This notice explains what personal data we collect, why, who we share it with, how long we keep it, and the rights you have over it — under the UK GDPR and the Data Protection Act 2018.
Thundercat Promotions Limited ("we," "our," "the Studio") is a company registered in England & Wales under company number 09260031, with registered office at 12 Goose Gate, Nottingham, NG1 1FF. We trade as Thundercat Tattoo Studio. We are a data controller under the UK GDPR for the data described in this notice.
We operate a two-party booking structure (see our Terms & Conditions). When you book a session:
This notice covers only the Studio's processing. Your Artist should provide their own privacy notice for their side of the relationship; where they don't, contact the Studio and we'll connect you.
Name; email; (optional) phone number; your tattoo idea, size, placement and timeframe; artist preference; reference URLs; submission timestamp and IP address (for fraud prevention); and UTM parameters (to understand which channel introduced you).
Our correspondence with you (email, SMS, call notes); consultation notes and design files; and photographs of existing tattoos or placement areas, with your consent.
Deposit payment details (processed by Stripe / Klarna — we do not store card numbers) and scheduling data.
An ID check on the day to confirm you're 18+ — we look at your photo ID when you attend, but we don't collect or store your ID number and don't keep a copy of it; your Tattoo Consent & Medical Questionnaire, including relevant medical history (special-category data — see Section 4); and your photography consent preferences.
Session outcomes (size, placement, artist, price); healing communications; review and feedback correspondence; and photography of the tattoo, if you consented.
Cookies and similar technologies (see Section 8); Google Analytics 4, Meta Pixel and Google Ads tags where enabled; and email open/click events, subscription status and engagement history from our email provider.
Your medical questionnaire data is special-category data under UK GDPR Article 9. We process it only to ensure your safety before and during the session, to comply with our insurance requirements, and to defend legal claims if necessary. We do not use it for marketing, analytics, or any purpose unrelated to delivering the tattoo safely.
Our lawful bases for special-category data are Article 9(2)(a) — your explicit consent, given via the Consent & Medical Form — and Article 9(2)(f) — establishing, exercising or defending legal claims, where relevant.
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Responding to your application | Legitimate interests (responding to an enquiry you've made) |
| Delivering the Studio Service Contract | Contract performance |
| Processing payments | Contract performance + legal obligation (tax records) |
| Safety checks before the session | Contract performance + legitimate interests (safety) + Art. 9(2)(a) for medical data |
| Sending aftercare messages | Contract performance |
| Marketing emails / SMS | Consent, or legitimate interests (soft opt-in for existing clients) |
| Website analytics | Consent (for non-essential cookies) |
| Tax, licence and legal obligations | Legal obligation |
| Defending against claims | Legitimate interests |
| Data | Retention period |
|---|---|
| Application data (if you don't book) | 24 months from submission, then deleted |
| Client records (booking, session, payment) | 6 years after last session (Limitation Act 1980 + HMRC rules) |
| Consent & Medical Questionnaire | 6 years (longer for clients who were minors) |
| Email marketing subscription | Until you unsubscribe, or 24 months of inactivity |
| Accounting records | 6 years (HMRC requirement) |
| CCTV footage (if any) | 31 days, then overwritten |
Under UK GDPR you have the right to:
To exercise any right, email hello@thundercattattoostudio.com. We respond within 30 days (occasionally extended to 90 days for complex requests). If you're unhappy with how we handle your data, you can complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk — though we'd rather hear from you first so we can put it right.
We use essential cookies by default and request your consent for analytics and marketing cookies via a banner on your first visit. You can change your choice any time by clearing the site's stored preference in your browser. Until you consent, our Google Analytics, Meta Pixel and Google Ads tags don't load.
Our services are for adults (18+). We don't knowingly collect data about under-18s. If a parent or guardian becomes aware that a child has applied to us, please email hello@thundercattattoostudio.com and we'll delete the data immediately.
We'll update this notice when our practices change. The current version always lives at this page, and we notify subscribers of material changes by email.