Owner Data Retention Policy
Effective Date: August 4, 2026
Governing language. This policy is provided in English. The Japanese translation is offered for the reader's convenience only. In the event of any inconsistency or conflict between the English and Japanese versions, the English version shall control.
準拠言語。本ポリシーは英語で作成されています。日本語訳は読者の便宜のために提供されるものです。英語版と日本語版との間に不一致または矛盾がある場合は、英語版が優先されます。
1. Posture
Rinkya Authentic holds as little personal information as the product allows. The serious registries in this category advertise not holding collector identity as a feature: Artory never asks a collector for their identity; the Art Loss Register never requests the current owner's name; fine art publishes "Private Collection"; grading companies put no owner on the certificate at all. We adopt the same posture: the certificate is permanent, the person is not part of the permanent record.
Already true in the product:
- Nothing personal is written to the blockchain. The anchored payload carries a display name that is "Anonymous" or, with the owner's own confirmation, their chosen public name. No email, phone, address, or note has ever been anchored.
- The first owner's street address is not collected at all.
- A name appears on the public certificate only after the owner personally confirms it through a signed-in owner session. A certifier cannot publish an owner's name on their behalf.
- Login artifacts (magic links, credential tokens, SMS codes) delete themselves at expiry.
- Scan logs store a one-way hash of the visitor's IP, never the IP itself.
2. What we hold, why, and for how long
| Class | What | Why held | Retention |
|---|---|---|---|
| Certificate provenance | First-owner name, email, phone, country, acquisition date, notes; current owner's display name; ownership history | The provenance chain is the product; owner contact enables transfer verification | Life of the certificate, erasable on the person's request (Section 3) |
| Transaction records | Submission details, client name/email/phone, shipping addresses, payment references, invoices | Fulfilment, tax, dispute defense; the 4-year transferable authenticity guarantee (Terms Section 13) must remain administrable | 7 years after the transaction closes, then eligible for redaction |
| Ownership claims | Claim contact details and evidence | Verifying and auditing ownership changes | While pending, then as part of the certificate's audit trail; personal fields erasable with the person (Section 3) |
| Authentication artifacts | Owner magic links, credential tokens, SMS codes (email/phone bearing) | Sign-in only | Self-deleting at expiry (minutes to days) |
| Newsletter subscription | Email address, language, signup page | Sending the Rinkya Authentic Newsletter you signed up for (confirmed opt-in) | Until you unsubscribe; unconfirmed signups self-delete after 7 days |
| Scan logs | Hashed IP, user agent, timestamp per seal scan | Abuse detection, scan-count statistics | Indefinite; contains no recoverable identity |
| Examination recordings | Remote-session recordings and stills | Governed separately by the remote-services terms: recordings of the person are deletable on request, photographs of the piece and a non-personal attestation are retained | Per the remote-services terms; not restated here |
3. Erasure: what it reaches, honestly
Erasure is yours to scope. You may have everything removed, or ask us to retain only your email address so you can still verify ownership of your certificates. Full erasure permanently ends owner sign-in, since the email we hold is how ownership is proven; if you keep the email, you can complete a full erasure at any later time. And if you only want your name off the public certificate, that is not erasure at all: withdraw your consent on the certificate page, and your owner access is unaffected.
On a verified request from the person concerned (or their estate):
Removed from the live product immediately: their name, email, phone, country and notes on any certificate; their ownership-claim records; any surviving login artifacts; their transactional contact details where the retention period in Section 2 has run. The public certificate then reads "Private Collection." The certificate itself, its images, verdict, grade, and blockchain anchors are records about the piece and are unaffected.
Recorded in place of the person: a non-personal tombstone (date, class of data removed, acting staff member). We keep proof that an erasure happened without keeping who was erased.
What erasure cannot reach, stated plainly:
- Database backups retain prior values until they expire on their rolling window; they are not edited in place. Erased data ages out of backups automatically.
- Records inside an open retention period in Section 2 (tax, dispute, guarantee administration) are redacted when that period runs, not before.
- Email delivery logs held by our email provider are outside our control.
- The blockchain cannot be edited, and holds no personal information to erase. This is by design and is why erasure of everything else is possible.
Any policy promising "total erasure" would be false. The honest promise is the above.
4. How a request is made
By email to authentic@rinkya.com, from (or verifiably on behalf of) the person concerned. Identity is checked against the records we already hold; we do not ask for identity documents. Requests are handled by staff; there is no self-serve deletion at current volume.
