<link rel="stylesheet" href="styles-ODNGYYJE.css">

PRIVACY POLICY

CLICK HERE TO READ ITS REPORTING VERSION


Pursuant to Articles 12, 13 and, where applicable, 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree No. 196 of 30 June 2003, as amended by Italian Legislative Decree No. 101 of 10 August 2018 (the "Italian Privacy Code")


Last updated  ·  25 August 2026


This Privacy Notice explains how Memorabid S.r.l. processes the personal data of users who visit or use www.memorabid.com and the related services, including account registration, participation in auctions, the management of bids, awards, payments, shipments, support and communications connected with the initiatives available on the platform (collectively, the "Service").



1. Data Controller

The Data Controller is:

Memorabid S.r.l.

Foro Buonaparte 59

20121 Milan (MI), Italy

E-mail: info@memorabid.com

Requests concerning personal data protection or the exercise of data protection rights may be sent to the e-mail address above.



2. Scope of this Notice

This Notice applies solely to processing carried out in connection with the Service. Third-party websites, platforms and services that may be accessed through links or embedded content operate under their own privacy notices, unless they process data on Memorabid's behalf as Data Processors.



3. Categories and sources of personal data

Memorabid may process the following categories of personal data:

•      identity and contact data: first name, last name, e-mail address, telephone number, physical address, shipping and billing address, city, postal code, province or state, and country;

•      tax and administrative data: Tax ID, billing information and information required to comply with accounting and tax obligations;

•      account data: login credentials or authentication identifiers, preferences, consent records, settings, followed auctions, favourite lots and the history of activities carried out through the profile;

•      auction and transaction data: bids, date and time of operations, auctions and lots of interest, awards, orders, amounts, payment status, any refunds or disputes, delivery data and communications relating to the transaction;

•      payment-related data: transaction and customer identifiers assigned by the payment service provider, the outcome of payment-method verification, and the last digits and type of payment method where made available by the provider. Memorabid does not receive or store the full card number or security code;

•      data provided by the user: the content of enquiries, messages, complaints, communications sent to customer support or through forms, and any other information provided while using the Service;

•      technical and usage data: IP address, requested URIs, date and time of requests, system logs, unique identifiers, device, browser and operating-system information, session data, pages visited, interactions, usage statistics, and approximate location derived from the IP address, such as city, metropolitan area, region, state, country, and city-level latitude and longitude;

•      communications and campaign data: newsletter subscription, message opening date and time, and interactions with links, where permitted by law;

•      cookie and tracking data: online identifiers, consent preferences and the information described in the Cookie Policy.

Personal data is collected:

•      directly from the user, for example during registration, participation in an auction, a purchase, a support request or newsletter subscription;

•      automatically by the website and the systems required for its operation;

•      from providers involved in delivering the Service, such as the payment service provider and courier, limited to the outcomes and updates that Memorabid needs;

•      from a partner or promoter of an initiative, where necessary to manage that initiative and after the user has been appropriately informed.

Users are responsible for ensuring that any third-party personal data they provide or publish through the Service has been obtained and disclosed lawfully.



4. Purposes, legal bases and data processed


4.1 Registration, authentication and account management

Memorabid processes identity, contact, tax and account data to create and manage the user's profile, authenticate the user, provide reserved features and keep account information up to date.

Legal basis: performance of a contract or steps taken at the user's request before entering into a contract, under Article 6(1)(b) GDPR; compliance with legal obligations, where applicable, under Article 6(1)(c) GDPR.


4.2 Participation in auctions, bids, awards and purchases

Account and transaction data is processed to enable participation in auctions, record bids, apply the auction rules, determine the successful bidder, manage orders, invoices, payments, refunds and disputes, and send updates strictly connected with the transaction.

Legal basis: performance of a contract or pre-contractual steps requested by the user, under Article 6(1)(b) GDPR; compliance with legal, accounting and tax obligations, under Article 6(1)(c) GDPR; Memorabid's legitimate interests in protecting its rights and preventing abuse or fraud, under Article 6(1)(f) GDPR.


