Privacy

Privacy Policy

We explain how the company processes data when handling an enquiry and administering a booking, and when it shares that data with the selected independent tattoo artist.

Controller
TETOVÁNÍ s.r.o.
Company ID (IČO)
05916933
Revision date
9 August 2026

Controller and contact details

The controller for operating the website, receiving and administering enquiries, maintaining its own internal records and meeting its own accounting and legal obligations is TETOVÁNÍ s.r.o., Company ID (Company ID (IČO)) 05916933, with its registered office at Stará 97/17, Zábrdovice, 602 00 Brno, registered with the Regional Court in Brno, Section C, File 98839. The tattooing service itself is not provided by the company, but by the selected tattoo artist acting as an independent business under their own trade authorisation.

The selected tattoo artist receives only the data needed to assess and provide their service. You will receive their identity, contact details and information about their role in the processing in an individual offer or written booking confirmation before the relevant data is shared. For purposes they determine themselves, particularly professional assessment of the project, performance of the tattooing-service contract, safe provision of the service, final collection of the price and receipt of the balance, their own accounting obligations and complaints, the selected tattoo artist is an independent controller. TETOVÁNÍ s.r.o. is an independent controller for the website, the initial enquiry, operation of the booking interface and its own administrative, accounting and legal purposes. Under a written power of attorney, it may also conclude a contract on behalf of the selected tattoo artist, administer the booking and deposit, and receive notices from the client. This contractual representation does not in itself change the allocation of roles under the GDPR. For their own purposes, the company and the selected tattoo artist are independent controllers. To the extent that administration is carried out solely on the documented instructions of the selected tattoo artist, the company processes data under a written agreement pursuant to Article 28 of the GDPR. Access is limited to data necessary for the specific enquiry, booking, deposit, communication or complaint; data is not automatically shared beyond that scope. Questions about the company's processing may be sent toinfo@tattoobar.cz.

What data we use

We limit the data we use to what is necessary for communication and the provision of the service.

  • Name and contact details
  • Description of the design, placement and approximate size
  • Selected tattoo artist, booking and changes to it
  • Deposit, payment, refund and related documents
  • Communication about a specific enquiry and appointment
  • Source of the visit and advertising parameters of the form
We do not collect health data in the online system.The paper declaration for the session is not part of the website processing described in this policy. The controller of the data contained in that declaration is the selected Provider, who uses it to assess and provide their service safely, comply with legal obligations and protect legal claims. The Administrator may retain it only on the Provider's documented instructions and within the scope of a written agreement pursuant to Article 28 of the GDPR. The company's CRM records only the fact that the declaration was signed, the date, the document version and the person who verified the signature. Answers, health notes and a scan of the document are not uploaded to Tilda or the CRM.

Purposes and legal basis

Handling enquiries and bookings

The company uses the data to receive and respond to an enquiry, select and introduce a suitable tattoo artist, administer its own operations and, once the relevant documents have been signed, arrange, confirm, change or cancel a booking on behalf of the selected tattoo artist. For the company's own purposes, the legal basis is its legitimate interest in receiving enquiries securely and with an auditable record, and in administering the studio. Where the company acts solely on the tattoo artist's documented instructions, the processing is governed by a written agreement pursuant to Article 28 of the GDPR. The company and the Provider do not act as joint controllers unless they jointly determine the purposes and means; if they introduce such a process in the future, they will enter into an arrangement pursuant to Article 26 of the GDPR before it begins, and the essence of that arrangement will be made available to the client. This does not make the company the provider of the tattooing service. The selected tattoo artist uses the necessary data to take pre-contractual steps at the customer's request, perform their contract, provide the service safely, comply with legal obligations and protect legal claims. Their exact identity, contact details, purposes, legal bases and retention periods are communicated to the customer before the data is shared or, at the latest, when the tattoo artist obtains it.

Required and optional data

Your name, description of your idea, chosen contact detail and confirmation that you have read this policy are required to submit an online enquiry. You may choose telephone, WhatsApp, email, Instagram or Facebook as the contact channel. Only the contact detail for the selected channel is required. Further tattoo-related information and voluntary marketing consent are optional. Confirming that you have read this policy is not consent to marketing.

