Privacy Policy
What personal data we hold, why we hold it, who we share it with, and the rights you have over it.
Last updated: 24 August 2026
Summary
This summary is for convenience only. It does not form part of the policy, and the numbered clauses below take precedence if there is any inconsistency.
- A saleroom cannot see you until you ask to bid with it.
- There is no directory of bidders for auction houses to browse. Registering with one shows that one your details, and no other.
- We never store your identity document.
- A passport or licence shown to a checking provider is not copied to us. We hold the outcome and the provider’s reference, and no image of anything.
- Nobody sees your watchlist, or who you follow.
- Not the salerooms, not us on any screen. Both are commercial signals you never agreed to hand over.
- No tracking, no marketing, no selling your data.
- We run no analytics at all, we email you only about things you or a saleroom did, every sale announcement you switched on can be switched off from the email itself, and we do not sell your data to anybody.
- One decision is automated, and you can challenge it.
- A sanctions match blocks bidding everywhere, with no human in the loop. Names collide, so a person will review it if you ask.
- You can see it, correct it, and have it deleted.
- With named exceptions we have to keep, and we will tell you exactly which rather than refusing vaguely.
1. Who we are
1.1
Digital Auction Solutions Limited operates The Bidding Floor, and is the controller of the personal data described in this policy. Our registered office is [registered office address], and our full company details are in clause 1 of our Website Terms of Use.
1.2
We are registered with the Information Commissioner’s Office under registration number [ICO registration number].
1.3
For anything to do with your personal data — a question, a request, or a complaint — write to [support email]. You do not need to use any particular form of words, and we will not charge you.
1.4
The auction house is a separate controller. When you register to bid with a saleroom, that saleroom becomes a controller of your data in its own right, for its own purposes — deciding whether to let you bid, invoicing you, and meeting the money-laundering duties that fall on it rather than on us. It has its own privacy notice, and we cannot answer for it. Clause 6 explains what we pass on and when.
2. Who this policy is about
2.1
It covers everybody whose data we hold: visitors who never sign up, bidders with an account on The Bidding Floor, and the staff of auction houses who use our console. Where a section applies to only one of those, it says so.
2.2
One account works across everything we operate, so if you both bid and work for a saleroom you are one person to us rather than two. The data described below is held once.
2.3
The Bidding Floor is not for children. You must be 18 to hold an account, and we do not knowingly collect data about anybody younger. If you believe we have, tell us and we will delete it.
3. What we hold
A complete list rather than an illustrative one. If something is not here, we do not hold it.
3.1
Your account. Your email address, your name, and a securely hashed version of your password — we never see the password itself. We also record when you last signed in.
3.2
Your bidder details. If you register to bid: your first and last name, a phone number, and your home address. If you bid as a business, its name and address as well. A saleroom needs these to know who it is selling to and how to reach you about a lot you have won.
3.3
What you have asked to bid on. Which salerooms you have registered with and what each decided, which sales you asked to bid in, any paddle number you were given, and the date of each. If a saleroom declines you, the reason it gave.
3.4
Identity and sanctions checks. Whether a check has been run, when, which provider ran it, the reference that provider gave it, when it expires, and the outcome. The same for sanctions screening. We do not store the document. A passport or driving licence you show a provider is not copied to us, and no image of one is held anywhere in our systems — we hold the answer and the reference, so that a saleroom can produce a file if it is ever asked to.
3.5
Your watchlist, and the salerooms you follow. The lots you have saved, and the salerooms you have asked to hear from. Both are yours alone: no auction house can see either, and no member of our staff has a screen that lists them. Clause 6.4 explains why we have kept it that way, and clause 5.2 what following a saleroom means for what we send you.
3.6
Messages we have sent you. The emails we have sent — confirmations, approvals, refusals, invitations, and notes that a saleroom you follow has published a sale — and whether each was delivered. Not the contents of anything you send a saleroom outside our system.
3.7
A record of changes. Every change to the records above is logged: what changed, when, and who did it. Clause 8 explains how long that lasts and what is held back from it.
3.8
Technical data. Our hosting and email providers keep ordinary server logs — an IP address, a timestamp, which page was requested — for a short period, to run the service and to spot abuse. We do not combine these into a profile of you, and, as our Cookie Policy sets out, we run no analytics of any kind.
