Mom Said No. Summer Breeze 2026

Summer Breeze 2026

Privacy notice

Privacy Notice

Version: 7 August 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation is:

Walhalla Ink e.K. Owner: Victoria Wolter Münchner Str. 21 85614 Kirchseeon Germany

Phone: +49 8091 55 40 700 E-mail: walhalla.ink@gmail.com Data protection enquiries: datenschutz@momsaidno.de

"Mom Said No" is a brand of Walhalla Ink e.K. and not a separate legal entity.

Where the designation "Mom Said No" is used on this website or in forms, the respective processing is carried out by Walhalla Ink e.K., unless expressly stated otherwise.

2. Hosting and Server Operation

This website, the online appointment booking and the electronic consent form are operated on systems of the hosting provider

Hetzner Online GmbH Industriestr. 25 91710 Gunzenhausen Germany

Hetzner processes personal data in the context of hosting as a processor pursuant to Art. 28 GDPR.

When you access the website, technically necessary data may be processed, in particular:

  • IP address,
  • date and time,
  • page or file accessed,
  • browser and operating system,
  • referrer information, and
  • technical status, connection and error data.

This processing serves the technical provision as well as the stability and security of the service.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of our systems.

Server log data is deleted as soon as it is no longer required for operation and security, unless a specific security incident or a legal obligation requires longer storage.

3. Online Appointment Booking

When you book an appointment, we process in particular:

  • first name,
  • last name,
  • e-mail address,
  • telephone number,
  • selected size category,
  • selected appointment,
  • amount of the appointment deposit,
  • optionally provided desired motif,
  • optionally entered notes, and
  • booking and transaction information.

This processing is carried out for the initiation and performance of the appointment reservation contract, for appointment management and for communication with you.

The legal basis is Art. 6(1)(b) GDPR.

Insofar as data is required after completion of the contract for the establishment, exercise or defence of legal claims, the processing is additionally based on Art. 6(1)(f) GDPR.

Insofar as data becomes part of records subject to retention under tax or commercial law, further storage takes place pursuant to Art. 6(1)(c) GDPR.

4. Appointment Deposit and PayPal

We use PayPal for the authorisation or, where applicable, settlement of the appointment deposit.

The provider of the corresponding payment services is in particular:

PayPal (Europe) S.à r.l. et Cie, S.C.A. 22–24 Boulevard Royal L-2449 Luxembourg

When PayPal is used, the information necessary for the payment or authorisation transaction is transmitted to PayPal or collected there directly.

This may include in particular:

  • name,
  • payment or PayPal account data,
  • authorisation amount,
  • transaction identifier,
  • date and time, and
  • technical payment and security information.

The transmission takes place for the performance of the appointment reservation contract pursuant to Art. 6(1)(b) GDPR.

PayPal processes some of this data as an independent controller under data protection law, in particular for payment processing, fraud prevention and the fulfilment of its own legal obligations.

Health data from the consent form is not transmitted to PayPal.

5. E-mail Communication via Google Workspace

We use Google Workspace for sending and receiving business e-mails.

The contractual partner for Google Workspace customers based in Germany is generally:

Google Cloud EMEA Limited 70 Sir John Rogerson's Quay Dublin 2 Ireland

Google processes the customer data transmitted in the context of Google Workspace as a processor in accordance with the applicable data processing agreement.

Via Google Workspace we send in particular appointment confirmations and organisational information regarding bookings.

In doing so, the following data in particular is processed:

  • e-mail address,
  • first and last name,
  • appointment details,
  • booking number and booked category, and
  • information regarding the appointment deposit.

This processing is carried out for the performance and organisation of the appointment reservation contract pursuant to Art. 6(1)(b) GDPR.

For other business communication, the legal basis is Art. 6(1)(f) GDPR.

The health information from our electronic consent form is not sent by our system via Google Workspace.

Please refrain, where possible, from sending us health data unsolicited by ordinary e-mail.

6. Electronic Consent Form

Prior to the tattooing, we process in the context of the consent form in particular:

  • first and last name,
  • telephone number,
  • e-mail address,
  • postal address,
  • country, postal code and city,
  • date of birth,
  • motif,
  • body location,
  • size of the tattoo,
  • declarations regarding information and consent,
  • place and date, and
  • signature.

This processing is carried out for the preparation and performance of the tattooing, for identification, for verifying our minimum-age requirement and for documenting that the information was provided and consent was given.

The legal basis is Art. 6(1)(b) GDPR.

The documentation of the information provided, the consent and the specific procedure is additionally based on our legitimate interest in being able to demonstrate proper performance and in the establishment or defence of possible legal claims pursuant to Art. 6(1)(f) GDPR.

The age limit of 18 years that we have set is a condition of our service offering and is not based on § 8 JuSchG (German Protection of Young Persons Act).

7. Health Data

As part of the consent form, we ask about health circumstances that may be relevant for assessing whether a tattoo can be performed safely and responsibly.

These include in particular information regarding:

  • allergies,
  • autoimmune and chronic diseases,
  • immunodeficiency,
  • blood clotting disorders and blood-thinning medication,
  • skin diseases,
  • infectious diseases,
  • diabetes,
  • epilepsy,
  • pregnancy,
  • regular use of medication, and
  • current illnesses or infections.

This is a special category of personal data pursuant to Art. 9 GDPR.

The processing is based on your explicit consent pursuant to Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR.

The consent may be withdrawn at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected.

You are not legally obliged to provide us with health data. However, without the information required for a responsible risk assessment, we may not be able to decide whether the tattoo can be performed safely and may therefore have to refuse to perform it.

