flash.

Data Processing Agreement

Last updated 4 September 2026

Where you use Flash to keep records about your clients, you are the data controller and CRTYX HOLDINGS LIMITED is your processor. This agreement sets out the terms UK GDPR Article 28 requires, and forms part of our Terms of Service. It applies to artists and studios; if you are booking a tattoo it is not about you.

1. Subject matter and duration

We process client personal data on your behalf only to provide Flash to you: receiving and storing booking enquiries, running the message threads between you and your clients, sending the notifications you have configured, and keeping the records your dashboard displays.

Processing lasts as long as your account is open, and ends when it is closed or this agreement is terminated, subject to section 8.

2. Nature and purpose, and the data involved

Categories of data subject: your clients, and the artists, studios and staff you interact with through the platform.

Types of personal data: name and pronouns, email address, a phone number where a client provides one for reminders, the booking brief, placement, size, budget, dates and deposit records, reference images, and the contents of message threads and their attachments.

Special category data: none. Consent and medical answers are completed on your own device and are never uploaded to us. All that is recorded against a booking is the date the paperwork was done. If you find a way to put health information into a free-text field, you are doing so outside the design of this service and outside this agreement.

3. Our obligations

We will:

  • process client data only on your documented instructions, which for these purposes are these terms, our Terms of Service, and the settings you choose in the product;
  • tell you if we think an instruction breaches data protection law;
  • make sure the people who can access the data are bound by confidentiality;
  • keep the security measures in section 5;
  • help you respond to data subject requests, and with your obligations on security, breach notification and impact assessments, so far as is reasonable given what we can see;
  • notify you without undue delay after becoming aware of a personal data breach affecting your client data; and
  • make available the information you reasonably need to show we are meeting these obligations.

4. Sub-processors

You give general authorisation for us to engage sub-processors for application hosting, database hosting, file storage for images, email delivery, and SMS delivery for the appointment reminder a client has opted into. We remain responsible for their performance, and none of them gets the data for their own purposes.

We keep a current list of the named sub-processors and will provide it on request. We will give reasonable notice before adding or replacing one, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may terminate.

5. Security

Message bodies and attachment references are encrypted at rest with AES-256-GCM. We hold the key, so this is not end-to-end encryption: it means a database dump shows who messaged whom and when, but not what was said. Data in transit is encrypted with TLS.

Access is enforced by a single authorisation layer covered by automated tests. Support access to an account is recorded in an append-only audit log and shown to the user in a banner throughout. Reading a message thread we are not party to requires a written reason, logged before any content is returned.

6. International transfers

Some of the sub-processors described in section 4 process data outside the UK. Where they do, transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or under UK adequacy regulations where those apply.

7. Your obligations

You are responsible for having a lawful basis to hold the client information you put here, for telling your clients how you use it, for the accuracy of what you upload, and for responding to your clients' requests about their data. We will help, but the relationship is yours.

8. Deletion and return

You can export everything we hold at any time from your settings, as a JSON file. On closing your account we anonymise the personal details in it. Bookings survive as anonymised records because they are your own business records and an artist needs them to stay intact; they no longer identify anyone.

Notification delivery records are deleted after 90 days.

One carve-out, stated plainly: entries in the audit log of administrative access are kept as a security record and are not deleted on request. For that log we act as controller in our own right rather than as your processor, because the whole point of it is that it cannot be edited or erased by the people it records — ourselves included. It holds who did what and when, not client content. Our Privacy Policy covers it.

9. Audit

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will answer reasonable questions about our processing and provide the evidence we hold. Where an on-site audit is genuinely necessary we will agree a scope and timing that does not disrupt the service for other customers.

10. Precedence and contact

This agreement forms part of our Terms of Service, and where it conflicts with them on the processing of client data, this agreement wins. Our Privacy Policy describes the data we hold as controller in our own right, which is a separate matter.

Data protection contact: privacy@flash.tattoo.

Flash is a trading name of CRTYX HOLDINGS LIMITED, a company registered in England and Wales under company number 12383952.

Terms · Privacy · Cookies · Refunds · DPA

Data Processing Agreement - booked in a flash