ArtX Privacy Policy

    Version 1.0 - Last updated: 10/5/2026

    1. Introduction

    ArtX, a platform for valuing artworks using Artificial Intelligence, is committed to protecting the privacy and security of your personal data. This policy explains in detail how we collect, use, store and protect your information in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act ("loi Informatique et Libertés").

    Full transparency: Given the innovative nature of our processing (AI valuation, blockchain, vector fingerprints), we specifically detail these aspects to ensure your understanding and control.

    2. Data controller

    Legal name: ArtX by Groupe COCORICO

    Registered office: 7 impasse du tennis, 30870 Clarensac, France

    SIRET: 89002202300026

    Email: contact@artx.art

    DPO (Data Protection Officer): dpo@artx.art

    3. Data collected

    3.1 Identification data

    • First and last name (or pseudonym for private collectors)
    • Email address
    • Phone number (optional)
    • Postal address (for deliveries)
    • User status (verified artist, collector, gallery)
    • Date of birth (age verification)

    3.2 Browsing and technical data

    • IP address
    • Browser type and version
    • Operating system
    • Pages visited and time spent
    • Browsing path
    • Device used (desktop, mobile, tablet)

    3.3 Artistic and creative data

    • Artwork images uploaded in high definition
    • Artwork metadata (title, dimensions, medium, year)
    • Text descriptions (optional)
    • Valuation history and value evolution
    • Vector fingerprints generated by AI (see section 5)
    • Digital certificates and blockchain hashes

    3.4 Transactional data

    • Purchase and sales history
    • Transaction amounts
    • Commissions charged
    • Payment methods used (via Stripe - banking data not stored by ArtX)
    • Delivery addresses
    • Tracking numbers
    • Gallery legal information (SIRET, VAT number, legal name)
    • Gallery-artist contracts (commission rate, publication rights)

    3.5 Communication data

    • Message exchanges via internal messaging
    • Customer support tickets
    • Contact requests
    • Reviews and comments (if feature enabled)

    4. Purposes of processing

    Your data is processed exclusively for the following purposes:

    4.1 User account management

    Creation, authentication, configuration and management of your profile (artist or collector).

    4.2 Automated AI valuation

    Visual analysis of artworks, extraction of vector fingerprints, calculation of native value (V0) and overall ArtX score (Vfinal).

    4.3 Marketplace and transactions

    Facilitating purchases/sales (primary and secondary market), commission management, artist resale rights.

    4.4 Issuance of digital certificates

    Generation of blockchain authenticity certificates (optional), ArtX NFT smart contracts.

    4.5 Improvement of the AI engine

    Training and calibration of the valuation model (never used for generative AI purposes).

    4.6 Communication and support

    Responding to inquiries, newsletters (with consent), transactional notifications.

    4.7 Legal obligations

    Compliance with tax and accounting obligations, anti-money laundering, legal compliance.

    5. Processing by Artificial Intelligence

    🔍 Critical section: Full transparency on AI usage

    5.1 How the valuation engine works

    When you upload an image of an artwork, our Artificial Intelligence system analyzes exclusively the visual characteristics of the image to calculate an objective valuation. This processing includes:

    • Vector fingerprint extraction: Generation of a digital vector representing 6 visual dimensions (CVS, SS, OCC, IEV, OM, CTA) - see Terms of Sale art. 11
    • Native value calculation (V0): Automatic estimate based on visual complexity
    • Artist rating integration: Application of a multiplier coefficient based on the artist's historical performance
    • Overall ArtX score (Vfinal): Final result displayed publicly

    5.2 Nature of the data processed by the AI

    Important: Our AI analyzes only the pixels of the image. It does not read, interpret or store any text content describing the artwork. The analysis is purely visual and technical.

    5.3 Retention of vector fingerprints

    The vector fingerprints generated (6-dimensional vectors) are kept in our database to enable:

    • Subsequent recalculation of the valuation (during engine updates)
    • Comparison with other artworks (similarity search)
    • Keeping a history of valuation versions
    • Generation of aggregated (anonymized) statistics

    5.4 Use for AI training

    ⚠️ Separate consent required: The use of your artwork images for training and improving our AI valuation model requires your explicit and separate consent, in accordance with the guidelines of the EDPB (European Data Protection Board) on AI.

