YieldSPM ← Back to home

Privacy Policy — Atteste

Yield SPM (Pty) Ltd · Version 1.0 · April 2026

This Privacy Policy explains how Yield SPM (Pty) Ltd ("we", "us", "Yield SPM") collects, uses, stores, and protects your personal information when you use the Atteste art collection management platform ("the Service").

This policy is drafted in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Promotion of Access to Information Act 2 of 2000 ("PAIA"), and the Electronic Communications and Transactions Act 25 of 2002 ("ECTA"). Where the Service is provided to consumers as defined by the Consumer Protection Act 68 of 2008 ("CPA"), the relevant provisions of that Act also apply.

1. Information Officer

NameLindie le Roux
DeputyKarel le Roux
Emailprivacy@practacular.com
Address23 Kameeldoringdraai, Woodland Hills, Bloemfontein, Free State, 9301

2. What Personal Information We Collect

2.1 Information You Provide Directly

CategoryExamplesPurpose
Account informationName, email address, password (hashed)Account creation and authentication
Profile preferencesDisplay name, subscription tier, notification settingsService personalisation
Artwork dataTitle, artist name, medium, dimensions, valuation, purchase date, provenance notesCore cataloguing functionality
ImagesPhotographs of artworks, certificates, documentsAI analysis, cataloguing, certificates of authenticity
Voice recordingsAudio narrations, art stories, memoirsTranscription and voice synthesis features
Written contentArt encounter notes, living letters, collection memoirsJournaling and AI enrichment
Estate designationsHeir names, contact details, relationships, estate instructionsLegacy and estate vault features
Gallery partner detailsBusiness name, contact person, email, subscription detailsGallery partnership management

2.2 Information Collected Automatically

CategoryExamplesPurpose
Location data (GPS)Coordinates logged during art encountersEncounter mapping and provenance
Device informationDevice type, operating system, app versionService delivery and debugging
Usage dataFeatures accessed, session duration, error logsService improvement
Audit trail dataTimestamps, actions performed, SHA-256 integrity hashesData integrity and provenance verification

2.3 Information Generated by AI Processing

CategorySourcePurpose
AI vision analysisArtwork images processed by Google GeminiStyle identification, condition assessment, valuation assistance
AI text enrichmentWritten content processed by Anthropic ClaudeArtist research, provenance enrichment, collection insights
Voice transcriptionsVoice recordings processed by Google Gemini STTConverting speech to searchable text
Synthesised voiceText processed by ElevenLabsCreating audio versions of stories and memoirs

2.4 Sensitive Information

We collect location data (GPS coordinates) when you use the encounter feature. Location data is considered personal information under POPIA and we process it only with your explicit consent.

We do not collect special personal information as defined in Section 26 of POPIA (race, ethnicity, religion, political affiliation, health, sex life, biometric data, criminal history, trade union membership).

3. How We Use Your Personal Information

PurposeLawful BasisPOPIA Section
To create and manage your accountContract performanceSection 11(1)(b)
To provide art cataloguing, provenance, and certificate featuresContract performanceSection 11(1)(b)
To process AI vision analysis of artwork imagesConsentSection 11(1)(a)
To process AI text enrichment of your written contentConsentSection 11(1)(a)
To transcribe voice recordings via AI speech-to-textConsentSection 11(1)(a)
To synthesise voice via ElevenLabsConsentSection 11(1)(a)
To record GPS location during encountersConsentSection 11(1)(a)
To generate anonymised gallery analyticsLegitimate interestSection 11(1)(f)
To process subscription paymentsContract performanceSection 11(1)(b)
To send service-critical notificationsLegitimate interestSection 11(1)(f)
To maintain audit trails and data integrityLegal obligation (ECTA s16) / legitimate interestSection 11(1)(c) and (f)
To detect and respond to security incidentsLegitimate interestSection 11(1)(f)
To comply with tax and company law obligationsLegal obligationSection 11(1)(c)

We do not use your personal information for direct marketing without separate, explicit consent as required by POPIA Section 69.

4. AI Processing Disclosure

This is a material aspect of how Atteste works. We disclose it in accordance with POPIA Condition 6 (Openness).

4.1 AI Providers

ProviderServiceWhat Is SentJurisdiction
Google LLC (Gemini 2.0 Flash)Vision analysis of artworks; text generation; speech-to-text transcriptionArtwork images, text queries, voice audioUnited States
Anthropic, PBC (Claude)Text enrichment, artist research, collection summaries, memoir generationText content, artwork metadataUnited States
ElevenLabs, Inc.Text-to-speech voice synthesisText content for audio renderingUnited States / EU

4.2 What This Means in Practice

When you use Atteste's AI features:

  • Photographing an artwork for AI analysis sends the image to Google Gemini for processing
  • Asking for artist research or collection insights sends text to Anthropic Claude
  • Recording a voice story sends audio to Google Gemini for transcription
  • Generating a voice memoir sends text to ElevenLabs for speech synthesis

The AI providers process this data to generate responses and return them to Atteste. They do not use your data for their own model training under their commercial API terms.

4.3 Data Minimisation

In accordance with POPIA Condition 3 (Purpose Limitation), we send only the information necessary for each AI interaction. We do not send your full collection or personal details for purposes unrelated to the specific feature you are using.

4.4 Your Control

You may choose not to use AI features. Core cataloguing, manual provenance recording, and basic collection management work without AI processing. If you withdraw consent for AI processing, these features will be disabled for your account, but your existing data will be retained.

5. Location Data

Atteste collects GPS coordinates when you use the Encounter feature (recording where you saw, acquired, or exhibited an artwork).

