Legal
This English version is provided for your convenience. Only the German version is legally binding.
Read the German version →Last updated: September 25, 2026
This privacy policy informs you, in accordance with Art. 13 and 14 GDPR, which personal data we process in connection with the "Needl" platform and mobile app, for what purpose, on what legal basis, and for how long we keep it.
The controller within the meaning of the GDPR is:
Jona Sebastian Schedelberger
Töllergasse 3/3/22
1210 Vienna, Austria
Phone: +43 677 61482892
Email: team@needl.at
No Data Protection Officer has been appointed under Art. 37 GDPR: Needl is not a public authority, and its core activity does not consist of large-scale, regular and systematic monitoring of individuals, nor of large-scale processing of special categories of personal data (Art. 9 GDPR). Inquiries can be directed to the contact details in Section 1.
Email address, password (stored only as a hash, never in plain text), role (client or artist), and email verification status. Processed to fulfill the usage agreement (Art. 6(1)(b) GDPR).
If you enable two-factor authentication: a TOTP secret and backup codes, both stored encrypted or hashed. Basis: Art. 6(1)(b) GDPR, since you activate this feature yourself.
Reference images, links, notes, desired placement, and timeframe that you upload. This content is hosted with an S3-compatible object storage service (see Section 4). Basis: Art. 6(1)(b) GDPR.
Message text within a booking chat is stored encrypted in the database (encryption at rest, with a key we hold — this is protection against unauthorized access to the database, not end-to-end encryption; see "Moderation Review" below for the one case in which staff read message content). Also stored: proposed appointment times, prices, desired tattoo size, and booking status. Basis: Art. 6(1)(b) GDPR.
Messages may occasionally contain voluntarily shared, health-related details (e.g. about skin condition, allergies, or medication). We do not separately categorize or analyze such details; the same safeguards apply as for messages generally. To the extent this constitutes processing of special categories of personal data under Art. 9 GDPR, we rely on Art. 9(2)(a) GDPR (you share this information on your own initiative as part of booking communication).
If you report or block another user, we store who reported/blocked whom, the reason, and any details you provide, for platform safety purposes. Basis: Art. 6(1)(f) GDPR (legitimate interest in trust and safety on the platform; for EU users, also DSA Art. 16, which requires a notice-and-action mechanism).
If a report is filed about you, you are not notified of it, and the identity of the reporting person is not disclosed to you — otherwise the system could be used to retaliate against people who report misconduct, defeating its purpose. You will be told about any restriction placed on your own account; you can request what report data is held about you via the contact details in Section 1 (see Section 10). This individual non-notification relies on Art. 14(5)(b) GDPR.
Outcome of a report you filed: we tell you once it has been reviewed and whether we acted on it — not what was decided about the other person's account, since that is their own data.
Moderation review: when a report is filed, staff review the reported content — the reported message and the conversation it belongs to, or the booking the two of you share — together with basic account details of both people involved (display name, email, role, account creation date, and prior reports/restrictions). This is necessary to decide on a report. The review is limited to the conversation the report came from, does not constitute a general right of access to your messages, and is logged internally (reviewer's name, time, scope).
If you contact us through the support section, we process the content of your request and our replies in order to handle it. Basis: Art. 6(1)(b) GDPR.
If you subscribe to a paid plan, our payment processor, Stripe, handles your payment details directly — we store only your subscription status and billing period, never your card details. Basis: Art. 6(1)(b) GDPR.
Publicly visible information such as studio name, address, phone number, portfolio, prices, and availability — entered by the artist themselves as public business information. Basis: Art. 6(1)(b) GDPR.
Your settings for which events reach you by email or push notification, plus a device token if you enable push notifications through the mobile app. Basis: depending on category, Art. 6(1)(a) GDPR (consent-based, optional notifications) or Art. 6(1)(b) GDPR (operationally necessary notifications).
When you register — and again whenever our Terms and Conditions change — we record that you confirmed you are at least 18 years old and which version of the Terms you accepted, together with the date and time. When you buy something on our website, we additionally record the two declarations the law requires before a digital service may start inside the 14-day withdrawal period — that you expressly asked us to begin, and that you knew this ends your right of withdrawal — together with the price you were shown.
For each of these confirmations, we also store the IP address and browser/app identification (user agent) it was given from, so that it can be attributed if ever disputed. Basis: the confirmations themselves rest on Art. 6(1)(c) GDPR (§ 8 FAGG and our Terms require this documentation); the IP address and user agent rest on Art. 6(1)(f) GDPR (legitimate interest in being able to evidence a disputed confirmation). This data serves only this evidentiary purpose and is never used for profiling or tracking.
