Privacy policy
How Tattoo Tobias handles your personal data · last updated
Short version: I only ask for what I need to plan your tattoo, I keep it in a secure European database and in my own agenda, I never sell or share it for marketing, and you can ask me to see or delete it at any time.
1Who is responsible
I am the "controller" of your data in the sense of the GDPR. Questions or requests: send an e-mail to the address above.
2What I collect, and why
When you send a booking request through the website (or by e-mail), I receive: your name, e-mail address and phone number; your idea, placement, size, black or colour and any notes; the duration, day and time you picked; and the reference photos you add. I use this to look at your idea, hold and confirm your slot, prepare the design, contact you about the appointment and carry out the tattoo. Legal basis: the steps needed to enter into and perform our agreement (art. 6.1.b GDPR).
When you become a client, I also keep what is needed for invoicing and bookkeeping (legal obligation, art. 6.1.c GDPR) and for a good follow-up of your tattoo — touch-ups, questions about healing (legitimate interest, art. 6.1.f GDPR).
Health information. Before the appointment I may ask about allergies, medication, skin conditions or pregnancy, because that affects whether and how I can tattoo you safely. I ask this in person or by e-mail, I only note what matters for the appointment, and I do not keep it longer than needed. By telling me, you agree that I use it for that purpose (art. 9.2.a GDPR).
Photos of your tattoo. I like to photograph finished work for my portfolio, website and Instagram. I will ask you on the day. You can always say no, or ask me later to take a photo down.
3Where your data is stored
- Booking database and reference photos — stored with Supabase (Supabase Inc.), on servers in the European Union (Paris). Only I can read the requests; the website itself only shows which hours are taken, never who booked them.
- Website hosting and e-mail notification — the website runs on Netlify (Netlify Inc.). When you send a request, Netlify also e-mails me a copy so that I notice it quickly.
- My agenda — confirmed appointments and pending requests appear in my Google Calendar (Google Ireland Ltd.) with your name, the time and the details of your request, so I never double-book.
- E-mail — our correspondence lives in my mailbox.
These companies act as processors on my behalf, under their data processing agreements and the EU standard contractual clauses where data may leave the EU. I never sell your data and I do not use it for advertising.
4How long I keep it
- Requests that were declined, expired or cancelled: deleted after months.
- Appointment history of clients (what, when, where on the body): years after the last appointment, so I can help with touch-ups and questions.
- Invoices and bookkeeping records: 7 years, as the law requires.
- Reference photos are deleted together with the request they belong to.
5Cookies and tracking
This website does not use tracking cookies, analytics scripts or advertising pixels, so there is no cookie banner. It only remembers two preferences in your own browser (the language and light/dark mode) and, while you fill in the form, your draft — nothing of that leaves your device.
Two parts of the website are loaded from Google: the fonts (Google Fonts) and the map on the contact section (Google Maps). Your browser then sends your IP address to Google; Google Maps may set its own cookies once you interact with the map. See Google's privacy policy. Links to Instagram and to the shop take you to those platforms, which have their own policies.
6Your rights
You can ask me at any time to see the data I hold about you, to correct it, to delete it, to limit how I use it, to receive a copy, or to object to a use based on my legitimate interest. Just e-mail me; I answer within a month. If you believe I handle your data incorrectly, you can lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be).
7Security
The website only works over HTTPS, the database is protected with access rules so that only my own login can read requests, and the studio administration is password-protected. No system is perfect; if something ever goes wrong with your data, I will inform you and the authority as the law requires.
8Changes
If I change this policy, the new version appears here with a new date. Minors: you must be or older to book; I do not knowingly collect data from younger people.
Privacyverklaring
Hoe Tattoo Tobias met je persoonsgegevens omgaat · laatst bijgewerkt
Kort gezegd: ik vraag alleen wat ik nodig heb om je tattoo te plannen, ik bewaar het in een beveiligde Europese databank en in mijn eigen agenda, ik verkoop of deel het nooit voor marketing, en je kunt me altijd vragen om het in te kijken of te wissen.
1Wie is verantwoordelijk
Ik ben de "verwerkingsverantwoordelijke" van je gegevens in de zin van de AVG/GDPR. Vragen of verzoeken: mail naar het adres hierboven.
2Wat ik verzamel, en waarom
Als je een aanvraag stuurt via de website (of per e-mail) ontvang ik: je naam, e-mailadres en telefoonnummer; je idee, plaatsing, grootte, zwart of kleur en eventuele opmerkingen; de duur, dag en het uur dat je koos; en de referentiefoto's die je toevoegt. Dat gebruik ik om je idee te bekijken, je plek vast te houden en te bevestigen, het ontwerp voor te bereiden, je te contacteren over de afspraak en de tattoo te zetten. Rechtsgrond: de stappen die nodig zijn om onze overeenkomst te sluiten en uit te voeren (art. 6.1.b AVG).