AspectDetail
When collectedOnly when you actively create an encounter
PrecisionStandard GPS accuracy (typically 3-10 metres)
PurposeMapping your art journey; provenance evidence
StorageStored with the encounter record in Firestore (africa-south1)
ConsentExplicit consent required; device location permission must be granted
WithdrawalYou can disable location permission at any time via device settings; existing encounter locations are retained unless you request deletion

6. Voice Data

Atteste allows you to record voice stories and have them transcribed and synthesised.

AspectDetail
What is recordedAudio narrations you voluntarily create
ProcessingAudio sent to Google Gemini (STT); text sent to ElevenLabs (TTS)
StorageAudio files stored in Firebase Storage (africa-south1); transcripts in Firestore
ConsentExplicit consent for voice recording and AI processing required
RetentionDuration of your account; deleted with account closure
Cross-borderAudio crosses to USA for AI processing; not permanently stored outside SA

7. Estate and Legacy Features

Atteste's Legacy Vault allows you to designate heirs and create estate instructions.

AspectDetail
Heir informationName, contact details, relationship — provided by you
AccessHeirs cannot access your collection during your lifetime without your explicit authorisation
ConsentYou are responsible for ensuring you have the right to provide heir personal information
RetentionEstate designations are retained for 5 years beyond last update, or until estate administration is confirmed complete
Audit trailAll estate access events are logged with SHA-256 integrity hashes

8. Gallery Partner Analytics

If you visit galleries that partner with Atteste, anonymised analytics may be generated.

AspectDetail
What is sharedAggregated, anonymised visitor counts, dwell time, artwork engagement
Not sharedYour name, identity, or individually identifiable information
Legal basisPOPIA Section 6(1)(c) — anonymised data is excluded from POPIA's scope
Opt-outYou may disable gallery analytics in your profile settings

9. Cross-Border Transfers

Your personal information may be transferred outside South Africa as described in Section 4. These transfers are governed by Section 72 of POPIA.

Legal BasisPOPIA SectionApplication
ConsentSection 72(1)(b)You consent via the POPIA consent gate before first use
Contractual safeguardsSection 72(1)(a)AI providers are bound by DPAs with POPIA-equivalent protections

Data residency: Your data at rest is stored in Google Cloud's africa-south1 region (Johannesburg, South Africa). Cross-border transfers occur only for active AI processing; data is not permanently stored outside South Africa.

10. How We Protect Your Information

In accordance with POPIA Section 19, we maintain:

MeasureDetail
Encryption at restAES-256-GCM for sensitive fields
Encryption in transitTLS 1.2+ for all communications
Access controlFirebase Authentication; user-scoped Firestore rules (you can only access your own data)
Data integritySHA-256 hash chains for provenance records and certificates (ECTA Section 14 compliance)
Append-only audit logsProvenance and encounter records cannot be retrospectively altered
Data residencyFirestore and Firebase Storage in africa-south1 (Johannesburg)
Soft deletionDeleted records retained 30 days for recovery, then permanently purged
Consent versioningPolicy changes trigger automatic re-consent
Continuous reviewSecurity measures reviewed and updated per POPIA Section 19(2)

11. How Long We Keep Your Information

Data CategoryRetentionLegal Basis
Account informationAccount lifetime + 12 monthsPOPIA Section 14(1)
Artwork metadataAccount lifetime; export availablePOPIA Section 14(1)
AI processing artefacts90 daysLegitimate interest (debugging)
Voice recordings / transcriptsAccount lifetimePOPIA Section 14(1)
GPS encounter logsAccount lifetimePOPIA Section 14(1)
Certificates of authenticityAccount lifetime + 5 yearsECTA Section 16 (evidentiary value)
Estate designationsAccount lifetime + 5 years or until estate administration completePOPIA Section 14(1)
Anonymised gallery analytics2 yearsAnonymised; POPIA Section 6(1)(c)
Consent recordsAccount lifetime + 5 yearsPOPIA accountability
Billing / payment records5 years from financial year endIncome Tax Act Section 29; VAT Act Section 55(3)
Soft-deleted records30 daysOperational recovery

Full details are in our Data Retention Schedule.

12. Your Rights

RightPOPIA SectionHow to Exercise
AccessSection 23Email privacy@practacular.com
CorrectionSection 24Email privacy@practacular.com
DeletionSection 24Email or in-app account deletion
Object to processingSection 11(3)Email privacy@practacular.com
Withdraw consentSection 11(2)(b)In-app settings (disables AI/location/voice features)
Data portability—Request data export in JSON format
Restrict automated decisionsSection 71Email privacy@practacular.com
ComplainSection 74See Section 13 below

We respond to access requests within 30 days (PAIA Section 56).

13. Complaints

  1. Contact our Information Officer at privacy@practacular.com
  2. Lodge a complaint with the Information Regulator:
PostP.O. Box 31533, Braamfontein, Johannesburg, 2017
Emailcomplaints.IR@justice.gov.za
Tel(010) 023 5200
Webhttps://inforegulator.org.za

14. Children

Atteste is not directed at persons under 18. We do not knowingly collect personal information from children. If we learn we have collected such information without consent of a competent person (POPIA Section 35), we will delete it.

15. Cookies

The Atteste application uses only session cookies strictly necessary for authentication. No third-party tracking or analytics cookies are used.

16. Changes to This Policy

Material changes will be notified via the app or email. The consent version tracking mechanism will require you to re-accept the updated policy before continued use.

17. Governing Law

This policy is governed by the laws of the Republic of South Africa, including POPIA, PAIA, ECTA, and the CPA where applicable.

Yield SPM (Pty) Ltd | Reg 2024/185151/07 | privacy@practacular.com

© 2026 Yield SPM (Pty) Ltd · Reg 2024/185151/07
Home PAIA Manual Contact IO