
PRIVACY POLICY FOR ART PLAY LONDON
Effective date: 25th October 2024
​
Art Play London is committed to protecting and respecting your privacy. This Privacy Policy outlines how we collect, use, store, and share your personal data, and explains your rights under the UK Data Protection Act 2018 and the General Data Protection Regulation (GDPR). By using our website, booking workshops, purchasing products, or interacting with us, you agree to the collection and use of information as outlined in this policy.
​
1. Introduction
At Art Play London, we take your privacy seriously and are dedicated to safeguarding your personal information. This Privacy Policy aims to give you a clear understanding of what personal data we collect, why we collect it, how we use it, and the choices you have regarding your personal data.
We are committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, participating in our workshops, or purchasing our products, you can be assured that it will only be used in accordance with this Privacy Policy.
This policy complies with the UK GDPR and the Data Protection Act 2018, and explains:
-
The type of personal data we collect and how we collect it.
-
How and why we use your personal data.
-
Your rights in relation to your personal data.
-
How we keep your personal data secure.
We reserve the right to modify this policy at any time. If changes are made, they will be posted on this page, and where appropriate, notified to you by email. It is your responsibility to check this policy regularly for updates. By continuing to use our website or services after any changes have been posted, you confirm your acceptance of the revised policy.
​
2. Definitions
For the purposes of this Privacy Policy, the following definitions apply:
-
“Personal Data”: Any information relating to an identified or identifiable natural person. This includes information such as your name, contact details, payment information, and IP address.
-
“Data Subject”: Any individual whose personal data is being collected, held, or processed by Art Play London.
-
“Processing”: Any operation or set of operations performed on personal data, such as collection, recording, storage, alteration, retrieval, or destruction.
-
“Controller”: The entity (Art Play London) that determines the purposes and means of processing personal data.
-
“Processor”: A third party (e.g., a payment gateway or email service provider) who processes personal data on behalf of the controller.
-
“Consent”: Freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them.
These definitions align with the terminology used in the GDPR and the UK Data Protection Act 2018 to ensure clarity in our obligations and your rights.
3. Data Controller
Art Play London is the data controller, meaning we are responsible for determining the purposes and means of processing your personal data. We are registered in the United Kingdom under the following details:
-
Company Name: Art Play London
-
Company Address: THE MARKET NEXT TO LULU LEMON, Old Spitalfields Market, London, UK
-
Email: info@artplaylondon.co.uk
-
Phone: [Insert contact number]
-
Data Protection Officer (DPO): [Insert DPO name/contact if applicable]
If you have any questions or concerns about how we handle your personal data, please feel free to contact us using the above details. We are committed to addressing your concerns in a timely and transparent manner.
​
4. Types of Data Collected
We collect different types of personal data depending on how you interact with us. The types of personal data we collect include:
​
4.1 Personal Data You Provide Directly
When you engage with Art Play London, you may provide personal data in the following ways:
-
Booking Workshops: When you book a workshop, we collect your name, contact information (e.g., email address, phone number), and payment details.
-
Purchasing Products: For e-commerce transactions, we collect your shipping address, billing details, and payment information.
-
Contacting Us: If you contact us via our website, phone, or email, we may collect your name, email address, phone number, and the content of your communication.
-
Creating an Account: If you create an account on our website, we collect your name, email address, and any additional profile information you provide.
4.2 Data Collected Automatically
When you visit our website, we collect certain information automatically, such as:
-
IP Address: Your device’s IP address, which can help us understand where our users are located.
-
Browser and Device Information: This includes the type of browser you are using, your device’s operating system, and other technical details about your interaction with our site.
-
Cookies: Small data files that are placed on your computer or mobile device when you visit our website (see Section 9 for more information on cookies).
4.3 Sensitive Personal Data
Art Play London does not generally collect any sensitive personal data (such as information related to health, race, or political beliefs). If, in rare circumstances, we do need to collect sensitive data (e.g., for health and safety purposes during an event), we will only do so with your explicit consent and in accordance with applicable data protection laws.
5. How We Collect Personal Data
We collect personal data in several ways, depending on how you interact with our services. The primary methods include:
5.1 Direct Interactions
-
When You Book a Workshop: You provide us with personal information (e.g., name, email address, payment details) during the booking process, either through our website, over the phone, or in person.
-
Purchasing Products: When making an online purchase of art supplies, artwork, or merchandise, you provide us with shipping and payment details.
-
Contacting Us: When you reach out via email, phone, or through a contact form on our website, you voluntarily provide personal data such as your contact information and the content of your communication.
