PRIVACY POLICY

1. INTRODUCTION

Alcemi Art is committed to protecting your personal information and ensuring it is processed in a reasonable, secure and transparent way. This privacy notice provides you with details of how I may collect and process your personal data through your use of my services and this website www.alcemiart.co.uk.    This includes any information you may provide browse this website, sign up to the mailing list, make a purchase or contact me.

Alcemi Art is the data controller and is responsible for your personal data.

My full details are:
Full name of legal entity: Alcemi Art (Jacqui Caley-Hawker)
Email address: jacqui@alcemiart.co.uk
Postal address: Ty Rhosyn, Bronllwyn, Pentyrch, Cardiff, CF159PT

I only collect and process personal data required to provide my services to you. This policy provides a breakdown of how I use this data within my business.

2. WHAT INFORMATION DO I COLLECT?

In order to operate my business and provide products and services to you I may process certain types of personal data. I will only ever collect necessary information which might include the following:

  • Identity Data: may include first name, last name, title, date of birth and photography.

  • Contact Data: may include billing address, email address and telephone numbers.

  • Financial Data: may include your bank account and payment card details.

  • Transaction Data: details about payments between us.

  • Technical Data: may include your internet protocol addresses, browser type and version, browser plug-in types and versions, time zone setting and location, operating system and platform and other technology on the devices you use to access my website.

  • Profile Data: may include your purchases or orders, your interests, preferences, feedback and survey responses.

  • Usage Data may include information about how you use my website, products and services.

  • Marketing and Communications Data: your preferences in receiving marketing communications from me.

3. HOW IS THIS INFORMATION COLLECTED?

I collect this data through a variety of methods including:

  • Direct interactions: You may provide data by filling in forms on this website (or in person) or by communicating with me by post, phone, email or otherwise, including when you:
    - purchase a product or service;
    - make an enquiry;
    - subscribe to my mailing list;
    - give me feedback;
    - attend an event.

  • Automated technologies or interactions: As you use my website, I may automatically collect Technical Data about your equipment, browsing actions and usage patterns. I collect this data by using cookies, server logs and similar technologies. Please see my Cookie Policy for more details.

  • Third parties or publicly available sources: I may receive personal data about you from various third parties and public sources as set out below:
    - analytics providers such as Google based outside the EU;
    - contact information from ConvertKit (if you sign up to my email newsletter)
    - contact, financial and transaction data from third party payment providers such as: Stripe and Paypal, both based in the USA.

4. HOW YOUR PERSONAL DATA IS USED

The most common uses of your personal data are:

  • Where I need to fulfil the contract between us (when you make a purchase, sign up to a course or workshop, or enter into a contract of employment)

  • Where it is necessary for my legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.

  • Where I need to comply with a legal or regulatory obligation.

Generally, I do not rely on consent as a legal ground for processing your personal data, other than in relation to sending marketing communications to you via email and in some cases for photography. You have the right to withdraw consent to marketing communications at any time by emailing me at info@katebroadhurst.com

I may process your personal data without your knowledge or consent where this is required by law.

Making a purchase through this website

The majority of data I collect is processed under a contractual basis to fulfil orders made through this website. When you buy something on this website, I collect personal information from you to fulfil the order. I may collect information like your:

  • Billing and shipping address

  • Details relating to your purchase 

  • Email address

  • Name

  • Phone number

I share this information with Squarespace, my online store hosting provider, so that they can provide website services to me.

As you go through checkout, this site may auto-complete your shipping and billing address by sharing what you type with the Google Places API and returning suggestions to you to improve your checkout experience.

I may email you with messages about your order or account activity. For example, I may email you to tell you that:

  • You’ve made a purchase

  • Your order has shipped

It’s not possible to unsubscribe from these messages.

You’ll receive an automated email within 24 hours after you abandon your shopping cart, if all of the following occur:

  • You enter your email address at checkout

  • You add a product which is in stock to your shopping cart.

  • You close your browser or leave this website without completing your purchase.

You can unsubscribe from these messages at the bottom of the email. The email will link back to this website, where you can pick up where you left off and complete your purchase.

I share your contact information with Squarespace, my website hosting provider, so they can send these emails to you on my behalf.

4. WHO I SHARE YOUR DATA WITH

I only share relevant personal data with other organisations where it is necessary to use their service to manage your contract and my business operations. I use the following third party services which act as ‘data processors’ to support the services and operations of Kate Broadhurst Studio.

Squarespace and Payment Gateways 

My website is hosted on Squarespace. They provide me with the online e-commerce platform that allows me to sell my products to you. Your data is stored through Squarespace’s data storage, databases and the general Squarespace application. They store your data on a secure server behind a firewall.

Squarespace are certified to the EU-US and Swiss-US Privacy Shield, which allows them to lawfully transfer EU and Swiss personal data to the US, including to their US-based data centers. You can read more about Squarespace’s Privacy Shield certifications here.

