Privacy policy
Privacy Policy
Last updated: March 2026
1. Who We Are
The Artist Studio ("we", "us", "our") is a creative agency based in Sherborne, Dorset. We provide digital marketing, web design, branding, social media management, content creation, photography, videography, and advertising services.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller.
Contact:
Email: hello@theartiststudio.agency
Phone: 07706 468581
Address: South Street, Sherborne, Dorset, DT9 3LU
2. What Information We Collect
We may collect and process the following personal data:
Information you provide to us directly:
- Name, email address, phone number, and business details when you contact us via our website, email, phone, or social media
- Information submitted through enquiry forms, booking forms, or newsletter sign-ups on our website
- Correspondence and communications between us
- Payment and billing information when you engage our services
- Testimonials or reviews you provide with your consent
Information collected automatically when you visit our website:
- IP address and approximate location
- Browser type and version, device type, and operating system
- Pages visited, time spent on pages, and referring website
- Cookie data and similar tracking technologies (see Section 7)
Information collected through our advertising and marketing activities:
- Data collected via advertising platforms (such as Meta Ads, Google Ads, TikTok Ads, and similar platforms) when you interact with our advertisements
- Engagement data from social media platforms where we maintain a presence
- Email open rates, click-through rates, and engagement data from marketing emails
3. How We Use Your Information
We use your personal data for the following purposes:
- To respond to your enquiries and provide information about our services
- To deliver our services including project management, invoicing, and client communications
- To send marketing communications including newsletters, offers, and updates about our work (only where you have opted in or where we have a legitimate interest to do so)
- To run advertising campaigns across platforms including Google, Meta (Facebook/Instagram), TikTok, and other digital advertising networks
- To manage and improve our website including analysing how visitors use our site, troubleshooting issues, and improving user experience
- To create and manage retargeting/remarketing audiences based on website visits and ad interactions
- To measure the effectiveness of our advertising campaigns and marketing activities
- To comply with legal obligations and protect our legitimate business interests
4. Lawful Basis for Processing
Under UK GDPR, we rely on the following lawful bases:
- Consent — where you have given clear consent for us to process your personal data for a specific purpose (e.g. subscribing to our newsletter, accepting non-essential cookies)
- Contract — where processing is necessary to fulfil a contract with you or to take steps at your request before entering into a contract
- Legitimate interests — where processing is necessary for our legitimate business interests (e.g. direct marketing to existing clients, website analytics, fraud prevention) provided these do not override your rights and freedoms
- Legal obligation — where processing is necessary to comply with a legal obligation
5. Advertising & Third-Party Platforms
We run advertising campaigns across various digital platforms. When you interact with our ads or visit our website after seeing an ad, the following may apply:
Advertising platforms we use may include:
- Google Ads / Google Analytics
- Meta (Facebook & Instagram) Ads
- TikTok Ads
- LinkedIn Ads
- Pinterest Ads
- Other platforms as required
These platforms use their own cookies, pixels, and tracking technologies to serve, measure, and optimise ads. When you interact with our ads, the relevant platform may collect data in accordance with their own privacy policy. We encourage you to review the privacy policies of these platforms directly.
Retargeting / Remarketing:We may use retargeting technologies to show relevant ads to people who have previously visited our website or interacted with our content. You can opt out of retargeting through the cookie preferences on our website or through the ad settings of the relevant platform.
Custom and Lookalike Audiences:We may upload hashed customer data (such as email addresses) to advertising platforms to create custom audiences or find similar audiences. This data is encrypted and used solely for ad targeting purposes.
6. Who We Share Your Data With
We do not sell your personal data. We may share your data with:
- Service providers who help us operate our business, including web hosting providers, email marketing platforms, accounting software, and payment processors
- Advertising platforms as described in Section 5
- Analytics providers such as Google Analytics
- Professional advisors including accountants and legal advisors where necessary
- Law enforcement or regulatory authorities where required by law
All third-party service providers are required to process your data in accordance with applicable data protection law and only on our instructions.
7. Cookies & Tracking Technologies
Our website uses cookies and similar technologies. Cookies are small text files placed on your device when you visit our website.
Types of cookies we use:
Strictly Necessary Cookies — Required for our website to function properly (e.g. session management, security). These do not require your consent.
Analytics Cookies — Help us understand how visitors interact with our website by collecting and reporting information anonymously (e.g. Google Analytics). These require your consent.
Marketing / Advertising Cookies — Used to track visitors across websites to display relevant advertisements and measure ad campaign effectiveness. These include pixels and tags from platforms such as Meta, Google, and TikTok. These require your consent.
Functional Cookies — Enable enhanced functionality and personalisation (e.g. remembering your preferences). These require your consent.
Managing your cookie preferences:When you first visit our website, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies. You can change your preferences at any time by [clicking here / accessing the cookie settings in the website footer].
You can also manage cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Client project data: For the duration of our working relationship and up to 6 years afterwards for legal and accounting purposes
- Enquiry data: Up to 2 years from the date of your last enquiry, unless you become a client
- Marketing data: Until you unsubscribe or withdraw consent
- Cookie and analytics data: In accordance with the retention settings of the relevant platform (typically 14–26 months)
- Financial records: Up to 7 years as required by HMRC
9. Your Rights
Under UK GDPR, you have the following rights:
- Right of access — to request a copy of the personal data we hold about you
- Right to rectification — to request correction of inaccurate or incomplete data
- Right to erasure — to request deletion of your personal data in certain circumstances
- Right to restrict processing — to request that we limit how we use your data
- Right to data portability — to request your data in a structured, commonly used format
- Right to object — to object to processing based on legitimate interests or for direct marketing purposes
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us at hello@theartiststudio.agency. We will respond within one month.
10. Marketing Communications
We may send you marketing communications where you have opted in or where we have a legitimate interest to contact you (e.g. you are an existing client).
Every marketing email we send includes an unsubscribe link. You can also contact us directly to opt out at any time.
11. Children's Privacy
Our services are not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will take steps to delete it promptly.
12. International Transfers
Some of the third-party services we use (e.g. Google, Meta) may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions, to protect your data in accordance with UK GDPR.
13. Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. However, no method of transmission over the internet or electronic storage is completely secure.
14. Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
15. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Website: ico.org.uk
Phone: 0303 123 1113
This privacy policy applies to theartiststudio.agency and all services provided by The Artist Studio.