How Agency Consent collects, uses, stores and protects personal data — for website visitors, platform users, and the subjects whose consent our customers record.
Agency Consent is operated by Imedia8 Ltd, a United Kingdom technology company that builds secure digital platforms for international organisations. In this policy, "we" and "us" mean Imedia8 Ltd. For any privacy enquiry, contact us and mark your message for the attention of the privacy team.
We handle three distinct kinds of personal data:
Website and contact-form data is processed on the basis of our legitimate interest in operating the site and responding to enquiries. Platform account data is processed to perform our contract with the customer organisation. Consent-record data belongs to a different arrangement: the customer organisation decides why and how it is collected and is the data controller; Imedia8 processes it strictly on that organisation's documented instructions as a processor. See our data processing page for detail.
Contact-form enquiries are kept for as long as needed to handle the enquiry and maintain the business relationship. Platform accounts exist for the life of the organisation's subscription. Consent records are retained according to each organisation's own configured retention policy. When a subject withdraws consent, the withdrawal is recorded against the original record — with a full audit trail — rather than erasing the history the record exists to prove.
Under UK and EU data protection law you may have the right to access, rectify, erase or restrict personal data about you, to object to processing, to data portability, and to withdraw consent you have given. If your data sits in a consent record, the organisation that collected it is the controller — contact that organisation to exercise your rights, and we will support it in responding. For anything we control directly, contact us. You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office.
Personal-data fields in consent records are encrypted at rest. Signatures and consent media are stored on private storage and served with restrictive, download-only headers. Back-office access is role-based, with two-factor authentication supported on every back-office account. Consent records are immutable once captured, changes to them are written to an audit trail, and each organisation's data is isolated from every other organisation's.
Questions about this policy or about how your data is handled: contact us and we will respond promptly.