Like most businesses, Christie’s International Real Estate (CIRE) holds and processes a wide range of information about its clients and other persons who may be interested in Christie’s services. This privacy notice applies to all CIRE operations in the EEA and other global locations, and explains the type of information that we process, why we are processing it and how that processing may affect you. The privacy notice is split into the sections listed below. The Glossary section explains what we mean by “personal data”, “processing”, and other terms used in this notice. We may update this privacy notice from time to time, and will post any revised notice on this webpage. Where appropriate we may notify you by email or by a notice on our website that our privacy notice has changed but we recommend that you check this page regularly. Any changes will be immediately effective on posting.
The CIRE group of companies consists of Christie’s International Real Estate, Inc, Christie’s International Real Estate Europe Limited and several other companies located inside and outside the EEA.
Christie’s International Real Estate Europe Limited (UK company number 05728332) of 8 King Street, St James’s, London SW1Y 6QT, is the primary Data Controller for the purposes of EU Data Protection Legislation. Christie’s International Real Estate, Inc. of 20 Rockefeller Plaza, New York, NY, 10020, United States may also control your data if you interact with Christie’s in the Americas.
Collection directly from you in response to our request
Most of the personal data we process about you comes directly from you (whether face to face, over the telephone, on a paper form, by email or online) for example:
when you agree to market or sell your property through Christie’s or ask us to perform a valuation;
when you express an interest to one of our staff or representatives in buying or selling real property;
when you subscribe to CIRE’s Magazine;
when you sign up on christiesrealestate.com or luxurydefined.christiesrealestate.com to receive news about real estate and upcoming events relating to particular areas of interest;
when you fill out a form on christiesrealestate.com or luxurydefined.christiesrealestate.com;
when you attend a CIRE event.
Automatic collection when you visit our premises or our website
Your image may be collected by CIRE if you attend our premises. We use CCTV at our salerooms and offices for the protection of our staff, our visitors and the property that we sell.
We collect data about your computer when you visit our website, which includes your internet address, your operating system and browser type. We use this information for our internal system administration, to help diagnose problems with our servers, to administer our website and monitor and improve the user experience.
We also collect data about you through cookies. A cookie is a simple text file that is stored on your computer or mobile device by our website’s server which allows our website to remember your preferences or transactions that are in progress. You can see more detail on cookies in our Cookies Policy.
Collection of data from other sources
We may also obtain information about you and/or your property from other sources, for example:
When someone introduces you to us;
When we research real property, artwork or other objects and we find information about you in sources such as newspaper articles, exhibition catalogues, public auction results, or one of our contacts gives us feedback in relation to objects or persons they have been told about.
We have set out below the types of personal data that we process, the purposes for which we use it and the legal grounds on which we process it. The Glossary contains more information about the legal grounds for processing.
Your personal data will be processed by the Christie’s company that initially receives it, and may also be transferred to and processed by other companies within the Christie’s group. Christie’s uses EU Commission approved standard contractual clauses to regulate the transfer and processing of data between group companies.
Outside the Christie’s Group
We do not transfer your personal data to organisations who wish to use it for their own marketing promotions or other purposes. We only transfer your personal data to other organisations where it is necessary to enable us to provide you with the services you have requested (for example: we may transfer your data to our bank, payment card acquirers, shippers, warehouses, insurers, experts who help us authenticate or value property, event venues, caterers, catalogue and direct marketing fulfilment and distribution). Where we do so it will be on the basis that these organisations are required to keep the information confidential and secure, and they will only use the information to carry out the instructed services. Some of these organisations may be located outside the EEA and you should refer to the section Is your personal data transferred out of the EEA? for more information.
We will also transfer your personal data that you provide to us regarding requested services for properties directly to our affiliate agents and brokers who are able to directly handle your request. Conduct anti-money laundering and trade sanction checks and to assist with fraud and crime prevention and detection.
No government entity has direct access to your data. Where we receive a request from a government or law enforcement authority to provide your data, we will only disclose such information where we are ordered to do so by a court or we are otherwise satisfied after internal review that the body making the request has both the right to seek disclosure and has followed the correct process.
