Last updated: 17 June 2026

This Privacy Policy explains how Peace & Colour Gallery (“we”, “us”, or “our”) collects, uses, shares, and protects your personal information when you visit https://peaceandcolour.com (the “Website”), enquire about or purchase artwork, or otherwise interact with us.

We are committed to protecting your privacy and handling your data in an open and transparent manner, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are (Data Controller)

The data controller responsible for your personal data is:

2. The information we collect

We collect and process the following categories of personal data:

Information you give us

Information we collect automatically

We do not knowingly collect any special category data (such as data about health, race, religion, or political opinions), and we ask that you do not send such information to us.

3. How and why we use your information (lawful bases)

Under UK GDPR we must have a lawful basis for processing your data. We rely on the following bases:

PurposeLawful basis
Responding to your enquiries and providing customer supportLegitimate interests; steps prior to entering a contract
Processing and fulfilling an artwork purchase, commission, or deliveryPerformance of a contract
Sending order updates and service messagesPerformance of a contract
Sending marketing emails or newsletters (where offered)Consent (you can withdraw at any time)
Operating, securing, and improving the WebsiteLegitimate interests
Analytics and understanding how the site is usedConsent (via cookie controls)
Meeting legal, accounting, and tax obligationsLegal obligation
Detecting, preventing, and addressing fraud or technical issuesLegitimate interests; legal obligation

Where we rely on legitimate interests, we have assessed that our use of your data is proportionate and does not override your rights and freedoms.

4. Marketing communications

We will only send you marketing communications where you have asked us to or otherwise consented. You can opt out at any time by clicking the “unsubscribe” link in any email, or by contacting us using the details in section 1. Opting out of marketing will not affect service messages relating to an order or enquiry.

5. How long we keep your data

We keep your personal data only for as long as necessary for the purposes set out in this policy:

6. Who we share your data with

We do not sell your personal data. We share it only with trusted third parties who help us run our business, and only to the extent necessary. These may include:

All our processors are required by contract to keep your data secure and to use it only for the purposes we specify.

7. International transfers

Some of our service providers may be based outside the UK. Where we transfer your personal data outside the UK, we ensure a similar degree of protection by relying on an adequacy decision (“adequacy regulations”) or appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses. You can contact us for more information about these safeguards.

8. Cookies and tracking

Cookies are small text files stored on your device when you visit a website. We use cookies and similar technologies to operate the site, remember your preferences, keep it secure, and understand how it is used.

You can manage or refuse cookies through your browser settings, and through any cookie banner shown on our Website. If you disable certain cookies, some parts of the site may not work properly.

Analytics

We may use Google Analytics, a service provided by Google, to analyse Website traffic and usage. Google may process this data on our behalf. You can opt out across all websites by installing the Google Analytics opt-out browser add-on. For details of how Google handles data, see Google’s Privacy Policy.

9. Your rights

Under UK data protection law, you have the right to:

To exercise any of these rights, contact us using the details in section 1. We will respond within one month. There is normally no charge.

10. How we protect your data

We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse, including secure hosting, encryption of data in transit (HTTPS), access controls, and regular review of our security practices. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

11. Links to other websites

Our Website may contain links to third-party websites, including artists’ pages or social media. We are not responsible for the privacy practices or content of those sites, and we encourage you to read their privacy policies.

12. Children’s privacy

Our Website and services are not directed at children under the age of 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. Where changes are significant, we will provide a more prominent notice. Please review this page periodically.

14. How to contact us or make a complaint

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

You also have the right to lodge a complaint with the UK’s data protection regulator, the Information Commissioner’s Office (ICO), at any time:

We would, however, appreciate the chance to address your concerns directly before you approach the ICO.