For the policy folder

Photo consent and safeguarding for a class book order

How consent is recorded twice, what happens to a child's photograph, what each parent can and cannot see, and what a setting needs in order to sign this off.

No director approves anything involving thirty children's photographs on the strength of a sentence on a pricing page. This is the page to read before you order and to print for the folder afterwards. The parent-facing version of the same answers is at /photo-privacy; this one is written for the person who has to sign it off.

Consent is recorded twice, by two different people

When you place the order you confirm that you hold each family's permission to use their child's photograph. That declaration is stored with the order along with the version of the wording you agreed to, when you agreed to it, and from where.

Then every parent confirms it again, themselves, on their own upload page - they cannot send a photograph without ticking their own box, and that tick is recorded against that child's seat with its own timestamp.

The point of the second one is that the permission does not rest on your word alone. If a family later says they never agreed, there is a record made by the family, not by the setting.

What happens to a photograph

It is used to draw that child's illustrations, and then it is deleted. It is not kept as a library, not attached to a marketing example, and not used to train any model.

It is never shown to another family. A parent's upload page shows their own child's name and the setting's name and nothing else - not the class list, not the other children, not how many families have responded.

Nothing about a child appears on any page a search engine can reach. The upload pages carry a noindex instruction and are addressed by a single-use token rather than by a guessable URL.

What each person can see

The parent sees their own child and the setting's name. That is the whole of it.

You, as the person who placed the order, see your class page: which seats have had a photograph and which have not, so you can chase the families who have not replied. You do not see other settings and nobody outside your order sees yours.

A link opens exactly one child's book and works once. If it is forwarded to somebody else it cannot overwrite a book that has already been made, and you can cancel and re-issue any link from your class page.

What to put in the folder

Print this page and the parent-facing one at /photo-privacy. Between them they cover the three things a policy check asks for: the lawful basis (explicit consent, captured from the parent), the retention period (deleted once the illustration is drawn), and the recipients (nobody outside the order).

If your setting needs something specific in writing that is not answered here - a named data-protection contact, a retention statement on letterhead, a supplier questionnaire - write to us and ask. We would rather answer a director's questionnaire than have a class quietly not go ahead because the paperwork was awkward.

What a family can ask for afterwards

To withdraw before the book is made: tell us and the seat is cancelled and refunded. Nothing has been drawn yet, so there is nothing to undo.

To have their data removed afterwards: the photograph is already gone, and the remaining record is the child's first name on their own book and the consent timestamps. Ask and we will remove what is left.

See a real chapter before you commit a class Nothing prints until you approve it What happens to the photos

Common questions

Is the parent's consent recorded, or just the school's?

Both, separately. You declare it at the point of ordering and each parent declares it again on their own upload page before they can send anything - two records, two timestamps, made by two different people.

How long do you keep the photograph?

Until the illustration is drawn, and then it is deleted. It is not retained as a library, not used as a marketing example and not used to train any model.

Can one parent see another family's child?

No. A parent's page shows their own child's name and the setting's name and nothing else. There is no class list on it and no way to reach another seat.

What if a link is forwarded to the wrong person?

A link opens one seat and works once, so it cannot overwrite a book that has already been made. You can cancel and re-issue any link from your class page at any time.

Do any of these pages appear in Google?

The upload pages do not - they carry a noindex instruction and are reached by a single-use token rather than a guessable address. Nothing identifying a child is published anywhere public.

Who do we contact about data protection?

Write to us through the contact page and say what your setting needs. A supplier questionnaire or a retention statement is an ordinary request and we would rather answer one than lose a class to paperwork.

Last updated:

If the paperwork is satisfied, the class itself takes a few minutes to set up.

Set up a class