Data Processing Addendum
Effective July 28, 2026 · Incorporated into the Terms of Service
1. Roles and scope
For personal information that you (the artist or studio, the “Customer”) collect from your clients and store in Tattoo Ledger (“Client Data”), you are the organization responsible for it (controller); Tattoo Ledger is your service provider (processor). This addendum governs all processing of Client Data for the duration of your subscription.
2. Details of processing
| Subject matter | Booking, client management, waivers, and client communication for the Customer’s tattoo business |
| Data subjects | The Customer’s clients; guardians of minor clients |
| Data categories | Contact details; appointment and project history; notes and images; waiver signatures with IP and timestamp; sensitive: health-history answers, government-ID photos, guardian identity data |
| Duration | Subscription term plus the export window in the Terms |
3. Our commitments
Instructions only
We process Client Data only to provide the service and on your documented instructions (your configuration and use of the product), never for our own marketing or profiling, and we never sell it.
Confidentiality
Personnel with access are bound by confidentiality obligations; access is role-limited and logged.
Security
We maintain the measures described on our Security page — encryption in transit and at rest, access control, tokenized client links, audit logging, backups — scaled to the sensitivity of health and identity data.
Subprocessors
You authorize the subprocessors listed at /legal/subprocessors. We post changes at least 30 days in advance; if you reasonably object to a change, you may terminate and export your data.
Assistance
We help you respond to client access, correction, and deletion requests (export tools, deletion on instruction) and provide information reasonably needed for your own compliance assessments.
Breach notice
We notify you without undue delay after becoming aware of a breach affecting Client Data, with enough detail for you to meet your own reporting duties. For Client Data, breach reporting to regulators and individuals is the Customer’s obligation; we support it.
Deletion and return
At termination, after the 90-day export window, we delete Client Data from production within 30 days and from backup rotation within a further 30 days.
Transfers
Client Data is hosted on Amazon Web Services in Canada (ca-central-1). Payment and email-delivery subprocessors process limited data in the United States. If GDPR ever applies to your clients, transfers rely on the subprocessors’ EU-approved mechanisms (standard contractual clauses / Data Privacy Framework), and this addendum operates as a processor agreement under Article 28.
Verification
On reasonable request (at most once yearly), we’ll answer security questionnaires and share summaries of our practices in lieu of on-site audits.