第1条 基本姿勢
Rinkya Authenticは、プロダクトが許す限り最小限の個人情報のみを保持します。この分野の主要なレジストリは、コレクターの身元を保持しないことを特長として掲げています。Artoryはコレクターに身元を尋ねません。Art Loss Registerは現所有者の氏名を求めません。美術業界では「個人蔵」と表記されます。グレーディング会社の証明書には所有者は一切記載されません。当社も同じ姿勢を採用します。証明書は永続的ですが、人は永続的記録の一部ではありません。
既にプロダクトにおいて実現していること:
- ブロックチェーンには個人情報は一切書き込まれません。アンカーされるペイロードに含まれる表示名は「Anonymous」であるか、所有者本人が確認した公開名のみです。メールアドレス、電話番号、住所またはメモがアンカーされたことは一度もありません。
- 最初の所有者の住所(番地)はそもそも収集していません。
- 公開証明書に氏名が表示されるのは、所有者本人がサインイン済みの所有者セッションを通じて自ら確認した場合に限られます。鑑定士が所有者に代わって氏名を公開することはできません。
- ログイン用の一時データ(マジックリンク、認証トークン、SMSコード)は、有効期限が切れると自動的に削除されます。
- スキャンログには訪問者のIPアドレスの一方向ハッシュのみが保存され、IPアドレスそのものは保存されません。
第2条 保持する情報、その理由および期間
| 区分 | 内容 | 保持する理由 | 保持期間 |
|---|---|---|---|
| 証明書の来歴 | 最初の所有者の氏名、メールアドレス、電話番号、国、取得日、メモ。現所有者の表示名。所有履歴 | 来歴の連鎖はプロダクトそのものであり、所有者への連絡手段は移転の検証を可能にします | 証明書の存続期間。本人の請求により消去可能(第3条) |
| 取引記録 | 提出内容、依頼者の氏名・メールアドレス・電話番号、配送先住所、決済参照情報、請求書 | 履行、税務、紛争への対応。4年間の譲渡可能な真贋保証(利用規約第13条)の管理 | 取引終了後7年間。その後、削除処理の対象となります |
| 所有権クレーム | クレームの連絡先情報および証拠 | 所有権変更の検証および監査 | 審査中は保持し、その後は証明書の監査証跡の一部として保持。個人に属するフィールドは本人とともに消去可能(第3条) |
| 認証アーティファクト | 所有者用マジックリンク、認証トークン、SMSコード(メールアドレス・電話番号を含む) | サインインのみ | 有効期限切れで自動削除(数分から数日) |
| ニュースレター登録 | メールアドレス、言語、登録元ページ | ご登録いただいた Rinkya Authentic ニュースレターの配信(確認済みオプトイン) | 登録解除まで。未確認の登録は7日後に自動削除されます |
| スキャンログ | シールスキャンごとのハッシュ化IP、ユーザーエージェント、タイムスタンプ | 不正検知、スキャン統計 | 無期限。復元可能な身元情報を含みません |
| 検査の録画 | リモートセッションの録画および静止画 | リモートサービスの規約に別途準拠します。人物の録画は請求により削除可能であり、作品の写真および非個人的な確認記録は保持されます | リモートサービスの規約によります。本ポリシーでは再掲しません |
第3条 消去が及ぶ範囲(誠実な記載)
消去の範囲はご本人が選べます。すべてを削除することも、証明書の所有者確認のためにメールアドレスのみを当社に残すこともできます。当社が保持するメールアドレスは所有者確認の手段であるため、完全な消去を行うと、所有者サインインは永久に利用できなくなります。メールアドレスを残した場合は、後からいつでも完全な消去を行えます。また、公開証明書から氏名を消したいだけの場合は、消去ではなく、証明書ページで同意を撤回してください。所有者アクセスには影響しません。
本人(またはその遺産管理人)からの検証済みの請求があった場合:
直ちにライブ環境から削除されるもの:あらゆる証明書上の氏名、メールアドレス、電話番号、国およびメモ。所有権クレーム記録。残存するログインアーティファクト。第2条の保持期間が経過した取引上の連絡先情報。公開証明書の表示は「個人蔵」となります。証明書そのもの、その画像、判定、グレードおよびブロックチェーンアンカーは品物に関する記録であり、影響を受けません。
本人に代わって記録されるもの:非個人的な削除記録(日付、削除されたデータの区分、担当スタッフ)。誰が消去されたかを保持することなく、消去が行われた事実の証拠を保持します。
消去が及ばない範囲(明記します):
- データベースのバックアップは、ローリング期間が満了するまで過去の値を保持します。バックアップは直接編集されません。消去されたデータはバックアップからも自動的に消滅します。
- 第2条の保持期間中の記録(税務、紛争、保証の管理)は、当該期間の満了時に削除処理され、それ以前には行われません。
- メールプロバイダーが保持する配信ログは当社の管理外です。
- ブロックチェーンは編集できませんが、消去すべき個人情報を一切保持していません。これは設計によるものであり、それ以外のすべての消去が可能である理由です。
「完全な消去」を約束するポリシーは虚偽となります。誠実な約束は上記のとおりです。
第4条 請求の方法
authentic@rinkya.com宛てに、本人(または本人を検証可能に代理する者)からメールでご請求ください。身元は、当社が既に保持する記録と照合して確認します。身分証明書の提出は求めません。請求はスタッフが対応します。現在の規模では、セルフサービスの削除機能は提供していません。