Privacy Policy
In line with applicable law, OneWish™ is committed to applying the technical and organizational measures appropriate to the risk level of the personal data collected.
Laws this policy complies with
This Privacy Policy is adapted to current Spanish and EU data protection law, specifically:
Regulation (EU) 2016/679 (GDPR)
Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPD-GDD)
Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE)
1. Data Controller
Itziar Samaniego, with contact email onewishvisuals@gmail.com, is the controller responsible for processing personal data collected through this website.
2. What data we collect and why
Contact form / inquiries — name, email, message, project details. Basis: consent / pre-contractual steps.
Client services — name, contact details, briefs, supplied images/video. Basis: performance of a contract.
Newsletter — name, email. Basis: consent.
Analytics — anonymized usage data. Basis: consent via cookie banner.
3. Categories of data processed
We only process basic identification data (e.g. name, email address, message content). We do not process special categories of data under Article 9 GDPR (health, religious beliefs, political opinions, etc.), and we ask that you don't include this type of information in any form or message to us.
4. Data retention
Your data is kept only as long as necessary for the purpose it was collected for — as a general rule, 12 months from your last interaction, or until you request deletion — and in any case no longer than required by Spanish tax/accounting law (generally up to 5 years for invoicing-related data).
5. Who we share data with
We don't sell your data. It may be shared with:
Framer, our website hosting and forms provider.
Google, for communication.
AI tools you use on client material, if relevant — e.g. editing/generative tools, only when necessary to deliver a commissioned project, and only with material you've explicitly provided for that purpose.
Public authorities, when legally required.
Some of these providers may process data outside the EU/EEA (e.g. the US). Where this happens, transfers rely on adequacy decisions or Standard Contractual Clauses, as required by GDPR Chapter V.
6. Minors
In line with Article 8 GDPR and Article 7 of Organic Law 3/2018, only users aged 14 or over may lawfully consent to the processing of their own personal data on this site. If you are under 14, a parent or legal guardian must provide consent on your behalf for any data processing to be lawful.
7. Your rights
Under GDPR, you have the right to:
Access the personal data we hold about you
Rectify inaccurate data
Erase your data ("right to be forgotten")
Restrict or object to processing
Data portability
Withdraw consent at any time, without affecting prior lawful processing
Not be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you
To exercise any of these rights, email [your@email.com] with: your name, a clear description of the right you'd like to exercise and why, and a contact address for our reply. We may ask for reasonable proof of identity where needed to protect your data. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) — www.aepd.es.
8. Security
This site uses SSL encryption to protect data in transit. We apply reasonable technical and organizational measures against unauthorized access, loss, or alteration of your data. While no system can guarantee absolute security, we commit to notifying you without undue delay if a data breach is likely to result in a high risk to your rights and freedoms, as required by Article 4 GDPR. All personal data is treated as confidential, including by anyone we authorize to access it on our behalf.
9. Links to third-party sites
This website may contain links to third-party sites not operated by [Your name]. Those sites have their own privacy policies,
for which they alone are responsible.
10. Changes to this policy
This policy may be updated periodically to reflect legal changes or AEPD guidance. Continued use of the site after an update implies acceptance of the revised policy. We recommend checking this page from time to time.
Last updated: 10/10/2026
In line with applicable law, OneWish™ is committed to applying the technical and organizational measures appropriate to the risk level of the personal data collected.
Laws this policy complies with
This Privacy Policy is adapted to current Spanish and EU data protection law, specifically:
Regulation (EU) 2016/679 (GDPR)
Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPD-GDD)
Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE)
1. Data Controller
Itziar Samaniego, with contact email onewishvisuals@gmail.com, is the controller responsible for processing personal data collected through this website.
2. What data we collect and why
Contact form / inquiries — name, email, message, project details. Basis: consent / pre-contractual steps.
Client services — name, contact details, briefs, supplied images/video. Basis: performance of a contract.
Newsletter — name, email. Basis: consent.
Analytics — anonymized usage data. Basis: consent via cookie banner.
3. Categories of data processed
We only process basic identification data (e.g. name, email address, message content). We do not process special categories of data under Article 9 GDPR (health, religious beliefs, political opinions, etc.), and we ask that you don't include this type of information in any form or message to us.
4. Data retention
Your data is kept only as long as necessary for the purpose it was collected for — as a general rule, 12 months from your last interaction, or until you request deletion — and in any case no longer than required by Spanish tax/accounting law (generally up to 5 years for invoicing-related data).
5. Who we share data with
We don't sell your data. It may be shared with:
Framer, our website hosting and forms provider.
Google, for communication.
AI tools you use on client material, if relevant — e.g. editing/generative tools, only when necessary to deliver a commissioned project, and only with material you've explicitly provided for that purpose.
Public authorities, when legally required.
Some of these providers may process data outside the EU/EEA (e.g. the US). Where this happens, transfers rely on adequacy decisions or Standard Contractual Clauses, as required by GDPR Chapter V.
6. Minors
In line with Article 8 GDPR and Article 7 of Organic Law 3/2018, only users aged 14 or over may lawfully consent to the processing of their own personal data on this site. If you are under 14, a parent or legal guardian must provide consent on your behalf for any data processing to be lawful.
7. Your rights
Under GDPR, you have the right to:
Access the personal data we hold about you
Rectify inaccurate data
Erase your data ("right to be forgotten")
Restrict or object to processing
Data portability
Withdraw consent at any time, without affecting prior lawful processing
Not be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you
To exercise any of these rights, email [your@email.com] with: your name, a clear description of the right you'd like to exercise and why, and a contact address for our reply. We may ask for reasonable proof of identity where needed to protect your data. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) — www.aepd.es.
8. Security
This site uses SSL encryption to protect data in transit. We apply reasonable technical and organizational measures against unauthorized access, loss, or alteration of your data. While no system can guarantee absolute security, we commit to notifying you without undue delay if a data breach is likely to result in a high risk to your rights and freedoms, as required by Article 4 GDPR. All personal data is treated as confidential, including by anyone we authorize to access it on our behalf.
9. Links to third-party sites
This website may contain links to third-party sites not operated by [Your name]. Those sites have their own privacy policies,
for which they alone are responsible.
10. Changes to this policy
This policy may be updated periodically to reflect legal changes or AEPD guidance. Continued use of the site after an update implies acceptance of the revised policy. We recommend checking this page from time to time.
Last updated: 10/10/2026