Privacy Policy
Effective Date: 14 January 2025
We understand that your personal information matters. This privacy policy explains how Xeravox collects, uses, and protects your data when you visit our website or engage with our watercolor illustration courses and resources.
We're committed to transparency. You'll find no jargon here—just straightforward information about what we do with your data and why. If something's unclear, get in touch and we'll explain it properly.
Information We Collect
When you interact with Xeravox, we gather different types of information depending on how you use our site. Here's what that looks like in practice:
Information You Give Us Directly
This includes anything you provide when filling out forms, creating an account, or reaching out to us:
- Your name and email address when you sign up for our newsletter or create an account
- Contact details when you enquire about courses or request information
- Payment information when you purchase a course (processed securely through our payment provider)
- Any messages you send through our contact forms or email correspondence
- Portfolio samples if you submit work for course admission consideration
Information We Collect Automatically
Like most websites, we gather certain data automatically when you visit:
- Your IP address and general location information
- Browser type and device information
- Pages you visit and how long you spend on them
- Links you click and resources you download
- Referring websites that brought you to our site
About Cookies: We use cookies to remember your preferences and understand how people use our site. You can control cookie settings through your browser, though some features might not work as smoothly if you disable them.
How We Use Your Information
We're not in the business of collecting data for the sake of it. Everything we gather serves a specific purpose related to running our courses and improving your experience.
Running Our Services
The main reason we need your information is to provide the courses and resources you're interested in:
- Processing your course registrations and managing your account
- Delivering course materials and updates about programs you've enrolled in
- Responding to your questions and providing support
- Sending important notices about schedule changes or technical issues
- Processing payments and maintaining transaction records
Improving What We Offer
We analyze how people use our site to make things better:
- Understanding which course topics generate the most interest
- Identifying technical problems or confusing parts of our website
- Testing new features and course formats
- Developing content that addresses common questions or challenges
Marketing Communications
If you've opted in, we'll send you information about new courses, watercolor techniques, and relevant updates. You can unsubscribe anytime—there's always a link at the bottom of our emails. We typically send one or two messages per month, and we won't bombard your inbox.
Legal Basis for Processing (UK GDPR)
Under UK data protection law, we need a valid reason to process your personal information. Here's what applies in different situations:
| Processing Purpose | Legal Basis |
|---|---|
| Course delivery and account management | Contractual necessity (we need this to provide the service you've paid for) |
| Marketing emails and newsletters | Your consent (which you can withdraw anytime) |
| Website improvements and analytics | Legitimate interests (improving our services for everyone) |
| Financial record keeping | Legal obligation (required by UK tax and business law) |
Sharing Your Information
We don't sell your personal data to anyone. Period. But we do work with certain trusted partners to run our business:
Service Providers We Work With
- Payment processors handle transaction details securely when you purchase a course
- Email service providers help us send course materials and newsletters
- Hosting providers store our website and course content
- Analytics tools help us understand website traffic and user behavior
These companies can only use your data to provide their specific service to us. They're contractually bound to protect your information and can't use it for their own purposes.
Legal Requirements
We might need to disclose information if required by law—for example, in response to a court order or to comply with UK regulations. This doesn't happen often, but we're legally obliged to cooperate with authorities when necessary.
Your Rights Under UK Law
UK data protection law gives you significant control over your personal information. Here's what you can do:
Access Your Information
You can request a copy of all personal data we hold about you. We'll provide this free of charge within one month of your request. Just email us at the address below.
Correct Inaccurate Information
If something we have on file is wrong or outdated, let us know and we'll fix it promptly.
Request Deletion
You can ask us to delete your personal information in certain circumstances—for instance, if you withdraw consent for marketing emails or if the data's no longer needed for its original purpose. We'll comply unless we have a legal reason to keep it (like financial records we're required to maintain).
Object to Processing
If we're processing your data based on legitimate interests, you can object. We'll stop unless we can demonstrate compelling legitimate grounds that override your interests.
Data Portability
You can request your personal data in a structured, machine-readable format to transfer to another service provider.
Withdraw Consent
Where we're processing data based on your consent (like marketing emails), you can withdraw that consent anytime. This won't affect the lawfulness of processing before you withdrew consent.
How to Exercise Your Rights: Send an email to [email protected] with details of your request. We'll verify your identity and respond within one month. If your request is complex, we might need an extra two months—but we'll let you know if that's the case.
How We Protect Your Data
Security isn't just a technical requirement for us—it's fundamental to how we operate. We take several measures to keep your information safe:
- All data transmitted to and from our website is encrypted using SSL/TLS technology
- Payment information never touches our servers—it goes directly to our PCI-compliant payment processor
- Access to personal data is restricted to staff members who genuinely need it
- We use secure hosting with regular security updates and backups
- Passwords are stored using industry-standard hashing algorithms
That said, no system is completely foolproof. While we do everything reasonable to protect your information, we can't guarantee absolute security—no one honestly can.
How Long We Keep Your Data
We don't keep information longer than necessary. Here's our general approach:
| Data Type | Retention Period | Reason |
|---|---|---|
| Course enrollment records | 7 years after course completion | Legal requirement for educational records |
| Financial transaction data | 7 years | UK tax law requirement |
| Marketing consent records | Until consent is withdrawn, then 30 days | Demonstrating compliance with consent requirements |
| Website analytics data | 26 months | Understanding long-term trends |
| General correspondence | 3 years | Customer service and business records |
When data reaches the end of its retention period, we securely delete it from our systems.
International Data Transfers
Some of our service providers are based outside the United Kingdom. When your data leaves the UK, we ensure it receives equivalent protection through:
- Adequacy decisions (countries recognized by the UK government as having adequate data protection)
- Standard contractual clauses approved by UK authorities
- Specific safeguards that ensure your rights remain protected
If you'd like details about where specific data is processed or what safeguards apply, just ask.
Children's Privacy
Our courses are designed for adults. We don't knowingly collect information from anyone under 16 without parental consent. If you're under 16 and interested in our courses, please have a parent or guardian contact us first.
If we discover we've collected information from a child without proper consent, we'll delete it immediately.
Changes to This Policy
We review this privacy policy regularly and update it when our practices change or legal requirements evolve. When we make significant changes, we'll notify you by email or through a prominent notice on our website.
The effective date at the top of this policy shows when it was last updated. Previous versions are available on request if you'd like to see what's changed.
Your Right to Complain
If you're unhappy with how we've handled your personal information, please contact us first so we can try to resolve the issue. If you're still not satisfied, you have the right to lodge a complaint with the UK's supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
Questions or Concerns?
If anything in this policy is unclear or you have questions about how we handle your data, get in touch. We'd genuinely rather answer your questions than have you worry about it.
Email: [email protected]
Post: Xeravox, Unit 6B The Old Forge, Pearson Road Sonning on Thames, Sonning, Reading RG4 6UH, United Kingdom
Phone: +44 7985 712264
We aim to respond to all privacy-related enquiries within 48 hours.