1. Our Commitment
AGCS LIMITED t/a ARTISTEHUB Systems is committed to ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take the protection of personal data seriously and have implemented appropriate measures to safeguard the information you entrust to us.
2. Data Controller Details
- Company: AGCS LIMITED t/a ARTISTEHUB Systems
- Company Registration: 10778479
- Contact: [email protected]
3. Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contractual necessity: To fulfil service requests you have placed with us.
- Legitimate interests: To operate and improve the Artiste Works platform, communicate with you about your requests, and ensure platform security.
- Legal obligation: To comply with tax, accounting, and regulatory requirements.
- Consent: Where you have explicitly opted in for specific processing activities.
4. Data Minimisation
We collect only the personal data necessary to fulfil your service requests and operate the platform. We do not collect excessive or unnecessary data.
5. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS).
- Secure password hashing using bcrypt.
- Secure payment processing via Stripe (PCI DSS compliant).
- Access controls limiting data access to authorised personnel only.
6. Your Rights Under UK GDPR
As a data subject, you have the following rights:
- Right of access (Article 15): Request a copy of the personal data we hold about you.
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your personal data, subject to legal retention requirements.
- Right to restrict processing (Article 18): Request limitation of how we use your data.
- Right to data portability (Article 20): Receive your data in a structured, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
7. Data Subject Access Requests
To exercise any of your rights, please email us at [email protected]. We will respond to your request within one calendar month, as required by UK GDPR.
8. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and inform affected individuals without undue delay.
9. International Transfers
Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements, including Standard Contractual Clauses where applicable.
10. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.