General Data Protection Regulation (GDPR)
Full name of legal entity: My Art Project Ltd
Email address: email@example.com
Address: Unit 2a, Atherstone Hill, Atherstone-on-Stour, Stratford-upon-Avon, Warwickshire. CV37 8NF
Telephone number: 0845 408 5194
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
What information does My Art Project collect about me and why?
We collect personal information from you when you request a free information pack or register for one of our projects. When doing so, you may be asked to provide personal information such as your name, e-mail address, mailing address and phone number.
We collect this information (and have a lawful legitimate interest to do so) so that we can send you information about running a project with us, or to manage a fundraising project for you.
Your personal data is NOT shared with any third parties.
Fundraising Projects – Children’s Names, Classes and Drawings
When you sign-up to run a fundraising project with My Art Project we will often be sent drawings, children’s names and class information to process a project for you. As you are collecting this information and sending it to us for processing, you act as a data controller in this transaction and we act as a data processor for you.
All paper based drawings are stored at our premises and are automatically returned to you after your project has finished. Electronic records of children’s names and classes are stored on our servers for as long as they are required to manage your order. This is to allow us to process corrections, updates and replacements some time after your project finishes. After 5 years this data is permanently deleted from our systems.
The children’s personal data is not shared with any third parties.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, political opinions, health, genetic or biometric data etc.).
Management/Storage of your personal data (data retention)
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements.
The personal data we hold on our system will be held indefinitely (see above for an exception for children’s names, classes and drawings which are periodically deleted from our system) whilst you hold an account with us.
However you can contact us at anytime to have your personal data edited or deleted.
What do we use your personal information for?
Any of the information we collect from you may be used to contact you by telephone, email or letter after requesting a free information pack or registering for one of our projects. We may occasionally contact you by letter or email for marketing purposes (My Art Project only).
Marketing Communication from us
You will receive marketing communications from us if you have requested information from us, provided you have opted in to receive marketing.
You can ask us to stop sending you marketing messages at any time by following the ‘unsubscribe’ link on any marketing message sent to you.
We will never share your personal data with any company outside of My Art Project for marketing purposes.
How do we protect your information?
We have in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way.
Our servers and database are maintained by a well-established IT company: Celsius Software Ltd.
Celsius Software Ltd complies with all Physical Security & Data Transfer legal requirements.
Our website chat facility is hosted and maintained by Live Chat INC., who are fully GDPR compliant.
In addition, we limit access to your personal data to those employees and third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
Online orders made via our website are protected by your Unique Reference Number. These are randomly generated by our database and are not repeated or reused.
Online payments are made directly through Stripe. This company complies with all Processing Procedures for Online Payment legal requirements. We do not record or store any bank card details on our servers or systems from online orders, nor for over the phone payments.
All confidential paper based data is archived on site for a period of 12 months, after which it is shredded and disposed of appropriately.
Do we disclose any information to outside parties?
We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information. This does not include trusted third parties named above, who assist us in operating our website & managing our database. Those parties have agreed to keep this information confidential.
We may also share your information where disclosure is required or permitted by law (for example to government bodies, HMRC and law enforcement agencies).
What are Cookies?
Cookies are small files that a site transfers to your computer through your web browser (if you allow) that enables the sites or service providers systems to recognise your browser and capture and remember certain information.
Third Party Cookies on our website
Please note that during your visits to the www.myartproject.co.uk website you may notice some cookies that are not related to us. When you visit a page with content embedded from, for example, Google, Facebook, LiveChat or Twitter, you may be presented with cookies from these websites. My Art Project Ltd does not control the dissemination of these cookies. You should check the third party websites for more information about these.
Cookies can be disabled in your browser options (please note that in these instances some functions of our website might be unavailable to you).
We do not transfer your personal data outside the European Economic Area (EEA).