1. Who controls your personal data?
Artpraisal is operated by MONDOIR L.L.C-FZ, Meydan Free Zone, Dubai, United Arab Emirates. For this notice, “Artpraisal”, “we”, “us” and “our” refer to that legal entity.
Questions and privacy requests may be sent to legal@mondoir.com. Do not use the public appraisal request form for privacy-rights requests.
2. What does this notice cover?
This notice covers the public Artpraisal website, appraisal inquiries, client authentication, private project portals, communications and records created during an appraisal engagement. It does not cover third-party websites linked from Artpraisal or information a third party controls independently.
3. What personal data do we collect?
Website inquiries
We collect your name, email address, optional telephone number and organisation, approximate client and artwork locations, the appraisal purpose and scope, expected timing, service preference, and a short property description. The submission is delivered to us as an email notification; the public form does not create a database record.
Accounts and client portals
When portal access is enabled, we process your email address, account and project identifiers, authentication and session records, access status, portal activity and files or records made available within the project.
Appraisal engagements and workfiles
If an engagement begins, we may collect client and intended-user details, ownership or representative information, property descriptions, photographs, provenance and condition records, correspondence, inspection notes, market evidence, valuation analyses, reports, signatures, instructions and other material needed for the agreed assignment.
Technical, security and communications data
We process IP addresses, request and event times, device or browser information made available through standard web requests, security events, audit records, email delivery status and correspondence. Security logs use identifiers and redact authentication secrets and cookie values.
Billing records
Where fees apply, we may retain proposals, invoices, payment status and accounting records. Artpraisal does not currently collect card details through this website. Do not submit payment information through the public request form.
Information from other sources
We may receive information from a person instructing us, authorised representatives, advisers, insurers, auction houses, dealers, public registers, market databases and public web sources where relevant to an assignment.
4. What should you not submit through the public form?
Do not submit identity documents, financial account details, payment-card information, portal codes, photographs, document links, detailed provenance records or special-category personal data through the public request form. If supporting material is needed, we will provide an appropriate channel.
5. How and why do we use personal data?
We use personal data to:
- review inquiries, respond and decide whether we can accept an assignment;
- prepare proposals, establish and perform appraisal engagements;
- identify property, intended users, intended use, value type and effective date;
- conduct research, inspections, analysis, quality review and report production;
- operate authentication, portals, exports, communications and client support;
- protect accounts, investigate misuse, maintain audit trails and secure the service;
- administer invoicing, record keeping, professional obligations and legal claims; and
- improve service reliability and correct errors.
Depending on the circumstances and applicable law, processing is based on your consent, steps requested before entering an engagement, performance of an engagement, compliance with legal or professional obligations, and our legitimate interests in providing, securing and administering the service. You may withdraw consent where consent is the basis, without affecting earlier lawful processing.
6. How are AI-assisted tools used?
Every active AI flow can receive project, appraisal or personal information. The business owner has authorized the currently declared flows under the applicable provider account terms. The application still limits each request to its declared flow, recipient, canonical HTTPS endpoint and data boundary, and blocks specified credentials, authentication material, payment data and identifiers.
Proposal drafting
Authorised personnel may use an operator-configured OpenAI-compatible service for proposal intake and to suggest proposal or rejection wording. During Copilot intake, the service may receive conversation-supplied client name, email address, telephone number, property location and assignment request. During drafting, it may receive an allowlisted inquiry snapshot containing the appraisal purpose, property description and scope, item count, property location, preferred currency, deadline, inspection preference, report format, intended users and, where present in the client-facing draft, the client name. It also receives the current editable proposal draft or rejection wording. The owner has authorized this declared transfer under the applicable provider terms; the typed flow, recipient, HTTPS endpoint and prohibited-data controls remain mandatory.
The proposal workflow excludes bank and card instructions, files, photographs, internal notes, comparables, methodology weights, margins, credentials, and authentication, session or audit data. Raw prompts and provider output are not stored by Artpraisal. A suggestion has no effect unless an authorised person reviews, applies and saves it; the provider does not accept an engagement or make an appraisal decision.
Admin writing support
For selected registered appraisal and workfile fields, an authorised administrator may ask the same provider to improve an administrator-supplied draft. The provider receives the field label, field-specific standards guidance and the current draft, limited to 4,000 characters. This tool can operate on text that forms part of an appraisal record.
Administrators are instructed not to enter credentials, authentication or session data, contact details, bank or payment information, uploads, photographs or unrelated project information into this tool. The service checks that the field is registered and limits the draft length, but it does not automatically detect or remove personal or confidential information from the draft. The owner has authorized this declared transfer under the applicable provider terms. Raw prompts and output are not stored or logged by Artpraisal as assistant records. A suggestion remains unsaved until the administrator reviews it, chooses to apply it and submits the relevant form; it cannot create facts, evidence, values or professional conclusions on its own.
Private Admin Copilot
Authorised administrators may use a private, scoped Copilot for operational questions. For general questions, the administrator's raw text and retained thread messages stay inside Artpraisal. Server code reduces the current question to one fixed operational intent and sends only that intent, bounded status counts, internal record references and reviewed guidance to OpenAI. Direct chat attachments and images are rejected. Request content is not logged at that boundary.
