Privacy Policy
Last updated: 4 July 2026
The Gallery OS is software for art galleries. This policy explains what personal data we handle, why, and the rights you have. It reflects how the product actually works; it is a first version and will be refined.
Who we are and our two roles
The Gallery OS is operated by Galleri Golsa AS (Norwegian organisation number 920255353), Henrik Ibsens gate 60, 0255 Oslo, Norway ("we", "us"). Governing law is Norway.
We act in two different roles. For your account, our waitlist, and analytics about how our own site is used, we are the data controller. For the information a gallery enters into the product about its own contacts, artists, and collectors, the gallery is the controller and we act only as its processor, on its documented instructions.
What we collect
As controller: account details (your name and email, via Supabase authentication and, if you use it, Google sign-in), any email you submit to our waitlist, first-party analytics about product usage and content views, an essential session cookie, and security and support records.
As processor, on the gallery's behalf: the data a gallery chooses to store - contacts and their names, emails, phone numbers, interests, budget ceilings, purchase history, notes and interaction history; artworks and images; the content of a connected Gmail account; and uploaded documents.
How we use it and our legal basis
We use controller data to provide and operate the service, to power AI features, for security, and for support. We do not sell personal data and we do not run advertising or ad-tech.
Our legal bases (for data where we are the controller): providing the service and your account - performance of a contract; the waitlist and Google sign-in - your consent; first-party usage analytics, security logs, and support - our legitimate interest in running and improving the service. When a gallery connects a Gmail account, the email content that is synced is gallery data we process on the gallery's behalf, and the gallery sets the legal basis for it.
For data a gallery enters, the gallery decides the purpose and legal basis; we process it only to run the service for that gallery.
AI processing and automated decisions
To deliver features, some content - for example contact, artwork, or email data - is processed by Anthropic (chat, vision, extraction, and summaries) and OpenAI (text embeddings for search). This processing exists to provide the service.
AI-assisted scoring and prioritisation are assistive only. We do not make solely automated decisions that produce legal or similarly significant effects: a person reviews before any message is sent or any financial action is taken, and this is enforced by the system. Where a gallery uses these features on its contacts, the gallery remains the controller; a data subject can object and ask for human review through the gallery.
Sub-processors
We use a small number of trusted providers to run the service. We list them so you know who processes data on our behalf and update the list as it changes.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, and backend functions | EU (Ireland) |
| Anthropic | AI features: chat, vision, extraction, and summaries | US |
| OpenAI | AI features: text embeddings for semantic search | US |
| Resend | Transactional and outbound email delivery | US |
| Vercel | Application hosting and content delivery | US |
| Sign-in and, if you connect it, Gmail integration | EU / US |
Cookies and tracking
We use a strictly-necessary session cookie to keep you signed in, and first-party analytics stored in our own database (with a per-gallery on/off setting) to understand how content is viewed. We do not use third-party advertising or tracking cookies.
Our public-page analytics is cookieless and stores no identifier on your device. IP addresses are minimised — stored as a salted, irreversible hash where possible, and otherwise kept only briefly to resolve approximate location and filter internal traffic, never exposed or used to identify you. On public pages a short notice lets visitors decline analytics, and you can object at any time. We rely on legitimate interest for this measurement and do not use it to build advertising profiles or track you across other sites.
International transfers
Your data is stored in the European Economic Area: our database, authentication, and file storage run in the EU (Ireland) via Supabase. Some processing still involves providers in the United States - AI features (Anthropic, OpenAI), email delivery (Resend), and application hosting (Vercel). For those transfers we rely on the European Commission Standard Contractual Clauses; Google LLC is additionally certified under the EU-US Data Privacy Framework. Contact us for the safeguards that apply to a particular provider.
Data breaches
As controller, we will notify the Norwegian Data Protection Authority (Datatilsynet) within 72 hours where a breach requires it, and affected individuals where the risk to them is high. As processor, we will notify the affected gallery without undue delay after becoming aware of a breach.
How long we keep data
We keep personal data only for as long as it is needed for the purpose it was collected, or as the law requires. Waitlist email is kept until launch or until you unsubscribe. Account and gallery data is kept while the account is active and is deleted or returned when the account is closed. You can ask us to delete your personal data at any time (see "Your rights" below).
Our first-party visitor analytics have fixed maximum retention periods, enforced automatically: public link & page views — 30 days; press kit views & downloads — 90 days; website analytics — 12 months; consent choices — 24 months. After these periods the underlying records are deleted; only anonymous aggregates may remain.
Your rights
You have the rights to access, correct, delete, port, restrict, and object to processing of your personal data, and to withdraw consent where we rely on it.
Gallery staff exercise these rights directly with us. If you are a collector or contact whose data a gallery holds, exercise your rights with that gallery, which is the controller. If you contact us directly, we will determine whether the request concerns data we control or data a gallery controls, and either handle it or pass it to the gallery and assist as its processor.
Contact and supervisory authority
For privacy questions or to exercise your rights, contact us at privacy@thegalleryos.com.
You may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet). We have assessed that we are not currently required to appoint a Data Protection Officer, and we keep this under review as the product grows; use the privacy contact above for any data-protection question. As an entity established in the EEA, we do not require an EU representative.