1 Controller and contact details
The controller for the activities described here is “INSTITUTE OF MODERN TATTOOING Ε.Ε.”, a limited partnership established under Greek law which operates IMT — Institute of Modern Tattooing.
Registered office and postal contact: 6 Kairi Street, 10551, Municipality of Athens, Athens, Greece. General Commercial Registry (G.E.MI.) number: 194013603000. For enquiries, personal data matters and rights requests, contact info@imtstudies.com or write to INSTITUTE OF MODERN TATTOOING Ε.Ε. at that address, marked “Personal data”. Describe your request and how you would like to receive a response. No particular form or registered postal service is required.
2 Scope
This policy covers visitors, people contacting IMT and prospective students in Tattoo, PMU, SMP and additional training, including introductory discussions and necessary portfolio assessment.
The study period, staff, models’ health, class photography/video and video surveillance require separate information before relevant collection. On external pages, the operator’s own privacy information also applies.
3 Data sources and form functionality
Information comes from you. The form includes full name, email, telephone, city or country, one or more programmes of interest, current experience, a portfolio or Instagram link if provided, and how you heard about IMT.
Completing, previewing or copying an application does not submit it to IMT. Online submission is available only when the form displays an active “Submit application” option. Selecting it sends your details over a secure connection to the website server, where they are checked and stored in IMT’s application management system for review by the responsible personnel. The website confirms receipt with a reference number only after storage is confirmed. If only preview or copy is available, those actions do not send your details. Confirmation of receipt does not constitute acceptance, enrolment or reservation of a place and does not imply that an email is sent automatically.
Full name, email, telephone with country code, city or country, programme, current experience and how you heard about IMT require a response. The portfolio or Instagram link is optional and may be left blank. At least one programme and exactly one current experience option must be selected. You have no statutory duty to provide information for browsing. Leaving a required response empty prevents previewing and online submission. An individual reply requires a suitable contact channel, and a sample of work may be requested later where assessment is needed. For a general enquiry, you can contact info@imtstudies.com without completing an application.
Online submission records your answers, the application language, receipt time, reference number, the version of this notice and technical identifiers used to recognise repeated submissions. The record may also include handling status, necessary notes and correspondence history. Possible duplicate records are flagged for review by responsible personnel. The optional copy action places text on your device’s clipboard; you decide whether and where to paste or send it. Autofill and restoration of fields depend on your browser settings. On a shared device, clear the fields and copied text after use.
The “How did you hear about IMT?” answer is intended to help understand information channels, based on our legitimate interest in improving communication. The form requires a response, but you may state that you do not remember or prefer not to disclose how you heard about us. This choice does not prevent consideration of your application. You may object to use of the information for improving communication. Do not include other people’s names or details. Anonymous information, unlinked to an applicant record, is preferred for aggregate conclusions.
4 Purposes and lawful bases
Website delivery and security
Delivering a page and handling requests requires technical communication with your device, including its IP address, the requested file or page and HTTP request information sent by your browser. To limit abusive submissions, the server generates a cryptographically pseudonymised identifier from the IP address using a secret key. The application database uses a derived identifier to count attempts and does not store the original IP address in this mechanism. This does not exclude technical processing of IP addresses by hosting providers. Operation and protection rely on the legitimate interest in securely providing the website and preventing abuse under Article 6(1)(f) GDPR. This basis does not cover advertising tracking. Necessary hosting and technical support providers have access.
General enquiries
We use contact details, the enquiry and related correspondence to respond to communications addressed to us. The lawful basis is the legitimate interest in handling and answering the communication under Article 6(1)(f) GDPR. Responsible contact personnel have access.
Programmes and possible enrolment
For information about a particular programme, introductory discussions and consideration of possible enrolment, we use your name, necessary contact details, selected programmes, relevant experience and information needed for your request. The application is recorded in IMT’s application management system together with the necessary receipt and handling information described in section 3. The basis is steps taken at your request before entering into a contract under Article 6(1)(b) GDPR. Admissions personnel and, where needed, educators have access.
