Stemma

Terms

Privacy notice

STEMMA ART (PTY) LTD

Last updated: 26 September 2026

Applies to stemma.art, the waitlist, and the Stemma service as it is made available.

This notice tells you what personal information we collect, why, who receives it, and what you can ask us to do. It is the notice required by section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA). If you are in the European Economic Area or the United Kingdom, the GDPR section at the end also applies to you.

This is a draft for publication. A lawyer should review it before it is relied on. Two facts the Acts ask for are not on file yet: our registered office address, and our company registration number. Until those are inserted below, contact us at studio@stemma.art.

1. Who we are

The responsible party is STEMMA ART (PTY) LTD ("Stemma", "we").

Legal statusPrivate company, Republic of South Africa
Websitehttps://stemma.art
Emailstudio@stemma.art
Registered officeNot yet published. It will be added here before we take a paid order.
Registration numberNot published. We will not invent one.
Information OfficerThe head of the company, contacted at studio@stemma.art. Registration with the Information Regulator is still required under section 55 of POPIA.

We do not publish a personal name, a street address, or a city on this notice until the company chooses to add the registered office.

2. What this notice covers

It covers:

  • the public site and the waitlist
  • an account, when accounts open
  • identity checks for people who ask to issue certificates
  • certificates, the registry, collection files, and custody or checkout tools, as each of those is offered

It does not cover a gallery, insurer, or shipper who keeps their own records. Their notice applies to them.

3. The information we collect

You give us

  • Waitlist: your email address, and your name if you give it.
  • Account: name, email, phone number, and the sign-in method (a passkey or a one-time code). We do not store a password you type if you use a passkey.
  • Artist profile: the public name you want on a certificate, and links or letters you offer so we can tell similar names apart.
  • Work records: title, year, medium, dimensions, photos, condition notes, and values you type for your own inventory or insurance export.
  • Certificate: the signed record, the tag identifier, and a hash of a surface check. Not a picture of your identity document.
  • Custody, when that tool is offered: who has the work, the dates, and the purpose you and the other party agree.
  • Support mail you send to studio@stemma.art.

A vendor collects, and we receive only the result

If you ask to be allowed to issue a certificate, an identity-check vendor (currently Didit) collects the government identity document, a liveness check, and a face match. That vendor also sees device and network data needed for the check.

We receive the outcome: pass or fail, the verification tier, the date, and the public artist name. We do not keep the passport image, the identity number, or the selfie in our database. Those stay in the vendor's vault.

We generate

  • A public key and a decentralised identifier for the signing key. The private key stays on your device.
  • Hashes of the signed certificate and of the identity credential.
  • Log data: time, the action, and a security log if a sign-in fails.

We do not collect for this product

  • We do not ask for a home address on a public record.
  • We do not put identity images, identity numbers, insurance values, or private notes on the registry.
  • We do not send identity documents or passport numbers to an AI tool. If we use a model to read a work note or a public name, the input is the redacted text, not the identity file.

4. Where it comes from

Most of it comes from you. The identity-check result comes from the vendor. A gallery or estate may send us a letter that you, or they, asked us to use to show authority to sign. We do not buy marketing lists.

5. Why we use it

InformationPurposePOPIA condition
Waitlist emailTo write to you about opening the service, and nothing else, unless you agree to moreConsent (section 11(1)(a)), and section 69 for electronic mail
Account and passkeyTo sign you in and to keep the account yoursContract, or steps you ask for before a contract
Identity check and tierSo a certificate is not issued under a name we have not checkedConsent for the check. The check is voluntary. Without it you can keep an inventory record, not a certificate of authenticity
Legal name, kept privateTo bind the checked person to the public artist nameConsent, and our legitimate interest in stopping a false issuer
Work, photos, valuesTo make the record, the collection file, and an insurance export you asked forContract
Public artist name, certificate hash, custody events you publishTo run the registry you asked us to publishContract, and your request to publish
Security logsTo protect accounts and the registryLegitimate interest, and a legal duty if a law later requires a record
Support mailTo answer youContract or legitimate interest

Giving information is voluntary. If you do not join the waitlist, we simply do not write to you. If you do not complete an identity check, we will not let that account issue a certificate of authenticity. No law requires you to use Stemma. If a later sale through the service makes us an accountable institution under the Financial Intelligence Centre Act, we will tell you which identity details that Act then requires, before we collect them.

6. Special personal information

Biometric information is special personal information under section 26 of POPIA. A liveness check and a face match are biometric. We do not run that check ourselves. The vendor does, and only if you consent and ask to be checked. You can refuse. The consequence is that the account stays unverified and cannot issue a certificate of authenticity.

We do not process information about children. You must be 18 or older to have an account.

7. Who receives it

RecipientWhat they getWhy
Identity-check vendor (currently Didit)The document, liveness capture, and face matchTo perform the check you asked for. They are an operator for that check.
Hosting and email providersThe data needed to run the site, store the private file, and send mailTo provide the service
A person you chooseA certificate, a custody offer, or an insurance exportBecause you sent it or published it
The public registryHashes, the public artist name, the certificate identifier, and custody events the parties agreed to publishBecause you asked for a record that outlives a private server
A professional adviser, insurer, or authorityOnly what the law, a court, or your instruction requiresLegal duty or your request

We do not sell personal information.