4.3 Payment verification and management

Memorabid uses Stripe to verify the validity of the payment method and manage payments. Card details are entered in the payment provider's environment and are not acquired in full by Memorabid. Stripe may carry out technical checks or authentication requests required by applicable law or payment schemes. The information displayed during checkout explains any verification or authorisation that may be requested.

Legal basis: performance of a contract and pre-contractual steps, under Article 6(1)(b) GDPR; legal obligations applicable to payments and fraud prevention, under Article 6(1)(c) GDPR; legitimate interests in transaction security and fraud prevention, under Article 6(1)(f) GDPR.

Depending on the activity, Stripe may act as a Data Processor, an independent Data Controller or a joint controller for regulated services and its own compliance obligations. Further information is available in the Stripe Privacy Center.


4.4 Shipping and delivery of lots

Following an award or purchase, identity, contact and shipping data is disclosed to the courier or logistics operator to the extent necessary to deliver the lot, provide updates and manage any delivery issues.

Legal basis: performance of a contract, under Article 6(1)(b) GDPR; compliance with legal obligations, where applicable, under Article 6(1)(c) GDPR.

Couriers and postal operators may act as independent Data Controllers for activities whose purposes and means they determine directly and in accordance with their own privacy notices.


4.5 Customer support, contact forms and service communications

Memorabid processes identity, contact, account and transaction data to respond to questions, requests, complaints and issues; send confirmations, invoices, payment reminders, auction notifications, shipment updates and other necessary communications by e-mail, SMS, WhatsApp, push notification or the channel requested or reasonably expected by the user.

Legal basis: performance of a contract or pre-contractual steps, under Article 6(1)(b) GDPR; legitimate interests in handling and documenting non-contractual requests, under Article 6(1)(f) GDPR.

Service communications do not contain unnecessary promotional content unless the user has given specific consent or the conditions for the limited e-mail marketing exception described in Section 4.11 are met.


4.6 Legal, administrative and tax obligations and requests from authorities

Personal data may be processed to comply with obligations arising from law, regulations or binding authority orders; maintain accounting records; issue and retain tax documents; respond to requests from competent authorities; and cooperate with them where required by law.

Legal basis: compliance with a legal obligation, under Article 6(1)(c) GDPR.


4.7 Security, fraud prevention, protection of rights and reCAPTCHA

Memorabid processes technical data, logs, account data and transaction data to protect the Service; prevent unauthorised access, fraudulent activity, inauthentic bids and other unlawful use; maintain business continuity; establish, exercise or defend legal claims; and manage disputes.

Google reCAPTCHA may be used in forms or higher-risk operations to distinguish human interactions from automated ones and prevent spam, fraud and abuse. Google processes reCAPTCHA service data on Memorabid's behalf as a Data Processor under the applicable agreements. Any access to or storage of information on the user's device is limited to what is strictly necessary for security; any additional purposes are subject to consent where required.

Legal basis: Memorabid's and its users' legitimate interests in the security of the Service, the prevention of fraud and abuse and the protection of legal rights, under Article 6(1)(f) GDPR; compliance with legal obligations, where applicable, under Article 6(1)(c) GDPR.


4.8 Technical operation, hosting, traffic distribution and monitoring

Technical data and, to the extent necessary, data handled through the Service are processed to host and distribute the website, balance and filter traffic, ensure performance and availability, identify errors and resolve issues. For these purposes Memorabid uses the following providers and services:

•      Amazon Web Services (AWS) and Amazon CloudFront;

•      Cloudflare;

•      Sentry, provided by Functional Software, Inc.;

•      Google Workspace for productivity, collaboration and storage;

•      Google Tag Manager for centralised tag management. Non-essential tags managed through Google Tag Manager are activated only after the required consent has been obtained.

