Updated April 2023

Privacy Policy

Who I am

My website address is: https://carolnunan.co.uk.

How to contact me

Email Chris Moss, at chris@carolnunan.co.uk about anything connected with this privacy notice. Or write to us at Carol Nunan - Printmaker, 16 Academy Road, Rothesay, Isle of Bute, PA20 0BG.

Privacy Policy in Brief

  • From time to time I will contact you to ask you to update your details to ensure they are current. You can unsubscribe at any time.

  • I promise I will never send you spam, or unsolicited emails, only information you have consented to receive about new work, new products, exhibitions, events and news that feeds into the creation of my work.

  • Your privacy is of utmost importance to me. I will NEVER provide, sell or loan this information to a third party without your permission, or unless I am required by law to do so.

Privacy Policy in Detail 

The personal data I collect and why.

The personal data I collect depends on whether you make a purchase, book a workshop, or sign up to the newsletter. I may collect some or all of the following data from you:


General

  • Your name

  • Your email address

  • Your address

  • Your phone number

  • Your business name

  • Your financial details

Website Hosting

The Website is hosted on the Squarespace platform. Squarespace provides us with the online platform that allows us to communicate with you. Your data may be stored through Squarespace’s data storage, databases and the general Squarespace applications. They store your data on secure servers behind a firewall.


Website

When you leave comments on the website, we collect the data shown on the comments form, plus the visitor’s IP address and browser user agent string to help spam detection.

  • An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/.

  • After approval of your comment, your profile picture is visible to the public in the context of your comment.

  • In the (unlikely) scenario where you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

  • Data about how you use my website.

  • Technical data such as your IP address, details about your browser, length of visit to pages on my website, page views and navigation paths, details on the number of times you view the website, time zones settings and other technology and devices you use to access my website.

  • Your marketing and communication preferences

  • Any other information you provide to me whether through my contact form, by email, over the phone or otherwise, such as entering a competition or completing a survey.

  • Photographs of you at events or workshops

  • Credit information from third parties.

Workshop specific

  • Your relevant medical details (for workshops)

  • Your dietary preferences (for workshops)

  • Emergency contact (for workshops)

Mailing List

​My Mailing List requires your explicit consent. When you join my mailing list, your name and email address are held on our website Contacts List held by Squarespace and MailChimp. You will only ever receive the information to which you have consented. You can unsubscribe from this mailing list at any time by either clicking the ‘unsubscribe’ button at the bottom of our emails or by sending a direct written request to us at chris@carolnunan.co.uk

 Contact form cookies

  • If you leave a comment on my site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

  • If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

  • When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select "Remember Me", your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

  • If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

  • Embedded content from other websites

  • Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

  • These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.


Analytics

With whom we share your data and for how long we retain it.

  • If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.

  • For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.


What are your rights over your data?

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.


How do I use your data?

I use your data in order to:

  • Enable me to fulfil your order for prints, other products, workshops or other services within my secure website, online and e-mail systems

  • Send you updates on exhibitions, workshops and other events I’m involved with, new prints and products, workshops and my work processes

  • Enable me to process orders, respond to enquiries related to an order and deal with any issues that may arise

  • Ensure you have a safe and enjoyable workshop by allowing me to make arrangements or adjustments necessary to cater for your needs or advise you on what you need to do

  • Ensure when that we provide your appropriate dietary requirements when you are attending a workshop

  • Reply to any enquiries you may have about my products, prints or services

  • Personalise your experience of my website

  • Monitor the use of my website and other online services

  • If you subscribe to my newsletter, I and our newsletter partner Mailchimp will hold your details securely

  • Ask you to complete surveys or invite you to take part in competitions

  • Analyse your use of my website and online services

  • Keep records of orders you place and communications in relation to those orders

  • Keep records of communications

  • Administer and protect my business and my website

  • Deliver relevant website content

  • Understand the effectiveness of my advertising

  • Carry out credit checks

  • Comply with any legal obligations I am subject to, or as required by a government authority

  • Obtain or maintain insurance policies

  • Manage my business

  • Obtain professional advice

What lawful grounds do I have for processing your data?

Under the UK Data Protection Regulations I am only allowed to process your data if I have lawful grounds for doing so.

My lawful grounds for doing so are: 

  • Customer Data you provide when placing an order with me that I have to hold in order to be able to fulfil said order. That data will allow me to keep you informed of updates to the product or service and to keep records of that contract (for tax purposes for example). Such processing is necessary in order to fulfil the contract and for my legitimate interests in informing you about updates, and record keeping and to establish, pursue or defend any legal claim as a responsible business operation.

  • Prospect Data we have obtained when you enquire about the products or services I offer (whether through my website or otherwise) and that I process in order to reply to your enquiry and keep records of it. Processing is necessary in order to take steps, at your request, prior to entering into a contract. It is also for my legitimate interests in record keeping and to establish, pursue or defend a legal claim.

  • Marketing Data I obtain when you sign up for my newsletter. In that process you told me what your marketing preferences are and you consent to me sending you details of my exhibitions, new prints, work processes, products and workshops. For the purposes of sending you marketing communications, this enables me to send you promotions like early bird discounts, competitions, prize draws, free giveaways, and to obtain your participation in surveys so that you can partake if you so wish. It also enables me to deliver relevant website content and advertisements to you and measure or understand the effectiveness of this advertising. My legitimate interests for processing in this case are:

  • To study how you, my customer and other users use my products/service

  • To develop them

  • To tailor them

  • To grow my business

  • To make decisions about my marketing strategy.