The public certificate shows the display name, the verification tier, and the date. It does not show the identity number or the document image.

8. Transfers out of South Africa

The identity vendor, and some hosting or email systems, process information outside South Africa. Section 72 of POPIA allows that when the recipient is bound by a contract, binding corporate rules, or a law that gives a comparable level of protection, or when you consent. We use a written operator contract for the identity check and for hosts who store personal information. We do not claim that every country we touch has been declared adequate. The identity images stay in the vendor's vault, not on the registry.

If you are in the European Economic Area or the United Kingdom, we use the same contracts, and standard contractual clauses where the GDPR requires them.

9. The public record, and what we cannot pull back

A certificate is meant to stay checkable. If you ask us to publish one, we publish the hash, the public name, and the events you chose. An independent public timestamp of that hash can be checked without us.

If you later ask us to delete your account:

  • we delete the private file we still hold (drafts, messages, unpublished notes, the private legal name)
  • we can mark a certificate revoked, so new reliance on a dead key fails
  • we cannot promise to erase a hash that has already been timestamped outside our servers, or a copy a collector already downloaded

That limit is why the publish step is a separate, explicit act, not a side effect of opening an account.

10. How long we keep it

RecordPeriod
Waitlist emailUntil you unsubscribe, then deleted within 30 days, unless a law requires a short suppression record so we do not mail you again
AccountFor the life of the account, then up to 24 months for disputes and security, unless a longer legal period applies
Identity-check imagesHeld by the vendor under its retention rules, not by us. We keep the pass or fail, the tier, and the date for as long as the issuing key is in use, and for a limited period after revocation so the historical badge stays explainable
Private collection fileUntil you delete it or close the account, subject to the dispute period above
Published certificate hash and public eventsKept, because that is the record you asked us to make. Revocation is a new event. It does not pretend the old signature never existed
Security logsUp to 24 months

11. Security

We use access control on the private database, encryption in transit, and a signing key that stays on your device. Identity images are not written into our database. No method is perfect. If a compromise of personal information creates a risk you should know about, we will tell you and, where POPIA section 22 requires it, the Information Regulator.

12. Direct marketing

We send the waitlist mail only if you asked to join. Each message has a way to stop. We do not send unrelated electronic marketing without a fresh consent, except the narrow case in section 69 of POPIA for a similar product to an existing customer, and even then you can opt out.

13. Cookies

The public site does not set advertising or analytics cookies. If we add any that are not strictly necessary, we will ask first where the law requires consent. When accounts open, a sign-in session cookie (or an equivalent) is necessary to keep you signed in. It is not used to advertise.

A separate cookie policy is not needed while that remains true.

14. Your rights

You may ask us to:

  • confirm whether we hold personal information about you, and for access to it (POPIA section 23, and PAIA where it applies)
  • correct it (section 24)
  • delete or destroy it where the Act allows, subject to section 9 of this notice
  • object to processing based on our legitimate interest (section 11(3))
  • withdraw consent, which stops future processing that relied only on consent, and does not undo a certificate you already asked us to publish
  • stop direct marketing

Write to studio@stemma.art. We may need enough detail to find the record and to confirm it is yours. We respond within a reasonable time, and we will tell you if a law requires us to refuse.

A PAIA manual under section 51 of the Promotion of Access to Information Act 2 of 2000 is a separate document. It is not published yet. Until it is, an access request to studio@stemma.art is still valid, and a refusal can be taken to the Information Regulator.

15. Complaints

Contact us first at studio@stemma.art. You may also complain to the Information Regulator:

POPIA complaintsPOPIAComplaints@inforegulator.org.za
PAIA complaintsPAIAComplaints@inforegulator.org.za
Generalenquiries@inforegulator.org.za, 010 023 5200, toll free 0800 017 160
OfficeWoodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Sitehttps://inforegulator.org.za

Use the Regulator's form 5 for a formal complaint.

16. European Economic Area and United Kingdom

If the GDPR or UK GDPR applies to you, the same sections describe the data, the purposes, and the recipients. Our lawful bases are consent, contract, legitimate interests (security and telling similar names apart), and a legal obligation if one arises. You also have the right to lodge a complaint with your local supervisory authority, and the right to data portability for information you gave us and that we process by automated means on the basis of consent or contract. We do not use solely automated decisions to refuse an identity check. The vendor performs the check. A namesake or a famous name is reviewed by a person.

17. California

We do not sell personal information, and we do not share it for cross-context behavioural advertising. If you are a California resident you may ask for the categories we collected, the sources, the purpose, and the categories of recipients, and you may ask us to delete what we hold, subject to section 9.

18. Changes

If we change this notice, we will change the date at the top. If a change is material and we have your email, we will tell you. The version on stemma.art is the current one.

19. Contact

STEMMA ART (PTY) LTD

studio@stemma.art

https://stemma.art

Stemma
studio@stemma.artPrivacyTerms