NATALI DEUS UNIVERSE

Privacy Policy

Effective Date: January 1, 2025

Last Updated: November 30, 2025

Natali Deus Universe ("we," "our," or "us") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.natalideusuniverse.com (the "Website"), which serves as the personal online portfolio and gallery of international artist Natali Deus Universe.

This Privacy Policy complies with the General Data Protection Regulation (GDPR) (EU) 2016/679, the California Consumer Privacy Act (CCPA) as amended, the Personal Information Protection and Electronic Documents Act (PIPEDA) (Canada), and other applicable international data protection laws effective in 2025.

By using our Website, you acknowledge that you have read and understood this Privacy Policy.

Consent for Data Processing: When you submit information through our contact form, you provide explicit consent for us to process your personal information for the purposes described in this Privacy Policy. You may withdraw your consent at any time by contacting us at hello@natalideusuniverse.com.

1. Information We Collect

1.1 Personal Information You Provide

We collect personal information that you voluntarily provide to us when you:

  • Contact us through our contact form or email
  • Make an inquiry about artworks or commission requests
  • Request information about exhibitions, events, or the artist's work

This information may include:

  • Name (first name and last name)
  • Email address
  • Phone number (optional, if provided)
  • Subject and message content
  • Any other information you choose to provide in your inquiry

Purchase and Commission Requests: When you contact us through the contact form to inquire about purchasing artwork or commissioning a piece, we use the information you provide to process your request. If you proceed with a purchase, we will provide you with a secure payment link to complete the transaction through a trusted third-party payment processor. We do not directly process or store payment card information on this Website.

1.2 Automatically Collected Information

When you visit our Website, we automatically collect certain information about your device and browsing behavior, including:

  • IP address
  • Browser type and version
  • Operating system
  • Referring website addresses
  • Pages viewed and time spent on pages
  • Clickstream data
  • Device identifiers
  • Cookies and similar tracking technologies (see Section 6)

1.3 Cookies and Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to enhance your experience, analyze usage patterns, and improve our services. You can control cookie preferences through your browser settings.

2. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), we process your personal data based on the following legal grounds:

  • Consent: When you provide explicit consent for specific processing activities
  • Contractual Necessity: To fulfill our contractual obligations to you
  • Legal Obligation: To comply with applicable laws and regulations
  • Legitimate Interests: For our legitimate business interests, such as website security, fraud prevention, and improving our services

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To respond to your inquiries, requests, and provide support regarding the artist's work
  • To process and fulfill commission requests and artwork inquiries
  • To improve and optimize our Website and online portfolio
  • To analyze usage patterns and trends to better understand how visitors interact with the portfolio (through Google Analytics, with your explicit opt-in consent - see Section 6 for details)
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations and enforce our Terms of Use
  • To protect the artist's rights, property, and safety, and that of our users
  • For any other purpose disclosed to you at the time of collection

Note: We do not currently send newsletters or marketing emails. If we add this functionality in the future, we will update this Privacy Policy and obtain your explicit consent before sending such communications.

4. Information Sharing and Disclosure

4.1 We Do Not Sell Your Personal Information

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

4.2 Service Providers

We may share your information with trusted third-party service providers who assist us in operating our Website and processing your requests, including:

  • Web hosting and cloud storage providers
  • Email service providers (for processing contact form submissions)
  • Analytics providers (e.g., Google Analytics, with your explicit opt-in consent - see Section 6 for details)
  • Payment processors (when you complete a purchase, we provide you with a secure payment link to a trusted third-party payment processor who handles the transaction)

These service providers are contractually obligated to protect your information and use it only for the purposes we specify. We do not share your information with marketing or advertising platforms.

Payment Processing: When you make a purchase, payment information (such as credit card details) is processed directly by the third-party payment processor through the secure payment link we provide. We do not have access to or store your full payment card information. The payment processor's use of your information is governed by their own privacy policy, which we encourage you to review.

4.3 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal process, including subpoenas, court orders, or government requests
  • Enforcement of our Terms of Use or other agreements
  • Protection of our rights, property, or safety
  • Prevention of fraud or other illegal activities

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

5. Data Security

We implement industry-standard technical and organizational security measures to protect your personal information, including:

  • SSL/TLS encryption for data transmission
  • Secure server infrastructure
  • Access controls and authentication procedures
  • Regular security assessments and updates

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience, analyze usage patterns, and improve our Website. We use the following types of cookies:

  • Essential Cookies: Required for the Website to function properly. These cookies are necessary and cannot be disabled. They are set automatically when you visit our Website.
  • Analytics Cookies: Help us understand how visitors interact with our Website by collecting anonymous information (e.g., Google Analytics). These cookies require your explicit opt-in consent under GDPR and similar laws. Analytics cookies are only loaded after you provide your consent through our cookie consent banner.
  • Functional Cookies: Remember your preferences and settings to enhance your experience (e.g., language preferences, cookie consent preferences). These cookies require your explicit opt-in consent.
  • Marketing Cookies: Currently not used. If we add marketing cookies in the future, they will only be used with your explicit opt-in consent.

