Controlled launch draft · Version 2026-10-03.2
Privacy
The substantive privacy framework is drafted. Public effectiveness remains fail-closed until the real operator, privacy-request channel, production provider configuration, retention behavior, rights workflow, and commercial-email compliance facts are verified.
1. Scope and controller
This notice describes personal-information processing for the GANTIÈRE website, Research, accounts when enabled, and prelaunch Auction and Boutique registration. The controller/operator will be the GANTIÈRE operating entity identified in the final launch notice. Public launch remains blocked until the legal identity and monitored privacy contact are verified.
2. Information we may receive
Depending on the feature, GANTIÈRE may receive account and contact details; authentication metadata; research questions; photographs; object details; signatures, maker's marks and labels visible in images; provenance documents; correspondence; Auction or Boutique interests; optional object notes; locale and market preferences; support communications; and technical request, security, device, and log data generated when the service is used, including short-lived pseudonymous abuse-prevention fingerprints where needed to protect public forms.
3. Sources of information
Information may come directly from you, from an authenticated account, from files or images you submit, from public or licensed research sources, from service providers operating on GANTIÈRE's behalf, and from technical systems used to secure and operate the service. GANTIÈRE does not treat a third-party provenance claim as verified merely because it was submitted or found online.
4. Why we process information
GANTIÈRE may process information to provide and improve the requested service; create, maintain, correct, and version research cases; respond to support; manage requested Auction or Boutique access; authenticate users; detect abuse and security incidents; maintain evidence provenance; debug failures; comply with law; establish or defend legal claims; and communicate about a registration or service the user requested.
5. Legal bases where applicable
Where a law such as the GDPR or UK GDPR applies, processing may rely on performance of a contract or steps requested before a contract, legitimate interests in operating and securing the service and maintaining reliable research records, consent where required, and compliance with legal obligations. The applicable basis depends on the processing activity and jurisdiction; consent is not treated as the legal basis when another basis actually governs the activity.
6. Research inputs and AI processing
Research inputs may be transmitted to approved AI service providers when a feature requires model processing. GANTIÈRE policy does not authorize use of customer submissions for provider model training unless a separate explicit opt-in is implemented and disclosed. The final launch review must verify the actual production provider, endpoint, retention, human-review, and data-control settings. AI output is treated as generated analysis, not as independent evidence.
7. Service providers and disclosures
GANTIÈRE may disclose information to hosting, database, authentication, AI, security, communications, observability, and research-source providers only as reasonably necessary for their role, subject to applicable contracts and safeguards. Information may also be disclosed when required by law, to protect rights or safety, in connection with a legitimate corporate transaction subject to appropriate protections, or at your direction. The launch configuration does not authorize sale of personal information for money or cross-context behavioral advertising.
8. Early-access registrations and email
Auction and Boutique registration may collect an email address, selected interests, optional object notes, account association when signed in, timestamps, source path, age/eligibility confirmation, and the accepted Terms and Privacy versions. Requesting access permits communications reasonably needed to process and deliver that request. Marketing email consent is separate and optional. Commercial marketing must not be sent until the sender postal address and a working opt-out workflow are verified; withdrawal from marketing does not prevent necessary service or security communications where those communications are otherwise lawful.
9. Cookies, analytics, and tracking
The launch contract disables non-essential tracking by default. GANTIÈRE must not enable advertising, cross-site behavioral tracking, or non-essential analytics until the disclosure and consent design is updated and technically verified. Essential authentication, security, load-balancing, and preference technologies may be used when necessary to provide the service.
10. Retention and deletion
GANTIÈRE keeps personal information only for as long as reasonably necessary for the purpose collected, security, legal obligations, dispute handling, and authorized research-record integrity. Public access-registration abuse fingerprints are derived with a keyed one-way digest rather than storing raw client IP and are configured for opportunistic deletion after 24 hours. Research cases may require durable version history so corrections and evidence lineage remain traceable. Exact category-specific production retention and deletion behavior must be implemented and verified before the retentionScheduleReviewed release gate can become true; this draft intentionally does not promise a deletion period the production system has not yet proven.
11. Security
GANTIÈRE uses administrative, technical, and organizational safeguards intended to protect personal information, including restricted server-side access to sensitive state, authentication controls, access separation, and security monitoring. No system can guarantee absolute security. Security controls are reviewed as the product and threat model change.
12. Privacy rights and requests
Depending on applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, or information about disclosures or automated processing, and to appeal certain decisions. GANTIÈRE will not require a user to waive non-waivable privacy rights. A verified request channel and operational identity-verification workflow must be live before the privacyRightsWorkflowReady release gate can become true.
13. United States state privacy rights
Some U.S. state laws provide additional rights or apply only when statutory thresholds or processing conditions are met. GANTIÈRE will evaluate requests under the law that applies to the requester and may choose to provide a broader right voluntarily. A privacy notice does not reduce rights that applicable law makes non-waivable.
14. Children
GANTIÈRE is a general-audience service for adults and is not directed to children. Interactive features require users to be at least 18. If GANTIÈRE learns that personal information was collected from a child in circumstances requiring parental authorization or deletion, it will take appropriate steps under applicable law.
15. International processing and transfers
GANTIÈRE is being prepared from the United States and may use providers in multiple jurisdictions. If EEA, UK, or other international transfer rules apply to a launch market, GANTIÈRE must use an applicable transfer mechanism or other lawful basis and provide required notices. Localized preview availability does not by itself mark international transactional launch readiness.
16. Changes to this notice
GANTIÈRE may update this notice as the service changes. Materially broader uses of previously collected personal information will not be introduced silently where applicable law requires additional notice or consent. The current version and effective date will be published with the final notice.
17. Contact
A monitored privacy-request method must be verified before public launch. The release gate remains closed until that workflow exists.
Launch facts still required
The release gate still requires verified provider behavior, category-specific retention and deletion, a working privacy-rights process, the real operator identity, monitored contact, effective date, and content-bound approval evidence. No external-attorney signature is required by the release policy.
