Privacy Policy
Effective Date: August 13, 2025
Version: 2.0 (GDPR & CCPA/CPRA Compliant)
Important: This Privacy Policy is compliant with the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and India's Digital Personal Data Protection Act (DPDPA) 2023. We are committed to protecting your privacy and personal data rights globally.
Musenex ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our digital art platform at musenex.com (the "Platform").
1. Data Controller and Contact Information
Data Controller: Musenex Platform
Email: privacy@musenex.com
Data Protection Officer: dpo@musenex.com
Address: Available upon request via contact form
2. Information We Collect
2.1 Personal Data (GDPR Article 4)
We collect the following categories of personal information:
Data Category | Examples | Purpose | Legal Basis (GDPR) | Retention Period |
---|---|---|---|---|
Identity Data | Name, username, profile information | Account creation, platform functionality | Contract (Art. 6(1)(b)) | Account lifetime + 2 years |
Contact Data | Email address, communication preferences | Communication, account verification | Contract (Art. 6(1)(b)) | Account lifetime + 2 years |
Technical Data | IP address, browser type, device info | Security, analytics, performance | Legitimate Interest (Art. 6(1)(f)) | 24 months |
Usage Data | Platform interactions, preferences | Service improvement, personalization | Legitimate Interest (Art. 6(1)(f)) | 24 months |
Content Data | Artwork uploads, comments, collections | Platform services, community features | Contract (Art. 6(1)(b)) | Account lifetime + 5 years |
Marketing Data | Communication preferences, interests | Marketing communications | Consent (Art. 6(1)(a)) | Until consent withdrawn + 1 year |
2.2 Special Categories of Data
We do not intentionally collect special categories of personal data (racial origin, political opinions, religious beliefs, health data, biometric data, etc.) as defined under GDPR Article 9. If such data is inadvertently collected through user-generated content, it will be processed under the explicit consent legal basis.
2.3 Children's Data
Our Platform is not intended for children under 16 years of age (or under 13 in the US). We do not knowingly collect personal data from children under these ages without parental consent.
3. How We Use Your Information
We process your personal data for the following purposes:
- Service Provision: To provide and maintain our Platform services (Legal basis: Contract)
- Account Management: To create and manage your user account (Legal basis: Contract)
- Content Display: To display your artwork and profile information (Legal basis: Contract)
- Community Features: To facilitate connections within the artist community (Legal basis: Legitimate interests)
- Platform Improvement: To analyze usage and improve user experience (Legal basis: Legitimate interests)
- Communications: To send important notifications and respond to inquiries (Legal basis: Contract/Legitimate interests)
- Security: To ensure platform security and prevent misuse (Legal basis: Legitimate interests)
- Legal Compliance: To comply with legal obligations (Legal basis: Legal obligation)
- Marketing: To send promotional communications (Legal basis: Consent - opt-in required)
4. Data Sharing and Transfers
4.1 Third-Party Sharing
We do not sell, rent, or trade your personal information to third parties. We may share your information in these limited circumstances:
- Service Providers: AWS, Google Cloud, and other infrastructure providers (Data Processing Agreements in place)
- Authentication Services: OAuth providers (Google, Facebook, Apple) - only basic profile information
- Analytics Services: Anonymized/pseudonymized data for platform analytics
- Legal Requirements: When required by law, court order, or to protect rights and safety
- Business Transfers: In connection with mergers, acquisitions (with user notification)
4.2 International Data Transfers
GDPR Compliance: When we transfer personal data outside the European Economic Area (EEA), we ensure adequate protection through:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules
- Appropriate safeguards under GDPR Article 46
5. Data Security
We implement comprehensive security measures including:
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access with multi-factor authentication
- Security Monitoring: 24/7 monitoring and incident response
- Regular Audits: Security assessments and penetration testing
- Data Minimization: We collect only necessary data and delete when no longer needed
- Pseudonymization: Personal data is pseudonymized where possible
Data Retention
We retain personal data only for as long as necessary for the purposes outlined in this policy or as required by law. Retention periods are detailed in the table above.
5.1 DPDPA Compliance (India's Digital Personal Data Protection Act 2023)
As a Data Fiduciary under DPDPA, we ensure:
- Lawful Processing: Processing personal data only with valid consent or legitimate grounds as specified in the Act
- Notice Requirements: Providing clear and comprehensive privacy notices before data collection
- Purpose Limitation: Using personal data only for specified, explicit, and legitimate purposes
- Data Minimization: Collecting only necessary and proportionate personal data
- Security Safeguards: Implementing reasonable security practices and procedures
- Data Principal Rights: Facilitating exercise of rights including access, correction, and erasure
- Grievance Redressal: Providing accessible grievance mechanisms
- Breach Notification: Notifying the Data Protection Board and affected individuals of breaches
Cross-Border Data Transfer: When transferring data outside India, we ensure compliance with DPDPA requirements and government notifications.
