Last updated: 3 August 2026
Privacy Policy
This Policy explains how Artmu Oy processes personal data in the private FunDesign Artists Portal. It covers members, applicants, artists, vendors, and representatives who use the Portal. It does not describe customer data processed in physical-shop payment systems.
1. Controller and contact details
Artmu Oy
Servinkuja 6 B 007, 02150 Espoo, Finland
Business ID: 3322952-2
VAT number: FI33229522
Privacy enquiries: info@fundesign.fi
Artmu Oy has not appointed a data protection officer. Privacy enquiries are handled through the address above.
2. Personal data we process
Account and identity data: email address, authentication provider and identifier, name, artist or brand name, account status, roles, permissions, and application-review information.
Profile and membership data: profile description, product range, category, links, brand or artist code, membership information, and a membership-card photo where you use the card. We do not use facial recognition.
Product and operational data: product names, descriptions, codes, categories, prices, VAT rates, approval status, inventory, locations, and related administration. The Portal does not currently store product photographs.
Vendor and financial administration: sales records linked to a vendor, payout calculations, invoice metadata, import history, and corrections. Imported reports are not intended to contain customer personal data.
Legal and technical records: versions and times of Terms acceptance and Privacy Policy presentation, service emails, support messages, and limited authentication, security, diagnostic, and aggregate usage information generated by the Portal and its providers. Web Analytics data may include the page or redacted route visited, timestamp, referrer, approximate location, browser, operating system, and device type.
We may add address or business-identification fields in the future. If this materially changes the processing, we will update this Policy before or when those fields are introduced.
3. Sources, purposes, and legal bases
We receive data from you, authorised Artmu Oy administrators, Google or another login provider you choose, and operational shop reports. We process it to register and authenticate users; review and manage membership and access; operate profiles, products, inventory, cards, sales, and payout administration; communicate service information; correct records; prevent misuse; secure and troubleshoot the Portal; understand aggregate Portal usage and improve the service; establish or defend legal claims; and meet accounting and other legal duties.
Processing needed to provide requested Portal and membership or vendor administration is based on taking steps at your request and performing the applicable agreement.
Selection, access management, record accuracy, service improvement, fraud prevention, security, and the operation of a private member service are based on Artmu Oy's legitimate interests, balanced against your rights.
Accounting, tax, and other mandatory records are processed to comply with legal obligations. If we rely on consent for a new, genuinely optional purpose, we will request it separately and you may withdraw it.
4. Who can access or receive data
Members can access their own information, products, cards, and relevant sales information. Authorised Artmu Oy administrators can access information needed to operate the Portal. Users assigned a moderator role may access profiles, products, inventory, and other operational information within that role. Other members cannot see your Portal records.
Shop employees do not currently use this Portal. Product data exported to the SumUp shop system may include the artist or brand name, product description, and artist or brand code. A legal name is not exported unless it is also the public artist or brand name. Physical-shop staff and visitors may see the public artist or brand name connected with products. Accountants may receive vendor sales, invoice, and payment information as required for accounting.
We do not sell personal data. We may disclose it where required by law, to protect legal rights or security, or as part of a corporate transaction subject to appropriate safeguards.
5. Service providers
We use Supabase for authentication, database, and file storage; Vercel for hosting, delivery, and privacy-focused Web Analytics; Resend for transactional emails; Google when you choose Google sign-in; and SumUp as the separate physical-shop product and payment system. These providers process data under their own service terms and, where they act for Artmu Oy, under appropriate data-processing arrangements.
Vercel Web Analytics is configured without analytics cookies or custom events. It provides aggregate page-view statistics and does not associate analytics records with Portal accounts. Query strings are removed and identifiers in dynamic Portal routes are replaced before an analytics event is sent. Vercel derives a short-lived visitor hash from a request and discards it after 24 hours; it does not use that hash to track a visitor across websites or days.
The primary Supabase database region is West Europe (Ireland). Provider support, delivery networks, subprocessors, or login services may process data elsewhere. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision, standard contractual clauses, or another transfer mechanism permitted by data-protection law, together with additional safeguards where appropriate.
6. Retention
Incomplete and rejected applications are normally removed within six months after the last activity or decision, unless a longer period is needed to resolve a request or dispute.
Active member, account, product, and vendor-administration data is kept while the relationship and Portal account remain active. Inactive accounts should be reviewed no later than three years after the last meaningful activity.
When deletion is confirmed, data that is not required for another purpose is removed without undue delay. A membership-card photo is removed from active storage when you delete it. Residual encrypted backup copies may remain until the provider's normal backup cycle completes.
Accounting and tax records are retained for the periods required by Finnish law. Information needed for claims, corrections, fraud prevention, or disputes may be retained until the relevant limitation or handling period ends. De-identified aggregate data may be retained without a fixed period where it can no longer be linked to a person.
7. Security
We use measures appropriate to this Portal, including authenticated access, role-based permissions, database row-level security, private storage for membership photos, encrypted connections, restricted administrative access, and service-provider security controls. No system is completely secure. Please protect your account and report a suspected incident to us promptly.
8. Your data-protection rights
Depending on the processing and applicable law, you may request access, correction, deletion, restriction, or portability of your personal data; object to processing based on legitimate interests; or withdraw consent where consent is the legal basis. These rights can have lawful exceptions, including accounting and legal-claim retention.
Send a request to info@fundesign.fi. We may ask for information needed to verify your identity. You may also lodge a complaint with the Office of the Data Protection Ombudsman in Finland.
9. Automated decisions and communications
Account and product decisions are currently made by people, not by solely automated decision-making that produces legal or similarly significant effects. We currently send operational and registration communications, not marketing messages. If product-update communications are introduced, we will provide any choices required by law.
10. Changes to this Policy
We may update this Policy when the Portal, providers, law, or our processing changes. The current version is published here. An updated Privacy Policy is presented through the Portal for review; it is not treated as consent unless we expressly request consent for a particular purpose. See the Cookie Policy for browser storage used by the Portal.