Payments, documents and legal obligations

The company processes data about its own payments and accounting documents to meet its legal obligations and protect its claims. It receives, records, applies or refunds a deposit for the selected tattoo artist's service only on that artist's behalf and for their account under a written power of attorney; it links each payment to the tattoo artist and booking and processes only the data necessary to receive, confirm, account for and refund the payment and to document compliance with legal obligations. The company is an independent controller for its own records of payments received and refunded, security and compliance with its own legal obligations. To the extent that it manages a booking, communicates or carries out an administrative action solely on the Provider's documented instructions, it acts as the Provider's processor under a written agreement pursuant to Article 28 of the GDPR. The Provider remains an independent controller for the tattooing-service contract, professional assessment, informed consent, final payment and substantive handling of complaints. The customer pays the final balance directly to the selected tattoo artist, who receives it and issues the receipt for the service.

This policy does not cover the sale of gift vouchers. If a specific voucher offer becomes available, the customer will receive separate information about the issuer, contracting party, purposes, legal bases, recipients and retention period before providing any data.

Secure operation and system protection

We may use necessary technical records to secure the form, detect misuse, restore data and manage incidents. The legal basis is our legitimate interest in the secure operation of the website and CRM and in data protection. We limit the scope and retention period to the necessary minimum.

The form uses Tilda's standard anti-spam protection. Google reCAPTCHA does not load during an ordinary page view. If a visitor repeatedly and expressly submits the form from the same IP address, Tilda's server may request additional Google reCAPTCHA verification through forms.tildaapi.one. During that verification, Tilda as a processor and Google Cloud EMEA Limited as a further processor engaged by Tilda may process the IP address, browser and device data, and behaviour and interaction data. The necessary _GRECAPTCHA cookie is set when the verification begins. The purpose is security analysis and protection of the form against spam and misuse, not analytics or marketing for this website. The legal basis for the company's processing is its legitimate interest in the secure operation and protection of the form and data pursuant to Article 6(1)(f) of the GDPR.

To display the website consistently and legibly, we load fonts from fonts.googleapis.com a fonts.gstatic.com. With this request, Google receives the IP address, requested URL, user agent and referrer. Google Fonts does not set or record cookies during this load, and the company does not use this technical data for its own analytics or marketing. The legal basis for the company's processing is its legitimate interest in displaying the website consistently, legibly and in a securely maintainable way pursuant to Article 6(1)(f) of the GDPR. If the external-font request is blocked, the website uses a local fallback font and remains functional.

Recipients and services used

The selected independent tattoo artist may receive necessary data so that they can assess the enquiry, prepare a design, communicate about the appointment and provide their own service. We will disclose the exact identity and contact details before the relevant data is shared. The company uses Tilda as a processor for forms and website management. It uses Google services as a processor, within the scope of the agreed services, for its own internal CRM, files, calendar and operational email. When Google Fonts loads, Google is a separate recipient of the technical data in the HTTP request for the operation of this web service. If Tilda's form protection requires Google reCAPTCHA, Google Cloud EMEA Limited processes technical data as a further processor engaged by Tilda for form security and risk analysis. In this chain, TETOVÁNÍ s.r.o. remains the controller, Tilda the processor and Google Cloud EMEA Limited a further processor. This model reflects the service rules applicable from 2 April 2026, under which the reCAPTCHA customer acts as controller and Google as processor. Further information is provided in the officialreCAPTCHA FAQ. The tattoo artist may use their own services and recipients and must inform you about them in accordance with their actual role. Only authorised persons have access to the company's records, and only to the extent necessary for their duties. We do not sell data.

Some providers may process data on technical infrastructure outside the European Economic Area. In that event, we use appropriate legal safeguards, in particular an adequacy decision or standard contractual clauses. You may request information about the safeguard used, or a copy of it, atinfo@tattoobar.cz.

We obtain data directly from you and from technical form data, such as the page address and advertising parameters. We do not make decisions to accept or reject an enquiry solely by automated means, and we do not carry out profiling that produces legal or similarly significant effects.

Retention periods

We determine retention periods by purpose and calculate them for the specific enquiry, service or document. We do not automatically retain the client's entire record for 10 years.

