
Privacy
What personal information Okasen collects, why, what we do with it, and the rights you have over it — including how we handle information about artists compiled from public sources.
Last updated: [TO CONFIRM: date of publication] Effective: [TO CONFIRM: effective date]
This policy explains what personal information Okasen collects, why, what we do with it, and what you can require of us. It covers okasen.art, our newsletters and notifications, our Advisory and Ratings engagements, and the information we hold about artists, galleries and market participants.
We have tried to write it so that it actually describes what happens, including the parts that are easy to leave vague.
The controller of the personal data described here is Okasen Technologies Limited, registered in [TO CONFIRM: jurisdiction] under number [TO CONFIRM: company number], registered office [TO CONFIRM: registered address].
Contact us about privacy at [TO CONFIRM: privacy@okasen.art].
[TO CONFIRM: whether a Data Protection Officer is required and appointed. Under the Nigeria Data Protection Act 2023 a "data controller of major importance" must register with the NDPC and appoint a DPO; registration thresholds should be checked against current NDPC guidance. Under GDPR Art. 37 a DPO is required where core activities involve regular and systematic monitoring of data subjects on a large scale — the behavioural profiling described in section 3.2 is precisely that activity, so if EU/UK visitor volumes are material this needs a considered answer rather than a default no.]
[TO CONFIRM: whether an EU and/or UK representative is required under GDPR Art. 27. If Okasen has no EU/UK establishment but offers services to or monitors people there, one is mandatory and must be named here.]
Depending on where you are, your rights come from different statutes. We apply this policy to everyone, and where a law gives you more, that law applies:
When you submit a consultation request, contact message, newsletter signup, or unlock a gated download, we collect: your name, email address, and your message, and where the form asks for them, your company, country, city, collector profile (new or experienced), and the approximate size of your collection. We also record which page you submitted from and the marketing campaign you arrived through.
| Why | Lawful basis |
|---|---|
| To respond to your request and provide what you asked for | Performance of a contract, or steps taken at your request |
| To understand who is asking, so we route it to the right person | Legitimate interests — operating an advisory business |
| To send you marketing, where you asked for it | Consent |
Providing the profile fields is optional. You can leave them blank and we will still respond.
This is the part most privacy policies describe badly, so here it is plainly.
We issue your browser a visitor identifier — a random code in a cookie — and use it to record what you do on the Site: pages viewed, articles read, how far you scrolled, how long you stayed, which gated items you unlocked, which emails you opened or clicked, and where you came from.
We use that history to decide what to recommend to you on the page and, where you have opted in, what to send you.
And this is the part that matters: if you later submit any form, we link that browsing history to your name and email address. From that point the record is no longer anonymous — it is a profile of you, combining what you told us with everything we observed before and after.
| Why | Lawful basis |
|---|---|
| Recommending content, building the profile described above | Consent, given through our cookie banner |
| Basic security, load balancing, and keeping the site working | Legitimate interests |
We do not do this unless you consent, and you can withdraw consent at any time through [TO CONFIRM: cookie settings link] without losing access to anything. The Site works fully without it; you will simply see our latest published work rather than something selected for you.
We are in the process of enforcing this control end-to-end across every tracking mechanism on the Site. Until that work is complete, please treat section 12's cookie table as the authoritative statement of current practice, and write to us at the address in section 14 if you have a question about where a particular control stands.
We use [TO CONFIRM: Plausible only, or Plausible and Google Analytics 4 — this should be resolved in favour of Plausible alone, which is cookieless and removes the consent problem entirely] to understand aggregate Site usage.
Where we use a cookieless analytics service, no cookie is set and no individual is identified. Where we use Google Analytics, it sets cookies in your browser and shares data with Google; we load it only after you consent, and you can decline.
If you engage us, we collect what the engagement requires: contact and identification details, information about the works or collection concerned, and the records needed for anti-money-laundering and sanctions checks where those apply.
| Why | Lawful basis |
|---|---|
| Delivering the engagement | Performance of a contract |
| Identity, sanctions and AML checks | Legal obligation, and legitimate interests in preventing financial crime |
| Keeping records of advice given and decisions made | Legal obligation, and legitimate interests in defending claims |
Identification documents are held securely, access-restricted, and retained only for as long as the applicable regulations require.
Okasen maintains a database of artists, galleries and art-market transactions. For living artists this includes name, nationality, year of birth, media worked in, gallery representation, exhibition history, and records of works attributed to them and the prices those works achieved — which is personal data about them.
Where it comes from. Publicly accessible sources: auction results and catalogues, gallery rosters and exhibition listings, institutional and reference databases, and published biographical sources. Every record carries a citation to its source and the date we retrieved it. We also receive information directly from data partners under written agreement.
Why we process it. To compile and publish a market record for African art, to compute indices and valuations, and to produce research. Our lawful basis is legitimate interests: there is a genuine public and market interest in a reliable, transparent, publicly available record of this market, the information concerns individuals' public professional activity rather than their private life, and it is already published elsewhere. We have assessed the balance against artists' rights and keep that assessment under review.
Notifying artists individually. Because we collect this from public sources rather than from artists themselves, data protection law would ordinarily require us to notify each person. Given the number of artists in the database and the public nature of the sources, individual notification would involve disproportionate effort, and we rely on the exemption that applies in that case. As the law requires when relying on it, we make this information public instead — that is what this section is — and we operate the correction route below.
If you are an artist, gallery or estate and you want to see what we hold, correct it, or object to it, write to [TO CONFIRM: corrections@okasen.art]. We will respond within [TO CONFIRM: 30] days. We take corrections seriously: our numbers are only worth something if they are right.
