Privacy Policy for RiqArt.com

We maintain an unwavering dedication to protecting and preserving all personal data provided by our website visitors and service users, implementing robust and comprehensive security measures throughout our services and operations.

This policy applies where we are acting as a data controller with respect to the personal data of our website visitors and service users; in other words, where we determine the purposes and means of the processing of that personal data. In this role, we are responsible for ensuring the proper handling, processing, and protection of all personal data submitted through our website.

We may process usage data (“usage data”), which comprehensively includes browser type, operating system, page views, navigation patterns, timestamps, referral sources, length of visit, buttons clicked, and scroll depth. This information is collected through server logs, cookies, and analytics tools and may include user interaction patterns, content preferences, and device information. The source of this data is our analytics software and server monitoring systems. We process this information for several important purposes, including improving website performance, enhancing user experience, analyzing content effectiveness, and optimizing site navigation, which enables us to deliver better service, personalize content, and make informed design decisions. The legal basis for this processing is our legitimate interests in monitoring and improving our website and services.

We may process account data (“account data”), which comprehensively includes email address, username, password hash, account settings, notification preferences, and account creation date. This information is collected through registration forms, account updates, and user preferences and may include communication preferences, security settings, and profile visibility options. The source of this data is direct user input during account creation and management. We process this information for account authentication, security maintenance, user communication, and service delivery, which enables us to provide secure access, personalized experiences, and account management capabilities. The legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.

We may process profile data (“profile data”), which comprehensively includes display name, biography, profile picture, artistic interests, portfolio links, and social media handles. This information is collected through profile creation forms, portfolio submissions, and profile updates and may include artistic preferences, creative accomplishments, and professional connections. The source of this data is user-provided information and profile customization. We process this information for community engagement, artistic showcase, networking opportunities, and content curation, which enables us to facilitate connections, promote artistic work, and enhance community interaction. The legal basis for this processing is our legitimate interests in operating and promoting our artistic platform.

You have the right to access your personal data, which means you can obtain confirmation about whether we process your personal data and receive a copy of that data in a structured format. This includes the ability to view all personal information we hold about you, understand how we use your data, and confirm the lawfulness of processing. To exercise this right, you can submit a formal request through our dedicated data access portal or contact our privacy team at [email protected]. We will respond within 30 days and may require government-issued identification, proof of address, and account verification to verify your identity.

You have the right to rectification, which means you can request corrections or updates to any inaccurate or incomplete personal data we hold about you. This includes the ability to update account information, correct profile details, and modify usage preferences. To exercise this right, you can use our account settings panel or submit a correction request through our support system. We will respond within 15 days and may require account password verification, email confirmation, and specific detail validation to verify your identity.

You have the right to erasure (right to be forgotten), which means you can request the deletion of your personal data when there is no compelling reason for its continued processing. This includes the ability to delete your account, remove personal information, and withdraw consent for data processing. To exercise this right, you can initiate account deletion through your account settings or submit an erasure request to our privacy team. We will respond within 30 days and may require account password verification, email confirmation, and identity verification documents to verify your identity.

You have the right to restrict processing, which means you can limit the way we use your personal data when you have particular concerns about its accuracy or use. This includes the ability to pause data processing, limit data usage, and temporarily block profile visibility. To exercise this right, you can adjust your privacy settings or submit a restriction request through our support system. We will respond within 15 days and may require two-factor authentication, account verification, and specific processing concerns to verify your identity.

You have the right to data portability, which means you can obtain and reuse your personal data across different services for your own purposes. This includes the ability to download your data, transfer information to another platform, and receive data in a machine-readable format. To exercise this right, you can use our data export tool or submit a portability request through our privacy dashboard. We will respond within 30 days and may require account ownership verification, email confirmation, and identity validation to verify your identity.Data Processing and Security Measures

We process Service Data which includes user profiles, artwork submissions, gallery preferences, and collaborative project information. This processing involves secure storage, analysis, and categorization, enabling us to deliver personalized art experiences and community features. For example, in the context of art, this includes curating personalized galleries and matching artists with potential collaborators. The legal basis for this processing is legitimate interest and contractual necessity, specifically to provide our core art platform services and maintain a vibrant creative community.

We process Technical Data which includes device information, browsing patterns, and interaction metrics. This processing involves automated collection and analysis, enabling us to optimize platform performance and user experience. For example, in the context of art, this includes adapting image resolution and loading times for optimal artwork display. The legal basis for this processing is legitimate interest, specifically to ensure technical functionality and enhance user experience.

We process Communication Data which includes messages, comments, and feedback on artworks. This processing involves storage, moderation, and delivery, enabling us to facilitate community interaction and artistic discourse. For example, in the context of art, this includes managing artwork critiques and collaborative discussions. The legal basis for this processing is consent and legitimate interest, specifically to maintain community engagement and artistic exchange.

We process Transaction Data which includes purchase history, commissions, and payment information. This processing involves secure payment processing and order management, enabling us to facilitate art sales and commissions. For example, in the context of art, this includes managing artwork purchases and artist payments. The legal basis for this processing is contractual necessity and legal obligation, specifically to complete transactions and maintain financial records.

