The Lovenhall RegistryThe LovenhallRegistry
In Confidence

Privacy Notice

What we hold, why we hold it, and how to make it all go away.

Last updated 29 July 2026

1.Who is responsible

The Lovenhall Registry — a sole trader established in Istanbul, Türkiye — is the data controller for everything described here. Write to enquiries@thelovenhallregistry.com about anything on this page.

One exception: when you pay, Paddle is the seller and handles your payment as a controller in its own right, under its own privacy notice. We never receive your card details.

2.What we collect

Your account. Your email address, and — if you sign in with Google or Apple — the display name and profile picture that provider gives us. We also store the accession number issued to your register and the date it was opened. If you sign in with a password, that password is held by Google Firebase Authentication and is never visible to us.

What you put in the vault. The details you type about a piece (what you call it, its maker, its year, your notes) and the files you upload — photographs, invoices, certificates and any other papers.

Records you buy. The reading produced for a piece, its accession number, and a copy of the photographs and details as they stood when you bought it. The copy is deliberate: a record has to still mean something years later, after you have tidied your vault.

Technical data. Ordinary server and security information — approximate location, device and browser details, and the signals Google reCAPTCHA and Firebase App Check use to tell a real browser from an automated one.

Measurement, only if you agree. If you accept the banner, Google Analytics records how the site is used and whether the visitor is a member. Decline it and nothing is loaded and nothing is recorded. You are never asked again in that session.

3.The vault is not read

Nobody at the house looks at what is in your vault, and no automated reading is performed on it, unless and until you buy a record for that particular piece. Keeping something here is not submitting it to us.

This is enforced rather than promised: the security rules permit only your own signed-in account to read your vault and your files, and the reading process runs only when a purchase creates a record.

4.Why we hold it, and on what basis

  • To provide the service — keeping your vault, issuing records, showing you your own things. Basis: performance of our contract with you.
  • To take payment and meet tax and accounting duties — through Paddle. Basis: contract, and legal obligation.
  • To keep the service secure — preventing abuse, fraud and automated attack. Basis: our legitimate interest in a service that is not being attacked.
  • To understand how the site is used — analytics. Basis: your consent, which you may withdraw.
  • To answer you when you write to us. Basis: legitimate interest in replying to correspondence.

We do not sell your data. We do not share it for advertising. We do not profile you to make decisions about you.

5.Artificial intelligence, and what it is shown

When — and only when — you buy a record, the photographs of that piece and the details you entered about it are sent to Google’s Vertex AI service, which runs the Gemini model that produces the reading. The reading comes back, is written to your record, and that is the end of the exchange.

Under Google’s Vertex AI terms, content sent this way is not used to train Google’s models and is not retained by Google to improve them. Documents you upload — invoices and certificates — are not sent; the reading is told they exist but is not shown their contents.

The reading is generated automatically. It is an opinion, not a decision about you, and it has no legal effect on you. Nothing about your account, your identity or your other pieces is sent with it.

6.Who else is involved

We keep the list of companies that touch your data as short as the service allows:

  • Google Cloud / Firebase — sign-in, the database, file storage, the functions that run the house, and the Vertex AI reading. Acting on our instructions, as our processor.
  • Paddle — the merchant of record. They take the payment and hold the billing relationship as their own controller.
  • Google Analytics — only with your consent.

We may also disclose data where the law requires it, or to establish or defend a legal claim. If the house is ever transferred to a new owner, your data may pass with it — and you would be told before it did.

7.Where your data is

The house is run from Istanbul, Türkiye, and the services above store and process data on Google’s infrastructure, which is located outside Türkiye — principally in the United States and the European Union. Transfers rely on the safeguards in Google’s and Paddle’s data-processing terms, including the European Commission’s standard contractual clauses where they apply.

8.How long we keep it

Your vault and your records are kept for as long as your register is open, because that is the point of them. We do not delete a piece because you have not looked at it.

When you close your register, we erase your profile, your vault, every file you uploaded from our storage, your records and your sign-in itself. This is not a flag set on a row that stays behind: the files are deleted from storage and the account is removed from the sign-in system. It is irreversible and we keep no copy.

Two things necessarily outlive that. Your accession number is retired rather than reused, so it is never issued to anyone else — but it no longer points to anything. And Paddle keeps the transaction record for as long as tax and accounting law requires them to, which is their obligation and not ours to waive.

9.Your rights

Under Turkish data protection law (KVKK) and, where it applies, the GDPR, you may ask us to confirm what we hold, to give you a copy, to correct it, to erase it, to restrict or object to how we use it, and to provide it in a portable form. Where we rely on consent, you may withdraw it at any time.

Most of these you can exercise yourself and immediately: everything in your vault can be edited or deleted from your account, and closing your register performs a complete erasure without asking us. For anything else, write to us and we will answer within thirty days.

If you are not satisfied with our answer, you may complain to the Turkish Personal Data Protection Authority (KVKK) or, if you are in the EU or UK, to your local supervisory authority.

10.Cookies and similar technology

The site sets what it needs to keep you signed in and to protect itself from automated abuse. Nothing for advertising is set at any point. Analytics is loaded only after you accept the banner; declining means it is never downloaded.

11.Security

Data is encrypted in transit and at rest. Access rules are enforced by the database and file storage themselves — not merely by the interface — so your vault is reachable only by your own signed-in account. Anything that could be abused, including issuing a record, runs on the server and is refused unless it is genuinely you asking. No system is perfectly secure, but this one is built so that a mistake in the interface does not become a leak.

12.If this changes

Everything above describes what the house collects today, in full. If we ever offer a service that needs something this notice does not cover, we will update it before that service opens and tell members of any material change. We will not quietly start collecting something new under a notice that does not mention it.

13.Children

The Registry is not intended for children, and we do not knowingly hold data about them. If you believe a child has opened a register, write to us and we will erase it.

Getting in touch

Write to enquiries@thelovenhallregistry.com for anything on this page — a question, a request about your data, or a refund. We answer every message ourselves.

The Lovenhall Registry is operated by a sole trader established in Türkiye. Full business particulars, including the proprietor's name and registered address, are provided on request to any customer, regulator or court that asks for them.

Make an enquiry →