GDPR Compliance

KidsForArt.com is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR). This page explains your rights under GDPR and how we handle your personal data.

1. Introduction to GDPR

The General Data Protection Regulation (GDPR) is a European Union law that protects the privacy and personal data of individuals in the EU and European Economic Area (EEA). Even if you are located outside the EU, we respect and apply these privacy principles to all our users.

2. Who We Are

Website: KidsForArt.com
Data Controller: KidsForArt.com

We are the data controller responsible for processing your personal data. If you have any questions or concerns about how we handle your data, please contact us using the information above.

3. What Personal Data We Collect

We collect and process the following types of personal data:

3.1 Information You Provide Directly

  • Name: When you subscribe to our newsletter or contact us
  • Email Address: For newsletters, communications, and contact requests
  • Message Content: When you use our contact form

3.2 Information Collected Automatically

  • IP Address: For security and analytics purposes
  • Browser and Device Information: Browser type, operating system, device type
  • Usage Data: Pages visited, time spent on pages, referring websites
  • Cookie Data: See our Cookie Policy for detailed information

3.3 Information from Third Parties

  • Analytics Data: From Google Analytics and similar services
  • Advertising Data: From Google Ads, Facebook Pixel, Pinterest Tag
  • Affiliate Data: From affiliate network partners

4. Legal Basis for Processing Your Data

We process your personal data based on the following legal grounds:

4.1 Consent (Article 6(1)(a) GDPR)

  • Email marketing and newsletters
  • Non-essential cookies (advertising, analytics)
  • Promotional communications

You have the right to withdraw consent at any time.

4.2 Legitimate Interests (Article 6(1)(f) GDPR)

  • Website analytics and performance monitoring
  • Security and fraud prevention
  • Improving user experience
  • Displaying content and coloring pages

4.3 Legal Obligations (Article 6(1)(c) GDPR)

  • Compliance with applicable laws
  • Response to legal requests
  • Tax and accounting requirements

4.4 Contract Performance (Article 6(1)(b) GDPR)

  • Providing services you request
  • Responding to your inquiries

5. Your Rights Under GDPR

As a data subject, you have the following rights under GDPR:

5.1 Right of Access (Article 15)

You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data.

How to exercise: Contact us via email with your request. We will provide the information within 30 days.

5.2 Right to Rectification (Article 16)

You have the right to request correction of inaccurate or incomplete personal data.

How to exercise: Contact us with the correct information, and we will update our records promptly.

5.3 Right to Erasure / “Right to be Forgotten” (Article 17)

You have the right to request deletion of your personal data in certain circumstances, including:

  • When data is no longer necessary for the purposes collected
  • When you withdraw consent
  • When you object to processing
  • When data has been unlawfully processed

How to exercise: Contact us with your erasure request. We will comply unless we have legitimate grounds to retain the data.

Limitations: We may retain data if required by law or for legitimate purposes (e.g., legal claims, accounting).

5.4 Right to Restriction of Processing (Article 18)

You have the right to request that we limit how we use your data in certain situations:

  • When you contest the accuracy of data
  • When processing is unlawful but you don’t want erasure
  • When we no longer need the data but you need it for legal claims
  • When you have objected to processing pending verification

How to exercise: Contact us with your restriction request.

5.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.

How to exercise: Contact us, and we will provide your data in CSV or JSON format within 30 days.

Applies to: Data provided with consent or for contract performance, and processed by automated means.

5.6 Right to Object (Article 21)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

How to exercise:

  • Direct Marketing: Click “unsubscribe” in emails or contact us
  • Other Processing: Contact us with your objection, and we will cease processing unless we have compelling legitimate grounds

5.7 Right to Withdraw Consent (Article 7(3))

When processing is based on consent, you have the right to withdraw that consent at any time.

How to exercise:

  • Email Marketing: Click “unsubscribe” in any email
  • Cookies: Adjust browser settings or use opt-out tools
  • Contact: Email us to withdraw consent for specific processing

Note: Withdrawal does not affect the lawfulness of processing before withdrawal.

5.8 Right to Lodge a Complaint (Article 77)

You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.

EU Supervisory Authorities: Contact your national data protection authority
Find your authority: https://edpb.europa.eu/about-edpb/board/members_en

6. How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us:

Email: [Your Contact Email]
Subject Line: “GDPR Request – [Type of Request]”

Include in your request:

  • Your full name
  • Your email address (the one associated with our records)
  • Specific right you wish to exercise
  • Any relevant details to help us locate your data

Response Time: We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days and will inform you of the delay.

Verification: We may request additional information to verify your identity before processing your request to protect your data security.

No Fee: Exercising your rights is free of charge unless requests are manifestly unfounded, excessive, or repetitive.

