Skip to main content

Legal

Privacy Policy

Last updated: 27 July 2026

Teodor is a small, EU-based art marketplace run by the guardians who represent the creators featured on this site. This policy explains what personal data we collect when you visit the site or buy or commission art, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR).

In this policy, "we" and "Teodor" refer to the guardian who operates this site on behalf of the featured creators. To contact us about anything in this policy, use the guardian contact address shown on the About and FAQ pages, or reply to any email you have received from the guardian about your order or commission.

1. What we collect and why

Commission and purchase requests. When you submit a commission or buy a piece, we collect your name, email address, an optional message, and — for physical originals — your shipping address. We use this to reply to your request, agree pricing and timing, prepare the order, and ship the artwork. Legal basis: performance of a contract (Art. 6(1)(b) GDPR), or steps taken at your request before entering into a contract.

Payment data. Payments are processed by Stripe, acting as an independent data controller and as our payment processor. Card details are entered directly into Stripe's checkout and are never stored on Teodor's servers. We receive from Stripe a payment reference, the amount, the currency, the buyer email, and the billing/shipping address you entered at checkout. Legal basis: performance of a contract, and our legitimate interest in receiving payment and preventing fraud (Art. 6(1)(b) and 6(1)(f) GDPR). See Stripe's own privacy notice at stripe.com/privacy.

Order correspondence. Emails you exchange with the guardian about a request or order are kept alongside the order record so we can service and resolve it.

Site usage. Our hosting provider records standard server logs (IP address, user agent, requested URL, timestamp) for security and reliability. We do not run third-party analytics or advertising trackers. Legal basis: legitimate interest in operating a secure site (Art. 6(1)(f) GDPR).

Authentication data (guardians and creators only). Accounts on the guardian dashboard and the creator studio use email/password authentication managed by our backend provider. This is not applicable to buyers, who do not create accounts.

2. Who we share data with

We share the minimum data needed with the following processors:

  • Stripe — to take and settle payments.
  • Our hosting and database provider — to run this site and store order records securely.
  • Our transactional email provider — to send order and commission emails to you and the guardian.
  • Shipping carriers — where you buy a physical original, your shipping address is passed to the carrier to deliver the piece.

We do not sell personal data and we do not share it for advertising.

3. International transfers

Some of our processors (notably Stripe) may process data outside the European Economic Area. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard.

4. How long we keep data

  • Commission enquiries that never turn into an order: up to 24 months, then deleted or anonymised.
  • Order records, invoices, and related correspondence: for as long as required by applicable tax and accounting law (typically up to 10 years in the EU).
  • Server logs: up to 30 days.

5. Your rights

Under the GDPR you have the right to: access the personal data we hold about you; ask us to correct it; ask us to delete it (subject to legal retention obligations); restrict or object to processing; and receive a copy in a portable format. You also have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, contact the guardian using the address shown on the About or FAQ pages. We will reply within 30 days.

6. Security

Data is stored on managed infrastructure with access controls, encryption in transit (HTTPS), and encryption at rest. Payment card data never touches our servers.

7. Changes to this policy

We may update this policy when the site changes. Material updates will be signalled by changing the "last updated" date at the top of this page.