  • Enquiry without a booking
    Usually 6 months from the last communication. If you expressly ask us to contact you later, we retain the enquiry for no longer than 12 months.
  • Copy of the submitted form in Tilda
    We retain a copy of an expressly submitted enquiry in the Tilda interface for no longer than 30 days; we then remove it from Tilda. This does not affect purpose-limited records to which the enquiry was lawfully transferred for handling and administration under this policy.
  • Client operational record and booking
    The company's administrative record is retained for the duration of the relationship and for 3 years after the relevant booking is completed or cancelled. This period does not determine the retention of the tattoo artist's separate records.
  • Restricted legal archive
    The necessary minimum for the establishment, exercise or defence of legal claims may be retained in a restricted-access archive after ordinary record-keeping ends, for no longer than 10 years from completion of the service or the due date of the relevant claim. Routine notes, reference files and communications are not transferred to that archive unless they are necessary for a specific dispute.
  • Accounting and tax documents
    Accounting documents are generally retained for 5 years from the end of the relevant accounting period. Financial statements and annual reports are retained for 10 years. VAT documents, where this obligation applies to the controller, are retained for 10 years from the end of the relevant tax period.
  • Marketing
    Until consent is withdrawn or an objection is raised, and for no longer than 3 years from the last active contact unless renewed. We retain a minimal opt-out record for as long as we conduct marketing so that we do not add you to the mailing list again by mistake.
  • Evidence of marketing consent or withdrawal
    We retain the necessary record of the wording and scope of the consent, and of its grant or withdrawal, for 5 years from withdrawal of consent or the end of marketing, unless a dispute or inspection is in progress.
  • Evidence of consent to publish specific photographs
    We retain a record of the specific file, purpose, selected channels, wording and granting of consent for 10 years from the date it was granted. If consent is withdrawn, a new ten-year evidence-retention period begins at the time of withdrawal. The consent record does not contain the photograph itself. We manually remove already-published copies from the affected channels and record that this was done.
  • Paper declaration at the studio
    The paper document is not part of the company's website records described in this policy. Its controller is the selected Provider. The Provider retains it only for as long as necessary to document the service safely, comply with legal obligations and protect legal claims, for no longer than 10 years unless the law requires a longer period; if the reason for retaining it ends sooner, the document is securely destroyed. The company's administrative record contains only the fact that it was signed, the date, the document version and the person who verified it. It does not contain the answers, health notes or a scan, and is governed by the period for the administrative record or restricted legal archive described above.
  • Operational and security records
    Ordinary access logs are retained for 12 months, and financial and administrator audit records for 24 months. Closed requests to exercise data subject rights and security incidents are retained for 5 years.
  • Form protection and reCAPTCHA
    We do not create a separate visitor profile in the CRM from the reCAPTCHA result. The _GRECAPTCHA cookie and related technical data are processed by Google Cloud EMEA Limited as a further processor for the period determined by the provider's settings for performing and protecting the security check; the company does not technically determine that period. Tilda retains its necessary security records only for as long as needed to protect the form and address misuse under its contractual rules.
  • Google Fonts
    The company does not separately store the technical data from the font request. Google may retain it for the period determined by its rules for operating, securing and delivering the service; the company does not technically determine that period.

Once the relevant period has expired, we delete or irreversibly anonymise the data. If a dispute, inspection or other proceeding is in progress, we retain only the affected data until it has been finally concluded and the related periods have expired.

Marketing and photographs

A response to an enquiry, appointment confirmation, deposit information and a session reminder are service messages. We do not add unnecessary advertising content to them.

We send news and offers by email and SMS only on the basis of separate, voluntary consent or another legal basis permitted by applicable law. Consent may be withdrawn at any time by replying to the message or by emailinginfo@tattoobar.cz.

The company publishes photographs on its own website, its own social-media accounts or in its own advertising only on the basis of separate consent granted for the specific photographs and channels. Publication by the tattoo artist is separate processing, for which the artist must provide their own information and legal basis. Refusing publication does not affect provision of the service. Consent to publication may also be withdrawn at any time by contacting the controller to whom it was given.

Your rights

Depending on the circumstances, you may request:

  • Access to personal data
  • Correction of inaccurate data
  • Erasure or restriction of processing
  • Data portability
  • Objection to processing
  • Withdrawal of consent previously given

Send a request concerning the company's processing to info@tattoobar.cz. We may reasonably verify your identity. For processing carried out by the selected tattoo artist, use the contact details provided in the individual offer or booking confirmation. The company may help you identify whom to send the request to, but that assistance does not replace exercising your rights with the relevant controller. You also have the right to lodge a complaint with the Office for Personal Data Protection,uoou.gov.cz.

Need something amended?

Tell us which data or specific communication your request concerns.

Contact the studio