Privacy policy
Last updated: [[DATUM]]
Entries in double square brackets are completed before launch.
Envis is a web application tattoo studios use to show a design to their customers on their own body via a link. This policy describes what data arises, what it is used for, how long it stays and what rights you have. It covers the website envis.at, the studio panel and the customer pages under envis.at/v/.
1. Controller
The controller for processing on this website and for studio accounts is [[NAME]], [[ANSCHRIFT]], email [[EMAIL]]. No data protection officer has been appointed, as the legal requirements for one are not met.
2. Two roles: studio and Envis
For the data of a studio's customers (designs, snapshots, placements, replies) the studio is the controller within the meaning of Art. 4(7) GDPR. The studio decides which design it uploads, who gets the link and when a project is archived. Envis processes this data as a processor under Art. 28 GDPR, solely on the studio's instructions and on the basis of the data processing agreement each studio concludes when creating its account.
For the studio accounts themselves (email address, sign-in, session) and for running the website, Envis is the controller.
3. Which data, for what, on what basis
Studio account
To sign in, studios provide their email address. Envis sends a sign-in link that is valid for 15 minutes and can be used once. Stored are the email address, the time of the last sign-in, the chosen language, the studio name, the city, an optional logo and the time the data processing agreement was confirmed. To prevent abuse, the IP address and time of each sign-in request are kept for one day. The basis is the contract with the studio (Art. 6(1)(b) GDPR), and for abuse prevention the legitimate interest in secure operation (Art. 6(1)(f) GDPR).
Projects and customer pages
A studio creates one project per customer: a label (such as a first name), the body part, the size, a note and the design in all its versions. On the customer page, placements, snapshots (photos from the customer's phone that the customer sends themselves) and replies as text or reaction are created. There is also a counter for how often a link was opened. The camera stream on the customer page is processed only on the device; only the snapshot the customer explicitly sends reaches Envis. The studio is the controller for this data; the legal basis follows from the relationship between studio and customer, usually the initiation of a contract (Art. 6(1)(b) GDPR).
Server logs
When a page is requested, Cloudflare's infrastructure processes the IP address, time, requested address and browser type in order to answer the request and fend off attacks. Envis itself keeps error messages and requests for seven days without building user profiles from them. The basis is the legitimate interest in secure and functioning operation (Art. 6(1)(f) GDPR).
4. Recipients and storage location
Envis runs on the infrastructure of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Database and image storage are pinned to the Western Europe region; the data is stored there. Cloudflare is certified under the EU-US Data Privacy Framework, and the EU Commission's standard contractual clauses apply in addition.
Sign-in links are sent through Resend (Plus Five Five, Inc., 2261 Market Street, San Francisco, CA 94114, USA), with processing in the EU region (Ireland). For this, Resend receives the studio's email address and the content of the sign-in mail.
There are no other recipients. Envis does not sell data and only hands it over where required by law.
5. Retention
- Sign-in links: valid for 15 minutes, deleted after one day.
- Sessions: 30 days after last use, immediately on sign-out.
- Projects, designs, snapshots and replies: as long as the studio keeps the project. Archived projects remain visible to the studio; the customer link is dead from the moment of archiving. The studio can instruct Envis to delete a project at any time; deletion takes place within 30 days.
- Studio account: until the studio requests deletion. Account, projects and images are then deleted within 30 days, unless a statutory retention duty applies.
- Server logs: seven days.
6. Cookies
Envis sets three cookies, all technically necessary and therefore permitted without consent (§ 165(3) Austrian TKG 2021): envis_s keeps the studio signed in (30 days), envis_lang remembers the chosen language (one year), envis_c marks the device on customer pages so that snapshots and placements from the same phone belong together (one year, only under envis.at/v/). There are no advertising or tracking cookies and therefore no cookie banner.
7. No analytics services
Envis embeds no analytics, advertising or social media services. Fonts, scripts and images are served from envis.at itself. There is no profiling and no automated decision-making.
8. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on a legitimate interest (Art. 21). Write to [[EMAIL]] for this.
If you are a studio's customer and your request concerns your design, your snapshots or your replies, the studio is your point of contact. Envis forwards requests that reach it directly to the studio and supports the studio in answering them.
You can also lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at, dsb.gv.at.
9. Changes
If anything about the processing changes, this policy is updated and the date at the top is refreshed. Studios hear about material changes by mail.