Privacy what I do with your data

Who I am the person responsible for your data

The Kaiiza Tattoo website is run by Kajsa Charlotta Koskinen, as a sole proprietorship registered under Swiss business identification number CHE-238.087.387. The business is neither liable for VAT nor entered in the commercial register. Address: Grand-Rue 10, 1844 Villeneuve (VD), Switzerland.

I am the one who decides what this site collects and what happens to it. In legal terms, I am the data controller.

For anything about this page or about your data, write to kaiiza.tattoo@gmail.com. It is the same address as for everything else: you reach me directly.

Amartato Studio is where I tattoo, nothing more. The studio does not run this site, does not receive project requests, and has access to neither your request nor our exchanges.

What you send the form fields

The project request form is the only place on this site where you give me information about yourself. There is no account to create, no newsletter and no online payment.

What I need in order to reply: your name, your email address and a description of your project. Without those three fields I can neither get back to you nor understand what you are after, so the form will not go through.

What stays optional: your phone number, the placement and size you have in mind, your timeframe, when you are free to talk it over, your budget range and how you found me. You can leave all of it blank: nothing is blocked, and it changes nothing about the attention your request gets.

The tick box: one, and it is required. It confirms that you have understood that your request leads to a studio appointment before any tattooing, that your data is only used to handle your request, and that you agree to receive the emails tied to your session, including the single review request afterwards.

What gets recorded without you filling anything in: the language you used the form in, technical security signals that check the submission is not coming from a bot, anti-abuse counters that cannot identify you, and the technical identifier of your confirmation email along with its delivery status.

No image goes through the form. If you want to send me references, you simply reply to the confirmation email you receive. Those images then live in my mailbox, not in the site's database.

The free text and what you choose to put in it

The description field is deliberately left without instructions or limits. A tattoo project often starts with a story, and I would rather you told it the way it comes than squeezed it into boxes.

Which means you may well write things that legally count as sensitive data: a health condition, a scar, an operation, a pregnancy, a religious belief, a bereavement, something from your intimate life. You are under no obligation to, and nothing in the form asks you to.

If you do choose to write them, you expressly agree that I process them in order to understand your project, prepare the design and adapt the session. They are used for nothing else, they are passed to nobody, and they follow exactly the same retention periods as the rest of your request.

If you would rather not write any of that, just say you want to talk about it in person: we will go through it at the studio, with nothing written down.

Why what I do with this information

To reply to you and prepare your session. That is what the form is for: reading your project, answering, setting an appointment, drawing, then tattooing. This processing follows directly from the step you take by writing to me.

To send you the confirmations and notifications tied to your request. The acknowledgement, the attached documents, my replies. Same logic: it is the service you asked for.

To protect the form. Checking that a submission is not coming from a bot, limiting repeated sends, keeping the site usable. I have a legitimate interest in not letting a public form get flooded, and these checks are built to learn as little as possible about you.

To send you a review request, once. It is part of the emails tied to your session that you agree to by ticking the box on the form, which is never pre-ticked. You can withdraw that agreement at any time by replying to me, and it changes nothing about your session.

To measure the site's audience and analyse how it is used. Only if you have accepted on the cookie banner, and never before.

To meet my accounting obligations and defend my rights. An invoiced session generates accounting records that the law requires me to keep. They follow their own regime, independent of your project request.

How long retention periods

I do not keep anything just in case. Each category has its own period, and deletion is automatic.

A request that does not turn into a project: 30 days. After that it is deleted from the site's database. If you write to me six months later, we start fresh, and that is perfectly fine.

A file that became a client file: 5 years after your last session. It lets me find what we did together, rework a piece, plan a follow-up, and answer if a question comes up later about a tattoo I did.

Emails and reference images: 90 days after the project closes. Whatever you sent me by reply is deleted from my mailbox at that point.

Proof of your agreement to the emails tied to your session: 365 days. It is kept with your request, purely to show that the review email rested on your agreement.

Anti-abuse counters: minutes to hours. The counter tied to an email address lives at most 48 hours, the one tied to an IP address at most 30 minutes. Technical email delivery logs are kept for 90 days.

Accounting records: the period set by law. They are not covered by the periods above, and keeping a client file for five years never automatically extends anything else.

Who else sees it my providers and their countries

I do not sell your data, I do not rent it, I do not trade it and I pass it to no advertising network. The only companies that touch it are the technical providers that keep the site running, and they are not allowed to use it for their own purposes.

Vercel hosts the site and runs the form processing. It therefore sees the requests, the IP addresses and the technical logs go past. Processing runs in the Frankfurt region, in Germany. Vercel is still an American company and may access the data from the United States; it is certified under the Swiss-U.S. Data Privacy Framework.

Neon hosts the PostgreSQL database where your request is stored until it is deleted. American company, covered by its parent company Databricks' certification under the Swiss-U.S. Data Privacy Framework.

Resend delivers the confirmation and notification emails. It therefore processes the addresses, the content and the metadata of those messages. American company, certified under the EU-U.S. Data Privacy Framework. Open tracking and click tracking are switched off: no invisible pixel, no rewritten link in the emails you receive.

Cloudflare provides the form's anti-bot check, which analyses technical signals from your browser without reading what you write. American company.

Google hosts the mailbox where I receive your request and where I reply to you. It is a personal Gmail account, governed by Google's consumer terms rather than by a negotiated data processing agreement: better said plainly. I am the only one with access, and the account is protected by two-factor authentication.

