BookInk LTD - Privacy and Data Protection Notice
Last Updated: September 2026
BookInk LTD ("BookInk", "we", "us", or "our") provides digital client booking software, electronic medical consent forms, and automated communication tools for professional tattoo studios, artists, and their clients. We take data protection and privacy seriously and are committed to safeguarding personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU GDPR, the Privacy and Electronic Communications Regulations (PECR), and mobile application distribution rules (including the Apple App Store Review Guidelines and Google Play Developer Policies).
This Privacy Notice explains how we collect, process, manage, and protect personal and medical data when you use the BookInk mobile applications, client portal, and related services (collectively, the "Platform").
1. Data Controller vs. Data Processor Architecture
Under UK and European data protection legislation, the role played by BookInk depends on the specific category of information being processed:
- The Tattoo Studio / Artist (Data Controller): When you complete an electronic tattoo consent form, provide health declarations, or opt in to receive promotional updates from a specific studio, the Tattoo Studio or Artist operates as the primary Data Controller. The Studio determines the necessity of the health questions, handles procedure assessments, and directs direct marketing.
- BookInk LTD (Data Processor): In storing completed consent documents, managing database infrastructure, encrypting medical records, and delivering client notification emails and SMS on behalf of the Studio, BookInk operates primarily as a Data Processor.
- BookInk LTD (Independent Data Controller): BookInk acts as an independent Controller for minimal platform account credentials, core audit logs, system security monitoring, and statutory accounting records.
If you have questions regarding personal records or medical disclosures held by a specific studio, you may contact that studio directly or email us at office@bookink.uk, and we will coordinate with the relevant Controller.
2. Categories of Information We Collect
We only collect and process information necessary to fulfill appointment bookings, satisfy statutory public health and council licensing requirements, process authorized payments, and send requested communications.
A. Identity and Contact Information
- Full legal name and preferred name;
- Residential address;
- Date of birth (DO😎 and photographic age verification records (to ensure statutory compliance with minimum age laws);
- Mobile phone number and email address;
- Electronic biometric signatures and submission timestamps.
B. Special Category Data (Medical and Health Declarations)
Under UK and EU GDPR, health information is categorized as "Special Category Data" and requires heightened protections. Via the Consent Form Tool, we collect and process disclosures strictly relevant to procedural safety, including:
- History of allergies (e.g., latex, pigments, antibiotics, antiseptics);
- Skin disorders, eczema, psoriasis, keloid scarring, or active infections;
- Blood-borne viruses (e.g., Hepatitis, HIV);
- Cardiovascular diseases, epilepsy, diabetes, or fainting tendencies;
- Pharmaceutical regimes (especially anticoagulant or blood-thinning medication);
- Pregnancy or nursing status.
C. Financial and Transactional Information
- Payment token identifiers, transaction dates, deposit amounts paid, and payment statuses.
- Note on Card Storage: BookInk does not collect, store, or view full payment card numbers, card verification codes (CVV/CVC), or banking passwords. Payments are processed directly through our secure, PCI-DSS compliant payment processing partner (e.g., Stripe).
D. Device, Diagnostic, and Telemetry Data
- Unique device identifiers (e.g., Apple IDFV, Android ID), operating system version, device hardware specifications, IP address, connection logs, and crash report data to ensure system security, fraud prevention, and app performance.
3. Lawful Bases for Processing
We process personal data only when a valid lawful basis applies under UK/EU GDPR:
| Processing Purpose | Data Categories Involved | Lawful Basis (GDPR Art. 6 / Art. 9) |
|---|---|---|
| Booking & Profile Setup | Name, email, mobile number, booking notes | Contractual Necessity (Art. 6(1)(b)) |
| Processing Deposits & Fees | Billing name, tokenized payment records | Contractual Necessity (Art. 6(1)(b)) & Legal Obligation (Art. 6(1)(c)) |
| Tattoo Consent Verification | Name, address, DOB, signature, ID confirmation | Legal Obligation (Art. 6(1)(c)) & Legitimate Interests: Satisfying local authority licensing and insurance conditions. |
| Medical Disclosures Assessment | Health records, skin conditions, medications | Explicit Consent (Art. 9(2)(a)): Freely given by you when reviewing and completing the health declaration prior to the procedure. |
| Transactional Notices | Email address, mobile phone number | Contractual Necessity / Legitimate Interests: Sending consent copies, booking receipts, and aftercare guidance. |
| Studio Marketing & Offers | Email address, mobile phone number | Consent (Art. 6(1)(a)): Clear, affirmative opt-in checkbox only. |
| App Security & Fraud Control | IP address, hardware ID, diagnostics | Legitimate Interests (Art. 6(1)(f)): Preventing fraud and maintaining app performance. |
4. Marketing Communications Policy (Email and SMS)
BookInk complies strictly with the Privacy and Electronic Communications Regulations (PECR) and UK/EU GDPR regarding direct marketing:
- Strict Opt-In Requirement: You will only receive promotional email or SMS communications (such as studio discount offers, flash day announcements, or newsletter campaigns) if you have explicitly ticked the opt-in checkbox on the booking screen or consent form.
