Skip to main content

Privacy Policy

How Milly Tattoo handles booking details, contact messages, reference images, website security data and your GDPR rights in Ireland.

How I use and protect information from enquiries, bookings, uploads and website visits.

Last updated: 2 July 2026.

This policy explains how Milly Tattoo handles personal data when you visit millytattoo.com, send a message, upload reference images or request an appointment.

1. Data controller and contact

Milly Tattoo, Unit 4, The Heritage, Main St, Townparks, Birr, County Offaly, R42 EK20, is the controller for the personal data described here. Privacy questions and rights requests can be sent to info@millytattoo.com or through the contact page.

2. Data I collect

I may collect your name, email address, phone number, tattoo brief, placement and size notes, reference images, appointment details, payment status, consent records and messages. If you create a client login, I also process the details needed to operate that account.

The website processes technical information needed for security and delivery, such as IP address, browser and device information, request logs, cookie choices and fraud-prevention results. I don't ask you to send medical information through a general enquiry. Tell me only what is relevant to carrying out the tattoo safely.

I use enquiry and booking details to answer your request, assess the tattoo, arrange an appointment and provide the service. The legal basis is taking steps at your request before a contract and performing a contract.

I keep invoices, payment records and records required for accounting or legal obligations. I use limited security logs, rate limits and consent evidence for legitimate interests in protecting clients, the studio and the website, and for demonstrating compliance.

Optional analytics or marketing tools are not loaded unless they are enabled and you consent. You can withdraw that consent through the cookie controls.

4. Who receives data

Data is shared only where needed with providers that support the website and studio. These may include the hosting and database provider, Cloudflare for delivery and security, object storage for uploaded images, the email delivery provider, Stripe for card payments, and professional advisers where necessary. Payment card details are handled by the payment provider and are not stored in the website database.

5. International transfers

Some providers may process data outside Ireland or the European Economic Area. Where that happens, I rely on an applicable adequacy decision, standard contractual clauses or another lawful transfer mechanism offered by the provider.

6. Retention

I delete unsuccessful enquiries and unused reference uploads when they are no longer needed. Any that remain are reviewed within 12 months. Booking, consent, payment and accounting records may be kept for up to six years where needed for tax, contract or legal records. Security logs are kept for a shorter operational period unless an incident requires investigation. Cookie-consent evidence is kept for up to two years. Backups expire on a rolling schedule.

7. Your rights

Under data-protection law you may have rights to access, correct or erase data, restrict or object to processing, receive portable data, and withdraw consent. A right can be limited where a record must be kept for a legal claim, accounting or another lawful reason.

You can also complain to the Irish Data Protection Commission at dataprotection.ie.

8. Automated decisions

The website uses automated security checks and rate limits to prevent abuse. They do not make decisions about whether your tattoo request is accepted.

9. Updates

I'll update this policy when the website, providers or processing purposes change. The date above identifies the current version.