The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data are any data that can be used to identify you personally. Detailed information on data protection can be found in the privacy policy set out below.
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. The operator’s contact details can be found in the section “Information about the controller” in this privacy policy.
How do we collect your data?
Some data are collected when you provide them to us. This may include, for example, data that you enter into a contact form.
Other data are collected automatically or after you have given your consent when you visit the website. These are primarily technical data, such as your internet browser, operating system or the time the page was accessed. These data are collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data are collected to ensure the secure and error-free provision of the website. We process further personal data in particular when you contact us via the contact form, by email or by telephone.
What rights do you have regarding your data?
You have the right to receive information free of charge about the origin, recipients and purpose of your stored personal data at any time. You also have the right to request the correction or deletion of these data.
If you have given your consent to data processing, you may withdraw this consent at any time with effect for the future. Under certain circumstances, you also have the right to request that the processing of your personal data be restricted.
Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time if you have further questions regarding data protection.
External hosting
This website is hosted by an external service provider. The hosting provider is:
Hetzner Online GmbH
Industriestraße 25
91710 Gunzenhausen
Germany
When you visit our website, the hosting provider processes technical connection data. These may include IP addresses, the date and time of access, pages and files accessed, the amount of data transferred, browser information, the operating system used and information about successful or failed page requests.
The hosting provider’s servers also store data that you submit to us, for example through the contact form.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and technically error-free provision of our website. Where the processing is necessary to initiate or perform a contract, it is also based on Art. 6(1)(b) GDPR.
The hosting provider processes personal data only to the extent necessary to provide its services and in accordance with our instructions.
Data protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the applicable data protection regulations and this privacy policy.
When you use this website, various personal data may be collected. Personal data are any data that can be used to identify you personally. This privacy policy explains which data we collect, how we use them and for what purposes the processing takes place.
Please note that data transmission over the internet, for example when communicating by email, may be subject to security vulnerabilities. Complete protection of data against access by third parties cannot be guaranteed.
Information about the controller
The controller responsible for data processing on this website is:
Raphael Cristescu
Sabotage Tattoo Aachen
Lochnerstraße 1
52064 Aachen
Germany
Telephone: +49 163 9540611
Email: sabotage-tattoo@outlook.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data, such as names, email addresses or contact details.
Storage period
Unless a more specific storage period is stated in this privacy policy, we store your personal data only for as long as necessary for the respective processing purpose.
If you submit a valid request for deletion or withdraw consent that you have previously given, the relevant data will be deleted unless there is another legal basis for their continued storage.
Longer storage may be necessary in particular where statutory retention obligations apply, where the data are required for the establishment, exercise or defence of legal claims, or where a security incident must be investigated.
Once these reasons no longer apply, the data will be deleted.
Data transfers to third countries
We sometimes use services provided by companies whose parent companies or affiliated entities are located outside the European Union or the European Economic Area. In this context, the processing of personal data in third countries, particularly in the United States, cannot be ruled out.
Where the European Commission has adopted an adequacy decision for the respective third country, the transfer of data is based on Art. 45 GDPR. For transfers of data to companies in the United States, this may apply in particular where the relevant company is certified under the EU-U.S. Data Privacy Framework.
Where no adequacy decision exists or the relevant recipient is not appropriately certified, personal data are transferred only on the basis of suitable safeguards. These may include, in particular, the European Commission’s Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and, where necessary, additional technical and organisational safeguards.
Further information on possible transfers of data to third countries can be found in the following sections concerning the individual services used.
Withdrawal of your consent to data processing
Many data processing operations are only permitted with your express consent. You may withdraw consent that you have previously given at any time. The lawfulness of the data processing carried out before the withdrawal remains unaffected by the withdrawal.
Right to object to data collection in specific cases and to direct marketing
Where data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation. This also applies to profiling based on these provisions.
If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defence of legal claims.
Where your personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. This also applies to profiling insofar as it is related to direct marketing.
If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes.
Right to lodge a complaint with the competent supervisory authority
In the event of a breach of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
This right to lodge a complaint exists without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or in the performance of a contract in a commonly used, machine-readable format.
Where technically feasible, you also have the right to request that these data be transmitted directly to another controller.
SSL or TLS encryption
This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as enquiries that you send to us.
