Privacy Policy

Antiks - Data protection for antique dealers

Last updated: March 2026

Data Controller

Company: Company being incorporated
Address: Bourgogne, France
Email: contact@antiks.fr
DPO: Not appointed — contact contact@antiks.fr

What data we collect

Account data

  • Email address, bcrypt-hashed password, first name, last name
  • Phone number, postal address (street, city, postal code, country)
  • Company name, website, biography
  • Purpose: account management, authentication, billing, user profile
  • Legal basis: contract performance
  • Retention: duration of subscription + 3 months

Catalog data

  • Furniture listings: titles, descriptions, prices, dimensions, materials, condition, style, period, categories per marketplace
  • Photos stored on our servers, perceptual hashes (pHash) for duplicate detection
  • Templates, scraped furniture, variations, deleted furniture (trash)
  • Sale data: sale price, platform, date
  • Purpose: core service functionality
  • Legal basis: contract performance
  • Retention: duration of account + 30 days (trash: 90 days)

Marketplace credentials

  • Marketplace usernames stored in plaintext (required for login on behalf of the user)
  • Marketplace passwords encrypted with Fernet (AES-128-CBC + HMAC-SHA256)
  • IMAP email addresses stored in plaintext, IMAP passwords encrypted with Fernet
  • IMAP server details (hostname, port, SSL setting)
  • Purpose: publishing and 2FA management on behalf of the user
  • Legal basis: contract performance
  • Retention: until disconnection from the marketplace

AI-generated content

  • Product photos (transmitted to the Anthropic API as base64 JPEG images for visual analysis)
  • Text prompts containing product descriptions, dimensions, categories
  • Full AI responses (raw text)
  • Token consumption, cost, processing duration
  • User email address linked to each generation request
  • Purpose: content generation for product listings
  • Legal basis: contract performance
  • Retention: 12 months (photos are not stored by Anthropic)

Important: Product photos are transmitted to Anthropic's Claude API (USA) for visual analysis and content generation. Antiks uses the API tier that does not retain data for model training. Only catalog content is sent — no personal user data (name, address) is transmitted to Anthropic.

Publication data

  • Task history: status, errors, duration, logs, site name
  • Screenshots of marketplace pages during publish/remove operations (may incidentally capture data visible on marketplace pages)
  • Network request logs from publishing tasks
  • External listing IDs and published URLs
  • Purpose: service monitoring, debugging, proof of publication
  • Legal basis: legitimate interest
  • Retention: screenshots and network logs 90 days, task history 12 months

Police book data (third-party personal data)

The digital police book, required by French law (articles R.321-1 to R.321-8 of the Penal Code) for antique dealers, requires collection of personal data about third parties (sellers and buyers).

Third-party data collected:

  • Full name, date of birth, full address
  • Identity document type (national ID, passport, driving license, residence permit)
  • Identity document number, expiry date, issuing authority
  • For legal entities: company name, SIRET number, headquarters address, representative name and ID

Object data: nature, description, brand, model, serial number, distinctive signs, provenance, historical monument status, purchase price, estimated value, payment method.

This data is stored in an append-only, tamper-proof format (SHA-256 hash chain). It cannot be modified or deleted, in compliance with French law. An audit log tracks all access to the police book. Retention: minimum 6 years.

Billing data

  • User name, email, company information on invoices
  • Invoice numbers, amounts, VAT, billing periods
  • Purpose: legal accounting obligation
  • Legal basis: legal obligation
  • Retention: 10 years

Technical data

  • Activity logs: 15 action types (login, logout, create/edit/delete furniture, publish, unpublish, sell, AI generation, template, photo upload, profile update) with timestamps
  • IP addresses (collected in activity logs and cookie consent records)
  • User-Agent strings (collected in activity logs and cookie consent, truncated to 500 characters for consent)
  • Session cookie, CSRF token
  • Cookie consent records (choices, timestamp, policy version, anonymous UUID for non-authenticated visitors)
  • WebAuthn public keys (biometric authentication — no biometric data stored server-side)
  • WebAuthn challenges (temporary, 5-minute expiry)
  • Push notification subscriptions (browser endpoint URL, encryption keys)
  • Purpose: security, authentication, GDPR compliance
  • Legal basis: contract performance, legal obligation, consent (biometrics, push notifications)

Transactional emails sent

Email typeContentTrigger
Password resetTemporary reset linkUser request
Account invitationActivation linkAdmin creates account
Marketplace connection failure alertSite name, error typeConnection test failure (production only)
InvoicePDF attachment with invoice detailsInvoice issued
Incomplete AI generationGeneration detailsPartial AI generation failure

Emails are sent via SMTP (configurable server, TLS required). Recipient email addresses are used solely for sending and are not shared with third parties.

