Privacy notice
STEMMA ART (PTY) LTD
Last updated: 26 September 2026
Applies to stemma.art, the waitlist, and the Stemma service as it is made available.
This notice tells you what personal information we collect, why, who receives it, and what you can ask us to do. It is the notice required by section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA). If you are in the European Economic Area or the United Kingdom, the GDPR section at the end also applies to you.
1. Who we are
The responsible party is STEMMA ART (PTY) LTD ("Stemma", "we").
| Website | https://stemma.art |
| studio@stemma.art | |
| Information Officer | The head of the company, contacted at studio@stemma.art. |
2. What this notice covers
It covers:
- the public site and the waitlist
- an account, when accounts open
- identity checks for people who ask to issue certificates
- certificates, the registry, collection files, and custody or checkout tools, as each of those is offered
It does not cover a gallery, insurer, or shipper who keeps their own records. Their notice applies to them.
3. The information we collect
You give us
- Waitlist: your email address, and your name if you give it.
- Account: name, email, phone number, and the sign-in method (a passkey or a one-time code). We do not store a password you type if you use a passkey.
- Artist profile: the public name you want on a certificate, and links or letters you offer so we can tell similar names apart.
- Work records: title, year, medium, dimensions, photos, condition notes, and values you type for your own inventory or insurance export.
- Certificate: the signed record, the tag identifier, and a hash of a surface check. Not a picture of your identity document.
- Custody, when that tool is offered: who has the work, the dates, and the purpose you and the other party agree.
- Support mail you send to studio@stemma.art.
A vendor collects, and we receive only the result
If you ask to be allowed to issue a certificate, an identity-check vendor (currently Didit) collects the government identity document, a liveness check, and a face match. That vendor also sees device and network data needed for the check.
We receive the outcome: pass or fail, the verification tier, the date, and the public artist name. We do not keep the passport image, the identity number, or the selfie in our database. Those stay in the vendor's vault.
We generate
- A public key and a decentralised identifier for the signing key. The private key stays on your device.
- Hashes of the signed certificate and of the identity credential.
- Log data: time, the action, and a security log if a sign-in fails.
We do not collect for this product
- We do not ask for a home address on a public record.
- We do not put identity images, identity numbers, insurance values, or private notes on the registry.
- We do not send identity documents or passport numbers to an AI tool. If we use a model to read a work note or a public name, the input is the redacted text, not the identity file.
4. Where it comes from
Most of it comes from you. The identity-check result comes from the vendor. A gallery or estate may send us a letter that you, or they, asked us to use to show authority to sign. We do not buy marketing lists.
5. Why we use it
| Information | Purpose | POPIA condition |
|---|---|---|
| Waitlist email | To write to you about opening the service, and nothing else, unless you agree to more | Consent (section 11(1)(a)), and section 69 for electronic mail |
| Account and passkey | To sign you in and to keep the account yours | Contract, or steps you ask for before a contract |
| Identity check and tier | So a certificate is not issued under a name we have not checked | Consent for the check. The check is voluntary. Without it you can keep an inventory record, not a certificate of authenticity |
| Legal name, kept private | To bind the checked person to the public artist name | Consent, and our legitimate interest in stopping a false issuer |
| Work, photos, values | To make the record, the collection file, and an insurance export you asked for | Contract |
| Public artist name, certificate hash, custody events you publish | To run the registry you asked us to publish | Contract, and your request to publish |
| Security logs | To protect accounts and the registry | Legitimate interest, and a legal duty if a law later requires a record |
| Support mail | To answer you | Contract or legitimate interest |
Giving information is voluntary. If you do not join the waitlist, we simply do not write to you. If you do not complete an identity check, we will not let that account issue a certificate of authenticity. No law requires you to use Stemma. If a later sale through the service makes us an accountable institution under the Financial Intelligence Centre Act, we will tell you which identity details that Act then requires, before we collect them.
6. Special personal information
Biometric information is special personal information under section 26 of POPIA. A liveness check and a face match are biometric. We do not run that check ourselves. The vendor does, and only if you consent and ask to be checked. You can refuse. The consequence is that the account stays unverified and cannot issue a certificate of authenticity.
We do not process information about children. You must be 18 or older to have an account.
7. Who receives it
| Recipient | What they get | Why |
|---|---|---|
| Identity-check vendor (currently Didit) | The document, liveness capture, and face match | To perform the check you asked for. They are an operator for that check. |
| Hosting and email providers | The data needed to run the site, store the private file, and send mail | To provide the service |
| A person you choose | A certificate, a custody offer, or an insurance export | Because you sent it or published it |
| The public registry | Hashes, the public artist name, the certificate identifier, and custody events the parties agreed to publish | Because you asked for a record that outlives a private server |
| A professional adviser, insurer, or authority | Only what the law, a court, or your instruction requires | Legal duty or your request |
We do not sell personal information.
