Processor shall assist Controller in ensuring compliance with obligations under Applicable Data Protection Laws regarding security, breach notification and data protection Impact assessments.
- Notification: Processor shall notify Controller without undue delay (and, where feasible, within 48 hours) after becoming aware of a personal data breach (as defined in Applicable Data Protection Laws) affecting Personal Data processed under the Agreement.
- Sub-processing
- Authorisation: Controller grants Processor a general written authorisation to engage sub-processors from the list at https://artlogic.net/legal/sub-processors/.
- Notification: Processor shall notify Controller of any addition or replacement of sub-processors at least 30 days in advance, giving Controller the right to object.
- International Transfers
- For transfers of Personal Data from the EEA to countries not deemed "adequate" by the European Commission, the parties agree to abide by the Standard Contractual Clauses (Module Two: Controller-to-Processor) annexed to the European Commission Implementing Decision 2021/914, customised and applied as specified in Annex II (“SCCs”).
- For transfers of Personal Data from the UK to countries not deemed "adequate" by the UK Information Commissioner's Office (“ICO”), the parties agree to comply with the SCCs and the International Data Transfer Addendum (Version B1.0) issued by the ICO, customised as specified in Annex II (“UK Addendum”).
- In the event of a conflict between this DPA and the SCCs/UK Addendum, the SCCs/UK Addendum shall prevail.
Annex I: Details of Processing
- Subject Matter: The provision of Products as specified in the Agreement.
- Duration and Frequency: The term of the Agreement plus the period until deletion of all data. Processing is expected to be regular and ongoing, at the discretion of Controller.
- Nature and Purpose: To provide data related to the Products as specified in the Agreement. Products generally involve services to galleries, artists and collectors of art.
- Data Subjects:
- Controller's employees, agents, advisors and freelancers, including Controller's authorised users of the Services.
- Controller's customers, prospects, professional contacts and suppliers.
- Controller's website visitors, mailing list subscribers.
- Employees, agents and freelancers of Controller's customers, prospects, professional contacts and suppliers.
- Collectors and prospective buyers who interact with the Controller's presence on the ArtCloud Marketplace.
- Categories of Data:
- Identity Data: first name, last name, title, job title, employer, user account details.
- Contact and Location Data: home address, work address, email addresses, telephone numbers, IP address (for technical and security purposes).
- Transaction and Financial Data: purchase history, offers made and received, invoicing and billing information, payment records, purchase enquiries, direct purchase records, and payment processing data where the Controller has enabled payment processing.
- Interests and Collection Data: art collections, collecting interests, artworks for sale or consignment.
- Technical and Usage Data: login credentials, device information, browser type, log files, cookies and similar technologies, usage patterns within the Services.
- Communications Data: enquiries, correspondence, and marketing preferences, including mailing list subscriptions.
- Visual / Media Data: images and other media uploaded to or processed through the Services, which may include personal data.
- Collector Preference and Behavioural Data: artwork favourites, curated lists, gallery and artist follows, and browsing and discovery activity within the ArtCloud Marketplace.
- Categories of Sensitive Data: The Controller may at its discretion provide special categories of personal data as defined in Art. 9 of EU and UK GDPR.
- Transfers to Sub-processors: As specified at https://artlogic.net/legal/sub-processors/.
Annex II: Cross-Border Transfer Agreements
1. SCCs
The parties agree that for the purposes of the SCCs (Module Two):
- Clause 7 (Docking) is excluded.
- Clause 9 (Sub-processors): Option 2 (General Authorisation) applies.
- Clause 17 (Governing Law): Option 1 and the laws of Ireland apply.
- Clause 18 (Forum): The courts of Dublin, Ireland.
- Annex I
- Parties: same as under the Agreement
- Description of transfer: per Annex I of this DPA
- Competent supervisory authority: Irish Data Protection Commission.
- Annex II: https://artlogic.net/legal/security/.
- Annex III: As specified at https://artlogic.net/legal/sub-processors/.
Processor has determined that application of the SCCs is appropriate under this DPA on the following grounds:
- Nature of the processing: Artlogic processes Personal Data solely on behalf of the Controller in order to provide the Services described in the Agreement. Processing activities are limited to hosting, storage, organisation, retrieval and transmission of data necessary for the operation of the Services.
- Nature of the data: The Products are designed primarily to process transactional and relationship information relating to individuals’ interactions with the Controller, such as collectors, contacts, customers, artists and suppliers. The system is not designed for the intentional processing of special category data. Where the Controller utilises the ArtCloud Marketplace, processing may include collector preference and behavioural data, purchase enquiries, and transaction data for collector interactions with the Controller's Marketplace presence.
- Limited risk profile: The categories of Personal Data processed are generally limited to identity, contact, transactional, communications and usage data connected with the Controller’s activities.
- Appropriate safeguards: Artlogic implements appropriate technical and organisational measures to protect Personal Data, including access controls, authentication mechanisms, encryption in transit, system monitoring, logging and vendor/sub-processor oversight.
- Processor role: Artlogic acts solely as a processor and processes Personal Data only on documented instructions from the Controller.
2. UK Addendum
The parties agree that the UK Addendum is appended to the SCCs, and completed as follows:
- Table 1
- Parties: same as under Agreement.
- Key contacts: Artlogic Data Protection Officer, privacy@artlogic.net.
- Tables 2 & 3: As specified in paragraph 1 of this Annex II.