User Data I obtained through cookies on my website or other online services for the purposes of:

  • Operating my website

  • Ensuring relevant content is provided to you

  • Ensuring the security of my website

  • Maintaining back-ups of my website and/or databases

  • Enabling publication and administration of my website, other online services and business


My legitimate interests for processing user data in this case are to enable me to administer my website and business.

  • Technical Data including data about your use of my website and online services such as:

  • Your IP address

  • Details of your browser

  • Length of visit to pages on my website

  • Page views and navigation paths

  • The number of times you use my website

  • Time zone settings

  • Other technology on the devices you use to access my website

We process this data in order to:

  • Analyse your use of my website and other online services

  • Administer and protect my website and business

  • Deliver relevant website content and advertising

  • Understand the effectiveness thereof.

  • My legitimate interests and lawful grounds for processing technical data in this case enable me to properly administer my website and other online services, my business and to develop an effective marketing strategy in order to grow the business.


I process your data in order to comply with legal requirements, or as required by a government authority. The processing is necessary for compliance with a legal obligation to which I am subject.

In relation to keeping records, this processing is either necessary for compliance with a legal obligation that I am subject to or for my legitimate interests in responsible business operations or defending, pursuing, or establishing a legal claim.

In relation to obtaining professional advice and insurance, this processing is necessary for my legitimate interests in order to protect and grow my business.

The only Sensitive Data about you I collect is directly connected with those who participate in workshops. My lawful grounds for processing are my legitimate interests which are in this case to enable me to properly ensure your health and safety when you participate in a workshop.



How is your personal data collected?

I collect data about you when you provide data directly to me (for example by filling in forms on my website or other online services, by sending me emails, or by filling in paper forms at my studio or in-person events). I automatically collect certain data from you as you use my website by using cookies and similar technologies. 

I may receive data from third parties such as analytics providers like Google based outside the EU, providers of technical, payment and delivery services, fraud detection agencies and data brokers or aggregators.



Marketing Communications

Giving me your consent to send you marketing communication or my legitimate interests (namely to grow my business) gives me lawful grounds for processing your personal data.

Under the Privacy and Electronic Communication Regulations, I may only communicate with you if: 

  1. You made a purchase or asked for information from us about my prints, products or services or

  2. You agreed to receive my newsletter and in each case, you have not opted out since. 

You can still opt out of receiving marketing emails from me at any time. 

You can ask me to stop sending you marketing messages at any time by emailing me at carol@carolnunan.co.uk or using the unsubscribe link at the bottom of my newsletter.

If you opt out of receiving marketing communications this opt-out does not apply to personal data provided as a result of other transactions, such as purchases. 



Circumstances in which I am allowed to make disclosures of personal data

In certain circumstances I may have to share your personal data with the parties set out below:

  • Service providers who provide IT and system administration services

  • Professional advisers including lawyers, bankers, accountants, auditors and insurers

  • Government bodies that require me to report processing activities or otherwise disclose your personal date

  • Market researchers and fraud prevention agencies

  • Third parties to whom we sell, transfer or merge parts of my business or my assets.

I require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. I only allow third parties to process your data for specified purposes and in accordance with my instructions.

International transfers of data

I may share your personal data with a group of companies who manage my website, mailing list, financial service providers, analytics, or social media channels (e.g., Squarespace, MailChimp, PayPal, Stripe, iZettle, Google Analytics, Pinterest, Facebook and Instagram - Meta, LinkedIn) which involves transferring your data outside the European Economic Area (EEA).

We are all subject to the provisions of the UK Data Protect Law that protect your personal data. Where your data is transferred to third parties outside the EEA, we will ensure that certain safeguards are in place to ensure a similar degree of security for your personal data. As such:

  • We may transfer your personal data to countries that UK Data Protection has approved as providing an adequate level of protection for personal data by; or

  • If we use US-based providers that are part of the EU-US Privacy Sheila, we may transfer data to them, as they have the equivalent safeguards in place; or

  • Where we use certain service providers who are established outside the EEA, we may use specific contracts or codes of conduct or certification mechanisms approved by the UK Data Protection which give personal data the same protection it has in the UK and Europe.

If none of the above safeguards is available, we may request your explicit consent to the specific transfer. You will have the right to withdraw this consent at any time.


Cookie Policy

Performance cookies.

These cookies collect information about how visitors use the website, for instance which pages visitors go to most often, and if they get error messages from web pages. These cookies don’t collect information that identifies you, the visitor. All information these cookies collect is aggregated and therefore anonymous. It is only used to improve how the website works.

Functionality cookies.

These cookies allow the website to remember choices you make (such as your user name, language or the region you are in) and provide enhanced, more personal features. For instance, a website may be able to provide you with information local to you by storing in a cookie the region in which you are currently located. These cookies also remember changes you make to text size, fonts and other parts of web pages that you chose to customize, or to provide services you have asked for such as watching a video or commenting on a blog. The information these cookies collect may be anonymized. They cannot track your browsing activity on other websites.

Targeting cookies. 

These cookies are used to deliver adverts more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. They are usually placed by advertising networks with the website operator’s permission. I do not currently have any advertisers seeking my permission to advertise. Should any advertisers seek to do so they would need to be able to demonstrate a direct correlation between their products or services and the focus of my website which is my work and printmaking in general. Targeting cookies remember that you have visited a website and this information is shared with other organisations such as advertisers. Quite often targeting or advertising cookies will be linked to site functionality provided by the other organisation.