Legal basis: performance of a contract for elements essential to providing the Service, under Article 6(1)(b) GDPR; legitimate interests in maintaining a secure, efficient and operational Service, under Article 6(1)(f) GDPR; consent for non-essential tags and tracking technologies, under Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code.


4.9 Analytics and measurement

Subject to consent, Memorabid uses Google Analytics 4, Meta Events Manager and other tools identified in the Cookie Policy to measure traffic and interactions, generate statistics, understand how the Service is used and evaluate its performance. Data may include Usage Data, the number of users, session statistics and Trackers and, for Meta Events Manager, identifiers such as first and last name, processed in accordance with data-minimisation principles and, where supported, using hashing techniques.

In Google Analytics 4, IP addresses are used when data is collected and then discarded before the data is logged in any Google data centre, according to the provider's documentation. This measure does not remove the need for consent where non-technical cookies or other tracking technologies are used.

Legal basis: consent, under Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code. Consent may be withdrawn at any time through the privacy-preferences panel.


4.10 Memorabid newsletters and marketing

With optional, specific and withdrawable consent, Memorabid may use the user's first name, last name and e-mail address and, only where that channel has been specifically selected, telephone number to send newsletters, updates, invitations, promotions and commercial communications through authorised channels. Mailchimp, provided by Intuit Inc., may be used to manage contacts and send messages.

Legal basis: consent, under Article 6(1)(a) GDPR and, for electronic communications, Article 130 of the Italian Privacy Code.

Refusal to consent does not prevent a user from registering, participating in auctions or making purchases. Consent may be withdrawn at any time through the unsubscribe link in messages, the account settings or by writing to info@memorabid.com.


4.11 Limited e-mail marketing to existing customers ("soft spam")

Within the limits of Article 130(4) of the Italian Privacy Code, Memorabid may use an e-mail address obtained in the context of a completed sale to promote, exclusively by e-mail, its own products or services that are similar to those purchased. The user is informed of this use and may refuse it from the outset or object free of charge and easily in every subsequent communication.

This exception does not apply to SMS, WhatsApp, push notifications, messages concerning products or services that are not similar, or marketing carried out by partners or other third parties.

Legal basis: Article 130(4) of the Italian Privacy Code, read together with Article 6(1)(f) GDPR.


4.12 Partners, promoters and beneficiaries of initiatives

Memorabid may disclose data that is strictly necessary to a partner, promoter or beneficiary of an initiative in which the user has chosen to participate where the disclosure is necessary to manage the initiative, perform contractual or legal obligations, document fundraising activities or allow a thank-you communication that relates strictly to the participation and contains no independent promotional content. Where necessary, the user receives a contextual notice identifying the recipient and its data-protection role.

Legal basis: performance of a contract or steps requested by the user, under Article 6(1)(b) GDPR; compliance with a legal obligation, under Article 6(1)(c) GDPR; legitimate interests in documenting and properly managing the initiative, under Article 6(1)(f) GDPR, subject to an appropriate balancing assessment.

Personal data is disclosed to partners, promoters or beneficiaries so that they may send their own promotional communications or information about other initiatives only on the basis of separate, specific and optional consent that identifies, or makes clearly identifiable, the recipients or their categories. Acceptance of the Terms and Conditions or this Privacy Notice does not constitute consent to third-party marketing.


4.13 Advertising, profiling and third-party platform content

Subject to consent, Memorabid may analyse interactions with the website and use Usage Data and Trackers to measure campaigns, create audience segments, personalise content and advertising and display advertisements consistent with the user's interests. The services used by Memorabid include:

•      Meta ads conversion tracking (Meta pixel) and Meta Events Manager;

•      Microsoft Advertising;

•      Facebook Like button and social widgets;

•      YouTube videos, including privacy-enhanced mode;

•      Google Maps, Google Fonts and Font Awesome.

Non-essential external content and its Trackers are blocked until consent has been obtained, unless implemented in a way that neither accesses nor stores information on the user's device and does not involve further processing that requires consent.