Third-party recipients

RecipientData sharedCountrySafeguards
Hosting provider (being finalized)All dataFranceDedicated server, data hosted in France
Anthropic (Claude API)Product photos (base64), descriptive text for AI generationUSAStandard contractual clauses, no training data retention
SMTP provider (being finalized)Recipient email addresses, email contentBeing finalizedTLS required
Marketplaces (16 platforms)Listings, photos, prices — transmitted on behalf of the userVarious (EU, USA, CH)Required for service, each platform has its own privacy policy
Browser push services (Google FCM, Apple APNs, Mozilla)Push endpoint, notification contentUSAInherent to Web Push standard (W3C)

Marketplace login credentials are never shared with third parties. They are used exclusively by Antiks servers to connect to platforms on behalf of the user.

Data security

  • Account passwords hashed with bcrypt
  • Marketplace passwords encrypted with Fernet (AES-128-CBC + HMAC-SHA256, key derived from environment variable)
  • Marketplace usernames stored in plaintext (required for login on behalf of the user)
  • IMAP passwords encrypted with Fernet (same method)
  • IMAP email addresses and server settings stored in plaintext (required for connection)
  • All communications encrypted via HTTPS
  • Strict per-user data isolation (each user can only access their own data)
  • Database with authentication and secure connection pooling
  • Police book with SHA-256 hash chain (guaranteed integrity, tamper-proof, append-only)
  • Password reset tokens are time-limited and deleted after use
  • WebAuthn biometric authentication: only public keys are stored server-side; no biometric data (fingerprints, face scans) ever leaves the user's device

Your rights (GDPR)

Under the GDPR (Articles 15-22), you have the right to:

Your GDPR rights:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten"), except where legal retention applies (invoices: 10 years, police book: 6 years)
  • Port your data in a structured format (JSON)
  • Object to processing based on legitimate interest
  • Restrict processing
  • Withdraw consent at any time for consent-based processing (push notifications, biometrics)

To exercise these rights: email contact@antiks.fr with proof of identity. Response within 30 days.

You may also lodge a complaint with the CNIL (French data protection authority, www.cnil.fr) or your local supervisory authority.

Third-party data rights (police book)

Individuals whose data is recorded in a user's police book have the same rights of access and rectification. However, in compliance with French law, police book data cannot be deleted (minimum 6-year legal retention). For any request, contact contact@antiks.fr.

Data transfers outside the EU

Data may be transferred outside the EU/EEA when:

  • Anthropic API (USA): product photos and text for AI generation — standard contractual clauses
  • International marketplaces (eBay USA, Etsy USA, Ricardo Switzerland, etc.): listings, photos, prices — necessary for service performance as requested by the user
  • Browser push services (Google, Apple, Mozilla — USA): notification endpoints — inherent to the Web Push standard

Changes to this policy

We may update this policy. Significant changes will be communicated by email. The last update date is indicated at the top of this page.

Etsy API Disclosure

Etsy API — Third-party application disclosure

Antiks uses the Etsy API to allow users to manage their Etsy listings from a centralized dashboard. By connecting your Etsy account to Antiks, you authorize Antiks to access and manage your Etsy shop data (listings, photos, descriptions, prices) on your behalf.

Data accessed via the Etsy API:

  • Shop and listing information (titles, descriptions, prices, photos, tags, categories)
  • Order and transaction data (for sales tracking purposes)

How we use this data:

  • To publish and manage listings on Etsy on behalf of the user
  • To synchronize listing status (active, sold, expired) with the Antiks dashboard
  • To display sales performance metrics

Data sharing: We do not sell, rent, or share your Etsy data with any third party. Your Etsy data is only used within the Antiks platform for the purposes described above.

Data retention: Your Etsy data is retained for the duration of your Antiks account + 30 days. You can disconnect your Etsy account at any time, which will remove the Etsy OAuth tokens from our system.

Revocation: You can revoke Antiks' access to your Etsy account at any time via your Etsy account settings (Etsy Security Settings) or from within the Antiks dashboard.

The term 'Etsy' is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.

Contact

For any questions regarding this policy or to exercise your rights:

Email: contact@antiks.fr
Back to homepage
Mentions légales CGU CGV Confidentialité (FR) Cookies