Egevej Custom ApS
Privacy policy
Privacy Policy for The Phoenix InkLast updated: August 18, 2026
This Privacy Policy describes how Egevej Custom ApS, which operates The Phoenix Ink, processes personal information when you visit our website, submit a booking request, order a gift card, sign up for our newsletter, or otherwise contact us.
1. Data Controller
Egevej Custom ApS is the data controller responsible for processing your personal information.
Egevej Custom ApS / The Phoenix Ink
Kapellanstræde 1, st. th.
5600 Faaborg
CVR No.: 43732293
Phone: 22 81 55 02
Email: info@faaborgtattoo.dk
2. What personal data do we process?
Depending on your interaction with us, we may process the following information:
- Name, email address, and phone number.
- The content of booking requests and other correspondence.
- Information about your preferred tattoo artist, design, placement, size, and desired appointment time.
- Reference images, sketches, and other materials that you send to us.
- Information about appointments, work performed, tattoo inks used, lot or batch numbers, and associated invoices.
- Information about gift cards, including the recipient, purchaser, amount, email address, payment status, delivery, and redemption.
- Billing and accounting information.
- Newsletter subscription, date of consent, and any unsubscription.
- Technical information such as IP address, time, browser information, and necessary session data.
You should not send health information or other sensitive personal data in free-text fields or attachments unless it is necessary for us to safely assess or perform the requested tattoo.
3. Purpose and Legal Basis for Processing
Bookings, Inquiries, and Customer Contact
We process your information to respond to your inquiry, evaluate your project, schedule an appointment, and enter into or fulfill an agreement. As a general rule, this processing is based on Article 6(1)(b) of the General Data Protection Regulation (GDPR).
Gift Cards, Invoices, and Bookkeeping
We process information to create and manage gift cards, payments, invoices, and accounting records. The legal basis is Article 6(1)(b) when processing is necessary for the performance of a contract, and Article 6(1)(c) when we must comply with accounting and tax laws.
Documentation of tattoo work and products used
We may record information about the work performed and the inks used in order to document the procedure, address any subsequent inquiries, and meet relevant documentation and safety requirements. This processing is based on Article 6(1)(b) and, where applicable, our legitimate interest under Article 6(1)(f).
Sensitive Information
If it is necessary to process health information in connection with the assessment or safe performance of a tattoo, we limit the processing to what is necessary. Where required by law, we obtain explicit consent in accordance with Article 9(2)(a). Consent may be withdrawn at any time with effect for future processing.
Newsletter and Marketing
We only send newsletters and electronic marketing communications if you have given your consent. The legal basis is Article 6(1)(a) and the provisions of the Marketing Act. You may unsubscribe at any time by clicking the link in the newsletter or by contacting us. Withdrawal does not affect the lawfulness of the processing that took place prior to the withdrawal.
Operation and Security
We process necessary technical information to operate, troubleshoot, and protect the website and the administration system. The legal basis is our legitimate interest in providing a secure and stable service, in accordance with Article 6(1)(f).
4. The Phoenix Ink Backend and Google Data
The Phoenix Ink Backend is our internal administration system. Following active approval by an administrator, the system can be connected to Google Calendar and Google Drive.
Google Calendar access is used to view, create, edit, move, and delete the company’s calendar appointments. Google Drive access is used to view, search, create, upload, download, move, rename, and delete files and folders in the Google Drive account that the administrator connects.
Access is limited to the Google account that the administrator explicitly authorizes via Google’s OAuth system. We do not use Google data for advertising, profiling, or the sale of information.
OAuth access and refresh tokens may be stored by our administration system to enable the authorized connection to function. Tokens and Google data may only be accessed by authorized administrators and relevant technical data processors. Access can be revoked in the Google Account’s security settings or by disconnecting the account in the administration system.
The Phoenix Ink Backend’s use and transfer to other apps of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
The Phoenix Ink Backend’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Recipients and Data Processors
We only disclose or transfer personal data when necessary and lawful. Data may be processed by:
- Our hosting and server provider.
- Our email provider.
- Google in connection with Google Calendar, Google Drive, and any embedded Google services.
- Accountants, auditors, and accounting system providers, when necessary.
- Government authorities, if we are legally required to do so.
We do not sell personal data. Data processors may only process data in accordance with our instructions and based on relevant data processing agreements.
6. Transfer to Countries Outside the EU/EEA
Some providers, including Google, may process data outside the EU/EEA. If such a transfer occurs, it must be based on a valid legal basis for the transfer, such as the European Commission’s adequacy decision or standard contractual clauses, supplemented as necessary by relevant security measures.
7. Retention and Deletion
We retain personal data only for as long as necessary for the purpose for which it was collected, or for as long as required by law.
- General inquiries that do not lead to a customer relationship are, as a rule, deleted or anonymized no later than 12 months after the most recent contact.
- Customer correspondence and contract information are retained for as long as necessary for the customer relationship and the handling of any subsequent claims.
- Accounting documents and necessary bookkeeping information are retained for the period required by accounting legislation.
- Information about active gift cards is retained for as long as the gift card is valid, and thereafter for as long as necessary for accounting and documentation purposes.
- Newsletter information is processed until you unsubscribe. Necessary documentation regarding consent and unsubscription may be retained for a limited period to demonstrate compliance with regulations.
- Google OAuth tokens are retained until the connection is terminated, access is revoked, or the integration is no longer in use.
Information may be retained for a longer period if necessary to establish, assert, or defend a legal claim.
8. Cookies and External Content
The website may use technically necessary cookies or similar technologies to ensure basic functionality and security. If we use non-essential cookies, analytics, marketing, or embedded content that sets or reads such cookies, these are loaded only on the basis of valid consent.
The website may contain Google Maps or links to external services. When an external service is loaded, the provider may receive technical information such as your IP address and browser data. You can read more in the respective provider’s privacy policy.
9. Security
We take appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and access. Access to the administration system is restricted to authorized users.
10. Your Rights
Under data protection regulations, depending on the circumstances, you have the right to:
- To access the personal data we process about you.
- To have inaccurate or incomplete information corrected.
- To have data deleted.
- To have the processing restricted.
- To object to processing based on legitimate interests.
- To receive data in a structured, commonly used, and machine-readable format when the rules on data portability apply.
- To withdraw consent with effect for future processing.
These rights may be limited, for example, if we are legally required to retain certain information. Contact us at info@faaborgtattoo.dk if you wish to exercise your rights.
11. Complaints
If you are dissatisfied with our processing of your personal data, we encourage you to contact us first. You also have the right to file a complaint with:
The
Danish Data Protection Agency
Carl Jacobsens Vej 35
2500 Valby
Phone: 33 19 32 00
Web: www.datatilsynet.dk
12. Changes
We may update this Privacy Policy if our processing practices, systems, or the law change. The current version will always be available on this page, along with the date of the most recent update.