Last updated: April 2026 (version 2026-05-26)
This policy applies to all users of ccauktioner.se — both buyers (bidders) and sellers (consignors).
CCAuktioner is responsible for the processing of your personal data.
Contact:
CCAuktioner, org. no. 5566255849
Länsmansgatan 17, 282 72 Sösdala, Sweden
Email: info@ccauktioner.se
Website: ccauktioner.se
Buyers (bidders) — when you create an account or place a bid, we collect:
We do not collect card or bank account details. Payment is made by you via Swish or bank transfer, and we only store the reference needed to reconcile the payment.
Sellers (consignors) — when you are registered as a seller and consign items, we additionally collect:
Processing of personnummer. Under Chapter 3, Section 10 of the Swedish Data Protection Act (2018:218), personal identity numbers may be processed only where it is clearly justified having regard to the purpose, the importance of secure identification, or other significant reasons. CCAuktioner processes sellers' personnummer in order to (i) comply with the Bookkeeping Act's requirement to identify counterparties (1999:1078, ch. 7), (ii) fulfil the reporting obligation under DAC7 (Act 2022:1682) toward the Swedish Tax Agency, (iii) report artist resale royalties via BUS (Act 1960:729), and (iv) comply with the Second-Hand Goods Act (1999:271). The personnummer is never disclosed for marketing and is not processed for purposes beyond these legal obligations.
| Purpose | Legal basis |
|---|---|
| Managing your account and login (buyers) | Contract (account terms) |
| Running and administering auctions | Contract |
| Contacting you when you win an auction | Contract |
| Sending email notifications (outbid, won) | Contract |
| Sending push notifications to browser/home screen (outbid) | Consent (may be withdrawn in account settings) |
| Handling bid disputes and complaints | Legitimate interest |
| Administering seller consignments and payouts (sellers) | Contract (seller agreement) |
| Bookkeeping and accounting records (buyers and sellers) | Legal obligation (Accounting Act, 7 years) |
| DAC7 reporting to the Swedish Tax Agency (sellers) | Legal obligation (Act 2022:1682) |
| Seller ID-document registration (second-hand trade) | Legal obligation (Act 1999:271 § 5, Ordinance 1999:272 § 11) + Legitimate interest |
| Buyer registration at POS sale of regulated second-hand goods | Legal obligation (Act 1999:271 § 4, Ordinance 1999:272) + Legitimate interest |
| Handling right-of-withdrawal requests under the Distance Contracts Act | Legal obligation + contract |
| Publishing the final price in our public price archive of sold lots (no seller data) | Legitimate interest (GDPR Art. 6(1)(f)) — opt-out before sale, Art. 21 objection after |
| Recording of incoming phone calls and voicemail | Legitimate interest (GDPR Art. 6(1)(f)) — right to object Art. 21 |
We may share your data with the following third parties:
We do not sell personal data to third parties.
Your personal data is primarily stored and processed within the EU/EEA. Exception: if you enable push notifications, endpoint URLs and technical metadata may be processed by Google (FCM, USA) or Apple (APNs, USA) to deliver notifications to your device. Contents are encrypted with VAPID (RFC 8291) and cannot be read by the push provider. Transfers rely on the EU-U.S. Data Privacy Framework or standard contractual clauses (SCC).
Our physical second-hand store and its entrances are under camera surveillance around the clock. Signs at the entrances inform visitors of the surveillance in accordance with Section 15 of the Swedish Camera Surveillance Act (2018:1200) and Article 13 GDPR.
Purpose. The surveillance is carried out to prevent, deter and investigate crime (theft, vandalism, threats) and to protect property and people in the store.
Legal basis and balancing test. The processing is based on legitimate interest (GDPR Art. 6(1)(f)). We have assessed that our interest in protecting property and in preventing and investigating crime outweighs the limited intrusion into personal privacy that the surveillance entails. The cameras only cover the inside of the store and its entrances — never the public space outside the premises — and footage is retained for a short period with restricted access, which minimises the intrusion.
Categories of data subjects. Visitors and customers present in the store premises.
Categories of data. Still and moving images (video recordings). No audio is recorded.
Retention period. Recordings are kept for 14 days and then automatically deleted, unless they need to be retained longer to investigate a specific incident or at the request of the Police.
Recipients. Footage is handled internally with restricted access. Where a crime is suspected, relevant footage may be disclosed to the Swedish Police. No data is transferred to a third country.
Data controller. Skånerot AB (reg. no. 556625-5849), trading as CCAuktioner. You have the rights described in § 10 below, including the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
CCAuktioner operates its own telephony service. Incoming calls to our switchboard number may be recorded, and anyone who leaves a message in our voicemail is recorded. This section concerns telephony and is separate from the camera surveillance in § 6 — the statement there that "no audio is recorded" applies only to the store's surveillance cameras, not to phone calls.
What we record. On incoming calls the entire call may be recorded (both parties' speech) after an initial spoken notice has informed about it. In the voicemail we record the message you choose to leave. We also store call metadata: your phone number, the time, the call duration and the action the call led to. Outgoing calls from us are not recorded as a rule; if in an individual case we record an outgoing call we inform you before the recording starts and you may then decline.
