This Policy covers information that you give to us when you bid on an item, purchase something from us,consign work of art or other goods to us, register for or attend any of our live auctions around the world,visit or register for any of our websites or apps, request a catalogue, sign up for any of our print oronline publications or newsletters, or publish information on our pages on social media platforms. Wewill publish a link to the Policy at the bottom of online properties to which it applies and as often aspossible, will include its URL on paper forms to which it is applicable.
HOW HESSINK’S COLLECT INFORMATION ABOUT YOU
Personal information is information, or a combination of pieces of information that could reasonablyallow you to be identified. We will collect personal information about you from a variety of sources,including information we collect from you directly (e.g. when you contact us), information we collectabout you from other sources and information we collect automatically from you, as described below:
Information We Collect Directly From You
The categories of information that we collect directly from you are: personal details (e.g., name, date ofbirth), contact details (e.g., phone number, email address, postal address), transaction information (e.g.,bidding or purchase records, shipping details, information about items you purchase or wish to consign),limited financial information (e.g., tokenized payment information in connection with your purchases,wire instructions) information about your property in our possession or storage, username andpassword, and identification information.
We rely on the information you provide to us or that we collect or observe about your individualinteractions with us, for example, if you attend a live event, participate in one of our auctions, become aclient, or register online. If you have registered with us online, we use data collection technologies tocollect information that indicates your individual interests in our websites, online platforms and apps,and your response to our emails and marketing campaigns.
Information We Collect From Other Sources
We may add public information about you from external sources, including social media sites. Thecategories of info we collect about you from other sources are your public profile information, familyrelationships, and organizational affiliations. We may work to expand our customer base by acquiringnames, contact data, financial information, affiliations, and demographic information from othersources such as private companies, public registers, and social media sites. We may also generate
information such as appraisals, profiles, and a history of our relationships with you based on theinformation you have provided or that we have obtained from other sources.
We may make video recordings of our auctions, gallery spaces, and certain live events.
Information We Collect Automatically
We may use common data collection technologies as you visit our websites or apps or interact with ouremails:
- Our logs gather date, time, information about your browser and system or device configuration, information about how you interact with our digital properties, and an IP address for all visitors to our sites. We use this information for our internal security purposes, for trend analysis and system administration, and to gather general information about our audiences and their geographic locations.
- In general, our app will funnel data you provide about yourself, for example, registration, purchase or bidding data, back to our data bases and systems. An app may however, rely on other data collection technologies to recognize the device you use for viewing and personalize your experience. If our app relies on additional data collection technologies that collect or use data about individual users, we will include additional notice either within the app or in a policy that accompanies it.
- We also use and allow certain other companies to use technologies that are similar to cookies (for example pixels and gifs) when we send you emails. This helps support the delivery of Internet-based content and advertisements to you.
The way we analyze personal information for advertising and marketing purposes and for clientdevelopment, risk assessment, or fraud prevention may involve profiling, which means that we mayprocess your personal information using software that is able to evaluate your personal aspects andpredict risks or outcomes. For example, we may use the information we collect (e.g., bidding andpurchase information, browsing history, and consignment history) to infer your interests. And we mayuse those inferences to support automated decisions about the content, recommendations, and offerswe present to you on our digital properties. We may use automated tools to flag for further reviewsuspicious activities associated with our digital services (e.g., multiple logins from different locationswithin a short period of time or activities associated with suspicious IP addresses). These automatedactivities will not, in themselves, have legal or similar effects for you.
HOW HESSINK’S USES INFORMATION ABOUT YOU
Hessink’s uses data about you for the following purposes:
- To manage and assure the integrity of our auctions.
- To fulfill your orders and purchases, facilitate consignments, provide the services, publications, catalogs, and information you request, and manage your account, enquiries and requests and to manage your relationship with us.
- To send you information about upcoming events and content that you may be interested in.
- To improve and personalize based on your inferred interests our website and services.
- To match online ads to your interests, arrange for Hessink’s and other companies’ ads to reach you after you have left our sites, and help advertisers show you ads that are more relevant to your interests.
- To expand our online audiences.
- To provide, maintain, and protect our digital offerings.
- To protect against risk of fraud by clients.
- To protect and defend our rights and property, you, or third parties.
- To comply with legal obligations to which we are subject and cooperate with regulators and law enforcement bodies.
- For any other purpose that we tell you about specifically when you register or provide data about yourself to us.
WHEN HESSINK’S MAY DISCLOSE INFORMATION THAT IDENTIFIES YOU
Hessink’s may disclose or transfer data that identifies you to other companies or entities only as follows:
- To business partners and vendors that work on our behalf to provide services such as item shipments, mailings, customer account and technology support, secure payment processing, fraud prevention, digital marketing management, and data storage.
- To our online auction partners in association with auctions.
- To consigners and others as needed to facilitate a consignment or purchase.
- To organizations we partner with to host events.
- To other companies within the Hessink’s group of companies for marketing, business development purposes and internal reporting.
- To law enforcement or other entities that present valid legal process or in our discretion, unless otherwise prohibited by law, to protect human safety, our rights, or the rights of others.
- To meet certain legal compliance requirements for example, under AML (anti-money laundering) laws, or customs laws and regulations.
- As part of a sale, merger, liquidation, or transfer of our business assets.
You have a choice about and control over:
- Receiving marketing messages from us. We may contact you by email, text, or SMS messaging.
- We encourage you to visit Hessink’s Preference Pages to let us know what information you would like us to send to you and your preferred means of delivery.
- You may also stop email marketing by using the “opt out,” or “unsubscribe” mechanism at the bottom of our email marketing messages. In most cases, we will give you a choice about stopping just one kind of email or opting out of all email marketing from us.
