PRIVACY POLICY
How we protect your personal data
1. Introduction
Iuppiter B.V. /Auction-it("we", "us", "our", or "Iuppiter") is committed to protecting your privacy and ensuring you have a positive experience on our online auction platform. This Privacy Policy explains how we collect, use, disclose, and otherwise process your personal data when you use our website www.auction-it.com, create an account, place bids, or purchase products.
We comply with the EU General Data Protection Regulation (GDPR), the Dutch Personal Data Protection Act (AVG), and other applicable data protection laws. Our commitment to data protection is further strengthened through our partnership with Shopify, which provides enterprise-grade security and GDPR compliance infrastructure.
2. Who We Are – Data Controller Information
Company Name: Iuppiter B.V./Auction-it
Address: Keersopstraat 51, 3044 EX Rotterdam, The Netherlands
Chamber of Commerce (KvK) Number: 65522133
Email: info@iuppiter.nl
Role: Iuppiter B.V. is the data controller, meaning we determine the purposes and means of processing your personal data.
2.1 Shopify – Our GDPR-Compliant Technology Partner
Account Infrastructure: Iuppiter B.V. uses Shopify, a leading global e-commerce and account management platform, to manage customer accounts, store personal data securely, and process transactions.
Data Processing Agreement: Shopify operates under a comprehensive Data Processing Agreement (DPA) that ensures full GDPR compliance. Shopify is designated as a Data Processor under Article 28 of the GDPR.
Security & Compliance Benefits:
Shopify maintains ISO 27001 certification for information security
All data is encrypted in transit (SSL/TLS) and at rest
Shopify undergoes regular third-party security audits and penetration testing
Automatic daily backups with disaster recovery procedures
Shopify maintains SOC 2 Type II compliance
Strict access controls limit employee access to customer data on a need-to-know basis
24/7 monitoring and intrusion detection systems
Data Location: Your account data is stored on Shopify's secure servers located within the European Union, ensuring compliance with GDPR data residency requirements.
3. What Personal Data We Collect
We collect different categories of personal data depending on how you interact with us:
3.1 Information You Provide to Us (Stored in Shopify)
Account Registration:
Name, email address, password, phone number, postal address, country of residence
Business Users (Companies):
Company name, business address, VAT number, contact person details, business registration information
Payment Information:
Bank account details, payment method information (Shopify processes payments with PCI-DSS compliance; we do not store credit card details)
Shipping Information:
Delivery address, shipping preferences
Communication:
Messages, inquiries, and correspondence with our customer service
All of the above information is securely managed through Shopify's enterprise-grade infrastructure.
3.2 Information Collected Automatically (Tracked and Stored Securely)
Website Activity:
Pages visited, products viewed, auction participation, bidding history, time spent on site
Device Information:
IP address, browser type, operating system, device type, unique device identifiers
Cookies and Tracking:
Session cookies, persistent cookies, local storage, analytics data (Shopify's analytics platform provides GDPR-compliant tracking)
3.3 Information From Third Parties
Compliance & Verification:
VAT verification through official EU VAT databases, KYC (Know Your Customer) checks through third-party verification services, credit checks (where applicable), sanction screening through specialized providers (Actradius, etc.)
Financial Institutions:
Information from payment processors and banks for fraud prevention and transaction verification
4. Why We Collect and Use Your Data (Legal Basis)
4.1 Account Management & Service Delivery
Create and manage your account (via Shopify platform)
Process your bids and auction participation
Process payments and invoicing
Arrange shipping and delivery
Provide customer support
Legal Basis: Performance of contract (our agreement with you) – GDPR Article 6(1)(b)
4.2 Compliance & Legal Obligations
Verify your identity and prevent fraud
Comply with the Dutch Money Laundering and Terrorist Financing Prevention Act (Wwft)
Perform Know Your Customer (KYC) checks
Screen against international sanction lists
Comply with export control regulations
Maintain records for audit and tax purposes
Legal Basis: Compliance with legal obligations – GDPR Article 6(1)(c)
4.3 Fraud Prevention & Security
Detect and prevent fraudulent bidding, non-payment, and misuse
Monitor transactions for suspicious activity
Secure our platform and protect against unauthorized access (Shopify's security measures support this)
Legal Basis: Our legitimate interests (protecting the platform and users) – GDPR Article 6(1)(f)
4.4 Marketing & Communication (With Your Consent)
Send newsletters and promotional information (if you opted in)
Notify you about new auctions matching your interests
Send service updates and important announcements
Legal Basis: Your consent – GDPR Article 6(1)(a)
4.5 Website Analytics & Improvement
Understand how users interact with our platform
Improve website functionality, user experience, and auction services
Generate anonymized analytics and statistics (via Shopify's GDPR-compliant analytics)
Legal Basis: Our legitimate interests (improving services) – GDPR Article 6(1)(f)
5. Who We Share Your Data With
We do NOT share your personal data with third parties for their marketing purposes. However, we may share your data with the following categories of recipients:
5.1 Service Providers & Data Processors
Shopify: Account management, data storage, and infrastructure (Data Processor under GDPR Article 28 with DPA in place)
Payment Processors: To process your payments securely (integrated with Shopify)
Shipping & Logistics Providers: To arrange and track your deliveries
Email Service Providers: To send you order confirmations and notifications
Verification & Compliance Services: To perform VAT checks, KYC verification, and sanction screening (e.g., Actradius, specialized verification providers)
Analytics Providers: To understand website usage patterns (Shopify Analytics)
Website & IT Service Providers: To host our website and maintain platform security
All service providers are contractually bound to protect your data with appropriate security measures. Shopify, in particular, maintains industry-leading security standards and GDPR compliance.
