Skip to content
Sign in
Back to Artheia

Privacy

This page says which personal data Artheia processes and what it does with it. Where part of the text still has to be approved by whoever answers for it, the page says so instead of filling the gap.

Who processes the data

The data controller is missing: company name, registered office, VAT number, an address to write to, and whether there is a data protection officer. It is the same company name that is missing at the foot of every page of the site, and Eugenio has to provide it.

The data processed

This list is taken from the tables and the file stores the system actually uses, not from a generic template.

Personal data processed, by category
CategoryWhatWhere
ProfileEmail address, name, year of birth, nationality, telephone, biographyThe user’s profile
BillingVAT number, tax code, electronic invoicing code, certified email address, and the billing name and addressThe user’s profile
MandateThe document by which a gallery declares that it acts on behalf of an artistA separate store, PDF only
WorkThe declared data of the work, the photographs, the documents uploadedThe record of the work and its stores
Tax code of the signatoryIt sits inside the document signed with a qualified signature, because the signing certificate puts it thereThe document store
TechnicalThe IP address from which a recorded action was taken, and failed sign in attemptsThe action register
Category
Profile
What
Email address, name, year of birth, nationality, telephone, biography
Where
The user’s profile
Category
Billing
What
VAT number, tax code, electronic invoicing code, certified email address, and the billing name and address
Where
The user’s profile
Category
Mandate
What
The document by which a gallery declares that it acts on behalf of an artist
Where
A separate store, PDF only
Category
Work
What
The declared data of the work, the photographs, the documents uploaded
Where
The record of the work and its stores
Category
Tax code of the signatory
What
It sits inside the document signed with a qualified signature, because the signing certificate puts it there
Where
The document store
Category
Technical
What
The IP address from which a recorded action was taken, and failed sign in attempts
Where
The action register

Three things worth saying, because they are not obvious

The public record of a certificate exposes personal data

The name of the author can be read by anyone holding the work or its identifier. The document, which opens after a tap on the chip, contains the tax code of whoever signed it. Whoever declares must know this before declaring, not afterwards.

The action register cannot be deleted

The database refuses every deletion and every modification of the rows in the register, and refuses them to Artheia as well. It is not a setting that can be relaxed: it is the reason that register has any value. A deletion request cannot touch it.

Taps are not tracked

When someone holds a phone to the chip of a work, Artheia records nothing about who is doing it: no IP address, no browser, no session. It is a choice in favour of the person looking, and it is also why the system cannot tell two visitors apart from one who reloaded the page.

Who processes data on Artheia’s behalf

The suppliers that process data on Artheia’s behalf
SupplierWhat it does
SupabaseThe database, authentication and the file stores
Amazon Web ServicesHolds the key from which the chip keys are derived. It processes no personal data
The platform that publishes the siteServes the pages and logs the requests that reach them
Supplier
Supabase
What it does
The database, authentication and the file stores
Supplier
Amazon Web Services
What it does
Holds the key from which the chip keys are derived. It processes no personal data
Supplier
The platform that publishes the site
What it does
Serves the pages and logs the requests that reach them

Where the data of each of the three physically sits is missing, and whether there are transfers outside the European Union. The region has already been chosen for publishing the site, but it has to be confirmed supplier by supplier, and «Europe» is not something to write by inference.

Why, on what basis, and for how long

The purposes and the legal basis of each category are missing, and so are the retention periods. Retention is the heaviest question on this page: the signed document contains a tax code and is meant to last twenty years. If that duration follows from an obligation, the obligation must be cited; if it is a choice, it must be written as a choice, and told to whoever signs before they sign.

Rights, and their real limits

Access, rectification, objection and restriction face no technical obstacle. Erasure and portability do, and this page says so rather than promising them and refusing later.

Erasure cannot be complete

The database forbids deleting a profile to which works, reviews, notifications or documents are attached, and forbids deleting rows of the action register at all. Anyone who has registered even one work cannot therefore have their profile deleted: that profile is what says who declared that work, and removing it would turn the certificate into a declaration with no one behind it.

Chip rows are never deleted

No row of the chip inventory is ever deleted, under any circumstances. They hold no personal data, and they are named here because a request to erase «everything» does not reach them.

Artheia does not promise an erasure that the database refuses.

How to exercise these rights is missing: which address to write to, how long the answer takes, and who to turn to if the answer does not satisfy.

What this page does not cover

What the site keeps on the device of whoever visits it has a page of its own, and it is a short list that can be checked.

Cookies and local storage