All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by this store and its service providers.

G-Suite by Google

I use G Suite for Business to help me administer many sides of my business. This includes GMail for email services and Google Drive for file storage. I also use Google Docs, Google Slides, Google Sheets, Google Contacts, Google Hangouts and Google Calendar.

These are online systems developed by Google (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043,USA). Personal data which you provide to me when making an enquiry or a purchase may be stored in these systems to allow me to manage my business affairs.

Google is committed to GDPR compliance across G Suite and Google Cloud Platform services. You can read more about their data processing terms for G Suite here.

Your data will be stored in Google's network of data centers. Information about the locations of Google data centers is available at: https://www.google.com/about/datacenters/inside/locations/index.html 

ConvertKit

I use ConvertKit as my email marketing platform. By opting in to marketing communications from me, you acknowledge that the information you provide will be transferred to ConvertKit for processing in accordance with their Privacy Policy and Terms.

You will only receive marketing communications from me if you have opted in by: 

  • filling in a sign up form on this website or in person; or

  • if you provided me with your details when making a purchase and ticked the box at the point of entry of your details for me to send you marketing communications; and

  • in each case, you have not opted out of receiving that marketing. 

You can ask me to stop sending you marketing emails at any time by following the unsubscribe links on any email or OR by contacting me at info@katebroadhurst.com 

Where you opt out of receiving my marketing communications, this will not apply to personal data provided to me as a result of a purchase or other contact enquiry. 

QuickBooks (Intuit)

Quickbooks is my online accounting service and transactional data will be shared with this service as part of my legal obligation to keep accurate financial records. QuickBooks Online uses AES256 encryption for all data that is processed and stored in its ecosystem, and TLS is used to encrypt all data in transit outside of Intuit ecosystems.

International Transfers

Some of my third party service providers (listed above) are based outside the European Economic Area (EEA) so their processing of your personal data will involve a transfer of data outside the EEA.

Whenever I transfer your personal data out of the EEA, I ensure at least one of the following safeguards is implemented: 

  • I will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission; or

  • Where I use certain service providers, I may use specific contracts or codes of conduct or certification mechanisms approved by the European Commission which give personal data the same protection it has in Europe; or

  • Where I use providers based in the United States, I may transfer data to them if they are part of the EU-US Privacy Shield, which requires them to provide similar protection to personal data shared between the Europe and the US.

Third party links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. I do not control these third-party websites and am not responsible for their privacy statements. When you leave my website, I encourage you to read the privacy notice of every website you visit.

6. DATA RETENTION 

I will only retain your personal data for as long as necessary to fulfil the purposes I collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

Contacting me
When you contact me you will provide your Name, Email Address and Phone Number. I hold this information to respond to your enquiry and retain in case of any follow ups. Generally, if more than 6 months have passed since your last contact and you have not entered into any further engagement then I will delete your data. 

When you have entered into a contract with me (by making a purchase)
I will hold your data for the duration of our contractual agreement. Following this, I will hold onto this data for a period of 7 years. By law I have to keep basic information about my customers and contractors (including Contact, Identity, Financial and Transaction Data) for 7 years after they cease being customers or contractors for tax purposes. If you ask me to delete your information I will delete what I can but will not delete all of your data until this 7 year period has ended. 

When you have subscribed to my mailing list
If you have consented to receive marketing emails from me, your name and email address will remain on my list until you unsubscribe which you can do at any time by contacting my or clicking the link to unsubscribe on any email. When you have unsubscribed I will delete your data within 6 months. This does not apply to other communications that may be required to fulfil my contractual obligations.

7. YOUR LEGAL RIGHTS

You have the right to object to my processing of your personal information and may do so at any time. 

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include:

  • The right to be informed - this notice tells you what information I collect, what I do with it, who I share it with and how long I hold it for.

  • The right to access - You can ask me at any time to  let you know what personal information I hold about you and I will provide you with a copy. I have a month to do this.

  • The right to rectification - I try to ensure your information is up to date. If I have got anything wrong, you have the right to correct it. You can do this at any time.

  • The right to erasure - You can make a request for erasure verbally or in writing. I have one month to respond to this request. This right is not absolute and only applies in certain circumstances.

  • The right to restrict processing - you have the right to request the restriction or suppression of your personal data. I have one month to respond to this request. This right is not absolute and only applies in certain circumstances.

  • The right to data portability - You can ask us to provide your data in a form that is easily transferable to another organisation and in a machine readable format.

  • Right to withdraw consent - where consent has been sought (when subscribing to a newsletter) you have the right to withdraw it by contacting me. This does not apply to any communications or data processing required for contractual or legal reasons. 

If you wish to exercise any of the rights set out above, please email me at info@katebroadhurst.com 

If you are not happy with any aspect of how I collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). I would be grateful if you would contact me first if you do have a complaint so that I can try to resolve it for you.

I reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website.

Last updated May 29th 2023