Clara T Media

Privacy policy

Information on the processing of personal data required by articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and by Spanish Organic Act 3/2018 (LOPDGDD).

Version v1.0-2026-09-01 · Last updated: 1 September 2026

1. Who processes your data

Data controller: Clara Taboada García, tax number 47289110Y, address Calle Pablo Gargallo 61, 28035 Madrid, trading as Clara T Media.

Contact email for any privacy matter, including exercising your rights: claratmedia@gmail.com.

There is no data protection officer: the activity does not fall within any of the cases in article 37 GDPR or article 34 of the Spanish LOPDGDD. The controller handles these requests personally at the address above.

2. What data is processed

Only the data needed to book a reportage and deliver the photographs is collected. There are no lead capture forms, no profiling and no purchased databases.

Providing the fields marked with an asterisk in the form (name, email address, phone number, rider's name and horse's name) is a requirement for the request to be processed and the commission to be arranged: without them the request cannot be assessed, you cannot be contacted, your rider-and-horse combination cannot be identified in the ring, and the form will not submit. Once Clara has published the days she is covering, at least one day has to be ticked. If you tick that the rider is under 18, the legal guardian's four details are mandatory for the same reason. Everything else is voluntary: the classes entered and the notes may be left blank, they only help with planning. Permission to publish the photographs is not requested in this form but on a separate screen, after the request is sent, and it affects neither the price nor the delivery.

Where the data comes from. Contact and account data comes from you. The rider's name and the horse's name may come from whoever makes the booking, when you are not the one riding: they are typed into the booking form and then organised into the rider and horse records. The photographs are taken at the show itself, in the arena and in the areas the organiser gives access to. Show and club data comes from the public calendar of the Royal Spanish Equestrian Federation, from what the relevant regional federation publishes, or is entered by hand; each show records which of the three was its source. Where the data did not come from you, it is not always possible to notify you one by one (article 14.5.b GDPR), and that is why this information is published here.

  • Identification and contact data: name, email address, phone number, language and country.
  • Booking data: the show, the days requested, the rider's name, the horse's name, the classes entered and any notes you write.
  • Financial data of the booking: agreed price, amount received, payment method, reference and the number of the invoice issued. No card data is processed, because no payment is taken on this site.
  • Images: the photographs taken at the show, in which people, horses and numbers appear, together with the capture date and time.
  • Account data: user identifier and a record of sign-ins made with a one-time code.
  • Minimal technical data: IP address and user agent, stored when a download is registered and when a consent is given or withdrawn, as evidence that it happened.
  • Phone notification data, if you enable them: the subscription address your browser generates, which identifies that browser on that device, its two encryption keys, and the user agent. They are used to deliver the notification and nothing else.
  • Parent or guardian data where the rider photographed is a minor: name, tax number, email and phone.

3. Why it is used, and on what legal basis

Each purpose is independent of the others and has its own legal basis. Accepting one does not oblige you to accept the rest.

  • Handling your request and your booking: receiving the request, answering it, accepting or declining it, agreeing the days and organising the diary. Legal basis: performance of a contract and pre-contractual steps taken at your request (article 6.1.b GDPR).
  • Delivering the photographs you commissioned: creating your private gallery, letting you view them, download them one by one or as a single archive, and keeping the download record. Legal basis: performance of the contract (article 6.1.b GDPR).
  • Telling you what is happening with your booking: acceptance, a reminder before the show and delivery of the gallery, by email or by phone notification if you have enabled it. Legal basis: performance of the contract (article 6.1.b GDPR). The phone notification is only offered after you book and can be turned off from the browser itself.
  • Publishing your photographs in the portfolio, on the public site or on social media: the sole legal basis is your consent (article 6.1.a GDPR and article 2.2 of Spanish Organic Act 1/1982). It is requested on a separate screen with versioned wording, never inside the booking form and never pre-ticked. It can be withdrawn at any time, and withdrawing it does not affect delivery or the rest of the service.
  • Alerting you when Clara confirms a show where your rider-and-horse combination is competing: legal basis is your consent (article 6.1.a GDPR), requested when you enable the alert and withdrawn from your account.
  • Meeting tax, accounting and invoicing obligations: legal basis is compliance with a legal obligation (article 6.1.c GDPR, together with the Spanish General Tax Act and Commercial Code).
  • Handling the rights you exercise and keeping evidence of consents given and withdrawn: legal basis is compliance with a legal obligation (article 6.1.c GDPR, read with articles 5.2 and 7.1).
  • Photographing the class, keeping the images and delivering them, including images in which someone who did not commission the reportage appears incidentally. Legal basis: the legitimate interest of the photographer and of the person commissioning the reportage in documenting a sporting competition (article 6.1.f GDPR), together with the exception for a merely incidental image in visual reporting on a public event (article 8.2.c of Spanish Organic Act 1/1982). That interest covers taking the photograph, keeping it and delivering it to whoever commissioned it, and nothing else: publication by Clara in the portfolio, on the public site or on her social media is not covered here, but by the consent described in the point on publishing in this same list. Whoever commissions the reportage receives the photographs under the licence of use set out in the terms of service and may share them within those limits. If you appear in a photograph you can object to this processing and ask for it to be taken down by writing to claratmedia@gmail.com (articles 21 and 17 GDPR).
Refusing to have your photographs published does not stop you booking, does not make the reportage more expensive and does not change what you receive. They are separate things and they are treated as such.