    If you give your consent, your images may be used for calibration, bias detection, and improving the accuracy of the valuation engine. No use for generative AI purposes or reproduction of artworks is carried out.

    You can withdraw this consent at any time from your account's privacy settings or by contacting dpo@artx.art. Withdrawing consent does not affect the lawfulness of processing carried out before such withdrawal.

    5.5 Nature of the valuation: a decision-support tool

    Important – Article 22 GDPR: The ArtX valuation constitutes a decision-support tool and has no automatic legal effect on you. It does not automatically determine the sale price, access to a service, or any other decision significantly affecting you.

    The valuation is produced by automated processing based on the visual analysis of the artwork. It provides an indicative value estimate intended to inform artists and collectors, but the final decision (setting the sale price, purchase, etc.) remains entirely human.

    In accordance with Article 22 of the GDPR, you retain the right to:

    • Request a human review of the valuation
    • Contest the result via contact@artx.art
    • Obtain detailed explanations of the criteria and calculation used
    • Express your point of view and put forward your arguments

    5.6 Impact Assessment (DPIA)

    Data Protection Impact Assessment (DPIA): In accordance with Article 35 of the GDPR, an impact assessment has been carried out for the Artificial Intelligence processing implemented by ArtX, given its innovative nature and the systematic use of visual data.

    This assessment evaluates the risks to your rights and freedoms, and documents the security measures in place. It is updated regularly and made available to the CNIL upon request.

    Consultation: A summary of this assessment can be requested from our DPO at dpo@artx.art.

    6. Legal basis for processing

    In accordance with Article 6 of the GDPR, our processing is based on:

    ConsentNewsletters, non-essential cookies, use of images for AI training
    ContractArtwork valuation, marketplace transactions, certificate issuance
    Legitimate interestService improvement, fraud prevention, statistics
    Legal obligationTax and accounting obligations, invoice retention for 10 years

    6.1 Minimum age requirement

    Minimum age required: Use of the ArtX platform is reserved for persons aged 18 or older. This condition is based on:

    • Legal basis: Article 8 of the GDPR and Article 7-1 of the French Civil Code (contractual capacity)
    • Justification: Financial transactions (purchase/sale of artworks) and the creation of contracts (certificates, marketplace) require full legal capacity
    • Verification: Age is declared at registration and may be subject to additional verification for significant transactions

    By registering on ArtX, you certify that you are at least 18 years old.

    7. Data recipients

    Your data may be shared with the following third parties:

    • Hosting: Supabase (secure infrastructure, EU hosting)
    • Payment: Stripe (transaction processing, PCI-DSS compliant)
    • Email: Transactional email service provider (GDPR data processor)
    • Blockchain: Public blockchain network for certificates (pseudonymized data)
    • Platform users: Public profile information, published artworks, valuations
    • Authorities: Upon justified legal request (judicial, tax, anti-money laundering)

    All our data processors are bound by GDPR agreements guaranteeing the security and confidentiality of your data.

    8. Retention period

    Active user accountAs long as the account is active
    Inactive account3 years after last login, then deletion
    Transaction data10 years (accounting obligations)
    Artwork imagesAs long as published, deleted on request or on account closure
    Vector fingerprints5 years after deletion of the artwork (historical traceability)
    Blockchain certificatesPermanent (immutable nature of the blockchain)
    Browsing logs13 months
    Cookies13 months maximum

    9. Your GDPR rights

    In accordance with Articles 15 to 22 of the GDPR, you have the following rights:

    ✓ Right of access (art. 15)

    Obtain a copy of all your personal data and vector fingerprints.

    ✓ Right to rectification (art. 16)

    Correct inaccurate or incomplete data.

    ✓ Right to erasure (art. 17)

    Request the deletion of your data, subject to our legal obligations (10-year invoice retention) and the immutability of the blockchain for certificates.

    ✓ Right to restriction (art. 18)

    Temporarily freeze the processing of your data.

    ✓ Right to data portability (art. 20)

    Receive your data in a structured format (JSON/CSV): profile, artworks, valuations, vector fingerprints, transaction history.

    ✓ Right to object (art. 21)

    Object to processing based on legitimate interest (e.g., use of images for AI training, commercial prospecting).

