Privacy policy
This privacy policy explains how Vitaly Tattoo Rīga processes personal data when you visit the website, book a session, leave a review or contact us. It describes what data we process, why and on what legal basis, how long we keep it, who may receive it and what your rights are.
We process data in accordance with Regulation (EU) 2016/679 – the General Data Protection Regulation (GDPR) – and the Latvian Personal Data Processing Law.
1. Controller
The controller responsible for processing your personal data is:
Vitaly Tattoo Rīga
Stabu street 35, Riga, LV-1011, Latvia
E-mail: [email protected]
Phone: +371 28389374
For any question or request regarding your data, please write to this e-mail.
2. Website maintainer – EvoEX
The website is developed, hosted and technically maintained by EvoEX (evoex.eu). The website, its database and backups are stored on EvoEX servers.
This means that EvoEX technically stores and can access data submitted through the website (booking requests and reviews) as well as technical server logs. EvoEX acts as a processor on our behalf (GDPR Art. 28): it processes data only for hosting, maintenance, security, backups and technical support, according to our instructions and under confidentiality. EvoEX does not use this data for its own purposes and does not share it with third parties.
3. What data we process, why and for how long
3.1. Booking request
Data: name, phone, e-mail (optional), chosen style, tattoo idea, size and placement, preferred date and time, site language, time of submission.
Purpose: to reply to your request, prepare an offer and agree on the appointment time and price.
Legal basis: steps taken at your request before entering into a contract (GDPR Art. 6(1)(b)).
Retention: up to 12 months after the last contact. If the service is provided, data may be kept longer where accounting or other laws require it.
Please do not include health information in the form (e.g. allergies, illnesses, pregnancy or medication). If it matters for safe tattooing, we will discuss it in person before the session.
3.2. Reviews
Data: name (a first name or initials are enough), review text, tattoo style.
Purpose: to publish the review on the website with the name you provide, after moderation.
Legal basis: your consent (GDPR Art. 6(1)(a)), given by submitting the review.
Retention: while the review is published or until consent is withdrawn. Unpublished reviews are deleted within 6 months.
3.3. Photos of work
We publish photos of completed work on the website and social media. If a photo shows your face, distinctive features or otherwise makes you identifiable, we only publish it with your consent (GDPR Art. 6(1)(a)). You can ask us to remove a photo at any time.
3.4. Contact by e-mail, phone and social media
Data: name, contact details, content of correspondence and attached images (e.g. sketches).
Purpose: to answer questions and arrange the service.
Legal basis: steps before entering into a contract (GDPR Art. 6(1)(b)) or our legitimate interest in replying (Art. 6(1)(f)).
Retention: up to 12 months after the last contact.
If you message us on Instagram or Facebook, that communication is also processed by Meta Platforms Ireland Ltd. under its own terms.
3.5. Website visits and technical data
Data: IP address, browser and device type, page visited, date and time of the visit.
Purpose: to display the website, keep it running and secure, and detect and prevent attacks and errors.
Legal basis: our legitimate interest in a secure and working website (GDPR Art. 6(1)(f)).
Retention: server logs are deleted automatically after a short period, usually within 30 days.
For information about cookies, see our cookie policy.
4. Is providing data mandatory?
Providing data is voluntary. To reply to a booking request we need your name, phone number and a description of the tattoo – without them we cannot process the request. All other fields are optional.
5. Recipients
We do not sell data or share it for advertising. Data may only be accessed by the following recipients, and only as far as necessary:
- EvoEX – website development, hosting on its servers, maintenance, security and backups (processor, see section 2).
- Google Ireland Ltd. (Gmail) – notifications about new booking requests are sent to the studio e-mail.
- Google Fonts and jsDelivr – provide the website’s fonts and icons; they receive your IP address when the page loads.
- Meta Platforms Ireland Ltd. (Instagram, Facebook) – only if you follow links to our profiles or message us there.
- Public authorities – only where required by law.
6. Transfers outside the EU/EEA
Some providers (e.g. Google and Meta) may also process data outside the European Economic Area, including in the USA. In such cases, data protection is ensured by a European Commission adequacy decision (the EU-US Data Privacy Framework) or Standard Contractual Clauses approved by the European Commission.
7. Your rights
- Access – find out whether we process your data and receive a copy.
- Rectification – have inaccurate or incomplete data corrected.
- Erasure – have your data deleted when it is no longer needed or there is no basis for processing.
- Restriction – for example, while the accuracy of the data is being checked.
- Objection – object to processing based on legitimate interests.
- Portability – receive the data you gave us in a structured, machine-readable format.
- Withdrawing consent – at any time; this does not affect the lawfulness of processing before withdrawal.
Send your request to [email protected]. To protect your data, we may ask you to confirm your identity. We will reply free of charge within one month; in complex cases this can be extended by two further months, and we will let you know.
If you believe your data is processed unlawfully, you can lodge a complaint with the Data State Inspectorate of Latvia (Elijas iela 17, Riga, LV-1050, [email protected]). We encourage you to contact us first – we will do our best to resolve the issue.
8. Automated decision-making
We do not use automated decision-making or profiling that would have legal or similarly significant effects on you.
9. Security
We protect data with appropriate technical and organisational measures: the website runs over an encrypted connection (HTTPS), forms are protected against automated spam, access to booking requests and administration is limited to authorised persons with personal credentials, and backups are made regularly. After deletion, data may remain in backups for a limited time until they are automatically overwritten.
In the event of a personal data breach we will act in accordance with the GDPR – where required, notifying the Data State Inspectorate within 72 hours and, if there is a high risk, you as well.
10. Children’s data
The website is not intended for children, and we do not knowingly collect children’s personal data. If we learn that a request was submitted by a child without the knowledge of a parent or guardian, we will delete that data.
11. Changes to this policy
We may update this policy, for example when our services or the law change. The current version is always available on this page, with its effective date shown at the top. We will announce significant changes on the website.
Crafted with care by EvoEX