Legal basis: consent, under Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code.

Consent may be given or withdrawn by category through the privacy-preferences panel. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.


4.14 Privacy-preference management and publication of this Notice

Memorabid uses iubenda to publish its privacy and cookie policies and, if enabled on the website, to collect and store preferences concerning cookies and other tracking technologies. Data processed may include the IP address, choices made, date and time of the choice and technical identifiers required to document it.

Legal basis: compliance with a legal obligation and the need to demonstrate compliance, under Article 6(1)(c) GDPR; legitimate interests in managing and documenting privacy preferences, under Article 6(1)(f) GDPR.



5. Mandatory and optional provision of personal data

Data marked as mandatory is required to create an account, participate in auctions, enter into and manage a transaction, make a payment, receive a lot or comply with a legal obligation. Failure to provide it may make it impossible to provide all or part of the requested Service.

The provision of data for Memorabid marketing, third-party marketing, profiling, non-technical analytics and non-essential tracking technologies is optional. Refusing or withdrawing consent does not affect access to the essential functions of the Service.



6. Processing methods and security measures

Processing is carried out mainly through computerised and electronic means, using procedures related to the purposes described above and in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality.

Memorabid applies technical and organisational measures appropriate to the risk to prevent unauthorised access, disclosure, alteration, loss or destruction of personal data. No information system can, however, be considered entirely free from risk.

Personal data is accessible only to authorised and appropriately instructed personnel, within the limits of their assigned duties, and to providers that need access to deliver the services entrusted to them.



7. Recipients and categories of recipients

Personal data may be disclosed, to the extent necessary, to:

•      Memorabid's authorised personnel and contractors;

•      hosting, cloud, content-delivery network, security, monitoring, technical-support and maintenance providers, including AWS, Amazon CloudFront, Cloudflare and Sentry;

•      productivity and tag-management providers, including Google Workspace and Google Tag Manager;

•      analytics, advertising, social-media and external-content providers activated in accordance with the user's preferences, including Google, Meta, Microsoft and Fonticons;

•      providers used to manage consent and publish privacy notices, including iubenda;

•      communications, newsletter and messaging providers, including Mailchimp/Intuit and, depending on the channel used, telecommunications operators and messaging platforms;

•      Stripe and other parties involved in the payment network;

•      couriers, freight forwarders and logistics operators;

•      legal, tax, accounting, insurance and IT advisers;

•      partners, promoters or beneficiaries of initiatives, only in the circumstances and subject to the conditions described in Section 4.12;

•      banks, judicial, administrative, regulatory or public-security authorities, and other parties to whom disclosure is required by law or a lawful order;

•      any purchasers, successors or counterparties in corporate transactions, subject to the required safeguards and compatibility with the original purposes.

Providers that process personal data on Memorabid's behalf are appointed as Data Processors under Article 28 GDPR. Certain recipients may act as independent Data Controllers for purposes that they determine directly. An up-to-date list of Data Processors may be requested at info@memorabid.com.

Personal data is not publicly disclosed unless publication is required by the nature of a specific feature, has been clearly communicated to the user and is supported by an appropriate legal basis.



8. Transfers of personal data outside the European Economic Area

Some providers identified in this Notice are based in, or use infrastructure located in, the United States or other countries outside the European Economic Area ("EEA"). In such cases, the transfer is carried out in accordance with Articles 44 et seq. GDPR on the basis of one of the following mechanisms:

•      an adequacy decision adopted by the European Commission, including the EU-U.S. Data Privacy Framework for US recipients that remain validly certified;

•      Standard Contractual Clauses approved by the European Commission, supplemented where necessary by a transfer impact assessment and additional safeguards;

•      another safeguard or derogation provided for by the GDPR, where applicable.

Users may request information about the specific transfer mechanism relied on and how to obtain a copy of the applicable safeguards by writing to info@memorabid.com.



