Legal

Privacy Policy

Version 2.0Effective 12 August 2026Phoebe Partners Limited · HE 126964

1. Who we are

This Policy explains how we collect, use and protect your personal data when you visit our website or buy an AYNI UNIT collectible, and what rights you have over that data.

Phoebe Partners Limited, registration number HE 126964, registered office 23 Agias Paraskevis, Germasogeia, 4044, Limassol, Cyprus, is the data controller for the personal data described here.

This Policy is issued under Regulation (EU) 2016/679 (the General Data Protection Regulation) and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data, Law 125(I)/2018.

Questions go to info@ayni-unit.com.

2. What we collect

CategoryExamplesWhere it comes from
Identity dataFirst and last name, date of birth, nationalityYou, at checkout
Contact dataEmail address, country of residence, postal address where you give oneYou
Order dataDesign bought, quantity, price, order reference, date and timeGenerated by us
Ownership dataThe serial numbers you hold, when you acquired them, and any transfer to or from another collectorGenerated by us
Payment dataPayment method type, last four digits of the card, transaction reference, billing countryOur payment provider
Verification dataIdentity document images, selfie or liveness capture, proof of address, evidence of source of fundsYou, through our verification provider
Consent recordsThe acknowledgements you ticked at checkout, with the timestamp and the document version you acceptedGenerated by us
Technical dataIP address, device and browser type, operating system, timestamps, pages viewedAutomatically
CommunicationsEmails and support messages between you and usYou and us

Biometric data. Where identity verification compares a selfie or liveness capture against your identity document, that is biometric processing and is special category data under Article 9 GDPR. We do it only with your explicit consent, taken at the point of verification, and only to confirm you are who you say you are. You may withdraw that consent, but we then cannot complete verification, which means we cannot pay out proceeds from a resale.

Children. We do not sell to anyone under 18 and do not knowingly collect data from children. Tell us if you believe a child has given us data and we will delete it.

3. Why we use it and our legal basis

PurposeLegal basis
Taking and fulfilling your order, assigning your serial number, maintaining your AccountPerformance of a contract (Art. 6(1)(b))
Maintaining the ownership Register, and recording transfers between collectorsPerformance of a contract, and legitimate interests (Art. 6(1)(f)) in maintaining reliable provenance for the Collection
Confirming you are 18 or over and live somewhere we can sell toLegal obligation (Art. 6(1)(c)) and performance of a contract
Identity verification, sanctions and politically exposed person screening, monitoring, and keeping the related recordsLegal obligation under Cyprus anti-money-laundering law
Comparing your selfie with your identity documentExplicit consent (Art. 9(2)(a))
Preventing and investigating fraud, chargeback abuse and misuse of the Marketplace; keeping our systems secureLegitimate interests in protecting our business and our collectors
Answering your questions and handling complaintsPerformance of a contract and legitimate interests
Establishing, exercising or defending legal claimsLegitimate interests and legal obligation
Sending you email about new designs or editionsConsent (Art. 6(1)(a)), which you can withdraw at any time

Where we rely on legitimate interests we have assessed that our interest is not overridden by your rights. You can ask us for that assessment.

4. The ownership Register

The Register is the record of every piece issued, its serial number, and who owns it. It matters because it is what lets you prove a piece is yours, and what lets a future buyer check its provenance. It works differently from the rest of your data, so it deserves its own explanation.

4.1 What it contains. The serial number, the design, the date of issue, and the identity of the current owner together with the chain of previous owners.

4.2 What other people can see. Other collectors do not see your name. When you list a piece for sale, the listing shows the design, the serial number and your price. Ownership history is shown to a prospective buyer in anonymised form — for example "third owner, acquired March 2027" — not as a list of names.

4.3 Why we keep it after you sell. Once you sell a piece, we retain the fact that you were a previous owner. Provenance that can be erased is not provenance, and the next owner's ability to evidence the chain depends on it. This is a legitimate interest, and it is a limitation on erasure that you should understand before buying — see section 8.

4.4 What we will do. On request we will show you everything the Register holds about you, correct anything inaccurate, and provide a durable copy of your entries. If we ever stop operating the Collection, we will give every owner a durable record of their pieces, as clause 7.5 of the Terms & Conditions requires.