You can recognise an encrypted connection by the fact that the address line in your browser changes from “http://” to “https://” and by the lock symbol displayed in your browser.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Access, erasure and rectification
Within the scope of the applicable legal provisions, you have the right at any time to receive information free of charge about your stored personal data, their origin and recipients, and the purpose of the data processing.
You also have the right to request the rectification or erasure of these data, where the relevant legal requirements are met.
You may contact us at any time if you have further questions regarding your personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You may contact us at any time to exercise this right.
The right to restriction of processing applies in particular in the following cases:
If you dispute the accuracy of the personal data stored by us, we generally need time to verify this. For the duration of the verification, you have the right to request that the processing of your personal data be restricted.
If the processing of your personal data is or was unlawful, you may request the restriction of data processing instead of the deletion of the data.
If we no longer require your personal data, but you need them for the establishment, exercise or defence of legal claims, you have the right to request the restriction of processing instead of deletion.
If you have objected to processing pursuant to Art. 21(1) GDPR, a balance must be made between your interests and ours. Until it has been determined whose interests prevail, you have the right to request that the processing of your personal data be restricted.
Where the processing of your personal data has been restricted, these data may, apart from being stored, only be processed with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
Objection to promotional emails
We hereby object to the use of contact details published within the scope of the legal notice obligation for the purpose of sending unsolicited advertising and informational materials.
The website operator expressly reserves the right to take legal action in the event of unsolicited promotional information being sent, for example through spam emails.
Cookies and consent management
Our website uses cookies and comparable technologies, such as your browser’s local storage. Cookies are small files stored on your device that may contain certain information.
Some of these technologies are strictly necessary for the secure and technically correct operation of the website. These may include technologies that store your privacy settings, enable security functions or ensure that the website is displayed and functions correctly.
Strictly necessary technologies are used on the basis of Section 25(2) TDDDG. Where personal data are processed in this context, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and user-friendly provision of our website.
Cookies and comparable technologies that are not technically necessary are used only after you have given your express consent. In this case, information is stored on or accessed from your device on the basis of Section 25(1) TDDDG. Any related processing of personal data is based on Art. 6(1)(a) GDPR.
When you first visit our website, you can use the displayed consent banner to select which non-essential technologies you wish to allow. Necessary technologies are required for the basic operation of the website and therefore cannot be disabled.
You can change your selection at any time via the website’s privacy settings and withdraw consent that you have previously given with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
The storage period of the technologies used depends on their respective purpose. Some cookies are deleted at the end of your visit, while others remain stored until their intended storage period expires or you delete them via your browser or the privacy settings.
Further information about any third-party providers used and the associated data processing can be found in the following sections of this privacy policy.
Server log files
When you access this website, our hosting provider automatically collects and stores technical information in so-called server log files. This information is transmitted automatically by your browser or device.
The data processed may include:
browser type and browser version
operating system used
page or file accessed
previously visited website
date and time of access
IP address of the accessing device
amount of data transferred
information about successful or failed page requests
We generally do not combine these data with other data sources.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and technically error-free provision of our website as well as in detecting and preventing attacks and misuse.
The data are deleted once they are no longer required for these purposes. Longer storage may take place where there are specific indications of a security incident or unlawful use.
Contact form
If you send us an enquiry using the contact form provided on this website, we process the information you enter, including your contact details, in order to handle your enquiry and answer any follow-up questions.
We use the WordPress plugin WPForms to provide the contact form. The submitted form data are stored on our hosting provider’s server and in the database of our WordPress website. Access to the stored enquiries is restricted to authorised persons.
The data processed may include, in particular, your name, email address, telephone number and any information you provide in the message field or other form fields. The specific data processed depend on the information you enter in the contact form.
Where your enquiry relates to the initiation or performance of a contract, the processing is based on Art. 6(1)(b) GDPR. In all other cases, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the appropriate and efficient handling of enquiries addressed to us.
Data received through the contact form will only be disclosed where this is necessary to process your enquiry, where we are legally required to do so or where you have previously given your consent.
The data submitted through the contact form will be deleted once your enquiry has been fully dealt with and there are no statutory retention obligations or other legitimate reasons requiring further storage. Statutory retention periods remain unaffected.
Contact by email and telephone
If you contact us by email or telephone, we process your enquiry, including the personal data arising from it, in order to handle your request and answer any follow-up questions.
The data processed may include, in particular, your name, email address, telephone number, the content of your message and any further information you voluntarily provide in connection with your enquiry.
