Privacy Policy

Sculpture for Change (“we,” “us,” or “our”) is fully committed to the protection and confidentiality of your personal data, and we recognize the importance of safeguarding your privacy. This Privacy Policy outlines how your information is collected, used, disclosed, and protected when interacting with our website, sculptureforchange.com. We process all personal data in accordance with the applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the California Consumer Privacy Act of 2018 (“CCPA”).

1. Commitment to Privacy and Data Protection

We are dedicated to maintaining robust privacy protections and providing you with transparency regarding how your data is handled. Your trust is vital to us, and we take precautions to ensure that your personal data is secure, used fairly, and processed in line with legal obligations.

2. Scope of Policy and Data Controller Role

This Privacy Policy applies to all users who interact with sculptureforchange.com and covers all processing of personal information collected via our website, services, and related communication channels. Sculpture for Change is the data controller of the personal data you provide through the website and may also act as a data processor in certain arrangements depending on context. The data controller can be contacted at [email protected].

3. Categories of Personal Data We Process

We may collect and process the following categories of personal data:

a. Usage Data – Includes information about your interactions with the website such as IP address, browser type, pages visited, date/time stamps, session duration, referring/exit URLs, and general site navigation behavior.

b. Account Data – Includes personal identifiers such as name, email address, postal address, and phone number that you provide when creating a user profile or submitting a form via sculptureforchange.com.

c. Profile Data – Includes information related to your interests, purchase history, preferences, demographic information, and behavior patterns relevant to product offerings.

d. Communication Data – Includes information generated through correspondence with us including support queries, feedback, and previous interactions such as email exchanges and contact form entries.

e. Technical Data – Includes device-level identifiers, internet services used, system configurations, geolocation (where enabled), operating system, browser plugins, and system performance data.

f. Transaction Data – Includes information about payments made via the website, delivery addresses, transaction history, billing records, and order fulfillment data. No full payment card data is stored by us.

g. Preference Data – Includes marketing preferences, user consents, product categories of interest, newsletter sign-ups, and survey or campaign responses.

4. Legal Bases for Processing

We process your personal data under the following legal bases:

– Consent: When you have affirmatively granted us permission, such as subscribing to a newsletter or accepting cookies.
– Contractual necessity: When processing is required to provide the services you have requested or contracted for, including order fulfillment and account services.
– Legal obligation: Where processing is required to comply with laws or regulatory duties.
– Legitimate interest: Where processing is necessary for our legitimate business interests and not overridden by your fundamental rights, such as improving website usability, preventing fraud, or developing new offerings.

5. Your Rights Under Data Protection Laws

Depending on your location and applicable data protection regime, you hold the following rights:

– Right of Access: You have the right to request a copy of the personal data we hold about you.
– Right to Rectification: You may request that we correct or update incomplete or inaccurate data.
– Right to Erasure (“Right to be Forgotten”): You may request deletion of your data where justified.
– Right to Restriction: You may ask us to restrict processing under certain circumstances.
– Right to Data Portability: Where applicable, you may request a copy of your personal data in a structured, commonly used, and machine-readable format.
– Right to Object: You can object to our processing of your data under certain lawful bases, such as for direct marketing.
– Rights under CCPA: California residents have additional rights to know, access, and delete their personal information, and to direct us not to “sell” their personal data.
To exercise these rights, contact us at [email protected].

6. Security Measures

We implement advanced security controls designed to protect your data, including encryption (for transmission and storage), access restrictions, firewalls, multi-factor authentication, routine security assessments, and secure backups. Our personnel receive regular privacy training to ensure that your data is handled responsibly and in accordance with data protection best practices.

7. International Data Transfers

Where your personal data is transferred outside the European Economic Area or other relevant jurisdictions, we ensure an adequate level of protection is maintained. This is achieved through standard contractual clauses approved by the European Commission, adequacy decisions, or appropriate technical and organizational safeguards. By using sculptureforchange.com, you understand and agree that your data may be transferred to and processed in jurisdictions that may not offer the same level of data protection as your home country.

8. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including satisfying legal, regulatory, tax, accounting, or reporting requirements. Retention periods may include:

– Usage and Technical Data: Up to 12 months for analytics and security.
– Account and Transaction Data: Retained for as long as your account remains active and up to 7 years thereafter in compliance with tax and legal obligations.
– Communication Records: Retained for up to 3 years following last interaction.
– Marketing Preferences: Retained until consent is withdrawn or until opt-out.
After expiry of these periods, data is securely deleted or anonymized.

9. Cookie Policy

We use cookies and similar tracking technologies on sculptureforchange.com to enhance user experience. Categories of cookies include:

– Essential Cookies: Required for basic functionality of the website (e.g., logins, cart management).
– Functional Cookies: Enable personalization and memory of preferences.
– Analytics Cookies: Help us understand how users interact with the site (e.g., Google Analytics).
– Performance Cookies: Assist in assessing overall performance, responsiveness, and usability.

10. Cookie Management and Compliance

Upon your first visit to sculptureforchange.com, you will be prompted to manage your cookie preferences in accordance with GDPR and CCPA regulations. You have the option to accept or reject non-essential cookies. You can also change cookie settings through your browser or device preferences at any time. Cookies that are not strictly necessary will only be set with your explicit consent. Opt-out mechanisms are provided for residents of jurisdictions requiring affirmative consumer rights, such as under CCPA.

11. Protection of Children’s Data

Sculpture for Change does not knowingly collect or solicit personal data from individuals under the age of 13. If we become aware that personal data from a child under 13 has been collected without verifiable parental consent, such data will be promptly deleted. Parents or legal guardians may contact us at [email protected] to address any concerns regarding child data.

12. Policy Updates and Notifications

We reserve the right to update this Privacy Policy to reflect changes in legal requirements, industry practices, or enhancements to our services. We encourage users to periodically review this page to stay informed. When material changes are made, we will provide reasonable notice through the website or direct communication where appropriate.

13. Contact Us

If you have any questions regarding this Privacy Policy, your personal data, or wish to exercise any of your rights under applicable data protection laws, please contact us at:

Email: [email protected]

We are committed to full compliance with global privacy legislation and are available to address any privacy concerns you may have.