Admin Copilot protected preparation
Finding review, human-finding preparation, typed capability extraction and report-narrative preparation can send a raw administrator instruction and a bounded confidential preparation packet to direct OpenAI only. A configured compatible endpoint is rejected for this flow. The business owner has authorized this declared transfer under the applicable provider terms. Before test overrides and provider dispatch, the application blocks detected secrets, credentials, authentication or session material, payment, bank or card data, and government identifiers. This is not a claim that all personal data is redacted.
Separately, an administrator may select verified catalogue photographs for one project item. The business owner has authorized those photographs to be sent independently to direct OpenAI and Google Gemini under the declared catalogue-observation flow. Only schema-validated visual observations are then sent to Anthropic for comparison; Anthropic receives no images. The workflow excludes direct chat uploads, document uploads, client contact fields, payment information, credentials and authentication records. Threads retain rendered messages, citations, uncertainty and privacy-minimised operational provenance, but not image payloads, hidden reasoning or unrestricted provider responses. Findings remain advisory and do not authenticate, attribute conclusively or value an item.
Personal-property visual observation
A catalogue workflow may send selected verified property photographs together with item class, dimensions and photograph labels to an operator-configured OpenAI-compatible service so it can propose an object description. Document scans, ownership papers, client contact details, appraisal values and other non-photograph uploads are excluded from that vision workflow.
Photographs can still reveal people, interiors, location clues or other personal information. Avoid including people or unrelated private material in property photographs. Structured observations and their input references are retained in the evidence ledger. The human appraiser reviews the proposed observation before use; the service does not attribute, authenticate or value an item.
Record reconciliation
An OpenAI-compatible service may compare recorded item class, material, stated maker, stated date or origin and condition with structured catalogue observations. The workflow selects no photographs, files, dedicated client or owner identity, contact or property-location fields, payment information, credentials, or authentication, session or audit records for this step. Item text is not automatically screened for personal or confidential information, so authorised personnel must keep those details out of item-description fields. Structured consistency verdicts and the compared evidence are retained in the evidence ledger. Deterministic controls turn unresolved conflicts into review flags; the service does not resolve them as facts.
Comparable review recommendations
An Anthropic service may receive bounded subject facts — title, stated maker and date, materials, dimensions, asset class, intended use, value type, effective date and existing catalogue or reconciliation evidence — together with candidate comparable descriptions, dates, venues, prices, premiums, transaction status, verification basis, sources and notes. The workflow selects no dedicated client, owner or representative identity or contact fields, property-location fields, files, photographs, payment information, credentials, or authentication, session or audit records. Comparable descriptions, sources and notes are supplied text and are not automatically screened for every form of personal or confidential information; authorised personnel must not place those details there.
The returned recommendations and input references are retained in the evidence ledger. They cannot accept or reject a comparable: a human appraiser must review the evidence and accept or reject each recommendation before methodology selection.
Web research
Anthropic cited web research: a subject packet may contain title, stated maker and date, materials, dimensions, asset class, intended use, value type, effective date and complete current catalogue or reconciliation evidence. Dedicated identity, contact and location fields, private files, uploaded images, payment information, credentials, and authentication, session or audit records are not selected, but supplied item and evidence text is not comprehensively screened and may be confidential. The owner has authorized this declared confidential transfer under the applicable provider terms. Bounded cited excerpts, source details, claims and input references are retained in the evidence ledger.
Perplexity research briefs: an authorised appraiser may prepare an object class, title, stated artist or maker, materials, stated date, dimensions, an appraiser-written research question and approved public-source guidance. Dedicated client or owner identity, contact, property-location, document, image, appraisal-value, report, account and payment fields are not selected. However, the selected item fields and question are supplied text; the sensitive-pattern screen is incomplete and cannot prove that they contain no confidential information. The owner has authorized this declared confidential transfer under the applicable provider terms. Bounded summaries, source metadata, model and usage records are retained with the project research brief.
Web content and research output are treated as untrusted reference material. Neither service authenticates property or supplies a verified conclusion; a human appraiser must review sources before relying on the material.
Report semantic quality review
An OpenAI-compatible service may receive a minimized quality-review packet containing report kind and date, value amount and currency, assignment categories, bounded approach and comparable fields, transfer records, disclosure-presence indicators, research record dates and deterministic checklist states. The packet excludes client and owner identity and contact details, signer email, raw images, external-source text, credentials, and free-form report assertions. The review packet, bounded findings, provider/model identity and usage are retained in report quality-review records.
This advisory review can identify inconsistencies and prevent release until required review steps pass. It cannot edit, sign or publish a report, change a value or invent evidence. Manual determinations and the signing appraiser's professional judgment remain required.
Human responsibility and provider retention: the human appraiser remains responsible for evidence, professional judgment and every final report. Artpraisal does not accept AI output as fact without review. The application retains only the records described above, but AI providers may keep request, response, safety or service records under their own terms. Artpraisal does not control those provider-side periods, and deleting an Artpraisal record does not by itself promise immediate deletion of a provider-held copy.
