Data processing agreement
Last updated: [[DATUM]]
Entries in double square brackets are completed before launch.
This agreement under Art. 28 GDPR is concluded between the studio that creates an account with Envis (controller) and [[NAME]], [[ANSCHRIFT]] (processor, hereafter Envis). It takes effect when the studio ticks the confirmation while creating its account; the time is stored with the account.
1. Subject matter and duration
Envis provides the studio with a web application to upload tattoo designs, generate customer links and receive its customers' snapshots and replies. Processing lasts for as long as the studio has an account with Envis.
2. Nature and purpose, data categories, data subjects
The purpose is previewing a tattoo design on the customer's body before tattooing, and the coordination about it between studio and customer.
Processed are: project label (usually a first name), body part and size, the design in all its versions, placements, snapshots (photos of the customer's body that the customer sends themselves), replies as text or reaction, a device identifier as a cookie, plus timestamps and view counters.
Data subjects are the studio's customers and the people who operate the panel for the studio.
3. Instructions
Envis processes the data only on the studio's documented instructions. The studio gives instructions by operating the application (uploading, archiving, revoking a link) and, beyond that, by email to [[EMAIL]]. If Envis considers an instruction unlawful, it informs the studio.
4. Confidentiality
Everyone at Envis with access to the data is bound to confidentiality. Customer data is accessed only for troubleshooting at the studio's request or to meet legal obligations.
5. Technical and organisational measures
Transport over TLS only. Database and image storage in Cloudflare's Western Europe region, stored encrypted. Images are reachable only through signed addresses with an expiry. Sign-in without passwords via one-time links; session and link tokens are stored as hashes only. Customer links are random with 80 bits of entropy, revocable and can be given an expiry. Access to production systems only through personal credentials kept in a secured keychain. Changes to projects are recorded in an event log.
6. Sub-processors
The studio approves the use of Cloudflare, Inc. (hosting, database, image storage, Western Europe region) and Resend (Plus Five Five, Inc.; delivery of sign-in mails, EU region). Agreements under Art. 28 GDPR and, where needed, standard contractual clauses are in place for both. Envis announces new or replaced sub-processors to the studio four weeks in advance by mail; the studio may object within that period and end the agreement.
7. Supporting the studio
Envis supports the studio in answering data subject requests, in reporting personal data breaches (notification to the studio without undue delay, at the latest 48 hours after becoming aware) and, where relevant, in data protection impact assessments.
8. Deletion and return
The studio can archive projects; the customer link ends immediately. On instruction, Envis deletes individual projects or the whole account including images within 30 days. Before that, the studio can download its designs and snapshots from the panel.
9. Evidence
On request, Envis provides the studio with the information needed to demonstrate compliance with this agreement and allows reviews to a reasonable extent, with two weeks' notice.
10. Final provisions
Austrian law applies. Envis announces changes to this agreement four weeks in advance. The current text is available at envis.at/avv; the version confirmed when the account was created is sent on request.