5.2 Legal Authorities & Compliance
We may disclose your data if required by law, court order, or government request (e.g., law enforcement, tax authorities, financial crime investigators).
5.3 Business Transactions
If Iuppiter B.V. is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you of any such change.
6. How Long We Keep Your Data (Data Retention)
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
Account Data: Retained while your account is active and for 5 years after closure (for legal and tax purposes)
Transaction & Payment Records: Retained for 7 years (Dutch tax law requirement)
Compliance & KYC Records: Retained for 5 years minimum (Wwft legal requirement)
Email Communications: Retained for 2 years or until you request deletion
Website Analytics: Retained for up to 26 months
Cookies: Session cookies deleted when you close your browser; persistent cookies retained for up to 12 months
After the retention period expires, we securely delete or anonymize your data. Shopify ensures secure deletion in compliance with GDPR standards.
7. How We Protect Your Data (Security)
We implement comprehensive technical and organizational security measures to protect your personal data:
Encryption: All data transmitted between your device and our servers is encrypted using SSL/TLS technology
Secure Database: Our data is stored in Shopify's databases, protected with industry-standard security protocols
Access Controls: Only authorized employees with a legitimate need can access your data
Regular Audits: Shopify conducts regular security assessments, penetration testing, and maintains ISO 27001 & SOC 2 Type II certifications
Firewalls: We maintain firewalls and intrusion detection systems
Data Minimization: We collect and retain only the data necessary for our stated purposes
Shopify Infrastructure: All data is backed up daily with disaster recovery procedures in place
While we implement robust security measures through Shopify's enterprise-grade infrastructure, no system is 100% secure. We encourage you to use strong passwords and protect your account credentials.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience:
Essential Cookies: Required for website functionality (login, security, auction participation)
Analytics Cookies: Help us understand how you use our platform (via Shopify Analytics, which is GDPR-compliant)
Preference Cookies: Remember your settings and preferences
Marketing Cookies: Track which products interest you (if you consent)
You can control cookies through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent.
9. Your Data Protection Rights
Under GDPR and Dutch law, you have the following rights regarding your personal data:
Right of Access: You can request a copy of the personal data we hold about you
Right to Rectification: You can correct inaccurate or incomplete data
Right to Erasure ("Right to be Forgotten"): You can request deletion of your data, subject to legal obligations
Right to Restrict Processing: You can limit how we use your data
Right to Data Portability: You can receive your data in a structured, commonly-used format
Right to Object: You can object to certain types of processing
Right to Withdraw Consent: If we process data based on your consent, you can withdraw it at any time
To exercise any of these rights, contact us at info@iuppiter.nl with your request and supporting documentation.
We will respond within 30 days of receiving your request.
10. International Data Transfers
Our servers and most of our service providers are located within the European Union. Shopify maintains data centers within the EU to ensure GDPR compliance. If your data is transferred to countries outside the EU, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses, adequacy decisions) to protect your data in accordance with GDPR requirements.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date below. Your continued use of our platform following any changes constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us:
Email: info@iuppiter.nl
Address: Iuppiter B.V., Keersopstraat 51, 3044 EX Rotterdam, The Netherlands
KvK Number: 65522133
Data Protection Authority:
If you are not satisfied with our response, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens – AP):
Website: www.autoriteitpersoonsgegevens.nl
Email: info@ap.nl
Last Updated: August 2026 (Updated for Shopify Integration)
Version: 2.0