Privacy and image authorization
Last updated: 17 September 2026
Basic information
- Controller
- ImageConsent.
- Privacy and withdrawal contact
- info@imageconsent.eu
- Purposes
- Manage the photography session; document image and voice authorization; retain the signature, audit trail and revocations; handle rights requests; and protect against unauthorized uses or legal claims.
- Legal bases
- Express consent for the selected image and voice uses; performance of the professional relationship to organize the session; and legitimate interests in security, record integrity and the establishment, exercise or defence of legal claims.
- Rights
- Access, rectification, erasure, restriction, objection and portability where applicable, as well as withdrawal of consent at any time.
Data processed
The data needed to identify and evidence the authorization is processed: name, national/foreigner ID or passport, email and telephone if supplied; legal-representative data where applicable; session or project; selected uses; signature; date, language, text version, signing method, status and revocation history.
Photographs, video or audio produced during the session are processed separately in accordance with the specific uses authorized by the individual. No automated decisions or profiling are carried out.
Scope of the image and voice authorization
The authorization permits capture and the acts of reproduction, distribution, public communication, making available and technical adaptation needed for the selected purposes. It does not permit unrelated purposes or uses that harm dignity, honour, privacy, reputation or, for a minor, their best interests.
Where an online channel is selected, its reach may be worldwide due to the nature of the Internet. Publication on social networks or third-party platforms is also subject to their terms and safeguards.
Withdrawal and revocation
Image authorization may be revoked and data-processing consent withdrawn at any time by writing to info@imageconsent.eu and identifying the authorization. Withdrawal does not affect earlier lawful processing or make previously valid uses unlawful.
Once a request is received, new uses will stop and material will be removed from channels controlled by the controller within a reasonable period, unless another legal basis or retention duty applies. Removal of copies already lawfully disseminated by third parties or outside the controller’s effective control cannot be guaranteed, although reasonable steps will be taken where appropriate.
Minors
The representative declares that they hold parental authority or guardianship and have sufficient authority. The minor must receive age-appropriate information, be heard and give their own consent whenever their maturity or applicable law so requires. Their best interests always prevail; authorization cannot legitimize a use that may harm them.
Recipients and transfers
Data may be processed by technical hosting, authentication and support providers acting on the controller’s behalf, and by clients, collaborators, media or platforms only where necessary for an expressly selected use. Data may also be disclosed to authorities where legally required.
Where an authorized provider or channel processes data outside the European Economic Area, GDPR safeguards such as an adequacy decision or standard contractual clauses will apply where required.
Retention
Remote-signing links expire after 20 minutes. Authorizations are retained while valid. If revoked or erased, the record may be retained with restricted access for the periods needed to evidence earlier consent and address potential liabilities, after which it will be deleted. Account data is kept while the account is active and can be exported or deleted from the Privacy Centre.
Signature and evidential value
The drawn signature and associated audit trail are electronic evidence of acceptance and cannot be denied admissibility merely because they are electronic. ImageConsent does not currently perform documentary identity verification or provide a qualified electronic signature; evidential weight therefore depends on all available evidence and the specific circumstances.
Security and exercise of rights
ImageConsent restricts access to the authenticated professional workspace, encrypts data in transit and at rest, adds application-level protection to identity fields and signatures, limits automated attempts and uses temporary links for remote signing. It does not retain complete authorization copies in permanent browser storage. If you receive a link you do not recognize, do not sign it and notify the professional contact.
You may exercise your rights free of charge through info@imageconsent.eu. The controller will generally respond within one month. If you believe your rights have not been respected, you may complain to the Spanish Data Protection Agency.
Legal framework applied
- Regulation (EU) 2016/679 (GDPR), particularly Articles 6, 7, 12, 13 and 15–22.
- Spanish Organic Law 3/2018 on data protection and digital rights.
- Spanish Organic Law 1/1982 on honour, privacy and image rights.
- Spanish Organic Law 1/1996 on the legal protection of minors.
- Regulation (EU) 910/2014 (eIDAS) on the legal effects of electronic signatures.