6. Your Privacy Rights
6.1 GDPR Rights (EU/EEA Residents)
Under the GDPR, you have the following rights:
- Right of Access (Article 15): Request copies of your personal data
- Right to Rectification (Article 16): Correct inaccurate or incomplete data
- Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing (Article 18): Limit how we process your data
- Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format
- Right to Object (Article 21): Object to processing based on legitimate interests
- Rights Related to Automated Decision-Making (Article 22): Not to be subject to automated decision-making
- Right to Withdraw Consent: Withdraw consent at any time (where consent is the legal basis)
Response Time: We will respond to your request within one month (extendable to three months for complex requests).
6.2 CCPA/CPRA Rights (California Residents)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have additional rights:
- Right to Know: Know what personal information we collect, use, share, and sell
- Right to Delete: Request deletion of personal information
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt-out of the sale or sharing of personal information
- Right to Limit: Limit the use and disclosure of sensitive personal information
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising privacy rights
Do Not Sell My Personal Information: We do not sell personal information. If this changes, we will provide an opt-out mechanism.
Response Time: We will respond to verifiable requests within 45 days (extendable to 90 days).
6.3 DPDPA Rights (Indian Residents)
Under India's Digital Personal Data Protection Act (DPDPA) 2023, Indian residents have the following rights as Data Principals:
- Right to Information: Obtain information about personal data processing and purposes
- Right to Correction and Erasure: Request correction of inaccurate data and deletion of personal data
- Right to Grievance Redressal: Access to grievance redressal mechanisms
- Right to Nominate: Nominate another person to exercise rights in case of death or incapacity
- Consent Management: Free, specific, informed, unconditional, and unambiguous consent
- Consent Withdrawal: Right to withdraw consent at any time
Data Fiduciary Obligations: We act as a Data Fiduciary under DPDPA and ensure:
- Lawful processing with valid consent or legitimate grounds
- Data minimization and purpose limitation
- Reasonable security safeguards
- Prompt breach notification
- Grievance redressal within timelines
Response Time: We will respond to DPDPA requests within reasonable time as prescribed by the Data Protection Board of India.
6.4 How to Exercise Your Rights
To exercise any of these rights, contact us at:
- Email: privacy@musenex.com
- Data Subject Request Form: Available at musenex.com/contact.html
- Account Settings: Many rights can be exercised directly through your account settings
7. Cookies and Tracking Technologies
We use cookies and similar technologies. You can manage cookie preferences through your browser settings. Our cookies include:
- Essential Cookies: Required for platform functionality (no consent required)
- Performance Cookies: Analytics and performance monitoring (consent required)
- Functional Cookies: Enhanced functionality and personalization (consent required)
- Marketing Cookies: Advertising and marketing (consent required)
For detailed cookie information, see our Cookie Policy.
8. Automated Decision-Making and Profiling
We do not engage in automated decision-making or profiling that produces legal effects or significantly affects you without human oversight. Any automated processing is used only for:
- Content recommendation algorithms
- Security and fraud prevention
- Platform optimization
9. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms:
- Supervisory Authority: We will notify within 72 hours (GDPR requirement)
- Individual Notification: You will be notified without undue delay if high risk is identified
- California Residents: We will comply with California breach notification laws
10. Third-Party Services and Links
Our Platform may integrate with third-party services. We are not responsible for their privacy practices. Review their privacy policies:
- OAuth Providers: Google, Facebook, Apple
- Cloud Services: AWS, Google Cloud
- Analytics: Platform analytics providers
11. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will:
- Post the updated policy on this page with a new "Last Updated" date
- Notify you via email for material changes (if you have an account)
- Provide prominent notice on the Platform for significant changes
- For GDPR subjects: Obtain new consent if required by law
12. Legal Basis Summary
Primary Legal Bases for Processing (GDPR):
- Contract (Article 6(1)(b)): Account management, service provision
- Legitimate Interests (Article 6(1)(f)): Security, analytics, platform improvement
- Consent (Article 6(1)(a)): Marketing communications, non-essential cookies
- Legal Obligation (Article 6(1)(c)): Compliance with applicable laws
13. Supervisory Authority
If you are an EU/EEA resident and believe we have not addressed your privacy concerns adequately, you have the right to lodge a complaint with your local data protection supervisory authority.
Contact Us
For any questions about this Privacy Policy or to exercise your privacy rights:
- Privacy Officer: privacy@musenex.com
- Data Protection Officer: dpo@musenex.com
- General Contact: musenex.com/contact.html
- Data Deletion Requests: musenex.com/data-deletion.html
Response Time: We will respond to privacy-related inquiries within 30 days (or as required by applicable law).
This Privacy Policy is designed to comply with:
- EU General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- California Privacy Rights Act (CPRA)
- India's Digital Personal Data Protection Act (DPDPA) 2023
- Other applicable privacy laws and regulations