Privacy Policy
Purpose
The purpose of this Policy is to set out the rules governing how INKJIN IKE, a company with the corporate name "INKJIN PRIVATE COMPANY," headquartered at 332 Kifisias Avenue, Chalandri, 15233, Attica, with Tax ID 803292939, Tax Office KEFODE Attikis, and General Commercial Registry No. 193959701000 (hereinafter the "Company"), collects, processes, and protects personal data through its website Inkjin.com (hereinafter "our Website") and its mobile application Inkjin ("Application" or "Inkjin"). This Policy sets out why the Company holds this data, the type of data it processes, how long it stores the data, and the appropriate technical and organizational protective measures it adopts.
The Company complies with Regulation (EU) 2016/679 (GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as well as applicable Greek legislation.
The Company reserves the right to update, amend, or revise the services offered and this Policy whenever it deems necessary, without prior notice, in accordance with applicable data protection legislation. For this reason, the Company encourages anyone interested to check this Policy periodically for any changes.
Data Controller
The Company, as identified above, is the Data Controller for the collection and processing of your data through the Application. This means the Company determines the purposes and means of processing your personal data, as described below.
In the context of your direct communication with Artists — including when this takes place through messages exchanged via the Application — the Data Controller of your personal data is the relevant Artist (see the "Communication/Booking Appointments with Artists" section below).
Definitions
General Data Protection Regulation (GDPR): Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data
Personal data: Any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to such data.
Processing: Any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Data Subject: Any living natural person whose personal data is processed.
Sources of Collection of Personal Data
All personal data processed by the Company is collected directly from data subjects, through their entry of data into the Application, their sending of data to the Company by other means, or through information provided by the data subjects' own equipment. The Company does not collect personal data from third-party sources.
Company Commitments
The Company, as data controller, is committed to complying with all its obligations under the GDPR, specifically:
- To collect personal data fairly and lawfully, for specific and defined purposes, and not to further process personal data in a manner incompatible with those purposes.
- To process only adequate and relevant personal data, limited to what is necessary in relation to the purposes for which it is processed.
- To process accurate personal data and to update it whenever necessary.
- To process personal data in accordance with one of the legal bases set out in Articles 6 and 9 of the GDPR.
- To inform data subjects about the processing of their personal data and to respect their rights.
- To take appropriate organizational and technical measures to secure personal data and protect it from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unlawful processing.
Types of Personal Data Processed
The personal data collected depends on the category of data subject:
A) Visitors to our Website (internet users who simply visit our Website without registering as Users or Artists): no personal data is required.
B) Users of the Application: upon registration, an email address must be provided. Optionally, users may also provide their full name, communication language, area of residence, whether they have other tattoos, and gender. The Application also processes the registration date and the frequency and dates of the User's visits to the Application, as well as the User's preferences regarding designs and Artists.
If a User makes use of Augmented Reality (AR) technology, the Application additionally processes AR data via access to the device's camera (solely for displaying the tattoo on the User's body), and, if the User chooses, captures and stores the photo in the User's profile. Image capture occurs only through an explicit action by the User — the Application does not store images or videos without the user's action.
If a User makes use of the AI Tattoo Price Estimator, the Application additionally processes information regarding the design selected, the placement location, and the estimated cost.
C) Users who communicate with Artists and book appointments with them: the Company additionally processes, in its capacity as processor on behalf of the Artist — Data Controller: the full name of the Artist selected by the User, the content of their communication, the service the User is requesting from the Artist, appointment details, any modification or cancellation, and payment details.
D) Artists on our Website: registration requires full name, email address, country of residence, mobile phone number, username, and optionally their website and social media profiles (Instagram, TikTok, YouTube). The Company also processes, for each Artist: professional profile details, professional experience, the tattoo studio they work with, their existing portfolio of designs, their specialization style, the dimensions offered for each design, estimated time and price per design, registration date, frequency and dates of visits to the Application, the content of their communications, the Users who book appointments with them, appointment/modification/cancellation details, and payment details.
Google Calendar Integration
Where an Artist connects their Google Calendar to Inkjin, the Company processes calendar data as follows:
Data Accessed: Inkjin accesses only calendar event data for events it creates on the Artist's connected Google Calendar — specifically the event date, time, and title/description generated by a booking. Inkjin does not read, access, or view any other events, calendar contents, or data already present on the Artist's Google Calendar.
Data Use: This calendar event data is used solely to synchronize appointment bookings, cancellations, and reschedules between Inkjin and the Artist's Google Calendar, so that confirmed bookings appear on the Artist's calendar and are automatically updated or removed if the booking is cancelled or rescheduled.
Data Transfer: Calendar data is not shared, sold, or transferred to any third party. It is used exclusively for the booking synchronization feature described above.
Data Protection: Calendar data is encrypted in transit and at rest, and access is restricted to the systems and personnel necessary to operate the booking synchronization feature.
Retention/Deletion: Calendar event data created by Inkjin is deleted from our systems when the corresponding booking is cancelled or completed, or immediately upon the Artist disconnecting their Google Calendar from Inkjin, whichever occurs first.
Limited Use Disclosure: Inkjin's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data accessed through the Google Calendar API is not used to develop, improve, or train generalized artificial intelligence and/or machine learning models, and is never used for any purpose beyond providing and maintaining the booking synchronization feature for the Artist who granted access.