Als je klant wordt bewaar ik ook wat nodig is voor facturatie en boekhouding (wettelijke verplichting, art. 6.1.c AVG) en voor een goede opvolging van je tattoo — touch-ups, vragen over de genezing (gerechtvaardigd belang, art. 6.1.f AVG).
Gezondheidsinformatie. Vóór de afspraak kan ik vragen naar allergieën, medicatie, huidaandoeningen of zwangerschap, omdat dat bepaalt of en hoe ik je veilig kan tatoeëren. Ik vraag dit persoonlijk of per e-mail, noteer enkel wat voor de afspraak van belang is en bewaar het niet langer dan nodig. Door het me te vertellen, ga je akkoord dat ik het daarvoor gebruik (art. 9.2.a AVG).
Foto's van je tattoo. Ik fotografeer graag afgewerkt werk voor mijn portfolio, website en Instagram. Ik vraag het je op de dag zelf. Je mag altijd nee zeggen, of me later vragen een foto weg te halen.
3Waar je gegevens staan
- Boekingsdatabank en referentiefoto's — bij Supabase (Supabase Inc.), op servers in de Europese Unie (Parijs). Alleen ik kan de aanvragen lezen; de website zelf toont enkel welke uren bezet zijn, nooit wie er geboekt heeft.
- Hosting van de website en e-mailmelding — de website draait bij Netlify (Netlify Inc.). Als je een aanvraag stuurt, mailt Netlify mij ook een kopie, zodat ik ze snel opmerk.
- Mijn agenda — bevestigde afspraken en openstaande aanvragen verschijnen in mijn Google Agenda (Google Ireland Ltd.) met je naam, het tijdstip en de details van je aanvraag, zodat ik nooit dubbel boek.
- E-mail — onze briefwisseling staat in mijn mailbox.
Deze bedrijven treden op als verwerkers in mijn opdracht, onder hun verwerkersovereenkomsten en de EU-standaardcontractbepalingen waar gegevens de EU zouden verlaten. Ik verkoop je gegevens nooit en gebruik ze niet voor reclame.
4Hoe lang ik het bewaar
- Aanvragen die afgewezen, vervallen of geannuleerd zijn: gewist na maanden.
- Afsprakenhistoriek van klanten (wat, wanneer, waar op het lichaam): jaar na de laatste afspraak, zodat ik kan helpen met touch-ups en vragen.
- Facturen en boekhoudstukken: 7 jaar, zoals de wet voorschrijft.
- Referentiefoto's worden samen met de bijbehorende aanvraag gewist.
5Cookies en tracking
Deze website gebruikt geen trackingcookies, analysescripts of advertentiepixels; daarom is er geen cookiebanner. Ze onthoudt enkel twee voorkeuren in je eigen browser (de taal en licht/donker) en, terwijl je het formulier invult, je ontwerp — niets daarvan verlaat je toestel.
Twee onderdelen van de website komen van Google: de lettertypes (Google Fonts) en de kaart bij het contactgedeelte (Google Maps). Je browser stuurt dan je IP-adres naar Google; Google Maps kan eigen cookies plaatsen zodra je met de kaart werkt. Zie het privacybeleid van Google. Links naar Instagram en naar de shop brengen je naar die platformen, met hun eigen beleid.
6Je rechten
Je kunt me altijd vragen welke gegevens ik over je heb, om ze te verbeteren, te wissen, het gebruik te beperken, een kopie te krijgen, of bezwaar te maken tegen een gebruik op basis van mijn gerechtvaardigd belang. Mail me gewoon; ik antwoord binnen de maand. Vind je dat ik verkeerd met je gegevens omga, dan kun je klacht indienen bij de Gegevensbeschermingsautoriteit (Drukpersstraat 35, 1000 Brussel, gegevensbeschermingsautoriteit.be).
7Beveiliging
De website werkt enkel over HTTPS, de databank is afgeschermd met toegangsregels zodat alleen mijn eigen login aanvragen kan lezen, en het studiobeheer is beveiligd met een wachtwoord. Geen enkel systeem is perfect; mocht er ooit iets misgaan met je gegevens, dan verwittig ik jou en de autoriteit zoals de wet het vraagt.
8Wijzigingen
Als ik deze verklaring aanpas, verschijnt de nieuwe versie hier met een nieuwe datum. Minderjarigen: je moet jaar of ouder zijn om te boeken; ik verzamel niet bewust gegevens van jongere personen.