4. Where it comes from
4.1
Almost all of it from you, when you create an account, fill in your details, or register for a sale.
4.2
From an identity or sanctions provider, when a check is run: the outcome and its reference, as clause 3.4 describes.
4.3
From an auction house, when it records a decision about you — approving you to bid, declining, or accepting an identity check it has seen.
5. Why we hold it, and on what basis
UK data protection law requires a lawful basis for each purpose. Ours are:
| What for | Lawful basis |
|---|---|
| Running your account and the bidding services you have asked for | Contract — performing our agreement with you |
| Passing your registration to a saleroom so it can decide whether to accept you | Contract, and the saleroom’s own bases for its own decision |
| Identity checks and sanctions screening | Legal obligationwhere one applies to us, and otherwise our and the saleroom’s legitimate interests in preventing fraud and in meeting the duties that fall on the saleroom |
| Keeping a record of changes to auction and bidder records | Legitimate interests — being able to show what happened in a sale, and to investigate a dispute or a suspected manipulation |
| Preventing fraud, non-payment and abuse, and sharing conduct information with salerooms | Legitimate interests — protecting the integrity of auctions on the platform and the salerooms trading on it |
| Service emails: confirmations, approvals, password resets | Contract |
| Keeping the service secure and available | Legitimate interests — running a service that works and is not abused |
5.1
Where we rely on legitimate interests we have weighed them against your rights and concluded they do not override yours. You can ask us for that assessment, and you can object — see clause 10.
5.2
We do not send marketing. Every email described in clause 3.6 is about something you did or something a saleroom decided. The one you switch on yourself is the note that a saleroom you follow has published a new sale, and every one of those carries a link that stops it — the link works without signing in, takes effect straight away, and ends nothing but that. If we ever want to send you anything else we will ask for your consent first, and you will be able to withdraw it at any time without affecting your account.
5.3
We never sell your data. Not to advertisers, not to data brokers, not to anybody. Clause 6 is the complete list of who sees it.
6. Who sees it
6.1
The salerooms you register with — and only those. An auction house cannot see you at all until you ask to bid with it. There is no directory of bidders for salerooms to browse. Once you have registered, that house sees your name, contact details, address, the standing it has granted you, and whether an identity check has been run and passed. A different saleroom sees none of that until you register with it too.
6.2
Salerooms keep their own notes. A house can record private notes about a customer, which we hold on its behalf and which are not visible to you through The Bidding Floor. They are still your personal data: if you want to see them, ask that saleroom, which is the controller of them and has to answer.
6.3
Conduct information is shared between salerooms. Non-payment, retracted bids and suspected bid manipulation may be shared with other houses using the platform, to prevent fraud and default. This is the only category of information that travels beyond the saleroom you dealt with, and the Bidder Terms say so as well.
6.4
Not your watchlist, and not who you follow. What you are watching, and which salerooms you have chosen to hear from, are commercial signals a saleroom would value and that you never agreed to give it. No house sees either — a saleroom is not told who follows it, or how many people do — and if we ever publish anything derived from them, it will be a count and never a list of names.
6.5
Our own staff. Our people can see your data where they need to — supporting you, reviewing a saleroom’s application, or recording the outcome of an identity check. Entering a saleroom’s account to help it opens a record of that visit which the saleroom itself can read, and there is no way for us to work inside an account without leaving one.
6.6
The companies that run our infrastructure. Supabase, for the database, sign-in and file storage; Vercel, for hosting; and Resend, for sending email. Each acts on our instructions under a contract, uses the data only to provide its service, and may not use it for its own purposes. An identity or sanctions provider joins this list when one is appointed, and we will name it here.
6.7
Where the law requires it. We will disclose data to a court, a regulator, the police, or a professional adviser where we are obliged to or where it is necessary to establish or defend a legal claim. If our business is sold or reorganised, data may pass to the buyer, who would be bound by this policy or one no less protective.
7. Where it is held
7.1
Our database and the files in it are hosted in [hosting region].
