GDPR

Privacy Policy

This document explains which personal data we process when you book a tattoo, request a callback, submit a review or order a gift voucher.

Personal Data Controller

Controller
Marina Cheremnykh
Czech business ID (IČO)
12345678
Address
Cesta brigádníků 819, Kralupy nad Vltavou, 278 01
GDPR contact
admin@sidmaink.cz
Phone
+420 776 053 175
Effective date
6.6.2026

The personal data controller is Marina Cheremnykh, Czech business ID 12345678, e-mail: admin@sidmaink.cz, phone: +420 776 053 175.

Clients' personal data is processed in connection with booking, preparing and performing tattoo services, communicating with the client, handling complaints and fulfilling legal obligations.

What Data We Process

We may process, in particular, first and last name, date of birth, phone, e-mail, booking and service information, and data provided in the client questionnaire.

The client questionnaire may also contain health information needed to assess whether the tattoo can be performed safely. This data is treated as confidential and is not used for marketing purposes.

We also process data that you provide during communication with the studio, such as preferred date, selected service, message, references, photographs or sketches attached to an enquiry.

For gift vouchers, we also process data needed to create and deliver the voucher, such as buyer name, contact details, recipient e-mail, amount, variable symbol, voucher message and PDF files generated during the order.

For reviews, we process name, contact, rating, selected service and review text. If a review is later published, we use only the data and scope agreed with the client.

How We Store Data

Paper client questionnaires and signed informed consents are stored in lockable storage that clients and other unauthorised persons cannot access.

Only the controller or an expressly authorised person has access to the documentation.

If some data is stored electronically, it is protected by an access password and access is limited to authorised persons only.

Data Sharing

Clients' personal data is not sold and is not routinely provided to third parties. If the studio uses external services necessary for its operation, such as e-mail, hosting, a booking system or accounting, data may be made available only to the necessary extent.

Forms are submitted to the form service operated for the studio. This service handles validation, anti-spam protection, attachments and delivery of notifications to the studio.

Selected form data may be delivered to Telegram as an internal studio notification so we can respond quickly. Attachments may contain references, sketches or photographs sent by the client.

We also use technical providers for hosting, e-mail, security tools and analytics. If personal data is transferred outside the EU/EEA, this is done only under GDPR-compliant safeguards, such as standard contractual clauses or another suitable mechanism.

Retention Periods

Data from ordinary enquiries and bookings is stored for the time needed to handle communication, booking, design preparation and service delivery. After that, we keep it only as long as necessary to protect legal claims.

Client questionnaires, informed consents and related documentation are normally stored for 5 years from the last service provided or the last record concerning the client.

If there is a legal obligation or another legitimate reason for longer storage, especially the need to protect or exercise legal claims, the relevant data may be stored for the strictly necessary period.

After the specified period expires, we assess whether further storage of the data is still necessary.

Unrealised enquiries are usually deleted or anonymised no later than 12 months after the last communication.

Accounting and tax documents are stored for the period required by law, usually up to 10 years. Marketing contacts are kept until consent is withdrawn or the purpose expires. Analytics data follows the settings of the analytics tools we use, especially Umami and Google Analytics, and any cookie consent.

Data Disposal

After the retention period ends, paper documents are securely destroyed so the data cannot be read or restored, for example by shredding.

Electronic data is securely deleted if there is no longer a legal reason for further storage.

Client Rights

For privacy matters, contact us at admin@sidmaink.cz. We will handle your request without undue delay, usually within 1 month under GDPR.

Under the conditions set by GDPR, the client has in particular the right to request information about the processing of their personal data, access to the data, correction of inaccurate data and, where applicable, erasure or restriction of processing.

A request concerning personal data may be sent to admin@sidmaink.cz.

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

  • The right to erasure does not automatically mean deletion of data we must keep because of a legal obligation, contract performance or defence of legal claims.
  • The client also has the right to lodge a complaint with the Czech Data Protection Authority, www.uoou.cz.

Security and Confidentiality

All clients' personal data is treated as confidential. The studio takes appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration, disclosure or destruction.

Clients should not send sensitive data through forms unless it is necessary for arranging the tattoo. Health information should be shared only to the extent needed for safe assessment of the session and later in the client questionnaire at the studio.

Changes to This Policy

We may update this policy according to changes in the website, forms, services used or legal requirements. The current version is always available on this page.