4. What is never done

Some processing simply does not exist in this service and will not exist. It is not switched off and it is not optional: it is not built, and there is nowhere to store it.

  • No facial recognition or any other biometric identification is applied to the photographs. It would be processing of special categories of data (article 9 GDPR) and, in a publicly accessible space, a practice prohibited by article 5.1.e of Regulation (EU) 2024/1689 on Artificial Intelligence.
  • No automated decisions with legal effects are taken and no profiling is carried out (article 22 GDPR).
  • Data is never sold or shared with third parties for advertising purposes.
  • Neither the photographs nor the data are used to train artificial intelligence systems, whether Clara's own or anyone else's.
  • There is no web analytics, no tracking pixels and no behavioural advertising.

5. Children

A great many children compete at equestrian shows, which is why this point is handled more carefully than any other.

The account and the contract always belong to an adult: an account is never opened in a child's name. Where the rider photographed is under eighteen, the booking form also asks for the name, tax number, email address and telephone number of their parent or legal guardian, because it is that person, and not the child, who can authorise the publication of the images. Booking does not authorise publishing anything: that consent is asked for separately, on its own screen, and it is recorded in the guardian's name, with their tax number and their relationship to the child. Article 7 of the Spanish LOPDGDD sets fourteen as the minimum age for consenting to the processing of one's own data, but that threshold is not used here: for as long as the rider is under eighteen, it is always their parent or guardian who authorises.

Publishing a child's image in the portfolio, on the public site or on social media requires the express consent of the parent or guardian, identified and with the relationship on record. Without that stored consent the gallery cannot be made public or indexable: the database itself prevents it, it is not merely a promise made in this document.

Publishing a child's image also carries a requirement of its own under the right to one's own image, separate from data protection. It applies where the child is not mature enough to decide for themselves, a test that does not match the fourteen-year threshold mentioned earlier, which governs data protection only. In that case, article 3 of Spanish Organic Act 1/1982 requires the parent or guardian to give consent to publication in writing and to notify the Public Prosecutor (Ministerio Fiscal) beforehand, who then has eight days to object. If they object, a judge decides. Until that step is done, the photograph is not published. This last check is a manual one, carried out before publishing; unlike the consent described in the previous paragraph, it is not enforced by the database. None of this affects delivery: receiving and downloading the photographs you commissioned requires none of these steps.

Any parent or guardian may withdraw that consent at any time and ask for their child's images to be deleted, without giving reasons and at no cost.

If you believe a photograph of a child has been published without consent, write to claratmedia@gmail.com. It is taken down first and checked afterwards.

6. Who else sees the data

Data is not disclosed to anyone except the suppliers needed for the service to work, who act as processors under an article 28 GDPR agreement, and public authorities where the law requires it.

Processors:

  • Supabase Inc. (United States), database and authentication. The instance is hosted in the West EU region, in Ireland, within the European Economic Area.
  • Supabase Inc. (United States), storage of the photographs delivered to clients and of their previews. The files sit in the same project and the same European region as the database, in Ireland.
  • Vercel Inc. (United States), hosting and execution of the application. The photographs never pass through its servers: the application only signs the links, and the files travel directly between your browser and the storage.
  • Resend (United States), delivery of the service's emails, including access codes.
  • The Spanish tax and accounting firm that prepares the invoices on behalf of and in the name of the controller, acting as a processor or as an independent controller depending on the case.
  • Backblaze Inc. (United States), encrypted cold backup of the original camera files.