A session cookie for login, a cookie protecting against cross-site request forgery (CSRF), and a cookie storing your language preference (see Section 7). We do not keep a general access log of individual page views; what is processed is limited to technical application logs (errors and security-relevant events such as invalid or suspicious requests), a sign-in history (time of each successful login, IP address, browser/app identification), and, to protect against automated login attempts (brute-force protection), a short-lived count of failed login attempts per IP address. Basis: Art. 6(1)(b) GDPR (session/CSRF cookie, operationally necessary) or Art. 6(1)(f) GDPR (application logs, sign-in history, and brute-force protection, legitimate interest in secure operation).
Your data is shared, to the extent necessary for the respective purpose, with the following categories of processors/recipients. A data processing agreement under Art. 28 GDPR is in place with each, where required:
send_default_pii is explicitly disabled on both platforms).
Processing takes place in Sentry's EU region (Frankfurt, Germany).No processor receives more data than is necessary for its task.
Hosting, database, and object storage are located entirely within the EU (Hetzner Online GmbH, Germany); no third-country transfer occurs there.
Our email delivery (Proton Mail, Section 4) is provided by Proton AG, based in Switzerland. Switzerland is not an EU/EEA member, but the European Commission has issued an adequacy decision for it under Art. 45 GDPR — a transfer there is therefore permitted without additional safeguards (e.g. standard contractual clauses).
Using Apple's services (Sign in with Apple, APNs) and Stripe may result in personal data being transferred to the USA. These providers state that such transfers rely on standard contractual clauses and/or an EU adequacy decision (e.g. the EU-U.S. Data Privacy Framework); you can check each provider's current certification/safeguard status on their own website.
Error tracking (Sentry, Section 4) is processed in Sentry's EU region (Frankfurt, Germany); no third-country transfer occurs for the data itself. Sentry's own corporate entity is based in the USA, so incidental access (e.g. by customer support) may still involve the USA — our data processing agreement with Sentry provides for this via standard contractual clauses, the same safeguard Apple and Stripe rely on above.
Account data is stored for as long as the account exists. After account deletion, personal data is deleted, with the following exceptions:
The confirmations described in Section 3.10 (age, acceptance of the Terms, withdrawal-period declarations) are not among these exceptions: they are deleted together with your account, since the contract they relate to ends with it.
If you had a paid subscription, deleting your account also cancels it and triggers deletion of your payment details at Stripe — Stripe may still be required to retain transaction records independently, due to its own legal (in particular tax) obligations.
Database backups (encrypted, at Hetzner Object Storage) are automatically deleted after 90 days. The technical application logs described in Section 3.11 are rotated on a size basis (not a calendar basis). The sign-in history described there is automatically deleted after 90 days. The failed-login-attempt count resets automatically after around an hour, as soon as the next failed login happens anywhere on the platform.
Needl uses only technically necessary cookies:
These cookies are necessary for operating the website, or for a function you have explicitly requested (§ 165(3) TKG 2021), and therefore do not require separate consent. No tracking, analytics, or marketing cookies are used, and no third-party tracking (e.g. web analytics services, social media plugins) is embedded.
No automated decision-making within the meaning of Art. 22 GDPR takes place that produces legal effects concerning you or similarly significantly affects you. No profiling for advertising or analytics purposes occurs.
Providing the account data listed in Section 3.1 is required to use Needl; without it, no account can be created and the service cannot be used. All other information (e.g. profile data, message content, two-factor authentication) is voluntary; if you choose not to provide it, individual platform features may be limited or unavailable.
Under the GDPR you have the right to:
For access and portability, use the automated export under "Account → Export data" in the app, which emails you a compilation of your data. Report records (Section 3.5) are excluded from that automated export, because releasing them automatically would disclose who reported you and why — which would adversely affect that person's own rights (Recital 63 GDPR). If you want to know what report data we hold about you, contact us using the details in Section 1 and we will compile it manually, with other people involved anonymized.
You also have the right to lodge a complaint with the Austrian data protection authority:
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at
We use technical and organizational measures to protect your data, including: passwords are stored only as hashes, booking messages are stored encrypted in the database, connections to our services are TLS-encrypted throughout, and access to particularly sensitive administrative functions is restricted to authorized staff and logged. Absolute security cannot, however, be guaranteed for data transmitted over the internet.
We update this privacy policy whenever Needl's processing of personal data changes, or new legal requirements make it necessary. The current version is always available at this address, with the date of the last update at the top of the document.