As a global organisation with a presence in more than 40 countries, CIRE may in the normal course of its business transfer your personal data outside of the EEA to CIRE in New York, Christie’s salerooms, offices and representatives, and to other organisations who need to process your data in connection with the services that CIRE provides to you (see Who gets to see my data?). Your data will also be held on Christie’s servers located in the USA and CIRE servers in both the USA and EEA.
Non- EEA countries offer varying standards for the protection of personal data and your privacy rights and in some cases, these standards are lower than equivalent EEA standards. When we send your personal data outside the EEA, we have in place the EU Commission approved standard contractual clauses in the form of an appropriate data transfer agreement. More details about typical standard clauses can be found here: http://ec.europa.eu/justice/data-protection/international-transfers/transfer/index_en.htm.
If you have any questions or would like further information about how we make personal data available to non-EEA countries please contact us (see Contact Information below).
We will retain your personal data for as long as is necessary to provide the relevant services, maintain business records to satisfy tax, legal and other regulatory requirements, and protect and defend against potential legal claims.
We will take all reasonable and appropriate steps to protect the security and integrity of all personal information provided via our website, or by any other means electronic or otherwise.
We use a variety of security technologies and procedures to help protect your personal details from unauthorised physical and electronic access.
As effective as modern security practices are, we cannot guarantee the complete security of personal data held in our systems, nor that that information you supply through the internet or any computer network is entirely safe from unauthorised intrusion, access or manipulation during transmission. Any transmission is at your own risk. We will not be liable for any resulting misuse of your personal data.
CIRE’s websites may contain links to other websites not operated by CIRE. The information you provide to us will not be transmitted to other websites, but these other websites may collect personal information about you in accordance with their own privacy notice. CIRE cannot accept any responsibility for the privacy practices or content of those websites.
We try to be as open as we can about the data that we process and recommend you ask us if you have questions about the data we hold on you.
Subject Access Requests
If you are a resident of the EU, you have the legal right to make a “subject access request”. If you exercise this right and we process personal data about you by automated means or as part of a Filing System, we are required to provide you with a description and copy of that personal data, and tell you why we are processing it.
Other rights for EU residents
As well as your subject access right, you may have a legal right to have your personal data rectified or erased, to object to its processing, or have its processing restricted.
If you have provided us with data about yourself and the grounds for processing is Contract or Consent (see What personal data do we process and why?), you have the right to be given the data in machine readable format for transmitting to another data controller.
If we are relying on Consent as the grounds for processing your data (see What personal data do we process and why?), you may withdraw consent at any time. This will not affect the lawfulness of Christie’s processing of your data prior to your withdrawal.
Rights for California residents
If you are a resident of California you may have a right pursuant to Section 1798.83 of the California Civil Code to obtain certain information about the types of personal data that we have shared with third parties for direct marketing purposes during the preceding calendar year, including the names and addresses of those third parties, and examples of the types of services or products marketed by those third parties.
Please contact us at email@example.com if you would like to exercise any of your rights explained above in relation to your personal data.
If you have any queries in relation to Christie’s processing of your personal data please contact us at firstname.lastname@example.org.
Compliance with a legal obligation – processing is necessary to ensure we comply with our legal and regulatory obligations.
Consent – you have given specific consent to the processing of your personal data.
Data Controller – the person who determines the purposes and means of processing personal data.
EEA – the European Economic Area which comprises countries that are members of the European Union and Norway, Iceland and Liechtenstein.
Filing System – a structured set of personal data that is accessible according to specific criteria.
Legitimate Interests – processing is necessary for our or a third party’s legitimate interests in carrying on, managing and administering our respective businesses effectively and properly (except where our or the third party’s interests are overridden by your own interests, rights and freedoms).
Performance of a contract – processing is necessary to carry out our contractual duties, exercise our contractual rights or otherwise perform our contract with you, or to take steps at your request to enter a contract.
Personal Data – any data relating to an identified or identifiable natural person. This can include names, user ID, location data, email addresses, photographs, job applications, purchase history, user account information, opinions, and correspondence to and from an individual.
Processing – any operation performed on personal data, such as collection, recording, storage, retrieval, use, combining it with other data, transmission, disclosure or deletion.
Public Interest – processing is necessary for the performance of a task carried out in the public interest.