Portfolio assessment
Assessment of the requested level uses selected works or their link, relevant experience, necessary comments and the assessment outcome. Article 6(1)(b) GDPR applies only insofar as assessment is necessary for your requested programme. The educators undertaking assessment and responsible admissions personnel have access.
Exercising rights
We use requester details, request content, strictly necessary identification information, the response and records of action to comply with Articles 12 to 22 GDPR, under Article 6(1)(c). Persons handling and implementing the request have access.
Incidents and legal claims
Only information relevant to a specific incident or claim is used. The basis is the legitimate interest in investigation and establishing, exercising or defending legal claims under Article 6(1)(f), or a specific legal obligation under Article 6(1)(c). Responsible personnel, legal advisers and authorities have access to the extent necessary.
5 Portfolios and third party information
Portfolio access is intended to assess relevant works and educational readiness. It does not authorise collection of unrelated posts, contacts, messages or information revealing sensitive aspects of your life. We do not request account passwords. Public availability of works or images does not make them freely reusable for advertising.
A link is used to review the works you identify. Assessment does not grant general permission to download an entire account or retain screenshots. Keeping a selected copy is restricted to what is demonstrably necessary for the assessment and follows section 8. No licence to publish or commercially exploit the works is granted. Copyright remains with its holder; additional use requires a separate lawful arrangement.
Prefer selected works without clients’ names, contact information, identifiable faces or other unnecessary third-party information. Do not send health data or images unnecessary for the educational purpose. Even an image without a face may identify a person through a distinctive design or other features.
When another person’s information appears in a portfolio, its source is the applicant who shared it or the linked page they identified. Unnecessary information must be removed from assessment material. If third-party data is retained for a specific lawful purpose, that person receives information about its source, categories and processing within a reasonable period and no later than one month, or earlier at the first communication or disclosure, as the GDPR requires. Any statutory exception is assessed specifically and is not presumed merely because the material was public.
6 Recipients and security
Access within IMT is restricted to persons handling the particular enquiry and, where assessment is needed, the relevant educators. It is not intended for all educators, all partners or other students indiscriminately.
In the event of a specific legal obligation or dispute, data is disclosed to the appropriate recipients only to the extent necessary and with a lawful basis. There is no general permission to disclose an applicant’s entire file.
Vercel provides website hosting, content delivery and the application submission server. Supabase provides application storage and management and authentication for authorised users of the internal system. These providers process technical data and, when you submit an application, the details necessary for their respective services. You do not need an applicant account to submit the form. External technical personnel have access only where needed for support. Email providers process delivery details and content when you communicate by email. Where providers act on behalf of IMT, Article 28 GDPR commitments are required. Services determining their own processing purposes are subject to their own responsibility and privacy information.
Protecting data requires access restricted by responsibility, confidentiality, secure transmission, account protection and incident handling proportionate to risk. No transmission or storage method guarantees absolute security. If you suspect unauthorised use of your details, contact IMT through section 1.
7 Transfers outside the EEA
Access to international providers’ services, including Vercel and Supabase, may involve processing outside the European Economic Area, including the United States. Selecting a European hosting region does not itself assure that all support services and all processing remain within the EEA.
Any transfer by IMT is permitted only under Chapter V GDPR: an applicable adequacy decision covering the particular recipient, or appropriate safeguards such as the European Commission’s standard contractual clauses, with the necessary assessment and supplementary measures. Merely using the website does not constitute consent to a transfer.
You may ask the contact point in section 1 for information about recipients and countries relevant to your data and a copy of applicable safeguards, subject to protection of third-party rights. When you choose to follow an external link, such as Instagram, the relevant service’s own privacy information also applies.
8 Retention and deletion
Retention is determined by purpose using the criteria below. There is no single indefinite period for all data, and revisiting the website does not restart retention of earlier correspondence.
Technical data: processing for page delivery relates to serving the request. Additional security retention is limited to necessary investigation of errors or specific indications of abuse. When that need ends, the data is deleted or genuinely anonymised; continued website operation does not justify permanent retention of each visitor’s history. Submission rate counters use a one-hour window; expired entries are cleared on the next call to the mechanism and do not constitute browsing history.