6.1 Cookie Consent Management

We implement a GDPR and CCPA compliant opt-in cookie consent system. When you first visit our Website, you will see a cookie consent banner that allows you to:

  • Accept All Cookies: Consent to all categories of cookies (essential, analytics, functional, and marketing)
  • Reject All Cookies: Only accept essential cookies (required for the Website to function)
  • Customize Preferences: Choose which categories of cookies you want to accept (e.g., analytics but not marketing)

Opt-In Consent: Non-essential cookies (analytics, functional, and marketing) are only loaded after you provide explicit opt-in consent through our cookie consent banner. Google Analytics and other analytics tools will not be loaded or activated until you consent to analytics cookies. This ensures full compliance with GDPR, CCPA, and similar privacy regulations.

Managing Your Cookie Preferences: You can manage your cookie preferences at any time by:

  • Clicking the "Cookie Preferences" link in the footer of any page
  • Using your browser settings to control cookies (note: this may affect Website functionality)
  • Contacting us at hello@natalideusuniverse.com to update your preferences

Withdrawing Consent: You can withdraw your consent to non-essential cookies at any time by updating your cookie preferences through the "Cookie Preferences" link in the footer or by adjusting your browser settings. Note that withdrawing consent will disable analytics and functional cookies, which may affect Website functionality and personalization features.

Consent Duration: Your cookie consent preferences are stored for one year, after which you will be asked to renew your consent. If we update our cookie policy or add new cookie categories, we will notify you and ask for renewed consent.

Third-Party Analytics: We use Google Analytics 4 to analyze Website usage. Google Analytics uses cookies and may collect information about your use of the Website, but only after you provide explicit opt-in consent for analytics cookies. Google Analytics is configured to anonymize IP addresses and does not collect personally identifiable information. For more information about how Google uses data, please visit Google's Privacy Policy. You can opt-out of Google Analytics tracking at any time by updating your cookie preferences.

7. Your Rights and Choices

7.1 GDPR Rights (European Users)

If you are located in the EEA, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of data processing
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

7.2 CCPA Rights (California Residents)

If you are a California resident, you have the following rights:

  • Right to Know: Request disclosure of personal information collected, used, or shared
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: Opt-out of the sale of personal information (we do not sell personal information)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

7.3 Other Jurisdictions

We respect privacy rights under applicable laws in other jurisdictions, including PIPEDA (Canada) and other international data protection regulations.

7.4 How to Exercise Your Rights

To exercise any of these rights, please contact us at hello@natalideusuniverse.com with a clear description of your request. We will respond to your request within:

  • GDPR: One month (30 days) from receipt of your request, which may be extended by two additional months for complex requests
  • CCPA: 45 days from receipt of your request
  • Other jurisdictions: As required by applicable law

We may request additional information to verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights.

Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

8. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Specific retention periods:

  • Contact form inquiries (general): Retained for up to 3 years after your last contact, unless you request earlier deletion
  • Purchase and commission inquiries: Retained for up to 7 years for legal and tax compliance purposes, including records of transactions, authenticity certificates, and related communications
  • Payment transaction records: Retained for up to 7 years as required by tax and financial regulations
  • Analytics data: Retained in anonymized form for up to 26 months (Google Analytics default)
  • Legal obligations: Some data may be retained longer if required by law (e.g., tax records, legal disputes, authenticity documentation)

When personal information is no longer needed, we will securely delete or anonymize it in accordance with our data retention policies and applicable law.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by relevant data protection authorities
  • Other legally recognized transfer mechanisms

10. Children's Privacy

Our Website is not intended for children. We do not knowingly collect personal information from children.

GDPR (European Union): If you are under 16 years of age, you must have parental consent to use this Website. We do not knowingly collect personal information from children under 16 without parental consent.

COPPA (United States): Our Website is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe we have collected information from a child under 13, please contact us immediately, and we will delete such information.

If you believe we have collected information from a child in violation of applicable laws, please contact us immediately at hello@natalideusuniverse.com, and we will promptly delete such information.

11. Third-Party Links

Our Website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on this page with a new "Last Updated" date
  • Sending an email notification (if you have provided your email address)
  • Displaying a prominent notice on our Website

Your continued use of the Website after such changes constitutes acceptance of the updated Privacy Policy.

13. Data Protection Contact

For questions or concerns about our data processing practices, or to exercise your privacy rights, please contact us:

Email: hello@natalideusuniverse.com

Note: As a personal website and portfolio, we may not be required to appoint a formal Data Protection Officer under GDPR. However, we are committed to protecting your privacy and will respond to all inquiries promptly.

14. Supervisory Authority and Right to Lodge a Complaint

If you are located in the EEA and believe we have violated your data protection rights, you have the right to lodge a complaint with your local data protection supervisory authority.

You can find contact information for your local supervisory authority at:

If you are located in the United Kingdom, you may contact the Information Commissioner's Office (ICO).

If you are located in Canada, you may contact the Office of the Privacy Commissioner of Canada.

We encourage you to contact us first to resolve any concerns before filing a complaint with a supervisory authority.

15. Contact Us

If you have questions, concerns, or wish to exercise your privacy rights, please contact us:

Natali Deus Universe
Email: hello@natalideusuniverse.com
Website: www.natalideusuniverse.com

This Privacy Policy is effective as of January 1, 2025, and was last updated on November 30, 2025.