5. Who we share it with

We do not sell your personal data. We share it only as follows:

  • Payment providers — to take payment, prevent fraud, and handle refunds and disputes. They are independent controllers for the card data they handle. We never receive or store your full card number.
  • Identity verification providers — regulated third parties carrying out document and biometric checks as our processors.
  • Screening data providers — to check you against sanctions, watch and politically exposed person lists.
  • Technology providers — hosting, email delivery, error monitoring and support tooling, as our processors under written contracts.
  • Professional advisers — lawyers, auditors and accountants, bound by professional confidentiality.
  • Authorities — regulators, tax authorities, law enforcement and courts where we are legally required to disclose. Where the disclosure relates to a suspicious activity report, the law prohibits us from telling you.
  • A buyer of our business — if we sell or reorganise, subject to equivalent protections.

6. International transfers

Your data is processed primarily inside the European Economic Area. Where a provider processes it outside the EEA, we put an appropriate safeguard in place, being either an adequacy decision of the European Commission covering that country, or the Commission's Standard Contractual Clauses supplemented where necessary following a transfer impact assessment.

You can request a copy of the safeguard applying to a particular transfer by writing to info@ayni-unit.com.

7. How long we keep it

DataHow long
Ownership Register entriesFor as long as the Collection exists, so ownership and provenance stay evidenceable — see section 4.3
Identity, verification and screening records5 years from the end of the relationship, as Cyprus anti-money-laundering law requires; longer only where a competent authority directs
Order and payment records7 years from the end of the relevant financial year, for accounting and tax
Consent recordsAs long as the related order records, as evidence of what you agreed to
Support correspondence3 years from last contact
Technical and security logs12 months
Marketing consent and suppression recordsUntil you withdraw consent; suppression records kept indefinitely so we do not contact you again by mistake

When a period ends we delete the data or irreversibly anonymise it.

8. Your rights

Under the GDPR you have the right to:

  • Access — confirmation of whether we process your data, and a copy of it.
  • Rectification — correction of inaccurate data and completion of incomplete data.
  • Erasure — deletion where we no longer have a lawful reason to keep it. Two limits apply: anti-money-laundering and accounting records must be kept by law, and Register entries are kept under section 4.3. Everything else goes.
  • Restriction — limiting processing while a dispute about accuracy or lawfulness is sorted out.
  • Portability — receiving the data you gave us in a structured, commonly used, machine-readable format, and having it sent to another controller where technically feasible.
  • Object — to processing based on legitimate interests, and to direct marketing at any time without giving a reason.
  • Withdraw consent — at any time, without affecting processing already carried out.
  • Not be subject to solely automated decisions with legal or similarly significant effects. If an automated screening result would block your order, you can ask a person to review it.

Write to info@ayni-unit.com. We reply within one month, extendable by two further months for complex requests, in which case we tell you inside the first month. We may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

9. Complaints

If you are unhappy with how we have handled your data, tell us first so we can put it right.

You can also complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, 15 Kypranoros Street, 1061 Nicosia, Cyprus. You may instead complain to the authority where you live or work.

10. Cookies and similar technologies

TypeWhat it doesConsent needed
Strictly necessaryKeeps your session, secures the checkout, remembers your cookie choices, balances loadNo
FunctionalRemembers preferences such as languageYes
AnalyticsShows us, in aggregate, how the site is used so we can improve itYes
MarketingMeasures how well our advertising worksYes

Non-essential cookies are set only after you consent through the cookie banner. You can change or withdraw your choices at any time there, and block or delete cookies in your browser, though the checkout will not work properly without the strictly necessary ones.

11. Security

We apply technical and organisational measures appropriate to the risk: encryption in transit and at rest, least-privilege access control, separation of verification data from everyday order data, logging and monitoring, vendor due diligence, and confidentiality obligations on staff.

No system is perfectly secure. If a breach occurs that is likely to risk your rights and freedoms, we notify the Office of the Commissioner for Personal Data Protection within 72 hours of becoming aware, and notify you directly without undue delay where the risk is high.

12. Changes to this Policy

We may update this Policy. The version in force is always here with its version number and effective date. Where a change materially affects how we use your data, we email you at least 30 days beforehand.

Contact

Phoebe Partners Limited, 23 Agias Paraskevis, Germasogeia, 4044, Limassol, Cyprus
Registration number HE 126964
Email: info@ayni-unit.com
Website: www.ayni-unit.com