Google Business Profile only comes into play if you click the link in the review request. At that point you leave my site, and what you write is published at Google, under its terms rather than mine.

What all of these have in common: they are American companies. Even when processing runs in Europe, access from the United States remains possible. Since 15 September 2024, the Swiss Federal Council has recognised the Swiss-U.S. Data Privacy Framework as providing an adequate level of protection for companies certified under it.

One person, finally, and not a machine: the agency that designed this site still maintains it, and therefore keeps administrative access to the Vercel project and to the database. That access is only there to keep the site running and to fix it. It does not use your data for its own purposes, and it is based in Switzerland.

Beyond these providers, nobody else sees your request. Not the studio, not a colleague, not a third party.

Measurement & experience the tools waiting for your consent

Two tools can measure what happens on this site, and neither starts before you have said yes. Until you answer the banner, nothing is loaded, no measurement cookie is set, and no request goes out to Google or to Microsoft.

One single consent covers both. Google Tag Manager is the one container that loads them, and your answer applies to the whole: accepting means accepting both; refusing means having neither.

Audience measurement. Google Analytics 4 tells me how many people come, which pages they land on and what they look at. The measurement data is kept for fourteen months. No advertising feature is switched on: no Google signals, no remarketing, no user ID, no ad personalisation.

Experience analysis. Microsoft Clarity records heatmaps and browsing sessions, which lets me see where the site gets in the way. At Microsoft, session playback is kept for 30 days and aggregated data for up to 9 months.

Refusing is as easy as accepting. Both buttons sit side by side, at the same level, from the very first screen. Your choice is kept for thirteen months, after which you are asked again. You can change it whenever you like, and going back deletes the measurement cookies already set.

What these tools will never see. The project request form is excluded from recording: neither what you type nor what you select. Page addresses are passed to them cleaned, without anything after the question mark or the hash, so that no identifier or token can slip in. No email address, no phone number and no field content is ever sent to them.

The site works perfectly without. Refusing degrades nothing: browsing, the form and the submission all behave exactly the same. The cookie-by-cookie detail is on its own page.

Security how I protect all this

The whole site is served over HTTPS: what you send is encrypted between your browser and the server. The database is reachable only by the site's own functions, never from outside, and access to the requests is limited to me.

The form is protected by an anti-bot check and by counters that limit repeated submissions. Those counters store neither your email address nor your IP address in the clear: they keep a fingerprint that cannot be traced back to you. The internal links I send you by email are signed, so that nobody can forge one.

No security is absolute, and I am not going to tell you otherwise. If an incident were to affect your data in a way that poses a risk to you, you would be informed, and so would the competent authority.

Images & reviews photos, testimonials, review request

Photos of your tattoo. I photograph the pieces I do, because that is my portfolio and my way of showing my work. Nothing is published on this site, on Instagram or anywhere else without my having asked for your agreement. Saying no changes nothing about your session, nor about how much I want to do it, and you owe me no reason. If you change your mind later, write to me: I take the photo down from the channels I control.

Testimonials. Same rule. I do not publish what you wrote to me without your agreement, and a testimonial is as easy to withdraw as it was to give.

The review request. By ticking the box on the form, you agree to receive one email after your session, a single one, inviting you to leave a Google review. You are never obliged to, there is no follow-up, and you can withdraw your agreement at any time by replying to me. What you then write at Google is published under Google's terms, not mine.

Adults only I don't tattoo minors

I do not tattoo anyone under 18, even with parental permission and even with the parents in the room. It is a personal choice: life is long, the body is large, and a few years' wait either confirms the urge or doesn't.

The form is therefore for adults only. If I receive a request from someone under 18, I do not process it and I delete it.

Your rights and how to exercise them

The Swiss Federal Act on Data Protection (FADP) gives you several rights over what I hold about you.

To know. You can ask me whether I process data about you and which data, and get a copy of it.

To correct. If something is wrong or incomplete, you can ask me to put it right.

To delete. You can ask for your request and our exchanges to be erased. I do it, except for what a legal obligation requires me to keep, in particular the accounting records of an invoiced session.

To refuse. You can object to a processing operation, and withdraw at any time an agreement you had given, whether that is the review request, the publication of a photo or the measurement tools. Withdrawal applies going forward and does not call into question what happened before.

How to do it. An email to kaiiza.tattoo@gmail.com is enough, with no form and no particular wording. I reply within a reasonable time and free of charge. If I have a genuine doubt about your identity, I may ask you for something that confirms it, and I will never ask for more than strictly necessary.

If my answer does not satisfy you, you can contact the Federal Data Protection and Information Commissioner (FDPIC) in Bern.

Finally, if the European General Data Protection Regulation applies to your situation, you additionally have the rights it provides, including restriction of processing and data portability, and you can lodge a complaint with the data protection authority of your country of residence. My business is aimed at the Swiss market, but I would rather you knew where to go than be sent off into a technicality about territorial scope.

Updates this page changes when the site does

This page describes how the site actually works, not an intention. So it is updated before any change that concerns it, never after.

Concretely: no new tool, no new tag, no embedded third-party content and no new provider is added to the site without its purpose, its data, its country, its retention period and its cookies being described here first. If a change alters what you had agreed to, you are asked again.

Last updated: 23 August 2026.