GDPR
Privacy Policy
TODO before final legal approval: controller’s full legal name / business name, company ID, registered address and register details where applicable; exact email and payment providers; deposit, cancellation and rescheduling rules.
Controller: Taterka Ink — TODO legal identification. Contacts: taterkaink@gmail.com, taterkaink@icloud.com.
What we process, why and for how long
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account email, name, phone, form of address, profile image | account management | contract; legitimate interest for security | account lifetime |
| Booking contact details, design, size, placement, budget, appointment, history | preparing and providing the service | pre-contractual steps and contract | during the relationship and generally 3 years afterwards; tax records as required |
| Uploads references and body-area images | design and tattoo performance | contract; consent for optional body image | through performance, then no longer than 90 days unless required for a dispute |
| Payments amount, status and identifier; not full card data | deposit/payment and accounting | contract and legal obligation | statutory accounting and tax periods |
| Technical data IP, time, browser, device, security log | operation and security | legitimate interest; analytics only with consent | necessary period under settings |
| Newsletter email, status, time, source and wording version | news and released appointments | consent | until withdrawal; evidence retained proportionately for legal defence |
Body photographs
A photograph may indirectly reveal sensitive data. Upload is optional and the image may instead be shown in the studio. Do not include a face, intimate areas or medical documents. If it nevertheless contains special-category data, it will be processed only with explicit consent for the specific booking, withdrawable for future processing.
Recipients and transfers
Access is limited to Taterka and necessary hosting, database/storage, authentication, email and payment providers. Identified services: OpenAI Sites / Cloudflare infrastructure, Supabase Auth and, after consent, embedded Instagram content provided by Meta Platforms Ireland Limited. Exact email and payment providers are TODO. Any transfer outside the EEA must use a GDPR-compliant mechanism.
Your rights
You may request access, correction, erasure, restriction and portability, object and withdraw consent. You may complain to the Czech Data Protection Authority. Required booking data is necessary to provide the service. No solely automated decision-making with legal effects is used.