Privacy Policy and Information on the Processing of Personal Data (GDPR)
Effective date: 8. 7. 2026
1. Data Controller
The controller of personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR) is:
Ivana Kleinová
Business ID (IČO): 17937833
Address: Holandská 277/22, 101 00 Prague, Czech Republic
Email: ivklevitattoo@gmail.com
(hereinafter referred to as the “Controller”).
The Controller has not appointed a Data Protection Officer.
2. What Personal Data We Process
The Controller may process the following categories of personal data:
Identification data (name, surname).
Contact data (email address, telephone number, social media profile).
Booking and appointment information.
Information provided during consultations.
Payment and invoicing data where required by law.
Photographs of completed tattoos, where consent has been provided.
Communication records exchanged via email, social media, contact forms, or messaging applications.
The Controller processes only personal data necessary for the purposes described below.
3. Purposes and Legal Bases for Processing
Personal data are processed for the following purposes:
a) Booking and provision of tattoo services
Legal basis: Article 6(1)(b) GDPR – performance of a contract or steps prior to entering into a contract.
Purpose:
managing appointments,
communicating with clients,
providing requested services.
b) Compliance with legal obligations
Legal basis: Article 6(1)(c) GDPR.
Purpose:
accounting,
tax obligations,
responding to requests from public authorities where required by law.
c) Protection of legitimate interests
Legal basis: Article 6(1)(f) GDPR.
Purpose:
protection against legal claims,
maintaining records necessary for business administration,
ensuring security of communications and services.
d) Marketing and presentation of work
Legal basis: Article 6(1)(a) GDPR – consent.
Purpose:
publication of tattoo photographs on the website,
publication of tattoo photographs on social media platforms,
sending newsletters or marketing communications.
Consent is voluntary and may be withdrawn at any time.
4. How Long We Keep Personal Data
Personal data are retained only for as long as necessary for the relevant purpose:
Contractual and booking data: up to 3 years after the last service provided.
Accounting and tax documents: for the period required by applicable law.
Marketing data and consents: until consent is withdrawn or for a maximum of 5 years from the date of consent.
After the retention period expires, personal data will be securely deleted or anonymized.
5. Recipients of Personal Data
Personal data may be shared with trusted service providers assisting the Controller in operating the business, including:
accounting providers,
website hosting providers,
email service providers,
online booking system providers,
cloud storage providers,
payment service providers.
These recipients process personal data only on the basis of the Controller’s instructions and under appropriate contractual safeguards.
6. International Transfers
Personal data may be processed through services whose servers are located outside the European Economic Area (for example, Google, Meta, Microsoft or similar providers).
Where such transfers occur, the Controller ensures that appropriate safeguards are in place in accordance with Chapter V GDPR.
7. Your Rights
Under GDPR, you have the right to:
request access to your personal data,
request correction of inaccurate data,
request deletion of personal data,
request restriction of processing,
object to processing based on legitimate interest,
receive your personal data in a portable format,
withdraw consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
To exercise your rights, contact:
You also have the right to lodge a complaint with the relevant supervisory authority. In the Czech Republic, this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).
8. Security Measures
The Controller has implemented appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
Access to personal data is limited to authorized persons only.
9. Changes to This Policy
The Controller reserves the right to amend or update this Privacy Policy at any time.
The latest version will always be available on the Controller’s website or provided upon request.
By using the services of the Controller, you acknowledge that you have been informed about the processing of your personal data in accordance with this Privacy Policy.