The public certificate shows the display name, the verification tier, and the date. It does not show the identity number or the document image.
8. Transfers out of South Africa
The identity vendor, and some hosting or email systems, process information outside South Africa. Section 72 of POPIA allows that when the recipient is bound by a contract, binding corporate rules, or a law that gives a comparable level of protection, or when you consent. We use a written operator contract for the identity check and for hosts who store personal information. We do not claim that every country we touch has been declared adequate. The identity images stay in the vendor's vault, not on the registry.
If you are in the European Economic Area or the United Kingdom, we use the same contracts, and standard contractual clauses where the GDPR requires them.
9. The public record, and what we cannot pull back
A certificate is meant to stay checkable. If you ask us to publish one, we publish the hash, the public name, and the events you chose. An independent public timestamp of that hash can be checked without us.
If you later ask us to delete your account:
- we delete the private file we still hold (drafts, messages, unpublished notes, the private legal name)
- we can mark a certificate revoked, so new reliance on a dead key fails
- we cannot promise to erase a hash that has already been timestamped outside our servers, or a copy a collector already downloaded
That limit is why the publish step is a separate, explicit act, not a side effect of opening an account.
10. How long we keep it
| Record | Period |
|---|---|
| Waitlist email | Until you unsubscribe, then deleted within 30 days, unless a law requires a short suppression record so we do not mail you again |
| Account | For the life of the account, then up to 24 months for disputes and security, unless a longer legal period applies |
| Identity-check images | Held by the vendor under its retention rules, not by us. We keep the pass or fail, the tier, and the date for as long as the issuing key is in use, and for a limited period after revocation so the historical badge stays explainable |
| Private collection file | Until you delete it or close the account, subject to the dispute period above |
| Published certificate hash and public events | Kept, because that is the record you asked us to make. Revocation is a new event. It does not pretend the old signature never existed |
| Security logs | Up to 24 months |
11. Security
We use access control on the private database, encryption in transit, and a signing key that stays on your device. Identity images are not written into our database. No method is perfect. If a compromise of personal information creates a risk you should know about, we will tell you and, where POPIA section 22 requires it, the Information Regulator.
12. Direct marketing
We send the waitlist mail only if you asked to join. Each message has a way to stop. We do not send unrelated electronic marketing without a fresh consent, except the narrow case in section 69 of POPIA for a similar product to an existing customer, and even then you can opt out.
13. Cookies
The public site does not set advertising or analytics cookies. If we add any that are not strictly necessary, we will ask first where the law requires consent. When accounts open, a sign-in session cookie (or an equivalent) is necessary to keep you signed in. It is not used to advertise.
A separate cookie policy is not needed while that remains true.
14. Your rights
You may ask us to:
- confirm whether we hold personal information about you, and for access to it (POPIA section 23, and PAIA where it applies)
- correct it (section 24)
- delete or destroy it where the Act allows, subject to section 9 of this notice
- object to processing based on our legitimate interest (section 11(3))
- withdraw consent, which stops future processing that relied only on consent, and does not undo a certificate you already asked us to publish
- stop direct marketing
Write to studio@stemma.art. We may need enough detail to find the record and to confirm it is yours. We respond within a reasonable time, and we will tell you if a law requires us to refuse.
An access request to studio@stemma.art is valid. A refusal can be taken to the Information Regulator.
15. Complaints
Contact us first at studio@stemma.art. You may also complain to the Information Regulator:
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| PAIA complaints | PAIAComplaints@inforegulator.org.za |
| General | enquiries@inforegulator.org.za, 010 023 5200, toll free 0800 017 160 |
| Office | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 |
| Site | https://inforegulator.org.za |
Use the Regulator's form 5 for a formal complaint.
16. European Economic Area and United Kingdom
If the GDPR or UK GDPR applies to you, the same sections describe the data, the purposes, and the recipients. Our lawful bases are consent, contract, legitimate interests (security and telling similar names apart), and a legal obligation if one arises. You also have the right to lodge a complaint with your local supervisory authority, and the right to data portability for information you gave us and that we process by automated means on the basis of consent or contract. We do not use solely automated decisions to refuse an identity check. The vendor performs the check. A namesake or a famous name is reviewed by a person.
17. California
We do not sell personal information, and we do not share it for cross-context behavioural advertising. If you are a California resident you may ask for the categories we collected, the sources, the purpose, and the categories of recipients, and you may ask us to delete what we hold, subject to section 9.
18. Changes
If we change this notice, we will change the date at the top. If a change is material and we have your email, we will tell you. The version on stemma.art is the current one.
19. Contact
STEMMA ART (PTY) LTD