Legal
Privacy policy
Draft. This policy has not been reviewed by a lawyer yet and must be checked before launch. Placeholders are marked [TODO].
1. Who is responsible
The controller responsible for this website under the GDPR is:
[Legal name — TODO]Paradyme — tattoo studio of Ted Faulmann
[Street and number — TODO]
[Postcode — TODO] Dresden, Germany
Email: hello@paradyme.art
For anything about your data, just email the address above. A data protection officer is not required for a business of this size [TODO: confirm].
2. In short
- No analytics, tracking pixels, advertising or marketing cookies.
- Fonts are hosted on this site — nothing is loaded from Google or other font services.
- There are no embedded social media widgets. Instagram is a plain link: nothing is sent to Meta unless you click it.
- Your data is only used to answer your booking request and to run the Ideate tool you choose to use. It is never sold.
3. Hosting & delivery (Cloudflare)
This website runs on the infrastructure of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (“Cloudflare”). We use:
- Cloudflare Workers and static asset hosting to serve the website;
- Cloudflare D1 (database) to store booking requests and Ideate accounts;
- Cloudflare R2 (file storage) for reference photos and images generated with Ideate;
- Cloudflare Email Service to send booking requests to Ted and sign-in codes to you;
- Cloudflare’s security features (e.g. DDoS protection and rate limiting).
Whenever you visit the site, Cloudflare necessarily processes technical data: your IP address, date and time of the request, the page requested, the referring page, your browser and operating system, and the approximate country derived from your IP address. This is used to deliver the site, keep it secure and prevent abuse. Technical logs are kept only for a short period [TODO: confirm log retention, e.g. 3–7 days].
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, reliable and fast website. Cloudflare acts as our processor under a data processing agreement (Art. 28 GDPR). For transfers to the USA see section 9. More: Cloudflare privacy policy.
4. Spam protection (Cloudflare Turnstile)
The booking form and the Ideate sign-in are protected by Cloudflare Turnstile. It only loads once you start filling in one of these forms. Turnstile evaluates technical signals from your browser and device (such as your IP address, browser characteristics and how the page is used) to tell people from automated bots, and occasionally shows a checkbox. To do this it may need to store or read technical information in your browser, which is strictly necessary for the form you are using (§ 25(2) no. 2 TDDDG).
Legal basis: Art. 6(1)(f) GDPR — protecting the forms, the inbox and the service from spam and abuse. More: Turnstile privacy addendum.
5. Booking requests
When you send a request through the booking form, we process:
- your name and email address;
- your description of the tattoo idea;
- up to three reference photos, if you add any;
- a link to an Ideate image, if you started your request from Ideate;
- the time of the request, your IP address and the country derived from it (to prevent spam and abuse).
With JavaScript enabled, photos are resized in your browser before they are uploaded — this also removes embedded metadata such as the GPS location where the photo was taken.
Purpose and legal basis: to reply to you and plan your tattoo — steps taken at your request before entering into a contract, Art. 6(1)(b) GDPR. IP address, country and timestamp are processed under Art. 6(1)(f) GDPR (legitimate interest in preventing spam and misuse). Name, email and idea are needed to reply; photos are optional.
Storage: requests are stored in Cloudflare D1, photos in Cloudflare R2, and a copy is emailed to Ted’s inbox [TODO: name the email provider].
Retention: requests are deleted 12 months after our last contact. If your request leads to an appointment, we keep what is needed for it, and business records for as long as German commercial and tax law requires (generally 6 or 10 years, § 257 HGB, § 147 AO).
Please don’t include health information (medical conditions, medication, allergies) in the form. If something is relevant for your appointment, Ted will go through it with you directly.
6. Email & Instagram
If you email us directly, we process your email address and the content of your message to answer you (Art. 6(1)(b) GDPR for booking enquiries, otherwise Art. 6(1)(f) GDPR). Retention is the same as for booking requests.
If you contact Ted on Instagram, Meta Platforms Ireland Ltd. processes that conversation under its own privacy policy. This website only links to Instagram and does not embed any Meta content.
7. Ideate (AI design tool)
Account
To use Ideate you sign in with a one-time code sent to your email — there is no password. We store your email address, when your account was created, and your sign-in sessions (a session token, IP address, browser user agent and expiry). One-time codes are stored hashed and expire after 10 minutes.
What you create
We store the prompts you write, the mode you chose (design sheet or on-skin mock-up), which reference images you picked, whether you uploaded a photo, the generated images, and daily usage counts (to enforce fair-use limits). If you upload a photo, it is used for that generation only [TODO: confirm uploads are not stored].
Generated images are stored in Cloudflare R2 and can be opened by anyone who has their unique, random link. The links are not published or indexed.
Image generation by OpenAI via Cloudflare
To create an image, your prompt, the selected reference images and any photo you upload are sent to an image-generation model made by OpenAI (OpenAI, L.L.C., San Francisco, USA), accessed through Cloudflare Workers AI. Cloudflare forwards the request to OpenAI, which returns the image. According to OpenAI’s API terms, this data is not used to train its models and may be kept for up to 30 days to detect abuse [TODO: verify current terms for requests routed via Cloudflare].
Please don’t upload photos of other people without their permission, and don’t include sensitive personal information in prompts.
Legal basis: Art. 6(1)(b) GDPR — providing the Ideate service you asked for; Art. 6(1)(f) GDPR for usage limits and abuse prevention.
Retention: your account, prompts and images are kept until you ask us to delete them — just email hello@paradyme.art. Inactive accounts are deleted after [TODO: e.g. 12 months] without sign-in. If you attach an Ideate image to a booking request, it becomes part of that request (section 5).
9. Recipients & transfers outside the EU
Your data is only shared where needed to run this site:
- Cloudflare, as hosting and email processor (all features above);
- OpenAI, via Cloudflare Workers AI (Ideate only);
- Ted’s email provider, for booking requests [TODO].
Cloudflare and OpenAI are based in the USA, so data may be processed there. Transfers rely on the EU–U.S. Data Privacy Framework adequacy decision (Art. 45 GDPR) where the provider is certified, and otherwise on the EU Standard Contractual Clauses (Art. 46 GDPR) [TODO: confirm certification status].
10. Your rights
You have the right to:
- access the data we hold about you (Art. 15 GDPR);
- have it corrected (Art. 16) or deleted (Art. 17);
- restrict how it is processed (Art. 18);
- receive it in a portable format (Art. 20);
- object at any time to processing based on Art. 6(1)(f) GDPR, on grounds relating to your particular situation (Art. 21);
- withdraw any consent you have given, with effect for the future (Art. 7(3)).
To use any of these rights, email hello@paradyme.art.
You can also complain to a data protection supervisory authority — for example the one where you live, or the authority responsible for us:
Sächsische Datenschutz- und TransparenzbeauftragteDevrientstraße 5, 01067 Dresden
www.datenschutz.sachsen.de
We don’t use automated decision-making or profiling within the meaning of Art. 22 GDPR.
11. Security & changes
All connections use HTTPS. Access to stored requests and images is limited to what is needed to run the studio and this site.
We will update this policy when the site or the law changes; the date at the top shows the latest version. See also the imprint.