Purposes and Legal Bases of Processing
The Company processes personal data only for purposes that are explicit, clear, lawful, and specified at the time of collection, including for:
- Providing the services offered to Visitors, Users, and Artists.
- Organizing and managing the Website and Application.
- Installation and registration on the Application (legal basis: performance of a contract, Article 6(1)(b) GDPR).
- Browsing Artists' designs (legal basis: the Company's legitimate interest, Article 6(1)(f) GDPR — corporate communication and promotion of corporate purposes).
- Use of AR technology (legal basis: consent of the data subject, Article 6(1)(a) GDPR).
- Payment for services provided (legal basis: performance of a contract, Article 6(1)(b) GDPR).
- Security of the Platform (legal basis: the Company's legitimate interest, Article 6(1)(f) GDPR).
- Effective cooperation with Artists and performance of contractual obligations.
- Fulfillment of legal obligations, responding to requests from supervisory/audit authorities, establishing, exercising, or defending legal claims, and managing accounting and tax obligations.
The general legal bases relied upon by the Company are: a) performance of a contract (Article 6(1)(b) GDPR), b) compliance with a legal obligation (Article 6(1)(c) GDPR), c) consent of the data subject (Article 6(1)(a) GDPR), and d) the legitimate interest of the Company or a third party, unless overridden by the interests or fundamental rights of the data subject (Article 6(1)(f) GDPR).
For clarity, the Company itself does not, through the Application, collect health data or other special categories of personal data. Where an Artist requests that Users communicating with them share health data or other special category data, the Artist alone is the data controller for such data.
Communication/Booking Appointments with Artists
When you communicate with Artists, or book, modify, or cancel appointments with them — whether outside the Application or through it — the Data Controller is the relevant Artist, who determines both the purposes and the means of processing your personal data. In this context, when the Company processes your personal data through the Application, it acts as processor on behalf of the Artist communicating with you.
Transfer of Personal Data
The Company does not sell the personal data of Visitors, Users, or Artists. However, this data may be processed by third-party sub-processors (or processors) on the Company's behalf, solely for the purposes set out in this Policy. Such third parties provide sufficient assurances of implementing appropriate technical and organizational measures and do not process personal data outside the EEA. Third parties who may process data from the Website or Application include:
- Providers of network or equipment maintenance services.
- In the case of an appointment booking: the Artist selected by the User.
- In the case of a payment: the payment provider.
- Employees and associates of the Company responsible for managing, maintaining, supporting, and hosting the Application, who are bound to the Company by confidentiality obligations.
Security of Personal Data
The Company makes every effort to protect the personal data it processes, both in terms of confidentiality and integrity. Taking into account available technology, implementation cost, the nature, scope, context, and purposes of processing, as well as the severity and likelihood of risks to the rights and freedoms of natural persons, the Company implements appropriate technical and organizational measures to ensure an appropriate level of data security.
Data Retention Period
Personal data is retained for as long as necessary to fulfill the purpose for which it was collected:
A) Users' personal data is retained until deletion of the User's profile from the Application, and is deleted within five (5) years from the date of deletion.
B) Artists' personal data is retained for five (5) years from the date their cooperation with the Company ends.
C) Visitors' personal data is retained for two (2) months from the date of collection.
After the applicable retention period, the Company ensures personal data is securely destroyed or rendered anonymous in a manner that does not permit re-identification of data subjects.
Fundamental Rights of Data Subjects
In compliance with the GDPR, every data subject has the following rights regarding their personal data:
- Right to information: to receive clear, transparent, and easily understandable information about how their data is processed.
- Right of access: to obtain access to their personal data free of charge.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of their personal data, subject to the limitations set out in the GDPR.
- Right to restriction of processing: to request restriction of processing, subject to the conditions set out in the GDPR.
- Right to data portability: to request transfer of their data to another controller, where provided for by the GDPR.
- Right to object: to object to the processing of their personal data, subject to the conditions set out in the GDPR.
- Right to lodge a complaint: to lodge a complaint with the Hellenic Data Protection Authority if they consider that their data protection rights have been infringed.
Where processing is based on consent, the data subject has the right to withdraw that consent at any time.
Requests to exercise these rights should be submitted in writing to privacy@inkjin.com, accompanied by identifying information. The Company may request additional means of identity verification. The Company will respond without undue delay and in any event within one month of receiving the request, with the possibility of extending this by a further two (2) months where necessary due to the complexity of the request. Responses are provided free of charge, unless a request is manifestly unfounded or excessive, in which case the Company may charge a reasonable fee or refuse to act on the request.
Contacting the Supervisory Authority
For further information, advice, or to lodge a complaint, you may contact the Hellenic Data Protection Authority:
1-3 Kifisias Avenue, 115 23, Athens
Switchboard: +30-210 6475600
Fax: +30-210 6475628
Email: contact@dpa.gr
Website: https://www.dpa.gr (detailed instructions for submitting a complaint)
Contact Details for Personal Data Matters
For any matter relating to the processing of your personal data or this Policy, you may contact Ilias Hatzis:
By post: Inkjin IKE, 332 Kifisias Avenue, 15233 Chalandri
By email: privacy@inkjin.com
Revisions
Our goal is to continuously review and update this Policy in order to comply with data protection legislation and new developments. Any update to this Policy will be communicated to you promptly.
Last updated: 15 July 2026