7. Who receives personal data?
We do not sell personal data. We disclose it only as needed for the purposes above, including to:
- Replit and infrastructure providers for application hosting, databases, runtime services and private object storage;
- Google Cloud Storage infrastructure used through the application’s private storage service;
- Resend for transactional and service email delivery, including recipient addresses and the content needed to send inquiry receipts, operator notifications and access messages;
- OpenAI, or an owner-configured OpenAI-compatible HTTPS endpoint for authorised proposal drafting, admin writing support, private Admin Copilot questions and visual review, catalogue observation, record reconciliation and report semantic quality review, subject to the separate data boundaries in section 6;
- Anthropic for catalogue-observation comparison, cited public-web research and comparable review recommendations, subject to the separate data boundaries in section 6;
- Google Gemini for an independent catalogue-observation review of selected verified item photographs;
- Perplexity for owner-authorized web-research briefs containing selected project item fields and an appraiser-written question;
- professional advisers, researchers or specialists engaged for an assignment where appropriate and authorised;
- authorities, courts or counterparties where disclosure is required by law or necessary to establish, exercise or defend legal rights; and
- a successor to the business in a lawful reorganisation, merger or transfer, subject to appropriate confidentiality and data-protection measures.
Service providers are permitted to process data only for the relevant service, subject to their agreements and applicable law. Their own security, subprocessors and provider-side retention terms also apply; contact us if you need current provider information before supplying private material.
Transactional email necessarily sends the recipient address, subject line and message content to the email-delivery provider. Inquiry receipts contain the requester’s address and service information; operator notifications may contain the submitted contact details and property description. We do not intentionally include authentication secrets, payment-card details or bank instructions in those messages. Copies and delivery records may remain with the provider for the period set by its applicable retention terms.
9. Is personal data processed outside the UAE?
Current infrastructure, email, storage or technology providers may process data outside the UAE. We do not promise that every provider, subprocessor or backup is located in the UAE.
On 5 September 2026, we reviewed public retention, residency, subprocessor and DPA material for direct OpenAI, Google Gemini and Anthropic. Public documents describe some provider controls, but they did not prove this deployment's account tier, regional routing, operative contract or UAE PDPL transfer basis. We did not collect equivalent account-specific evidence for Perplexity. The business owner nevertheless authorized the currently declared provider transfers under the applicable account terms.
This notice does not claim that UAE counsel approved a particular transfer safeguard, that all processing occurs in the UAE, or that every evidence gap has been resolved. Provider terms and optional controls may change. Technical controls continue to restrict declared recipients, endpoints and prohibited data categories.
10. How long do we keep personal data?
- Public appraisal inquiries: copies in our recipient mailbox are normally reviewed for deletion 365 days after submission unless an engagement, legal obligation, dispute or proceeding requires longer retention. Resend may retain delivery records under its applicable terms.
- Appraisal workfiles and reports: ordinarily seven years under our UAE operational retention policy. This exceeds the five-year professional appraisal minimum and may be extended where an engagement, legal obligation, dispute or proceeding requires it.
- Portal and account records: while the portal or engagement is active and afterwards as needed for workfile, security, contractual and legal records. Archiving a portal does not automatically erase the underlying appraisal workfile.
- Session and security records: until expiry or revocation, and security or audit records for a proportionate period needed to investigate misuse and demonstrate accountability.
- Invoices and business records: for the period required by applicable accounting, tax and legal obligations.
We may retain a record longer when preservation is required for a legal claim, regulatory request, fraud prevention or an active deletion hold. When a record becomes eligible for deletion, the applicable administrative deletion or purge process must still run. Completion may depend on required workfile retention, linked records, active holds, backup cycles and provider-side retention terms; eligibility does not promise immediate or automatic erasure.
11. What rights do you have?
Subject to applicable law and relevant exemptions, you may ask us to confirm whether we process your data and request access, correction, erasure, restriction, objection or a portable copy. You may withdraw consent where processing relies on consent and may object to certain processing based on legitimate interests.
Send requests to legal@mondoir.com. Describe the request and the email or project concerned. We may verify your identity and authority before disclosing or changing records. Some information cannot be deleted immediately where retention is required by law, professional standards, an engagement or legal proceedings.
You may also raise a concern with the competent UAE data-protection authority where applicable. We encourage you to contact us first so we can review the issue.
12. How do we protect personal data?
We use access controls, one-time-code authentication, protected session cookies, private storage, encryption in transit, input validation, rate limiting, audit records and deletion controls designed to protect the service. No online system can be guaranteed completely secure. Keep access links and codes confidential and notify us promptly if you suspect unauthorised access.
13. Children
The website and appraisal services are intended for persons aged 18 or over. We do not knowingly solicit personal data from children. If you believe a child has provided data without appropriate authority, contact us so we can review and, where required, delete it.
14. Changes to this notice
We may update this notice when services, providers or legal requirements change. The effective date will identify the current version. Material changes will be communicated through the website or directly where appropriate.