5.2 Automated Technologies or Interactions
When you interact with our website, we may automatically collect technical data about your device, browsing actions, and patterns. This data is collected using cookies, server logs, and similar technologies.
5.3 Third-Party Sources
In some instances, we may receive personal data about you from third-party sources, such as:
-
Payment Providers: To process transactions, we work with payment gateways (e.g., PayPal, Stripe), who provide us with payment confirmations and related details.
-
Marketing Platforms: We may receive information about your marketing preferences if you engage with third-party marketing campaigns (e.g., social media ads).
6. Purpose of Data Processing
We process your personal data for specific and legitimate purposes. These purposes include, but are not limited to:
6.1 To Provide Services
We use your personal data to:
-
Facilitate your booking of workshops, private sessions, or events.
-
Process and deliver your online purchases, including handling shipping and returns.
-
Send confirmation emails, receipts, and updates related to your bookings and purchases.
6.2 To Manage Your Account
If you create an account on our website, we will use your data to manage your profile, track your bookings, and provide a personalized experience.
6.3 To Communicate with You
We use your personal data to respond to your inquiries, provide customer service, and notify you of any changes to your bookings or services.
6.4 Marketing and Promotions
If you have provided consent, we may use your data to send you marketing emails or promotional offers related to our workshops, products, or services. You can withdraw your consent at any time (see Section 8 for more details).
6.5 To Comply with Legal Obligations
We may process your personal data where necessary to comply with legal obligations, such as record-keeping for tax and accounting purposes or responding to law enforcement requests.
6.6 To Improve Our Services
We may use your data (including automatically collected data) to analyze how users interact with our website, products, and services, allowing us to improve the overall user experience.
7. Legal Basis for Data Processing
Under GDPR, we must have a valid legal basis to process your personal data. The legal bases we rely on include:
7.1 Performance of a Contract
Most of our data processing is based on the necessity to perform a contract with you. For example, when you book a workshop or purchase products, we need to process your personal data to fulfill that contract.
7.2 Consent
We will obtain your explicit consent for certain types of processing, such as sending marketing communications. You have the right to withdraw your consent at any time.
7.3 Legal Obligation
We may process personal data to comply with legal obligations, such as tax reporting, anti-fraud measures, or fulfilling governmental requests.
7.4 Legitimate Interests
In certain cases, we may process your personal data to pursue our legitimate business interests. This might include improving our services, maintaining the security of our website, or analyzing the effectiveness of our marketing campaigns. We will always balance our legitimate interests with your privacy rights, and you have the right to object to this processing.
8. Marketing Communications
Art Play London may send you marketing communications to keep you informed about our workshops, products, special offers, and events. We are committed to ensuring that your privacy is respected, and we will only send marketing communications when you have provided your explicit consent.
8.1 Opting In
We will only send you marketing emails if you have opted in to receive them. You can opt in by:
-
Subscribing to our newsletter via our website.
-
Indicating your preference to receive marketing when booking a workshop or purchasing a product.
-
Filling out a physical form at an Art Play event or workshop.
8.2 Opting Out
You have the right to opt out of receiving marketing communications from us at any time. You can do this by:
-
Clicking the "unsubscribe" link in any marketing email you receive from us.
-
Contacting us directly at info@artplaylondon.co.uk to request removal from our marketing list.
Please note that even if you opt out of marketing communications, we may still send you non-promotional emails, such as those related to your bookings, purchases, or customer service inquiries.
8.3 Right to Object
Under GDPR, you have the right to object to the processing of your personal data for direct marketing purposes at any time. Once you object, we will cease processing your personal data for marketing purposes.
9. Cookies and Tracking Technologies
Please refer to our Cookie Policy for more information on this section.
10. Data Sharing and Third-Party Processors
Art Play London does not sell, rent, or trade your personal data with third parties for marketing purposes. However, we may share your personal data with trusted third-party service providers who help us deliver our services, process payments, or run our website.
10.1 Third-Party Processors
We work with carefully selected third-party providers who assist us with:
-
Payment Processing: We use payment gateways (e.g., PayPal, Stripe) to process payments securely.
-
Email and Marketing Platforms: We use third-party email providers (e.g., Mailchimp) to send newsletters and marketing communications to users who have consented.
-
Analytics and Website Management: We use third-party analytics tools (e.g., Google Analytics) to understand how users interact with our website and to improve user experience.
All third-party service providers we work with are required to comply with GDPR and other relevant data protection laws. They only process your personal data based on our instructions and must not use your data for any other purpose.