Where your contact relates to the initiation or performance of a contract, the processing is based on Art. 6(1)(b) GDPR. In all other cases, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the appropriate and efficient handling of enquiries addressed to us.
We use Microsoft Outlook or Outlook.com to manage our email communication. The provider responsible for users in the European Economic Area is:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland
When you send us an email, the personal data contained in it are processed through Microsoft’s systems. Processing or transfer of personal data to the United States or other third countries cannot be completely ruled out.
Microsoft states that it uses appropriate safeguards for international data transfers. Further information can be found in Microsoft’s privacy statement.
The data you provide will be deleted once your enquiry has been fully dealt with and there are no statutory retention obligations or other legitimate reasons requiring further storage. Statutory retention periods remain unaffected.
Linking to Instagram
Our website contains links to our profile on the Instagram social network.
Merely visiting our website does not generally establish a direct connection to Instagram’s servers through such a link. A connection is only established when you click the relevant link and are redirected to the Instagram website or app. Instagram may then process personal data, in particular your IP address, device and browser information, and information about the page accessed.
The provider responsible for users in the European Economic Area is:
Meta Platforms Ireland Limited
Merrion Road
Dublin 4, D04 X2K5
Ireland
If you are logged in to Instagram, Instagram may be able to associate your visit with your user account. We have no influence over the subsequent processing of data by Instagram.
Further information on the processing of personal data can be found in Meta’s privacy policy.
Google Web Fonts – local hosting
This website uses Google Fonts to ensure the consistent display of fonts.
The fonts used are hosted locally on our web server. Therefore, no connection to Google’s servers is established when you visit our website, and no personal data are transmitted to Google in connection with the display of these fonts.
Adobe Fonts
This website uses Adobe Fonts to ensure the consistent display of fonts. Adobe Fonts is a service provided by the Adobe group of companies.
When you access a page, your browser may load the required fonts from Adobe’s servers. In doing so, a connection to Adobe’s servers is established. In particular, your IP address, the hostname of the website accessed and technical information about your browser and device may be transmitted to Adobe.
Adobe states that it does not place cookies on the embedded website when providing Adobe Fonts for websites. According to Adobe, the IP address is transmitted for technical purposes in order to deliver the relevant font.
Where Adobe Fonts are loaded only after you have given your consent, the processing is based on your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future.
Processing of personal data outside the European Union or the European Economic Area cannot be completely ruled out. Further information can be found in Adobe’s privacy information and the specific privacy information relating to Adobe Fonts.
Security plugins Wordfence and Security Ninja
We use the security plugins Wordfence and Security Ninja to protect our website against unauthorised access, malware, brute-force attacks and other security risks.
As part of their security functions, these plugins may process IP addresses, accessed URLs, the date and time of access, browser information, failed login attempts and other technical information relating to possible attacks or suspicious activities.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure provision of our website and in protecting our systems and the personal data processed through them against unauthorised access and other attacks.
Wordfence is provided by Defiant, Inc., United States. Depending on the plugin configuration, security data may be transmitted to the provider’s systems for the purpose of detecting and preventing attacks.
Security Ninja primarily processes security information within our WordPress installation. Depending on the functions and settings enabled, data or technical information may also be transmitted to services operated by the provider or associated service providers.
Security logs are stored only for as long as necessary to detect, document and prevent attacks. Longer storage may take place where a specific security incident must be investigated.
Processing of personal data in the United States or other third countries cannot be completely ruled out when external security services are used.
Google Maps
We use Google Maps on our directions page to display our location and enable route planning. Google Maps is a service provided by the Google group of companies.
The provider responsible for users in the European Economic Area is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
When Google Maps is loaded, your IP address, information about your browser and device, the page accessed, and the date and time of access may be transmitted to Google.
If you enter a starting address for route planning, this information will also be transmitted to Google and processed for the purpose of calculating the route.
In connection with the use of Google Maps, Google may store cookies or comparable technologies on your device or access information already stored on it.
Where Google Maps is loaded only after you have given your consent, the storage of or access to information on your device is based on Section 25(1) TDDDG. The associated processing of personal data is based on Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future via the privacy settings on our website.
Processing of personal data in the United States or other third countries cannot be completely ruled out. Further information can be found in Google’s privacy policy and the Google Maps terms of service.