If you message us on Instagram or another messaging platform, we process the conversation to respond to you, and we may record that you contacted us and what you asked about. The platform itself also processes your data under its own policy, which we do not control.
Where a conversation is handled with AI assistance, we tell you so in the conversation. Where it shows real advisory intent and you provide an email address, we may create an inquiry record as described in section 3.1.
We use automated systems, including AI models, to:
None of these produce a decision about you with legal or similarly significant effects. Content recommendations affect what you are shown, not any right or entitlement. Advisory proposals concerning a client's collection are reviewed and approved by a person before they reach the client.
You can object to profiling for recommendations at any time, by withdrawing consent under section 3.2 or by writing to us.
We send newsletters and notifications only to people who have opted in, and we record when and how you opted in.
Every email has a one-click unsubscribe. You can also set frequency or turn sends off by writing to us. Unsubscribing from marketing does not stop us replying to something you have actually asked us about.
We do not sell your personal data, and we do not share it for third-party marketing.
We do share it with service providers who process it on our instructions, under written contracts requiring confidentiality and security:
| Provider | Purpose | Location |
|---|---|---|
| [TO CONFIRM: Render] | Application and database hosting | [TO CONFIRM] |
| [TO CONFIRM: Resend] | Sending email and recording delivery, opens, clicks | [TO CONFIRM] |
| [TO CONFIRM: Plausible / Google] | Website analytics | [TO CONFIRM] |
| [TO CONFIRM: Anthropic] | AI model inference | [TO CONFIRM] |
| [TO CONFIRM: Meta] | Instagram messaging, where you use that channel | [TO CONFIRM] |
[TO CONFIRM: complete this table against the actual deployed stack and confirm a data processing agreement is in place with each. Confirm specifically whether any personal data is included in prompts sent to the AI provider — if it is, that needs a processing agreement and a line in this policy; if it is not, we should say so, because "we do not send your personal information to AI providers" is a meaningfully better statement than silence.]
We also disclose personal data where we are legally required to, to professional advisers under duty of confidence, and to a buyer or successor if the business is sold (in which case we will tell you).
Our providers operate in several countries, so your information may be processed outside the country you are in, including [TO CONFIRM: jurisdictions].
Where data leaves the EEA, the UK, Nigeria or South Africa, we rely on an appropriate safeguard: an adequacy decision where one exists, or Standard Contractual Clauses (with the UK Addendum where relevant) together with a transfer risk assessment. [TO CONFIRM: confirm per provider, and note NDPA s.41's requirements for transfers out of Nigeria and POPIA s.72's for transfers out of South Africa — these are not identical to the GDPR mechanism and need to be satisfied on their own terms.]
You can ask us for details of the safeguards for any particular transfer.
| Data | Retention |
|---|---|
| Inquiries and contact messages | [TO CONFIRM: e.g. 3 years from last contact] |
| Newsletter subscription and consent records | Until you unsubscribe, plus [TO CONFIRM: 2 years] to evidence consent |
| Visitor identifiers and behavioural events | [TO CONFIRM: e.g. 14 months from last activity] |
| Advisory and Ratings engagement records | [TO CONFIRM: 6-7 years after the engagement ends — align with limitation periods and any AML record-keeping obligation] |
| AML and identification records | [TO CONFIRM: 5 years after the relationship ends, where MLR 2017 or equivalent applies] |
| Artist, gallery and transaction records | Retained as part of the permanent market record, subject to correction and to objections we uphold |
[TO CONFIRM: these are placeholders reflecting conventional periods, and must be confirmed against actual business need before publication. A retention schedule that nobody implements is worse than none — it is a published commitment we would be breaching. Retention should be enforced by a scheduled job, not by intention.]
We protect personal data with access controls, encryption in transit, restricted administrative access, and audit logging of curator and administrative decisions.
Our internal review tools, where staff handle inquiry and account data, are access-restricted to authorized personnel only.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to you, we will notify the relevant regulator within the applicable deadline — 72 hours under GDPR/UK GDPR, and as required under NDPA and POPIA — and tell you directly where the risk is high.
Wherever you are, you can ask us to:
Write to [TO CONFIRM: privacy@okasen.art]. We will respond within one month — under POPIA and NDPA some requests have different timeframes, and we will apply whichever is shorter. We do not charge, and we will not ask you why.
If you are unhappy with our answer, tell us first and we will try to put it right. You can also complain to your regulator:
The Site is not directed at children and we do not knowingly collect their personal data. If you believe a child has given us information, tell us and we will delete it.
| Cookie | Purpose | Type | Consent needed |
|---|---|---|---|
visitor_id | The visitor identifier described in section 3.2 | Analytics / profiling | Yes |
okasen_unlocked | Remembers that you have already subscribed, so gated downloads stay open | Functional, set in response to your own action | No |
| Google Analytics cookies | Aggregate usage analytics | Analytics | Yes |
You can manage your choices at [TO CONFIRM: cookie settings link] and through your browser settings. Declining the analytics cookies does not restrict your access to anything.
We may update this policy. Where a change is material we will post a notice on the Site and, if we hold your email address and the change affects you, tell you directly. The "Last updated" date above always reflects the current version, and we keep prior versions.
Okasen Technologies Limited [TO CONFIRM: registered address] Privacy: [TO CONFIRM: privacy@okasen.art] Corrections to artist or market records: [TO CONFIRM: corrections@okasen.art] [TO CONFIRM: DPO and/or EU/UK representative details, if appointed]