Data Protection & Privacy Standards

Privacy Policy

Effective Date: September 4, 2026 · Compliance: UK GDPR, EU GDPR, Data Protection Act 2018 & PECR

1. Data Controller & Commitment

Ozgo Gallery is operated by Ozgo Productions Ltd ("we", "us", or "our"), registered in England and Wales. We act as the Data Controller regarding personal data processed through gallery.ozgo.co.uk, creator subdomains, proofing portals, and digital download delivery systems.

We are committed to maintaining the highest standards of data privacy, integrity, and confidentiality for our visual creators, commercial licensing clients, print buyers, and visitors.

2. Categories of Personal Data We Collect

Depending on how you interact with our platform, we collect and process the following categories of information:

A. Creator & Studio Profile Data

Full name, studio brand name, email address, profile avatar/logo, customized storefront slug (/g/[slug]), custom domain DNS mappings, storage utilization statistics, and multi-factor authentication enrollment logs.

B. Buyer, Client & Order Data

Customer full name, email address, billing postal code, physical shipping delivery address (for Prodigi print lab orders), purchased media asset IDs, license tier selections (Personal, Commercial, Extended), and digital download access tokens.

C. Financial & Stripe Connect Data

For creators: Stripe Connected Account IDs, onboarding completion status, charges/payouts enablement flags, and payout history. Note: All credit card details and bank account numbers are processed directly by Stripe on their PCI-DSS Level 1 certified servers; no card numbers are ever stored on Ozgo Gallery servers.

D. Client Proofing & Review Data

Favorite photo/video selections (hearting), star ratings, frame-accurate retouching notes, client comments, and gallery PIN passcode access verifications.

E. Telemetry, Security & Audit Logs

IP addresses, browser user agent strings, authentication timestamps, MFA verification codes, admin audit records (/api/admin/audit-logs), and video streaming player telemetry.

3. Lawful Bases for Processing (UK / EU GDPR Article 6)

We only collect and process personal data where we have a valid legal basis under UK GDPR and EU GDPR:

  • Contractual Necessity (Art. 6(1)(b)): To manage your creator account, transcode video clips, process digital license purchases, disburse Stripe Connect payouts, fulfill physical print lab orders, and deliver uncompressed master downloads.
  • Legitimate Interests (Art. 6(1)(f)): To maintain platform security, prevent unauthorized account takeovers with MFA, protect copyrighted media with 10% preview watermarks, maintain admin audit logs, and improve streaming performance.
  • Legal Obligation (Art. 6(1)(c)): To maintain tax, VAT, and accounting transaction records in compliance with UK HMRC regulations.
  • Consent (Art. 6(1)(a)): For non-essential analytics tracking (Google Analytics 4 / Tag Manager), which is only loaded after you click "Accept All" on our Cookie Consent banner.

4. Cookie Policy & Tracking Classification

We classify cookies and local browser storage mechanisms into three distinct tiers:

1. Strictly Necessary / Essential Cookies

Essential for user authentication sessions, MFA verification state, cross-site request security, and shopping cart persistence. These cannot be disabled as the platform cannot function without them.

2. Functional & Preference Cookies

Used to remember your display preferences, cinema mode state, client proofing heart selections, and dismissed notices.

3. Analytics Cookies (Google Analytics 4 / GTM)

Used to evaluate aggregate traffic volumes, popular marketplace search keywords, and page engagement (Measurement ID: G-GYG18H5L7M). These cookies are strictly disabled by default and will only execute after explicit user consent.

You can modify or withdraw your cookie consent preferences at any time using the persistent Cookie Settings button in the website footer.

5. Third-Party Sub-Processors

To provide our global infrastructure, digital licensing, and physical drop-shipping, we partner with industry-leading, GDPR-compliant service providers:

Google Cloud Platform & Firebase

Cloud hosting, Firestore database, high-resolution media storage (GCS), authentication, and CDN.

Location: UK / EU / US (Standard Contractual Clauses)
Stripe, Inc.

Secure payment processing, Stripe Connect creator payouts, fraud detection, and customer billing portal.

Certification: PCI-DSS Level 1 Service Provider
Prodigi Group

Automated fine-art print production, custom framing, museum canvas manufacture, and worldwide courier drop-shipping.

Location: United Kingdom & Global Labs
Resend

Transactional email delivery, 6-digit MFA security codes, master download links, and support tickets.

Security: TLS Encrypted Transport

6. Data Retention & Storage Lifecycles

We retain personal data only for as long as necessary to fulfill the operational purposes described in this policy:

  • Active Creator Accounts: Account data and media files are retained for the lifetime of your active studio membership or under the terms of our Legacy Library Retention Policy.
  • Order & Transaction Records: In accordance with UK HMRC statutory accounting requirements, sales records, digital license receipts, and invoice metadata are retained for 7 years.
  • Support Tickets & Audit Logs: Security logs and customer support correspondence are retained for 24 months for forensic and quality assurance purposes.

7. Your Rights under UK / EU GDPR (Articles 15–22)

Under UK and EU data protection legislation, you possess comprehensive legal rights regarding your personal information:

Right of Access (Art. 15)

You may request a complete copy of the personal data we hold about you.

Right to Rectification (Art. 16)

You may update or correct inaccurate or incomplete profile details at any time in your Settings.

Right to Erasure / Forgotten (Art. 17)

You may request the permanent deletion of your account, media files, and galleries.

Right to Data Portability (Art. 20)

You may request your account metadata in a structured, machine-readable format (CSV/JSON).

To exercise any of these statutory rights, please email our Data Protection Team at privacy@ozgo.co.uk. We respond to all verified requests within 30 days free of charge. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).

8. Information Security Architecture

We employ robust administrative, technical, and physical safeguards to protect your personal data:

  • Encryption in Transit: All platform communications use TLS 1.3 encryption with modern cipher suites and HSTS enforcement.
  • Encryption at Rest: Cloud databases and media master files are encrypted using industry-standard AES-256 encryption.
  • Secure Master Delivery: Purchased uncompressed master files are generated using time-limited, cryptographically signed URLs to prevent unauthorized hotlinking or scraping.
  • Multi-Factor Authentication (MFA): Step-up authentication and 6-digit email security challenges protect sensitive studio operations.

9. Contact Data Protection Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please reach out to us:

Data Protection Team: Ozgo Gallery / Ozgo Productions Ltd

Email: privacy@ozgo.co.uk

Support Portal: gallery.ozgo.co.uk/contact

Location: London, United Kingdom