Terms of Use Privacy Policy
1. About this policy
This is Arts Bound’s privacy policy and sets out our policies in relation to the data and information we collect and use from our visitors, customers and members. We keep your data confidential (unless your data is made available for others to view, such as in forum posts) and will only use and share it as
detailed in this privacy policy. We will comply with the Data Protection Act 1998 and the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) in relation to your data. We do not sell your data to third parties.
2. What types of data we store about you
The data and information we store and process about you includes:
a. Information about you:
• Your account details
• Your name
• Your contact details including address, telephone, mobile, fax, your own website and email address.
• Your account information, including each membership and other accounts you have registered with
us.
• Your account login information, including your username and password.
• Entries in your address book, including other shipping addresses you provide.
• Any contact information and messages you provide when you refer a friend.
• Your account settings and other account information.
b. Information related to your orders
• Your purchase transactions
• Your purchase orders
• Your payment information and payment history
• Information about shipping, fulfillment, and returns on orders.
c. Your online activity
• Your content
• Your professional artist information, including but not limited to personal information, galleries,
portraits, biography, exhibitions, awards, training, media, and items.
• Messages you exchange with other members using any of the services we provide.
• Any other content you provide.
d. Administrative information
• Communications between you and us, including inquiries, problems, support and survey responses,
including via email, web forms and telephone.
e. Technical information when you visit our website
• Web browser information, including the brand of your browser (e.g. Internet Explorer, Firefox, Safari,
Opera, Chrome),
• Operating system (e.g. Microsoft Windows, OSX, Android)
• IP address (a unique identifier assigned to your computer to connect to the Internet).
• Information relating to your use of our website, including where you came to our website from and
the pages you visit on our website.
3. How we obtain your data
We obtain your data in a variety of ways, including:
a. Forms you fill in/data you provide.
• From forms you complete and submit on our website
• From printed forms you receive from our website or from us
• Data we collect in person, by email or over the phone
b. Other information you provide
• From data, information and images you post, upload or otherwise make available on our website,
including our forum.
• From any other information you provide from time to time, including through phone calls, emails and
other communications between you and us.
• From any information provided by other users of our site and other customers.
c. Generated information
• From information generated by us as a result of our business relationships, transactions and
communications with you, including the supply of any goods or services to you, the provision of our
website functionality, the administration of competitions and the handling of inquiries, support requests
and complaints.
d. Technical information
• From information that is automatically provided by your web browser when you visit our website.
• From information recorded by our server when you view any page on our website.
4. Use of Data
We use your data for the following operational purposes:
a. To operate and improve our website
• To provide our website, its features and functionality.
• To analyse the performance and improve our website.
• To provide you with status or other administrative notices.
b. To supply goods and services
• To fulfil each order you place for the supply of goods and services.
• To collect payments due from you.
c. To provide member accounts
• To provide, administer and manage your accounts and the related services included in those accounts.
• To collect payment of all account fees.
• To pay commissions on sales to artists.
d. General administration
• To supervise our staff.
• To contact you for administrative and support purposes.
• To manage complaints, disputes and claims.
• To enforce our contracts and terms and to pursue claims.
Marketing emails and communications
We will also use your data to send you marketing materials and newsletters relating to our website, products, services and events, but only if you have consented to this via the relevant setting in your website account and have not withdrawn your consent. You can change your consent by changing the
relevant setting or by notifying us via our contact details in this policy. The data we hold about you is stored on our secure computer servers. We retain this data to ensure that we can manage your account and provide you with details of previous purchases, wishlist items and your account preferences. If you require us to delete this information, please see section 11.
5. Who we disclose your data to
a. Public Data
Where the functionality of our website or any service, competition or event we provide or run means that some of your data will be available to the general public or other members, then we may make that
data available on that basis. For example, your forum posts, elements of your profile and professional
artist information, your galleries, tuition fees etc. may be made public. We will make it clear to you on
our website or in our communications with you which elements of your data will be made available in
this way. Where our website settings allow you to control which elements of your data are made public,
then we will abide by your settings.
b. Our contractors and suppliers
Where we use third parties to provide or supply any part of our website or any goods, services, events,
insurance or other things, or to secure or administer any contracts or terms, we may share your data
with them as necessary for those purposes, including artists from whom work is purchased, delivery
agents, payment processors and insurers.
Your data may be stored by them as data processors on our behalf, in which case we will remain the
data controller and your data will only be stored and used by them on our behalf and in accordance with
our instructions and this policy. Your data will also only be stored for as long as or as necessary to enable
them to provide the services, after which it will be securely deleted from their systems.
In some cases, they may need to use your data for their own purposes as a data controller where
reasonably necessary for the purposes of providing any goods, services, insurance, events etc. In such a
case, they must separately inform you that they are storing your data as a data controller.
c. Legal requirements
We may provide your data to a public authority where it is necessary to do so for compliance with legal
requirements, for the administration of justice or where it is reasonably necessary to protect your vital
interests.
g. Handling Complaints
We may disclose your identity to any third party who makes any claim against us in relation to any of
your data that you have posted or uploaded to our website, including where it is claimed that it violates
their rights or privacy.
6. Where we process your data
We and our contractors and suppliers will generally store and process your data in the United Kingdom.
However, we and our contractors and suppliers may from time to time store and process your data
elsewhere, including outside the European Economic Area. This may be because our contractor or
supplier who carries out any order fulfilment or payment processing, for example, may be based
elsewhere.
Where your data is stored or processed outside the European Economic Area, we will comply with, and
take all reasonable steps to ensure that our contractors and suppliers comply with, the rules set out in
the Data Protection Act 1998 and the General Data Protection Regulation (GDPR) (Regulation (EU)
2016/679) for the processing of personal data outside the European Economic Area.
7. Data security and preventing unauthorised access
a. Our Security Measures
We will take and use reasonable endeavours to ensure that our contractors and suppliers take all
reasonable steps and implement all reasonable measures to keep your data secure and to prevent
unauthorised access to it (except for those parts of your data that are intended to be made available to
the public or to our other customers or members, such as your public profile, forum posts, gallery, etc.),
and to prevent accidental loss of or damage to your data.
b. Your Passwords
You are responsible for maintaining the confidentiality of your username and password for logging in
and we ask that you do not share them with anyone.
Information Security Policy
All employees are responsible for maintaining the confidentiality of confidential information. Arts Bound
Gallery recognises the importance of information security. The primary objective of our information
security is to protect the services to members and customers and the customer information that we
are safe in the knowledge that we are responsive to their security concerns.
Arts Bound Gallery will adhere to all PCI DSS requirements for the protection of customer card data.
Each employee of Arts Bound Gallery plays an important role, and each employee has their own specific
tasks and responsibilities. We expect that our core behavior of professionalism and customer focus will
be reflected in our protection of customer information. We support staff efforts to protect information
through policies, as well as staff training and awareness events.
This policy is subject to annual review to ensure that it strategically addresses evolving information
security threats and the objectives necessary for the successful operation of the organization.
Payment Card Security
Arts Bound Gallery processes payment cards through the PayPal payment page, which is accessed from
authorized PCs on a dedicated network segment. Access to this network segment from the Internet or
from other areas of Arts Bound Gallery is not possible. PCs and other devices on this network must be
configured in accordance with PCI DSS requirements and may only be accessed by authorized users.