    ✓ Right regarding automated decisions (art. 22)

    Request a human review of the AI valuation, obtain detailed explanations.

    ✓ Right to withdraw consent

    Withdraw your consent at any time (newsletters, cookies, AI training).

    To exercise your rights: Send an email to dpo@artx.art with the subject "Exercising my GDPR rights" and a copy of your identity document. Response guaranteed within 1 month.

    10. Security measures

    We implement robust technical and organizational measures to protect your data against any unauthorized access, alteration, disclosure or destruction:

    • Encryption: HTTPS/TLS for all communications, encryption at rest for sensitive data
    • Authentication: Hashed passwords (bcrypt), two-factor authentication (2FA) available
    • Access control: Least-privilege policy, logging of administrator access
    • Backup: Automatic daily backups, geographically distributed storage
    • Monitoring: 24/7 monitoring, intrusion detection, automatic alerts
    • Security testing: Regular audits, penetration testing, rapid vulnerability remediation
    • Training: Team awareness training on GDPR best practices and cybersecurity

    11. Cookies and trackers

    Our site uses cookies to improve your experience:

    Essential cookies (no consent required)

    • User session (authentication)
    • Shopping cart
    • Language and theme preferences
    • Security (CSRF protection)

    Analytics cookies (with consent)

    • Visit statistics (anonymized)
    • User journey analysis
    • Experience optimization

    You can manage your preferences via our cookie manager or your browser settings. Declining non-essential cookies does not affect the platform's core functionality.

    12. Blockchain data and certificates

    ⚠️ Permanence of blockchain data: Data recorded on the blockchain (certificates, ArtX NFT smart contracts) is immutable and cannot be deleted, due to the technical nature of this technology.

    ArtX digital certificates contain only:

    • Cryptographic hash of the image (unique, non-reversible fingerprint)
    • Artwork and artist ID (pseudonymized)
    • ArtX valuation score
    • Creation timestamp
    • Ownership history (wallet addresses, pseudonyms)

    No directly identifiable personal data is recorded on the blockchain. Certificates are publicly viewable but pseudonymized.

    If you exercise your right to erasure, we will delete all your data outside the blockchain and anonymize references to you in our internal systems.

    13. International data transfers

    Our main servers are hosted in the European Union (Supabase - GDPR-compliant infrastructure). Some data processors may process your data outside the EU:

    • Stripe (USA): Standard Contractual Clauses (SCCs) approved by the European Commission, GDPR-compliant Data Processing Agreement
    • Public blockchain: Global decentralized network (pseudonymized data only, no directly identifiable personal data)

    Transfer Impact Assessment (TIA)

    In accordance with the EDPB recommendations (01/2020), we have carried out a Transfer Impact Assessment (TIA) to assess the level of data protection in the relevant third countries. This analysis takes into account:

    • Local legislation applicable to data processors
    • Additional safeguards in place (encryption, pseudonymization)
    • Government surveillance practices of the destination country
    • The existence of effective remedies for data subjects

    This assessment is kept up to date and available upon request from our DPO.

    All transfers are secure and comply with Chapter V of the GDPR (adequate protection mechanisms: standard contractual clauses, additional technical measures).

    14. Policy changes

    This policy may be modified to reflect legal, technical or functional changes to the platform. We will inform you of any significant changes by:

    • Email to your registered address
    • Notification in your user area
    • Information banner on the site

    The last update date is always displayed at the top of this page. We encourage you to check it regularly.

    15. Contact and complaints

    For any question regarding your personal data:

    📧 General email: contact@artx.art

    🔒 Data Protection Officer (DPO): dpo@artx.art

    ⚖️ Legal department: legal@artx.art

    📍 Postal address: ArtX by Groupe COCORICO, 7 impasse du tennis, 30870 Clarensac, France

    🛡️ Right to lodge a complaint with the supervisory authority

    If you believe your rights are not being respected, you have the right to lodge a complaint with the French Data Protection Authority (CNIL):

    CNIL
    3 Place de Fontenoy - TSA 80715
    75334 Paris Cedex 07
    Phone: +33 1 53 73 22 22
    Website: www.cnil.fr

    Version 1.0 - Effective since 10/5/2026
    Document viewable and downloadable at any time at artx.art/privacy