7. International transfers

The service is designed so that data is stored inside the European Union: the database and the photographs delivered to clients, along with their previews, sit in Supabase's West EU region, in Ireland. The application, by contrast, runs on Vercel's infrastructure, which may serve the request from outside the European Union; along the way it processes the session cookie, the IP address, the user agent and the booking data you are looking at, but the photographs never pass through that server. That processing outside the European Union is also an international transfer and is covered by the safeguards listed below.

Even so, the suppliers listed above are US companies and their support staff may occasionally access data from outside the European Economic Area. Such access constitutes an international transfer and is covered by:

  • The standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914, signed with each supplier as part of its data processing agreement.
  • Where the supplier is certified, the Commission adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework.
  • Supplementary technical measures: encryption in transit and at rest, access to original files only through signed links that expire after fifteen minutes, and per-client isolation enforced by row level security in the database.
You can request a copy of the safeguards in place by writing to claratmedia@gmail.com.

8. How long data is kept

Each item is kept for as long as its purpose requires and then for as long as liabilities could arise. After that it is deleted or anonymised.

  • Booking and invoicing data: six years from the close of the transaction under article 30 of the Spanish Commercial Code, and four years for tax purposes under article 66 of the General Tax Act. The longer period applies.
  • Client gallery: available for twelve months from publication. It is archived after that and stops being visible.
  • Original camera files: five years in cold storage as the author's archive, unless deletion is requested sooner.
  • Image consents: for as long as they are in force and five years after withdrawal, as evidence of when they were given and when they were withdrawn.
  • Download and audit records: twelve months.
  • Data of people who get in touch but do not book: twelve months from the last message.
  • User account: for as long as it is active; if you ask to close it, it is deleted except for what must be kept by legal obligation.
  • Phone notification subscription: for as long as you keep it active. If you turn the notifications off in your browser they stop being sent, and the subscription is deleted on its own as soon as the push service reports that the browser no longer has it. It is also deleted when you delete your account.

9. Your rights

You may exercise the following rights at any time and free of charge:

  • Access: find out what data is processed and obtain a copy (article 15 GDPR).
  • Rectification: correct anything wrong or incomplete, for example the horse's or the rider's name (article 16).
  • Erasure: ask for your data to be deleted and your photographs taken down (article 17).
  • Objection: object to a specific processing operation on grounds relating to your particular situation (article 21).
  • Restriction: ask that data be kept but not used while a disagreement is resolved (article 18).
  • Portability: receive your data in a structured, commonly used format, or have it sent to another controller (article 20).
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand (article 7.3).
The quickest way to exercise erasure is the «Remove my photos» button inside your account. It records the request and applies removal to every photograph linked to your rider-and-horse combination, not just to one gallery.

10. How to exercise them, and their limits

Just write to claratmedia@gmail.com stating which right you are exercising. Reasonable verification of your identity may be requested if there is genuine doubt about who is asking. Requests are resolved within one month, extendable to two if complex, with notice of the reason.

A few limits, stated plainly so there are no surprises: invoices and accounting entries cannot be deleted while the legal obligation to keep them lasts; and deleting a photograph does not bind third parties who had already downloaded it legitimately, although they can be asked to take it down.

If you believe the processing does not comply with the rules, you can complain to the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid, sedeagpd.gob.es), preferably after trying to resolve it in writing with the controller.

11. Security

The technical and organisational measures in place are proportionate to the risk (article 32 GDPR) and are built into the design of the service rather than bolted on at the end:

  • Your sign-in needs no password: you get an email with a one-time link or code that expires within minutes and cannot be used twice. The sign-in screen also accepts a password, but one can only be set from the management dashboard, which client accounts cannot reach; where a password exists, Supabase stores it as a hash, never in plain text, and there is no way to read it from this site.
  • Sessions held in first-party cookies flagged SameSite equal to Lax, so they are only ever sent to this site, and deleted from your browser when you press «Sign out».
  • Row level security in the database: each client can only read their own bookings, galleries and photographs, and that separation is enforced by the server, not by the screen.
  • Delivery files are not public addresses: they are served through signed links that expire after fifteen minutes.
  • HTTPS encryption in transit across the whole site, and encryption at rest in storage.
  • An in-house audit log of significant events, kept for twelve months.

12. Changes to this policy

This policy may be updated. Every version carries a number and a date, and the version under which each consent was given is stored alongside the consent itself, so it is always possible to know which text was accepted.

If a change materially affects processing already under way, notice is given by email before it is applied.