We process Preference Data which includes artistic interests, favorite styles, and viewing habits. This processing involves analysis and personalization, enabling us to provide tailored content and recommendations. For example, in the context of art, this includes suggesting relevant artworks and artists. The legal basis for this processing is legitimate interest and consent, specifically to enhance user experience and content discovery.

Security Implementation

Our comprehensive encryption protocols ensure end-to-end protection of your data, incorporating industry-standard algorithms and regular security updates to maintain data integrity. This includes regular security assessments and penetration testing by qualified professionals.

We implement multi-layered security infrastructure, including advanced firewalls and intrusion detection systems that continuously monitor for and prevent unauthorized access attempts. This infrastructure undergoes regular updates and enhancements.

Access to personal data is strictly controlled through role-based permissions, multi-factor authentication, and detailed access logs. We maintain comprehensive audit trails of all data access and modifications.

Our continuous monitoring systems provide real-time threat detection and automated response protocols, ensuring immediate action against potential security threats.

We maintain comprehensive backup procedures with encrypted offsite storage and regular recovery testing, ensuring data availability and integrity.

All staff undergo regular security awareness training and must comply with detailed data protection protocols, including specific training for handling sensitive data.

International Data Transfers

We may transfer your personal data to countries outside your jurisdiction. These transfers are protected by appropriate safeguards, including Standard Contractual Clauses, Binding Corporate Rules, and adequacy decisions. Each international transfer is conducted under strict protocols that ensure:
– Adequate data protection standards
– Compliant processing procedures
– Enforceable data subject rights
– Effective legal remedies

International transfers are protected by ISO 27001, GDPR standards, and Privacy Shield principles, ensuring compliance with international data protection regulations. We implement additional measures including:
– Regular compliance audits
– Data protection impact assessments
– Documented transfer mechanisms
– Continuous monitoring procedures

Regarding international transfers, you maintain specific rights including:
– Right to information about transfers
– Right to object to transfers
– Right to withdraw consent
– Right to data protection guarantees

Data Retention

We maintain specific retention periods for different data categories:

Account Information: 2 years after account closure to maintain service continuity
Usage Data: 12 months to analyze platform trends and improve services
Transaction Records: 7 years to comply with financial regulations
Communication History: 3 years to maintain community engagement records
Technical Logs: 6 months for security and performance optimization

These retention periods are determined by:
– Legal requirements
– Business purposes
– Technical necessities
– User preferences

Special circumstances affecting retention:
– Legal obligations
– Dispute resolution
– Security investigationsCookie Policy for RiqArt.com

Essential cookies serve fundamental functions for our website’s core operations. These cookies process authentication data, security tokens, and session information to enable basic site functionality. In our art context, these cookies maintain your login status while browsing galleries, ensure secure transactions when purchasing artwork, and preserve your current viewing preferences. We specifically use them for user authentication, security measures, basic site operations, session management, and technical stability.

Functional cookies enhance your experience by remembering your preferences and artistic interests. These cookies process user interface selections and regional preferences to deliver a personalized experience. For example, they remember your preferred art categories, gallery viewing layouts, and creative workspace settings. They enable language preferences, region-specific content, user interface customization, feature optimization, and personalized settings.

Analytics cookies help us understand how visitors interact with our artistic content. These cookies collect anonymous data about gallery interactions, artwork viewing patterns, and creative tool usage. On RiqArt.com, they track which art pieces receive the most attention, how users navigate through collections, and which creative features are most valuable. They monitor page interactions, navigation patterns, feature usage, session duration, and user preferences.

Performance cookies assess and improve our platform’s operation by monitoring technical metrics. These cookies process loading times, server response data, and content delivery efficiency. For our art platform, they ensure smooth gallery loading, optimal image rendering, and seamless creative tool functionality. They focus on monitoring site speed, identifying technical issues, optimizing content delivery, analyzing user experience, and tracking system performance.

Cookie Management

You can control your cookie preferences through your browser settings, our cookie consent tool, privacy preferences center, and account settings. We respect your right to choose which cookies you accept, while ensuring essential functions remain accessible.

GDPR Compliance

For EU residents, we maintain strict data protection standards including explicit consent mechanisms, data minimization practices, purpose limitation protocols, storage limitations, and complete processing transparency. All art-related data processing adheres to these principles.

CCPA Compliance

California residents are entitled to specific rights regarding their personal information, including the right to know about collected information, delete personal data, opt-out of data sales, receive non-discriminatory service, and access collected information.

COPPA Compliance

For users under 13, we implement strict protection measures including age verification requirements, parental consent procedures, limited data collection protocols, special protection measures, and comprehensive parental access rights to ensure safe engagement with our artistic platform.

Updates and Changes

We maintain our policy through regular review procedures, user notifications, consent renewal when required, clear change documentation, and continuous compliance monitoring to ensure alignment with current practices and regulations.

Contact Information

For privacy-related inquiries:
Primary Contact: [email protected]
Response Time: Within 48 hours
Verification Required: For data-related requests
Available Support: Privacy concerns, data requests, rights exercise

This policy was created specifically for riqart.com and covers all associated services within the art industry.