Privacy & Security Policy
Last updated: July 6, 2026
TL;DR — The Short Version
- Publicly Available Data: We aggregate public IRS (Form 990) and state charity registry data, which inherently includes names, titles, and compensation of nonprofit officers. We do not alter this public record.
- User-Provided Data: If you claim an organization profile to add narrative overlays, you own that data. We never sell your personal or organizational data.
- Security Baseline: We enforce encryption (in transit/rest), strict role-based access controls (RBAC), and minimize data storage to essentials.
Overview & Our Role
ArtMetrics.co ("ArtMetrics," "we," "us") provides governance intelligence and infrastructure for the arts and culture sector. This policy outlines our data handling practices for both the publicly sourced data we structure and the user data we collect when organizations interact with our platform.
Processing of Public IRS & State Data
Our core product relies on public records to generate scores and trajectories. This includes:
- Sources: IRS Form 990 financials, IRS TEOS XML Part VII (officer data), IRS TEOS XML Part III (program narratives), and state charity registries (e.g., NM, OR, CO).
- Personal Data in Public Records: These public filings legally mandate the disclosure of named officers, titles, hours worked per week, and compensation. We process this data under the legal basis of legitimate public interest and transparency.
- Accuracy & Latency: We display the data as filed. Because IRS releases can be delayed by 6 months to 3 years, we clearly timestamp all data. We do not alter the historical public record.
Information You Provide to Us
When you register for an account, claim a profile, or use our enterprise tools, we collect:
- Account Information: Name, email address, organization affiliation, and role.
- Narrative Overlays: Text, context, or corrections you provide when managing a claimed organization profile.
- Usage Data: Application logs, timestamps, and feature interactions used strictly to improve the platform and maintain audit trails.
How We Use Information
User-provided data is used exclusively to provide and improve the ArtMetrics platform. We use this data to authenticate users, facilitate profile claims, generate enterprise analytical reports, and communicate service updates. We do not sell your personal data to third parties or data brokers.
Data Security & Controls
ArtMetrics implements robust security measures designed for enterprise and funder trust:
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access Controls: We utilize strict Role-Based Access Control (RBAC). Only authenticated and authorized personnel can access infrastructure systems.
- Infrastructure: We host on top-tier cloud providers with continuous monitoring, regular security reviews, and automated threat detection.
Data Retention & Minimization
We practice data minimization. We only ingest and store the specific fields from public filings required for our governance algorithms. User account data is retained only as long as the account is active. Upon account deletion, user-provided data is purged within 30 days, though immutable audit logs may be retained for security compliance.
Your Rights (CCPA / GDPR)
If you are a resident of California or the European Economic Area, you possess specific data rights:
- Right to Access & Portability: You may request a copy of the personal data you have provided to us.
- Right to Rectification: You may correct inaccurate user-provided account data. (Note: To correct errors in public IRS filings, you must file an amended return with the IRS; we cannot overwrite the public historical record).
- Right to Erasure: You may request the deletion of your user account.
To exercise these rights, or to submit a data-subject request, please contact our privacy team.
Contact & DPA
For privacy inquiries, security questions, Data Processing Agreement (DPA) requests, or to appeal/contextualize a public score, please contact us at privacy@artmetrics.co.