Privacy Policy
Last Updated: October 9, 2025
1. Introduction
Welcome to Express My Hart.
We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your personal information when you visit our website www.expressmyhart.co.uk (the “Site”), purchase or download digital artwork, or otherwise use our services (the “Services”).
By using our Site, you agree to the practices described in this Privacy Policy.
2. Who We Are
Express My Hart is a UK-based digital arts platform that allows users to purchase, sell, and download digital artwork.
Data Controller:
Express My Hart
Website: www.expressmyhart.co.uk
Email: privacy@expressmyhart.co.uk
We are responsible for determining how your personal information is collected and used under UK GDPR.
3. Information We Collect
We collect the following categories of personal information:
a. Information You Provide to Us
Account Details: Name, email address, password, and other account information.
Payment Details: Billing address and payment confirmation (handled securely by third-party processors; we do not store full card details).
Communications: Messages or enquiries you send to us.
Artist Submissions: If you upload or sell digital artwork, we may collect artwork files, titles, and associated metadata.
b. Information Automatically Collected
When you visit our Site, we automatically collect:
Technical Data: IP address, browser type, operating system, device identifiers, and referral URLs.
Usage Data: Pages visited, downloads, time spent on the Site, and interaction details.
Cookies and Tracking Data: We use cookies and analytics tools (e.g., Google Analytics) to improve performance and personalise your experience.
4. How We Use Your Information
We use your personal information to:
Provide and operate our digital art platform;
Process purchases and deliver downloads;
Manage your account and provide customer support;
Send important service updates, notifications, and marketing emails (you can opt out anytime);
Improve our Site, products, and user experience;
Detect and prevent fraud or unauthorised activity;
Comply with legal obligations and resolve disputes.
5. Legal Basis for Processing (UK GDPR)
We process your data under the following lawful bases:
Contractual Necessity: To provide our Services and fulfil your purchases.
Consent: For marketing communications and certain analytics activities.
Legal Obligation: To comply with applicable laws and tax requirements.
Legitimate Interests: To maintain and improve our Services, prevent abuse, and protect users.
6. Sharing Your Information
We do not sell or rent your personal data.
We may share information with:
Service Providers: Trusted partners who assist with hosting, payment processing, analytics, and email communications.
Artists/Contributors: When you purchase digital artwork, limited information (e.g., username or transaction reference) may be shared for licensing purposes.
Legal Authorities: When required by law, regulation, or legal process.
Business Transfers: In the event of a merger, acquisition, or reorganisation.
All third-party service providers are required to handle your information securely and in compliance with UK GDPR.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to:
Enable core website functionality;
Remember your preferences;
Analyse traffic and improve performance;
Personalise recommendations.
You can manage or disable cookies in your browser settings. For more information, please see our Cookie Policy (if applicable).
8. Data Security
We use appropriate technical and organisational measures to protect your information against loss, misuse, or unauthorised access.
All sensitive transactions are protected using SSL (Secure Socket Layer) encryption.
However, no internet transmission is completely secure, and we cannot guarantee absolute security.
9. Data Retention
We retain personal data only as long as necessary to:
Provide Services and support;
Comply with legal, tax, and accounting obligations;
Resolve disputes and enforce agreements.
After this period, data will be securely deleted or anonymised.
10. International Data Transfers
Your personal data may be transferred and processed outside the United Kingdom (for example, by cloud service providers).
When this occurs, we ensure that appropriate safeguards are in place — such as UK Government-approved standard contractual clauses — to protect your information.
11. Your Data Protection Rights
Under the UK GDPR, you have the right to:
Access a copy of your personal data;
Rectify inaccurate or incomplete information;
Erase your data (“right to be forgotten”);
Restrict or object to certain processing;
Data portability, allowing you to obtain and reuse your data;
Withdraw consent at any time (for activities based on consent).
To exercise any of these rights, please contact privacy@expressmyhart.co.uk.
We may need to verify your identity before processing your request.
12. Children’s Privacy
Our Services are not directed at children under 16.
We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us, and we will delete it promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
The updated version will be posted on this page with a revised “Last Updated” date.
Your continued use of our Services after any changes indicates your acceptance of the new terms.
14. Contact Us
If you have any questions, concerns, or complaints regarding this Privacy Policy or our data handling practices, please contact us at:
Express My Hart
📧 privacy@expressmyhart.co.uk
🌐 www.expressmyhart.co.uk
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk.