Privacy notice
Last updated: 28 September 2026
Controller and contact
Tattoo Armour GmbH, Bayreuther Str. 26, 92224 Amberg, Germany. Registered with Amtsgericht Amberg, HRB 7497. Managing directors: Moriel Seror and Günther Jahn. VAT ID: DE360618238.
For privacy requests, contact info@tattooarmour.com.
Data we process
Account data includes your name, e-mail, role, region, timezone, password hash if set, login timestamps, and session records including IP address and browser information. Login-attempt records contain IP address, e-mail, time and outcome for rate limiting and security.
Artist records include public Instagram profile figures and posts, contact details entered by the team, programme information, notes, decisions and check-ins. The artist area processes profile information and uploaded portraits and work images. Images may contain EXIF metadata, including location data; we do not strip metadata. Please upload images without location data.
Purposes and legal bases
We process these data to run the sponsored-artist programme, manage our contractual relationship with artists and keep accounts and the app secure. The legal bases are Article 6(1)(b) GDPR for contractual processing, Article 6(1)(f) GDPR for our legitimate interests in programme management and security, and Article 6(1)(a) GDPR for publication of portraits and quotes on our website with consent.
Account and programme data are needed to provide access and manage the programme. Without necessary data, we cannot provide the relevant service. Website publication is optional. You can withdraw consent at any time by contacting us; withdrawal does not affect the lawfulness of earlier processing.
Access, hosting and notifications
Authorised team members access records for their programme duties. Phone numbers and addresses are restricted to admin and ops users. The app is hosted by Hetzner Online GmbH, Nürnberg, Germany, in the EU.
Decision notifications reach the admin via Telegram (Telegram FZ-LLC; servers may be outside the EEA). They contain artist name, Instagram handle, region and the decision type only. Signal status and the proposing team member’s first name may also appear; proposal text, comments, e-mail, phone numbers and addresses are excluded.
Consented website content is publicly accessible. Instagram figures originate from public profiles; other artist records come from the artist or the team.
Retention
We delete account data 12 months after deactivation and artist records 24 months after the artist leaves the programme. The admin carries out these deletions manually.
The rate-limit window is 15 minutes. Login attempts are deleted after 24 hours. Expired or revoked sessions are deleted after 30 days. This cleanup runs after successful login. Other security logs are retained for 30 days.
Cookies
We use only the essential ta-session cookie to authenticate your session. It expires with the session, after no more than 30 days. We do not use analytics or advertising cookies.
Your rights
You may request access, rectification, erasure, restriction of processing and data portability, and object to processing based on legitimate interests. Contact us using the address above. You may lodge a complaint with the Bavarian State Office for Data Protection Supervision (BayLDA), www.lda.bayern.de.
We do not make automated decisions with legal or similarly significant effects. Programme decisions are made by people.