- Studio-Specific Scope: Marketing communications sent via the Platform originate from and represent the specific Studio or Artist you have engaged with. We do not sell or lease your contact information to third-party advertisers.
- Unsubscribe Mechanism: You can withdraw your marketing consent at any time without penalty:
- By clicking the "Unsubscribe" link located at the footer of any promotional email;
- By following the text stop instructions included in promotional SMS messages;
- By emailing a withdrawal request to office@bookink.uk.
- Transactional Messages Excluded: Opting out of marketing does not disable mandatory operational notifications, including booking confirmations, deposit receipts, digital consent confirmations, or post-procedure tattoo aftercare instructions.
5. Third-Party Disclosures and Data Sharing
BookInk does not sell, rent, or trade your personal data or mobile numbers to third parties for independent marketing. Personal information is disclosed exclusively to:
- The Selected Studio and Artist: Enabling them to assess your medical suitability for the tattoo, service your appointment, and retain legally required client documentation;
- Regulated Payment Processors: PCI-compliant payment gateways (e.g., Stripe) executing secure transaction tokenization and disbursements;
- Vetted Technology Infrastructure Providers: Specialized cloud hosting providers, encrypted database facilities, and transactional email/SMS delivery gateways bound by strict Data Processing Agreements;
- Statutory and Regulatory Bodies: Local council Environmental Health Officers, police forces, courts, or insurance underwriting bodies where disclosure is legally required under statutory licensing mandates or to defend legal liability claims.
6. Data Storage, Security, and Retention
Technical Safeguards
- End-to-End Encryption: All data transmitted between your device and the Platform is encrypted using TLS (Transport Layer Security).
- Database Protection: Stored personal details, completed consent PDFs, and health records are encrypted at rest using AES-256 standards in restricted-access cloud environments.
- Role-Based Access Control: Access to your completed medical declarations is strictly limited to authorized studio personnel and authenticated system administrators.
Retention Periods
- Consent and Medical Records (3 Years): Completed consent forms, health declarations, and identity verification logs are retained on the Platform for three (3) years from the date of completion. This duration is strictly aligned with UK local government hygiene licensing rules, public health record guidelines, and the standard statutory limitation period for personal injury liability claims. After three years, records are securely expunged or irreversibly anonymized.
- Financial and Invoicing Records (6 Years): Transaction identifiers, deposit receipts, and accounting records are preserved for six (6) years to satisfy statutory UK corporate tax and financial accounting requirements.
7. International Data Transfers
Where our third-party infrastructure providers maintain servers situated outside the UK or the European Economic Area (EEA), BookInk ensures that statutory data export safeguards are in place. These safeguards include the UK International Data Transfer Addendum/Agreement (IDTA), the EU Standard Contractual Clauses (SCCs), or verification under the UK-US Data Bridge (Extension to the EU-U.S. Data Privacy Framework).
8. Your Legal Rights Under Data Protection Law
Subject to specific legal and statutory exemptions (such as records we must retain for local council licensing or insurance defense), you hold the following rights under UK and EU GDPR:
- Right of Access: You may request confirmation of and a copy of the personal and health data we hold about you.
- Right to Rectification: You may request correction of inaccurate, obsolete, or incomplete personal details.
- Right to Erasure ("Right to be Forgotten"): You may request that we delete your personal information, provided the records are no longer required to satisfy ongoing legal compliance, environmental health regulations, or active insurance claims.
- Right to Restriction and Objection: You may request restriction of processing or object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: You can withdraw consent for direct marketing or special category health processing at any time (without affecting the lawfulness of processing carried out prior to withdrawal).
To exercise any of these statutory rights, please submit your request in writing to: office@bookink.uk. We respond to all verified requests within one calendar month.
9. Regulatory Complaints and Inquiries
If you have questions or concerns regarding our handling of your personal data, we encourage you to contact us first at office@bookink.uk so that we can promptly investigate.
You also maintain the right to lodge a formal complaint with the relevant data protection supervisory authority:
- United Kingdom: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF | Website: www.ico.org.uk | Helpline: 0303 123 1113.
- European Union: Your national Data Protection Authority (DPA).
10. Revisions to this Privacy Notice
We may periodically revise this Privacy Notice to reflect operational updates, new platform features, or evolving legal frameworks. Revisions will be published on the Platform and will be immediately accessible via the public link registered on our Apple App Store and Google Play Store listings.