Last updated: February 2026 · GDPR / RGPD / DSGVO compliant
The controller for personal data collected on inkos.me is HIGH LABS FZE, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. Our Data Protection Officer can be reached at privacy@highlabs.tech. Because we process personal data of EU residents, GDPR (EU 2016/679) applies extra-territorially (Art. 3(2)).
Account data — name, email, phone, password hash, language, IP, session identifiers. Studio data — business name, VAT ID, address, artist profiles, portfolio media, bank / payment details, invoicing information. Client data — name, email, phone, date of birth, nationality, ID document copy if the studio requests it, session records, care notes, ink references, uploaded reference images, messages and payment history. Usage data — device, IP, log files, cookie identifiers.
a) Providing and improving the service — Art. 6(1)(b) contract; (b) Handling payments — Art. 6(1)(b) contract; (c) Fraud prevention and platform security — Art. 6(1)(f) legitimate interest; (d) Complying with tax, accounting and consumer-protection laws — Art. 6(1)(c) legal obligation; (e) Marketing communications — Art. 6(1)(a) consent, revocable at any time via the unsubscribe link in every email.
Account data is kept for the duration of the subscription plus 12 months after termination for legal defence purposes. Invoicing and tax records are kept for 10 years (obrigação fiscal em PT / § 147 AO na Alemanha). Client data on the studio account is retained under the studio's instructions; on account deletion, all client records are anonymised or deleted within 30 days. Server access logs are rotated after 90 days.
We share data on a need-to-know basis with: MongoDB Atlas (database hosting, EU region); Stripe Inc. (payment processing, EU + US via SCCs); Resend Inc. (transactional email, US via SCCs); Twilio Ireland Ltd (SMS); Google Ireland Ltd (OAuth login); Anthropic PBC / OpenAI Ltd (AI assistants — no client data is used to train their models under the enterprise agreement); Cloudflare (CDN and DDoS protection). International transfers rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR) and supplementary measures where required.
Access, rectification, erasure ("right to be forgotten"), restriction, portability, objection to processing based on legitimate interest, and withdrawal of consent. Requests are handled within 30 days at privacy@highlabs.tech. You also have the right to lodge a complaint with a supervisory authority — for Portugal: Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt; for Germany: Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI), www.bfdi.bund.de, or your regional Landesbeauftragter für Datenschutz.
INKOS does not take decisions producing legal effects on data subjects based solely on automated processing (Art. 22 GDPR). AI-generated suggestions inside the platform are always advisory and reviewed by the studio staff before execution.
We use strictly necessary cookies (session, CSRF, load-balancing) which do not require consent under ePrivacy Directive Art. 5(3). Analytics and marketing cookies are only set after explicit opt-in via the cookie banner and can be revoked at any time from the footer link.
All data in transit is encrypted with TLS 1.2+. Passwords are hashed with bcrypt (cost 12). Backups are encrypted at rest with AES-256. Access is restricted to authorised staff bound by confidentiality agreements. Suspected breaches are reported to affected data subjects and the CNPD within 72 h per Art. 33/34 GDPR.
The Platform is not intended for children under 16. Studios must not create client records for minors without parental / guardian consent under national law.
Material changes to this policy are notified at least 30 days in advance via email or in-app banner.
HIGH LABS FZE — Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. General: founder@highlabs.tech. Privacy / DPO: privacy@highlabs.tech.
When you connect your Google account under Settings → Integrations → Google Calendar, INKOS requests the scope https://www.googleapis.com/auth/calendar so that your INKOS bookings can be synchronised with your primary Google Calendar. Concretely: (a) INKOS reads events on your primary calendar (events.list) so that external commitments already on Google Calendar automatically block the corresponding slots on your public booking page, preventing double-booking; (b) INKOS creates, updates and deletes events on your primary calendar (events.insert / update / delete) so that every booking you confirm, reschedule or cancel inside INKOS is reflected in your Google Calendar on all your devices. Access and refresh tokens are stored encrypted at rest, isolated per studio, and refreshed via Google's standard OAuth flow. You can disconnect at any moment from Settings → Integrations → Google Calendar → Disconnect, which immediately revokes the tokens via oauth2.googleapis.com/revoke and deletes them from our database. You may also revoke access directly at https://myaccount.google.com/permissions. We never sell Google user data, never share it with advertisers, never use it to train machine-learning models, and never allow humans to read it beyond the individual studio owner who granted the access.
INKOS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.