7.2
Some of the providers in clause 6.6 operate internationally, so support and administrative access may take place from outside the United Kingdom. Where data is transferred out of the UK, we rely on adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with additional safeguards where needed. Ask us at [support email] for details of the transfers relevant to you.
8. How long we keep it
8.1
Your account and bidder details, for as long as you have an account, and then for six years — the period in which a claim arising from a sale can normally be brought, and the period a saleroom’s own record-keeping duties tend to run to.
8.2
Identity and sanctions outcomes, for five years after our relationship with you ends, which is the retention the money-laundering rules apply to a saleroom’s own records. As clause 3.4says, this is the outcome and the provider’s reference, never a document.
8.3
Your watchlist and the salerooms you follow, until you remove a lot, unfollow a saleroom or close your account. Both are deleted with the account and no copy is kept anywhere, including in the record of changes.
8.4
The record of changes is different, and you should know how. It is designed to outlive the records it describes — an account of what happened in a sale is worthless if it disappears when somebody deletes a row — and it cannot be switched off. So that it does not become a permanent second copy of your personal details, your address and phone number are held back from it at the moment it is written and were never in it to remove. The outcome of an identity or sanctions check is not held back, because that is the compliance record a saleroom may have to produce. We keep it for six years.
8.5
Our own operational records. A message we have sent you is kept for twelve monthsafter it went out, and then deleted — the record of what it was about lives on the invoice, the sale or the record of changes rather than in a copy of the email. An invitation to join a saleroom’s team is deleted ninety days after it is accepted, withdrawn or runs out, because it carries a credential we have no reason to hold once it is spent. Both are deleted automatically, on a schedule, whether or not anybody asks.
8.6
When a period ends we delete or anonymise, so that what is left cannot be traced back to you.
9. Automated decisions
9.1
We do this because trading with a designated person is prohibited, and the consequence of getting it wrong falls on you as well as on us. It is a decision with a significant effect on you, which is why it is set out here rather than buried.
9.2
You can challenge it. Screening matches on names, and names collide — a match is not a finding about you. Ask us at your account, or write to [support email], and a person will review it, you can put your side, and we will tell you the outcome within [X] working days. If it is wrong we will correct it and you will be able to bid.
9.3
Not having been screened is not a match. It means the check has not been run, which is a gap in our process rather than anything about you, and it does not by itself stop you bidding.
9.4
Beyond that one decision, whether you may bid in a particular sale is a saleroom’s judgement, not an algorithm’s. Where a house approves returning customers automatically, that is a shortcut past its own queue for somebody it has already vetted — never past the vetting.
10. Your rights
Under UK data protection law you can ask us to:
10.1
Give you a copy of the personal data we hold about you, and tell you what we do with it.
10.2
Correct it if it is wrong or incomplete. Most of it you can correct yourself in your account.
10.3
10.4
Restrict what we do with it while a dispute about accuracy or our grounds is resolved.
10.5
Object to processing we base on legitimate interests, including the sharing of conduct information in clause 6.3.
10.6
Receive it in a portable form, for the data you gave us that we hold on the basis of contract or consent.
10.7
Ask for a human review of the automated decision in clause 9.
10.8
Write to [support email]. We answer within one month, and will say so if a complicated request needs longer. We may ask you to confirm who you are, so that we do not hand your data to somebody else.
10.9
For data an auction house holds about you as its own controller — including the notes in clause 6.2 — ask that saleroom. Tell us if you cannot get an answer and we will help you reach the right person.
11. Keeping it safe
11.1
Access is enforced in the database itself rather than only in the software in front of it, so a saleroom can reach its own records and no others, and a bidder can reach their own. Traffic is encrypted in transit, passwords are stored only as a hash, and our staff’s access is limited to what their role needs and is logged.
11.2
No system is perfectly secure. If a breach happens that is likely to result in a risk to your rights, we will report it to the Information Commissioner within 72 hours and tell you without undue delay where the risk to you is high.
12. Changes, and complaints
12.1
We will update this policy when what we do changes, and the “Last updated” date will say when. If a change materially affects you we will tell you by email rather than relying on you to notice.
12.2
If you are unhappy with how we have handled your data, tell us first at [support email]and we will try to put it right. You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. Complaining to us first does not affect that right.
