Privacy Policy
This document explains which personal data we process when you book a tattoo, request a callback, submit a review or order a gift voucher.
Personal Data Controller
- Controller
- Marina Cheremnykh
- Czech business ID (IČO)
- 12345678
- Address
- Cesta brigádníků 819, Kralupy nad Vltavou, 278 01
- GDPR contact
- admin@sidmaink.cz
- Phone
- +420 776 053 175
- Effective date
- 6.6.2026
The personal data controller is Marina Cheremnykh, Czech business ID 12345678, e-mail: admin@sidmaink.cz, phone: +420 776 053 175.
Clients' personal data is processed in connection with booking, preparing and performing tattoo services, communicating with the client, handling complaints and fulfilling legal obligations.
What Data We Process
We may process, in particular, first and last name, date of birth, phone, e-mail, booking and service information, and data provided in the client questionnaire.
The client questionnaire may also contain health information needed to assess whether the tattoo can be performed safely. This data is treated as confidential and is not used for marketing purposes.
We also process data that you provide during communication with the studio, such as preferred date, selected service, message, references, photographs or sketches attached to an enquiry.
For gift vouchers, we also process data needed to create and deliver the voucher, such as buyer name, contact details, recipient e-mail, amount, variable symbol, voucher message and PDF files generated during the order.
For reviews, we process name, contact, rating, selected service and review text. If a review is later published, we use only the data and scope agreed with the client.
Purposes and Legal Bases
Data from booking and contact forms is used to answer enquiries, arrange consultations, prepare designs, confirm appointments and perform a contract or pre-contractual steps requested by the client.
Gift voucher data is used to handle the order, create the voucher, check payment, deliver PDF documents and keep related communication records.
Clients' personal data is also processed in connection with performing tattoo services, handling complaints and fulfilling legal obligations.
Some data is also stored based on legitimate interest, especially protection of legal claims, form security, abuse prevention and proof of communication. Data on accounting or tax documents is stored under legal obligations.
- Marketing messages are sent only with separate consent or where the law allows communication with existing customers. Consent can be withdrawn at any time.
- We use Umami for basic traffic and event measurement. Google Analytics cookies are used only after consent is given in the cookie banner.
- The mandatory form confirmation proves that you have read this policy; for bookings, the main legal basis is handling your request and the contractual relationship, not consent.
How We Store Data
Paper client questionnaires and signed informed consents are stored in lockable storage that clients and other unauthorised persons cannot access.
Only the controller or an expressly authorised person has access to the documentation.
If some data is stored electronically, it is protected by an access password and access is limited to authorised persons only.
Data Sharing
Clients' personal data is not sold and is not routinely provided to third parties. If the studio uses external services necessary for its operation, such as e-mail, hosting, a booking system or accounting, data may be made available only to the necessary extent.
Forms are submitted to the form service operated for the studio. This service handles validation, anti-spam protection, attachments and delivery of notifications to the studio.
Selected form data may be delivered to Telegram as an internal studio notification so we can respond quickly. Attachments may contain references, sketches or photographs sent by the client.
We also use technical providers for hosting, e-mail, security tools and analytics. If personal data is transferred outside the EU/EEA, this is done only under GDPR-compliant safeguards, such as standard contractual clauses or another suitable mechanism.
Retention Periods
Data from ordinary enquiries and bookings is stored for the time needed to handle communication, booking, design preparation and service delivery. After that, we keep it only as long as necessary to protect legal claims.
Client questionnaires, informed consents and related documentation are normally stored for 5 years from the last service provided or the last record concerning the client.
If there is a legal obligation or another legitimate reason for longer storage, especially the need to protect or exercise legal claims, the relevant data may be stored for the strictly necessary period.
After the specified period expires, we assess whether further storage of the data is still necessary.
Unrealised enquiries are usually deleted or anonymised no later than 12 months after the last communication.
Accounting and tax documents are stored for the period required by law, usually up to 10 years. Marketing contacts are kept until consent is withdrawn or the purpose expires. Analytics data follows the settings of the analytics tools we use, especially Umami and Google Analytics, and any cookie consent.
Data Disposal
After the retention period ends, paper documents are securely destroyed so the data cannot be read or restored, for example by shredding.
Electronic data is securely deleted if there is no longer a legal reason for further storage.
Client Rights
For privacy matters, contact us at admin@sidmaink.cz. We will handle your request without undue delay, usually within 1 month under GDPR.
Under the conditions set by GDPR, the client has in particular the right to request information about the processing of their personal data, access to the data, correction of inaccurate data and, where applicable, erasure or restriction of processing.
A request concerning personal data may be sent to admin@sidmaink.cz.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- The right to erasure does not automatically mean deletion of data we must keep because of a legal obligation, contract performance or defence of legal claims.
- The client also has the right to lodge a complaint with the Czech Data Protection Authority, www.uoou.cz.
Security and Confidentiality
All clients' personal data is treated as confidential. The studio takes appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration, disclosure or destruction.
Clients should not send sensitive data through forms unless it is necessary for arranging the tattoo. Health information should be shared only to the extent needed for safe assessment of the session and later in the client questionnaire at the studio.
Changes to This Policy
We may update this policy according to changes in the website, forms, services used or legal requirements. The current version is always available on this page.