Purpose. To ensure the quality of our customer contact, document oral agreements on consignment, bidding, valuation and payout, and to be able to investigate and substantiate matters in complaints and disputes.
Legal basis. Legitimate interest (GDPR Art. 6(1)(f)). We have carried out a balancing test and concluded that our interest in quality assurance, documentation and securing evidence outweighs the limited privacy intrusion the recording entails — in particular because (i) you are informed of the recording at the start of the call and can ask us to switch it off, (ii) the recording is stored encrypted on a server in Sweden with restricted access, (iii) the material is automatically erased after a short time, and (iv) we neither profile you nor share the recording for other purposes. If the call concerns sensitive data (Art. 9) we instead obtain your explicit consent before any recording takes place.
Retention period. Call recordings are automatically deleted after 90 days. Voicemail messages are automatically deleted after 30 days. Call metadata (number, time, duration) may be kept somewhat longer for statistics and troubleshooting, but no longer than 12 months. If a recording is needed to investigate or defend a specific legal claim it may be retained until the matter is concluded.
Your right to object (GDPR Art. 21). Because the processing is based on legitimate interest you have the right to object to recording at any time. You can do so already during the call — just tell us and we will switch off the recording — or afterwards by contacting info@ccauktioner.se, whereupon we erase the recording unless there are compelling legitimate grounds for continued processing or it is needed to establish, exercise or defend a legal claim.
Recipients and processors. Telephony traffic is carried by our telecom operator 46elks AB (Sweden), which is a data processor. Recordings are downloaded from 46elks and stored encrypted at our web host Loopia AB (Sweden) within the EU/EEA. Both are data processors and process the data solely on our instructions and under data processing agreements (GDPR Art. 28). Where a crime is suspected a recording may be disclosed to the Swedish Police. No data is transferred to a third country.
Data controller. Skånerot AB (reg. no. 556625-5849), trading as CCAuktioner. You have the rights described in the "Your Rights" section below, and you may lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
At ccauktioner.se/priser/ we publish an archive of final prices for sold lots. The archive typically shows title, category, photo, description, sale date and the final hammer price. No information about the seller is published — neither name, initials, town, seller ID nor any other identifying information.
Purpose. Market transparency, historical price documentation, an independent valuation reference for buyers, sellers and third parties, and buyer protection. Publication of final prices is moreover standard industry practice among comparable operators.
Legal basis. Legitimate interest (GDPR Art. 6(1)(f)). We have performed a legitimate-interest assessment (LIA) and concluded that the interest in historical price transparency outweighs the limited privacy intrusion the publication entails — in particular because (i) no seller data is published, (ii) auction prices are already public during the auction itself and the archive is a continuation of that publicity, and (iii) the seller has a reasonable expectation that the sale price will become lasting market information.
Categories of data. Item data: title, category, photograph(s), description, sale date, final price. No seller-identifying data.
Retention. Entries in the price archive are retained indefinitely as a historical price reference, subject to individual review on objection (see below).
Opt-out before sale. The seller may choose that an individual item shall not be included in the archive by ticking the opt-out box at intake or by changing the setting in the seller portal no later than the auction start date. For items where opt-out is activated before the auction starts, neither image nor final price is published in the archive.
Right to object after sale (GDPR Art. 21). Even after a lot has been sold the seller retains the right to object to continued publication by contacting info@ccauktioner.se. CCAuktioner will then carry out an individual assessment of whether compelling legitimate grounds for continued publication exist that override the seller's interests, rights and freedoms, or whether the publication is for the establishment, exercise or defence of legal claims. A reply is given within 30 days. If the objection is upheld, the item's entry (including image) is promptly removed from the archive.
Buyers. The buyer's identity is never published in the price archive.
We use only technically necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| PHPSESSID | Login session | Session (until browser closes) |
| lang | Language preference (SV/EN) | 1 year |
| cookie_consent | Records your choice in the cookie notice (1 = accepted, essential = essential only), so the banner is not shown again. |
1 year |
Local storage (localStorage)
| Key | Purpose | Duration |
|---|---|---|
| ccauk_listing_view | Saves your preferred listing layout (grid, card, or list) on the auction page. Functional. | Until you clear browser data |
| cookie_consent | Same value as the cookie_consent cookie. Used as a fallback in browsers that block session or third-party cookies (e.g. Brave in strict mode). |
1 year |
Other local storage
cc-shell-v<n>) — if you install or use CCAuktioner as a Progressive Web App (PWA), the shell pages (home, search, offline page) are cached locally by the service worker so the app works without an internet connection. No personal data is cached. Deleted when you uninstall the PWA, clear site data, or when a new version of the service worker is published.All fonts (Playfair Display, Inter) are self-hosted on our own server. No requests are made to Google Fonts or other external font services, so no IP addresses are transmitted to third parties for font loading.
Under GDPR you have the right to:
To exercise your rights, contact us at info@ccauktioner.se.
We apply appropriate technical and organisational security measures: encrypted connections (HTTPS), hashed passwords (bcrypt), CSRF protection, brute-force lockout, and regular security reviews.