Your privacy matters. This page explains, in plain terms, what data 1M2F Gallery collects, why we collect it, who we may share it with, and the rights you have — in compliance with Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018).
1. Who we are
1M2F Gallery is a contemporary art gallery based in São Paulo, Brazil, representing the artist Maria França, which acts as the data controller. This policy describes how we handle the personal data collected on our website.
2. Data we collect
Contact form: name, email, subject and message.
Newsletter: email address.
Inquiries about works: the details you choose to send us.
Favorites: IDs of saved works — stored only in your browser (localStorage). They are not sent to our servers unless you choose to share your list by email (see below).
Favorites shared by email: if you email your saved-favorites list, we receive and store your email address, the selected works and the originating IP address.
Technical data: IP address and basic request data. For security and abuse prevention (rate limiting) the IP is processed transiently; when you submit an inquiry or share your favorites by email, the originating IP is also recorded with that entry and retained as described in the Data retention section.
Session cookies: used solely for administrator authentication. Regular visitors receive no tracking cookies.
3. How we use your data
Respond to your messages and inquiries about works.
Send our newsletter with news, exhibitions and events — only if you subscribed.
Keep the site secure and prevent abuse.
We do not sell, rent or share your data with third parties for marketing purposes.
4. Legal basis (LGPD)
Processing is based on consent (Art. 7, I) for the newsletter and optional cookies, and on legitimate interest (Art. 7, IX) to respond to contact messages and keep the service secure.
5. Sharing & data processors
We never sell your data. To operate the site we rely on a few trusted service providers that act as data processors (operadores, LGPD Art. 39), handling data only under our instructions and their own security standards:
Hosting provider (VPS) — website hosting and delivery.
Resend — sending transactional emails and the newsletter.
Cloudinary — hosting and delivery of artwork images.
Cloudflare — bot protection on forms (Turnstile) and content delivery.
Sentry — error monitoring and diagnostics, when enabled; error reports may include technical data such as the IP address.
We may also disclose data when required by law or a competent authority.
6. International data transfer
Some of the providers above are located outside Brazil. When your data is transferred internationally, it is done in accordance with Art. 33 of the LGPD, relying on providers that offer an adequate level of data protection and appropriate contractual safeguards.
7. Data retention
Contact messages: kept for up to 30 days.
Artwork inquiries and private viewing requests: kept for up to 1 year, including the originating IP address.
Saved-favorites lists sent by email: kept for up to 6 months, including the originating IP address.
Newsletter emails: kept while you remain subscribed; unconfirmed sign-ups are removed after 30 days. Every newsletter email carries an unsubscribe link — one click removes your address from our database immediately, with no need to contact us.
Internal audit logs: kept for up to 1 year.
Technical/security data used for rate limiting: kept transiently (minutes to hours). The IP recorded with an inquiry or a favorites-share is retained with that record, per the items above.
8. Your rights
Under the LGPD, you have the right to:
Confirm whether your data is being processed.
Access the data we hold about you.
Correct incomplete, inaccurate or outdated data.
Request deletion or anonymization of your data.
Request data portability.
Withdraw consent at any time.
To exercise any of these rights, reach us through our contact form.
9. Cookies
We use only strictly necessary cookies (admin authentication). We do not use tracking, analytics or third-party advertising cookies. You can decline optional cookies via the banner shown on your first visit.
10. Security
Your data is transmitted via HTTPS and stored on protected servers. We apply security practices such as rate limiting, expiring tokens, a strict Content-Security-Policy and hashing of sensitive credentials.
11. Children & minors
Our website is not directed to children. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy to reflect legal or operational changes. The current version is always available on this page, with its date shown at the top. Significant changes may also be communicated through the site or by email.
13. Data Protection Officer (DPO)
In accordance with Art. 41 of the LGPD, the officer responsible for data processing is Maria França, as the controller. To exercise your rights, or to clarify questions about the processing of your personal data, contact us through the channels below. The response time is up to 15 calendar days, per Art. 19 of the LGPD.
14. Contact
Questions about this policy or requests related to your personal data? Reach us via the contact page or directly through the WhatsApp listed in the site footer.