Legal

Data Processing Addendum

Your clients’ data stays yours. This is the Article 28 agreement that says so, and it applies from the day you register.

Last updated

1. Who this is between

This Addendum is between you — the studio or artist with an InkTok account — and Amare Baltic SIA. It forms part of the Terms of Service and applies automatically from the day you register. You do not have to sign anything separately.

For your clients' personal data, you are the controller and we are the processor. You decide what is collected and why; we only act on your instructions. Article 28 of the GDPR says that has to be written down, and this is it.

If you need this as a signed document on paper — some larger studios do — email privacy@inktok.pro and we will send one.

2. What we process, and about whom

ItemDetail
Subject matterRunning the booking service you subscribed to
DurationWhile your account is open, plus 90 days
Data subjectsYour clients and prospective clients; your artists and staff
Categories of data Name, email, phone, messages; appointment dates, prices and deposits; photographs the client uploads, including photographs of their own body; notes you write about them; consent forms they sign
Special categories A consent form may record health information — allergies, medication, pregnancy, skin conditions. This is Article 9 data, and it is treated accordingly

Health answers on a consent form are the most sensitive thing in the system. Collect only what you actually need for the tattoo, tell the client why you are asking, and do not keep it longer than the law where you work requires.

3. What we promise

  • To act only on your instructions. Using the product is the instruction. We do not decide on our own to do something else with your clients' data.
  • Not to use it for ourselves. Not to sell it, not to market to your clients, not to train AI models on your portfolio or your clients' photographs.
  • To keep it confidential. Everyone with access is bound to confidentiality and only gets the access their job needs.
  • To secure it. The measures are listed in section 6 below.
  • To help you. When a client exercises a right, or you need to assess a risk or report a breach, we help — at no charge.
  • To tell you quickly. If there is a breach affecting your clients' data, we notify you without undue delay and in any case within 48 hours of finding it, with what we know and what we are doing.
  • To give it back or delete it. At the end, you choose: export it, or have us delete it. Backups age out on their own 30-day cycle.

4. What you are responsible for

You are the controller, which means the decisions are yours and so is the accountability for them.

  • Having a lawful basis for collecting what you collect, and telling your clients about it
  • Your own privacy notice — your booking page can link to it
  • Keeping your logins, and your artists' logins, under control
  • Answering your clients when they ask to see, correct or delete their data
  • Not putting things into free-text notes that have no business being there
  • Only turning on SMS, WhatsApp or email reminders for people who agreed to them

5. Sub-processors

You give us general authorisation to use the companies below, each under a contract with the same obligations we have to you. We stay responsible for what they do.

CompanyWhat forWhere
Hetzner Online GmbHServers and database hostingGermany (EU)
Stripe, Inc. (Managed Payments)Merchant of record for InkTok subscriptions — takes your payment, handles VAT and issues the invoiceIreland (EU) and United States
Stripe, Inc. / Stripe Payments EuropeCard payments between a studio and its own clients (deposits, flash)Ireland (EU) and United States
Google Ireland Ltd. (Gemini API)Reads an uploaded reference image to estimate size, placement and complexityEU and United States
Google Ireland Ltd. (Calendar API)Two-way calendar sync, only for studios that connect itEU and United States
Twilio Ireland Ltd.SMS and WhatsApp reminders, only when a studio turns them onIreland (EU) and United States
Email delivery provider (SMTP)Booking confirmations, offers, reminders and aftercareEU

If we want to add one, we will tell you at least 30 days before. If you object on reasonable data-protection grounds, you may cancel and get the unused part of your term back.

Transfers outside the EU are covered by Standard Contractual Clauses or by the provider's EU–US Data Privacy Framework certification.

6. Security measures

  • TLS on everything in transit; encrypted storage at rest
  • Passwords stored only as bcrypt hashes
  • Every query scoped to one studio, so one account cannot read another's data
  • Role-based access inside a studio: an artist sees their own diary, not the payroll
  • Encrypted backups, kept separately, on a 30-day rolling cycle
  • Servers in an ISO 27001 certified data centre in Germany
  • Production access limited to named people, and reviewed

7. Audits

You may ask us to demonstrate that we are doing what this document says. In the first instance we answer in writing and send what documentation we have. Where that is genuinely not enough, an audit can be arranged with 30 days' notice, once a year, at your cost, by someone who is not a competitor of ours.

8. When it ends

When your account closes you have 90 days to export everything. After that we delete it, except anything we are legally required to keep — invoices, essentially. Backups containing it expire within 30 days and are not restored.

Who you are dealing with

InkTok is operated by Amare Baltic SIA, a limited liability company registered in Latvia.

Company
Amare Baltic SIA
Registration
40203563664 · Commercial Register of the Republic of Latvia
VAT number
LV40203563664
Registered address
Kluba iela 13A-8, Aloja, Limbaži Municipality, LV-4064, Latvia