Effective Date: 30 May 2025

Last Updated: 30 May 2025


Who We Are

Legal Entity: Art.One Unipessoal LDA

Company Number / VAT: PT515874540

Address: Avenida Portugal, 590, Estoril, 2765-272, Portugal

Email Contact: info@artpointone.store

Data Protection Officer (DPO): Not appointed

We have assessed our data processing activities and concluded that appointing a Data Protection Officer is not legally required under Article 37 of the GDPR.


What Personal Data We Collect

We collect personal data to provide our products and services, process orders, and improve your experience. This includes:

a. Information You Provide Directly (Legal Basis: Contract, Consent):

  • Name, shipping/billing address, email, and phone number
  • Payment and transaction details (processed securely via Shopify and third-party providers)
  • Account registration information
  • Messages and reviews you submit

b. Information We Collect Automatically (Legal Basis: Legitimate Interests, Consent):

  • IP address, browser type, device information
  • Usage data and session logs
  • Cookie-based tracking and analytics data

Legal Bases for Processing

We process your data under the following legal bases:

  • Performance of a contract: to process and fulfill your orders
  • Legitimate interests: to improve our services, prevent fraud, and communicate relevant updates (we have conducted a Legitimate Interests Assessment to ensure your rights are not overridden)
  • Legal obligation: for accounting, tax, and compliance requirements
  • Consent: for email marketing and cookie-based personalization (you may withdraw consent at any time)

How We Use Your Data

We use your data to:

  • Fulfill and manage orders and payments
  • Respond to customer support requests
  • Improve our Site and services through analytics
  • Send order confirmations, updates, and optional promotional emails
  • Prevent fraud and ensure platform security

We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects.

We do not use your data for profiling or automated decision-making that produces legal or similarly significant effects.


Cookies and Tracking

We use cookies to:

  • Ensure site functionality (Legal Basis: Legitimate Interests)
  • Analyze traffic via tools like Google Analytics (Legal Basis: Consent)
  • Personalize advertising (e.g., Facebook Pixel) (Legal Basis: Consent)
  • Send cart reminder emails (Legal Basis: Consent)

You can manage cookies through your browser settings or via our cookie banner. For more details, see our Cookie Policy.

Our cookie banner enables you to accept, reject, or customize cookie preferences. We do not place non-essential cookies until consent is given, in line with the ePrivacy Directive and GDPR.

We use a GDPR-compliant tool (e.g., Cookiebot or OneTrust) to collect and log your cookie preferences. Consent records are securely stored and may be presented upon request. Cookies are retained for a maximum of 12 months unless renewed by user action.


Sharing Your Data

We share data only as necessary with:

  • Shopify (e-commerce platform)
  • Payment processors (e.g., PayPal, Stripe)
  • Email providers (e.g., Klaviyo)
  • Shipping/logistics partners
  • Analytics and advertising tools (e.g., Google Analytics, Meta Pixel)

All third-party service providers are bound by contractual data protection obligations and process your data in compliance with GDPR. We have signed Article 28-compliant Data Processing Agreements with each of them.


International Data Transfers

Some data may be processed outside the EU, including in countries such as the United States and Canada. In these cases, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Other appropriate safeguards to ensure your data is protected

Data Retention

We retain your data only as long as necessary:

  • Order and transaction data: typically 6 years (for legal/accounting reasons)
  • Newsletter subscription data: until you unsubscribe
  • Account data: until you request deletion
  • Cookie and analytics data: retained for up to 12 months

We will review and securely delete or anonymize unnecessary data.


Your Rights Under GDPR

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Object to or restrict processing
  • Receive a copy of your data (portability)
  • Withdraw consent at any time

To exercise your rights, email info@artpointone.store. We may ask for proof of identity to protect your data.

We aim to respond to all data subject requests within one month, in accordance with Article 12 of the GDPR. If your request is complex, we may extend this period by up to two additional months and will inform you accordingly.

You have the right to lodge a complaint with a supervisory authority, such as the Comissão Nacional de Proteção de Dados (CNPD) in Portugal: www.cnpd.pt, Tel: +351 213 928 400, Email: geral@cnpd.pt


Data Security

We implement security measures like SSL encryption, access controls, and secure infrastructure (via Shopify and other partners). However, no system is 100% secure — transmission over the internet is at your own risk.


Children's Privacy

Our site is not intended for children under 16. We do not knowingly collect personal data from minors without parental consent. If you believe a child has provided personal data to us, please contact us immediately to have it removed.


Third-Party Links

Our website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their policies independently.


Updates to This Policy

We may update this policy periodically. Changes will be posted on this page with an updated effective date. We recommend reviewing it regularly. Previous versions are available upon request.


Contact Us

For any questions or concerns regarding your privacy or this policy, contact:

Email: info@artpointone.store

Mail: Avenida Portugal, 590, Estoril, 2765-272, Portugal