Privacy Policy

Last updated: 14 August 2026

This Privacy Policy explains how Digital Bacon Ltd processes personal data when you use the DIZON website, dashboard, Wallet app, Artwork Identities and related services.

1. Controller

Digital Bacon Ltd
Solonos Michailidi 6, Chloraka Pines, House 4
8220 Chloraka, Paphos, Republic of Cyprus
Company registration number HE406662
Email: info@dizon.io
Phone: +357 96806909

2. Personal data we process

  • Account and profile data: name, email address, contact details, login and authentication information, account type and preferences.
  • Artist and artwork data: artist information, artwork descriptions, images, dates, dimensions, ownership-related information and data connected with Artwork Identities.
  • Public Identity Card data: information that an authorised user chooses to publish, which may include artist details, artwork information, price or contact information.
  • Transaction data: products, membership, billing period, payment status, invoices, currency and transaction identifiers. Complete card details are normally handled by the payment provider.
  • Usage and device data: IP address, browser or app version, device type, operating system, language, timestamps, diagnostic data, security events and interactions with the service.
  • QR and transfer data: scans, access events, assignment and transfer history and information needed to provide an Artwork Identity to its current owner.
  • Communications: messages, support requests, feedback and newsletter preferences.

3. Purposes and legal bases

  • Performance of a contract: to create and manage accounts, memberships and Artwork Identities; provide the dashboard and Wallet; process orders; support transfers; and respond to service requests.
  • Legal obligations: to maintain accounting and transaction records, respond to lawful requests and meet tax, consumer-protection and compliance obligations.
  • Legitimate interests: to secure and improve DIZON, prevent fraud and misuse, diagnose technical issues, defend legal claims and communicate essential service information. We balance these interests against your rights.
  • Consent: for optional marketing, non-essential cookies, push notifications or other processing where consent is requested. Consent can be withdrawn at any time.

4. Public information

Artwork Identity Cards are designed to make selected artwork information accessible to people who scan or open them. Before publishing personal data, you must have the authority to do so. Avoid publishing private addresses, confidential documents or other information that is not intended for the public.

5. Recipients and service providers

We disclose personal data only where necessary to provide or protect the service, comply with law or complete a transaction. Recipients may include hosting and cloud infrastructure providers, authentication and security providers, payment processors, email and customer-support providers, analytics providers used with the required consent, professional advisers and public authorities.

Payment providers process payment information under their own privacy notices. Public Identity Card information can be viewed by anyone with access to the relevant link or QR code.

5a. Enquiries through Meta instant forms

When you submit a DIZON instant form on Facebook or Instagram, we receive the information entered by you, or pre-filled by Meta and confirmed by you, through Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. This may include your name, email address, answers concerning your role and a proposed artwork, an optional portfolio, website or Instagram link supplied by you, and technical form, campaign and lead identifiers.

We process this information to assess your enquiry concerning the DIZON pilot offer, contact you personally and, if requested, assist you with setting up a DIZON Identity. Where your enquiry relates to potentially entering into a contract, processing is necessary to take steps at your request before entering into a contract under Article 6(1)(b) GDPR. Where you submit only a general business enquiry without a specific intention to contract, processing is based on Article 6(1)(f) GDPR and our legitimate interest in responding to voluntarily initiated business enquiries in an organised and personal manner. You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation.

Submitting the form does not create a purchase contract or membership. We will not use the information for a newsletter or other marketing unrelated to your enquiry merely because you submitted the form.

Within DIZON, access is restricted to persons handling the enquiry. Where actually used, carefully selected processors providing email, hosting or customer-management services may receive access; the relevant providers or recipient categories are identified in the “Recipients and service providers” section of this Privacy Policy. We do not sell lead data or disclose it for a third party’s own purposes.

If no contract is concluded, we delete personal lead data no later than 90 days after the last substantive contact or, where no contact takes place, 90 days after receipt. If you expressly request contact at a later date, we retain the necessary information until that date and for no more than a further 30 days. If a contract is concluded, only information required for the customer and contractual records is transferred to those records, and redundant lead copies are deleted. Statutory retention obligations remain unaffected. Campaign results may subsequently be retained only in a form that no longer identifies individuals.

Providing the information is voluntary. Without your name and a means of contact, however, we cannot respond to your enquiry. We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.

Meta additionally processes information under its own responsibility when providing its platforms and delivering the form and may use global infrastructure. Information about Meta’s purposes, legal bases, recipients, retention and international transfers is available in Meta’s Privacy Policy. Deletion by DIZON does not affect information processed by Meta under its own responsibility.

Your data protection rights and the controller’s contact details are provided in the relevant sections of this Privacy Policy.

6. International transfers

Some providers may process data outside the European Economic Area. Where required, we use an adequacy decision, the European Commission’s Standard Contractual Clauses or another legally recognised safeguard. Information about relevant safeguards can be requested using the contact details above.

7. Retention

We retain personal data only for as long as needed for the purposes described above. Account data is generally retained while the account is active and for a reasonable period afterwards for security, dispute resolution and reactivation. Transaction and invoice records are kept for the period required by applicable tax and accounting law. Support and security records are retained according to their relevance and risk. Consent records are retained as evidence for as long as necessary.

Information connected with an Artwork Identity may need to remain available after a membership or account ends so that the Identity and its artwork history continue to function. Where possible, unnecessary personal data will be removed, restricted or anonymised. You may request information about the retention period applicable to specific data.

8. Your rights

Subject to the conditions of applicable law, you may request access to, correction or deletion of your personal data, restriction of processing, data portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing carried out before withdrawal.

Send requests to info@dizon.io. We may need to verify your identity. You also have the right to complain to the Office of the Commissioner for Personal Data Protection in the Republic of Cyprus or, where applicable, your local data-protection authority.

9. Cookies and similar technologies

We use technologies required for security, account sessions, preferences and core service functionality. Optional technologies, including analytics or marketing technologies, are used only where an appropriate legal basis and any required consent exist. Details and controls are provided in our Cookie Policy and cookie settings.

10. Marketing communications

We send promotional email only where permitted by law. You can unsubscribe using the link in the message or contact us. Essential account, security, billing and service notices are not marketing communications.

11. Security

We use technical and organisational measures intended to protect personal data, including access controls, secure communication, monitoring and data minimisation. No online system can be guaranteed completely secure. Please use a strong password and notify us promptly of suspected unauthorised access.

12. Children

DIZON accounts and purchases are not intended for persons under 18. We do not knowingly create accounts for children. If you believe a child has provided personal data, please contact us.

13. Changes to this Policy

We may update this Policy to reflect changes to DIZON, our providers or legal requirements. The current version and update date will be published here. Material changes may also be communicated through the service or by email.

14. Contact

For privacy questions or requests, contact Digital Bacon Ltd at info@dizon.io.