10.2 Legal and Regulatory Requirements
We may share your personal data where required to comply with legal obligations, such as:
-
To comply with a court order or legal process.
-
To protect the safety, property, or legal rights of Art Play London or third parties.
-
To report fraudulent activities or suspected illegal activities to law enforcement authorities.
11. International Data Transfers
Art Play London operates within the United Kingdom but may need to transfer your personal data to third-party processors located outside the UK or European Economic Area (EEA). We will only transfer personal data to countries or organizations that provide an adequate level of data protection.
11.1 Transfers Outside the UK/EEA
When transferring data outside the UK or EEA, we will ensure that appropriate safeguards are in place, such as:
-
Adequacy Decisions: Ensuring that the destination country has been deemed by the UK or EU to have an adequate level of data protection.
-
Standard Contractual Clauses (SCCs): Using legally binding contracts between us and the third-party processor to ensure your data is protected according to UK GDPR standards.
11.2 Your Rights Regarding International Transfers
You have the right to request details of the mechanisms under which your data is transferred outside the UK or EEA. If you wish to exercise this right, please contact us at info@artplaylondon.co.uk.
12. Data Retention Policy
We will retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
12.1 Retention Periods
We retain personal data according to the following guidelines:
-
Booking Information: Retained for seven (7) years for tax and accounting purposes.
-
Customer Profiles: Retained as long as your account is active or until you request deletion.
-
Marketing Data: Retained until you opt out or withdraw consent.
-
Technical Data (Cookies): Retention periods vary by cookie type and will be explained in our Cookie Policy (see Section 9).
12.2 Deletion of Personal Data
When we no longer need your personal data, we will securely delete or anonymize it. If you request the deletion of your personal data, we will honor that request unless we are required by law to retain certain information (e.g., for tax or legal reasons).
13. Data Security Measures
Art Play London takes the security of your personal data very seriously and has implemented appropriate technical and organizational measures to protect it from unauthorized access, disclosure, alteration, or destruction.
13.1 Technical Measures
We use industry-standard security measures to protect your data, including:
-
Encryption: Sensitive data (e.g., payment details) is encrypted using Secure Socket Layer (SSL) technology during transmission.
-
Firewalls and Anti-Virus Software: To prevent unauthorized access to our systems.
-
Access Controls: Limiting access to your personal data to employees and third parties who need it for legitimate business purposes.
13.2 Organizational Measures
We take steps to ensure that all staff members handling personal data are aware of their responsibilities and are trained in data protection best practices. Access to personal data is limited to authorized personnel only.
13.3 Security Breaches
In the event of a data breach that affects your personal data, we will notify you and the Information Commissioner’s Office (ICO) where legally required. We will take immediate steps to mitigate the breach and prevent future occurrences.
14. Data Subject Rights
Under GDPR, you have the following rights in relation to your personal data:
14.1 Right to Access
You have the right to request access to the personal data we hold about you. This is commonly known as a “Subject Access Request.” Upon verification of your identity, we will provide a copy of your personal data, free of charge, within one (1) month of receiving your request.
14.2 Right to Rectification
You have the right to request that we correct any inaccuracies or incomplete data we hold about you. We will make the requested changes promptly, usually within one (1) month.
14.3 Right to Erasure ("Right to be Forgotten")
You have the right to request the deletion of your personal data where:
-
The data is no longer necessary for the purposes for which it was collected.
-
You withdraw consent and no other legal ground exists for processing.
-
The data was processed unlawfully.
14.4 Right to Restriction of Processing
You may request that we restrict the processing of your data if:
-
You contest the accuracy of the data.
-
The processing is unlawful, but you oppose deletion.
-
We no longer need the data, but you require it to establish, exercise, or defend legal claims.
14.5 Right to Data Portability
You have the right to request the transfer of your personal data to another service provider, where technically feasible, in a structured, commonly used, and machine-readable format.
14.6 Right to Object
You have the right to object to the processing of your data in certain circumstances, including:
-
Processing based on legitimate interests.
-
Direct marketing purposes.
14.7 Right to Withdraw Consent
Where we rely on your consent for data processing (e.g., marketing communications), you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
15. Exercising Data Subject Rights
At Art Play London, we are committed to ensuring that you can easily exercise your rights regarding your personal data. If you wish to make a request regarding your data (e.g., accessing, correcting, or deleting your personal data), you can do so as follows:
15.1 How to Submit a Request
You can exercise your rights by contacting us through the following methods:
-
Email: Send your request to info@artplaylondon.co.uk
-
Postal Mail: Address your request to Art Play London, THE MARKET NEXT TO LULU LEMON, Old Spitalfields Market, London, UK.