9. Retention periods

Memorabid retains personal data only for as long as necessary for the purposes for which it was collected, according to the following periods or criteria:

•      account data: for the duration of the account; after closure, data not connected with legal obligations or disputes is deleted or anonymised within 24 months;

•      auctions and bids that do not result in a purchase: generally for 24 months after the auction closes, unless further retention is necessary for security, fraud prevention, dispute management or the protection of legal rights;

•      contracts, awards, orders, payments, shipments and support related to a transaction: for 10 years after completion of the transaction, or longer where needed for a dispute;

•      accounting and tax records: for 10 years after the relevant entry, unless a longer period is required by law or necessary in connection with an audit or assessment;

•      contact and support requests unrelated to a transaction: for up to 24 months after the request is closed, unless further retention is required for disputes or legal obligations;

•      technical and security logs: generally for up to 12 months; information relating to fraud, abuse or incidents may be retained for up to 24 months or, where an investigation or dispute arises, until it has been resolved;

•      consent-based marketing: until consent is withdrawn and, in any event, no longer than 24 months after the user's last meaningful interaction, without prejudice to the possibility of requesting renewed consent;

•      advertising profiling and personalisation: until consent is withdrawn and, in any event, no longer than 12 months after the data used for the profile was collected;

•      limited e-mail marketing to existing customers: until the user objects and, in any event, no longer than 24 months after the last relevant purchase;

•      evidence of consent, withdrawal and objections: for as long as necessary to demonstrate compliance and protect Memorabid's rights, generally up to 10 years after the last relevant choice or communication;

•      cookies and other tracking technologies: for the duration specified in the Cookie Policy and privacy-preferences panel, without prejudice to the retention strictly necessary to document the user's choices;

•      litigation and authority requests: until the proceedings have been finally resolved and the relevant appeal or limitation periods have expired.

At the end of the applicable period, personal data is deleted or irreversibly anonymised unless further retention is required by law or an authority order. Providers may apply technical backup and gradual-deletion periods described in their agreements and privacy notices.



10. Cookies and other tracking technologies

The website uses cookies and similar technologies. Technical cookies and tools strictly necessary for operation, security, authentication, preference management or delivery of a service requested by the user may be used without consent within the limits of Article 122 of the Italian Privacy Code.

Cookies and technologies used for non-technical analytics, advertising, profiling, social media or external content are used only after the user's consent has been obtained. On the first visit, users may accept, refuse or select purposes by category with equal ease. Preferences may be changed or withdrawn at any time through the "Privacy Settings" command or an equivalent tool available on the website.

Up-to-date information about individual technologies, providers, purposes and duration is available in the Memorabid Cookie Policy.



11. Profiling and automated decision-making

Subject to consent, Memorabid may create segments or profiles concerning the user's interests based on pages visited, lots viewed or marked as favourites, auctions followed and interactions with communications in order to personalise recommendations and advertising and measure campaigns. Advertising profiling is not required to use the Service and may be disabled at any time.

Memorabid does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the user within the meaning of Article 22 GDPR, except for the automatic and transparent application of the auction rules, including determining the successful bid using objective criteria accepted by the user. This operation is necessary for performance of the contract and does not use marketing profiles. Users may contact customer support to report errors, ask for an explanation or challenge an outcome in the circumstances provided for in the Terms and Conditions.



12. Data subject rights

Subject to the circumstances and limits set out in the GDPR, data subjects have the right to:

•      obtain confirmation as to whether their personal data is being processed and access that data and the information required by Article 15 GDPR;

•      request rectification of inaccurate data or completion of incomplete data under Article 16 GDPR;

•      request erasure of personal data under Article 17 GDPR;

•      request restriction of processing under Article 18 GDPR;

•      receive personal data they have provided in a structured, commonly used and machine-readable format and, where technically feasible, transmit it to another controller under Article 20 GDPR;

•      object, on grounds relating to their particular situation, to processing based on legitimate interests under Article 21 GDPR;

•      object at any time and without giving reasons to direct marketing, including related profiling, under Article 21(2) and (3) GDPR;

•      withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal, under Article 7(3) GDPR;

•      where applicable, obtain human intervention, express their point of view and contest an automated decision under Article 22 GDPR;

•      be informed of recipients to whom rectification, erasure or restriction has been communicated under Article 19 GDPR;

•      lodge a complaint with the competent Supervisory Authority or seek a judicial remedy.

