01 / Responsibility
Who looks after your data?
ArtifactArchive is responsible for deciding how personal information collected through artifact-archive.com is used. In data-protection law, this role is called the data controller. Contact us at [email protected] for privacy questions, requests or complaints.
This notice covers the archive, artwork viewer, print customisation, checkout and order updates. Independent websites you visit through our links have their own notices. This notice describes our handling of information under the UK General Data Protection Regulation, the Data Protection Act 2018 and applicable rules on cookies and electronic communications.
02 / Information
What reaches us?
You can explore the archive without creating an account. We receive information you provide, technical information needed to operate the site, and payment and delivery updates from our service providers.
Required checkout fields are needed to calculate delivery and process the order; without them, we cannot prepare checkout or arrange delivery. Optional address fields can be left empty where they are not needed. If you provide another person's delivery details, please share this notice with them.
03 / Purpose & legal basis
A reason for each use.
Views measure requested article pages, not unique people. Reloading an article can add another view; restoring a cached page without a server request does not. Automated requests may be included. We do not use advertising pixels or behavioural advertising, or use order emails for marketing. Your view-counting preference does not authorise other tracking or marketing.
Prices and delivery options depend on the selected edition and destination. We do not make solely automated decisions with legal or similarly significant effects on you. Stripe operates its own payment authentication and fraud-risk systems; contact us if a payment problem needs review.
05 / International processing
Services across borders.
Payment, hosting, email and print fulfilment can involve processing outside the UK, including in the United States. Printify works with print providers and delivery services internationally; the product and destination affect where your order is fulfilled.
Stripe and Printify describe international processing and safeguards in their published privacy policies and data processing terms. Earlier Prodigi orders remain covered by that supplier's published terms.
ArtifactArchive remains responsible for ensuring that its own restricted transfers have appropriate safeguards. Using a provider does not remove that responsibility. Email [email protected] to ask about a transfer affecting your information or request a copy or explanation of the relevant safeguards.
06 / Retention
Kept for a purpose.
Retention depends on the record and why it is needed. Where there is no fixed duration, the following criteria determine the necessary retention period. A quote expiring does not mean its stored record has been deleted automatically.
Ask us about a particular record or request deletion using the contact details below. We will explain if an applicable legal obligation or unresolved matter requires retention. Providers may also retain information for their own obligations, as explained in their notices.
08 / Security
Care with access.
The application restricts administrative access using authentication and an email verification step. Private order pages require an access token. Stripe handles card entry; this application does not store full card details.
Your private order-status link grants access to order information. Keep it safe and contact us if it is shared without permission. No online service can promise absolute security; applicable breach notification duties still apply.
We do not ask for sensitive personal information to explore the archive. If a child or another person submits information unintentionally, contact us so we can assess the record and take appropriate action.
09 / Your rights
Ask. Correct. Take control.
Depending on the data and legal basis, you can request access, correction, deletion, restriction of processing, or a portable copy of information you provided where portability conditions apply.
Your right to object: you can object to processing based on legitimate interests for reasons relating to your circumstances. We must consider your objection and stop unless the law permits us to continue. You can always object to direct marketing.
Where processing relies on consent, you can withdraw it at any time without affecting earlier lawful processing. Aggregate article view counting does not rely on consent. You can stop future counting at any time by choosing Stop view counting in Privacy preferences.
Email [email protected] with enough information to find the record, such as your checkout email and order reference. Do not send card details or identity documents unless we explain why proportionate verification is needed.
We normally respond without charge and within one calendar month. Where the law allows additional time, clarification or identity verification, we will explain what is needed and any applicable extension. If a request cannot be granted in full, we will explain the reason and how to challenge it.
10 / Contact & complaints
A direct line to us.
Email [email protected] for a privacy question, data request or complaint. A subject such as “Privacy request” or “Privacy complaint” helps identify the message but is not required.
We acknowledge data-protection complaints within 30 days, investigate without undue delay, keep you informed and explain the outcome. Raising a concern does not affect your other legal rights.
You can also contact the Information Commissioner's Office, the UK's data-protection regulator, on 0303 123 1113, or write to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Where applicable, you can complain to the supervisory authority in your country.
We update this notice when our services or practices change. The date above identifies this version. If a new use requires fresh information or consent, we will provide that before it starts; publishing an update alone is not consent.