Artcestry Privacy Policy (pilot)

> STATUS: AI-drafted 2026-08-13. Not legal advice. Adopted for pilot at operator's accepted risk; professional review required before public launch. Revised 2026-08-13: corrected for GVOC LTD's UK registration. Revised 2026-09-15: section 7 names the email objection route (privacy-v3).

# Artcestry Privacy Policy (pilot)

Last updated: 2026-09-24. This policy covers the pilot of Artcestry, a service where artists keep dated, tamper-evident records of their works, issue certificates of authenticity in their own name, and record consignments and ownership transfers acknowledged by the people involved.

Standing disclaimer, shown on every certificate and record-check page:

> This certificate records an attestation made by the issuing account on the date shown. Artcestry records entries and their history; it does not verify identity, authenticate artworks, or establish legal ownership.

## 1. Who we are

Artcestry is operated by GVOC LTD, a company registered in the United Kingdom (Companies House number 15935169, registered office 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ) ("we", "us"). We are the data controller for the personal data described here. We serve artists, galleries, and buyers across Africa and beyond. Contact: hello@artcestry.org, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

## 2. What we collect

We collect only what the record-keeping service needs:

- Account and profile data: your name or chosen display name, and your contact channels (WhatsApp number and/or email address).
- Work records: the details an artist enters about a work (title, year, medium, dimensions, images) and the fixed attestation statement version they sign off. These become part of the work's exportable record, which the artist can export at any time.
- Event records: the append-only history of each work (registration, certificate issuance, consignment, transfer, corrections, disputes). Events reference people by internal codes only; they never contain names, contact details, or free text about you.
- Contact details entered by someone else: when a seller proposes a transfer to you, they enter your WhatsApp number or email and confirm you agreed to be contacted about it. We create a private record for you from those details so the work's record can attach to you if you accept.
- Action evidence: when an account or link recipient takes an action (for example accepting a transfer), we store a hashed form of the IP address, the browser type, and which contact channel was used. This is kept separately, never shown publicly, and used only for security and dispute handling.
- Delivery and support data: notification delivery logs, and the content of reports or dispute statements you send us, kept in a private case file.
- Site analytics: first-party, consent-gated analytics only. Public pages carry no third-party trackers. Strictly necessary cookies work without a tick-box; everything else asks first.

We do not collect payment details (the pilot has no payments), precise location, or any data about you from data brokers.

## 3. Why we process it (lawful bases)

Because we are a United Kingdom company, the UK General Data Protection Regulation (UK GDPR) governs our processing. The bases are:

- To run your account and keep the records you create: performance of our contract with you (UK GDPR Article 6(1)(b)).
- To show an artist's display name on their public record pages and certificates: the artist's consent, given at registration (UK GDPR Article 6(1)(a)). Buyers, owners, and galleries are never named on public pages. If the current owner is not the artist, the public record describes them only as "Private collector"; consignments and custody handovers appear only by type and date.
- To create your private record from seller-entered details and send you one message about a proposed transfer: our and the seller's legitimate interests in completing a transfer you agreed to (UK GDPR Article 6(1)(f)). We document this assessment and you can object at any time.
- To keep action evidence and case files: our legitimate interest in keeping the service safe, preventing fraud, and handling disputes (UK GDPR Article 6(1)(f)).
- Analytics: your consent (UK GDPR Article 6(1)(a)).

## 4. Where your data is stored

We are a United Kingdom company and your data is processed in the United Kingdom: our database and application run with hosting providers, and images, certificates, and integrity checkpoints are stored on Amazon Web Services in the eu-west-2 (London, United Kingdom) region. Our processors during the pilot are: Amazon Web Services (storage and delivery), our application hosting provider, Meta Platforms (WhatsApp Business messaging), and our email delivery provider. We are putting data-processing agreements in place with each of them before the service opens beyond this pilot.

## 5. How long we keep it

- Account, profile, and contact data: for as long as your account or record relationship is active, and until you ask us to erase it.
- Work and event records: indefinitely. They are the record the service exists to keep for everyone involved with a work. They contain no names or contact details.
- Action evidence (hashed IP, browser type, channel reference): 24 months, then deleted automatically. We keep it this long because disputes about a transfer can arise well after the event, and this evidence is what lets anyone establish or defend a claim about what happened.
- Notification delivery payloads: neutralized six calendar months after delivery; the delivery record itself is retained for service accounting. Channel references are redacted when you are erased. No scheduled deletion date applies to the notification log itself; that retention job is not yet in service.
- Backups: short-term point-in-time recovery plus encrypted weekly copies kept up to 90 days. If we restore from a backup, recorded erasures are re-applied automatically.

## 6. Your rights, including erasure, and how the artwork record persists

Under the UK GDPR, you can ask us, free of charge, to:

- confirm what we process about you and get a copy in a usable electronic format (access and data portability);
- correct data that is inaccurate, out of date, incomplete, or misleading;
- erase your personal data;
- restrict or object to processing, including any future direct marketing (we send none during the pilot);
- withdraw any consent you gave, as easily as you gave it.

How erasure works here, stated plainly. The history of an artwork is append-only: entries are never rewritten, and each work's record must stay whole for everyone else attached to it. So when you ask for erasure:

- your name, display name, and contact channels are deleted, and the link between you and the record is severed;
- the artwork's event history remains, now pointing to an anonymous participant (for an erased artist, works remain attributed to an anonymised artist record);
- pending links and queued messages to your channels are cancelled, and your account is disabled;
- certificate PDFs that carried your display name are withdrawn from download on our surfaces; copies other people already downloaded are outside our control and cannot be recalled;
- corrections work by appending: a corrected entry supersedes the old one, and the record shows both, because the record's job is to show what was claimed and when.

We may retain the minimum needed where the law allows it, for example evidence needed to establish or defend legal claims. UK GDPR Article 12(3) requires us to respond to rights requests without undue delay: this states our legal duty, not a service-level promise.

You also have the right to lodge a complaint with a supervisory authority, and nothing in this policy limits that right. Our home regulator is the UK Information Commissioner's Office (ico.org.uk).

## 7. Messaging and opt-out

We send transactional messages only: things like "you have a transfer to review" with a link. Message bodies are deliberately generic; they never contain names or work titles. If a seller gave us your number or email, the first message you receive will be about that transfer, sent once, with details behind the link, including where your contact details came from. Reply STOP to any WhatsApp message and we stop using that number immediately. To object to email about a transfer, write to hello@artcestry.org and we stop using that address. We send no marketing messages during the pilot. Where we have your email address, we prefer email over WhatsApp for first contact.

## 8. International transfers

We are a United Kingdom company and our storage is in the United Kingdom (AWS eu-west-2), under the UK's comprehensive data-protection law. Where a processor handles data outside the United Kingdom (for example message or email delivery involving the United States), that transfer takes place under safeguards recognised by UK law, such as the UK Extension to the EU-US Data Privacy Framework or UK-approved contract clauses.

## 9. Security

Sign-in uses emailed or messaged one-time links; we store no passwords. Transfer links are single-use, expire in 7 days, and require a one-time code sent to the same channel. Acceptance pages are excluded from analytics and search indexing. Records are protected by an append-only database design with daily integrity checkpoints to write-once storage.

## 10. Changes and contact

This is a pilot policy; we will notify account holders of material changes before they take effect. Questions, rights requests, and complaints: hello@artcestry.org. This address is monitored; we do not promise a specific response time beyond the legal duty described in section 6. If you believe someone is impersonating an artist, use the report link on any public page.