Effective Date: 15.01.2026

This Privacy Policy explains how personal information is collected, used, and protected when you visit or interact with this website, https://leighcurtis.co.uk. This site is operated by Leigh Curtis, a UK-based artist.

1. Who We Are

Leigh Curtis is the sole owner and operator of this website. For any data protection queries, you can contact Leigh at leighkcurtis@hotmail.com.

2. Personal Data We Collect

We collect and process the following personal data:

  • Name and email address when you subscribe to our mailing list through the contact form
  • Comments data including your IP address and browser user agent (used for spam detection)
  • Technical and analytics data from cookies and Google Analytics, including browsing activity and device/browser information

3. Mailing List

If you subscribe to the mailing list, we will only use your name and email address to send occasional updates (3–4 per year) about exhibitions and related news.

  • You opt in by clicking a subscribe button
  • You can unsubscribe at any time using the link provided in every email
  • Mailing list data is managed through MailerLite, and only Leigh Curtis has access to subscriber information

4. Legal Basis for Processing

We process your data under the following lawful bases as defined by UK GDPR:

  • Consent – for email subscriptions and marketing
  • Legitimate interests – to maintain and protect the website and prevent spam
  • Legal obligation – where applicable for record keeping or compliance

5. Cookies and Analytics

This site uses cookies to:

  • Save comment details (name, email, website) for your convenience
  • Recognize returning users and track usage with Google Analytics

You may disable cookies in your browser settings.

6. Comments

If you leave a comment:

  • We collect the data entered, your IP address, and browser user agent
  • An anonymized hash of your email may be sent to Gravatar to check for an associated profile image
  • Your profile picture (if any) may be displayed alongside your comment

7. Embedded Content

Pages may contain embedded content (e.g. videos or articles from other websites). These sites may collect data about you, use cookies, and track your interaction as if you visited them directly.

8. Media Uploads

Avoid uploading images that contain embedded location data (EXIF GPS). Visitors can extract this data from images on the website.

9. Data Sharing

We do not sell or rent your personal data. We only share it with trusted service providers necessary to operate the website and mailing list, such as:

  • MailerLite (for managing emails)
  • Web hosting and spam detection services

These providers are contractually bound to handle your data securely.

10. International Data Transfers

We do not knowingly transfer your personal data outside the UK or European Economic Area (EEA). Where service providers host data abroad, we ensure appropriate safeguards are in place (e.g. standard contractual clauses).

11. Data Retention

  • Comments and their metadata are retained indefinitely
  • Email subscription data is retained until you unsubscribe or request deletion
  • Analytics data may be stored up to 26 months

12. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccuracies in your data
  • Request deletion of your data
  • Withdraw consent at any time
  • Object to or restrict certain data uses

To exercise your rights, contact leighkcurtis@hotmail.com.

13. Security

We take appropriate technical and organizational measures to protect your data from unauthorized access, loss, or misuse.

14. Changes to This Policy

We may update this Privacy Policy occasionally. The most recent version will always be posted on this page.