General enquiries: until a final answer has been given and requested actions completed. Once the matter is closed, information no longer serving a specific obligation or pending matter is removed.
Applicants who do not enrol: until the admissions process for the requested programme or intake concludes, a final negative decision is made or interest is withdrawn, depending on the event that closes the particular request. Retention for a subsequent intake requires your request to continue and does not amount to subscription to a marketing list.
Portfolios: until assessment and the related admissions process conclude or interest is withdrawn. A specific reconsideration justifies retaining only the works and comments needed until its outcome. Access and unnecessary copies cease when the purpose ends.
Rights requests: until the final response and required actions have been completed. Thereafter, only necessary evidence of compliance is retained for a specific accountability obligation or an open investigation or complaint, until these conclude. Additional identification documents are not retained simply because they accompanied a request.
Specific disputes: relevant evidence alone is retained until final resolution and, where necessary, completion of enforcement or expiry of the applicable period for pursuing or challenging the particular claim. Any statutory suspension or interruption is taken into account. This does not extend retention of unrelated records.
On enrolment, only necessary data moves to the educational file, subject to the relevant notice. Backups, where they exist, must not be used as active records after the purpose ends; access is restricted to recovery and completed deletions must be reapplied before normal use resumes. The technical replacement cycle of backups does not create a new processing purpose.
9 Your rights
You may request confirmation of processing, access to and a copy of your personal data, rectification of inaccurate information and completion of incomplete information. Subject to the GDPR’s conditions, you may also request erasure or restriction of processing. Erasure is not absolute, particularly where particular information is lawfully needed for an obligation or legal claim.
You have a right to portability for data you have provided where processing is based on consent or a contract and carried out by automated means, subject to the statutory conditions. You may object to processing based on legitimate interests on grounds relating to your particular situation. We consider the objection and stop processing unless a lawful reason for continuing applies.
Where a particular activity is based on consent, you may withdraw it just as easily, without retrospectively affecting the lawfulness of earlier processing. Answering your enquiry or carrying out pre-contractual assessment is not based on general consent to this policy. Communication about your enquiry does not subscribe you to promotional messages. The right to object to direct marketing is absolute.
Submit your request to the contact point in section 1. We respond without undue delay and ordinarily within one month of receipt. If an extension of up to two additional months is necessary because of complexity or the number of requests, we inform you within the first month and explain why. Additional identification is requested only where there are reasonable doubts and only to the extent necessary, not through an automatic requirement for an identity document copy.
Exercising rights is generally free of charge. A fee or refusal is permitted only in the limited circumstances provided by the GDPR and must be explained. You may complain to the Hellenic Data Protection Authority or another competent supervisory authority, particularly where you usually live or work or where the alleged infringement occurred, and seek relief before the competent courts. You do not have to exhaust an internal IMT complaints procedure first.
Hellenic Data Protection Authority: www.dpa.gr, 1–3 Kifisias Avenue, 11523 Athens, Greece. Information and complaint submission are available through the Authority’s website.
10 Assessment and automated decisions
Preparing, previewing, copying, submitting or recording an application does not constitute an automated admissions decision or score the applicant. Educators assess portfolios and responsible personnel make admissions decisions. Technical field checks, recognition of repeated submissions and possible duplicate flags do not replace human assessment and are not automated admissions decisions under Article 22 GDPR.
11 Minors and sensitive information
The general form is not intended to collect medical history, information about conditions or other special categories of data. For questions about a minor’s possible participation, first request general guidance without sending identity or health documents through the form. Enrolment and lawful representation requirements are considered separately; the age limit stated for models does not itself determine the age requirements for prospective students.
12 Updates
The date and version appear at the beginning of this policy. Before data is used for a new purpose, the required information is provided and the relevant lawful basis is assessed. Publishing a revised text does not retrospectively legitimise processing or replace specific consent where it is required.