Insofar as health data is required in an individual case for the establishment, exercise or defence of specific legal claims, the data necessary for this purpose may be further processed pursuant to Art. 9(2)(f) GDPR.

Health data from the health questionnaire is not transmitted by us to Google Workspace, PayPal or the festival organiser.

Health data is not used for advertising, marketing or profiling.

8. Voluntary Photo Consent

Photos are used for advertising or presentation purposes only with voluntary consent.

The legal basis is Art. 6(1)(a) GDPR.

Granting or refusing photo consent has no influence on whether the tattoo is performed or on its price.

Consent that has been given may be withdrawn at any time with effect for the future.

After a withdrawal, we cease further use and remove publications under our control, unless another legal basis exists for the further processing.

Content that has already been copied, shared or otherwise redistributed by third parties may not be fully retrievable.

In the event of publication on social networks, the image data is transmitted to the respective platform operator and processed there in accordance with its own privacy policies.

9. On-site Payment via the Festival Cashless System

Payment for the actual tattooing service is made via the cashless system provided by the festival.

This system is operated by the festival organiser or the payment service provider engaged by it under its own responsibility.

Walhalla Ink e.K. may receive the transaction information necessary for allocation, settlement and accounting.

The legal bases for this are Art. 6(1)(b) and, insofar as statutory bookkeeping and retention obligations exist, Art. 6(1)(c) GDPR.

Health data is not transmitted to the cashless system.

10. Recipients

Within Walhalla Ink e.K., only persons receive access to personal data insofar as this is necessary for their respective tasks.

External recipients or service providers may include in particular:

  • Hetzner Online GmbH as hosting and server service provider,
  • Google Cloud EMEA Limited in the context of Google Workspace,
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. for the appointment deposit,
  • tax advisors or accounting service providers,
  • lawyers and insurers, and
  • authorities and courts, insofar as a legal obligation exists or this is necessary for the pursuit of legal claims.

Health data is made accessible only to the most restricted group of persons possible and is not disclosed for third-party advertising purposes.

11. Storage Period

Personal data is generally stored only for as long as is necessary for the respective purpose.

Booking and Contract Data

Booking, contact and contract data is generally stored for the performance of the booking and subsequently for the period during which contractual claims may still be asserted.

The standard limitation period under civil law is generally three years and regularly begins at the end of the relevant calendar year.

Accounting Records

Insofar as data is part of accounting documents subject to retention under tax law, the respective statutory retention periods apply. Under current law, accounting documents must generally be retained for eight years.

Consent Form and Health Data

Health data is not stored solely on account of tax-law retention obligations.

After expiry of the period required for the regular documentation of the contract and of claims, it is reviewed whether further storage is necessary.

If there is a specific incident, a complaint, an asserted claim or another legally relevant occasion, only the data required for this purpose is stored further until the matter is finally resolved or until the expiry of the relevant statutory periods.

Photo Consent and Photos

Photos are processed until the consent is withdrawn or until the respective publication purpose ceases to apply.

Evidence of the granting and withdrawal of a consent may subsequently be stored for the duration of possible legal claims.

Server Log Data

Server log data is deleted as soon as it is no longer required for technical operation and IT security, unless a security incident requires longer storage.

12. Transfers to Third Countries

Our website and the electronic consent form are hosted via Hetzner.

When Google Workspace and PayPal are used, the respective providers may engage affiliated companies or subcontractors as part of their international technical infrastructure.

Insofar as personal data is processed outside the European Economic Area in this context, this takes place in accordance with Art. 44 et seq. GDPR, in particular on the basis of an adequacy decision of the European Commission or appropriate safeguards such as the EU Standard Contractual Clauses.

Health data from our health questionnaire is not transmitted by us to Google Workspace or PayPal.

13. Cookies and Tracking

We do not use any analytics, advertising or tracking services such as Google Analytics or Meta Pixel on this website.

We do not use any social media plugins that transmit data to social networks as soon as a page is merely accessed.

Insofar as technically necessary cookies or comparable storage technologies are used, this is done exclusively to the extent required to provide a function requested by you.

Insofar as § 25 TDDDG (German Telecommunications Digital Services Data Protection Act) is applicable, the storage of, or access to, information on the end device for technically strictly necessary functions takes place on the basis of § 25(2) no. 2 TDDDG.

The connection to PayPal is established in connection with the booking and payment function initiated by you.

14. Data Security

We take appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration or unauthorised disclosure.

Due to its particular sensitivity, access to health data is restricted to persons who need it for the preparation, performance or documentation of the tattooing.

15. Your Rights

Subject to the statutory requirements, you have in particular the following rights:

  • access pursuant to Art. 15 GDPR,
  • rectification pursuant to Art. 16 GDPR,
  • erasure pursuant to Art. 17 GDPR,
  • restriction of processing pursuant to Art. 18 GDPR,
  • data portability pursuant to Art. 20 GDPR,
  • objection pursuant to Art. 21 GDPR, and
  • withdrawal of consent given pursuant to Art. 7(3) GDPR.

Consent may be withdrawn at any time with effect for the future.

Data protection enquiries may be directed to:

datenschutz@momsaidno.de

16. Right to Lodge a Complaint

Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority.

The authority generally competent for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18 91522 Ansbach Germany

17. Provision of Data

The information marked as mandatory fields in the online booking is required in order to carry out the appointment reservation.

The identity, tattoo and consent information required prior to the tattooing is necessary in order to perform and document the service responsibly.

The health information is processed on the basis of explicit consent. Without the information required for the risk assessment, the tattoo may not be able to be performed.

The photo consent is voluntary.

18. Automated Decision-Making

No exclusively automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

← Back to the form