7. How We Protect Your Data

We implement appropriate technical and organizational measures to protect your personal data:

7.1 Technical Measures

  • SSL/TLS Encryption: Secure data transmission
  • Secure Servers: Data stored on secure hosting infrastructure
  • Access Controls: Limited access to personal data
  • Regular Backups: Data backup and recovery procedures
  • Security Monitoring: Ongoing security assessments

7.2 Organizational Measures

  • Data Minimization: We collect only necessary data
  • Privacy by Design: Privacy considerations in system development
  • Staff Training: Regular privacy and security training
  • Data Processing Agreements: Contracts with third-party processors
  • Incident Response: Procedures for data breach notification

7.3 Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Notify affected individuals without undue delay
  • Provide information about the breach and mitigation measures

8. Data Retention

We retain your personal data only as long as necessary for the purposes collected:

8.1 Email Addresses (Newsletter Subscribers)

  • Retention Period: Until you unsubscribe or request deletion
  • Purpose: Send newsletters and updates
  • Deletion: Immediate upon unsubscribe request

8.2 Contact Form Submissions

  • Retention Period: Up to 2 years after last contact
  • Purpose: Respond to inquiries and maintain communication history
  • Deletion: Upon request or after retention period

8.3 Analytics Data (Google Analytics)

  • Retention Period: Default Google Analytics settings (14-26 months)
  • Purpose: Website performance analysis and improvement
  • Control: Managed by Google’s retention policies

8.4 Cookie Data

  • Retention Period: Varies by cookie type (see Cookie Policy)
  • Essential Cookies: Session or up to 1 year
  • Analytics Cookies: 1-2 years
  • Advertising Cookies: Up to 2 years
  • Control: Browser settings and opt-out tools

8.5 IP Addresses and Log Files

  • Retention Period: Up to 12 months
  • Purpose: Security, fraud prevention, technical troubleshooting
  • Deletion: Automatic after retention period

8.6 Legal Retention Requirements

Some data may be retained longer if required by:

  • Tax and accounting laws
  • Legal claims and disputes
  • Regulatory requirements

9. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where our servers and service providers are located.

9.1 Safeguards for International Transfers

We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs): EU-approved data transfer mechanisms
  • Adequacy Decisions: Transfers to countries with adequate protection
  • Privacy Shield (where applicable): Though invalidated, replaced with alternative mechanisms
  • Service Provider Certifications: Third parties with GDPR-compliant practices

9.2 Third-Party Processors

Our service providers outside the EEA include:

  • Google LLC (USA): Analytics, advertising, email services
  • Meta Platforms, Inc. (USA): Facebook Pixel and advertising
  • Pinterest, Inc. (USA): Pinterest Tag and advertising
  • Hosting Providers: Server infrastructure
  • Email Marketing Platforms: Mailchimp and similar services

All third-party processors are contractually obligated to protect your data according to GDPR standards.

10. Children’s Data

While our Website provides coloring pages suitable for children, we do not knowingly collect personal data from children under 16 without parental consent.

Parental Responsibility: Parents and guardians should supervise children’s online activities and newsletter subscriptions.

If you are under 16: Please have a parent or guardian subscribe to our newsletter or contact us on your behalf.

Discovery of Children’s Data: If we discover we have collected data from a child under 16 without proper consent, we will delete it promptly.

11. Third-Party Services and GDPR

We use third-party services that process your data. These services have their own GDPR compliance measures:

11.1 Google Services

  • Privacy Policy: https://policies.google.com/privacy
  • GDPR Compliance: https://privacy.google.com/businesses/compliance/
  • Data Processing Terms: Standard Contractual Clauses in place

11.2 Facebook/Meta

  • Privacy Policy: https://www.facebook.com/privacy/policy/
  • GDPR Compliance: https://www.facebook.com/business/gdpr
  • Data Processing: EU-US data transfer mechanisms

11.3 Pinterest

  • Privacy Policy: https://policy.pinterest.com/privacy-policy
  • GDPR Rights: https://help.pinterest.com/en/article/privacy-rights-in-europe

11.4 Email Marketing Platforms

  • Mailchimp and similar services maintain GDPR compliance
  • Standard Contractual Clauses in place
  • Data Processing Agreements established

12. Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.

Advertising Profiling: Third-party advertising services may use cookies to build user profiles for targeted advertising. You can opt out using the methods described in our Cookie Policy.

Analytics: We use analytics to understand aggregate user behavior, but this does not result in automated decisions affecting you individually.

13. Updates to GDPR Compliance

We may update this GDPR Compliance page to reflect:

  • Changes in data processing practices
  • New legal requirements
  • Updates to your rights or our obligations

Notification of Changes: Significant changes will be communicated through:

  • Email notifications to subscribers
  • Prominent notices on our Website
  • Updated “Effective Date” at the top of this page

Your Responsibility: Review this page periodically to stay informed about how we protect your data.

14. Contact and Questions

If you have any questions about GDPR compliance, your rights, or how we process your data, please contact us:

Data Controller Contact:
Email: Contact Us
Website: www.KidsForArt.com

Response Time: We aim to respond to all inquiries within 5 business days.

For Data Requests: Please use the subject line “GDPR Request” and specify the type of request (access, deletion, rectification, etc.).

15. Supervisory Authority

If you are not satisfied with our response to your GDPR request or believe we are not complying with GDPR, you have the right to lodge a complaint with a supervisory authority.

Find Your Supervisory Authority:

  • EU Member States: https://edpb.europa.eu/about-edpb/board/members_en
  • UK: Information Commissioner’s Office (ICO) – https://ico.org.uk/

What to Include in Your Complaint:

  • Your contact information
  • Description of the issue
  • Any correspondence with us
  • Desired outcome


Last Updated:
December 22, 2025

KidsForArt.com is committed to respecting your privacy rights and maintaining GDPR compliance. Your trust is important to us.