Privacy Policy
Last updated: 31 January 2026
This privacy policy explains how I collect, use, and protect your personal information when you visit this website or interact with my services. I am committed to protecting your privacy and handling your data in a transparent and lawful manner.
1. Who I Am
I am an independent artist based in the United Kingdom, creating and selling original paintings. This website is operated solely by me for the purpose of showcasing and selling my artwork.
Data Controller: Sasha Bride Haine
Contact: policy [at] sashabridehaine [dot] com
Location: United Kingdom
2. Information I Collect
2.1 Information You Provide Directly
When you interact with this website, you may choose to provide the following information:
- Newsletter Subscription: Your email address when you sign up for my newsletter via MailChimp
- Contact Forms: Your name, email address, and any other information you choose to include in your message
- Purchase Information: Details necessary to complete transactions and deliver artwork (name, email, delivery address, phone number)
2.2 Information Collected Automatically
When you visit this website, the following information may be collected automatically:
- Technical Data: IP address, browser type, operating system, and device information
- Usage Data: Pages visited, time spent on pages, links clicked, and navigation patterns
- Cookies: Small data files stored on your device (see Cookie Policy for details)
2.3 Third-Party Services
This website uses the following third-party services that may collect information:
- Google Fonts: Used to display typography. Google may collect usage data and IP addresses. See Google’s Privacy Policy
- MailChimp: Used for email newsletter distribution. MailChimp collects and processes email addresses and related subscription data. See MailChimp’s Privacy Policy
3. How I Use Your Information
I use your personal information for the following purposes:
- Newsletter Communications: To send you updates about new artwork, exhibitions, and news (only if you have subscribed)
- Transaction Processing: To process orders, arrange delivery, and provide customer service
- Communication: To respond to your enquiries and communicate about your requests or purchases
- Website Improvement: To understand how visitors use the site and improve its functionality
- Legal Compliance: To comply with legal obligations, such as tax and accounting requirements
4. Legal Basis for Processing (UK GDPR)
Under UK GDPR, I process your personal data on the following legal bases:
- Consent: When you sign up for the newsletter or contact me voluntarily
- Contract: When processing is necessary to fulfill a purchase or service you have requested
- Legitimate Interests: For website functionality and improvement, where not overridden by your privacy rights
- Legal Obligation: Where required by law (e.g., tax records)
5. How I Share Your Information
I do not sell or rent your personal information to third parties. I may share your information in the following limited circumstances:
- Service Providers: MailChimp for newsletter distribution, delivery companies for shipping artwork
- Payment Processors: To process payments securely
- Legal Requirements: If required by law or to protect legal rights
All third-party service providers are required to handle your data securely and only for the purposes specified.
6. International Data Transfers
Some service providers (such as MailChimp) may be based outside the UK or European Economic Area (EEA). When data is transferred internationally, I ensure that appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
7. How Long I Keep Your Information
I retain your personal information only for as long as necessary:
- Newsletter Subscribers: Until you unsubscribe
- Transaction Records: For 7 years as required by UK tax law
- Contact Enquiries: For up to 2 years unless ongoing correspondence is required
- Technical Data: Typically for up to 12 months
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data I hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal obligations)
- Restriction: Request that I limit how I use your data
- Portability: Request your data in a structured, commonly used format
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time (e.g., unsubscribe from newsletter)
To exercise any of these rights, please contact me at [Your Email Address].
9. Newsletter Unsubscribe
You can unsubscribe from my newsletter at any time by clicking the “unsubscribe” link in any email, or by contacting me directly. Your email address will be removed from the mailing list within 48 hours.
10. Security
I take appropriate technical and organisational measures to protect your personal information from unauthorised access, loss, or misuse. However, no internet transmission is completely secure, and I cannot guarantee absolute security.
11. Children’s Privacy
This website is not directed at children under 16. I do not knowingly collect personal information from children. If you believe a child has provided information to me, please contact me so I can delete it.
12. Changes to This Policy
I may update this privacy policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. Continued use of the website after changes constitutes acceptance of the updated policy.
13. Complaints
If you have concerns about how I handle your personal data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
ICO Website: ico.org.uk
Helpline: 0303 123 1113
14. Contact Me
If you have any questions about this privacy policy or how I handle your data, please contact me:
Email: policy [at] sashabridehaine [dot] com
Response Time: I aim to respond within 5 business days