Rights may be exercised free of charge by writing to info@memorabid.com and providing the information necessary to identify the data subject and the request. Memorabid may request additional information to verify the requester's identity. A response is normally provided within one month. That period may be extended by two further months where requests are complex or numerous, provided the data subject is informed within the first month. The measures permitted by Article 12(5) GDPR may apply to requests that are manifestly unfounded or excessive.



13. Complaints to the Supervisory Authority

Data subjects may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome, using the procedures available at www.garanteprivacy.it, or with the Supervisory Authority of the EU Member State in which they habitually reside or work or where the alleged infringement occurred, under Article 77 GDPR.



14. Children

Registration and participation in auctions are limited to persons who have the legal capacity required by applicable law and the Terms and Conditions to enter into the relevant contract. Memorabid does not knowingly collect children's personal data in breach of those requirements. If Memorabid becomes aware that data has been collected unlawfully or without any authorisation required from the holder of parental responsibility, it will take reasonable steps to delete it, subject to applicable legal obligations. A holder of parental responsibility may contact Memorabid using the details in Section 1.



15. Contextual notices and changes

Memorabid may provide additional notices at the point of collection for specific processing operations or initiatives. In the event of a conflict, the specific notice prevails solely with respect to the processing activity to which it relates.

Memorabid may update this Notice to reflect legal, organisational or technical changes. The updated version is published on this page with the date of the latest revision. If a change materially affects users' rights or processing activities, Memorabid will provide appropriate notice and, where necessary, obtain new consent.



16. Additional information for users outside the EEA


16.1 Switzerland

For users subject to the Swiss Federal Act on Data Protection, Memorabid recognises, to the extent provided by applicable law, rights of access, rectification, erasure or destruction, restriction or objection, and data portability. Requests may be sent to info@memorabid.com. Users may also contact the Swiss Federal Data Protection and Information Commissioner.


16.2 Brazil

For users subject to the Lei Geral de Proteção de Dados (LGPD), processing is based on one of the legal grounds available under the LGPD. To the extent applicable, users may request confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or unlawfully processed data, portability, information about recipients, withdrawal of consent, objection and review of automated decisions, and may lodge a complaint with the Autoridade Nacional de Proteção de Dados. Requests may be sent to info@memorabid.com.


16.3 United States

For residents of US states where comprehensive privacy laws apply, Memorabid may collect the categories described in this Notice, including identifiers, Internet or other electronic-network activity, commercial information and approximate geolocation data. This information is collected directly from the user, automatically during use of the Service or from providers required for a transaction, and is used for the purposes described in Sections 4 and 11.

Memorabid does not sell personal data for money. However, certain disclosures of online identifiers, Usage Data and approximate geolocation to advertising and measurement providers identified in this Notice constitute, or may constitute, a "sale", "sharing" or "targeted advertising" under some US state laws. Users may opt out through the privacy-preferences panel or by writing to info@memorabid.com. Where provided by applicable law, users may request access or confirmation, correction, deletion, portability, information about recipients, limitation of the use of sensitive data, opt-out from sale, sharing, targeted advertising or profiling, an appeal of a decision on a request, and non-discrimination. Memorabid does not discriminate against users who exercise their rights. An authorised agent may submit a request where permitted by law, subject to verification of the agent's authority and the data subject's identity.



17. Contact details

For questions about this Notice, to request the up-to-date list of Data Processors or to exercise data protection rights:

Memorabid S.r.l.

Foro Buonaparte 59, 20121 Milan (MI), Italy

E-mail: info@memorabid.com

Memorabid