1. Who this is between
This Addendum is between you — the studio or artist with an InkTok account — and Amare Baltic SIA. It forms part of the Terms of Service and applies automatically from the day you register. You do not have to sign anything separately.
For your clients' personal data, you are the controller and we are the processor. You decide what is collected and why; we only act on your instructions. Article 28 of the GDPR says that has to be written down, and this is it.
If you need this as a signed document on paper — some larger studios do — email privacy@inktok.pro and we will send one.
2. What we process, and about whom
| Item | Detail |
|---|---|
| Subject matter | Running the booking service you subscribed to |
| Duration | While your account is open, plus 90 days |
| Data subjects | Your clients and prospective clients; your artists and staff |
| Categories of data | Name, email, phone, messages; appointment dates, prices and deposits; photographs the client uploads, including photographs of their own body; notes you write about them; consent forms they sign |
| Special categories | A consent form may record health information — allergies, medication, pregnancy, skin conditions. This is Article 9 data, and it is treated accordingly |
Health answers on a consent form are the most sensitive thing in the system. Collect only what you actually need for the tattoo, tell the client why you are asking, and do not keep it longer than the law where you work requires.
3. What we promise
- To act only on your instructions. Using the product is the instruction. We do not decide on our own to do something else with your clients' data.
- Not to use it for ourselves. Not to sell it, not to market to your clients, not to train AI models on your portfolio or your clients' photographs.
- To keep it confidential. Everyone with access is bound to confidentiality and only gets the access their job needs.
- To secure it. The measures are listed in section 6 below.
- To help you. When a client exercises a right, or you need to assess a risk or report a breach, we help — at no charge.
- To tell you quickly. If there is a breach affecting your clients' data, we notify you without undue delay and in any case within 48 hours of finding it, with what we know and what we are doing.
- To give it back or delete it. At the end, you choose: export it, or have us delete it. Backups age out on their own 30-day cycle.
4. What you are responsible for
You are the controller, which means the decisions are yours and so is the accountability for them.
- Having a lawful basis for collecting what you collect, and telling your clients about it
- Your own privacy notice — your booking page can link to it
- Keeping your logins, and your artists' logins, under control
- Answering your clients when they ask to see, correct or delete their data
- Not putting things into free-text notes that have no business being there
- Only turning on SMS, WhatsApp or email reminders for people who agreed to them
5. Sub-processors
You give us general authorisation to use the companies below, each under a contract with the same obligations we have to you. We stay responsible for what they do.
| Company | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Servers and database hosting | Germany (EU) |
| Stripe, Inc. (Managed Payments) | Merchant of record for InkTok subscriptions — takes your payment, handles VAT and issues the invoice | Ireland (EU) and United States |
| Stripe, Inc. / Stripe Payments Europe | Card payments between a studio and its own clients (deposits, flash) | Ireland (EU) and United States |
| Google Ireland Ltd. (Gemini API) | Reads an uploaded reference image to estimate size, placement and complexity | EU and United States |
| Google Ireland Ltd. (Calendar API) | Two-way calendar sync, only for studios that connect it | EU and United States |
| Twilio Ireland Ltd. | SMS and WhatsApp reminders, only when a studio turns them on | Ireland (EU) and United States |
| Email delivery provider (SMTP) | Booking confirmations, offers, reminders and aftercare | EU |
If we want to add one, we will tell you at least 30 days before. If you object on reasonable data-protection grounds, you may cancel and get the unused part of your term back.
Transfers outside the EU are covered by Standard Contractual Clauses or by the provider's EU–US Data Privacy Framework certification.
6. Security measures
- TLS on everything in transit; encrypted storage at rest
- Passwords stored only as bcrypt hashes
- Every query scoped to one studio, so one account cannot read another's data
- Role-based access inside a studio: an artist sees their own diary, not the payroll
- Encrypted backups, kept separately, on a 30-day rolling cycle
- Servers in an ISO 27001 certified data centre in Germany
- Production access limited to named people, and reviewed
7. Audits
You may ask us to demonstrate that we are doing what this document says. In the first instance we answer in writing and send what documentation we have. Where that is genuinely not enough, an audit can be arranged with 30 days' notice, once a year, at your cost, by someone who is not a competitor of ours.
8. When it ends
When your account closes you have 90 days to export everything. After that we delete it, except anything we are legally required to keep — invoices, essentially. Backups containing it expire within 30 days and are not restored.
Who you are dealing with
InkTok is operated by Amare Baltic SIA, a limited liability company registered in Latvia.
- Company
- Amare Baltic SIA
- Registration
- 40203563664 · Commercial Register of the Republic of Latvia
- VAT number
- LV40203563664
- Registered address
- Kluba iela 13A-8, Aloja, Limbaži Municipality, LV-4064, Latvia
- hello@inktok.pro