Please specify the nature of your request (e.g., access, correction, deletion) and provide sufficient information for us to verify your identity.
15.2 Proof of Identity
To protect your privacy, we may ask you to provide proof of identity before we can process your request. This could include a government-issued identification document such as a passport or driving license.
15.3 Response Time
We will acknowledge receipt of your request and aim to respond within one (1) month. In some cases, such as particularly complex requests, this period may be extended by a further two (2) months. If an extension is necessary, we will inform you within the first month.
15.4 Fees
Most requests are handled free of charge. However, if a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee to cover the administrative costs of complying with the request. Alternatively, we may refuse the request under such circumstances and explain our reasons for doing so.
15.5 Right to Lodge a Complaint
If you are dissatisfied with our response to your request or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
-
Website: www.ico.org.uk
-
Phone: 0303 123 1113
16. Children's Privacy
At Art Play London, we understand the importance of protecting the privacy of children. Our services are generally aimed at adults, but we may offer family-friendly workshops where children can participate under parental supervision.
16.1 Data Collection from Minors
We do not knowingly collect personal data from children under the age of 13 without parental consent. If you are under 13, please do not provide us with any personal data unless you have received explicit permission from a parent or guardian.
16.2 Parental Consent
If we collect personal data from children aged 13 to 18, we require explicit parental consent before processing the child’s data. Parents or guardians are encouraged to monitor their children’s use of our website and services and to ensure that their data is being shared with appropriate consent.
16.3 Rights of Parents
Parents or guardians have the right to review and request the deletion of any personal data we have collected from their children. If you believe we have collected personal data from a child without appropriate consent, please contact us immediately at info@artplaylondon.co.uk, and we will take steps to delete such information promptly.
17. Data Breach Notification
At Art Play London, we take the security of your personal data very seriously. Despite our best efforts, there is always a risk of data breaches due to malicious attacks, technical failures, or other unforeseen circumstances.
17.1 Our Responsibility
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
-
Notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach.
-
Take immediate steps to mitigate the breach and prevent further unauthorized access or disclosure.
17.2 Notification to Affected Individuals
If the breach is likely to result in a high risk to your rights and freedoms (e.g., identity theft, financial loss, or other significant harm), we will notify you directly without undue delay. Our notification will include:
-
A description of the nature of the breach.
-
The likely consequences of the breach.
-
Measures we have taken or plan to take to address the breach.
-
Information on how you can protect yourself from potential adverse effects.
If you have any concerns regarding a potential data breach, please contact us immediately at info@artplaylondon.co.uk.
18. Links to Third-Party Websites
Our website may contain links to third-party websites, including payment gateways, event partners, or social media platforms. This Privacy Policy only applies to data collected directly by Art Play London. We are not responsible for the privacy practices or content of third-party websites.
18.1 Third-Party Privacy Policies
When you follow a link to a third-party website, we encourage you to read their privacy policy carefully, as they will have their own terms regarding the collection and use of your personal data. We are not responsible for any data shared with or collected by third-party sites.
18.2 Social Media Plug-ins
Our website may include social media plug-ins (e.g., Facebook, Instagram, or Twitter). When you interact with these plug-ins, your browser may share certain data with the social media platform, including your IP address and the pages you visited on our website. We recommend reviewing the privacy policies of these platforms to understand how your data is processed.
19. Changes to This Privacy Policy
Art Play London reserves the right to update or modify this Privacy Policy at any time. Changes may be necessary to reflect updates in our practices, legal requirements, or new features on our website.
19.1 Notification of Changes
We will notify you of significant changes to this Privacy Policy by:
-
Posting the updated policy on our website.
-
Sending an email notification to registered users if the changes are material.
19.2 Effective Date
Any changes to this Privacy Policy will become effective when posted on our website. The "last updated" date at the top of the policy will reflect when the latest changes were made. Your continued use of our website, services, or participation in our workshops after any changes are posted constitutes your acceptance of the revised Privacy Policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data.
20. Contact Information
If you have any questions, concerns, or complaints about this Privacy Policy or how Art Play London processes your personal data, please do not hesitate to contact us:
-
Email: info@artplaylondon.co.uk
-
Postal Mail: Art Play London, THE MARKET NEXT TO LULU LEMON, Old Spitalfields Market, London, UK
We take all privacy-related concerns seriously and will do our best to resolve any issues in a timely and transparent manner.