- If you have provided data about yourself to a member of Hessink’s and reside in the European Union (“EU”) you have the legal right to ask us not to process that personal data about you for marketing purposes and to revoke your consent at any time. To make such a request, please contact firstname.lastname@example.org .
- Whether your account is up to date. You may review and edit the Personal Information that is stored in your user account on our website (e.g., your passwords and other contact information) by visiting the “Profile” area of your account on our website or by contacting Hessink’s via the email address at the end of this policy. We will endeavor to respond to your request as soon as practicable. Before we are able to provide you with any information, correct any inaccuracies, or delete any information, however, we may ask you to verify your identity and to provide other details to help us to respond to your request.
INFORMATION SECURITY AND STORAGE
Hessink ltd. is a global company. We receive data collected locally by members of the Hessink’s group ofcompanies and collect data online directly from individuals in countries around the world. We mayprocess that data on servers globally. We have put recognized protections in place for the transfer ofdata from members of the Hessink’s group of companies in the EU to our servers in Jersey and theNetherlands.
We protect your information using physical, technical, and administrative security measures to reducethe risks of loss, misuse, unauthorized access, disclosure, and alteration. Please be aware, though, thatno security measures are perfect or impenetrable. You remain responsible for protecting your usernameand password and for the security of information you transmit to us over the Internet.
We will keep your personal information for as long as we have a relationship with you. Once ourrelationship with you has come to an end, we will retain your personal information for a period of timethat enables us to:
- Maintain business records for analysis and/or audit purposes.
- Comply with record retention requirements under the law or other relevant legal or regulatory requirements.
- Defend or bring any existing or potential legal claims.
- Deal with any complaints regarding the services.
- Preserve historical records of transactions and property.
We will delete your personal information when it is no longer required for these purposes.
Our websites are directed to adults, including young adults. They are not directed to children,particularly those under the age of thirteen. We do not accept them as clients or knowingly collect dataabout them.
LINKS TO THIRD PARTY WEBSITES
Our websites may contain links to other websites not owned or controlled by Hessink’s. Those websitesmay collect information about you. Hessink’s is not responsible for their practices or content.
HOW TO CONTACT US
ADDITIONAL INFORMATION FOR EEA CUSTOMERS & VISITORS TO HESSINK’S SITES AND APPS
In order to meet privacy regulations in the European Economic Area (“EEA”) and Switzerland, Hessink’sprovides additional information to its EEA based customers, website visitors, and users of its apps.Who is responsible for your data?
If you transact in an auction or private sale in a Hessink’s office in the EEA or Switzerland, then theHessink’s entity running the auction will be the data controller for that data. The name and contactdetails for this entity will be set out in your consignment agreement, private sale agreement, invoice, orConditions of Business for the auction.
If you visit Hessink.com, another Hessink’s website or use a Hessink’s app, then the data controller willbe Hessink’s, a Mauritius based entity, and this Policy contains our contact details. Hessink’srepresentative in the EU is Hessink’s Netherlands.
What is the legal basis on which Hessink’s relies to process your data?
On some occasions, Hessink’s processes your data with your consent (e.g., when you agree that we mayplace cookies, or if you ask Hessink’s to send you information about upcoming events).
On other occasions, Hessink’s processes your data when we need to do this to fulfill a contract with you(e.g., for billing purposes) or where we are required to do this by law (e.g., where we have to fulfill anti-money laundering requirements). If it is mandatory for you to provide data for these purposes, we willmake this clear at the time and will also explain what will happen if you do not provide the data (e.g.,that we will not be able to process a bid at auction).
Hessink’s also processes your data when it is our legitimate interests to do this and when these interestsare not overridden by your data protection rights. For example, Hessink’s has a legitimate interest inensuring the security and integrity of our auctions, in learning about the interests and preferences ofour current and prospective clients, in developing new business opportunities, in maintaining accuratebusiness and provenance records, and in ensuring that our websites and apps operate effectively. Whenwe process personal information to meet our legitimate interests, we put in place robust safeguards toensure that your privacy is protected and to ensure that our legitimate interests are not overridden byyour interests or fundamental rights and freedoms.
Hessink’s may transfer personal data to countries outside the EEA, including to countries which havedifferent data protection standards to those which apply in the EEA. Hessink’s has put in place EuropeanCommission approved standard contractual clauses to protect this data. For more information on theappropriate safeguards in place, please contact us at the details above.
You may ask Hessink’s for a copy of your personal information, to correct it, erase it, restrict our use ofit, or to transfer it to other organizations at your request subject to local law. You also have rights toobject to some processing and, where we have asked for your consent to process your data, towithdraw this consent. In particular, you have rights to object to direct marketing at any time. Where weprocess your data because we have a legitimate interest in doing so (as explained above), you also havea right to object to this. These rights may be limited in some situations – for example, where we candemonstrate that we have a legal requirement to process your data.
If you would like to discuss or exercise such rights, please contact us at the details above. We encourageyou to contact us to update or correct your information if it changes or if the personal information wehold about you is inaccurate. We will contact you if we need additional information from you in order tohonor your requests.
We hope that we can satisfy queries you may have about the way we process your data. We arecommitted to working with you to obtain a fair resolution of any complaint or concern about privacy.However, if you have unresolved concerns and believe that we have not been able to assist with yourcomplaint or concern, you also have the right to complain to data protection authorities.
Changes to this Policy
You may request a copy of this Policy from us using the contact details set out above. We may modify orupdate this Policy from time to time.
If we change this Policy, we will notify you of the changes by updating this Policy on our website. Wherechanges to this Policy notice will have a fundamental impact on the nature of the processing orotherwise have a substantial impact on you, we will give you sufficient advance notice so that you havethe opportunity to exercise your rights (e.g., to object to the processing if you are located in the EEA orSwitzerland).