Rinkya
Rinkya Authentic
In Japan since 2001

Owner Data Retention Policy

Effective Date: August 4, 2026

Governing language. This policy is provided in English. The Japanese translation is offered for the reader's convenience only. In the event of any inconsistency or conflict between the English and Japanese versions, the English version shall control.

準拠言語。本ポリシーは英語で作成されています。日本語訳は読者の便宜のために提供されるものです。英語版と日本語版との間に不一致または矛盾がある場合は、英語版が優先されます

1. Posture

Rinkya Authentic holds as little personal information as the product allows. The serious registries in this category advertise not holding collector identity as a feature: Artory never asks a collector for their identity; the Art Loss Register never requests the current owner's name; fine art publishes "Private Collection"; grading companies put no owner on the certificate at all. We adopt the same posture: the certificate is permanent, the person is not part of the permanent record.

Already true in the product:

  • Nothing personal is written to the blockchain. The anchored payload carries a display name that is "Anonymous" or, with the owner's own confirmation, their chosen public name. No email, phone, address, or note has ever been anchored.
  • The first owner's street address is not collected at all.
  • A name appears on the public certificate only after the owner personally confirms it through a signed-in owner session. A certifier cannot publish an owner's name on their behalf.
  • Login artifacts (magic links, credential tokens, SMS codes) delete themselves at expiry.
  • Scan logs store a one-way hash of the visitor's IP, never the IP itself.

2. What we hold, why, and for how long

Class What Why held Retention
Certificate provenance First-owner name, email, phone, country, acquisition date, notes; current owner's display name; ownership history The provenance chain is the product; owner contact enables transfer verification Life of the certificate, erasable on the person's request (Section 3)
Transaction records Submission details, client name/email/phone, shipping addresses, payment references, invoices Fulfilment, tax, dispute defense; the 4-year transferable authenticity guarantee (Terms Section 13) must remain administrable 7 years after the transaction closes, then eligible for redaction
Ownership claims Claim contact details and evidence Verifying and auditing ownership changes While pending, then as part of the certificate's audit trail; personal fields erasable with the person (Section 3)
Authentication artifacts Owner magic links, credential tokens, SMS codes (email/phone bearing) Sign-in only Self-deleting at expiry (minutes to days)
Newsletter subscription Email address, language, signup page Sending the Rinkya Authentic Newsletter you signed up for (confirmed opt-in) Until you unsubscribe; unconfirmed signups self-delete after 7 days
Scan logs Hashed IP, user agent, timestamp per seal scan Abuse detection, scan-count statistics Indefinite; contains no recoverable identity
Examination recordings Remote-session recordings and stills Governed separately by the remote-services terms: recordings of the person are deletable on request, photographs of the piece and a non-personal attestation are retained Per the remote-services terms; not restated here

3. Erasure: what it reaches, honestly

Erasure is yours to scope. You may have everything removed, or ask us to retain only your email address so you can still verify ownership of your certificates. Full erasure permanently ends owner sign-in, since the email we hold is how ownership is proven; if you keep the email, you can complete a full erasure at any later time. And if you only want your name off the public certificate, that is not erasure at all: withdraw your consent on the certificate page, and your owner access is unaffected.

On a verified request from the person concerned (or their estate):

Removed from the live product immediately: their name, email, phone, country and notes on any certificate; their ownership-claim records; any surviving login artifacts; their transactional contact details where the retention period in Section 2 has run. The public certificate then reads "Private Collection." The certificate itself, its images, verdict, grade, and blockchain anchors are records about the piece and are unaffected.

Recorded in place of the person: a non-personal tombstone (date, class of data removed, acting staff member). We keep proof that an erasure happened without keeping who was erased.

What erasure cannot reach, stated plainly:

  • Database backups retain prior values until they expire on their rolling window; they are not edited in place. Erased data ages out of backups automatically.
  • Records inside an open retention period in Section 2 (tax, dispute, guarantee administration) are redacted when that period runs, not before.
  • Email delivery logs held by our email provider are outside our control.
  • The blockchain cannot be edited, and holds no personal information to erase. This is by design and is why erasure of everything else is possible.

Any policy promising "total erasure" would be false. The honest promise is the above.

4. How a request is made

By email to authentic@rinkya.com, from (or verifiably on behalf of) the person concerned. Identity is checked against the records we already hold; we do not ask for identity documents. Requests are handled by staff; there is no self-serve deletion at current volume.